Inbound Nostr events are dispatched without signature verification #9
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
NostrEvent.check_signature()(nostr/event.py:31) is never called.process_nostr_message(services.py:515-528) parses the relay payload into aNostrEvent, runs the in-memory dedup on the self-declaredevent.id, and dispatches onevent.kind. Kind 30017/30018 handlers (services.py:905-957) resolve the merchant viaget_merchant_by_pubkey(event.pubkey)and insert pending stalls/products with name/price/quantity taken from the event; kind 0 callsupdate_customer_profile(crud.py:924-938), which updates bypublic_keyalone with no merchant scoping. The NIP-59 path (nostr/nip59.py:174-195unseal) checksrumor.pubkey == seal.pubkeybut never verifies the seal's Schnorr signature, so sender authenticity there rests solely on the NIP-44 MAC.Impact: the subscription filter only constrains what we ask the relay for; a malicious or compromised relay (nostrclient fans out to whatever relays are configured) can inject stalls/products into any merchant's catalog, overwrite any customer profile, and pre-seed the dedup cache with chosen ids to shadow legitimate events.
Fix direction: call
event.check_signature()at the top ofprocess_nostr_messagebefore the dedup check and drop failures with a warning; addseal.check_signature()inunseal. The sandbox fix (sandbox-team/nostrmarket PR #14) is exactly this plus tests and applies to the fork as-is.Found during reforge run #1 (sandbox nostrmarket#2).