Files
Amber/app
Claude 62e10cbf70 nip44 v3: accept non-standard padding lengths on decrypt
The nip44v3 spec was updated (nostr-land/nip44v3) to clarify that the
padding length is not constrained: "The padding should be checked to be
all-zeroes. Implementations must not do any other checks on the padding
length." The standard padding algorithm is only a SHOULD (anti-
fingerprinting), so a conforming peer may send more or fewer padding
bytes than we produce.

Our unpad() previously rejected any ciphertext whose buffer length did
not match our own canonical target size, which would wrongly reject
valid messages. Remove that check and keep only the all-zeroes
validation (and the declared-length bounds check).

Also sync the test vectors with upstream, adding the new decrypt_only
section (5 vectors with non-standard padding sizes) and a test that
exercises them.
2026-06-03 10:20:28 +00:00
..
2024-03-01 06:56:32 -03:00
2023-07-26 16:44:33 -03:00
2026-06-01 11:05:58 -03:00