{"_id":"@bsv/ecpm-permission-module","_rev":"4-7b35b3c554f04f60da10c728c0cfdcc7","name":"@bsv/ecpm-permission-module","dist-tags":{"security-bootstrap":"0.0.0-security-bootstrap.0","latest":"0.1.1"},"versions":{"0.0.0-security-bootstrap.0":{"name":"@bsv/ecpm-permission-module","version":"0.0.0-security-bootstrap.0","license":"UNLICENSED","_id":"@bsv/ecpm-permission-module@0.0.0-security-bootstrap.0","maintainers":[{"name":"johngalt5","email":"dylan@murraydt.com"},{"name":"loftsteinn","email":"oli@oskarsson.nl"},{"name":"dkellen","email":"darrkellen@gmail.com"},{"name":"braydude","email":"brayden167@gmail.com"},{"name":"tyeverett","email":"p2ppsr@tyweb.us"}],"dist":{"shasum":"b9ca228ee9a1505b2af51a84d087f532c92b2267","tarball":"https://registry.npmjs.org/@bsv/ecpm-permission-module/-/ecpm-permission-module-0.0.0-security-bootstrap.0.tgz","fileCount":2,"integrity":"sha512-kH0lldUlHc/oGugsN2RQltnTotNb4GCevR5xMJL8oEJpIt6izG+gyGOws7gxOUNWCJCIPfXPHaii0RZWeA381A==","signatures":[{"sig":"MEYCIQCbifW7VTgTCq4Z6s2S5CeS8HHyCd97pnM3F16cwRQLrwIhALz7FqSSb01YKKBwhQ1dqZrANxtC+zmreUv4NXx5UEFt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":552},"_npmUser":{"name":"tyeverett","email":"p2ppsr@tyweb.us"},"deprecated":"Non-functional trusted-publishing bootstrap; use 0.1.0 or later.","_npmVersion":"11.12.1","description":"Non-functional placeholder used only to establish npm trusted publishing.","directories":{},"_nodeVersion":"25.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ecpm-permission-module_0.0.0-security-bootstrap.0_1789066580959_0.7578663523879299","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@bsv/ecpm-permission-module","version":"0.1.0","keywords":["brc-98","brc-229","ecpm","permissions","wallet","BSV"],"author":{"name":"BSV Association"},"license":"SEE LICENSE IN LICENSE.txt","_id":"@bsv/ecpm-permission-module@0.1.0","maintainers":[{"name":"johngalt5","email":"dylan@murraydt.com"},{"name":"loftsteinn","email":"oli@oskarsson.nl"},{"name":"dkellen","email":"darrkellen@gmail.com"},{"name":"braydude","email":"brayden167@gmail.com"},{"name":"tyeverett","email":"p2ppsr@tyweb.us"}],"homepage":"https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/ecpm-permission-module#readme","bugs":{"url":"https://github.com/bsv-blockchain/ts-stack/issues"},"dist":{"shasum":"4486bab62b55c03531646c627caa554dd38451a4","tarball":"https://registry.npmjs.org/@bsv/ecpm-permission-module/-/ecpm-permission-module-0.1.0.tgz","fileCount":6,"integrity":"sha512-ZPrN/KfLUWNib1Z90Vg5w3qMWYMXQeX+a0zuDaB8E1TLCD5dC/OTU1mMOIgGjpBbTPXebDikjYC9uZHCRD4OYA==","signatures":[{"sig":"MEQCIAjHl0QqmUP0VCd+20PACUkHei4Y1xLkUIi46WWqm4tNAiBKEzW07NnhBysZX2OdQXt/OgRboni2/m9HVefE15koNw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBzDUS2MD76wSIVYFUFM8VQfGxQqtDpiHv5RSXDFc3XqAiEAkjRwbw+I/5buTsj2Od0HbqXPSmEGYM6HFCeph3LxuKE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bsv%2fecpm-permission-module@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":37822},"main":"./dist/index.mjs","type":"module","_from":"file:/home/runner/work/ts-stack/ts-stack/release-artifacts/packages/bsv-ecpm-permission-module-0.1.0.tgz","types":"./dist/index.d.mts","module":"./dist/index.mjs","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"}}},"scripts":{"lint":"oxlint src --deny-warnings","test":"jest","build":"tsdown src/index.ts --format esm --dts --sourcemap --clean --out-dir dist --tsconfig tsconfig.build.json","clean":"rm -rf dist","typecheck":"tsc --project tsconfig.typecheck.json","pack:check":"node ../../../scripts/check-package-artifact.mjs . --modes esm --exports EcpmPermissionModule,createEcpmModule","format:check":"pnpm --workspace-root exec prettier --check \"packages/wallet/ecpm-permission-module/src/**/*.ts\" \"packages/wallet/ecpm-permission-module/README.md\" \"packages/wallet/ecpm-permission-module/*.