diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 15:48:51 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 15:48:51 +0200 |
| commit | 8926f163dad9d32dc06c3a142658a4e11d9c12c1 (patch) | |
| tree | 4d36d1c18154cb46e6e80c59ef6c607972caa81e /packages/meshbay-hub/src/meshbay_hub/static/crypto.js | |
| parent | 8d96cf2314b45e0737f932998b5422c27a2ae72e (diff) | |
| download | meshbay-8926f163dad9d32dc06c3a142658a4e11d9c12c1.tar.gz | |
refactor(hub): the transport holds an identity, never a private key
Two public keys, sign() and shared(); the apps take transport.signFn. What
holds the keys (this page, or the desktop main process) is the identity's
business alone.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/crypto.js')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/static/crypto.js | 14 |
1 files changed, 7 insertions, 7 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/crypto.js b/packages/meshbay-hub/src/meshbay_hub/static/crypto.js index 0ca8ee5..27e97d3 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/crypto.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/crypto.js @@ -278,17 +278,17 @@ async function verifyChatSignature(deviceRaw, groupId, epoch, nonce, ct, sig) { // ── GEK unwrapping (ECIES) ───────────────────────────────────────────────────── -async function unwrapGEK(bundle, skXPkcs8, pkXRaw) { +/** + * Unwrap a group key wrapped for our X25519 key. `shared(pkEphRaw)` is the + * agreement with the ephemeral key — done by whatever holds the private key + * (the identity object, transport.js), so this never sees one. + */ +async function unwrapGEK(bundle, shared, pkXRaw) { const pkEphRaw = b64decode(bundle.pk_eph_b64); const nonce = b64decode(bundle.nonce_b64); const wrapped = b64decode(bundle.wrapped_b64); - const skX = await crypto.subtle.importKey( - 'pkcs8', skXPkcs8, { name: 'X25519' }, false, ['deriveBits']); - const pkEph = await crypto.subtle.importKey( - 'raw', pkEphRaw, { name: 'X25519' }, false, []); - const sharedBits = await crypto.subtle.deriveBits( - { name: 'X25519', public: pkEph }, skX, 256); + const sharedBits = await shared(pkEphRaw); const sharedKey = await crypto.subtle.importKey( 'raw', sharedBits, 'HKDF', false, ['deriveKey']); |