commit ab2bda16beed08db8819299d4cda167d89428da2
parent 59b737cea14c03552f20a3cd49873906249f5c5d
Author: triesap <tyson@radroots.org>
Date: Sun, 19 Jul 2026 20:34:23 +0000
signing: remove generic wire-part authoring bypass
- retire the public arbitrary wire-parts builder and signing adapter
- keep relay tests at an explicit already-signed transport boundary
- qualify the standalone signing feature with radroots_nostr std support
- guard the SDK surface against reintroducing generic signing APIs
Diffstat:
8 files changed, 25 insertions(+), 82 deletions(-)
diff --git a/crates/sdk/Cargo.toml b/crates/sdk/Cargo.toml
@@ -45,7 +45,7 @@ identity-models = [
"radroots_identity/std",
]
identity-storage = ["identity-models", "std", "radroots_identity/std"]
-signing = ["dep:nostr", "dep:radroots_nostr", "nostr"]
+signing = ["dep:nostr", "dep:radroots_nostr", "nostr", "radroots_nostr/std"]
transport-nostr-client = ["signing", "std", "serde_json", "radroots_nostr/client"]
radrootsd-execution = [
"std",
diff --git a/crates/sdk/README b/crates/sdk/README
@@ -102,7 +102,8 @@ Optional advanced substrate is explicitly feature-scoped:
- `identity-models`: identity data types without local storage coupling
- `identity-storage`: encrypted identity-file helpers
-- `signing`: Nostr builder and local signing adapters
+- `signing`: dependency substrate for curated Nostr adapters; it exposes no
+ generic builder or caller-constructed wire-part signing module
- `transport-nostr-client`: Nostr relay WebSocket client and publish adapters
- `signer-adapters`: SDK local-key and Myc NIP-46 signer providers plus configured-signer product
write APIs
diff --git a/crates/sdk/src/adapters/mod.rs b/crates/sdk/src/adapters/mod.rs
@@ -4,5 +4,3 @@ pub mod nostr;
pub mod radrootsd;
#[cfg(feature = "signer-adapters")]
pub mod signer;
-#[cfg(feature = "signing")]
-pub mod signing;
diff --git a/crates/sdk/src/adapters/signing.rs b/crates/sdk/src/adapters/signing.rs
@@ -1,32 +0,0 @@
-use crate::identity::RadrootsIdentity;
-use radroots_event::wire::RadrootsNip01EventWireParts;
-use radroots_nostr::prelude::{
- RadrootsNostrError, RadrootsNostrEvent, RadrootsNostrEventBuilder, radroots_nostr_build_event,
-};
-
-pub type SigningError = RadrootsNostrError;
-
-pub fn event_builder_from_parts(
- parts: RadrootsNip01EventWireParts,
-) -> Result<RadrootsNostrEventBuilder, SigningError> {
- radroots_nostr_build_event(parts.kind, parts.content, parts.tags)
-}
-
-pub fn sign_parts_with_identity(
- identity: &RadrootsIdentity,
- parts: RadrootsNip01EventWireParts,
-) -> Result<RadrootsNostrEvent, SigningError> {
- let builder = event_builder_from_parts(parts)?;
- sign_builder_with_identity(identity, builder)
-}
-
-pub fn sign_builder_with_identity(
- identity: &RadrootsIdentity,
- builder: RadrootsNostrEventBuilder,
-) -> Result<RadrootsNostrEvent, SigningError> {
- builder.sign_with_keys(identity.keys()).map_err(Into::into)
-}
-
-#[cfg(test)]
-#[path = "../../tests/unit/adapters_signing_tests.rs"]
-mod tests;
diff --git a/crates/sdk/src/lib.rs b/crates/sdk/src/lib.rs
@@ -8,7 +8,6 @@ extern crate alloc;
mod actor_json;
#[cfg(any(
feature = "radrootsd-execution",
- feature = "signing",
feature = "transport-nostr-client",
feature = "signer-adapters"
))]
diff --git a/crates/sdk/tests/source_boundary.rs b/crates/sdk/tests/source_boundary.rs
@@ -91,3 +91,19 @@ fn active_sources_do_not_describe_compatibility_paths() {
}
}
}
+
+#[test]
+fn sdk_does_not_expose_generic_wire_part_signing() {
+ let manifest = manifest_dir();
+ let lib = read_source(&manifest.join("src/lib.rs"));
+ let adapters = read_source(&manifest.join("src/adapters/mod.rs"));
+
+ assert!(!manifest.join("src/adapters/signing.rs").exists());
+ assert!(
+ !manifest
+ .join("tests/unit/adapters_signing_tests.rs")
+ .exists()
+ );
+ assert!(!lib.contains("feature = \"signing\",\n"));
+ assert!(!adapters.contains("pub mod signing"));
+}
diff --git a/crates/sdk/tests/unit/adapters_nostr_tests.rs b/crates/sdk/tests/unit/adapters_nostr_tests.rs
@@ -2,10 +2,9 @@ use super::{
client_from_identity, configure_write_relays, connected_client_from_identity,
connected_relay_urls, publish_signed_event, signerless_client, signerless_client_with_options,
};
-use crate::adapters::signing::sign_parts_with_identity;
use crate::identity::RadrootsIdentity;
use core::time::Duration;
-use radroots_event::wire::RadrootsNip01EventWireParts;
+use nostr::{EventBuilder, Kind};
use radroots_nostr::prelude::RadrootsNostrClientOptions;
use tokio::runtime::Runtime;
@@ -72,15 +71,11 @@ fn relay_helpers_accept_empty_relay_sets_without_network_endpoints() {
.expect("connected client");
assert_eq!(connected_relay_urls(&connected).await, Vec::<String>::new());
- let signed = sign_parts_with_identity(
- &identity,
- RadrootsNip01EventWireParts {
- kind: 1,
- content: "hello".to_owned(),
- tags: Vec::new(),
- },
- )
- .expect("signed event");
+ // Relay publication consumes an already-signed transport fixture; it
+ // does not expose an SDK event-authoring path.
+ let signed = EventBuilder::new(Kind::Custom(30_001), "hello")
+ .sign_with_keys(identity.keys())
+ .expect("signed event");
let error = publish_signed_event(&connected, &signed)
.await
.expect_err("publish without relays");
diff --git a/crates/sdk/tests/unit/adapters_signing_tests.rs b/crates/sdk/tests/unit/adapters_signing_tests.rs
@@ -1,34 +0,0 @@
-use super::{event_builder_from_parts, sign_parts_with_identity};
-use crate::identity::RadrootsIdentity;
-use radroots_event::wire::RadrootsNip01EventWireParts;
-
-#[test]
-fn event_builder_from_parts_preserves_kind_and_content() {
- let builder = event_builder_from_parts(RadrootsNip01EventWireParts {
- kind: 30402,
- content: "hello".into(),
- tags: vec![vec!["x".into(), "y".into()]],
- })
- .expect("builder");
- let identity = RadrootsIdentity::generate();
- let event = builder.build(identity.keys().public_key());
-
- assert_eq!(u16::from(event.kind), 30402);
- assert_eq!(event.content, "hello");
-}
-
-#[test]
-fn sign_parts_with_identity_signs_event() {
- let identity = RadrootsIdentity::generate();
- let event = sign_parts_with_identity(
- &identity,
- RadrootsNip01EventWireParts {
- kind: 30402,
- content: "hello".into(),
- tags: vec![],
- },
- )
- .expect("signed event");
-
- assert_eq!(event.pubkey.to_hex(), identity.public_key_hex());
-}