Skip to content

fix(event): keep a preset created_at in GenericEvent.update() (2.4.2) - #560

Merged
tcheeric merged 3 commits into
developfrom
fix/mcp-verbatim-tags
Oct 4, 2026
Merged

tcheeric merged 3 commits into
developfrom
fix/mcp-verbatim-tags

Conversation

@tcheeric

@tcheeric tcheeric commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Summary

GenericEvent.update() restamped created_at with the clock before computing the id. A caller that set created_at, called update() and signed got an id for a different second than the one it saw, so relays rejected the event as invalid: bad event id. NIP-59 randomised timestamps were also replaced by the send time. NIP-01 derives the id from the event's own fields, so this aligns update() with the protocol.

Closes #559

Type of change

  • fix - Bug fix (non-breaking)
  • docs - Documentation only
  • chore - Build, CI, or tooling changes

What changed?

  • GenericEvent.update() keeps a created_at that is already set and only stamps the clock when it is unset (null or 0).
  • New GenericEvent.updateWithCurrentTime() for deliberate restamping.
  • Regression tests in GenericEventUpdateTest, including the NIP-01 id check suggested in the issue.
  • MCP server how-to: "See it in use" section pointing to the Lyrebird bot.
  • Release bump to 2.4.2 across all modules, plus CHANGELOG.

Testing

  • Unit tests pass: mvn -q clean install -DskipITs (exit 0)
  • Integration tests pass: mvn -q verify has one failure, NostrMcpServerStdioIT.aHostCanSeeWhichIdentitiesTheServerHolds. It also fails on the commit before this fix: the test expects an empty keystore but reads the local OS keychain, which holds an identity. Unrelated to this change.
  • End to end: set created_at, update(), waited 1.1s, signed with a real Identity. created_at kept, id unchanged through signing, id equals the NIP-01 hash, Schnorr signature verifies.

Checklist

  • PR title follows conventional commits
  • Changes are focused and under 300 lines
  • Tests added/updated for new functionality
  • No new compiler warnings introduced
  • CHANGELOG.md updated

tcheeric added 3 commits October 4, 2026 13:18
update() restamped created_at with the clock before computing the id, so
callers that set created_at got an id for a different second, and NIP-59
randomised timestamps were replaced by the send time. NIP-01 derives the
id from the event's own fields, so update() now only stamps the clock
when created_at is unset (null or zero). Restamping on purpose is
available through the new updateWithCurrentTime().

Fixes #559
- nostr-java (all modules): 2.4.1 → 2.4.2 (patch) [maven]

Fixed: GenericEvent.update() overwrote a caller-set created_at, so ids
could be computed for a different second (#559).
Added: GenericEvent.updateWithCurrentTime(), and the Lyrebird mention in
the MCP server how-to.
@tcheeric
tcheeric changed the base branch from main to develop October 4, 2026 12:48
@tcheeric
tcheeric merged commit 6860c97 into develop Oct 4, 2026
4 of 5 checks passed
@tcheeric tcheeric mentioned this pull request Oct 4, 2026
7 of 8 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GenericEvent.update() silently overwrites created_at, so callers that set it get a mismatched id

1 participant