TaggedHash for BOLT 12 signing function
[rust-lightning] / lightning / src / offers / invoice_request.rs
1 // This file is Copyright its original authors, visible in version control
2 // history.
3 //
4 // This file is licensed under the Apache License, Version 2.0 <LICENSE-APACHE
5 // or http://www.apache.org/licenses/LICENSE-2.0> or the MIT license
6 // <LICENSE-MIT or http://opensource.org/licenses/MIT>, at your option.
7 // You may not use this file except in accordance with one or both of these
8 // licenses.
9
10 //! Data structures and encoding for `invoice_request` messages.
11 //!
12 //! An [`InvoiceRequest`] can be built from a parsed [`Offer`] as an "offer to be paid". It is
13 //! typically constructed by a customer and sent to the merchant who had published the corresponding
14 //! offer. The recipient of the request responds with a [`Bolt12Invoice`].
15 //!
16 //! For an "offer for money" (e.g., refund, ATM withdrawal), where an offer doesn't exist as a
17 //! precursor, see [`Refund`].
18 //!
19 //! [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
20 //! [`Refund`]: crate::offers::refund::Refund
21 //!
22 //! ```
23 //! extern crate bitcoin;
24 //! extern crate lightning;
25 //!
26 //! use bitcoin::network::constants::Network;
27 //! use bitcoin::secp256k1::{KeyPair, PublicKey, Secp256k1, SecretKey};
28 //! use core::convert::Infallible;
29 //! use lightning::ln::features::OfferFeatures;
30 //! use lightning::offers::offer::Offer;
31 //! use lightning::util::ser::Writeable;
32 //!
33 //! # fn parse() -> Result<(), lightning::offers::parse::Bolt12ParseError> {
34 //! let secp_ctx = Secp256k1::new();
35 //! let keys = KeyPair::from_secret_key(&secp_ctx, &SecretKey::from_slice(&[42; 32])?);
36 //! let pubkey = PublicKey::from(keys);
37 //! let mut buffer = Vec::new();
38 //!
39 //! "lno1qcp4256ypq"
40 //!     .parse::<Offer>()?
41 //!     .request_invoice(vec![42; 64], pubkey)?
42 //!     .chain(Network::Testnet)?
43 //!     .amount_msats(1000)?
44 //!     .quantity(5)?
45 //!     .payer_note("foo".to_string())
46 //!     .build()?
47 //!     .sign::<_, Infallible>(
48 //!         |message| Ok(secp_ctx.sign_schnorr_no_aux_rand(message.as_ref().as_digest(), &keys))
49 //!     )
50 //!     .expect("failed verifying signature")
51 //!     .write(&mut buffer)
52 //!     .unwrap();
53 //! # Ok(())
54 //! # }
55 //! ```
56
57 use bitcoin::blockdata::constants::ChainHash;
58 use bitcoin::network::constants::Network;
59 use bitcoin::secp256k1::{KeyPair, PublicKey, Secp256k1, self};
60 use bitcoin::secp256k1::schnorr::Signature;
61 use core::convert::{AsRef, Infallible, TryFrom};
62 use core::ops::Deref;
63 use crate::sign::EntropySource;
64 use crate::io;
65 use crate::blinded_path::BlindedPath;
66 use crate::ln::PaymentHash;
67 use crate::ln::features::InvoiceRequestFeatures;
68 use crate::ln::inbound_payment::{ExpandedKey, IV_LEN, Nonce};
69 use crate::ln::msgs::DecodeError;
70 use crate::offers::invoice::{BlindedPayInfo, DerivedSigningPubkey, ExplicitSigningPubkey, InvoiceBuilder};
71 use crate::offers::merkle::{SignError, SignatureTlvStream, SignatureTlvStreamRef, TaggedHash, self};
72 use crate::offers::offer::{Offer, OfferContents, OfferTlvStream, OfferTlvStreamRef};
73 use crate::offers::parse::{Bolt12ParseError, ParsedMessage, Bolt12SemanticError};
74 use crate::offers::payer::{PayerContents, PayerTlvStream, PayerTlvStreamRef};
75 use crate::offers::signer::{Metadata, MetadataMaterial};
76 use crate::util::ser::{HighZeroBytesDroppedBigSize, SeekReadable, WithoutLength, Writeable, Writer};
77 use crate::util::string::PrintableString;
78
79 use crate::prelude::*;
80
81 /// Tag for the hash function used when signing an [`InvoiceRequest`]'s merkle root.
82 pub const SIGNATURE_TAG: &'static str = concat!("lightning", "invoice_request", "signature");
83
84 pub(super) const IV_BYTES: &[u8; IV_LEN] = b"LDK Invreq ~~~~~";
85
86 /// Builds an [`InvoiceRequest`] from an [`Offer`] for the "offer to be paid" flow.
87 ///
88 /// See [module-level documentation] for usage.
89 ///
90 /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
91 ///
92 /// [module-level documentation]: self
93 pub struct InvoiceRequestBuilder<'a, 'b, P: PayerIdStrategy, T: secp256k1::Signing> {
94         offer: &'a Offer,
95         invoice_request: InvoiceRequestContentsWithoutPayerId,
96         payer_id: Option<PublicKey>,
97         payer_id_strategy: core::marker::PhantomData<P>,
98         secp_ctx: Option<&'b Secp256k1<T>>,
99 }
100
101 /// Indicates how [`InvoiceRequest::payer_id`] will be set.
102 ///
103 /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
104 pub trait PayerIdStrategy {}
105
106 /// [`InvoiceRequest::payer_id`] will be explicitly set.
107 ///
108 /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
109 pub struct ExplicitPayerId {}
110
111 /// [`InvoiceRequest::payer_id`] will be derived.
112 ///
113 /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
114 pub struct DerivedPayerId {}
115
116 impl PayerIdStrategy for ExplicitPayerId {}
117 impl PayerIdStrategy for DerivedPayerId {}
118
119 impl<'a, 'b, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, ExplicitPayerId, T> {
120         pub(super) fn new(offer: &'a Offer, metadata: Vec<u8>, payer_id: PublicKey) -> Self {
121                 Self {
122                         offer,
123                         invoice_request: Self::create_contents(offer, Metadata::Bytes(metadata)),
124                         payer_id: Some(payer_id),
125                         payer_id_strategy: core::marker::PhantomData,
126                         secp_ctx: None,
127                 }
128         }
129
130         pub(super) fn deriving_metadata<ES: Deref>(
131                 offer: &'a Offer, payer_id: PublicKey, expanded_key: &ExpandedKey, entropy_source: ES
132         ) -> Self where ES::Target: EntropySource {
133                 let nonce = Nonce::from_entropy_source(entropy_source);
134                 let derivation_material = MetadataMaterial::new(nonce, expanded_key, IV_BYTES);
135                 let metadata = Metadata::Derived(derivation_material);
136                 Self {
137                         offer,
138                         invoice_request: Self::create_contents(offer, metadata),
139                         payer_id: Some(payer_id),
140                         payer_id_strategy: core::marker::PhantomData,
141                         secp_ctx: None,
142                 }
143         }
144 }
145
146 impl<'a, 'b, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, DerivedPayerId, T> {
147         pub(super) fn deriving_payer_id<ES: Deref>(
148                 offer: &'a Offer, expanded_key: &ExpandedKey, entropy_source: ES, secp_ctx: &'b Secp256k1<T>
149         ) -> Self where ES::Target: EntropySource {
150                 let nonce = Nonce::from_entropy_source(entropy_source);
151                 let derivation_material = MetadataMaterial::new(nonce, expanded_key, IV_BYTES);
152                 let metadata = Metadata::DerivedSigningPubkey(derivation_material);
153                 Self {
154                         offer,
155                         invoice_request: Self::create_contents(offer, metadata),
156                         payer_id: None,
157                         payer_id_strategy: core::marker::PhantomData,
158                         secp_ctx: Some(secp_ctx),
159                 }
160         }
161 }
162
163 impl<'a, 'b, P: PayerIdStrategy, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, P, T> {
164         fn create_contents(offer: &Offer, metadata: Metadata) -> InvoiceRequestContentsWithoutPayerId {
165                 let offer = offer.contents.clone();
166                 InvoiceRequestContentsWithoutPayerId {
167                         payer: PayerContents(metadata), offer, chain: None, amount_msats: None,
168                         features: InvoiceRequestFeatures::empty(), quantity: None, payer_note: None,
169                 }
170         }
171
172         /// Sets the [`InvoiceRequest::chain`] of the given [`Network`] for paying an invoice. If not
173         /// called, [`Network::Bitcoin`] is assumed. Errors if the chain for `network` is not supported
174         /// by the offer.
175         ///
176         /// Successive calls to this method will override the previous setting.
177         pub fn chain(mut self, network: Network) -> Result<Self, Bolt12SemanticError> {
178                 let chain = ChainHash::using_genesis_block(network);
179                 if !self.offer.supports_chain(chain) {
180                         return Err(Bolt12SemanticError::UnsupportedChain);
181                 }
182
183                 self.invoice_request.chain = Some(chain);
184                 Ok(self)
185         }
186
187         /// Sets the [`InvoiceRequest::amount_msats`] for paying an invoice. Errors if `amount_msats` is
188         /// not at least the expected invoice amount (i.e., [`Offer::amount`] times [`quantity`]).
