MessageHashUtils.sol 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384
  1. // SPDX-License-Identifier: MIT
  2. // OpenZeppelin Contracts (last updated v5.0.0) (utils/cryptography/MessageHashUtils.sol)
  3. pragma solidity ^0.8.20;
  4. import {Strings} from "../Strings.sol";
  5. /**
  6. * @dev Signature message hash utilities for producing digests to be consumed by {ECDSA} recovery or signing.
  7. *
  8. * The library provides methods for generating a hash of a message that conforms to the
  9. * https://eips.ethereum.org/EIPS/eip-191[ERC-191] and https://eips.ethereum.org/EIPS/eip-712[EIP 712]
  10. * specifications.
  11. */
  12. library MessageHashUtils {
  13. /**
  14. * @dev Returns the keccak256 digest of an ERC-191 signed data with version
  15. * `0x45` (`personal_sign` messages).
  16. *
  17. * The digest is calculated by prefixing a bytes32 `messageHash` with
  18. * `"\x19Ethereum Signed Message:\n32"` and hashing the result. It corresponds with the
  19. * hash signed when using the https://eth.wiki/json-rpc/API#eth_sign[`eth_sign`] JSON-RPC method.
  20. *
  21. * NOTE: The `messageHash` parameter is intended to be the result of hashing a raw message with
  22. * keccak256, although any bytes32 value can be safely used because the final digest will
  23. * be re-hashed.
  24. *
  25. * See {ECDSA-recover}.
  26. */
  27. function toEthSignedMessageHash(bytes32 messageHash) internal pure returns (bytes32 digest) {
  28. assembly ("memory-safe") {
  29. mstore(0x00, "\x19Ethereum Signed Message:\n32") // 32 is the bytes-length of messageHash
  30. mstore(0x1c, messageHash) // 0x1c (28) is the length of the prefix
  31. digest := keccak256(0x00, 0x3c) // 0x3c is the length of the prefix (0x1c) + messageHash (0x20)
  32. }
  33. }
  34. /**
  35. * @dev Returns the keccak256 digest of an ERC-191 signed data with version
  36. * `0x45` (`personal_sign` messages).
  37. *
  38. * The digest is calculated by prefixing an arbitrary `message` with
  39. * `"\x19Ethereum Signed Message:\n" + len(message)` and hashing the result. It corresponds with the
  40. * hash signed when using the https://eth.wiki/json-rpc/API#eth_sign[`eth_sign`] JSON-RPC method.
  41. *
  42. * See {ECDSA-recover}.
  43. */
  44. function toEthSignedMessageHash(bytes memory message) internal pure returns (bytes32) {
  45. return
  46. keccak256(bytes.concat("\x19Ethereum Signed Message:\n", bytes(Strings.toString(message.length)), message));
  47. }
  48. /**
  49. * @dev Returns the keccak256 digest of an ERC-191 signed data with version
  50. * `0x00` (data with intended validator).
  51. *
  52. * The digest is calculated by prefixing an arbitrary `data` with `"\x19\x00"` and the intended
  53. * `validator` address. Then hashing the result.
  54. *
  55. * See {ECDSA-recover}.
  56. */
  57. function toDataWithIntendedValidatorHash(address validator, bytes memory data) internal pure returns (bytes32) {
  58. return keccak256(abi.encodePacked(hex"19_00", validator, data));
  59. }
  60. /**
  61. * @dev Returns the keccak256 digest of an EIP-712 typed data (ERC-191 version `0x01`).
  62. *
  63. * The digest is calculated from a `domainSeparator` and a `structHash`, by prefixing them with
  64. * `\x19\x01` and hashing the result. It corresponds to the hash signed by the
  65. * https://eips.ethereum.org/EIPS/eip-712[`eth_signTypedData`] JSON-RPC method as part of EIP-712.
  66. *
  67. * See {ECDSA-recover}.
  68. */
  69. function toTypedDataHash(bytes32 domainSeparator, bytes32 structHash) internal pure returns (bytes32 digest) {
  70. assembly ("memory-safe") {
  71. let ptr := mload(0x40)
  72. mstore(ptr, hex"19_01")
  73. mstore(add(ptr, 0x02), domainSeparator)
  74. mstore(add(ptr, 0x22), structHash)
  75. digest := keccak256(ptr, 0x42)
  76. }
  77. }
  78. }