Better websocket

This commit is contained in:
2026-08-27 16:18:19 +02:00
parent 02a444d6ed
commit a4d675bda9
10 changed files with 141 additions and 142 deletions
+30 -44
View File
@@ -3,10 +3,9 @@ use std::{
time::{SystemTime, UNIX_EPOCH},
};
use axum::extract::ws::WebSocket;
use ed25519_dalek::{Signer, VerifyingKey};
use crate::server::Server;
use crate::{server::Server, ws::EnclaveWebSocket};
use super::*;
use crate::server::UserConnections;
@@ -14,23 +13,21 @@ use crate::server::UserConnections;
impl UserConnections {
pub async fn initialize(
server: &Arc<Server>,
mut socket: WebSocket,
) -> anyhow::Result<(WebSocket, VerifyingKey, ClientMeta)> {
socket: Arc<EnclaveWebSocket>,
) -> anyhow::Result<(Arc<EnclaveWebSocket>, VerifyingKey, ClientMeta)> {
let Some(ServerMethod::Initialize {
public_key: public_key_string,
signature,
timestamp,
hostname,
}) = read_socket(&mut socket).await?
}) = socket.read().await?
else {
send_socket(
&mut socket,
&ClientMethod::Error {
socket
.send(&ClientMethod::Error {
error: Cow::Borrowed("Initialization required"),
},
)
.await?;
})
.await?;
return Err(anyhow::anyhow!(
"Failed to initialize: Client sent the wrong method"
@@ -40,23 +37,20 @@ impl UserConnections {
let server_timestamp = SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis() as u64;
if server_timestamp.saturating_sub(timestamp) > 2000 {
send_socket(
&mut socket,
&ClientMethod::Error {
socket
.send(&ClientMethod::Error {
error: Cow::Borrowed(
"Timestamp doesn't match, make sure it's in secs and is (<= 2secs)",
),
},
)
.await?;
})
.await?;
return Err(anyhow::anyhow!("Client tampstamp wasn't correct"));
}
if hostname != server.config.public_hostname || !server.config.hostnames.contains(&hostname)
{
send_socket(
&mut socket,
socket.send(
&ClientMethod::Error {
error: Cow::Owned(format!("Invalid Hostname, to avoid man-in-the-middle attacks, please use the correct hostname: {}", server.config.public_hostname)),
},
@@ -67,13 +61,11 @@ impl UserConnections {
}
let Ok(public_key) = crate::crypto::from_string(&public_key_string) else {
send_socket(
&mut socket,
&ClientMethod::Error {
socket
.send(&ClientMethod::Error {
error: Cow::Borrowed("Invalid public key"),
},
)
.await?;
})
.await?;
return Err(anyhow::anyhow!("Invalid public key"));
};
@@ -85,21 +77,18 @@ impl UserConnections {
)
.is_err()
{
send_socket(
&mut socket,
&ClientMethod::Error {
socket
.send(&ClientMethod::Error {
error: Cow::Borrowed("Invalid signature"),
},
)
.await?;
})
.await?;
return Err(anyhow::anyhow!("Invalid signature"));
}
{
send_socket(
&mut socket,
&ClientMethod::Initialized {
socket
.send(&ClientMethod::Initialized {
public_key: crate::crypto::to_string(&server.key.verifying_key()),
signature: crate::crypto::to_string_sig(&server.key.sign(
format!("{server_timestamp}@{hostname}@{public_key_string}").as_bytes(),
@@ -107,19 +96,16 @@ impl UserConnections {
timestamp: server_timestamp,
hostname,
},
)
.await?;
})
.await?;
}
let Some(ServerMethod::Meta(meta)) = read_socket(&mut socket).await? else {
send_socket(
&mut socket,
&ClientMethod::Error {
let Some(ServerMethod::Meta(meta)) = socket.read().await? else {
socket
.send(&ClientMethod::Error {
error: Cow::Borrowed("Expected meta"),
},
)
.await?;
})
.await?;
return Err(anyhow::anyhow!(
"Expected meta, client called another method"