{cjs,json,ts}\"","test:browser":"pnpm build && node ../../../scripts/check-browser-package.mjs .","test:coverage":"jest --coverage","test:property":"jest --runInBand --runTestsByPath src/__tests__/EcpmPermissionModule.property.test.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f1cdd6ae-2512-4fe2-aec2-cc09501d185f"}},"_resolved":"/home/runner/work/ts-stack/ts-stack/release-artifacts/packages/bsv-ecpm-permission-module-0.1.0.tgz","_integrity":"sha512-ZPrN/KfLUWNib1Z90Vg5w3qMWYMXQeX+a0zuDaB8E1TLCD5dC/OTU1mMOIgGjpBbTPXebDikjYC9uZHCRD4OYA==","repository":{"url":"git+https://github.com/bsv-blockchain/ts-stack.git","type":"git","directory":"packages/wallet/ecpm-permission-module"},"_npmVersion":"11.16.0","description":"BRC-98 ECPM semantic module for elliptic-curve point multiplication in BRC-100 wallets","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","oxlint":"^1.76.0","tsdown":"0.22.14","ts-jest":"^29.4.12","@bsv/sdk":"^2.5.0","fast-check":"^4.9.0","typescript":"npm:@typescript/typescript6@6.0.2","@types/jest":"^30.0.0","@types/node":"^26.1.2","@jest/globals":"^30.4.1","@typescript/native":"npm:typescript@7.0.2","@bsv/wallet-toolbox-client":"^2.12.0"},"peerDependencies":{"@bsv/sdk":"^2.4.1","@bsv/wallet-toolbox-client":"^2.11.0"},"_npmOperationalInternal":{"tmp":"tmp/ecpm-permission-module_0.1.0_1789067496994_0.9758746376500533","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"_id":"@bsv/ecpm-permission-module@0.1.1","bugs":{"url":"https://github.com/bsv-blockchain/ts-stack/issues"},"dist":{"shasum":"5ae0b432f464e2d96b993cabeecc844e68b595f6","tarball":"https://registry.npmjs.org/@bsv/ecpm-permission-module/-/ecpm-permission-module-0.1.1.tgz","fileCount":6,"integrity":"sha512-EbDNkCT5sH391nexu0jAVgFitnCbR10D9rTgLzowTlvlcVOmRwrBIrvg24HEcn4qlQ5/BgiIxuO79kop5Nx4GQ==","signatures":[{"sig":"MEQCICe1eJ1kAfoMWzgUAaY2foHnyJS6UwD++FFow1yjnXeNAiBg2mX4N3V2Li46lBcsISoZcN20O2ne+ohRnHVU4cY90Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAK2iRWhasBgwI4Hpg2ZlFVF7EwY32AFkuKDNRU5QIsfAiEAuBKMkPJi3vQ66B3rl45CpM/EZ+e1yW+or2ldsmI+JEg="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bsv%2fecpm-permission-module@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":42447},"main":"./dist/index.mjs","name":"@bsv/ecpm-permission-module","type":"module","_from":"file:/home/runner/work/ts-stack/ts-stack/release-artifacts/packages/bsv-ecpm-permission-module-0.1.1.tgz","types":"./dist/index.d.mts","author":{"name":"BSV Association"},"module":"./dist/index.mjs","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"}}},"license":"SEE LICENSE IN LICENSE.txt","scripts":{"lint":"oxlint src --deny-warnings","test":"jest","build":"tsdown src/index.ts --format esm --dts --sourcemap --clean --out-dir dist --tsconfig tsconfig.build.json","clean":"rm -rf dist","typecheck":"tsc --project tsconfig.typecheck.json","pack:check":"node ../../../scripts/check-package-artifact.mjs . --modes esm --exports EcpmPermissionModule,createEcpmModule","format:check":"pnpm --workspace-root exec prettier --check \"packages/wallet/ecpm-permission-module/src/**/*.ts\" \"packages/wallet/ecpm-permission-module/README.md\" \"packages/wallet/ecpm-permission-module/*.{cjs,json,ts}\"","test:browser":"pnpm build && node ../../../scripts/check-browser-package.mjs .","test:coverage":"jest --coverage","test:property":"jest --runInBand --runTestsByPath src/__tests__/EcpmPermissionModule.property.test.ts"},"version":"0.1.