aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/nodes.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/nodes.py15
1 files changed, 13 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
index 0770148..67e65f2 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
@@ -1,5 +1,6 @@
"""Node endpoints — /v1/nodes/*"""
+from datetime import datetime, timezone
import base64
import time
@@ -130,10 +131,18 @@ async def announce_node(
select(Node).where(Node.user_id == current_user.id,
Node.pk_node == body.pk_node))
node = existing.scalar_one_or_none()
+ # The address is taken from the connection, never from the body: the
+ # signature above proves who is announcing, and this is where they are
+ # announcing from. What the node believes its address to be — endpoint_hint,
+ # learned from a STUN server — is kept separately and is not evidence.
+ seen_from = client_ip(request)
+
if node is not None:
node.endpoint_hint = body.endpoint_hint
+ node.observed_ip = seen_from
+ node.last_seen = datetime.now(timezone.utc)
db.add(IPLog(user_id=current_user.id, event="node_announce",
- ip_address=client_ip(request), detail=body.endpoint_hint))
+ ip_address=seen_from, detail=body.endpoint_hint))
await db.commit()
return {"node_id": node.id}
@@ -141,12 +150,14 @@ async def announce_node(
user_id=current_user.id,
pk_node=body.pk_node,
endpoint_hint=body.endpoint_hint,
+ observed_ip=seen_from,
+ last_seen=datetime.now(timezone.utc),
)
db.add(node)
db.add(IPLog(
user_id=current_user.id,
event="node_announce",
- ip_address=client_ip(request),
+ ip_address=seen_from,
detail=body.endpoint_hint,
))
await db.commit()