6 / 9
Signed requests
Proofs expire
A captured proof is useless after it expires, so every proof says when that is. Its data holds four fields, all inside the signature:
action: what it's for, likecreate-noteidentityKey: who signed itexpiresAt: when it stops working, in millisecondsnonce: random and single-use, for replay protection
Your task#
- Click Sign a proof in the preview and look at the fields. Then Send it 3 minutes late. The server refuses it:
refused: Proof expiredin the Server panel. (The tutorial fakes the delay, so you don't wait; see the comment inserver/src/index.ts.) - Make proofs last 30 seconds. In
server/src/index.ts, setWINDOW_MS = 30_000. Sign and Send now: refused again,Proof expiry too far in the future. The client still signs proofs that live 2 minutes, which is longer than this server allows. - In
client/src/App.tsx, setWINDOW_MS = 30_000too. Sign, send now:window 30s: valid.
Your task
- Send a proof too late and see it refused
- Shorten the server's window and see the client's proofs refused
- Make both sides agree on 30 seconds