feat(nwcp): add NIP-44 v2 encryption - #51
Conversation
There was a problem hiding this comment.
Pull request overview
This PR adds NIP-44 v2 support to NWCServiceProvider so the provider can advertise, decrypt requests, and encrypt responses using nip44_v2, while preserving nip04 as a fallback for compatibility with existing clients.
Changes:
- Add NIP-44 v2 encrypt/decrypt implementation (HKDF-SHA256 + ChaCha20 + HMAC-SHA256) and route request/response handling based on an
encryptiontag. - Advertise supported encryptions (
nip44_v2 nip04) in the kind-13194 info event. - Add unit tests for the published NIP-44 v2 vector and for end-to-end request/response handling using
nip44_v2.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
nwcp.py |
Implements NIP-44 v2 crypto, adds encryption negotiation via tags, and updates info event advertisement + response encryption behavior. |
tests/unit/test_nwcp.py |
Adds vector test and async handling tests to cover NIP-44 v2 request decryption and response encryption/tagging. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
I maintain Padding. I transcribed Constants. One suggestion. NIP-44 publishes extended length prefix test vectors covering exactly the 65535 to 65536 boundary, given as SHA-256 checksums of the plaintext and payload since the payloads are too large to inline. Since this PR implements the 6-byte prefix path, those vectors would exercise it directly. Offer. If it would help, I am happy to build this branch, point a NIP-44-only client at it and report back on the thread. That is worth slightly more than the usual smoke test here: most NWC clients negotiate down to NIP-04, so they pass whether or not the NIP-44 path is correct. One that cannot fall back exercises it or fails. Thanks for writing this. Advertising |
Summary
nip44_v2 nip04in the NIP-47 kind-13194 info event["encryption", "nip44_v2"]Closes #41
Testing
uvx ruff check nwcp.py tests/unit/test_nwcp.pyuvx black --check nwcp.py tests/unit/test_nwcp.pypython -m py_compile nwcp.py tests/unit/test_nwcp.pypynostr,coincurve==20.0.0,cryptography,loguru, andwebsocketsplus lightweight LNbits stubsNote: full
uv run pytestis blocked in this Windows environment because LNbits pullsuvloop, which does not support Windows.