189         ///
190         /// Successive calls to this method will override the previous setting.
191         ///
192         /// [`quantity`]: Self::quantity
193         pub fn amount_msats(mut self, amount_msats: u64) -> Result<Self, Bolt12SemanticError> {
194                 self.invoice_request.offer.check_amount_msats_for_quantity(
195                         Some(amount_msats), self.invoice_request.quantity
196                 )?;
197                 self.invoice_request.amount_msats = Some(amount_msats);
198                 Ok(self)
199         }
200
201         /// Sets [`InvoiceRequest::quantity`] of items. If not set, `1` is assumed. Errors if `quantity`
202         /// does not conform to [`Offer::is_valid_quantity`].
203         ///
204         /// Successive calls to this method will override the previous setting.
205         pub fn quantity(mut self, quantity: u64) -> Result<Self, Bolt12SemanticError> {
206                 self.invoice_request.offer.check_quantity(Some(quantity))?;
207                 self.invoice_request.quantity = Some(quantity);
208                 Ok(self)
209         }
210
211         /// Sets the [`InvoiceRequest::payer_note`].
212         ///
213         /// Successive calls to this method will override the previous setting.
214         pub fn payer_note(mut self, payer_note: String) -> Self {
215                 self.invoice_request.payer_note = Some(payer_note);
216                 self
217         }
218
219         fn build_with_checks(mut self) -> Result<
220                 (UnsignedInvoiceRequest, Option<KeyPair>, Option<&'b Secp256k1<T>>),
221                 Bolt12SemanticError
222         > {
223                 #[cfg(feature = "std")] {
224                         if self.offer.is_expired() {
225                                 return Err(Bolt12SemanticError::AlreadyExpired);
226                         }
227                 }
228
229                 let chain = self.invoice_request.chain();
230                 if !self.offer.supports_chain(chain) {
231                         return Err(Bolt12SemanticError::UnsupportedChain);
232                 }
233
234                 if chain == self.offer.implied_chain() {
235                         self.invoice_request.chain = None;
236                 }
237
238                 if self.offer.amount().is_none() && self.invoice_request.amount_msats.is_none() {
239                         return Err(Bolt12SemanticError::MissingAmount);
240                 }
241
242                 self.invoice_request.offer.check_quantity(self.invoice_request.quantity)?;
243                 self.invoice_request.offer.check_amount_msats_for_quantity(
244                         self.invoice_request.amount_msats, self.invoice_request.quantity
245                 )?;
246
247                 Ok(self.build_without_checks())
248         }
249
250         fn build_without_checks(mut self) ->
251                 (UnsignedInvoiceRequest, Option<KeyPair>, Option<&'b Secp256k1<T>>)
252         {
253                 // Create the metadata for stateless verification of a Bolt12Invoice.
254                 let mut keys = None;
255                 let secp_ctx = self.secp_ctx.clone();
256                 if self.invoice_request.payer.0.has_derivation_material() {
257                         let mut metadata = core::mem::take(&mut self.invoice_request.payer.0);
258
259                         let mut tlv_stream = self.invoice_request.as_tlv_stream();
260                         debug_assert!(tlv_stream.2.payer_id.is_none());
261                         tlv_stream.0.metadata = None;
262                         if !metadata.derives_keys() {
263                                 tlv_stream.2.payer_id = self.payer_id.as_ref();
264                         }
265
266                         let (derived_metadata, derived_keys) = metadata.derive_from(tlv_stream, self.secp_ctx);
267                         metadata = derived_metadata;
268                         keys = derived_keys;
269                         if let Some(keys) = keys {
270                                 debug_assert!(self.payer_id.is_none());
271                                 self.payer_id = Some(keys.public_key());
272                         }
273
274                         self.invoice_request.payer.0 = metadata;
275                 }
276
277                 debug_assert!(self.invoice_request.payer.0.as_bytes().is_some());
278                 debug_assert!(self.payer_id.is_some());
279                 let payer_id = self.payer_id.unwrap();
280
281                 let invoice_request = InvoiceRequestContents {
282                         inner: self.invoice_request,
283                         payer_id,
284                 };
285                 let unsigned_invoice_request = UnsignedInvoiceRequest::new(self.offer, invoice_request);
286
287                 (unsigned_invoice_request, keys, secp_ctx)
288         }
289 }
290
291 impl<'a, 'b, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, ExplicitPayerId, T> {
292         /// Builds an unsigned [`InvoiceRequest`] after checking for valid semantics. It can be signed
293         /// by [`UnsignedInvoiceRequest::sign`].
294         pub fn build(self) -> Result<UnsignedInvoiceRequest, Bolt12SemanticError> {
295                 let (unsigned_invoice_request, keys, _) = self.build_with_checks()?;
296                 debug_assert!(keys.is_none());
297                 Ok(unsigned_invoice_request)
298         }
299 }
300
301 impl<'a, 'b, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, DerivedPayerId, T> {
302         /// Builds a signed [`InvoiceRequest`] after checking for valid semantics.
303         pub fn build_and_sign(self) -> Result<InvoiceRequest, Bolt12SemanticError> {
304                 let (unsigned_invoice_request, keys, secp_ctx) = self.build_with_checks()?;
305                 debug_assert!(keys.is_some());
306
307                 let secp_ctx = secp_ctx.unwrap();
308                 let keys = keys.unwrap();
309                 let invoice_request = unsigned_invoice_request
310                         .sign::<_, Infallible>(
311                                 |message| Ok(secp_ctx.sign_schnorr_no_aux_rand(message.as_ref().as_digest(), &keys))
312                         )
313                         .unwrap();
314                 Ok(invoice_request)
315         }
316 }
317
318 #[cfg(test)]
319 impl<'a, 'b, P: PayerIdStrategy, T: secp256k1::Signing> InvoiceRequestBuilder<'a, 'b, P, T> {
320         fn chain_unchecked(mut self, network: Network) -> Self {
321                 let chain = ChainHash::using_genesis_block(network);
322                 self.invoice_request.chain = Some(chain);
323                 self
324         }
325
326         fn amount_msats_unchecked(mut self, amount_msats: u64) -> Self {
327                 self.invoice_request.amount_msats = Some(amount_msats);
328                 self
329         }
330
331         fn features_unchecked(mut self, features: InvoiceRequestFeatures) -> Self {
332                 self.invoice_request.features = features;
333                 self
334         }
335
336         fn quantity_unchecked(mut self, quantity: u64) -> Self {
337                 self.invoice_request.quantity = Some(quantity);
338                 self
339         }
340
341         pub(super) fn build_unchecked(self) -> UnsignedInvoiceRequest {
342                 self.build_without_checks().0
343         }
344 }
345
346 /// A semantically valid [`InvoiceRequest`] that hasn't been signed.
347 pub struct UnsignedInvoiceRequest {
348         bytes: Vec<u8>,
349         invoice_request: InvoiceRequestContents,
350         tagged_hash: TaggedHash,
351 }
352
353 impl UnsignedInvoiceRequest {
354         fn new(offer: &Offer, invoice_request: InvoiceRequestContents) -> Self {
355                 // Use the offer bytes instead of the offer TLV stream as the offer may have contained
356                 // unknown TLV records, which are not stored in `OfferContents`.
357                 let (payer_tlv_stream, _offer_tlv_stream, invoice_request_tlv_stream) =
358                         invoice_request.as_tlv_stream();
359                 let offer_bytes = WithoutLength(&offer.bytes);
360                 let unsigned_tlv_stream = (payer_tlv_stream, offer_bytes, invoice_request_tlv_stream);
361
362                 let mut bytes = Vec::new();
363                 unsigned_tlv_stream.write(&mut bytes).unwrap();
364
365                 let tagged_hash = TaggedHash::new(SIGNATURE_TAG, &bytes);
366
367                 Self { bytes, invoice_request, tagged_hash }
368         }
369
370         /// Signs the invoice request using the given function.
371         ///
372         /// This is not exported to bindings users as functions are not yet mapped.
373         pub fn sign<F, E>(mut self, sign: F) -> Result<InvoiceRequest, SignError<E>>
374         where
375                 F: FnOnce(&Self) -> Result<Signature, E>
376         {
377                 let pubkey = self.invoice_request.payer_id;
378                 let signature = merkle::sign_message(sign, &self, pubkey)?;
379
380                 // Append the signature TLV record to the bytes.
381                 let signature_tlv_stream = SignatureTlvStreamRef {
382                         signature: Some(&signature),
383                 };
384                 signature_tlv_stream.write(&mut self.bytes).unwrap();
385
386                 Ok(InvoiceRequest {
387                         bytes: self.bytes,
388                         contents: self.invoice_request,
389                         signature,
390                 })
391         }
392 }
393
394 impl AsRef<TaggedHash> for UnsignedInvoiceRequest {
395         fn as_ref(&self) -> &TaggedHash {
396                 &self.tagged_hash
397         }
398 }
399
400 /// An `InvoiceRequest` is a request for a [`Bolt12Invoice`] formulated from an [`Offer`].
401 ///
402 /// An offer may provide choices such as quantity, amount, chain, features, etc. An invoice request
403 /// specifies these such that its recipient can send an invoice for payment.
