{"_id":"@algovoi/rfc9421-ecdsa","name":"@algovoi/rfc9421-ecdsa","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@algovoi/rfc9421-ecdsa","version":"0.1.0","description":"ECDSA (P-256/P-384) provider add-on for @algovoi/rfc9421-verifier","keywords":["rfc9421","ecdsa","p-256","p-384","http-signatures","add-on"],"homepage":"https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa","repository":{"type":"git","url":"git+https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa.git","directory":"typescript"},"license":"Apache-2.0","author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","test":"vitest run","clean":"rimraf dist","prepublishOnly":"npm run clean && npm run build && npm test"},"engines":{"node":">=18"},"peerDependencies":{"@algovoi/rfc9421-verifier":">=0.4.2"},"dependencies":{"@noble/curves":"^1.6.0"},"devDependencies":{"@algovoi/rfc9421-verifier":">=0.4.2","@types/node":"^20.0.0","rimraf":"^5.0.0","typescript":"^5.4.0","vitest":"^1.6.0"},"publishConfig":{"access":"public"},"gitHead":"9baf4853884ea386e90ca3606a2ce48042a17368","_id":"@algovoi/rfc9421-ecdsa@0.1.0","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa/issues"},"_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-nHRMEfzsBDM/vTFIkaCVsBPCxwI2mP4pPaRqNfzr3/xVxHM1luusoU1jJddN33gHGf7c8YjjQaX8AlITBAfN4Q==","shasum":"678ac618e08b150e962b6c1129e9b86edd498ae5","tarball":"https://registry.npmjs.org/@algovoi/rfc9421-ecdsa/-/rfc9421-ecdsa-0.1.0.tgz","fileCount":13,"unpackedSize":38035,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGkrls/kEVDFVefKUB7DFiKC3TouOsC1UvYJPxLFyFUuAiEA6yFhF9fthHz1a06M/zlak/XSrB64THrEE90sZEDuhV8="}]},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"directories":{},"maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/rfc9421-ecdsa_0.1.0_1786286385572_0.6383150280323346"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-09T14:39:45.425Z","0.1.0":"2026-08-09T14:39:45.722Z","modified":"2026-08-09T14:39:45.925Z"},"maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"description":"ECDSA (P-256/P-384) provider add-on for @algovoi/rfc9421-verifier","homepage":"https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa","keywords":["rfc9421","ecdsa","p-256","p-384","http-signatures","add-on"],"repository":{"type":"git","url":"git+https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa.git","directory":"typescript"},"author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"bugs":{"url":"https://github.com/chopmob-cloud/algovoi-rfc9421-ecdsa/issues"},"license":"Apache-2.0","readme":"# @algovoi/rfc9421-ecdsa\n\nECDSA (P-256 / P-384) add-on for\n[@algovoi/rfc9421-verifier](https://www.npmjs.com/package/@algovoi/rfc9421-verifier).\n\nA **pure add-on**: it does not modify or re-publish the core verifier. It gives\nyou a drop-in `verifyRequest` that accepts Ed25519 (delegated verbatim to the\nuntouched verifier) plus the two RFC 9421-registered ECDSA suites:\n\n- `ecdsa-p256-sha256` (RFC 9421 3.3.5): P-256, SHA-256, 64-byte `r‖s` signature\n- `ecdsa-p384-sha384` (RFC 9421 3.3.6): P-384, SHA-384, 96-byte `r‖s` signature\n\nThe ECDSA path reuses the verifier's already-hardened primitives (Signature-Input\nparsing, freshness/replay, Content-Digest, signing-base, downgrade/allow-list) and\nadds only the ECDSA signature check. The core verifier stays Ed25519-only and\nunchanged; this package brings its own `@noble/curves` dependency.\n\n```ts\nimport { verifyRequest } from \"@algovoi/rfc9421-ecdsa\";\n\nconst result = await verifyRequest({\n  method: \"POST\",\n  authority: \"api.example.com\",\n  path: \"/a2a\",\n  headers,\n  body,\n  publicKey: sec1PointBytes,\n  allowedAlgorithms: [\"ecdsa-p256-sha256\"], // opt in per request\n});\n// Ed25519 requests are delegated to the core verifier automatically.\n```\n\n## Hardening\n\nBefore accepting an ECDSA signature the provider enforces:\n\n- the public-key point is on the curve and not the identity;\n- the signature is exactly the curve size (64 / 96 bytes, raw `r‖s`, not DER);\n- `r` and `s` are each in `[1, n-1]`;\n- optional canonical low-`s` enforcement (anti-malleability) via\n  `setStrictLowS(true)`, off by default for spec interop.\n\nByte-for-byte decision parity with the Python `algovoi-rfc9421-ecdsa` package,\nverified by a cross-implementation differential. Apache-2.0.\n","readmeFilename":"README.md","_rev":"1-4d9c063e9ef57556cb109917a6e8f1c1"}