aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/crypto.js
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/crypto.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/crypto.js11
1 files changed, 9 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/crypto.js b/packages/meshbay-hub/src/meshbay_hub/static/crypto.js
index f9cff08..24d1399 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/crypto.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/crypto.js
@@ -111,8 +111,9 @@ async function decryptChunkBin(gek, fileHashHex, chunkIndex, nonce, ct) {
// ── Sealing a payload under the group key ────────────────────────────────────
//
-// Mirrors meshbay_common/groupbox.py. `index_sync`, `index_delta` and the
-// `handshake_ack` config payload travel sealed under a GEK-derived subkey; the
+// Mirrors meshbay_common/groupbox.py. `index_sync`, `index_delta`, the
+// `handshake_ack` config payload and both halves of an upload travel sealed
+// under a GEK-derived subkey; the
// routing fields (type, v, group_id) and the ack's own authentication (node_pk,
// proof, sig) stay in clear, because a receiver must route, version-check and
// *authenticate* before it would trust a decryption.
@@ -126,6 +127,12 @@ async function decryptChunkBin(gek, fileHashHex, chunkIndex, nonce, ct) {
const GROUPBOX_INFO = {
index: new TextEncoder().encode('meshbay:index:v1'),
ack: new TextEncoder().encode('meshbay:ack:v1'),
+ // MNP 2.0: `file_upload` and `file_upload_ack`. This is the one purpose that
+ // seals *towards* the node — it holds the GEK for its own group — and the one
+ // with real message volume, one per 48 KB chunk. groupbox.py carries the
+ // nonce-collision arithmetic that makes a random 96-bit nonce fine at that rate.
+ upload: new TextEncoder().encode('meshbay:upload:v1'),
+ // The group's chat epoch keys, on their way to a member.
chat_keys: new TextEncoder().encode('meshbay:chat_keys:v1'),
};