Important: This documentation covers Yarn 1 (Classic).
For Yarn 2+ docs and migration guide, see yarnpkg.com.

Package detail

@metamask/eth-sig-util

MetaMask1.6mISC8.1.2TypeScript support: included

A few useful functions for signing ethereum data

ethereum, signature

readme

@metamask/eth-sig-util

A small collection of Ethereum signing functions.

Available on NPM

Installation

yarn add @metamask/eth-sig-util

or

npm install @metamask/eth-sig-util

API

The full API documentation for the latest published version of this library is available here.

Contributing

Setup

  • Install Node.js version 18
    • If you are using nvm (recommended) running nvm use will automatically choose the right node version for you.
  • Install Yarn v3
  • Run yarn install to install dependencies and run any required post-install scripts

Testing and Linting

Run yarn test to run the tests once. To run tests on file changes, run yarn test:watch.

Run yarn lint to run the linter, or run yarn lint:fix to run the linter and fix any automatically fixable issues.

Documentation

The API documentation can be generated with the command yarn docs, which saves it in the ./docs directory. Open the ./docs/index.html file to browse the documentation.

Release & Publishing

The project follows the same release process as the other libraries in the MetaMask organization. The GitHub Actions action-create-release-pr and action-publish-release are used to automate the release process; see those repositories for more information about how they work.

  1. Choose a release version.

    • The release version should be chosen according to SemVer. Analyze the changes to see whether they include any breaking changes, new features, or deprecations, then choose the appropriate SemVer version. See the SemVer specification for more information.
  2. If this release is backporting changes onto a previous release, then ensure there is a major version branch for that version (e.g. 1.x for a v1 backport release).

    • The major version branch should be set to the most recent release with that major version. For example, when backporting a v1.0.2 release, you'd want to ensure there was a 1.x branch that was set to the v1.0.1 tag.
  3. Trigger the workflow_dispatch event manually for the Create Release Pull Request action to create the release PR.

    • For a backport release, the base branch should be the major version branch that you ensured existed in step 2. For a normal release, the base branch should be the main branch for that repository (which should be the default value).
    • This should trigger the action-create-release-pr workflow to create the release PR.
  4. Update the changelog to move each change entry into the appropriate change category (See here for the full list of change categories, and the correct ordering), and edit them to be more easily understood by users of the package.

    • Generally any changes that don't affect consumers of the package (e.g. lockfile changes or development environment changes) are omitted. Exceptions may be made for changes that might be of interest despite not having an effect upon the published package (e.g. major test improvements, security improvements, improved documentation, etc.).
    • Try to explain each change in terms that users of the package would understand (e.g. avoid referencing internal variables/concepts).
    • Consolidate related changes into one change entry if it makes it easier to explain.
    • Run yarn auto-changelog validate --rc to check that the changelog is correctly formatted.
  5. Review and QA the release.

    • If changes are made to the base branch, the release branch will need to be updated with these changes and review/QA will need to restart again. As such, it's probably best to avoid merging other PRs into the base branch while review is underway.
  6. Squash & Merge the release.

    • This should trigger the action-publish-release workflow to tag the final release commit and publish the release on GitHub.
  7. Publish the release on npm.

    • Wait for the publish-release GitHub Action workflow to finish. This should trigger a second job (publish-npm), which will wait for a run approval by the npm publishers team.
    • Approve the publish-npm job (or ask somebody on the npm publishers team to approve it for you).
    • Once the publish-npm job has finished, check npm to verify that it has been published.

changelog

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

Unreleased

8.1.2

Changed

  • Bump @metamask/abi-utils from ^2.0.4 to ^3.0.0 (#405)
  • Bump @metamask/utils from ^9.0.0 to ^11.0.1 (#405)

8.1.1

Fixed

  • Revert "fix: Add Permit type schema" (#401)

8.1.0

Added

  • Add Permit type to signTypedData schema (#399)

8.0.0

Changed

  • BREAKING: Values of type number are not accepted as address parameter anymore. Valid values are string and Uint8Array. (#391)
  • BREAKING: Drop support for Node.js versions 16, 21. (#390)

7.0.3

Changed

  • Bump @metamask/abi-utils to ^2.0.4 (#381)
  • Bump @metamask/utils from ^9.0.0 (#381)

7.0.2

Fixed

  • Replace dependency tweetnacl-util with @scure/base (#358)

7.0.1

Changed

  • Remove dependency ethjs-util (#349)

Fixed

  • BREAKING: fix: interpret 0x as hex in bytes encodeField (#354)
    • This fixes a regression introduced in 6.0.1 which caused inconsistent signatures when data was supplied as literal 0x.
  • fix: Exclude test files from published release (#350)
  • fix: Bump @babel/traverse from 7.21.5 to 7.23.2 (#341)

7.0.0

Changed

  • BREAKING: Increase minimum Node.js version to v16 (#332)
  • BREAKING: Bump @metamask/abi-utils from ^1.0.2 to ^2.0.2 (#326)
  • Bump @metamask/utils from ^5.0.2 to ^8.1.0 (#333)

6.0.1

Changed

  • Swap out legacy ethereumjs-abi for @metamask/abi-utils (#319)

