aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/nodes.py24
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/revocation.py11
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/signaling.py101
3 files changed, 79 insertions, 57 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
index 6205180..403f450 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/nodes.py
@@ -21,10 +21,18 @@ from meshbay_hub.db.models import GroupMember, IPLog, Node, User
router = APIRouter(prefix="/v1/nodes", tags=["nodes"])
+class MnpTokenRequest(BaseModel):
+ # The base64 Ed25519 key of the node this token is for. The token is bound
+ # to it (E10), so it cannot be replayed to another node. The client knows it
+ # from `/v1/groups/{id}/nodes` before it connects.
+ node_pk: str = ""
+
+
@router.post("/mnp-token")
@limiter.limit("60/minute")
async def mnp_token(
request: Request,
+ body: MnpTokenRequest | None = None,
current_user: User = Depends(require_user_scope),
db: AsyncSession = Depends(get_db),
):
@@ -32,16 +40,22 @@ async def mnp_token(
Asked for with the member's own session token (require_user_scope, so a node
daemon token cannot mint one). The result carries the member's current group
- membership and `aud=MNP_AUD`, so it authorises the member to a node and is
- refused by the hub API. Short-lived on purpose; the client refetches it for a
- new connection or a reconnect, and it is checked only at the handshake, so a
- film already playing is never interrupted by its expiry.
+ membership, `aud=MNP_AUD` and the target node's key, so it authorises the
+ member to **that** node only and is refused by the hub API and by any other
+ node. Short-lived on purpose; the client refetches it for a new connection or
+ a reconnect, and it is checked only at the handshake, so a film already
+ playing is never interrupted by its expiry.
+
+ The hub does not verify the node key it is handed — binding the token to it
+ only *restricts* the token to whatever node holds that key, which is the one
+ the client is connecting to; a wrong key yields a token no node will accept.
"""
rows = await db.execute(
select(GroupMember.group_id).where(GroupMember.user_id == current_user.id))
group_ids = [gid for (gid,) in rows.all()]
return {
- "mnp_token": issue_mnp_token(current_user.id, groups=group_ids),
+ "mnp_token": issue_mnp_token(current_user.id, groups=group_ids,
+ node_pk=(body.node_pk if body else "")),
"expires_in": 900,
}
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
index f8cae8a..2c0b8db 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
@@ -441,6 +441,7 @@ async def notify_incoming(
body: IncomingRequest,
request: Request,
current_user: User = Depends(get_current_user),
+ db: AsyncSession = Depends(get_db),
):
"""
Signal a node that a client wants to connect (NAT punch coordination).
@@ -450,8 +451,18 @@ async def notify_incoming(
arbitrary node emit UDP packets to an address of their choosing — a small
reflection primitive using someone else's machine. The probe target must now be
the caller's own source address.
+
+ Like the offer relay, the caller must share an active group with the node —
+ checked **before** anything reveals whether the node is connected, so this is
+ not a liveness oracle a stranger can poll, and a stranger cannot make a node
+ punch on their behalf.
"""
from meshbay_hub.api.netutil import client_ip
+ from meshbay_hub.api.signaling import require_shared_active_group
+
+ # First, and before anything reveals whether the node is connected: a
+ # stranger cannot poll this for a node's liveness, nor make it punch.
+ await require_shared_active_group(db, node_id, current_user.id)
caller_ip = client_ip(request)
if body.peer_ip != caller_ip:
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/signaling.py b/packages/meshbay-hub/src/meshbay_hub/api/signaling.py
index 60d5e20..fc40204 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/signaling.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/signaling.py
@@ -102,6 +102,51 @@ def _take_offer(user_id: str, node_id: str, now: float) -> float | None:
return None
+async def require_shared_active_group(db: AsyncSession, node_id: str, user_id: str) -> None:
+ """The caller must share an **active** group with this node, or the node must
+ host an open group while public groups are on (that path *is* what a public
+ group means, so it follows the instance switch). Raises 403 with a uniform
+ message otherwise — the same answer whether the node is a member's or a
+ stranger's, and whether it is connected or not, so it is not a liveness
+ oracle for a non-member.
+
+ Membership is read from the connected-node registry, so a node hosting no
+ group shares one with nobody (AV24, AV1): the empty claim is "no groups", not
+ "all of its owner's". Both the WebRTC offer relay and the NAT-punch signal
+ call this, so they gate the same way (H6).