404 ///
405 /// [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
406 /// [`Offer`]: crate::offers::offer::Offer
407 #[derive(Clone, Debug)]
408 #[cfg_attr(test, derive(PartialEq))]
409 pub struct InvoiceRequest {
410         pub(super) bytes: Vec<u8>,
411         pub(super) contents: InvoiceRequestContents,
412         signature: Signature,
413 }
414
415 /// The contents of an [`InvoiceRequest`], which may be shared with an [`Bolt12Invoice`].
416 ///
417 /// [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
418 #[derive(Clone, Debug)]
419 #[cfg_attr(test, derive(PartialEq))]
420 pub(super) struct InvoiceRequestContents {
421         pub(super) inner: InvoiceRequestContentsWithoutPayerId,
422         payer_id: PublicKey,
423 }
424
425 #[derive(Clone, Debug)]
426 #[cfg_attr(test, derive(PartialEq))]
427 pub(super) struct InvoiceRequestContentsWithoutPayerId {
428         payer: PayerContents,
429         pub(super) offer: OfferContents,
430         chain: Option<ChainHash>,
431         amount_msats: Option<u64>,
432         features: InvoiceRequestFeatures,
433         quantity: Option<u64>,
434         payer_note: Option<String>,
435 }
436
437 impl InvoiceRequest {
438         /// An unpredictable series of bytes, typically containing information about the derivation of
439         /// [`payer_id`].
440         ///
441         /// [`payer_id`]: Self::payer_id
442         pub fn metadata(&self) -> &[u8] {
443                 self.contents.metadata()
444         }
445
446         /// A chain from [`Offer::chains`] that the offer is valid for.
447         pub fn chain(&self) -> ChainHash {
448                 self.contents.chain()
449         }
450
451         /// The amount to pay in msats (i.e., the minimum lightning-payable unit for [`chain`]), which
452         /// must be greater than or equal to [`Offer::amount`], converted if necessary.
453         ///
454         /// [`chain`]: Self::chain
455         pub fn amount_msats(&self) -> Option<u64> {
456                 self.contents.inner.amount_msats
457         }
458
459         /// Features pertaining to requesting an invoice.
460         pub fn features(&self) -> &InvoiceRequestFeatures {
461                 &self.contents.inner.features
462         }
463
464         /// The quantity of the offer's item conforming to [`Offer::is_valid_quantity`].
465         pub fn quantity(&self) -> Option<u64> {
466                 self.contents.inner.quantity
467         }
468
469         /// A possibly transient pubkey used to sign the invoice request.
470         pub fn payer_id(&self) -> PublicKey {
471                 self.contents.payer_id
472         }
473
474         /// A payer-provided note which will be seen by the recipient and reflected back in the invoice
475         /// response.
476         pub fn payer_note(&self) -> Option<PrintableString> {
477                 self.contents.inner.payer_note.as_ref()
478                         .map(|payer_note| PrintableString(payer_note.as_str()))
479         }
480
481         /// Signature of the invoice request using [`payer_id`].
482         ///
483         /// [`payer_id`]: Self::payer_id
484         pub fn signature(&self) -> Signature {
485                 self.signature
486         }
487
488         /// Creates an [`InvoiceBuilder`] for the request with the given required fields and using the
489         /// [`Duration`] since [`std::time::SystemTime::UNIX_EPOCH`] as the creation time.
490         ///
491         /// See [`InvoiceRequest::respond_with_no_std`] for further details where the aforementioned
492         /// creation time is used for the `created_at` parameter.
493         ///
494         /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
495         ///
496         /// [`Duration`]: core::time::Duration
497         #[cfg(feature = "std")]
498         pub fn respond_with(
499                 &self, payment_paths: Vec<(BlindedPayInfo, BlindedPath)>, payment_hash: PaymentHash
500         ) -> Result<InvoiceBuilder<ExplicitSigningPubkey>, Bolt12SemanticError> {
501                 let created_at = std::time::SystemTime::now()
502                         .duration_since(std::time::SystemTime::UNIX_EPOCH)
503                         .expect("SystemTime::now() should come after SystemTime::UNIX_EPOCH");
504
505                 self.respond_with_no_std(payment_paths, payment_hash, created_at)
506         }
507
508         /// Creates an [`InvoiceBuilder`] for the request with the given required fields.
509         ///
510         /// Unless [`InvoiceBuilder::relative_expiry`] is set, the invoice will expire two hours after
511         /// `created_at`, which is used to set [`Bolt12Invoice::created_at`]. Useful for `no-std` builds
512         /// where [`std::time::SystemTime`] is not available.
513         ///
514         /// The caller is expected to remember the preimage of `payment_hash` in order to claim a payment
515         /// for the invoice.
516         ///
517         /// The `payment_paths` parameter is useful for maintaining the payment recipient's privacy. It
518         /// must contain one or more elements ordered from most-preferred to least-preferred, if there's
519         /// a preference. Note, however, that any privacy is lost if a public node id was used for
520         /// [`Offer::signing_pubkey`].
521         ///
522         /// Errors if the request contains unknown required features.
523         ///
524         /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
525         ///
526         /// [`Bolt12Invoice::created_at`]: crate::offers::invoice::Bolt12Invoice::created_at
527         pub fn respond_with_no_std(
528                 &self, payment_paths: Vec<(BlindedPayInfo, BlindedPath)>, payment_hash: PaymentHash,
529                 created_at: core::time::Duration
530         ) -> Result<InvoiceBuilder<ExplicitSigningPubkey>, Bolt12SemanticError> {
531                 if self.features().requires_unknown_bits() {
532                         return Err(Bolt12SemanticError::UnknownRequiredFeatures);
533                 }
534
535                 InvoiceBuilder::for_offer(self, payment_paths, created_at, payment_hash)
536         }
537
538         /// Creates an [`InvoiceBuilder`] for the request using the given required fields and that uses
539         /// derived signing keys from the originating [`Offer`] to sign the [`Bolt12Invoice`]. Must use
540         /// the same [`ExpandedKey`] as the one used to create the offer.
541         ///
542         /// See [`InvoiceRequest::respond_with`] for further details.
543         ///
544         /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
545         ///
546         /// [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
547         #[cfg(feature = "std")]
548         pub fn verify_and_respond_using_derived_keys<T: secp256k1::Signing>(
549                 &self, payment_paths: Vec<(BlindedPayInfo, BlindedPath)>, payment_hash: PaymentHash,
550                 expanded_key: &ExpandedKey, secp_ctx: &Secp256k1<T>
551         ) -> Result<InvoiceBuilder<DerivedSigningPubkey>, Bolt12SemanticError> {
552                 let created_at = std::time::SystemTime::now()
553                         .duration_since(std::time::SystemTime::UNIX_EPOCH)
554                         .expect("SystemTime::now() should come after SystemTime::UNIX_EPOCH");
555
556                 self.verify_and_respond_using_derived_keys_no_std(
557                         payment_paths, payment_hash, created_at, expanded_key, secp_ctx
558                 )
559         }
560
561         /// Creates an [`InvoiceBuilder`] for the request using the given required fields and that uses
562         /// derived signing keys from the originating [`Offer`] to sign the [`Bolt12Invoice`]. Must use
563         /// the same [`ExpandedKey`] as the one used to create the offer.
564         ///
565         /// See [`InvoiceRequest::respond_with_no_std`] for further details.
566         ///
567         /// This is not exported to bindings users as builder patterns don't map outside of move semantics.
568         ///
569         /// [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
570         pub fn verify_and_respond_using_derived_keys_no_std<T: secp256k1::Signing>(
571                 &self, payment_paths: Vec<(BlindedPayInfo, BlindedPath)>, payment_hash: PaymentHash,
572                 created_at: core::time::Duration, expanded_key: &ExpandedKey, secp_ctx: &Secp256k1<T>
573         ) -> Result<InvoiceBuilder<DerivedSigningPubkey>, Bolt12SemanticError> {
574                 if self.features().requires_unknown_bits() {
575                         return Err(Bolt12SemanticError::UnknownRequiredFeatures);
576                 }
577
578                 let keys = match self.verify(expanded_key, secp_ctx) {
579                         Err(()) => return Err(Bolt12SemanticError::InvalidMetadata),
580                         Ok(None) => return Err(Bolt12SemanticError::InvalidMetadata),
581                         Ok(Some(keys)) => keys,
582                 };
583
584                 InvoiceBuilder::for_offer_using_keys(self, payment_paths, created_at, payment_hash, keys)
585         }
586
587         /// Verifies that the request was for an offer created using the given key. Returns the derived
588         /// keys need to sign an [`Bolt12Invoice`] for the request if they could be extracted from the
589         /// metadata.
590         ///
591         /// [`Bolt12Invoice`]: crate::offers::invoice::Bolt12Invoice
592         pub fn verify<T: secp256k1::Signing>(
593                 &self, key: &ExpandedKey, secp_ctx: &Secp256k1<T>
594         ) -> Result<Option<KeyPair>, ()> {
595                 self.contents.inner.offer.verify(&self.bytes, key, secp_ctx)
596         }
597
598         #[cfg(test)]
599         fn as_tlv_stream(&self) -> FullInvoiceRequestTlvStreamRef {
600                 let (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream) =
601                         self.contents.as_tlv_stream();
602                 let signature_tlv_stream = SignatureTlvStreamRef {
603                         signature: Some(&self.signature),
604                 };
605                 (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, signature_tlv_stream)
606         }
607 }
608
609 impl InvoiceRequestContents {
610         pub(super) fn metadata(&self) -> &[u8] {
611                 self.inner.metadata()
612         }
613
614         pub(super) fn derives_keys(&self) -> bool {
615                 self.inner.payer.0.derives_keys()
616         }
617
618         pub(super) fn chain(&self) -> ChainHash {
619                 self.inner.chain()
620         }
621
622         pub(super) fn payer_id(&self) -> PublicKey {
623                 self.payer_id
624         }
625
626         pub(super) fn as_tlv_stream(&self) -> PartialInvoiceRequestTlvStreamRef {
627                 let (payer, offer, mut invoice_request) = self.inner.as_tlv_stream();
628                 invoice_request.payer_id = Some(&self.payer_id);
629                 (payer, offer, invoice_request)
630         }
631 }
632
633 impl InvoiceRequestContentsWithoutPayerId {
634         pub(super) fn metadata(&self) -> &[u8] {
635                 self.payer.0.as_bytes().map(|bytes| bytes.as_slice()).unwrap_or(&[])
636         }
637
638         pub(super) fn chain(&self) -> ChainHash {
639                 self.chain.unwrap_or_else(|| self.offer.implied_chain())
640         }
641
642         pub(super) fn as_tlv_stream(&self) -> PartialInvoiceRequestTlvStreamRef {
643                 let payer = PayerTlvStreamRef {
644                         metadata: self.payer.0.as_bytes(),
645                 };
646
647                 let offer = self.offer.as_tlv_stream();
648
649                 let features = {
650                         if self.features == InvoiceRequestFeatures::empty() { None }
651                         else { Some(&self.features) }
652                 };
653
654                 let invoice_request = InvoiceRequestTlvStreamRef {
655                         chain: self.chain.as_ref(),
656                         amount: self.amount_msats,
657                         features,
658                         quantity: self.quantity,
659                         payer_id: None,
660                         payer_note: self.payer_note.as_ref(),
661                 };
662
663                 (payer, offer, invoice_request)
664         }
665 }
666
667 impl Writeable for InvoiceRequest {
668         fn write<W: Writer>(&self, writer: &mut W) -> Result<(), io::Error> {
669                 WithoutLength(&self.bytes).write(writer)
670         }
671 }
672
673 impl Writeable for InvoiceRequestContents {
674         fn write<W: Writer>(&self, writer: &mut W) -> Result<(), io::Error> {
675                 self.as_tlv_stream().write(writer)
676         }
677 }
678
679 /// Valid type range for invoice_request TLV records.
680 pub(super) const INVOICE_REQUEST_TYPES: core::ops::Range<u64> = 80..160;
681
682 /// TLV record type for [`InvoiceRequest::payer_id`] and [`Refund::payer_id`].
683 ///
684 /// [`Refund::payer_id`]: crate::offers::refund::Refund::payer_id
685 pub(super) const INVOICE_REQUEST_PAYER_ID_TYPE: u64 = 88;
686
687 tlv_stream!(InvoiceRequestTlvStream, InvoiceRequestTlvStreamRef, INVOICE_REQUEST_TYPES, {
688         (80, chain: ChainHash),
689         (82, amount: (u64, HighZeroBytesDroppedBigSize)),
690         (84, features: (InvoiceRequestFeatures, WithoutLength)),
691         (86, quantity: (u64, HighZeroBytesDroppedBigSize)),
692         (INVOICE_REQUEST_PAYER_ID_TYPE, payer_id: PublicKey),
693         (89, payer_note: (String, WithoutLength)),
694 });
695
696 type FullInvoiceRequestTlvStream =
697         (PayerTlvStream, OfferTlvStream, InvoiceRequestTlvStream, SignatureTlvStream);
698
699 #[cfg(test)]
700 type FullInvoiceRequestTlvStreamRef<'a> = (
701         PayerTlvStreamRef<'a>,
702         OfferTlvStreamRef<'a>,
703         InvoiceRequestTlvStreamRef<'a>,
704         SignatureTlvStreamRef<'a>,
705 );
706
707 impl SeekReadable for FullInvoiceRequestTlvStream {
708         fn read<R: io::Read + io::Seek>(r: &mut R) -> Result<Self, DecodeError> {
709                 let payer = SeekReadable::read(r)?;
710                 let offer = SeekReadable::read(r)?;
711                 let invoice_request = SeekReadable::read(r)?;
712                 let signature = SeekReadable::read(r)?;
713
714                 Ok((payer, offer, invoice_request, signature))
715         }
716 }
717
718 type PartialInvoiceRequestTlvStream = (PayerTlvStream, OfferTlvStream, InvoiceRequestTlvStream);
719
720 type PartialInvoiceRequestTlvStreamRef<'a> = (
721         PayerTlvStreamRef<'a>,
722         OfferTlvStreamRef<'a>,
723         InvoiceRequestTlvStreamRef<'a>,
724 );
725
726 impl TryFrom<Vec<u8>> for InvoiceRequest {
727         type Error = Bolt12ParseError;
728
729         fn try_from(bytes: Vec<u8>) -> Result<Self, Self::Error> {
730                 let invoice_request = ParsedMessage::<FullInvoiceRequestTlvStream>::try_from(bytes)?;
731                 let ParsedMessage { bytes, tlv_stream } = invoice_request;
732                 let (
733                         payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream,
734                         SignatureTlvStream { signature },
735                 ) = tlv_stream;
736                 let contents = InvoiceRequestContents::try_from(
737                         (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream)
738                 )?;
739
740                 let signature = match signature {
741                         None => return Err(Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingSignature)),
742                         Some(signature) => signature,
743                 };
744                 merkle::verify_signature(&signature, SIGNATURE_TAG, &bytes, contents.payer_id)?;
745
746                 Ok(InvoiceRequest { bytes, contents, signature })
747         }
748 }
749
750 impl TryFrom<PartialInvoiceRequestTlvStream> for InvoiceRequestContents {
751         type Error = Bolt12SemanticError;
752
753         fn try_from(tlv_stream: PartialInvoiceRequestTlvStream) -> Result<Self, Self::Error> {
754                 let (
755                         PayerTlvStream { metadata },
756                         offer_tlv_stream,
757                         InvoiceRequestTlvStream { chain, amount, features, quantity, payer_id, payer_note },
758                 ) = tlv_stream;
759
760                 let payer = match metadata {
761                         None => return Err(Bolt12SemanticError::MissingPayerMetadata),
762                         Some(metadata) => PayerContents(Metadata::Bytes(metadata)),
763                 };
764                 let offer = OfferContents::try_from(offer_tlv_stream)?;
765
766                 if !offer.supports_chain(chain.unwrap_or_else(|| offer.implied_chain())) {
767                         return Err(Bolt12SemanticError::UnsupportedChain);
768                 }
769
770                 if offer.amount().is_none() && amount.is_none() {
771                         return Err(Bolt12SemanticError::MissingAmount);
772                 }
773
774                 offer.check_quantity(quantity)?;
775                 offer.check_amount_msats_for_quantity(amount, quantity)?;
776
777                 let features = features.unwrap_or_else(InvoiceRequestFeatures::empty);
778
779                 let payer_id = match payer_id {
780                         None => return Err(Bolt12SemanticError::MissingPayerId),
781                         Some(payer_id) => payer_id,
782                 };
783
784                 Ok(InvoiceRequestContents {
785                         inner: InvoiceRequestContentsWithoutPayerId {
786                                 payer, offer, chain, amount_msats: amount, features, quantity, payer_note,
787                         },
788                         payer_id,
789                 })
790         }
791 }
792
793 #[cfg(test)]
794 mod tests {
795         use super::{InvoiceRequest, InvoiceRequestTlvStreamRef, SIGNATURE_TAG};
796
797         use bitcoin::blockdata::constants::ChainHash;
798         use bitcoin::network::constants::Network;
799         use bitcoin::secp256k1::{KeyPair, Secp256k1, SecretKey, self};
800         use core::convert::{Infallible, TryFrom};
801         use core::num::NonZeroU64;
802         #[cfg(feature = "std")]
803         use core::time::Duration;
804         use crate::sign::KeyMaterial;
805         use crate::ln::features::InvoiceRequestFeatures;
806         use crate::ln::inbound_payment::ExpandedKey;
807         use crate::ln::msgs::{DecodeError, MAX_VALUE_MSAT};
808         use crate::offers::invoice::{Bolt12Invoice, SIGNATURE_TAG as INVOICE_SIGNATURE_TAG};
809         use crate::offers::merkle::{SignError, SignatureTlvStreamRef, TaggedHash, self};
810         use crate::offers::offer::{Amount, OfferBuilder, OfferTlvStreamRef, Quantity};
811         use crate::offers::parse::{Bolt12ParseError, Bolt12SemanticError};
812         use crate::offers::payer::PayerTlvStreamRef;
813         use crate::offers::test_utils::*;
814         use crate::util::ser::{BigSize, Writeable};
815         use crate::util::string::PrintableString;
816
817         #[test]
818         fn builds_invoice_request_with_defaults() {
819                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
820                         .amount_msats(1000)
821                         .build().unwrap()
822                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
823                         .build().unwrap()
824                         .sign(payer_sign).unwrap();
825
826                 let mut buffer = Vec::new();
827                 invoice_request.write(&mut buffer).unwrap();
828
829                 assert_eq!(invoice_request.bytes, buffer.as_slice());
830                 assert_eq!(invoice_request.metadata(), &[1; 32]);
831                 assert_eq!(invoice_request.chain(), ChainHash::using_genesis_block(Network::Bitcoin));
832                 assert_eq!(invoice_request.amount_msats(), None);
833                 assert_eq!(invoice_request.features(), &InvoiceRequestFeatures::empty());
834                 assert_eq!(invoice_request.quantity(), None);
835                 assert_eq!(invoice_request.payer_id(), payer_pubkey());
836                 assert_eq!(invoice_request.payer_note(), None);
837                 assert!(
838                         merkle::verify_signature(
839                                 &invoice_request.signature, SIGNATURE_TAG, &invoice_request.bytes, payer_pubkey()
840                         ).is_ok()
841                 );
842
843                 assert_eq!(
844                         invoice_request.as_tlv_stream(),
845                         (
846                                 PayerTlvStreamRef { metadata: Some(&vec![1; 32]) },
847                                 OfferTlvStreamRef {
848                                         chains: None,
849                                         metadata: None,
850                                         currency: None,
851                                         amount: Some(1000),
852                                         description: Some(&String::from("foo")),
853                                         features: None,
854                                         absolute_expiry: None,
855                                         paths: None,
856                                         issuer: None,
