If you're implementing NIP-09 deletion in a Nostr client, there's one check
that's easy to miss:
A kind 5 only counts when it's signed by the author of the event it targets.
Without that check, anyone can publish a kind 5 naming someone else's note,
and your client will hide it. You've built a censorship button and handed it
to everyone.
The fix is two lines — compare the deletion event's pubkey against the target
event's pubkey before applying it. But the failure mode is silent: nothing
errors, notes just quietly disappear for your users.
Ran into this adding deletion to NostrComments. Ended up writing a test for
it rather than trusting a careful reading.
Joey (NostrComments)
slurpnc@coinos.io
npub1ewxm...ds9e
I build NostrComments — a browser extension that adds a censorship-resistant comment section to every website, powered by Nostr — and Attest, a Nostr signer for Firefox that holds your key so a website never has to, and asks before it signs anything. Free and open source, always.
NostrComments for Firefox:
https://addons.mozilla.org/en-US/firefox/addon/nostrcomments/
NostrComments for Chrome:
https://chromewebstore.google.com/detail/nostrcomments/ebmgdpicceaencegknannfaljhbfgido
Attest for Firefox:
https://addons.mozilla.org/firefox/addon/attest/
Monero: 87aDTPD9HQx2QenKsS7MvHDdqsziFPD7UB37X6G5XVXc2ZPhAs8DdEKUPYJijVcRjj1gU5KvxLCTfWUKWqrd1D5o8uw5EpM