Implement NIP-98 HTTP auth for GET/PUT/DELETE /subscription/email #9
Loading…
Reference in a new issue
No description provided.
Delete branch "mailship-uxf-implement-nip-98-auth-for-get-put-delete-9b9"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
mailship-uxf
Three browser-facing subscription endpoints now require a NIP-98 kind-27235 HTTP auth event proving the caller controls the pubkey. The server-side verification decodes the
Authorization: Nostr <base64>header, parses the event, checks kind, verifies the signature viaverifyEvent(nostr-tools/pure), then validatesu/method/payloadtags against the request URL/method/body.Changes:
pubkeyfrom query param. The authenticated pubkey is extracted from the NIP-98 auth header and used to look up the subscription.pubkeyin the body. The pubkey comes from the auth header; body only carriesemailandfrequency.Nostr <base64>header usingmakeHttpAuth+Nip01Signer.sign+makeHttpAuthHeaderfrom @welshman/util.The existing server-to-server routes (
/notify/:id,/confirm,/unsubscribe) remain secret-authenticated as before.How to test:
Run
bash test/integration.sh— 15 tests exercise both success paths (authenticated PUT/GET/DELETE) and rejection paths (missing auth → 401, wrong-owner → 403). The NIP-98 auth headers are generated dynamically from a random test keypair via the script helper.Three browser-facing endpoints now require a kind-27235 HTTP auth event (NIP-98) proving the caller controls the pubkey: - GET /subscription/email — pubkey extracted from auth header instead of query param; returns subscription for the authed pubkey. - PUT /subscription/email — pubkey extracted from auth header instead of trusting a client-supplied body field. - DELETE /subscription/:key — verifies auth pubkey matches subscription owner (returns 403 if mismatch). Server-side: decode base64 'Nostr <b64>' Authorization header, JSON.parse, check kind === 27235, verifyEvent (nostr-tools/pure), then check u / method / payload tags against the request URL / method / body. README updated to reflect 'implemented' auth (not 'planned'). Integration test updated to generate NIP-98 auth headers via a new helper script (script/nip98-auth-header.mjs).