857                                         quantity_max: None,
858                                         node_id: Some(&recipient_pubkey()),
859                                 },
860                                 InvoiceRequestTlvStreamRef {
861                                         chain: None,
862                                         amount: None,
863                                         features: None,
864                                         quantity: None,
865                                         payer_id: Some(&payer_pubkey()),
866                                         payer_note: None,
867                                 },
868                                 SignatureTlvStreamRef { signature: Some(&invoice_request.signature()) },
869                         ),
870                 );
871
872                 if let Err(e) = InvoiceRequest::try_from(buffer) {
873                         panic!("error parsing invoice request: {:?}", e);
874                 }
875         }
876
877         #[cfg(feature = "std")]
878         #[test]
879         fn builds_invoice_request_from_offer_with_expiration() {
880                 let future_expiry = Duration::from_secs(u64::max_value());
881                 let past_expiry = Duration::from_secs(0);
882
883                 if let Err(e) = OfferBuilder::new("foo".into(), recipient_pubkey())
884                         .amount_msats(1000)
885                         .absolute_expiry(future_expiry)
886                         .build().unwrap()
887                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
888                         .build()
889                 {
890                         panic!("error building invoice_request: {:?}", e);
891                 }
892
893                 match OfferBuilder::new("foo".into(), recipient_pubkey())
894                         .amount_msats(1000)
895                         .absolute_expiry(past_expiry)
896                         .build().unwrap()
897                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
898                         .build()
899                 {
900                         Ok(_) => panic!("expected error"),
901                         Err(e) => assert_eq!(e, Bolt12SemanticError::AlreadyExpired),
902                 }
903         }
904
905         #[test]
906         fn builds_invoice_request_with_derived_metadata() {
907                 let payer_id = payer_pubkey();
908                 let expanded_key = ExpandedKey::new(&KeyMaterial([42; 32]));
909                 let entropy = FixedEntropy {};
910                 let secp_ctx = Secp256k1::new();
911
912                 let offer = OfferBuilder::new("foo".into(), recipient_pubkey())
913                         .amount_msats(1000)
914                         .build().unwrap();
915                 let invoice_request = offer
916                         .request_invoice_deriving_metadata(payer_id, &expanded_key, &entropy)
917                         .unwrap()
918                         .build().unwrap()
919                         .sign(payer_sign).unwrap();
920                 assert_eq!(invoice_request.payer_id(), payer_pubkey());
921
922                 let invoice = invoice_request.respond_with_no_std(payment_paths(), payment_hash(), now())
923                         .unwrap()
924                         .build().unwrap()
925                         .sign(recipient_sign).unwrap();
926                 assert!(invoice.verify(&expanded_key, &secp_ctx));
927
928                 // Fails verification with altered fields
929                 let (
930                         payer_tlv_stream, offer_tlv_stream, mut invoice_request_tlv_stream,
931                         mut invoice_tlv_stream, mut signature_tlv_stream
932                 ) = invoice.as_tlv_stream();
933                 invoice_request_tlv_stream.amount = Some(2000);
934                 invoice_tlv_stream.amount = Some(2000);
935
936                 let tlv_stream =
937                         (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, invoice_tlv_stream);
938                 let mut bytes = Vec::new();
939                 tlv_stream.write(&mut bytes).unwrap();
940
941                 let message = TaggedHash::new(INVOICE_SIGNATURE_TAG, &bytes);
942                 let signature = merkle::sign_message(recipient_sign, &message, recipient_pubkey()).unwrap();
943                 signature_tlv_stream.signature = Some(&signature);
944
945                 let mut encoded_invoice = bytes;
946                 signature_tlv_stream.write(&mut encoded_invoice).unwrap();
947
948                 let invoice = Bolt12Invoice::try_from(encoded_invoice).unwrap();
949                 assert!(!invoice.verify(&expanded_key, &secp_ctx));
950
951                 // Fails verification with altered metadata
952                 let (
953                         mut payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, invoice_tlv_stream,
954                         mut signature_tlv_stream
955                 ) = invoice.as_tlv_stream();
956                 let metadata = payer_tlv_stream.metadata.unwrap().iter().copied().rev().collect();
957                 payer_tlv_stream.metadata = Some(&metadata);
958
959                 let tlv_stream =
960                         (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, invoice_tlv_stream);
961                 let mut bytes = Vec::new();
962                 tlv_stream.write(&mut bytes).unwrap();
963
964                 let message = TaggedHash::new(INVOICE_SIGNATURE_TAG, &bytes);
965                 let signature = merkle::sign_message(recipient_sign, &message, recipient_pubkey()).unwrap();
966                 signature_tlv_stream.signature = Some(&signature);
967
968                 let mut encoded_invoice = bytes;
969                 signature_tlv_stream.write(&mut encoded_invoice).unwrap();
970
971                 let invoice = Bolt12Invoice::try_from(encoded_invoice).unwrap();
972                 assert!(!invoice.verify(&expanded_key, &secp_ctx));
973         }
974
975         #[test]
976         fn builds_invoice_request_with_derived_payer_id() {
977                 let expanded_key = ExpandedKey::new(&KeyMaterial([42; 32]));
978                 let entropy = FixedEntropy {};
979                 let secp_ctx = Secp256k1::new();
980
981                 let offer = OfferBuilder::new("foo".into(), recipient_pubkey())
982                         .amount_msats(1000)
983                         .build().unwrap();
984                 let invoice_request = offer
985                         .request_invoice_deriving_payer_id(&expanded_key, &entropy, &secp_ctx)
986                         .unwrap()
987                         .build_and_sign()
988                         .unwrap();
989
990                 let invoice = invoice_request.respond_with_no_std(payment_paths(), payment_hash(), now())
991                         .unwrap()
992                         .build().unwrap()
993                         .sign(recipient_sign).unwrap();
994                 assert!(invoice.verify(&expanded_key, &secp_ctx));
995
996                 // Fails verification with altered fields
997                 let (
998                         payer_tlv_stream, offer_tlv_stream, mut invoice_request_tlv_stream,
999                         mut invoice_tlv_stream, mut signature_tlv_stream
1000                 ) = invoice.as_tlv_stream();
1001                 invoice_request_tlv_stream.amount = Some(2000);
1002                 invoice_tlv_stream.amount = Some(2000);
1003
1004                 let tlv_stream =
1005                         (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, invoice_tlv_stream);
1006                 let mut bytes = Vec::new();
1007                 tlv_stream.write(&mut bytes).unwrap();
1008
1009                 let message = TaggedHash::new(INVOICE_SIGNATURE_TAG, &bytes);
1010                 let signature = merkle::sign_message(recipient_sign, &message, recipient_pubkey()).unwrap();
1011                 signature_tlv_stream.signature = Some(&signature);
1012
1013                 let mut encoded_invoice = bytes;
1014                 signature_tlv_stream.write(&mut encoded_invoice).unwrap();
1015
1016                 let invoice = Bolt12Invoice::try_from(encoded_invoice).unwrap();
1017                 assert!(!invoice.verify(&expanded_key, &secp_ctx));
1018
1019                 // Fails verification with altered payer id
1020                 let (
1021                         payer_tlv_stream, offer_tlv_stream, mut invoice_request_tlv_stream, invoice_tlv_stream,
1022                         mut signature_tlv_stream
1023                 ) = invoice.as_tlv_stream();
1024                 let payer_id = pubkey(1);
1025                 invoice_request_tlv_stream.payer_id = Some(&payer_id);
1026
1027                 let tlv_stream =
1028                         (payer_tlv_stream, offer_tlv_stream, invoice_request_tlv_stream, invoice_tlv_stream);
1029                 let mut bytes = Vec::new();
1030                 tlv_stream.write(&mut bytes).unwrap();
1031
1032                 let message = TaggedHash::new(INVOICE_SIGNATURE_TAG, &bytes);
1033                 let signature = merkle::sign_message(recipient_sign, &message, recipient_pubkey()).unwrap();
1034                 signature_tlv_stream.signature = Some(&signature);
1035
1036                 let mut encoded_invoice = bytes;
1037                 signature_tlv_stream.write(&mut encoded_invoice).unwrap();
1038
1039                 let invoice = Bolt12Invoice::try_from(encoded_invoice).unwrap();
1040                 assert!(!invoice.verify(&expanded_key, &secp_ctx));
1041         }
1042
1043         #[test]
1044         fn builds_invoice_request_with_chain() {
1045                 let mainnet = ChainHash::using_genesis_block(Network::Bitcoin);
1046                 let testnet = ChainHash::using_genesis_block(Network::Testnet);
1047
1048                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1049                         .amount_msats(1000)
1050                         .build().unwrap()
1051                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1052                         .chain(Network::Bitcoin).unwrap()
1053                         .build().unwrap()
1054                         .sign(payer_sign).unwrap();
1055                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1056                 assert_eq!(invoice_request.chain(), mainnet);
1057                 assert_eq!(tlv_stream.chain, None);
1058
1059                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1060                         .amount_msats(1000)
1061                         .chain(Network::Testnet)
1062                         .build().unwrap()
1063                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1064                         .chain(Network::Testnet).unwrap()
1065                         .build().unwrap()
1066                         .sign(payer_sign).unwrap();
1067                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1068                 assert_eq!(invoice_request.chain(), testnet);
1069                 assert_eq!(tlv_stream.chain, Some(&testnet));
1070
1071                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1072                         .amount_msats(1000)
1073                         .chain(Network::Bitcoin)
1074                         .chain(Network::Testnet)
1075                         .build().unwrap()
1076                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1077                         .chain(Network::Bitcoin).unwrap()
1078                         .build().unwrap()
1079                         .sign(payer_sign).unwrap();
1080                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1081                 assert_eq!(invoice_request.chain(), mainnet);
1082                 assert_eq!(tlv_stream.chain, None);
1083
1084                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1085                         .amount_msats(1000)
1086                         .chain(Network::Bitcoin)
1087                         .chain(Network::Testnet)
1088                         .build().unwrap()
1089                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1090                         .chain(Network::Bitcoin).unwrap()
1091                         .chain(Network::Testnet).unwrap()
1092                         .build().unwrap()
1093                         .sign(payer_sign).unwrap();
1094                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1095                 assert_eq!(invoice_request.chain(), testnet);
1096                 assert_eq!(tlv_stream.chain, Some(&testnet));
1097
1098                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1099                         .amount_msats(1000)
1100                         .chain(Network::Testnet)
1101                         .build().unwrap()
1102                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1103                         .chain(Network::Bitcoin)
1104                 {
1105                         Ok(_) => panic!("expected error"),
1106                         Err(e) => assert_eq!(e, Bolt12SemanticError::UnsupportedChain),
1107                 }
1108
1109                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1110                         .amount_msats(1000)
1111                         .chain(Network::Testnet)
1112                         .build().unwrap()
1113                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1114                         .build()
1115                 {
1116                         Ok(_) => panic!("expected error"),
1117                         Err(e) => assert_eq!(e, Bolt12SemanticError::UnsupportedChain),
1118                 }
1119         }
1120
1121         #[test]
1122         fn builds_invoice_request_with_amount() {
1123                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1124                         .amount_msats(1000)
1125                         .build().unwrap()
1126                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1127                         .amount_msats(1000).unwrap()
1128                         .build().unwrap()
1129                         .sign(payer_sign).unwrap();
1130                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1131                 assert_eq!(invoice_request.amount_msats(), Some(1000));
1132                 assert_eq!(tlv_stream.amount, Some(1000));
1133
1134                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1135                         .amount_msats(1000)
1136                         .build().unwrap()
1137                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1138                         .amount_msats(1001).unwrap()
1139                         .amount_msats(1000).unwrap()
1140                         .build().unwrap()
1141                         .sign(payer_sign).unwrap();
1142                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1143                 assert_eq!(invoice_request.amount_msats(), Some(1000));
1144                 assert_eq!(tlv_stream.amount, Some(1000));
1145
1146                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1147                         .amount_msats(1000)
1148                         .build().unwrap()
1149                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1150                         .amount_msats(1001).unwrap()
1151                         .build().unwrap()
1152                         .sign(payer_sign).unwrap();
1153                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1154                 assert_eq!(invoice_request.amount_msats(), Some(1001));
1155                 assert_eq!(tlv_stream.amount, Some(1001));
1156
1157                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1158                         .amount_msats(1000)
1159                         .build().unwrap()
1160                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1161                         .amount_msats(999)
1162                 {
1163                         Ok(_) => panic!("expected error"),
1164                         Err(e) => assert_eq!(e, Bolt12SemanticError::InsufficientAmount),
1165                 }
1166
1167                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1168                         .amount_msats(1000)
1169                         .supported_quantity(Quantity::Unbounded)
1170                         .build().unwrap()
1171                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1172                         .quantity(2).unwrap()
1173                         .amount_msats(1000)
1174                 {
1175                         Ok(_) => panic!("expected error"),
1176                         Err(e) => assert_eq!(e, Bolt12SemanticError::InsufficientAmount),
1177                 }
1178
1179                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1180                         .amount_msats(1000)
1181                         .build().unwrap()
1182                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1183                         .amount_msats(MAX_VALUE_MSAT + 1)
1184                 {
1185                         Ok(_) => panic!("expected error"),
1186                         Err(e) => assert_eq!(e, Bolt12SemanticError::InvalidAmount),
1187                 }
1188
1189                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1190                         .amount_msats(1000)
1191                         .supported_quantity(Quantity::Unbounded)
1192                         .build().unwrap()
1193                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1194                         .amount_msats(1000).unwrap()
1195                         .quantity(2).unwrap()
1196                         .build()
1197                 {
1198                         Ok(_) => panic!("expected error"),
1199                         Err(e) => assert_eq!(e, Bolt12SemanticError::InsufficientAmount),
1200                 }
1201
1202                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1203                         .build().unwrap()
1204                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1205                         .build()
1206                 {
1207                         Ok(_) => panic!("expected error"),
1208                         Err(e) => assert_eq!(e, Bolt12SemanticError::MissingAmount),
1209                 }
1210
1211                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1212                         .amount_msats(1000)
1213                         .supported_quantity(Quantity::Unbounded)
1214                         .build().unwrap()
1215                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1216                         .quantity(u64::max_value()).unwrap()
1217                         .build()
1218                 {
1219                         Ok(_) => panic!("expected error"),
1220                         Err(e) => assert_eq!(e, Bolt12SemanticError::InvalidAmount),
1221                 }
1222         }
1223
1224         #[test]
1225         fn builds_invoice_request_with_features() {
1226                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1227                         .amount_msats(1000)
1228                         .build().unwrap()
1229                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1230                         .features_unchecked(InvoiceRequestFeatures::unknown())
1231                         .build().unwrap()
1232                         .sign(payer_sign).unwrap();
1233                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1234                 assert_eq!(invoice_request.features(), &InvoiceRequestFeatures::unknown());
1235                 assert_eq!(tlv_stream.features, Some(&InvoiceRequestFeatures::unknown()));
1236
1237                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1238                         .amount_msats(1000)
1239                         .build().unwrap()
1240                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1241                         .features_unchecked(InvoiceRequestFeatures::unknown())
1242                         .features_unchecked(InvoiceRequestFeatures::empty())
1243                         .build().unwrap()
1244                         .sign(payer_sign).unwrap();
1245                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1246                 assert_eq!(invoice_request.features(), &InvoiceRequestFeatures::empty());
1247                 assert_eq!(tlv_stream.features, None);
1248         }
1249
1250         #[test]
1251         fn builds_invoice_request_with_quantity() {
1252                 let one = NonZeroU64::new(1).unwrap();
1253                 let ten = NonZeroU64::new(10).unwrap();
1254
1255                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1256                         .amount_msats(1000)
1257                         .supported_quantity(Quantity::One)
1258                         .build().unwrap()
1259                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1260                         .build().unwrap()
1261                         .sign(payer_sign).unwrap();
1262                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1263                 assert_eq!(invoice_request.quantity(), None);
1264                 assert_eq!(tlv_stream.quantity, None);
1265
1266                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1267                         .amount_msats(1000)
1268                         .supported_quantity(Quantity::One)
1269                         .build().unwrap()
1270                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1271                         .amount_msats(2_000).unwrap()
1272                         .quantity(2)
1273                 {
1274                         Ok(_) => panic!("expected error"),
1275                         Err(e) => assert_eq!(e, Bolt12SemanticError::UnexpectedQuantity),
1276                 }
1277
1278                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1279                         .amount_msats(1000)
1280                         .supported_quantity(Quantity::Bounded(ten))
1281                         .build().unwrap()
1282                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1283                         .amount_msats(10_000).unwrap()
1284                         .quantity(10).unwrap()
1285                         .build().unwrap()
1286                         .sign(payer_sign).unwrap();
1287                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1288                 assert_eq!(invoice_request.amount_msats(), Some(10_000));
1289                 assert_eq!(tlv_stream.amount, Some(10_000));
1290
1291                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1292                         .amount_msats(1000)
1293                         .supported_quantity(Quantity::Bounded(ten))
1294                         .build().unwrap()
1295                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1296                         .amount_msats(11_000).unwrap()
1297                         .quantity(11)
1298                 {
1299                         Ok(_) => panic!("expected error"),
1300                         Err(e) => assert_eq!(e, Bolt12SemanticError::InvalidQuantity),
1301                 }
1302
1303                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1304                         .amount_msats(1000)
1305                         .supported_quantity(Quantity::Unbounded)
1306                         .build().unwrap()
1307                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1308                         .amount_msats(2_000).unwrap()
1309                         .quantity(2).unwrap()
1310                         .build().unwrap()
1311                         .sign(payer_sign).unwrap();
1312                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1313                 assert_eq!(invoice_request.amount_msats(), Some(2_000));
1314                 assert_eq!(tlv_stream.amount, Some(2_000));
1315
1316                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1317                         .amount_msats(1000)
1318                         .supported_quantity(Quantity::Unbounded)
1319                         .build().unwrap()
1320                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1321                         .build()
1322                 {
1323                         Ok(_) => panic!("expected error"),
1324                         Err(e) => assert_eq!(e, Bolt12SemanticError::MissingQuantity),
1325                 }
1326
1327                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1328                         .amount_msats(1000)
1329                         .supported_quantity(Quantity::Bounded(one))
1330                         .build().unwrap()
1331                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1332                         .build()
1333                 {
1334                         Ok(_) => panic!("expected error"),
1335                         Err(e) => assert_eq!(e, Bolt12SemanticError::MissingQuantity),
1336                 }
1337         }
1338
1339         #[test]
1340         fn builds_invoice_request_with_payer_note() {
1341                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1342                         .amount_msats(1000)
1343                         .build().unwrap()
1344                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1345                         .payer_note("bar".into())
1346                         .build().unwrap()
1347                         .sign(payer_sign).unwrap();
1348                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1349                 assert_eq!(invoice_request.payer_note(), Some(PrintableString("bar")));
1350                 assert_eq!(tlv_stream.payer_note, Some(&String::from("bar")));
1351
1352                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1353                         .amount_msats(1000)
1354                         .build().unwrap()
1355                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1356                         .payer_note("bar".into())
1357                         .payer_note("baz".into())
1358                         .build().unwrap()
1359                         .sign(payer_sign).unwrap();
1360                 let (_, _, tlv_stream, _) = invoice_request.as_tlv_stream();
1361                 assert_eq!(invoice_request.payer_note(), Some(PrintableString("baz")));
1362                 assert_eq!(tlv_stream.payer_note, Some(&String::from("baz")));
1363         }
1364
1365         #[test]
1366         fn fails_signing_invoice_request() {
1367                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1368                         .amount_msats(1000)
1369                         .build().unwrap()
1370                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1371                         .build().unwrap()
1372                         .sign(|_| Err(()))
1373                 {
1374                         Ok(_) => panic!("expected error"),
1375                         Err(e) => assert_eq!(e, SignError::Signing(())),
1376                 }
1377
1378                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1379                         .amount_msats(1000)
1380                         .build().unwrap()
1381                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1382                         .build().unwrap()
1383                         .sign(recipient_sign)
1384                 {
1385                         Ok(_) => panic!("expected error"),
1386                         Err(e) => assert_eq!(e, SignError::Verification(secp256k1::Error::InvalidSignature)),
1387                 }
1388         }
1389
1390         #[test]
1391         fn fails_responding_with_unknown_required_features() {
1392                 match OfferBuilder::new("foo".into(), recipient_pubkey())
1393                         .amount_msats(1000)
1394                         .build().unwrap()
1395                         .request_invoice(vec![42; 32], payer_pubkey()).unwrap()
1396                         .features_unchecked(InvoiceRequestFeatures::unknown())
1397                         .build().unwrap()
1398                         .sign(payer_sign).unwrap()
1399                         .respond_with_no_std(payment_paths(), payment_hash(), now())
1400                 {
1401                         Ok(_) => panic!("expected error"),
1402                         Err(e) => assert_eq!(e, Bolt12SemanticError::UnknownRequiredFeatures),
1403                 }
1404         }
1405
1406         #[test]
1407         fn parses_invoice_request_with_metadata() {
1408                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1409                         .amount_msats(1000)
1410                         .build().unwrap()
1411                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1412                         .build().unwrap()
1413                         .sign(payer_sign).unwrap();
1414
1415                 let mut buffer = Vec::new();
1416                 invoice_request.write(&mut buffer).unwrap();
1417
1418                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1419                         panic!("error parsing invoice_request: {:?}", e);
1420                 }
1421         }
1422
1423         #[test]
1424         fn parses_invoice_request_with_chain() {
1425                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1426                         .amount_msats(1000)
1427                         .build().unwrap()
1428                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1429                         .chain(Network::Bitcoin).unwrap()
1430                         .build().unwrap()
1431                         .sign(payer_sign).unwrap();
1432
1433                 let mut buffer = Vec::new();
1434                 invoice_request.write(&mut buffer).unwrap();
1435
1436                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1437                         panic!("error parsing invoice_request: {:?}", e);
1438                 }
1439
1440                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1441                         .amount_msats(1000)
1442                         .build().unwrap()
1443                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1444                         .chain_unchecked(Network::Testnet)
1445                         .build_unchecked()
1446                         .sign(payer_sign).unwrap();
1447
1448                 let mut buffer = Vec::new();
1449                 invoice_request.write(&mut buffer).unwrap();
1450
1451                 match InvoiceRequest::try_from(buffer) {
1452                         Ok(_) => panic!("expected error"),
1453                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::UnsupportedChain)),
1454                 }
1455         }
1456
1457         #[test]
1458         fn parses_invoice_request_with_amount() {
1459                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1460                         .amount_msats(1000)
1461                         .build().unwrap()
1462                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1463                         .build().unwrap()
1464                         .sign(payer_sign).unwrap();
1465
1466                 let mut buffer = Vec::new();
1467                 invoice_request.write(&mut buffer).unwrap();
1468
1469                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1470                         panic!("error parsing invoice_request: {:?}", e);
1471                 }
1472
1473                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1474                         .build().unwrap()
1475                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1476                         .amount_msats(1000).unwrap()
1477                         .build().unwrap()
1478                         .sign(payer_sign).unwrap();
1479
1480                 let mut buffer = Vec::new();
1481                 invoice_request.write(&mut buffer).unwrap();
1482
1483                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1484                         panic!("error parsing invoice_request: {:?}", e);
1485                 }
1486
1487                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1488                         .build().unwrap()
1489                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1490                         .build_unchecked()
1491                         .sign(payer_sign).unwrap();
1492
1493                 let mut buffer = Vec::new();
1494                 invoice_request.write(&mut buffer).unwrap();
1495
1496                 match InvoiceRequest::try_from(buffer) {
1497                         Ok(_) => panic!("expected error"),
1498                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingAmount)),
1499                 }
1500
1501                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1502                         .amount_msats(1000)
1503                         .build().unwrap()
1504                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1505                         .amount_msats_unchecked(999)
1506                         .build_unchecked()
1507                         .sign(payer_sign).unwrap();
1508
1509                 let mut buffer = Vec::new();
1510                 invoice_request.write(&mut buffer).unwrap();
1511
1512                 match InvoiceRequest::try_from(buffer) {
1513                         Ok(_) => panic!("expected error"),
1514                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::InsufficientAmount)),
1515                 }
1516
1517                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1518                         .amount(Amount::Currency { iso4217_code: *b"USD", amount: 1000 })
1519                         .build_unchecked()
1520                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1521                         .build_unchecked()
1522                         .sign(payer_sign).unwrap();
1523
1524                 let mut buffer = Vec::new();
1525                 invoice_request.write(&mut buffer).unwrap();
1526
1527                 match InvoiceRequest::try_from(buffer) {
1528                         Ok(_) => panic!("expected error"),
1529                         Err(e) => {
1530                                 assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::UnsupportedCurrency));
1531                         },
1532                 }
1533
1534                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1535                         .amount_msats(1000)
1536                         .supported_quantity(Quantity::Unbounded)
1537                         .build().unwrap()
1538                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1539                         .quantity(u64::max_value()).unwrap()
1540                         .build_unchecked()
1541                         .sign(payer_sign).unwrap();
1542
1543                 let mut buffer = Vec::new();
1544                 invoice_request.write(&mut buffer).unwrap();
1545
1546                 match InvoiceRequest::try_from(buffer) {
1547                         Ok(_) => panic!("expected error"),
1548                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::InvalidAmount)),
1549                 }
1550         }
1551
1552         #[test]
1553         fn parses_invoice_request_with_quantity() {
1554                 let one = NonZeroU64::new(1).unwrap();
1555                 let ten = NonZeroU64::new(10).unwrap();
1556
1557                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1558                         .amount_msats(1000)
1559                         .supported_quantity(Quantity::One)
1560                         .build().unwrap()
1561                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1562                         .build().unwrap()
1563                         .sign(payer_sign).unwrap();
1564
1565                 let mut buffer = Vec::new();
1566                 invoice_request.write(&mut buffer).unwrap();
1567
1568                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1569                         panic!("error parsing invoice_request: {:?}", e);
1570                 }
1571
1572                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1573                         .amount_msats(1000)
1574                         .supported_quantity(Quantity::One)
1575                         .build().unwrap()
1576                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1577                         .amount_msats(2_000).unwrap()
1578                         .quantity_unchecked(2)
1579                         .build_unchecked()
1580                         .sign(payer_sign).unwrap();
1581
1582                 let mut buffer = Vec::new();
1583                 invoice_request.write(&mut buffer).unwrap();
1584
1585                 match InvoiceRequest::try_from(buffer) {
1586                         Ok(_) => panic!("expected error"),
1587                         Err(e) => {
1588                                 assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::UnexpectedQuantity));
1589                         },
1590                 }
1591
1592                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1593                         .amount_msats(1000)
1594                         .supported_quantity(Quantity::Bounded(ten))
1595                         .build().unwrap()
1596                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1597                         .amount_msats(10_000).unwrap()
1598                         .quantity(10).unwrap()
1599                         .build().unwrap()
1600                         .sign(payer_sign).unwrap();
1601
1602                 let mut buffer = Vec::new();
1603                 invoice_request.write(&mut buffer).unwrap();
1604
1605                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1606                         panic!("error parsing invoice_request: {:?}", e);
1607                 }
1608
1609                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1610                         .amount_msats(1000)
1611                         .supported_quantity(Quantity::Bounded(ten))
1612                         .build().unwrap()
1613                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1614                         .amount_msats(11_000).unwrap()
1615                         .quantity_unchecked(11)
1616                         .build_unchecked()
1617                         .sign(payer_sign).unwrap();
1618
1619                 let mut buffer = Vec::new();
1620                 invoice_request.write(&mut buffer).unwrap();
1621
1622                 match InvoiceRequest::try_from(buffer) {
1623                         Ok(_) => panic!("expected error"),
1624                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::InvalidQuantity)),
1625                 }
1626
1627                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1628                         .amount_msats(1000)
1629                         .supported_quantity(Quantity::Unbounded)
1630                         .build().unwrap()
1631                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1632                         .amount_msats(2_000).unwrap()
1633                         .quantity(2).unwrap()
1634                         .build().unwrap()
1635                         .sign(payer_sign).unwrap();
1636
1637                 let mut buffer = Vec::new();
1638                 invoice_request.write(&mut buffer).unwrap();
1639
1640                 if let Err(e) = InvoiceRequest::try_from(buffer) {
1641                         panic!("error parsing invoice_request: {:?}", e);
1642                 }
1643
1644                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1645                         .amount_msats(1000)
1646                         .supported_quantity(Quantity::Unbounded)
1647                         .build().unwrap()
1648                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1649                         .build_unchecked()
1650                         .sign(payer_sign).unwrap();
1651
1652                 let mut buffer = Vec::new();
1653                 invoice_request.write(&mut buffer).unwrap();
1654
1655                 match InvoiceRequest::try_from(buffer) {
1656                         Ok(_) => panic!("expected error"),
1657                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingQuantity)),
1658                 }
1659
1660                 let invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1661                         .amount_msats(1000)
1662                         .supported_quantity(Quantity::Bounded(one))
1663                         .build().unwrap()
1664                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1665                         .build_unchecked()
1666                         .sign(payer_sign).unwrap();
1667
1668                 let mut buffer = Vec::new();
1669                 invoice_request.write(&mut buffer).unwrap();
1670
1671                 match InvoiceRequest::try_from(buffer) {
1672                         Ok(_) => panic!("expected error"),
1673                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingQuantity)),
1674                 }
1675         }
1676
1677         #[test]
1678         fn fails_parsing_invoice_request_without_metadata() {
1679                 let offer = OfferBuilder::new("foo".into(), recipient_pubkey())
1680                         .amount_msats(1000)
1681                         .build().unwrap();
1682                 let unsigned_invoice_request = offer.request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1683                         .build().unwrap();
1684                 let mut tlv_stream = unsigned_invoice_request.invoice_request.as_tlv_stream();
1685                 tlv_stream.0.metadata = None;
1686
1687                 let mut buffer = Vec::new();
1688                 tlv_stream.write(&mut buffer).unwrap();
1689
1690                 match InvoiceRequest::try_from(buffer) {
1691                         Ok(_) => panic!("expected error"),
1692                         Err(e) => {
1693                                 assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingPayerMetadata));
1694                         },
1695                 }
1696         }
1697
1698         #[test]
1699         fn fails_parsing_invoice_request_without_payer_id() {
1700                 let offer = OfferBuilder::new("foo".into(), recipient_pubkey())
1701                         .amount_msats(1000)
1702                         .build().unwrap();
1703                 let unsigned_invoice_request = offer.request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1704                         .build().unwrap();
1705                 let mut tlv_stream = unsigned_invoice_request.invoice_request.as_tlv_stream();
1706                 tlv_stream.2.payer_id = None;
1707
1708                 let mut buffer = Vec::new();
1709                 tlv_stream.write(&mut buffer).unwrap();
1710
1711                 match InvoiceRequest::try_from(buffer) {
1712                         Ok(_) => panic!("expected error"),
1713                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingPayerId)),
1714                 }
1715         }
1716
1717         #[test]
1718         fn fails_parsing_invoice_request_without_node_id() {
1719                 let offer = OfferBuilder::new("foo".into(), recipient_pubkey())
1720                         .amount_msats(1000)
1721                         .build().unwrap();
1722                 let unsigned_invoice_request = offer.request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1723                         .build().unwrap();
1724                 let mut tlv_stream = unsigned_invoice_request.invoice_request.as_tlv_stream();
1725                 tlv_stream.1.node_id = None;
1726
1727                 let mut buffer = Vec::new();
1728                 tlv_stream.write(&mut buffer).unwrap();
1729
1730                 match InvoiceRequest::try_from(buffer) {
1731                         Ok(_) => panic!("expected error"),
1732                         Err(e) => {
1733                                 assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingSigningPubkey));
1734                         },
1735                 }
1736         }
1737
1738         #[test]
1739         fn fails_parsing_invoice_request_without_signature() {
1740                 let mut buffer = Vec::new();
1741                 OfferBuilder::new("foo".into(), recipient_pubkey())
1742                         .amount_msats(1000)
1743                         .build().unwrap()
1744                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1745                         .build().unwrap()
1746                         .invoice_request
1747                         .write(&mut buffer).unwrap();
1748
1749                 match InvoiceRequest::try_from(buffer) {
1750                         Ok(_) => panic!("expected error"),
1751                         Err(e) => assert_eq!(e, Bolt12ParseError::InvalidSemantics(Bolt12SemanticError::MissingSignature)),
1752                 }
1753         }
1754
1755         #[test]
1756         fn fails_parsing_invoice_request_with_invalid_signature() {
1757                 let mut invoice_request = OfferBuilder::new("foo".into(), recipient_pubkey())
1758                         .amount_msats(1000)
1759                         .build().unwrap()
1760                         .request_invoice(vec![1; 32], payer_pubkey()).unwrap()
1761                         .build().unwrap()
1762                         .sign(payer_sign).unwrap();
1763                 let last_signature_byte = invoice_request.bytes.last_mut().unwrap();
1764                 *last_signature_byte = last_signature_byte.wrapping_add(1);
1765
1766                 let mut buffer = Vec::new();
1767                 invoice_request.write(&mut buffer).unwrap();
1768
1769                 match InvoiceRequest::try_from(buffer) {
1770                         Ok(_) => panic!("expected error"),
1771                         Err(e) => {
1772                                 assert_eq!(e, Bolt12ParseError::InvalidSignature(secp256k1::Error::InvalidSignature));
1773                         },
1774                 }
1775         }
1776
1777         #[test]
1778         fn fails_parsing_invoice_request_with_extra_tlv_records() {
1779                 let secp_ctx = Secp256k1::new();
1780                 let keys = KeyPair::from_secret_key(&secp_ctx, &SecretKey::from_slice(&[42; 32]).unwrap());
1781                 let invoice_request = OfferBuilder::new("foo".into(), keys.public_key())
1782                         .amount_msats(1000)
1783                         .build().unwrap()
1784                         .request_invoice(vec![1; 32], keys.public_key()).unwrap()
1785                         .build().unwrap()
1786                         .sign::<_, Infallible>(
1787                                 |message| Ok(secp_ctx.sign_schnorr_no_aux_rand(message.as_ref().as_digest(), &keys))
1788                         )
1789                         .unwrap();
1790
1791                 let mut encoded_invoice_request = Vec::new();
1792                 invoice_request.write(&mut encoded_invoice_request).unwrap();
1793                 BigSize(1002).write(&mut encoded_invoice_request).unwrap();
1794                 BigSize(32).write(&mut encoded_invoice_request).unwrap();
1795                 [42u8; 32].write(&mut encoded_invoice_request).unwrap();
1796
1797                 match InvoiceRequest::try_from(encoded_invoice_request) {
1798                         Ok(_) => panic!("expected error"),
1799                         Err(e) => assert_eq!(e, Bolt12ParseError::Decode(DecodeError::InvalidValue)),
1800                 }
1801         }
1802 }