fix: verify EdDSA TSS transactions before signing - #9813
Conversation
3cdb8f0 to
3f0cd37
Compare
3f0cd37 to
c88d36d
Compare
|
|
|
@claude review |
|
Claude finished @danielpeng1's task —— View job Code Review for EdDSA TSS Verification PRTodo List:
SummaryThis PR successfully implements EdDSA MPCv1 TSS transaction verification to align with other TSS drivers. The implementation adds Key Implementation Analysis✅ Core Changesmodules/sdk-core/src/bitgo/wallet/wallet.ts (lines 2391-2426)
modules/sdk-core/src/bitgo/utils/tss/eddsa/eddsa.ts (lines 770-777)
✅ Test CoverageThe test additions are comprehensive:
Security & Design Review✅ Security Strengths
✅ Code Quality
|
898c39b to
a65ebf6
Compare
a65ebf6 to
a402a27
Compare
Align EdDSA MPCv1 TSS transaction signing with other TSS drivers by verifying transactions locally before signing.
verifyTransactionin EdDSA MPCv1signRequestBaseviaresolveEffectiveTxParamsfor tx requestssignEddsaTssUsingExternalSigner(afterdeleteSignatureShares/ tx resolve) and in ExpresscreateCommitmentShareFromTxRequest/createGShareFromTxRequestverifyTxParamsis set but prebuild lacks usable bytes; verify TSS tx requests by id and sign the same resolved request viaresolvedTxRequestForSigningverifyTxParams/buildParamsinto the external-signer path for intent-aware verificationTests:
signTxRequestguard tests (intent recipients, malicious empty intent, deactivate allowlist)signEddsaTssUsingExternalSignerguard test (rejects before external callbacks)signTransactiontest whenverifyTxParamscannot runsignTxRequestfixtures/stubs for verificationTICKET: WCN-2113