{"_id":"@bns-x/png","_rev":"1-89130122061144aefa698809156d5246","name":"@bns-x/png","dist-tags":{"latest":"0.2.5"},"versions":{"0.2.4":{"name":"@bns-x/png","version":"0.2.4","license":"MIT","private":false,"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/mechanismHQ/bns-x.git#main"},"types":"./dist/index.d.ts","main":"./dist/index.js","module":"./dist/index.js","import":"./dist/index.js","type":"module","sideEffects":false,"dependencies":{"@noble/hashes":"1.3.0","micro-packed":"^0.3.2","micro-stacks":"^1.2.1","pako":"^2.1.0"},"devDependencies":{"@types/jest":"^29.2.4","@types/pako":"^2.0.0","jest":"^29.3.1","ts-jest":"^29.0.3","tsup":"^6.7.0","tsx":"^3.12.3","typescript":"4.9.5","vitest":"^0.31.0","zod":"3.20.6"},"scripts":{"typecheck":"tsc --noEmit","build":"tsup","test":"vitest"},"description":"A library for verifying and creating \"Verified PNGs\".","bugs":{"url":"https://github.com/mechanismHQ/bns-x/issues"},"homepage":"https://github.com/mechanismHQ/bns-x/tree/main#readme","_id":"@bns-x/png@0.2.4","_integrity":"sha512-WSVo1nGhtcmLESrZegqHzDewl+FwkVRjzQQOkb2L7Dto32DN8UqdJDBF+JbVK2CHOJ1pHI1+ecQgARPvnX2zsA==","_resolved":"/private/var/folders/x_/1x7_dfws2976t3wzgzrsg4cr0000gn/T/47bcd6821abd781f0392931ce437b855/bns-x-png-0.2.4.tgz","_from":"file:bns-x-png-0.2.4.tgz","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-WSVo1nGhtcmLESrZegqHzDewl+FwkVRjzQQOkb2L7Dto32DN8UqdJDBF+JbVK2CHOJ1pHI1+ecQgARPvnX2zsA==","shasum":"c37528a82e0518f19c4de2855127c2c07fa66f12","tarball":"https://registry.npmjs.org/@bns-x/png/-/png-0.2.4.tgz","fileCount":7,"unpackedSize":66415,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAH6qiQSA2dG4lna4YFwjIN3Ca3Axyv8wxU3aY7aBG2GAiEAscCt+YV9JukNpXx24rb3QNPMDsLsQpX3Kc2UroX3o54="}]},"_npmUser":{"name":"hstove","email":"hstove@gmail.com"},"directories":{},"maintainers":[{"name":"hstove","email":"hstove@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/png_0.2.4_1683745564061_0.19908972582856976"},"_hasShrinkwrap":false},"0.2.5":{"name":"@bns-x/png","version":"0.2.5","license":"MIT","private":false,"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/mechanismHQ/bns-x.git#main"},"types":"./dist/index.d.ts","main":"./dist/index.js","module":"./dist/index.js","import":"./dist/index.js","type":"module","sideEffects":false,"dependencies":{"@noble/hashes":"1.3.0","micro-packed":"^0.3.2","micro-stacks":"^1.2.1","pako":"^2.1.0"},"devDependencies":{"@types/jest":"^29.2.4","@types/pako":"^2.0.0","jest":"^29.3.1","ts-jest":"^29.0.3","tsup":"^6.7.0","tsx":"^3.12.3","typescript":"4.9.5","vitest":"^0.31.0","zod":"3.20.6"},"scripts":{"typecheck":"tsc --noEmit","build":"tsup","test":"vitest"},"description":"A library for verifying and creating \"Verified PNGs\".","bugs":{"url":"https://github.com/mechanismHQ/bns-x/issues"},"homepage":"https://github.com/mechanismHQ/bns-x/tree/main#readme","_id":"@bns-x/png@0.2.5","_integrity":"sha512-XUSzqQidG2KCbePRGAA6TtomJJmwYHgBmBZWvHmBdwwkt0dQi3YOlMicFkP4tg9cC3V4qxMZYzjPq3AzHjYimQ==","_resolved":"/private/var/folders/x_/1x7_dfws2976t3wzgzrsg4cr0000gn/T/58e70798ea4e4272a4eb0ad2a7d41809/bns-x-png-0.2.5.tgz","_from":"file:bns-x-png-0.2.5.tgz","_nodeVersion":"18.13.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-XUSzqQidG2KCbePRGAA6TtomJJmwYHgBmBZWvHmBdwwkt0dQi3YOlMicFkP4tg9cC3V4qxMZYzjPq3AzHjYimQ==","shasum":"5c20439546cc6e0f2d1b85758b9a0be63e6be804","tarball":"https://registry.npmjs.org/@bns-x/png/-/png-0.2.5.tgz","fileCount":7,"unpackedSize":66305,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCXwNliz6Ql9Lv1v67Xv27xb8Y/fjQKpp4tJ6x6x1p7fAIhAJq9/QVdHVln4CCBSO4kauOZqibDs+Py0N0VKym8JoLQ"}]},"_npmUser":{"name":"hstove","email":"hstove@gmail.com"},"directories":{},"maintainers":[{"name":"hstove","email":"hstove@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/png_0.2.5_1684263533361_0.566635113328936"},"_hasShrinkwrap":false}},"time":{"created":"2023-05-10T19:06:03.993Z","0.2.4":"2023-05-10T19:06:04.237Z","modified":"2023-05-16T18:58:53.681Z","0.2.5":"2023-05-16T18:58:53.556Z"},"maintainers":[{"name":"hstove","email":"hstove@gmail.com"}],"description":"A library for verifying and creating \"Verified PNGs\".","homepage":"https://github.com/mechanismHQ/bns-x/tree/main#readme","repository":{"type":"git","url":"git+https://github.com/mechanismHQ/bns-x.git#main"},"bugs":{"url":"https://github.com/mechanismHQ/bns-x/issues"},"license":"MIT","readme":"## `@bns-x/png`\n\nA library for verifying and creating \"Verified PNGs\".