bip93: Reject non-ASCII normalized input - #13
BenWestgate wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 364e3d5060
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
364e3d5 to
b064fb5
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Not a very likely situation bot OK Rob |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b064fb5aa2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
1b17d8a to
d2f8589
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review, posted at the maintainer's request.
ACK d2f8589.
|
Agent release-gate review at exact head |
d2f8589 to
4f24148
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
1 similar comment
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
afee360 to
a860035
Compare
4f24148 to
49f5cdc
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Reject non-ASCII identifiers, indices, and raw CLI creation headers before lowercasing so Unicode lookalikes cannot normalize into valid Bech32 symbols. Make whole-card confirmation fold ASCII case only. Non-ASCII lookalikes now stay visibly mismatched and enter the normal retry flow for shared, unshared, and derived cards instead of being accepted or reaching the ceremony callback as an apparent match. Document the ASCII-only confirmation boundary in the API and security model. Validation: 867 tests passed normally and under python -O; Ruff check and format passed; strict mypy passed; git diff --check passed.
a860035 to
bbcfb56
Compare
49f5cdc to
4f01561
Compare
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
What
Why
Unicode Kelvin sign
Klowercases to ASCIIk. It could therefore cross header/generation validation boundaries or make a card transcription appear valid even though the parser rejects it. This adapts Rob1Ham#9 onto the current target.Current head
4f01561is the same two human-authored patches mechanically replayed onto refreshed #12; both stable patch-ids are unchanged/; all inline review threads are resolved. The small duplicated ASCII-fold helper is intentionally left to #53, which already owns the overlapping vector/API cleanup and will centralize it once this behavior fix lands.Validation
python -O;