memory.copy(changetype<usize>(S), changetype<usize>(s) + 32, 32)
- if (ge_frombytes(expected_r, s) != 0) return -1
- if (ge_has_small_order(expected_r) != 0) return -1
-
// signature is nonce point R and scalar S (R || S)
// data to hash is nonce point R, public key A, and message M
// from parameter arguments: R = s[0,32], A = pk, M = m
* Verify signature `s` was made by signing message `M` using public key `pub`.
*
* Unlike `crypto_verify_relaxed`, this function is intended for single-use
- * verifications and thus can compute and set `A` by calling
- * `crypto_verify_pubkey` itself.
+ * verifications and thus can compute and set `A` itself.
* @returns -1 if signature fails to verify, else return 0 if signature is good
*/
export function crypto_verify_strict (s: StaticArray<u8>, M: StaticArray<u8>, mlen: i32, pub: StaticArray<u8>): i32 {
return ge_has_small_order(check) - 1
// if (ge_has_small_order(check) == 0) return -1
- // return equalbytes(s, check_r) - 1
+ // return equalbytes(s, check) - 1
}