Files
mantra-kmp/composeApp
Kgothatso Ngako 12189dcd75 Address high-severity MLS/nostr review findings
Verify inbound nostr signatures (C1): NostrEvent.fromEvent now calls
quartz Event.verify() (id-hash integrity + Schnorr) and drops the event
on failure. fromEvent is the single inbound parse choke point, so forged
events from a malicious/compromised relay can no longer reach the DB
(profile overwrites, fake notes/reactions, etc.).

Persist + retain PrivateMessage commits (H2): applyCommit's
PRIVATE_MESSAGE branch captured no epoch secrets and never persisted the
advance, so decrypt()'s inline commit was lost on reload and prior-epoch
messages became undecryptable. Capture retainedSecrets before decrypt and
pushRetainedEpoch + persistGroup on a successful advance, matching
decryptMessageBytes/processCommit.

Fix membership/admin reconciliation inversions (H3/M1/M2) in
processGroupMembershipChanges: new-member filter now negates correctly so
new joiners are persisted; the new-member admin flag uses == true instead
of == null (previously marked everyone admin when adminPubkeys was absent,
nobody when present); removedAdmins uses != true so admins actually
dropped from the list are demoted instead of stripping current admins.

Document retained-epoch impersonation (C2) and plaintext-at-rest (H1):
these can't be fixed in-app (RetainedEpochSecrets carries no tree/leaf sig
keys/groupContext to verify a past-epoch signature; encryption-at-rest
needs a platform keystore). Add prominent SECURITY warnings/TODOs at
tryDecryptWithRetainedEpoch, the ncryptsec* key-package fields, and the
mlsGroupState persistence, with the required fix in each case.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-26 00:29:29 +02:00
..
2026-07-15 01:14:46 +02:00