Repository navigation
Dark SDK 0.4.2: Recipient key cross-check
Security release. Upgrading is recommended for every integration that sends private transfers.
Changes
- A transfer encrypts to a recipient key only when two independent RPC sources agree on it. The recipient's registry key decides who can read a transfer's amount and note, so one RPC's answer is no longer enough:
LiveDarkClient.transfer()cross-checksregistry.keyOf(to)against a second source before it builds the ciphertext and the hint. The second source is the chain's public RPC when the client reads through anything else, or Dark's relay when anapiis configured. A disagreement throwsRPC_DISAGREEMENTwith nothing encrypted or sent; an unreachable second source fails closed (STALE_STATE). The new optionskeyCheckRpcUrlandkeyCheckClientoverride the choice;nulldisables the check for single-RPC development setups. newDisclosureId()redraws a mainnet id that would start witht_, so a mainnet link can never be routed to the testnet API.
Compatibility
New error code RPC_DISAGREEMENT. No other API changes; upgrading from 0.4.1 requires no code changes unless a client is built with an injected publicClient and no RPC URL, in which case there is no second source and the check is skipped — pass keyCheckRpcUrl to enable it.