Files
buzz/desktop/src-tauri
npub1qyvc0c5kl4gqv2fd97fsk46tu378sqgy35vc83rvgfwne90sel7s0ed67dandTyler Longwell 64f819dc86 fix(desktop): enforce curve validation on locked-card pubkeys + plain-byte compat vector
Closes both findings from Wren's cross-review at 4434d3976:

1. parse_canonical_pubkey now requires PublicKey::xonly() to succeed —
   nostr 0.44's from_hex only decodes 32 bytes and defers lift-x
   validation, so a non-point like "f"*64 previously passed structural
   transit/save validation and failed only at unlock. Non-points are
   now rejected structurally, per the agreed wire contract; the
   malformed-pubkeys vector asserts structural rejection instead of
   pinning the deferred-failure behavior. mint_agent_card uses the same
   canonical check on record.pubkey so a non-point fails BEFORE the
   API spend.

2. Added the plain-byte compatibility vector that the review claim
   referenced: plain_encoder_bytes_identical_to_pre_envelope_encoder
   reimplements the pre-refactor encode_snapshot_png body verbatim and
   asserts byte-identical output across all three composition paths —
   placeholder, PNG-avatar (chunk injection ordering), and JPEG
   transcode.

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
2026-07-28 01:56:58 -04:00
..