From e62bf97accf0d7987a6a52639e3e90ec808af436 Mon Sep 17 00:00:00 2001 From: Yasuhiro Matsumoto Date: Wed, 15 Jul 2026 09:42:31 +0900 Subject: [PATCH] dekey: don't keep a decrypted key that doesn't match the announced pubkey, it could end up being redistributed to other devices. --- dekey.go | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/dekey.go b/dekey.go index e14a7a5..65bf6de 100644 --- a/dekey.go +++ b/dekey.go @@ -236,12 +236,14 @@ var dekey = &cli.Command{ if err != nil { continue } - eSec, err = nostr.SecretKeyFromHex(eSecHex) + candidate, err := nostr.SecretKeyFromHex(eSecHex) if err != nil { continue } - // check if it matches mainPub - if eSec.Public() == ePub { + // check if it matches mainPub -- only keep it if it does, otherwise a + // stale key received from another device would end up being redistributed + if candidate.Public() == ePub { + eSec = candidate log(color.GreenString("successfully received decoupled encryption key from another device\n")) // store it os.MkdirAll(filepath.Dir(eKeyPath), 0700)