Skip to content

fix(auth): Normalize client_sig and callerSig to SHA-1 hex digest - #262

Merged
LisoUseInAIKyrios merged 1 commit into
MorpheApp:devfrom
zeldrisho:fix/oauth-cert-sha1-normalization
Sep 13, 2026
Merged

LisoUseInAIKyrios merged 1 commit into
MorpheApp:devfrom
zeldrisho:fix/oauth-cert-sha1-normalization

Conversation

@zeldrisho

@zeldrisho zeldrisho commented Sep 11, 2026 •

Copy link
Copy Markdown

While integrating a separate custom Zalo patch maintained in Zeldris Patches, I found that Google Drive login could not acquire an OAuth token with microG-RE. This prevented Zalo’s image sync and backup/restore flow from working. Zalo is the reproduction case only; this PR contains no Zalo-specific changes.

The auth request was sending the certificate’s raw DER encoding as hexadecimal in client_sig and callerSig, while the endpoint expects the developer-console certificate SHA-1 fingerprint. That mismatch caused UNREGISTERED_ON_API_CONSOLE.

This change normalizes both fields immediately before the auth request: existing 40-character SHA-1 values are preserved in lowercase, while DER-encoded certificate hex is decoded and hashed to a lowercase 40-character SHA-1 digest. The separate Zalo integration now completes Google Drive OAuth and backup/restore successfully, and existing integrations such as patched YouTube OAuth continue to work.

@zeldrisho
zeldrisho marked this pull request as ready for review September 11, 2026 10:41
@LisoUseInAIKyrios LisoUseInAIKyrios changed the title fix(auth): normalize client_sig and callerSig to SHA-1 hex digest fix(auth): Normalize client_sig and callerSig to SHA-1 hex digest Sep 13, 2026
@LisoUseInAIKyrios
LisoUseInAIKyrios changed the base branch from main to dev September 13, 2026 09:27
@LisoUseInAIKyrios
LisoUseInAIKyrios merged commit e5cb8ed into MorpheApp:dev Sep 13, 2026
2 checks passed
@LisoUseInAIKyrios

Copy link
Copy Markdown

Thanks for the help.

@zeldrisho
zeldrisho deleted the fix/oauth-cert-sha1-normalization branch September 13, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants