security(M1): verify Nostr event signatures on kind 21000
Add verifyEvent() check before processing kind 21000 events from Lightning.Pub. While NIP-44v1 encryption provides implicit authentication (relay can't forge encrypted content without the shared secret), verifying signatures adds defense-in-depth against any future changes that might weaken the encryption assumption. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
f1011e7cee
commit
adbfffa0c3
1 changed files with 7 additions and 0 deletions
|
|
@ -22,6 +22,7 @@ import {
|
|||
type MachineIdentity,
|
||||
type Event as NostrEvent,
|
||||
} from '@lamassu/nostr-client'
|
||||
import { verifyEvent } from 'nostr-tools'
|
||||
import { LightningPubClient } from '@lamassu/lightning'
|
||||
import {
|
||||
CLINKClient,
|
||||
|
|
@ -533,6 +534,12 @@ function startDebitApprovalService(
|
|||
return
|
||||
}
|
||||
|
||||
// Verify event signature (defense-in-depth: relay can't forge, but verify anyway)
|
||||
if (!verifyEvent(event as any)) {
|
||||
console.warn('[Debit] SECURITY: Event failed signature verification:', event.id.slice(0, 16))
|
||||
return
|
||||
}
|
||||
|
||||
try {
|
||||
console.log('[Debit] Decrypting event content...')
|
||||
const decrypted = decryptContent(identity, CONFIG.lightningPubPubkey, event.content)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue