IntersectMBO / IntersectMBO/evolution-sdk
COSE HeaderMap: header() and equality use Map reference equality; build() creates duplicate label entries
- Lenguaje dominante
- TypeScript
- Estrellas
- 22
- Forks
- 30
- Merge medio
- 5 h 29 min
- PR fusionados (30 d)
- 12
Descripción
## Summary
HeaderMap stores headers in a JS `Map` keyed by `Label` objects, but `Label` uses structural equality while `Map.get`/`Map.set` use reference equality. As a result:
- (a) the public `header()` accessor calls `this.headers.get(label)` with a freshly built `Label`, so it always returns `undefined`;
- (b) `HeaderMap` `[Equal.symbol]` looks up keys from `this` in `that`'s map by reference, so two structurally-equal HeaderMaps never compare equal;
- (c) `setAlgorithmId` followed by `setHeader(labelFromInt(1n), ...)` inserts two distinct `Label` objects for logical key 1, leaving two entries in the map.
No functional or security impact today: the security paths (`verifyData`, `algorithmId`, `keyId`) iterate the map manually with `Equal.equals` and are unaffected, `header()` is unused, and the duplicate label-1 entries collapse to a single correct entry on CBOR encode (encode re-keys by primitive value). Latent correctness / cleanup.
## Affected
packages/evolution/src/cose/Header.ts
- header() (L260-262): `this.headers.get(label)` uses reference equality -> always undefined
- [Equal.symbol] (L43-51): `that.headers.get(key)` uses reference equality -> HeaderMaps never equal
packages/evolution/src/cose/Key.ts
- EdDSA25519Key.build() (L248-252): `setAlgorithmId(1n)` then `setHeader(labelFromInt(1n), ...)` create two entries at logical key 1
## Fix
Stop keying a JS `Map` by objects with custom equality. Either intern `Label` instances so structurally-equal labels share a reference, or replace the map lookups (`header()`, equality, `setHeader` overwrite) with `Equal.equals`-based iteration (as the working accessors already do). Making `setHeader` overwrite an existing logical key also removes the duplicate label-1 entries in `build()`.
## Regression test
- given: a HeaderMap built with `setHeader(labelFromText("address"), bytes)`
- before fix: `hm.header(labelFromText("address"))` returns undefined
- after fix: returns the bytes
Must FAIL on main today and PASS after the fix.
## Reference
Reported informally (HeaderMap reference-equality). No live security impact; cleanup for a broken public accessor and a fragile build path.
Guía de contribución
Línea de trabajo
Start with packages/evolution/src/cose/Header.ts, especially header() and [Equal.symbol], then inspect packages/evolution/src/cose/Key.ts around EdDSA25519Key.build(). Add the described regression test for a text label, and verify that header() returns the bytes, structurally equal HeaderMaps compare correctly, and setHeader does not leave duplicate logical labels.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- typescript
- Área
- security
- Tipo de issue
- Error
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Estado de actividad
- Tranquilo
- Claridad
- Bien especificado
- Aptitud para principiantes
- 70/100