aboutsummaryrefslogtreecommitdiffstats
path: root/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java
diff options
context:
space:
mode:
authorTim Bray <tbray@textuality.com>2014-11-21 19:44:05 -0800
committerTim Bray <tbray@textuality.com>2014-11-21 19:44:05 -0800
commite72c082acd9f17be4a21970603df0f6a621221d7 (patch)
treea0f58b3a231c481c848fee3452d5efdc13c456e0 /OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java
parentbbbc45e4e9909806a91afe415265b507533f7556 (diff)
downloadopen-keychain-e72c082acd9f17be4a21970603df0f6a621221d7.tar.gz
open-keychain-e72c082acd9f17be4a21970603df0f6a621221d7.tar.bz2
open-keychain-e72c082acd9f17be4a21970603df0f6a621221d7.zip
Add check that proof & database fingerprints are the same
Diffstat (limited to 'OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java')
-rw-r--r--OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java9
1 files changed, 6 insertions, 3 deletions
diff --git a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java
index a4a3a801a..dc9592710 100644
--- a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java
+++ b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/service/KeychainIntentService.java
@@ -30,7 +30,6 @@ import com.textuality.keybase.lib.Proof;
import com.textuality.keybase.lib.prover.Prover;
import org.json.JSONObject;
-import org.openintents.openpgp.OpenPgpSignatureResult;
import org.spongycastle.openpgp.PGPUtil;
import org.sufficientlysecure.keychain.Constants;
import org.sufficientlysecure.keychain.R;
@@ -324,6 +323,11 @@ public class KeychainIntentService extends IntentService implements Progressable
sendProofError(prover.getLog(), getString(R.string.keybase_problem_fetching_evidence));
return;
}
+ String requiredFingerprint = data.getString(KEYBASE_REQUIRED_FINGERPRINT);
+ if (!prover.checkFingerprint(requiredFingerprint)) {
+ sendProofError(getString(R.string.keybase_key_mismatch));
+ return;
+ }
String domain = prover.dnsTxtCheckRequired();
if (domain != null) {
@@ -361,13 +365,12 @@ public class KeychainIntentService extends IntentService implements Progressable
InputData inputData = createDecryptInputData(data);
OutputStream outStream = createCryptOutputStream(data);
- String fingerprint = data.getString(KEYBASE_REQUIRED_FINGERPRINT);
PgpDecryptVerify.Builder builder = new PgpDecryptVerify.Builder(
this, new ProviderHelper(this), this,
inputData, outStream
);
- builder.setSignedLiteralData(true).setRequiredSignerFingerprint(fingerprint);
+ builder.setSignedLiteralData(true).setRequiredSignerFingerprint(requiredFingerprint);
DecryptVerifyResult decryptVerifyResult = builder.build().execute();
outStream.close();