Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

signMessage drops the COSE_Key, producing an incomplete CIP-30 DataSignature

Đang mở
#481 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
typescript
Lĩnh vực
api

Hướng nghiên cứu

Đọc packages/evolution/src/sdk/client/internal/Signing.ts signMessage và packages/evolution/src/sdk/wallet/Wallet.ts SignedMessage, sau đó so sánh chúng với packages/evolution/src/cose/SignData.ts. Thêm một bài kiểm thử hồi quy cho wallet.signMessage và verifyData, đồng thời xác minh rằng kết quả được trả về bao gồm COSE_Key và việc xác minh thành công cho cả hai đường dẫn API của wallet.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug external-review

Summary

CIP-30 signData returns a DataSignature of { signature, key }, where key is the CBOR-encoded COSE_Key needed to verify the signature. SignData.signData produces both, but the wallet's signMessage returns only { payload, signature } and drops the key, and the SignedMessage interface has no key field. A consumer therefore cannot verify a message signed via the wallet API without obtaining the public key some other way, which breaks self-contained CIP-30 verification. No security impact: the dropped value is a public key, so nothing is leaked or made forgeable — it is a functional / spec-compliance gap.

Affected

packages/evolution/src/sdk/client/internal/Signing.ts

  • signMessage (L363-381): returns { payload, signature } at L380, dropping signed.key

packages/evolution/src/sdk/wallet/Wallet.ts

  • SignedMessage interface (L37-39): has payload + signature, no key

contrast: packages/evolution/src/cose/SignData.ts SignedMessage (L39-41) already carries { signature, key }

Fix

Add a key field to the wallet SignedMessage interface and return Bytes.toHex(signed.key) from signMessage. Ensure the CIP-30 api-wallet path carries the key through as well, so both wallet types return a complete DataSignature.

Regression test

  • given: a message signed via wallet.signMessage
  • before fix: result has no key field; verifyData cannot be called without externally supplying the public key
  • after fix: result includes the COSE_Key hex, and verifyData(address, keyHash, payload, { signature, key }) verifies
    Must FAIL on main today and PASS after the fix.

Reference

Reported informally (signMessage drops COSE_Key). Standard basis: CIP-30 DataSignature = { signature, key }.

Ngôn ngữ chính
TypeScript
Star
22
Fork
33
Merge trung bình
2 ngày 1 giờ
Pull request đã merge (30 ngày)
44

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của IntersectMBO/evolution-sdk

Tất cả issue của IntersectMBO/evolution-sdk

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.