signMessage drops the COSE_Key, producing an incomplete CIP-30 DataSignature
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- typescript
- Lĩnh vực
- api
Hướng nghiên cứu
Đọc packages/evolution/src/sdk/client/internal/Signing.ts signMessage và packages/evolution/src/sdk/wallet/Wallet.ts SignedMessage, sau đó so sánh chúng với packages/evolution/src/cose/SignData.ts. Thêm một bài kiểm thử hồi quy cho wallet.signMessage và verifyData, đồng thời xác minh rằng kết quả được trả về bao gồm COSE_Key và việc xác minh thành công cho cả hai đường dẫn API của wallet.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
CIP-30 signData returns a DataSignature of { signature, key }, where key is the CBOR-encoded COSE_Key needed to verify the signature. SignData.signData produces both, but the wallet's signMessage returns only { payload, signature } and drops the key, and the SignedMessage interface has no key field. A consumer therefore cannot verify a message signed via the wallet API without obtaining the public key some other way, which breaks self-contained CIP-30 verification. No security impact: the dropped value is a public key, so nothing is leaked or made forgeable — it is a functional / spec-compliance gap.
Affected
packages/evolution/src/sdk/client/internal/Signing.ts
- signMessage (L363-381): returns
{ payload, signature }at L380, droppingsigned.key
packages/evolution/src/sdk/wallet/Wallet.ts
- SignedMessage interface (L37-39): has payload + signature, no
key
contrast: packages/evolution/src/cose/SignData.ts SignedMessage (L39-41) already carries { signature, key }
Fix
Add a key field to the wallet SignedMessage interface and return Bytes.toHex(signed.key) from signMessage. Ensure the CIP-30 api-wallet path carries the key through as well, so both wallet types return a complete DataSignature.
Regression test
- given: a message signed via
wallet.signMessage - before fix: result has no
keyfield;verifyDatacannot be called without externally supplying the public key - after fix: result includes the COSE_Key hex, and
verifyData(address, keyHash, payload, { signature, key })verifies
Must FAIL on main today and PASS after the fix.
Reference
Reported informally (signMessage drops COSE_Key). Standard basis: CIP-30 DataSignature = { signature, key }.
- Ngôn ngữ chính
- TypeScript
- Star
- 22
- Fork
- 33
- Merge trung bình
- 2 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 44
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của IntersectMBO/evolution-sdk
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
IntersectMBO/evolution-sdk#559 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
IntersectMBO/evolution-sdk#557 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
dependencies good first issue
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 93/100
IntersectMBO/evolution-sdk#541 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
IntersectMBO/evolution-sdk#518 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement external-review
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
IntersectMBO/evolution-sdk#456 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của IntersectMBO/evolution-sdk
Issue tương tự
-
Table: Space fires onActivate in single-selection mode — the reference doc and the JSDoc disagreeĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
sidorares/react-x11-components#764 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
backnotprop/plannotator#1840 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
JoviDeCroock/pracht#432 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add: CNN en Espanol SDĐang mởapproved check:passed streams:add
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Hardware attribute name "app Connection Support" has inconsistent casingCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
walletbeat/walletbeat#1628 ·
Maintainer thường phản hồi trong vòng 1 ngày