diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/nodes.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/nodes.py | 15 |
1 files changed, 13 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py index 0770148..67e65f2 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py @@ -1,5 +1,6 @@ """Node endpoints — /v1/nodes/*""" +from datetime import datetime, timezone import base64 import time @@ -130,10 +131,18 @@ async def announce_node( select(Node).where(Node.user_id == current_user.id, Node.pk_node == body.pk_node)) node = existing.scalar_one_or_none() + # The address is taken from the connection, never from the body: the + # signature above proves who is announcing, and this is where they are + # announcing from. What the node believes its address to be — endpoint_hint, + # learned from a STUN server — is kept separately and is not evidence. + seen_from = client_ip(request) + if node is not None: node.endpoint_hint = body.endpoint_hint + node.observed_ip = seen_from + node.last_seen = datetime.now(timezone.utc) db.add(IPLog(user_id=current_user.id, event="node_announce", - ip_address=client_ip(request), detail=body.endpoint_hint)) + ip_address=seen_from, detail=body.endpoint_hint)) await db.commit() return {"node_id": node.id} @@ -141,12 +150,14 @@ async def announce_node( user_id=current_user.id, pk_node=body.pk_node, endpoint_hint=body.endpoint_hint, + observed_ip=seen_from, + last_seen=datetime.now(timezone.utc), ) db.add(node) db.add(IPLog( user_id=current_user.id, event="node_announce", - ip_address=client_ip(request), + ip_address=seen_from, detail=body.endpoint_hint, )) await db.commit() |