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f1cdd6ae-2512-4fe2-aec2-cc09501d185f"}},"homepage":"https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/ecpm-permission-module#readme","keywords":["brc-98","brc-229","ecpm","permissions","wallet","BSV"],"_resolved":"/home/runner/work/ts-stack/ts-stack/release-artifacts/packages/bsv-ecpm-permission-module-0.1.1.tgz","_integrity":"sha512-EbDNkCT5sH391nexu0jAVgFitnCbR10D9rTgLzowTlvlcVOmRwrBIrvg24HEcn4qlQ5/BgiIxuO79kop5Nx4GQ==","repository":{"url":"git+https://github.com/bsv-blockchain/ts-stack.git","type":"git","directory":"packages/wallet/ecpm-permission-module"},"_npmVersion":"11.16.0","description":"BRC-98 ECPM semantic module for elliptic-curve point multiplication in BRC-100 wallets","directories":{},"maintainers":[{"name":"johngalt5","email":"dylan@murraydt.com"},{"name":"loftsteinn","email":"oli@oskarsson.nl"},{"name":"dkellen","email":"darrkellen@gmail.com"},{"name":"braydude","email":"brayden167@gmail.com"},{"name":"tyeverett","email":"p2ppsr@tyweb.us"}],"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","oxlint":"^1.76.0","tsdown":"0.22.14","ts-jest":"^29.4.12","@bsv/sdk":"^2.8.0","fast-check":"^4.9.0","typescript":"npm:@typescript/typescript6@6.0.2","@types/jest":"^30.0.0","@types/node":"^26.1.2","@jest/globals":"^30.4.1","@typescript/native":"npm:typescript@7.0.2","@bsv/wallet-toolbox-client":"^2.13.2"},"peerDependencies":{"@bsv/sdk":"^2.4.1","@bsv/wallet-toolbox-client":"^2.11.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ecpm-permission-module_0.1.1_1790141763456_0.6972297694799678"}}},"time":{"created":"2026-09-10T18:56:20.756Z","modified":"2026-09-23T05:36:03.934Z","0.0.0-security-bootstrap.0":"2026-09-10T18:56:21.096Z","0.1.0":"2026-09-10T19:11:37.155Z","0.1.1":"2026-09-23T05:36:03.541Z"},"bugs":{"url":"https://github.com/bsv-blockchain/ts-stack/issues"},"author":{"name":"BSV Association"},"license":"SEE LICENSE IN LICENSE.txt","homepage":"https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/ecpm-permission-module#readme","keywords":["brc-98","brc-229","ecpm","permissions","wallet","BSV"],"repository":{"url":"git+https://github.com/bsv-blockchain/ts-stack.git","type":"git","directory":"packages/wallet/ecpm-permission-module"},"description":"BRC-98 ECPM semantic module for elliptic-curve point multiplication in BRC-100 wallets","maintainers":[{"name":"johngalt5","email":"dylan@murraydt.com"},{"name":"loftsteinn","email":"oli@oskarsson.nl"},{"name":"dkellen","email":"darrkellen@gmail.com"},{"name":"braydude","email":"brayden167@gmail.com"},{"name":"tyeverett","email":"p2ppsr@tyweb.us"}],"readme":"# ECPM Permission Module\n\n`@bsv/ecpm-permission-module` implements the BRC-229 `p ecpm` semantic module\nfor BRC-100 wallets. It applies or removes a BRC-42/43-derived scalar to an\narbitrary validated secp256k1 point without adding a method or wire call to the\nfixed BRC-100 interface.\n\n## Protocol\n\nApplications call the existing `getPublicKey` method with:\n\n```text\np ecpm <apply|remove> <pointHex> <logicalProtocolID>\n```\n\nThe logical protocol ID is 5–273 ASCII bytes. The complete dispatch envelope\nmay be 353 bytes for `apply` or 354 bytes for `remove`; this preserves the full\nBRC-43 logical protocol namespace while remaining inside BRC-100's 400-byte\nprotocol-string limit.\n\nThe security level remains in the normal BRC-43 tuple. The key ID,\ncounterparty, privileged selection, privileged reason, and permission behavior\nremain in their existing `getPublicKey` fields.