Skip to content

feat(server): dedicated signing key and signed expiry for GET render URLs - #132

Merged
ajianaz merged 1 commit into
developfrom
feat/signing-key-expiry
Oct 7, 2026
Merged

ajianaz merged 1 commit into
developfrom
feat/signing-key-expiry

Conversation

@ajianaz

@ajianaz ajianaz commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

What

Dedicated --signing-key / COSY_SIGNING_KEY for signed GET render URLs and optional signed exp expiry. Stacked on #131.

Why

Signed URLs reused the API key as HMAC key (leaking one leaks both) and never expired. Closes #129.

How

Signing key falls back to API key for compatibility; exp is part of the signed payload so it cannot be stripped or injected; Cache-Control capped to remaining lifetime.

Testing

  • cargo test passes
  • cargo fmt --all -- --check passes
  • cargo clippy --all-targets -- -D warnings passes
  • cargo build --release passes (CI)
  • Manual smoke-test: reproduced the issue against cosy serve before the fix; regression tests added.

Related Issues

Closes #129

Checklist

  • Branch name follows convention
  • Branch is from develop

🤖 Generated with Claude Code

@ajianaz
ajianaz force-pushed the perf/render-pipeline branch from aec4846 to 82bc054 Compare October 7, 2026 07:09
@ajianaz
ajianaz force-pushed the feat/signing-key-expiry branch from a0ee090 to 5c321ca Compare October 7, 2026 07:16
…URLs

Closes #129

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@ajianaz
ajianaz force-pushed the feat/signing-key-expiry branch from 5c321ca to 43123bd Compare October 7, 2026 07:19
@ajianaz
ajianaz changed the base branch from perf/render-pipeline to develop October 7, 2026 07:19
@ajianaz ajianaz closed this Oct 7, 2026
@ajianaz ajianaz reopened this Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔍 Cora AI Code Review

✅ No issues found. Code looks good!


Review powered by cora-code · BYOK · MIT

@ajianaz
ajianaz merged commit 71c00a2 into develop Oct 7, 2026
14 checks passed
@ajianaz
ajianaz deleted the feat/signing-key-expiry branch October 7, 2026 07:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: separate signing key and expiry for signed GET render URLs

1 participant