Eip712 review (#355)
* Possible security fix. It is possible to send a new structure definition after sending a structure implementation, which makes the app treat unrestricted data as if it was a well defined structure. This commit tries to fix that behaviour. Once a structure implementation is sent, we consider all structures to be defined and we do not allow new definitions. * Fix previous commit
This commit is contained in:
@@ -52,6 +52,11 @@ bool handle_eip712_struct_def(const uint8_t *const apdu_buf) {
|
||||
if (eip712_context == NULL) {
|
||||
ret = eip712_context_init();
|
||||
}
|
||||
|
||||
if (struct_state == DEFINED) {
|
||||
ret = false;
|
||||
}
|
||||
|
||||
if (ret) {
|
||||
switch (apdu_buf[OFFSET_P2]) {
|
||||
case P2_DEF_NAME:
|
||||
|
||||
Reference in New Issue
Block a user