\n\n```ts\nconst applied = await wallet.getPublicKey({\n  protocolID: [2, `p ecpm apply ${pointHex} mental poker deal`],\n  keyID: 'deck mask',\n  counterparty: 'self'\n})\n\nconst removed = await wallet.getPublicKey({\n  protocolID: [2, `p ecpm remove ${applied.publicKey} mental poker deal`],\n  keyID: 'deck mask',\n  counterparty: 'self'\n})\n```\n\nFor both calls, the module derives the scalar under the canonical namespace\n`p ecpm mental poker deal`. The operation and point are deliberately excluded\nfrom the BRC-42 invoice so every point uses the same scalar and `remove`\nselects the inverse of the scalar used by `apply`.\n\n## Installation\n\nCreate the module with the wallet's ordinary `KeyDeriverApi` and an\nauthorization callback, then register it under the `ecpm` scheme:\n\n```ts\nimport { createEcpmModule } from '@bsv/ecpm-permission-module'\nimport { WalletPermissionsManager } from '@bsv/wallet-toolbox-client'\n\nconst ecpm = createEcpmModule({\n  keyDeriver: setup.keyDeriver,\n  authorize: async request => {\n    return await showTrustedWalletPrompt({\n      originator: request.originator,\n      protocol: request.logicalProtocolID,\n      counterparty: request.counterparty,\n      privileged: request.privileged\n    })\n  },\n  privilegedKeyDeriver: async reason => {\n    return await acquirePrivilegedKeyDeriver(reason)\n  }\n})\n\nconst wallet = new WalletPermissionsManager(setup.wallet, adminOriginator, {\n  permissionModules: { ecpm }\n})\n```\n\nCall `ecpm.dispose()` when the host tears down the wallet. The method clears\ncached and pending authorization state.\n\nSuccessful grants are capped at 1,024 entries with oldest-grant eviction, and\nat most 64 distinct authorization prompts may remain in flight. Requests that\nwould exceed the pending limit fail closed until an existing prompt settles.\nThese receiver-local bounds prevent a hostile application from turning a\npermanently pending authorization UI into unbounded wallet memory.\n\nSecurity level 0 primary-key requests do not prompt. Levels 1 and 2 require\nthe authorization callback, with level 2 grants scoped to the counterparty.\nEvery privileged request requires authorization regardless of security level,\nand cached or in-flight privileged grants are scoped to the exact approved\n`privilegedReason`. Changing the reason requires a separate authorization.\n`seekPermission: false` fails unless an applicable grant is already cached.\n\n## Security model\n\nThe module:\n\n- accepts only `getPublicKey` in the `p ecpm` namespace, preventing the same\n  derived key from being reused for signatures, HMACs, or BRC-2 encryption;\n- rejects identity-key and `forSelf` requests;\n- keeps the point and operation outside the derived-key identity;\n- isolates ordinary and privileged derivation providers;\n- checks the encoded x coordinate before parsing so a reducing parser cannot\n  accept a non-canonical point;\n- accepts only finite, on-curve, lowercase compressed secp256k1 points; and\n- returns the existing `{ publicKey }` result shape, so no BRC-100 wire change\n  is required.\n\nThe module is trusted wallet code. Applications never receive a key deriver or\nprivate scalar. A privileged provider should acquire protected key material\nonly after its reason has been displayed and authorized, and should retain it\nfor no longer than the host wallet's existing privileged-key policy permits.\n\n## Verification\n\n```bash\npnpm --filter @bsv/sdk build\npnpm --filter @bsv/wallet-toolbox-client build\npnpm --filter @bsv/ecpm-permission-module typecheck\npnpm --filter @bsv/ecpm-permission-module lint\npnpm --filter @bsv/ecpm-permission-module test:coverage\npnpm --filter @bsv/ecpm-permission-module test:property\npnpm --filter @bsv/ecpm-permission-module build\npnpm --filter @bsv/ecpm-permission-module pack:check\n```\n\n## License\n\nOpen BSV License version 6. See `LICENSE.txt`.\n","readmeFilename":"README.md"}