This release hardens how both sides of a payjoin validate what the
counterparty sends. Fee rates, fee arithmetic, PSBT amounts, endpoint URLs,
and directory responses are now checked before they can overflow, panic, or
redirect a request. It deprecates the v2 SenderBuilder::new constructor,
which panics on a BIP 78 only endpoint, and raises the minimum rust-bitcoin
version.
Selected Improvements:
Deprecations
send::v2::SenderBuilder::newis deprecated because it panics when the
URI'spjendpoint is BIP 78 only. UseSenderBuilder::from_partswith
the v2PjParamfrom the parsed URI, and handle v1 endpoints explicitly
(#1884)
Dependencies
- Raise the minimum
bitcoinversion from 0.32.9 to 0.32.102 and
bitcoin-unitsfrom 0.1.3 to 0.1.101. Cargo already resolved 1.0.0 to
these versions, so most dependents see no change (#1879) - Raise
bitcoin-hpkefrom 0.13.0 to 0.20.0 andbitcoin-ohttpfrom 0.6.0 to
0.7.0. Neither crate appears in payjoin's public API, so dependents need no
change (#1817) - The crate now uses Rust edition 2024. The MSRV stays at 1.85 (#1874)
Features
- Add an optional
arbitraryfeature with anArbitraryimplementation for
Url, for use in fuzzing (#1662) PersistedErrorand the v1 receiverRequestErrorimplementPartialEq
(#1873)
Bug Fixes
- Reject userinfo in endpoint URLs with the new
ParseError::UserinfoNotSupported, and reject malformed ports instead of
storing them in the path.http://x.onion:1@evil.com/pjpreviously passed
the v1 onion check and sent the Original PSBT toevil.comin cleartext
(#1896) - Reject Original PSBT output and input UTXO values above
MAX_MONEY, and use
checked addition when the receiver contributes inputs, so a crafted PSBT
can no longer panic the receiver. The sender runs the same check on its own
Original PSBT.substitute_receiver_scriptnow reads the receiver output
value from the payjoin PSBT (#1897) - Harden fee handling on both sides. The receiver rejects NaN, negative, and
above-ceilingminfeeratevalues, ignores a sender fee contribution larger
than the output meant to pay it, and returnsFeeTooHighinstead of
panicking when its fee exceeds its change output. Both sender and receiver
now check fee rate arithmetic for overflow and underflow (#1845, #1889) - Cap the size of OHTTP key responses from the directory and return the new
io::Error::OhttpKeysBodyTooLargewhen a response exceeds it (#1846) - The receiver rejects mailbox responses too short to decrypt instead of
panicking (#1843)
What's Changed
- Introduce
arbitrarycrate by @shinghim in #1662 - chore: update cargo.lock by @payjoin-robot[bot] in #1852
- chore: update flake.lock by @payjoin-robot[bot] in #1854
- chore: update nightly toolchain pin by @payjoin-robot[bot] in #1855
- Add fuzz target for payjoin v2 URI parsing by @caarloshenriq in #1848
- Shared cache keys by @benalleng in #1856
- chore: update cargo.lock by @payjoin-robot[bot] in #1861
- chore: update flake.lock by @payjoin-robot[bot] in #1863
- Build Javascript Bindings in Release Mode by @xstoicunicornx in #1865
- Cap the ohttp key body size from directory by @benalleng in #1846
- Add fuzz target for the v1 payjoin roundtrip by @caarloshenriq in #1872
- Add UniFFI Kotlin bindings for payjoin-ffi by @ram0verflow in #1869
- chore: update cargo.lock by @payjoin-robot[bot] in #1876
- Bump rust-bitcoin minimums to the 0.32.10x line by @caarloshenriq in #1879
- chore: update flake.lock by @payjoin-robot[bot] in #1880
- Update toml edition 2024 by @benalleng in #1874
- chore: update nightly toolchain pin by @payjoin-robot[bot] in #1883
- Fee rate check hardening by @benalleng in #1845
- Add PartialEq to errors compared in tests by @Hardeezah in #1873
- Resolve every binding build against the lockfile by @DanGould in #1885
- Deprecate v2 SenderBuilder::new, fix FFI v1 panic by @DanGould in #1884
- chore: update cargo.lock by @payjoin-robot[bot] in #1891
- Kill && mutant in build_recommended sweep check by @xstoicunicornx in #1893
- chore: update flake.lock by @payjoin-robot[bot] in #1894
- Reject userinfo and malformed ports in Url::parse by @DanGould in #1896
- More fee rate guard protection by @benalleng in #1889
- Reject Amount overflow in receiver contribution by @DanGould in #1897
- Bump payjoin version to 1.1.0 by @DanGould in #1899
New Contributors
- @ram0verflow made their first contribution in #1869
- @Hardeezah made their first contribution in #1873
Full Changelog: payjoin-javascript-0.2.0+payjoin-1.0.0...payjoin-1.1.0