Skip to content

#2 Issue 2: [Auth] Verify Watch Time Pings #2

@elizabetheonoja-art

Description

@elizabetheonoja-art

Description:
The frontend sends a 'ping' every minute. The backend must verify this ping is signed by the user's wallet before updating the DB.

Acceptance Criteria:

[ ] Verify x-signature header using stellar-sdk.

[ ] Check if timestamp is recent (replay attack prevention).

[ ] Update student_progress table only if valid.

Priority: Critical
Labels: security, api

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions