From f0248975908ad670fa8a820f865bf22ea8d0172d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 13 Aug 2026 03:56:30 +0200 Subject: feat: Phase 12 — P2P crypto material, password split, node Ed25519 auth MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Baseline commit capturing in-progress Phase 12 work that was already present in the working tree (uncommitted) before the Phase 11.5 security remediation begins. Committed as-is, without review or modification, so that remediation changes arrive as a separable diff. Contents: BundleStore (P2P GEK + keypair bundles), password split (auth_key / bundle_key), node Ed25519 auth (POST /v1/nodes/auth, node-scoped JWT), GEK-HMAC handshake proof with DTLS channel binding, Ed25519 admin challenge-response, node local admin UI rewrite, browser key persistence. Not authored in this session — captured to establish a baseline. Co-Authored-By: Claude Opus 5 --- packages/meshbay-hub/src/meshbay_hub/static/app.js | 551 ++++++++++++++++----- .../meshbay-hub/src/meshbay_hub/static/crypto.js | 16 + .../meshbay-hub/src/meshbay_hub/static/i18n.js | 19 +- .../src/meshbay_hub/static/keyderive.js | 127 ++++- .../meshbay-hub/src/meshbay_hub/static/style.css | 192 ++++++- .../src/meshbay_hub/static/transport.js | 178 ++++++- 6 files changed, 907 insertions(+), 176 deletions(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/app.js b/packages/meshbay-hub/src/meshbay_hub/static/app.js index d8f9df5..ddff928 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/app.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/app.js @@ -66,6 +66,58 @@ async function getAllCachedIndexes() { // ── Auth persistence ───────────────────────────────────────────────────────── let _sessionKeys = null; +let _bundleKey = null; +let _pendingBundlePush = null; + +function _openKeyDB() { + return new Promise((resolve, reject) => { + const req = indexedDB.open('meshbay_keys', 1); + req.onupgradeneeded = () => req.result.createObjectStore('k'); + req.onsuccess = () => resolve(req.result); + req.onerror = () => reject(req.error); + }); +} +async function _storeBundleKey(key) { + try { + const db = await _openKeyDB(); + const tx = db.transaction('k', 'readwrite'); + tx.objectStore('k').put(key, 'bk'); + await new Promise(r => { tx.oncomplete = r; }); + db.close(); + } catch {} +} +async function _loadBundleKey() { + try { + const db = await _openKeyDB(); + const tx = db.transaction('k', 'readonly'); + const g = tx.objectStore('k').get('bk'); + const val = await new Promise(r => { g.onsuccess = () => r(g.result); }); + db.close(); + return val || null; + } catch { return null; } +} +async function _clearKeyDB() { + try { + const db = await _openKeyDB(); + const tx = db.transaction('k', 'readwrite'); + tx.objectStore('k').clear(); + await new Promise(r => { tx.oncomplete = r; }); + db.close(); + } catch {} +} +function _saveSessionKeys() { + try { + if (_sessionKeys) sessionStorage.setItem('meshbay_sk', JSON.stringify(_sessionKeys)); + } catch {} +} +function _restoreSessionKeys() { + try { + if (!_sessionKeys) { + const sk = sessionStorage.getItem('meshbay_sk'); + if (sk) _sessionKeys = JSON.parse(sk); + } + } catch {} +} function loadAuth() { try { @@ -81,6 +133,10 @@ function saveAuth(auth) { } else { localStorage.removeItem(AUTH_KEY); _sessionKeys = null; + _bundleKey = null; + _pendingBundlePush = null; + _clearKeyDB(); + try { sessionStorage.removeItem('meshbay_sk'); } catch {} } } @@ -139,9 +195,74 @@ function navigate(path) { const AuthContext = createContext(null); function useAuth() { return useContext(AuthContext); } +// ── User Menu ──────────────────────────────────────────────────────────────── + +function UserMenu({ user, theme, onThemeChange, onLogout }) { + const [open, setOpen] = useState(false); + const [langOpen, setLangOpen] = useState(false); + const ref = useRef(null); + + useEffect(() => { + if (!open) return; + const close = (e) => { + if (ref.current && !ref.current.contains(e.target)) setOpen(false); + }; + document.addEventListener('click', close); + return () => document.removeEventListener('click', close); + }, [open]); + + const resolved = resolveTheme(theme); + + return html` +
+ + ${open && html` +
+
+ ${user.username[0].toUpperCase()} +
+
${user.username}
+
${user.role || 'user'}
+
+
+
+ + ${langOpen && LOCALES.map(l => html` + + `)} + + +
+ +
+ `} +
+ `; +} + // ── Nav ────────────────────────────────────────────────────────────────────── -function Nav({ user, theme, onThemeToggle, onLogout, onMenuToggle, unreadCount }) { +function Nav({ user, theme, onThemeChange, onLogout, onMenuToggle, unreadCount }) { return html`