Class VoucherFingerprint
java.lang.Object
xyz.tcheeric.cashu.voucher.domain.VoucherFingerprint
Cryptographic fingerprinting for Cashu vouchers.
Provides collision-resistant fingerprints for vouchers based on their unique identifiers. The fingerprint is deterministic and can be used for:
- Duplicate detection during redemption
- Idempotency key generation for API calls
- Tracking redemption attempts across distributed systems
Algorithm
The fingerprint is computed as SHA-256 of a canonical string representation:
SHA-256(voucherId || "|" || issuerId || "|" || signature)
Including the signature ensures that even if a voucher ID is reused (which should not happen), different signatures produce different fingerprints.
Security Properties
- Deterministic: Same voucher always produces same fingerprint
- Collision-resistant: Different vouchers produce different fingerprints
- Non-reversible: Cannot derive voucher details from fingerprint
- See Also:
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionComputes the fingerprint from raw voucher components.compute(xyz.tcheeric.cashu.common.VoucherSecret secret) Computes the fingerprint for a voucher secret.compute(SignedVoucher voucher) Computes the fingerprint for a signed voucher.booleanValidates that a fingerprint matches the expected format.
-
Constructor Details
-
VoucherFingerprint
public VoucherFingerprint()
-
-
Method Details
-
compute
Computes the fingerprint for a signed voucher.- Parameters:
voucher- the signed voucher to fingerprint (must not be null)- Returns:
- 64-character hex-encoded SHA-256 hash
- Throws:
IllegalArgumentException- if voucher is null
-
compute
Computes the fingerprint for a voucher secret.The fingerprint includes:
- Voucher ID (UUID)
- Issuer ID
- Signature (if present)
- Parameters:
secret- the voucher secret to fingerprint (must not be null)- Returns:
- 64-character hex-encoded SHA-256 hash
- Throws:
IllegalArgumentException- if secret is null or missing required fields
-
compute
Computes the fingerprint from raw voucher components.This method is useful when you have the components but not the full VoucherSecret object.
- Parameters:
voucherId- the voucher ID (must not be null or blank)issuerId- the issuer ID (must not be null or blank)signature- the signature hex string (may be null)- Returns:
- 64-character hex-encoded SHA-256 hash
-
isValid
Validates that a fingerprint matches the expected format.- Parameters:
fingerprint- the fingerprint to validate- Returns:
- true if the fingerprint is a valid 64-character hex string
-