Download the PHP package innis/nostr-nip46 without Composer

On this page you can find all versions of the php package innis/nostr-nip46. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package nostr-nip46

innis/nostr-nip46

CI

NIP-46 (Nostr Connect / "bunker") remote-signer protocol for PHP — both roles

Both sides of NIP-46:

The two roles share one wire vocabulary (Nip46Method, Nip46Request/Nip46Response, the envelope codec, the subscription filter) and one transport port, and the test suite runs the shipped client against the shipped bunker over real cryptography.

The library performs no network I/O of its own: the relay transport arrives as an injected port, so it is relay-pool-agnostic and the protocol logic is tested entirely against in-memory doubles.


Features


Requirements


Installation


Running a bunker

Provide four things and the bunker handles the protocol.

1. A signer — LocalNip46Signer for a key held in process (for a self-hosted signer, the key decrypted from a NIP-49 ncryptsec at unlock), or your own Nip46SignerInterface implementation over whatever holds the key.

2. A transport — implement Nip46TransportInterface to subscribe and publish on your relays.

3. An authenticator — implement Nip46AuthenticatorInterface to validate a client's connect secret (a ?ConnectSecret — null when the client sent none) and return an opaque AppId (or null to reject). Returning a distinct id per secret is what lets you run many named pairings off one signer and attribute each request to an app.

Secret-reuse policy lives in your authenticator, not the library: a secret can be a durable per-app pairing token or single-use (reject a secret once a connection has been established). authenticate is called exactly at connection time and its non-null return is what establishes the connection, so enforce whichever policy you want there against your own store — the library holds no secret state of its own.

4. An authoriser — implement Nip46AuthoriserInterface to say whether an app's grants cover a Permission (sign_event:1, nip44_decrypt, …). It decides answer now versus ask the host, never refuse: a request the app was not granted is queued for approve / reject exactly as a signing request is. PermissionCollection::grantable() lists every permission the bunker will ask about, and fromPermsString / toPermsString parse and render the spec's comma-separated form.

connect, ping, switch_relays (which reports the signer's own relay set) and logout carry no capability and are always answered. get_public_key, sign_event and the four nip04_* / nip44_* methods are answered when granted, and queued when not.

For an audit trail of what each connected app did, register an activity listener — the bunker's optional observability hook, mirroring setQueueListener:

It receives a BunkerActivity for every request the bunker answers on its own, carrying the method name, the resolved AppId, the counterparty public key of a crypto operation, and an Answered / Failed outcome. A queued request never reaches it — record those where you decide them, at approve / reject (see docs/adr/0020).


Connecting as a client

Provide a transport (the same port as the bunker), a throwaway session key, and an implementation of the pending-response port for your runtime — awaiting a reply is deliberately left to the host so the library carries no event-loop dependency (see docs/adr/0008). On amp, the implementation is ~40 lines around a DeferredFuture; a synchronous loopback needs only an array.

connect() performs the handshake (connect with the URL's secret, then get_public_key) and returns the user's public key; signEvent() verifies the returned event's author and signature before handing it back. Every anticipated outcome — timeout, rejection, invalid or forged response, a request too large for the session cipher — is a returned Nip46Failure with a reason and a human-readable describe().

To have the remote signer encrypt or decrypt a payload as the user's identity, call one of the four typed cipher methods — each takes the counterparty's PublicKey and returns the resulting string (or a Nip46Failure):

The client offers one typed method per capability rather than a general call(method, params) escape hatch: that keeps signEvent() the only way to obtain a signed event, so the author-and-signature check it performs cannot be bypassed (see docs/adr/0007).

Run the worked end-to-end example (both roles, real secp256k1 + NIP-44 crypto, no network):


Architecture

Design rationale lives in docs/adr/.


Development


All versions of nostr-nip46 with dependencies

PHP Build Version
Package Version
Requires php Version ^8.4
innis/nostr-core Version ^0.8.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package innis/nostr-nip46 contains the following files

Loading the files please wait ...