Problem/Motivation

OtpController and the Otp gate method always hash codes with file_gate.settings:download_secret (legacy). Named-only installs ($settings['file_gate.secrets'] only) still pass hasAnySecret(), so OTP can issue, but HMAC material may be empty or inconsistent with mint/scope secrets.

GitHub: Wilkes-Liberty/file_gate#39.

Steps to reproduce

  1. Configure only named secrets in $settings['file_gate.secrets']; leave legacy download_secret empty.
  2. Enable OTP gate method and request an OTP for a gated file.
  3. Observe that OTP issue still succeeds while hashing is not keyed by the named secret material used for mint/scope.

Proposed resolution

Hash OTP codes with the authenticated secret material from SecretRegistry / ActiveSecret used for the request (same as mint).

Remaining tasks

  • Wire OTP hashing to the active/named secret path
  • Kernel test for named-secrets-only deploy
  • Dual-venue status updated on ship

API changes

None for clients; internal hashing only.

Data model changes

None.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

jmcerda’s picture

Status: Fixed » Closed (fixed)
jmcerda’s picture

Closed (fixed): OTP hashing uses named secret material (not legacy-only) shipped in 1.4.0 (GH #39).

https://www.drupal.org/project/file_gate/releases/1.4.0
https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.4.0

jmcerda’s picture

Confirm Closed (fixed). Work shipped; removing from Open queue.