Skip to content

Dark SDK 0.4.2: Recipient key cross-check

Choose a tag to compare

@DarkWalletRH DarkWalletRH released this 07 Oct 07:03
· 3 commits to main since this release

Security release. Upgrading is recommended for every integration that sends private transfers.

Changes

  • A transfer encrypts to a recipient key only when two independent RPC sources agree on it. The recipient's registry key decides who can read a transfer's amount and note, so one RPC's answer is no longer enough: LiveDarkClient.transfer() cross-checks registry.keyOf(to) against a second source before it builds the ciphertext and the hint. The second source is the chain's public RPC when the client reads through anything else, or Dark's relay when an api is configured. A disagreement throws RPC_DISAGREEMENT with nothing encrypted or sent; an unreachable second source fails closed (STALE_STATE). The new options keyCheckRpcUrl and keyCheckClient override the choice; null disables the check for single-RPC development setups.
  • newDisclosureId() redraws a mainnet id that would start with t_, so a mainnet link can never be routed to the testnet API.

Compatibility

New error code RPC_DISAGREEMENT. No other API changes; upgrading from 0.4.1 requires no code changes unless a client is built with an injected publicClient and no RPC URL, in which case there is no second source and the check is skipped — pass keyCheckRpcUrl to enable it.