mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-06 11:28:22 +00:00
The nip44v3 spec was updated (nostr-land/nip44v3) to clarify that the padding length is not constrained: "The padding should be checked to be all-zeroes. Implementations must not do any other checks on the padding length." The standard padding algorithm is only a SHOULD (anti- fingerprinting), so a conforming peer may send more or fewer padding bytes than we produce. Our unpad() previously rejected any ciphertext whose buffer length did not match our own canonical target size, which would wrongly reject valid messages. Remove that check and keep only the all-zeroes validation (and the declared-length bounds check). Also sync the test vectors with upstream, adding the new decrypt_only section (5 vectors with non-standard padding sizes) and a test that exercises them.