open-eid / eudi-qeaa-wallet-mock

MIT License
0 stars 1 forks source link

Wallet private key leak in wallet instance attestation #2

Closed ydanneg closed 7 months ago

ydanneg commented 7 months ago

https://github.com/open-eid/eudi-qeaa-wallet-mock/blob/3fe009bc464c7393cec54dedca4bd36ba409afa8/src/main/java/ee/ria/eudi/qeaa/wallet/configuration/WalletAttestationConfiguration.java#L35

.claim("cnf", Map.of("jwk", walletSigningKey.toJSONObject()))

should be

.claim("cnf", Map.of("jwk", walletSigningKey.toPublicJWK().toJSONObject()))