Fixes T4 and the rest of T5 of the review of the session of 1 and 2
October:
- note.ts: checkNote refuses a string with a lone surrogate, which UTF-8
cannot hold, after its length and with the text that extension.CheckNote
gives for invalid UTF-8. newNote wrote U+FFFD in its place, and the note
is public and permanent (spec §62.1 rules 15 and 23).
- note.ts: publicNote reads the data with decodeUtf8, which keeps a leading
U+FEFF: such a note is unusable, as in Go, where it showed without it.
- author.ts: authorCode takes the eight bytes of the code as Go's
AuthorCode takes them, a leading U+FEFF kept.
- inspector/drand.ts: an answer of a relay that starts with a BOM is
refused, as json.Unmarshal refuses it in the client of the reference.
- The texts of the head and the paths of format 3 already kept it, since
cbor.ts decodes them with decodeUtf8: head.test.ts now pins it with the
texts of Go. The other TextDecoder of src/lib, in age.ts, reads tokens of
ASCII that are checked byte by byte before.
The texts are those of extension.CheckNote, extension.Note,
capsule.DecodeHead and capsule.AuthorCode at spec-v0.11, taken with an
oracle on the same bytes; the drand client of the reference refuses the
answer with json.Unmarshal. npm run verify passes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ -15,10 +15,19 @@ import { checkAuthor } from './pathrule.ts';
exportconstNOTE_ID='datekeys.note';
exportconstMAX_NOTE_LEN=1024;
/** The text of a public note is from 1 to 1024 bytes of valid UTF-8 that meets the rules of the declared author (spec §24.1). Throws a DateKeysError when it is not. */
'Ningún relay de drand dio la firma: api.drand.sh respondió algo que no es una firma; api2.drand.sh no se pudo conectar; api3.drand.sh no se pudo conectar.',