Proper signature management

This commit is contained in:
2026-08-11 23:43:56 -04:00
parent aacb11bc01
commit 019c2888cb
6 changed files with 80 additions and 11 deletions
+25 -6
View File
@@ -1,11 +1,16 @@
use std::sync::Arc;
use axum::extract::ws::WebSocket;
use ed25519_dalek::Signer;
use crate::server::Server;
use super::*;
impl super::Client {
pub async fn initialize(mut socket: WebSocket) -> anyhow::Result<Self> {
pub async fn initialize(server: &Arc<Server>, mut socket: WebSocket) -> anyhow::Result<Self> {
let Some(ServerMethod::Initialize {
public_key,
public_key: public_key_string,
timestamp,
signature,
}) = Client::read_socket(&mut socket).await?
@@ -23,12 +28,26 @@ impl super::Client {
));
};
let public_key = crate::signature::from_string(&public_key_string)?;
if public_key
.verify_strict(
format!("{public_key_string}@{timestamp}@").as_bytes(),
&crate::signature::from_string_sig(&signature)?,
)
.is_ok()
{
return Err(anyhow::anyhow!("Invalid signature"));
}
Client::send_socket(
&mut socket,
ClientMethod::Initialized {
public_key,
timestamp,
signature,
public_key: crate::signature::to_string(&server.key.verifying_key()),
signature: server
.key
.sign(format!("{public_key_string}@{timestamp}").as_bytes())
.to_string(),
},
)
.await?;
@@ -36,7 +55,7 @@ impl super::Client {
Ok(Self {
socket,
meta: super::ClientMeta {},
public_key: String::new(),
public_key,
})
}
}