Skip to content

fix(097-C1): commitment hash over ciphertext, version-gated verify#3

Merged
ValidPay-io merged 1 commit into
mainfrom
fix/commitment-hash-ciphertext
Jun 15, 2026
Merged

fix(097-C1): commitment hash over ciphertext, version-gated verify#3
ValidPay-io merged 1 commit into
mainfrom
fix/commitment-hash-ciphertext

Conversation

@ValidPay-io

Copy link
Copy Markdown
Owner

Prompt 097 — Fix 1 (C-1). React Native SDK half of the commitment-hash fix. Pairs with ValidPay-API#95.

  • computeCommitmentHash now hashes the ciphertext blob, not the plaintext.
  • create paths hash encrypted_payload after encryption.
  • checkCommitmentHash recomputes SHA-256(ciphertext) and enforces it only when commitment_version >= 2; legacy v1 intents skip and still verify.
  • Selective integrity is now role-independent. IntentApiResponse gains commitment_version.
  • All 32 client tests pass.

Publish bump happens after all 097 PRs land (combined with PR5).
🤖 Generated with Claude Code

computeCommitmentHash now hashes the ciphertext blob, not the plaintext
(C-1). create paths hash encrypted_payload after encryption.
checkCommitmentHash recomputes SHA-256(ciphertext) and enforces it ONLY
when commitment_version >= 2; legacy v1 intents skip the check and still
verify. Selective integrity is now role-independent. IntentApiResponse
gains commitment_version. Tests updated.

Co-authored-by: Mike <mtn.mh1.inv@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@ValidPay-io
ValidPay-io merged commit 6b1a93b into main Jun 15, 2026
2 checks passed
@ValidPay-io
ValidPay-io deleted the fix/commitment-hash-ciphertext branch June 15, 2026 01:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant