mitm checks
This commit is contained in:
+5
-1
@@ -1,4 +1,4 @@
|
||||
use std::path::PathBuf;
|
||||
use std::{collections::HashSet, path::PathBuf};
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
@@ -7,6 +7,8 @@ use crate::protocol::ServerMeta;
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct Config {
|
||||
pub meta: ServerMeta,
|
||||
pub public_hostname: String,
|
||||
pub hostnames: HashSet<String>,
|
||||
}
|
||||
|
||||
impl Config {
|
||||
@@ -16,6 +18,8 @@ impl Config {
|
||||
name: "New Server".to_string(),
|
||||
description: String::new(),
|
||||
},
|
||||
|
||||
hostnames: HashSet::from_iter(["localhost:3000".to_string()]),
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -37,6 +37,34 @@ impl UserConnections {
|
||||
));
|
||||
};
|
||||
|
||||
let server_timestamp = SystemTime::now().duration_since(UNIX_EPOCH)?.as_secs();
|
||||
|
||||
if server_timestamp - timestamp > 2 {
|
||||
send_socket(
|
||||
&mut socket,
|
||||
&ClientMethod::Error {
|
||||
error: Cow::Borrowed(
|
||||
"Timestamp doesn't match, make sure it's in secs and is (<= 2secs)",
|
||||
),
|
||||
},
|
||||
)
|
||||
.await?;
|
||||
|
||||
return Err(anyhow::anyhow!("Client tampstamp wasn't correct"));
|
||||
}
|
||||
|
||||
if !server.config.hostnames.contains(&hostname) {
|
||||
send_socket(
|
||||
&mut socket,
|
||||
&ClientMethod::Error {
|
||||
error: Cow::Owned(format!("Invalid Hostname, to avoid man-in-the-middle attacks, please use the correct hostname: {}", server.config.public_hostname)),
|
||||
},
|
||||
)
|
||||
.await?;
|
||||
|
||||
return Err(anyhow::anyhow!("Client's hostname wasn't correct"));
|
||||
}
|
||||
|
||||
let Ok(public_key) = crate::signature::from_string(&public_key_string) else {
|
||||
send_socket(
|
||||
&mut socket,
|
||||
@@ -68,8 +96,6 @@ impl UserConnections {
|
||||
}
|
||||
|
||||
{
|
||||
let timestamp = SystemTime::now().duration_since(UNIX_EPOCH)?.as_secs();
|
||||
|
||||
send_socket(
|
||||
&mut socket,
|
||||
&ClientMethod::Initialized {
|
||||
@@ -79,7 +105,7 @@ impl UserConnections {
|
||||
.sign(format!("{timestamp}@{hostname}@{public_key_string}").as_bytes())
|
||||
.to_string(),
|
||||
|
||||
timestamp,
|
||||
timestamp: server_timestamp,
|
||||
hostname,
|
||||
},
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user