aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-common/src
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-common/src')
-rw-r--r--packages/meshbay-common/src/meshbay_common/handshake.py10
1 files changed, 9 insertions, 1 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/handshake.py b/packages/meshbay-common/src/meshbay_common/handshake.py
index 2f3d641..f7d4911 100644
--- a/packages/meshbay-common/src/meshbay_common/handshake.py
+++ b/packages/meshbay-common/src/meshbay_common/handshake.py
@@ -77,6 +77,13 @@ ROLE_NODE = "node"
NONCE_LEN = 32
+# Clock-skew tolerance for JWT `iat`/`exp`/`nbf`. The token is issued by the
+# hub and verified by a node, on two machines whose clocks are only as close
+# as their NTP — and a VM guest that has just resumed can be tens of seconds
+# out. Without this a slightly-fast client cannot connect at all
+# ("token is not yet valid (iat)").
+JWT_LEEWAY_SECONDS = 60
+
class HandshakeError(Exception):
"""
@@ -230,7 +237,8 @@ def authorize_token(
check entirely and fell back to the node's first group (M1).
"""
try:
- decoded = jwt.decode(token, hub_pk_pem, algorithms=["EdDSA"])
+ decoded = jwt.decode(token, hub_pk_pem, algorithms=["EdDSA"],
+ leeway=JWT_LEEWAY_SECONDS)
except Exception as exc:
raise HandshakeError(f"Invalid JWT: {exc}") from exc