BLS secret key validation is missing

Open
#96 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
typescript
Domain
cryptography

Research direction

Read the BLS specification section linked in the issue, then inspect src/blst/secretKey.ts and src/lib.ts at the two fromBytes implementations. Verify how secret keys are currently accepted and use the existing test setup to cover the boundary; done means values with SK >= r are rejected in both paths while valid keys remain accepted.

Written by the indexing model from the issue text.

Description

good first issue help wanted

Describe the bug
The BLS spec requires that the secret key (SK) must be a uniformly random integer such that 1 <= SK < r.
Where r is the order curve.

The last check is missing:

Expected behavior

Check that the provided SK < r.

Dominant language
TypeScript
Stars
106
Forks
24
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from ChainSafe/bls

All issues in ChainSafe/bls

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.