Skip to content

feat(nwcp): add NIP-44 v2 encryption#51

Open
satwise wants to merge 1 commit into
lnbits:mainfrom
satwise:feat/nip44-v2
Open

feat(nwcp): add NIP-44 v2 encryption#51
satwise wants to merge 1 commit into
lnbits:mainfrom
satwise:feat/nip44-v2

Conversation

@satwise

@satwise satwise commented Jul 4, 2026

Copy link
Copy Markdown

Summary

  • advertise nip44_v2 nip04 in the NIP-47 kind-13194 info event
  • decrypt NIP-44 v2 request events when the request includes ["encryption", "nip44_v2"]
  • encrypt responses with the same scheme requested by the client while preserving NIP-04 fallback
  • add coverage for the published NIP-44 vector and NIP-44 request/response handling

Closes #41

Testing

  • uvx ruff check nwcp.py tests/unit/test_nwcp.py
  • uvx black --check nwcp.py tests/unit/test_nwcp.py
  • python -m py_compile nwcp.py tests/unit/test_nwcp.py
  • direct NIP-44 harness with real pynostr, coincurve==20.0.0, cryptography, loguru, and websockets plus lightweight LNbits stubs

Note: full uv run pytest is blocked in this Windows environment because LNbits pulls uvloop, which does not support Windows.

Copilot AI review requested due to automatic review settings July 4, 2026 15:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds NIP-44 v2 support to NWCServiceProvider so the provider can advertise, decrypt requests, and encrypt responses using nip44_v2, while preserving nip04 as a fallback for compatibility with existing clients.

Changes:

  • Add NIP-44 v2 encrypt/decrypt implementation (HKDF-SHA256 + ChaCha20 + HMAC-SHA256) and route request/response handling based on an encryption tag.
  • Advertise supported encryptions (nip44_v2 nip04) in the kind-13194 info event.
  • Add unit tests for the published NIP-44 v2 vector and for end-to-end request/response handling using nip44_v2.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
nwcp.py Implements NIP-44 v2 crypto, adds encryption negotiation via tags, and updates info event advertisement + response encryption behavior.
tests/unit/test_nwcp.py Adds vector test and async handling tests to cover NIP-44 v2 request decryption and response encryption/tagging.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread nwcp.py
Comment on lines +314 to +318
def _encrypt_nip44_v2_message(
self, message: str, public_key_hex: str, nonce: bytes | None = None
) -> str:
nonce = nonce or secrets.token_bytes(32)
conversation_key = self._get_conversation_key(public_key_hex)
Comment thread nwcp.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add NIP-44 v2 encryption

2 participants