mirror of
https://github.com/Xahau/xahaud.git
synced 2026-09-29 00:18:06 +00:00
jsontx_strict: the comment claimed \u sequences were rejected but the code only tracked backslashes without checking if they introduced a unicode escape. Now properly throws on \u inside strings, which also covers NUL-byte injection (\u0000) and prevents canonical form mismatches caused by jsoncpp silently decoding \uXXXX. tests: add coverage for \u rejection, jsontx_u64 negative/non-integer/ infinity rejection, delta size scaling with transaction complexity, and sanitize rejection of unicode escapes. Fixes a subtle security concern: without this check, a signer could send a preimage with \uXXXX that jsoncpp would decode into a different character, causing the canonical form to diverge from what the signer actually signed while still passing the delta round-trip.