Build a useful investigation brief
Build timestamp fixtures
Create recent, boundary, stale, seconds-versus-milliseconds, invalid, wrong-secret, and altered-body cases. Record expected signature and freshness results before execution. Use synthetic timestamps and bodies. Preserve timestamp unit in each case for review.
Trace verifier stages
Capture raw time label, parsed time, receiver clock, tolerance, signature comparison, freshness result, and final disposition. Compare the first divergence between valid recent and stale fixtures. Keep secret and body values protected.
Vary one clock input
Change only receiver clock, timestamp unit, tolerance, body, secret, or delivery delay. Compare results and side effects. If sender time cannot be trusted or observed, state the gap instead of widening acceptance. Document the source timing.
What to carry forward
The investigation is ready when fixtures show whether the first divergence is signature, parsing, clock, or freshness. Deliver a narrow time or verifier change. Keep replay and sender-delay limits explicit. Keep timestamp parsing separate from cryptographic verification. Record the time-source owner.
Technical background: Coinbase developer documentation.
Keep the decision with the work.
Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.
Create an account See the product workflow