Skip to content

Parse an event that carries a key NIP-01 does not name - #107

Merged
sepehr-safari merged 1 commit into
mainfrom
extra-event-fields-are-ignored
Sep 23, 2026
Merged

sepehr-safari merged 1 commit into
mainfrom
extra-event-fields-are-ignored

Conversation

@sepehr-safari

Copy link
Copy Markdown
Contributor

Closes #106.

fromJson and the relay message parser read the event object with default std.json options, so a key beyond the seven NIP-01 names failed the parse with UnknownField. A valid event carrying one was dropped, and on a relay connection it failed the whole EVENT message.

The id is the hash of the seven named fields and the signature is over the id, so an extra key cannot change what was signed. Both parse paths now share one set of options that skips unknown keys. Duplicate keys are still refused: with two content keys it would be ambiguous which one the signature covers.

Tests

an event carrying a field NIP-01 does not name still parses and verifies signs an event, adds an array-valued and a nested object-valued key, and checks that it parses, keeps its id, verifies, and writes back out byte-identical to what was signed. It failed with UnknownField before the change.

parse EVENT message whose event carries a field NIP-01 does not name covers the relay message path, which goes through fromValueLeaky rather than fromJson. It also failed before the change.

an event naming the same field twice is still refused pins the duplicate-key refusal so a later loosening of the options cannot drop it quietly.

All 206 tests pass.

fromJson and the relay message parser refused any key beyond the seven named fields with UnknownField, so a valid event carrying one was dropped, and on a relay connection it failed the whole EVENT message. The id and the signature cover the seven fields and nothing else, so the extra key is now skipped. A key named twice is still refused.

Closes #106.
@sepehr-safari
sepehr-safari merged commit 97dda9d into main Sep 23, 2026
2 checks passed
@sepehr-safari
sepehr-safari deleted the extra-event-fields-are-ignored branch September 23, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

An event that carries a key NIP-01 does not name fails to parse

1 participant