mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Closes both findings from Wren's cross-review at 4434d3976:
1. parse_canonical_pubkey now requires PublicKey::xonly() to succeed —
nostr 0.44's from_hex only decodes 32 bytes and defers lift-x
validation, so a non-point like "f"*64 previously passed structural
transit/save validation and failed only at unlock. Non-points are
now rejected structurally, per the agreed wire contract; the
malformed-pubkeys vector asserts structural rejection instead of
pinning the deferred-failure behavior. mint_agent_card uses the same
canonical check on record.pubkey so a non-point fails BEFORE the
API spend.
2. Added the plain-byte compatibility vector that the review claim
referenced: plain_encoder_bytes_identical_to_pre_envelope_encoder
reimplements the pre-refactor encode_snapshot_png body verbatim and
asserts byte-identical output across all three composition paths —
placeholder, PNG-avatar (chunk injection ordering), and JPEG
transcode.
Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>