aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-node/src/meshbay_node/transport/webrtc/apps
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-28 21:14:10 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-28 21:14:10 +0200
commita421a03d2be16670dc8d9076d26f4a7eac669986 (patch)
treece8a0053497278086696a8f802e97605f80903f4 /packages/meshbay-node/src/meshbay_node/transport/webrtc/apps
parentf63104b82da24ff3f406c53346300bd50788796f (diff)
downloadmeshbay-a421a03d2be16670dc8d9076d26f4a7eac669986.tar.gz
fix: bound pending admin challenges and sign every value an op acts on
Any member could make a node hold unbounded challenge requests; a connection now keeps at most 8, 64 KiB each. root_add, group_attach, invite_create and tmdb_config signed less than they did; their subjects are now canonical JSON of every value (the TMDB token by SHA-256). MNP 5.0, floor kept at 4.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-node/src/meshbay_node/transport/webrtc/apps')
-rw-r--r--packages/meshbay-node/src/meshbay_node/transport/webrtc/apps/video_meta.py13
1 files changed, 7 insertions, 6 deletions
diff --git a/packages/meshbay-node/src/meshbay_node/transport/webrtc/apps/video_meta.py b/packages/meshbay-node/src/meshbay_node/transport/webrtc/apps/video_meta.py
index 834bac4..a9b35dc 100644
--- a/packages/meshbay-node/src/meshbay_node/transport/webrtc/apps/video_meta.py
+++ b/packages/meshbay-node/src/meshbay_node/transport/webrtc/apps/video_meta.py
@@ -11,6 +11,7 @@ from meshbay_common.adminop import (
OP_TMDB_ENABLED,
OP_TMDB_OVERRIDE,
OP_TMDB_REMATCH,
+ tmdb_config_subject,
)
from meshbay_common.protocol import MNP
@@ -60,12 +61,12 @@ class VideoMetaMixin:
if not self._has_admin_authority():
self._send({"type": "error", "detail": "No authorized key for this"})
return
- # The subject is the signed, audited, human-shown string — it must
- # never contain the token itself (it would end up in the audit log
- # in plaintext). The actual token travels only in `payload`, which
- # is node-side context, never re-sent or re-verified from the wire.
- # The language is not a secret, so it travels in the subject itself.
- subject = f"custom_token={'yes' if token else 'no'},language={language or 'default'}"
+ # The subject is the signed, audited string, so it must never contain
+ # the token itself (it would end up in the audit log in plaintext); it
+ # carries the token's SHA-256 instead, which binds the signature to this
+ # token without writing it down. `None` (unchanged) and `""` (clear)
+ # stay distinct, for the token and the language alike.
+ subject = tmdb_config_subject(token, language)
self._issue_admin_challenge(
OP_TMDB_CONFIG, subject,
payload={"token": token, "language": language},