IntersectMBO / IntersectMBO/evolution-sdk

COSE HeaderMap: header() and equality use Map reference equality; build() creates duplicate label entries

Aperta
#482 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement external-review
Lingua principale
TypeScript
Stelle
22
Fork
30
Merge medio
5h 29m
PR unite (30g)
12

Descrizione

## Summary
HeaderMap stores headers in a JS `Map` keyed by `Label` objects, but `Label` uses structural equality while `Map.get`/`Map.set` use reference equality. As a result:
- (a) the public `header()` accessor calls `this.headers.get(label)` with a freshly built `Label`, so it always returns `undefined`;
- (b) `HeaderMap` `[Equal.symbol]` looks up keys from `this` in `that`'s map by reference, so two structurally-equal HeaderMaps never compare equal;
- (c) `setAlgorithmId` followed by `setHeader(labelFromInt(1n), ...)` inserts two distinct `Label` objects for logical key 1, leaving two entries in the map.

No functional or security impact today: the security paths (`verifyData`, `algorithmId`, `keyId`) iterate the map manually with `Equal.equals` and are unaffected, `header()` is unused, and the duplicate label-1 entries collapse to a single correct entry on CBOR encode (encode re-keys by primitive value). Latent correctness / cleanup.

## Affected
packages/evolution/src/cose/Header.ts
- header() (L260-262): `this.headers.get(label)` uses reference equality -> always undefined
- [Equal.symbol] (L43-51): `that.headers.get(key)` uses reference equality -> HeaderMaps never equal

packages/evolution/src/cose/Key.ts
- EdDSA25519Key.build() (L248-252): `setAlgorithmId(1n)` then `setHeader(labelFromInt(1n), ...)` create two entries at logical key 1

## Fix
Stop keying a JS `Map` by objects with custom equality. Either intern `Label` instances so structurally-equal labels share a reference, or replace the map lookups (`header()`, equality, `setHeader` overwrite) with `Equal.equals`-based iteration (as the working accessors already do). Making `setHeader` overwrite an existing logical key also removes the duplicate label-1 entries in `build()`.

## Regression test
- given: a HeaderMap built with `setHeader(labelFromText("address"), bytes)`
- before fix: `hm.header(labelFromText("address"))` returns undefined
- after fix: returns the bytes
Must FAIL on main today and PASS after the fix.

## Reference
Reported informally (HeaderMap reference-equality). No live security impact; cleanup for a broken public accessor and a fragile build path.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with packages/evolution/src/cose/Header.ts, especially header() and [Equal.symbol], then inspect packages/evolution/src/cose/Key.ts around EdDSA25519Key.build(). Add the described regression test for a text label, and verify that header() returns the bytes, structurally equal HeaderMaps compare correctly, and setHeader does not leave duplicate logical labels.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
typescript
Ambito
security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
70/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.