mint.rs 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340
  1. use std::collections::{HashMap, HashSet};
  2. use cashu::dhke::{sign_message, verify_message};
  3. pub use cashu::error::mint::Error;
  4. use cashu::nuts::{
  5. BlindedMessage, BlindedSignature, MeltBolt11Request, MeltBolt11Response, Proof, SplitRequest,
  6. SplitResponse, *,
  7. };
  8. #[cfg(feature = "nut07")]
  9. use cashu::nuts::{CheckSpendableRequest, CheckSpendableResponse};
  10. use cashu::secret::Secret;
  11. use cashu::Amount;
  12. use serde::{Deserialize, Serialize};
  13. use tracing::{debug, info};
  14. use crate::types::Quote;
  15. pub struct Mint {
  16. // pub pubkey: PublicKey
  17. secret: String,
  18. pub keysets: HashMap<Id, nut02::mint::KeySet>,
  19. pub keysets_info: HashMap<Id, MintKeySetInfo>,
  20. pub spent_secrets: HashSet<Secret>,
  21. pub pending_secrets: HashSet<Secret>,
  22. pub fee_reserve: FeeReserve,
  23. pub quotes: HashMap<String, Quote>,
  24. }
  25. impl Mint {
  26. pub fn new(
  27. secret: &str,
  28. keysets_info: HashSet<MintKeySetInfo>,
  29. spent_secrets: HashSet<Secret>,
  30. quotes: Vec<Quote>,
  31. min_fee_reserve: Amount,
  32. percent_fee_reserve: f32,
  33. ) -> Self {
  34. let mut keysets = HashMap::default();
  35. let mut info = HashMap::default();
  36. let mut active_units: HashSet<String> = HashSet::default();
  37. let quotes = quotes.into_iter().map(|q| (q.id.clone(), q)).collect();
  38. // Check that there is only one active keyset per unit
  39. for keyset_info in keysets_info {
  40. if keyset_info.active && !active_units.insert(keyset_info.unit.clone()) {
  41. // TODO: Handle Error
  42. todo!()
  43. }
  44. let keyset = nut02::mint::KeySet::generate(
  45. secret,
  46. keyset_info.unit.clone(),
  47. keyset_info.derivation_path.clone(),
  48. keyset_info.max_order,
  49. );
  50. keysets.insert(keyset.id, keyset);
  51. info.insert(keyset_info.id, keyset_info);
  52. }
  53. Self {
  54. secret: secret.to_string(),
  55. keysets,
  56. quotes,
  57. keysets_info: info,
  58. spent_secrets,
  59. pending_secrets: HashSet::new(),
  60. fee_reserve: FeeReserve {
  61. min_fee_reserve,
  62. percent_fee_reserve,
  63. },
  64. }
  65. }
  66. /// Retrieve the public keys of the active keyset for distribution to
  67. /// wallet clients
  68. pub fn keyset_pubkeys(&self, keyset_id: &Id) -> Option<KeysResponse> {
  69. let keys: Keys = match self.keysets.get(keyset_id) {
  70. Some(keyset) => keyset.keys.clone().into(),
  71. None => {
  72. return None;
  73. }
  74. };
  75. Some(KeysResponse { keys })
  76. }
  77. /// Return a list of all supported keysets
  78. pub fn keysets(&self) -> KeysetResponse {
  79. let keysets = self
  80. .keysets_info
  81. .values()
  82. .map(|k| k.clone().into())
  83. .collect();
  84. KeysetResponse { keysets }
  85. }
  86. pub fn keyset(&self, id: &Id) -> Option<KeySet> {
  87. self.keysets.get(id).map(|ks| ks.clone().into())
  88. }
  89. pub fn process_mint_request(
  90. &mut self,
  91. mint_request: nut04::MintRequest,
  92. ) -> Result<nut04::PostMintResponse, Error> {
  93. let mut blind_signatures = Vec::with_capacity(mint_request.outputs.len());
  94. for blinded_message in mint_request.outputs {
  95. blind_signatures.push(self.blind_sign(&blinded_message)?);
  96. }
  97. Ok(nut04::PostMintResponse {
  98. promises: blind_signatures,
  99. })
  100. }
  101. fn blind_sign(&self, blinded_message: &BlindedMessage) -> Result<BlindedSignature, Error> {
  102. let BlindedMessage {
  103. amount,
  104. b,
  105. keyset_id,
  106. } = blinded_message;
  107. let keyset = self.keysets.get(keyset_id).ok_or(Error::UnknownKeySet)?;
  108. // Check that the keyset is active and should be used to sign
  109. if !self
  110. .keysets_info
  111. .get(keyset_id)
  112. .ok_or(Error::UnknownKeySet)?
  113. .active
  114. {
  115. return Err(Error::InactiveKeyset);
  116. }
  117. let Some(key_pair) = keyset.keys.0.get(amount) else {
  118. // No key for amount
  119. return Err(Error::AmountKey);
  120. };
  121. let c = sign_message(key_pair.secret_key.clone().into(), b.clone().into())?;
  122. Ok(BlindedSignature {
  123. amount: *amount,
  124. c: c.into(),
  125. id: keyset.id,
  126. })
  127. }
  128. pub fn process_split_request(
  129. &mut self,
  130. split_request: SplitRequest,
  131. ) -> Result<SplitResponse, Error> {
  132. let proofs_total = split_request.input_amount();
  133. let output_total = split_request.output_amount();
  134. if proofs_total != output_total {
  135. return Err(Error::Amount);
  136. }
  137. let proof_count = split_request.inputs.len();
  138. let secrets: HashSet<Secret> = split_request
  139. .inputs
  140. .iter()
  141. .map(|p| p.secret.clone())
  142. .collect();
  143. // Check that there are no duplicate proofs in request
  144. if secrets.len().ne(&proof_count) {
  145. return Err(Error::DuplicateProofs);
  146. }
  147. for proof in &split_request.inputs {
  148. self.verify_proof(proof)?