Fixed

  • Bump ethereum-cryptography from ^2.0.0 to ^2.1.2 (#302)
  • Bump ethereumjs/util from ^8.0.6 to ^8.1.0 (#302)
  • Remove unused dependency bn.js (#334) (#302)

6.0.0

Changed

  • BREAKING: Fix normalize for empty strings and 0 (#315)
    • This is breaking as it changes the behavior of the function with an empty string or 0 as input: it will now return 0x for an empty string and 0x00 for 0, instead of undefined

5.1.0

Changed

  • rawEncode: fix broken BigNumber negativity check (#307)
  • Specify type interface for multiple functions (#307)
  • Improve type parameter input validation (#307)
  • deps: bn.js@4.11.8->4.12.0 (#309)
  • devDeps: Support TypeScript version ~4.8.4 (#307)

5.0.3

Changed

  • Bump ethereum-cryptography, @ethereumjs/util (#302)

5.0.2

Changed

  • allow bn.js to resolve any minor/patch version above 4.11.8 (#280)

5.0.1

Fixed

  • Fix issue introduced in v5.0.0 where the method encodeField encoded fields typed as bytes and passed as hexstrings were encoded differently than previous versions (#271, #274)

5.0.0 [DEPRECATED]

Changed

  • BREAKING: Removed support for Node v12 in favor of v14 (#137)
  • Replace heavy crypto packages for lighter noble implementations via upgrading ethereumjs-util to latest (now called @ethereumjs/util) (#260)
  • Migrate to Yarn 3 (#264)

4.0.1

Fixed

  • Fix mistake in TYPED_MESSAGE_SCHEMA (#243)
    • The schema changed in v4 in a way that accidentally disallowed "reference types" (i.e. custom types) apart from the primary type. Reference types are now once again allowed.

4.0.0

Added

Changed

  • BREAKING: Consolidate signTypedData and recoverTypedSignature functions (#156)
    • The functions signTypedDataLegacy, signTypedData, and signTypedData_v4 have been replaced with a single signTypedData function with a version parameter. The version parameter determines which type of signature you get.
      • If you used signTypedDataLegacy, switch to signTypedData with the version V1.
      • If you used signTypedData, switch to signTypedData with the version V3.
      • If you used signTypedData_v4, switch to signTypedData with the version V4.
    • The functions recoverTypedSignatureLegacy, recoverTypedSignature, and recoverTypedSignature_v4 have been replaced with a single recoverTypedSignature function.
      • If you used recoverTypedSignatureLegacy, switch to recoverTypedMessage with the version V1.
      • If you used recoverTypedMessage, switch to recoverTypedMessage with the version V3.
      • If you used recoverTypedSignature_v4, switch to recoverTypedMessage with the version V4.
  • BREAKING: Rename TypedDataUtils.sign to TypedDataUtils.eip712Hash (#104)
    • This function never actually signed anything. It just created a hash that was later signed. The new name better reflects what the function does.
  • BREAKING: Move package under @metamask npm organization (#162)
    • Update your require and import statements to import @metamask/eth-sig-util rather than eth-sig-util.
  • BREAKING: Simplify function type signatures (#198)
    • This is only a breaking change for TypeScript projects that were importing types used by the function signatures. The types should be far simpler now.
    • The TypedData has been updated to be more restrictive (it only allows valid typed data now), and it was renamed to TypedDataV1
  • BREAKING: Replace MsgParams parameters with "options" parameters (#204)
    • This affects the following functions:
      • personalSign
      • recoverPersonalSignature
      • extractPublicKey
      • encrypt
      • encryptSafely
      • decrypt
      • decryptSafely
      • signTypedData
      • recoverTypedSignature
    • All parameters are passed in as a single "options" object now, instead of the MsgParams type that was used for most of these functions previously. Read each function signature carefully to ensure you are correctly passing in parameters.
    • personalSign example:
      • Previously it was called like this: personalSign(privateKey, { data })
      • Now it is called like this: personalSign({ privateKey, data })
  • BREAKING: Rename Version type to SignTypedDataVersion (#218)
  • BREAKING: Rename EIP712TypedData type to TypedDataV1Field (#218)
  • Add signTypedData version validation (#201)
  • Add validation to check that parameters aren't nullish (#205)
  • Enable inline sourcemaps (#159)
  • Update ethereumjs-util to v6 (#138, #195)
  • Allow TypedDataUtils functions to be called unbound (#152)
  • Update minimum tweetnacl-util version (#155)
  • Add Solidity types to JSON schema for signTypedData (#189)
  • Replace README API docs with generated docs (#213)

3.0.1 - 2021-02-04

Changed

  • Update ethereumjs-abi (#96)
  • Remove unused dependencies (#117)
  • Update minimum tweetnacl to latest version (#123)

3.0.0 - 2020-11-09

Changed

  • [BREAKING] Migrate to TypeScript (#74)
  • Fix package metadata (#81
  • Switch from Node.js v8 to Node.js v10 (#76 and #80)

2.5.4 - 2021-02-04

Changed

  • Update ethereumjs-abi (#121)
  • Remove unused dependencies (#120)
  • Update minimum tweetnacl to latest version (#124)

2.5.3 - 2020-03-16 [WITHDRAWN]

Changed

  • [BREAKING] Migrate to TypeScript (#74)
  • Fix package metadata (#81
  • Switch from Node.js v8 to Node.js v10 (#76 and #80)