Skip to content

refactor(auth): address EIP-712 follow-up feedback - #3898

Open
VAIBHAVJINDAL3012 wants to merge 19 commits into
0xMiden:nextfrom
inicio-labs:vaibhav/eip712-review-followup
Open

VAIBHAVJINDAL3012 wants to merge 19 commits into
0xMiden:nextfrom
inicio-labs:vaibhav/eip712-review-followup

Conversation

@VAIBHAVJINDAL3012

Copy link
Copy Markdown
Contributor

Summary

Follow-up to #3856 addressing review feedback:

  • groups the generic EIP-712 verifier and transaction-summary adapter under auth::eip712;
  • extracts optional EIP-712 witness verification into a focused MASM helper while preserving raw-signature-first behavior;
  • clarifies the MASM stack documentation and retains the existing approver terminology.

Tests

  • cargo +nightly fmt --all -- --check
  • cargo test -p miden-testing --test lib — 725 passed
  • forge test -vv — 1 passed

Comment thread CHANGELOG.md Outdated
Comment thread crates/miden-standards/asm/standards/auth/signature.masm
@VAIBHAVJINDAL3012

Copy link
Copy Markdown
Contributor Author

Hi @mmagician, I have the helper out of the signature.masm. Can you please take a look?

Comment thread crates/miden-standards/asm/standards/auth/signature.masm Outdated
Comment thread crates/miden-standards/asm/standards/auth/eip712/transaction_summary.masm Outdated

@partylikeits1983 partylikeits1983 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

I just think we need to make a slight adjustment to the tests (see comment below)

Comment on lines +302 to +300
CodeExecutor::with_default_host()
.extend_advice_inputs(advice)
.run(&script)
.await
.map(|_| ())
verify_eip712_signature(
domain.separator().into(),
transaction.eip712_hash_struct().into(),
public_key,
signature,
)
.await

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should still use the MASM transaction summary adapter here. Computing the EIP-712 domain separator and transaction summary struct hash in Rust skips part of the production MASM code, so these fixtures no longer test the entire in production execution path.

@partylikeits1983 partylikeits1983 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

Lets get 1 more approval before merging though cc @mmagician @PhilippGackstatter

@PhilippGackstatter PhilippGackstatter left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM with one suggestion.

#! - signature verification fails.
#!
#! Invocation: exec
pub proc verify_eip712_signature(

@PhilippGackstatter PhilippGackstatter Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't this more like a helper for signatures::verify_signatures rather than general-purpose? Consider making it a helper procedure in signatures.masm to remove it from the public API. Having this and verify isn't super clean.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would prefer keeping the EIP-712 logic together under eip712, consistent with @mmagician’s earlier feedback. I agree this procedure is specific to the signature-verification flow, though. Is your main concern exposing it publicly, or the module placement itself?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is your main concern exposing it publicly, or the module placement itself?

The main concern is that it is publicly accessible and that I don't think any external caller would call it, because it is effectively an miden-standards-internal helper.

I prefer moving it to signatures.masm, as it is a helper for that module, but making it private where it is is also fine, if you prefer the current structure.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @PhilippGackstatter, I’ve moved verify_eip712_signature into signature.masm as a private helper. Making the procedure private in the eip712 module would prevent signature.masm from calling it.

@partylikeits1983

Copy link
Copy Markdown
Contributor

Looks good to me, I think all thats left is to resolve merge conflict with changelog & address Philipp's comment.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants