Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

signMessage drops the COSE_Key, producing an incomplete CIP-30 DataSignature

Abierto
#481 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 7 días

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
78/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Tranquilo
Stack tecnológico
typescript
Área
api

Línea de trabajo

Lee packages/evolution/src/sdk/client/internal/Signing.ts signMessage y packages/evolution/src/sdk/wallet/Wallet.ts SignedMessage, y compáralos con packages/evolution/src/cose/SignData.ts. Añade una prueba de regresión para wallet.signMessage y verifyData, y verifica que el resultado devuelto incluya el COSE_Key y que la verificación sea exitosa para ambas rutas de la API de wallet.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug external-review

Summary

CIP-30 signData returns a DataSignature of { signature, key }, where key is the CBOR-encoded COSE_Key needed to verify the signature. SignData.signData produces both, but the wallet's signMessage returns only { payload, signature } and drops the key, and the SignedMessage interface has no key field. A consumer therefore cannot verify a message signed via the wallet API without obtaining the public key some other way, which breaks self-contained CIP-30 verification. No security impact: the dropped value is a public key, so nothing is leaked or made forgeable — it is a functional / spec-compliance gap.

Affected

packages/evolution/src/sdk/client/internal/Signing.ts

  • signMessage (L363-381): returns { payload, signature } at L380, dropping signed.key

packages/evolution/src/sdk/wallet/Wallet.ts

  • SignedMessage interface (L37-39): has payload + signature, no key

contrast: packages/evolution/src/cose/SignData.ts SignedMessage (L39-41) already carries { signature, key }

Fix

Add a key field to the wallet SignedMessage interface and return Bytes.toHex(signed.key) from signMessage. Ensure the CIP-30 api-wallet path carries the key through as well, so both wallet types return a complete DataSignature.

Regression test

  • given: a message signed via wallet.signMessage
  • before fix: result has no key field; verifyData cannot be called without externally supplying the public key
  • after fix: result includes the COSE_Key hex, and verifyData(address, keyHash, payload, { signature, key }) verifies
    Must FAIL on main today and PASS after the fix.

Reference

Reported informally (signMessage drops COSE_Key). Standard basis: CIP-30 DataSignature = { signature, key }.

Lenguaje dominante
TypeScript
Estrellas
22
Forks
30
Merge medio
1 d 13 h
PR fusionados (30 d)
13

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de IntersectMBO/evolution-sdk

Todos los issues de IntersectMBO/evolution-sdk

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.