add some comments explaining the weird signature verification thing
This commit is contained in:
@@ -1409,6 +1409,15 @@ verify_signature(Sig, Message, PubKey) ->
|
|||||||
end.
|
end.
|
||||||
|
|
||||||
verify_signature2(Sig, Message, PK) ->
|
verify_signature2(Sig, Message, PK) ->
|
||||||
|
% Superhero salts/hashes the message before signing it, in order to protect
|
||||||
|
% the user from accidentally signing a transaction disguised as a message.
|
||||||
|
% In order to verify the signature, we have to duplicate superhero's
|
||||||
|
% salt/hash procedure here.
|
||||||
|
%
|
||||||
|
% Salt the message then hash with blake2b. See:
|
||||||
|
% 1. Erlang Blake2 blake2b/2 function: https://github.com/aeternity/eblake2/blob/60a079f00d72d1bfcc25de8e6996d28f912db3fd/src/eblake2.erl#L23-L25
|
||||||
|
% 2. SDK salting step: https://github.com/aeternity/aepp-sdk-js/blob/370f1e30064ad0239ba59931908d9aba0a2e86b6/src/utils/crypto.ts#L171-L175
|
||||||
|
% 3. SDK hashing: https://github.com/aeternity/aepp-sdk-js/blob/370f1e30064ad0239ba59931908d9aba0a2e86b6/src/utils/crypto.ts#L83-L85
|
||||||
Prefix = <<"aeternity Signed Message:\n">>,
|
Prefix = <<"aeternity Signed Message:\n">>,
|
||||||
{ok, PSize} = vencode(byte_size(Prefix)),
|
{ok, PSize} = vencode(byte_size(Prefix)),
|
||||||
{ok, MSize} = vencode(byte_size(Message)),
|
{ok, MSize} = vencode(byte_size(Message)),
|
||||||
@@ -1419,6 +1428,8 @@ verify_signature2(Sig, Message, PK) ->
|
|||||||
{ok, Result}.
|
{ok, Result}.
|
||||||
|
|
||||||
|
|
||||||
|
% This is Bitcoin's variable-length unsigned integer encoding
|
||||||
|
% See: https://en.bitcoin.it/wiki/Protocol_documentation#Variable_length_integer
|
||||||
vencode(N) when N < 0 ->
|
vencode(N) when N < 0 ->
|
||||||
{error, {negative_N, N}};
|
{error, {negative_N, N}};
|
||||||
vencode(N) when N < 16#FD ->
|
vencode(N) when N < 16#FD ->
|
||||||
@@ -1433,6 +1444,9 @@ vencode(N) when N < (2 bsl 64) ->
|
|||||||
NBytes = eu(N, 8),
|
NBytes = eu(N, 8),
|
||||||
{ok, <<16#FF, NBytes/binary>>}.
|
{ok, <<16#FF, NBytes/binary>>}.
|
||||||
|
|
||||||
|
|
||||||
|
% eu = encode unsigned (little endian with a given byte width)
|
||||||
|
% means add zero bytes to the end as needed
|
||||||
eu(N, Size) ->
|
eu(N, Size) ->
|
||||||
Bytes = binary:encode_unsigned(N, little),
|
Bytes = binary:encode_unsigned(N, little),
|
||||||
NExtraZeros = Size - byte_size(Bytes),
|
NExtraZeros = Size - byte_size(Bytes),
|
||||||
|
|||||||
Reference in New Issue
Block a user