+ """
+ from meshbay_hub.api.revocation import _node_groups
+ node_group_ids = set(_node_groups.get(node_id, []))
+ if not node_group_ids:
+ raise HTTPException(status_code=403,
+ detail="Not a member of any group on this node")
+ shared = [gid for (gid,) in (await db.execute(
+ select(GroupMember.group_id).where(
+ GroupMember.user_id == user_id,
+ GroupMember.group_id.in_(node_group_ids),
+ ))).all()]
+ if not shared:
+ has_open = None
+ if await hub_settings.public_groups_allowed(db):
+ has_open = (await db.execute(
+ select(Group.id).where(
+ Group.id.in_(node_group_ids),
+ Group.join_policy == "open",
+ Group.status == "active",
+ ))).first()
+ if not has_open:
+ raise HTTPException(status_code=403,
+ detail="Not a member of any group on this node")
+ return
+ statuses = set((await db.execute(
+ select(Group.status).where(Group.id.in_(shared)))).scalars().all())
+ if "active" not in statuses:
+ # Report the strongest state present — "revoked" is the signed,
+ # node-enforced one; "suspended" is the reversible hub flag.
+ state = "revoked" if "revoked" in statuses else next(iter(statuses), "suspended")
+ raise HTTPException(status_code=403, detail=f"Group is {state}")
+
+
@router.post("/{node_id}/webrtc/offer", response_model=WebRTCOfferResponse)
# Per address and per node, and only a coarse guard in front of authentication:
# the account's budget above is the limit that means something. 600 because an
@@ -143,58 +188,10 @@ async def webrtc_offer(
if not ws:
raise HTTPException(status_code=404, detail="Node not connected")
- # The caller must share at least one active group with the target node,
- # OR the node must host at least one open-join group (public groups admit
- # anyone — the node's MNP handshake handles authorization).
- #
- # That second path is exactly what "public groups" means, so it is gated by
- # the instance switch: with public groups off, a non-member is not brokered a
- # connection to a node just because it happens to host an open group. Members
- # of that group are unaffected — they match `shared` below.
- node_group_ids = set(_node_groups.get(node_id, []))
- # A node registered for no group shares no group with anybody, which is this
- # check's own answer — and `if node_group_ids:` used to skip the whole thing,
- # membership, group status and the public-group gate together. Since AV1 made
- # an empty claim mean "no groups" rather than "all of my owner's", that is
- # the *normal* registration of a node hosting nothing: exactly the
- # unconfigured node left running that took a group down on 2026-09-11. So the
- # machine least able to defend itself was the one any authenticated account
- # could make allocate a peer connection and gather ICE, which is H6 restored
- # in the one case AV1 made common.
- #
- # Nothing legitimate is lost by refusing here: a browser cannot complete a
- # handshake with such a node anyway — `group_id` is mandatory (M1) and a node
- # holding no group key refuses outright (NS8) — so this only declines work
- # the node would decline one step later, at its own expense.
- if not node_group_ids:
- raise HTTPException(status_code=403,
- detail="Not a member of any group on this node")
-
- result = await db.execute(
- select(GroupMember.group_id).where(
- GroupMember.user_id == current_user.id,
- GroupMember.group_id.in_(node_group_ids),
- ))
- shared = [gid for (gid,) in result.all()]
- if not shared:
- has_open = None
- if await hub_settings.public_groups_allowed(db):
- has_open = (await db.execute(
- select(Group.id).where(
- Group.id.in_(node_group_ids),
- Group.join_policy == "open",
- Group.status == "active",
- ))).first()
- if not has_open:
- raise HTTPException(status_code=403, detail="Not a member of any group on this node")
- else:
- statuses = set((await db.execute(
- select(Group.status).where(Group.id.in_(shared)))).scalars().all())
- if "active" not in statuses:
- # Report the strongest state present — "revoked" is the signed,
- # node-enforced one; "suspended" is the reversible hub flag.
- state = "revoked" if "revoked" in statuses else next(iter(statuses), "suspended")
- raise HTTPException(status_code=403, detail=f"Group is {state}")
+ # The caller must share an active group with the node (or the node must host
+ # an open group when public groups are on). One implementation, shared with
+ # the NAT-punch signal (`notify_incoming`), so both gate the same way.
+ await require_shared_active_group(db, node_id, current_user.id)
# Both refusals say when to come back, and transport.js does: a 429 here is
# the hub being busy, never the node being down.