dekey: don't keep a decrypted key that doesn't match the announced pubkey, it could end up being redistributed to other devices.

This commit is contained in:
Yasuhiro Matsumoto
2026-07-15 10:07:02 +09:00
parent c709647823
commit e62bf97acc
+5 -3
View File
@@ -236,12 +236,14 @@ var dekey = &cli.Command{
if err != nil {
continue
}
eSec, err = nostr.SecretKeyFromHex(eSecHex)
candidate, err := nostr.SecretKeyFromHex(eSecHex)
if err != nil {
continue
}
// check if it matches mainPub
if eSec.Public() == ePub {
// check if it matches mainPub -- only keep it if it does, otherwise a
// stale key received from another device would end up being redistributed
if candidate.Public() == ePub {
eSec = candidate
log(color.GreenString("successfully received decoupled encryption key from another device\n"))
// store it
os.MkdirAll(filepath.Dir(eKeyPath), 0700)