aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/transport.js
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/transport.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/transport.js54
1 files changed, 42 insertions, 12 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport.js b/packages/meshbay-hub/src/meshbay_hub/static/transport.js
index d636085..18faea1 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/transport.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/transport.js
@@ -129,11 +129,16 @@ class MeshBayTransport {
await channelReady;
+ // The client nonce is what makes the NODE's proof fresh (C3) — without it a
+ // recorded handshake_ack could be replayed by an impersonating peer.
+ this._nonceClient = crypto.getRandomValues(new Uint8Array(32));
+
const reply = await this._sendAndWait({
type: 'handshake',
v: '0.1',
token: jwtToken,
group_id: groupId || '',
+ nonce: window.MeshBayCrypto.b64encode(this._nonceClient),
});
if (reply.type === 'handshake_challenge') {
@@ -190,28 +195,53 @@ class MeshBayTransport {
throw new Error('Node requires GEK proof but no GEK available');
}
- let proof = '';
- if (gekRaw) {
- const offerFp = _extractDtlsFingerprint(this._pc.localDescription.sdp);
- const answerFp = _extractDtlsFingerprint(this._rawAnswerSdp);
- proof = await window.MeshBayCrypto.hmacGEK(gekRaw, reply.nonce, offerFp, answerFp);
- }
+ const C = window.MeshBayCrypto;
+ // Node's answer SDP carries ITS fingerprint; our offer carries ours. Throws
+ // if either is missing rather than proceeding with an unbound proof (L4).
+ const binding = C.webrtcBinding(
+ _extractDtlsFingerprint(this._pc.localDescription.sdp),
+ _extractDtlsFingerprint(this._rawAnswerSdp),
+ );
+ const nonceNode = C.b64decode(reply.nonce);
+ const gid = groupId || '';
+
+ const proof = await C.handshakeProof(
+ gekRaw, 'client', gid, this._nonceClient, nonceNode, binding);
+
const ack = await this._sendAndWait({
type: 'handshake_response',
v: '0.1',
- proof,
+ proof: C.b64encode(proof),
});
if (ack.type !== 'handshake_ack') {
throw new Error('GEK proof rejected: ' + (ack.detail || JSON.stringify(ack)));
}
- return ack;
- }
- if (reply.type !== 'handshake_ack') {
- throw new Error('MNP handshake rejected: ' + (reply.detail || JSON.stringify(reply)));
+ // Authenticate the NODE before trusting anything it says (C3). Until this
+ // ran, node_pk was decorative: a peer that had hijacked signaling could
+ // accept our proof, ignore it, and serve a forged index, chat history and
+ // is_node_admin flag.
+ const expected = await C.handshakeProof(
+ gekRaw, 'node', gid, this._nonceClient, nonceNode, binding);
+ if (!ack.proof || !C.constantTimeEqual(C.b64decode(ack.proof), expected)) {
+ throw new Error('Node failed to prove GEK possession — refusing connection');
+ }
+ const transcript = C.handshakeTranscript(
+ 'node', gid, this._nonceClient, nonceNode, binding);
+ if (!ack.node_pk || !ack.sig
+ || !await C.verifyNodeSignature(ack.node_pk, ack.sig, transcript)) {
+ throw new Error('Node signature invalid — refusing connection');
+ }
+ this.nodePk = ack.node_pk;
+
+ return ack;
}
- return reply;
+ // A node that answers a handshake with anything other than a challenge is not
+ // running the mutual protocol. Accepting a bare handshake_ack here would let a
+ // peer skip proving GEK possession entirely (C3/C6).
+ throw new Error(
+ 'MNP handshake rejected: ' + (reply.detail || `unexpected ${reply.type}`));
}
async fetchIndex() {