bitcoinjs-lib/src/message.js

64 lines
1.6 KiB
JavaScript
Raw Normal View History

/// Implements Bitcoin's feature for signing arbitrary messages.
var Address = require('./address')
2014-03-27 02:00:08 +01:00
var convert = require('./convert')
var crypto = require('./crypto')
var ecdsa = require('./ecdsa')
2014-03-29 07:44:03 +01:00
var ECPubKey = require('./eckey').ECPubKey
// FIXME: magicHash is incompatible with other magic messages
var magicBytes = convert.stringToBytes('Bitcoin Signed Message:\n')
function magicHash(message) {
2014-03-27 02:00:08 +01:00
var messageBytes = convert.stringToBytes(message)
var buffer = [].concat(
2014-03-27 02:00:08 +01:00
convert.numToVarInt(magicBytes.length),
magicBytes,
convert.numToVarInt(messageBytes.length),
messageBytes
)
return crypto.hash256(buffer)
2014-03-27 02:00:08 +01:00
}
// TODO: parameterize compression instead of using ECKey.compressed
function sign(key, message) {
var hash = magicHash(message)
2014-03-27 02:00:08 +01:00
var sig = key.sign(hash)
var obj = ecdsa.parseSig(sig)
2014-04-17 11:08:16 +02:00
var i = ecdsa.calcPubKeyRecoveryParam(key.pub.Q, obj.r, obj.s, hash)
2014-03-27 02:00:08 +01:00
i += 27
2014-04-17 11:08:16 +02:00
if (key.pub.compressed) {
2014-03-27 02:00:08 +01:00
i += 4
}
2014-03-27 02:00:08 +01:00
var rBa = obj.r.toByteArrayUnsigned()
var sBa = obj.s.toByteArrayUnsigned()
// Pad to 32 bytes per value
2014-03-31 05:47:47 +02:00
while (rBa.length < 32) rBa.unshift(0);
while (sBa.length < 32) sBa.unshift(0);
2014-03-27 02:00:08 +01:00
sig = [i].concat(rBa, sBa)
return sig
2014-03-27 02:00:08 +01:00
}
function verify(address, sig, message) {
sig = ecdsa.parseSigCompact(sig)
var pubKey = new ECPubKey(ecdsa.recoverPubKey(sig.r, sig.s, magicHash(message), sig.i))
2014-04-17 11:08:16 +02:00
pubKey.compressed = !!(sig.i & 4)
address = new Address(address)
return pubKey.getAddress(address.version).toString() === address.toString()
2014-03-27 02:00:08 +01:00
}
module.exports = {
magicHash: magicHash,
sign: sign,
verify: verify
}