security(M1): verify Nostr event signatures on kind 21000

Add verifyEvent() check before processing kind 21000 events from
Lightning.Pub. While NIP-44v1 encryption provides implicit
authentication (relay can't forge encrypted content without the
shared secret), verifying signatures adds defense-in-depth against
any future changes that might weaken the encryption assumption.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-07 09:56:25 -05:00
commit adbfffa0c3

View file

@ -22,6 +22,7 @@ import {
type MachineIdentity, type MachineIdentity,
type Event as NostrEvent, type Event as NostrEvent,
} from '@lamassu/nostr-client' } from '@lamassu/nostr-client'
import { verifyEvent } from 'nostr-tools'
import { LightningPubClient } from '@lamassu/lightning' import { LightningPubClient } from '@lamassu/lightning'
import { import {
CLINKClient, CLINKClient,
@ -533,6 +534,12 @@ function startDebitApprovalService(
return return
} }
// Verify event signature (defense-in-depth: relay can't forge, but verify anyway)
if (!verifyEvent(event as any)) {
console.warn('[Debit] SECURITY: Event failed signature verification:', event.id.slice(0, 16))
return
}
try { try {
console.log('[Debit] Decrypting event content...') console.log('[Debit] Decrypting event content...')
const decrypted = decryptContent(identity, CONFIG.lightningPubPubkey, event.content) const decrypted = decryptContent(identity, CONFIG.lightningPubPubkey, event.content)