  149. }
  150. for secret in secrets {
  151. self.spent_secrets.insert(secret);
  152. }
  153. let promises: Vec<BlindedSignature> = split_request
  154. .outputs
  155. .iter()
  156. .map(|b| self.blind_sign(b).unwrap())
  157. .collect();
  158. Ok(SplitResponse::new(promises))
  159. }
  160. fn verify_proof(&self, proof: &Proof) -> Result<(), Error> {
  161. if self.spent_secrets.contains(&proof.secret) {
  162. return Err(Error::TokenSpent);
  163. }
  164. let keyset = self.keysets.get(&proof.id).ok_or(Error::UnknownKeySet)?;
  165. let Some(keypair) = keyset.keys.0.get(&proof.amount) else {
  166. return Err(Error::AmountKey);
  167. };
  168. verify_message(
  169. keypair.secret_key.clone().into(),
  170. proof.c.clone().into(),
  171. &proof.secret,
  172. )?;
  173. Ok(())
  174. }
  175. #[cfg(feature = "nut07")]
  176. pub fn check_spendable(
  177. &self,
  178. check_spendable: &CheckSpendableRequest,
  179. ) -> Result<CheckSpendableResponse, Error> {
  180. let mut spendable = Vec::with_capacity(check_spendable.proofs.len());
  181. let mut pending = Vec::with_capacity(check_spendable.proofs.len());
  182. for proof in &check_spendable.proofs {
  183. spendable.push(!self.spent_secrets.contains(&proof.secret));
  184. pending.push(self.pending_secrets.contains(&proof.secret));
  185. }
  186. Ok(CheckSpendableResponse { spendable, pending })
  187. }
  188. pub fn verify_melt_request(&mut self, melt_request: &MeltBolt11Request) -> Result<(), Error> {
  189. let quote = self.quotes.get(&melt_request.quote).unwrap();
  190. let proofs_total = melt_request.proofs_amount().to_sat();
  191. let required_total = quote.amount + quote.fee_reserve;
  192. if proofs_total < required_total {
  193. debug!(
  194. "Insufficient Proofs: Got: {}, Required: {}",
  195. proofs_total, required_total
  196. );
  197. return Err(Error::Amount);
  198. }
  199. let secrets: HashSet<&Secret> = melt_request.inputs.iter().map(|p| &p.secret).collect();
  200. // Ensure proofs are unique and not being double spent
  201. if melt_request.inputs.len().ne(&secrets.len()) {
  202. return Err(Error::DuplicateProofs);
  203. }
  204. for proof in &melt_request.inputs {
  205. self.verify_proof(proof)?
  206. }
  207. Ok(())
  208. }
  209. pub fn process_melt_request(
  210. &mut self,
  211. melt_request: &MeltBolt11Request,
  212. preimage: &str,
  213. total_spent: Amount,
  214. ) -> Result<MeltBolt11Response, Error> {
  215. self.verify_melt_request(melt_request)?;
  216. let secrets = Vec::with_capacity(melt_request.inputs.len());
  217. for secret in secrets {
  218. self.spent_secrets.insert(secret);
  219. }
  220. let mut change = None;
  221. if let Some(outputs) = melt_request.outputs.clone() {
  222. let change_target = melt_request.proofs_amount() - total_spent;
  223. let mut amounts = change_target.split();
  224. let mut change_sigs = Vec::with_capacity(amounts.len());
  225. if outputs.len().lt(&amounts.len()) {
  226. debug!(
  227. "Providing change requires {} blinded messages, but only {} provided",
  228. amounts.len(),
  229. outputs.len()
  230. );
  231. // In the case that not enough outputs are provided to return all change
  232. // Reverse sort the amounts so that the most amount of change possible is
  233. // returned. The rest is burnt
  234. amounts.sort_by(|a, b| b.cmp(a));
  235. }
  236. for (amount, blinded_message) in amounts.iter().zip(outputs) {
  237. let mut blinded_message = blinded_message;
  238. blinded_message.amount = *amount;
  239. let signature = self.blind_sign(&blinded_message)?;
  240. change_sigs.push(signature)
  241. }
  242. change = Some(change_sigs);
  243. } else {
  244. info!(
  245. "No change outputs provided. Burnt: {} sats",
  246. (melt_request.proofs_amount() - total_spent).to_sat()
  247. );
  248. }
  249. Ok(MeltBolt11Response {
  250. paid: true,
  251. proof: preimage.to_string(),
  252. change,
  253. })
  254. }
  255. }
  256. pub struct FeeReserve {
  257. pub min_fee_reserve: Amount,
  258. pub percent_fee_reserve: f32,
  259. }
  260. #[derive(Debug, Hash, Clone, PartialEq, Eq, Serialize, Deserialize)]
  261. pub struct MintKeySetInfo {
  262. pub id: Id,
  263. pub unit: String,
  264. pub active: bool,
  265. pub valid_from: u64,
  266. pub valid_to: Option<u64>,
  267. pub derivation_path: String,
  268. pub max_order: u8,
  269. }
  270. impl From<MintKeySetInfo> for KeySetInfo {
  271. fn from(keyset_info: MintKeySetInfo) -> Self {
  272. Self {
  273. id: keyset_info.id,
  274. unit: keyset_info.unit,
  275. }
  276. }
  277. }