\n\nA demo is available on [Dots](https://www.dots.so/verifier).\n\n## Why?\n\nCryptographic signatures are a mechanism that allows anyone to attest to certain information. Blockchains utilize this technology to verify whether a transaction came from a specific address.\n\nWith the growth of NFTs and especially [Ordinals](https://ordinals.com/) inscriptions, there is often a need to establish provenance around a specific image. For example, an artist may wish to use signatures to provably establish that they endorse an artwork.\n\nThis library provides an efficient mechanism for anyone to embed their signature in a PNG file, without effecting how the image is displayed.\n\n## How it works\n\nPNG files are made up of many \"chunks\". These chunks contain information about the image, such as the dimensions, color profile, and raw pixel data. Chunks can also be used to include \"extra\" information, including arbitrary text.\n\nThis library utilizes PNG chunks to store signatures.\n\n### Creating signatures\n\nThe workflow for creating a signature chunk is:\n\n**1. Generate a hash of the PNG**\n\nFor the purposes of this specification, it's not possible to immediately hash the image like any other file, because the file's hash will change after signatures are added. Instead, to generate a hash, you first need to _remove_ any signature-based chunks. This way, a file's hash can remain the same after adding signatures.\n\n**2. Create a signature**\n\nWhen generating a signature, the \"message\" is of the format:\n\n```\n\nPNG_VERIFICATION:{pngHash}\n\n```\n\nWhere `pngHash` is created from step 1.\n\n**3. Encode signature data**\n\nOnce a signature is created, it must be encoded as follows:\n\n| Name           | Format                 | Notes                                                                              |\n| -------------- | ---------------------- | ---------------------------------------------------------------------------------- | --- | --- | --- |\n| Protocol       | Null-terminated string | Used to denote the method for verifying signature data                             |\n| Version        | `uint8`                | To support future versions of this specification. At the moment, `1` is supported. |\n| Signature Data | Bytes                  |                                                                                    |     |     |     |\n\nThe contents of \"Signature Data\" is dependent on the \"protocol\" label. For the \"STX\" protocol, the format is:\n\n| Name       | Format         | Notes                     |\n| ---------- | -------------- | ------------------------- |\n| Public key | 33 bytes       |                           |\n| Signature  | 64 or 65 bytes | Signature in \"RSV\" format |\n\n**4. Create a new chunk**\n\nThis specification uses the `zTXt` chunk type, because it supports compressed data, which reduces the size of added signatures.\n\nThe \"label\" for the chunk must be `verified-inscription`. The compression flag must be `0`, and the value must be the zlib compressed value of the encoded signature data bytes.\n\n**5. Add the chunk to the PNG**\n\nThe chunk can be included anywhere other than as the last chunk of the PNG. This library appends the chunk as the second-to-last chunk in the file.\n\n### Verifying signatures\n\n**1. Create the PNG hash**\n\nRefer to the process from \"creating inscriptions\". This is the `sha256` hash of the image, **after** removing signature chunks.\n\n**2. Extract verification chunks**\n\nA verification chunk is any chunk of the `zTXt` type with the `verified-inscription` label. There may be more than one verification chunk.\n\n**3. Verify chunk signatures**\n\nThe methodology for verifying each chunk's signature is dependent on the `protocol` flag of that chunk. The `message` used to verify each signature is `sha256(\"PNG_VERIFICATION\" + sha256(pngHash))`.\n\n## Using the library\n\nTo extract and verify all verification chunks, use `getPngVerifications(pngFile)`.\n\n```ts\nimport { PNG, getPngVerifications } from '@bns-x/png';\n\nconst url = 'https://www.dots.so/signed-example.png';\nconst response = await fetch(url);\nconst bytes = new Uint8Array(await response.arrayBuffer());\nconst png = PNG.decode(bytes);\nconst verifications = getPngVerifications(png);\n```\n","readmeFilename":"README.md"}