Skip to content

Align CoseKey async verification with synchronous validation - #130973

Merged
vcsjones merged 4 commits into
mainfrom
copilot/fix-cosekey-verify-methods
Jul 18, 2026
Merged

vcsjones merged 4 commits into
mainfrom
copilot/fix-cosekey-verify-methods

Conversation

Copilot AI commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

CoseKey async verification accepted signatures with missing or mismatched protected alg headers, unlike synchronous verification.

  • Validation

    • Validate the protected algorithm before async verification.
    • Apply consistent validation to CoseSign1Message and CoseSignature.
  • Coverage

    • Cover missing and mismatched algorithm headers.
    • Assert matching sync and async behavior.

Copilot AI requested review from Copilot and removed request for Copilot July 17, 2026 14:29
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Co-authored-by: vcsjones <361677+vcsjones@users.noreply.github.com>
Copilot AI requested review from Copilot and removed request for Copilot July 17, 2026 14:54
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

Copilot AI changed the title [WIP] Fix CoseKey overloads of VerifyAsync to match synchronous Verify Align CoseKey async verification with synchronous validation Jul 17, 2026
Copilot AI requested a review from vcsjones July 17, 2026 15:01
@vcsjones
vcsjones marked this pull request as ready for review July 17, 2026 15:29
Copilot AI temporarily deployed to copilot-pat-pool July 17, 2026 15:29 Inactive
Copilot AI review requested due to automatic review settings July 17, 2026 15:29
Copilot AI temporarily deployed to copilot-pat-pool July 17, 2026 15:30 Inactive
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR makes COSE signature verification stricter and consistent by ensuring async verification performs the same protected alg header validation as the sync paths when verifying with a CoseKey.

Changes:

  • Add protected alg validation to VerifyDetachedAsync(CoseKey, Stream, …) for both CoseSign1Message and CoseSignature.
  • Refactor CoseSign1Message sync verification to reuse a shared ValidateAlgorithm helper.
  • Add regression tests covering missing and mismatched protected alg headers and asserting sync/async parity.
Show a summary per file
File Description
src/libraries/System.Security.Cryptography.Cose/tests/CoseSign1MessageTests.Verify.Stream.cs Adds regression coverage for missing/mismatched protected alg headers and asserts sync/async both throw.
src/libraries/System.Security.Cryptography.Cose/tests/CoseMultiSignMessageTests.Verify.Stream.cs Adds parallel regression coverage for CoseSignature verification in CoseMultiSignMessage.
src/libraries/System.Security.Cryptography.Cose/src/System/Security/Cryptography/Cose/CoseSignature.cs Adds ValidateAlgorithm(key) before async verification and inside the sync verification core to enforce protected alg matching.
src/libraries/System.Security.Cryptography.Cose/src/System/Security/Cryptography/Cose/CoseSign1Message.cs Replaces inline sync validation with ValidateAlgorithm(key) and adds the same validation to the async verification entrypoint.

Copilot's findings

  • Files reviewed: 4/4 changed files
  • Comments generated: 2

Copilot AI review requested due to automatic review settings July 17, 2026 20:09
@vcsjones
vcsjones temporarily deployed to copilot-pat-pool July 17, 2026 20:09 — with GitHub Actions Inactive
@vcsjones
vcsjones temporarily deployed to copilot-pat-pool July 17, 2026 20:09 — with GitHub Actions Inactive

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 5/5 changed files
  • Comments generated: 1

Comment thread src/libraries/System.Security.Cryptography.Cose/src/Resources/Strings.resx Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 17, 2026 20:32
@vcsjones
vcsjones temporarily deployed to copilot-pat-pool July 17, 2026 20:32 — with GitHub Actions Inactive
@vcsjones
vcsjones temporarily deployed to copilot-pat-pool July 17, 2026 20:32 — with GitHub Actions Inactive

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 5/5 changed files
  • Comments generated: 0 new

@vcsjones
vcsjones merged commit 3522269 into main Jul 18, 2026
90 checks passed
@vcsjones
vcsjones deleted the copilot/fix-cosekey-verify-methods branch July 18, 2026 03:06
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 11.0-preview7 milestone Jul 19, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 19, 2026

This branch was previously deployed

1 inactive deployment
copilot-pat-pool — 2f56a462 Deployed Jul 17, 2026 by vcsjones via pat_pool #15685
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

CoseKey overloads of VerifyAsync do not always agree with (synchronous) Verify

4 participants