diff options
Diffstat (limited to 'packages/meshbay-common/src')
| -rw-r--r-- | packages/meshbay-common/src/meshbay_common/handshake.py | 10 |
1 files changed, 9 insertions, 1 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/handshake.py b/packages/meshbay-common/src/meshbay_common/handshake.py index 2f3d641..f7d4911 100644 --- a/packages/meshbay-common/src/meshbay_common/handshake.py +++ b/packages/meshbay-common/src/meshbay_common/handshake.py @@ -77,6 +77,13 @@ ROLE_NODE = "node" NONCE_LEN = 32 +# Clock-skew tolerance for JWT `iat`/`exp`/`nbf`. The token is issued by the +# hub and verified by a node, on two machines whose clocks are only as close +# as their NTP — and a VM guest that has just resumed can be tens of seconds +# out. Without this a slightly-fast client cannot connect at all +# ("token is not yet valid (iat)"). +JWT_LEEWAY_SECONDS = 60 + class HandshakeError(Exception): """ @@ -230,7 +237,8 @@ def authorize_token( check entirely and fell back to the node's first group (M1). """ try: - decoded = jwt.decode(token, hub_pk_pem, algorithms=["EdDSA"]) + decoded = jwt.decode(token, hub_pk_pem, algorithms=["EdDSA"], + leeway=JWT_LEEWAY_SECONDS) except Exception as exc: raise HandshakeError(f"Invalid JWT: {exc}") from exc |