9dfa06ffee
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Signed-off-by: cls_宁波本机 <908705107@qq.com>
80 lines
2.3 KiB
Dart
80 lines
2.3 KiB
Dart
import 'dart:convert';
|
|
import 'dart:typed_data';
|
|
|
|
import 'package:flutter_test/flutter_test.dart';
|
|
import 'package:nostr/nostr.dart' as nostr;
|
|
import 'package:pointycastle/digests/sha256.dart';
|
|
import 'package:buzz/shared/crypto/nip_oa.dart';
|
|
|
|
String _sha256Hex(String input) {
|
|
final digest = SHA256Digest().process(Uint8List.fromList(utf8.encode(input)));
|
|
return digest.map((b) => b.toRadixString(16).padLeft(2, '0')).join();
|
|
}
|
|
|
|
List<String> authTag(
|
|
nostr.Keys owner,
|
|
String agentPubkey, {
|
|
String conditions = '',
|
|
}) {
|
|
final message = _sha256Hex('nostr:agent-auth:$agentPubkey:$conditions');
|
|
final sig = nostr.Schnorr.sign(secretKey: owner.secret, message: message);
|
|
return ['auth', owner.public, conditions, sig];
|
|
}
|
|
|
|
void main() {
|
|
final owner = nostr.Keys.generate();
|
|
final agent = nostr.Keys.generate();
|
|
|
|
test('returns the owner pubkey for a valid auth tag', () {
|
|
final tag = authTag(owner, agent.public);
|
|
expect(
|
|
verifiedOaOwnerPubkey([tag], agent.public),
|
|
owner.public.toLowerCase(),
|
|
);
|
|
});
|
|
|
|
test('accepts valid conditions strings', () {
|
|
final tag = authTag(owner, agent.public, conditions: 'kind=0');
|
|
expect(
|
|
verifiedOaOwnerPubkey([tag], agent.public),
|
|
owner.public.toLowerCase(),
|
|
);
|
|
});
|
|
|
|
test('rejects a signature over a different agent pubkey', () {
|
|
final otherAgent = nostr.Keys.generate();
|
|
final tag = authTag(owner, otherAgent.public);
|
|
expect(verifiedOaOwnerPubkey([tag], agent.public), isNull);
|
|
});
|
|
|
|
test('rejects a tampered signature', () {
|
|
final tag = authTag(owner, agent.public);
|
|
final tampered = [...tag];
|
|
tampered[3] = tampered[3].replaceRange(
|
|
0,
|
|
1,
|
|
tampered[3][0] == '0' ? '1' : '0',
|
|
);
|
|
expect(verifiedOaOwnerPubkey([tampered], agent.public), isNull);
|
|
});
|
|
|
|
test('rejects self-attestation', () {
|
|
final tag = authTag(agent, agent.public);
|
|
expect(verifiedOaOwnerPubkey([tag], agent.public), isNull);
|
|
});
|
|
|
|
test('rejects malformed conditions', () {
|
|
final tag = authTag(owner, agent.public, conditions: 'kind=abc');
|
|
expect(verifiedOaOwnerPubkey([tag], agent.public), isNull);
|
|
});
|
|
|
|
test('ignores unrelated tags', () {
|
|
expect(
|
|
verifiedOaOwnerPubkey([
|
|
['p', owner.public],
|
|
], agent.public),
|
|
isNull,
|
|
);
|
|
});
|
|
}
|