# redux-signatures

> Secure cryptographic signing of Redux actions

Latest version **0.2.0** (published 2017-03-28) · MIT license · 0 weekly downloads

## Install

```sh
npm install redux-signatures
pnpm add redux-signatures
yarn add redux-signatures
bun add redux-signatures
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.2.0 |
| Published | 2017-03-28 |
| First published | 2017-01-08 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 3 |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 6 |
| Maintainers | grrowl |

## Links

- npm: https://www.npmjs.com/package/redux-signatures
- Repository: https://github.com/grrowl/redux-signatures
- Issues: https://github.com/grrowl/redux-signatures/issues
- npm.io page: https://npm.io/package/redux-signatures

## Dependencies (3)

- [sinon](https://npm.io/package/sinon.md) ^1.17.7
- [elliptic](https://npm.io/package/elliptic.md) ^6.3.2
- [json-stable-stringify](https://npm.io/package/json-stable-stringify.md) ^1.0.1

## Recent versions

- 0.2.0 (latest) — 2017-03-28
- 0.0.4 — 2017-01-22
- 0.0.3 — 2017-01-21
- 0.0.2 — 2017-01-12
- 0.0.1-rc.2 — 2017-01-10
- 0.0.1-rc.1 — 2017-01-08

## README

# redux-signatures

Signs redux (or flux) actions for you cryptographically.

Designed for use with
[redux-scuttlebutt](https://github.com/grrowl/redux-scuttlebutt)

Contributions, suggestions and questions welcome.

## signatures

* *[Ed25519](https://ed25519.cr.yp.to/)*:
  "High speed, high security signatures". On my machine, signs in 1ms, verifies
  in 6ms.
  * Sign actions against a public key
  * Verifies actions against their signature and a public key (author)
  * Secure against modification, but not omission.

## use

### sign and verify

For `import { verifyAction, signAction } from 'redux-signatures'`,

* `verifyAction(identity, callback, action)`:
  calls `callback(true)` if `action` is valid, `callback(false)` otherwise.
  * usually `callback` is a `redux` store `dispatch`
* `signAction(identity, callback, action)`:
  calls `callback` with `action`, with publicKey and signature added to the
  `meta` key
  * publicKey and signature constants are exported as `META_PUBLIC_KEY` and
  `META_SIGNATURE` respectively.

### identity

For `import { Ed25519 } from 'redux-signatures'`,

* `identity = new Ed25519()`:
  generates a new Ed25519 identity.
* `identity = new Ed25519(privateKey: string)`:
  recreates an existing Ed25519 identity from privateKey.

* `identity.sign(message: string) => signature: string`:
  Returns the signature for a given message.
* `identity.verifyPublic(message: string, signature: string, publicKey:string) => valid: bool`:
  Verifies a given message against the given signature and publicKey.
* `identity.verify(message: string, signature: string) => valid: bool`:
  Verifies a given message against the given signature and this identity.
* `identity.publicKey => hex: string`:
  Returns the identity's publicKey
* `identity.privateKey => hex: string`:
  Returns the identity's privateKey

### example

```js
const { Ed25519, signAction, verifyAction } from 'redux-signatures'

// create the identity object with a random key.
const identity = new Ed25519()

// serialise action, calls identity.sign, returns action with signature
signAction(identity, callback, action)

// serialise action, calls identity.verify with the action and its included signature
verifyAction(identity, callback, action)

// maintain identity
const identity = new Ed25519(localStorage['privateKey'])
localStorage['privateKey'] = identity.privateKey

// now the app can render the local identity
const initialState = {
  identity: identity.publicKey,
}

// for use with redux-scuttlebutt
return createStore(rootReducer, initialState, scuttlebutt({
  verifyAsync: verifyAction.bind(undefined, identity),
  signAsync: signAction.bind(undefined, identity),
}))
```

## licence

MIT.

---
_Source: https://npm.io/package/redux-signatures · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
