IntersectMBO / IntersectMBO/evolution-sdk

COSE HeaderMap: header() and equality use Map reference equality; build() creates duplicate label entries

Abierto
#482 0 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement external-review
Lenguaje dominante
TypeScript
Estrellas
22
Forks
30
Merge medio
5 h 29 min
PR fusionados (30 d)
12

Descripción

## Summary
HeaderMap stores headers in a JS `Map` keyed by `Label` objects, but `Label` uses structural equality while `Map.get`/`Map.set` use reference equality. As a result:
- (a) the public `header()` accessor calls `this.headers.get(label)` with a freshly built `Label`, so it always returns `undefined`;
- (b) `HeaderMap` `[Equal.symbol]` looks up keys from `this` in `that`'s map by reference, so two structurally-equal HeaderMaps never compare equal;
- (c) `setAlgorithmId` followed by `setHeader(labelFromInt(1n), ...)` inserts two distinct `Label` objects for logical key 1, leaving two entries in the map.

No functional or security impact today: the security paths (`verifyData`, `algorithmId`, `keyId`) iterate the map manually with `Equal.equals` and are unaffected, `header()` is unused, and the duplicate label-1 entries collapse to a single correct entry on CBOR encode (encode re-keys by primitive value). Latent correctness / cleanup.

## Affected
packages/evolution/src/cose/Header.ts
- header() (L260-262): `this.headers.get(label)` uses reference equality -> always undefined
- [Equal.symbol] (L43-51): `that.headers.get(key)` uses reference equality -> HeaderMaps never equal

packages/evolution/src/cose/Key.ts
- EdDSA25519Key.build() (L248-252): `setAlgorithmId(1n)` then `setHeader(labelFromInt(1n), ...)` create two entries at logical key 1

## Fix
Stop keying a JS `Map` by objects with custom equality. Either intern `Label` instances so structurally-equal labels share a reference, or replace the map lookups (`header()`, equality, `setHeader` overwrite) with `Equal.equals`-based iteration (as the working accessors already do). Making `setHeader` overwrite an existing logical key also removes the duplicate label-1 entries in `build()`.

## Regression test
- given: a HeaderMap built with `setHeader(labelFromText("address"), bytes)`
- before fix: `hm.header(labelFromText("address"))` returns undefined
- after fix: returns the bytes
Must FAIL on main today and PASS after the fix.

## Reference
Reported informally (HeaderMap reference-equality). No live security impact; cleanup for a broken public accessor and a fragile build path.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start with packages/evolution/src/cose/Header.ts, especially header() and [Equal.symbol], then inspect packages/evolution/src/cose/Key.ts around EdDSA25519Key.build(). Add the described regression test for a text label, and verify that header() returns the bytes, structurally equal HeaderMaps compare correctly, and setHeader does not leave duplicate logical labels.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
typescript
Área
security
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Tranquilo
Claridad
Bien especificado
Aptitud para principiantes
70/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.