verifySignature: return false if the id is invalid

This commit is contained in:
Alex Gleason
2023-09-02 17:31:39 -05:00
parent 34e0ad8c41
commit 54f3bedf38
2 changed files with 29 additions and 2 deletions

View File

@@ -115,8 +115,14 @@ export function validateEvent<T>(event: T): event is T & UnsignedEvent<number> {
/** Verify the event's signature. This function mutates the event with a `verified` symbol, making it idempotent. */
export function verifySignature<K extends number>(event: Event<K>): event is VerifiedEvent<K> {
if (typeof event[verifiedSymbol] === 'boolean') return event[verifiedSymbol]
const hash = getEventHash(event)
if (hash !== event.id) {
return false
}
try {
event[verifiedSymbol] = schnorr.verify(event.sig, getEventHash(event), event.pubkey)
event[verifiedSymbol] = schnorr.verify(event.sig, hash, event.pubkey)
return event[verifiedSymbol]
} catch (err) {
return false