aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/revocation.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/revocation.py11
1 files changed, 11 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
index f8cae8a..2c0b8db 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
@@ -441,6 +441,7 @@ async def notify_incoming(
body: IncomingRequest,
request: Request,
current_user: User = Depends(get_current_user),
+ db: AsyncSession = Depends(get_db),
):
"""
Signal a node that a client wants to connect (NAT punch coordination).
@@ -450,8 +451,18 @@ async def notify_incoming(
arbitrary node emit UDP packets to an address of their choosing — a small
reflection primitive using someone else's machine. The probe target must now be
the caller's own source address.
+
+ Like the offer relay, the caller must share an active group with the node —
+ checked **before** anything reveals whether the node is connected, so this is
+ not a liveness oracle a stranger can poll, and a stranger cannot make a node
+ punch on their behalf.
"""
from meshbay_hub.api.netutil import client_ip
+ from meshbay_hub.api.signaling import require_shared_active_group
+
+ # First, and before anything reveals whether the node is connected: a
+ # stranger cannot poll this for a node's liveness, nor make it punch.
+ await require_shared_active_group(db, node_id, current_user.id)
caller_ip = client_ip(request)
if body.peer_ip != caller_ip: