Skip to content

getTransportFlags silently encodes an unmapped transport as Ble #110

Description

@Firehed

Codecs\Credential::getTransportFlags() resolves each transport to a bit position via array_search:

private static function getTransportFlags(array $transports): int
{
    $flags = 0;
    foreach ($transports as $transport) {
        $bit = array_search($transport, self::TRANPSORT_FLAGS, true);
        $flags |= (1 << $bit);
    }
    return $flags;
}

array_search returns false when the value is absent, and 1 << false evaluates to 1 << 0 — the bit for Ble. An unmapped transport is therefore silently encoded as Ble rather than raising.

This is unreachable today: Enums\AuthenticatorTransport has exactly six cases and TRANPSORT_FLAGS maps all six. It becomes reachable the moment a case is added to the enum without updating the map — which is easy to miss, since nothing links the two.

The decode side is not symmetric either: parseTransportFlags() iterates bits 0-5 and ignores bits 6-7, so a round-trip through a future encoder that used the RFU bits would silently drop them.

Suggested resolution

Have the lookup fail loudly on a miss, or move the bit position onto the enum itself (a method or a match) so the mapping cannot drift from the cases.

Unrelated but adjacent: the constant is spelled TRANPSORT_FLAGS, while the class docblock refers to it as TRANSPORT_FLAGS.


This issue body was written by AI. The underlying findings were reviewed by a human.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions