mitm checks
This commit is contained in:
+5
-1
@@ -1,4 +1,4 @@
|
|||||||
use std::path::PathBuf;
|
use std::{collections::HashSet, path::PathBuf};
|
||||||
|
|
||||||
use serde::{Deserialize, Serialize};
|
use serde::{Deserialize, Serialize};
|
||||||
|
|
||||||
@@ -7,6 +7,8 @@ use crate::protocol::ServerMeta;
|
|||||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
pub struct Config {
|
pub struct Config {
|
||||||
pub meta: ServerMeta,
|
pub meta: ServerMeta,
|
||||||
|
pub public_hostname: String,
|
||||||
|
pub hostnames: HashSet<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Config {
|
impl Config {
|
||||||
@@ -16,6 +18,8 @@ impl Config {
|
|||||||
name: "New Server".to_string(),
|
name: "New Server".to_string(),
|
||||||
description: String::new(),
|
description: String::new(),
|
||||||
},
|
},
|
||||||
|
|
||||||
|
hostnames: HashSet::from_iter(["localhost:3000".to_string()]),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -37,6 +37,34 @@ impl UserConnections {
|
|||||||
));
|
));
|
||||||
};
|
};
|
||||||
|
|
||||||
|
let server_timestamp = SystemTime::now().duration_since(UNIX_EPOCH)?.as_secs();
|
||||||
|
|
||||||
|
if server_timestamp - timestamp > 2 {
|
||||||
|
send_socket(
|
||||||
|
&mut socket,
|
||||||
|
&ClientMethod::Error {
|
||||||
|
error: Cow::Borrowed(
|
||||||
|
"Timestamp doesn't match, make sure it's in secs and is (<= 2secs)",
|
||||||
|
),
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
return Err(anyhow::anyhow!("Client tampstamp wasn't correct"));
|
||||||
|
}
|
||||||
|
|
||||||
|
if !server.config.hostnames.contains(&hostname) {
|
||||||
|
send_socket(
|
||||||
|
&mut socket,
|
||||||
|
&ClientMethod::Error {
|
||||||
|
error: Cow::Owned(format!("Invalid Hostname, to avoid man-in-the-middle attacks, please use the correct hostname: {}", server.config.public_hostname)),
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
return Err(anyhow::anyhow!("Client's hostname wasn't correct"));
|
||||||
|
}
|
||||||
|
|
||||||
let Ok(public_key) = crate::signature::from_string(&public_key_string) else {
|
let Ok(public_key) = crate::signature::from_string(&public_key_string) else {
|
||||||
send_socket(
|
send_socket(
|
||||||
&mut socket,
|
&mut socket,
|
||||||
@@ -68,8 +96,6 @@ impl UserConnections {
|
|||||||
}
|
}
|
||||||
|
|
||||||
{
|
{
|
||||||
let timestamp = SystemTime::now().duration_since(UNIX_EPOCH)?.as_secs();
|
|
||||||
|
|
||||||
send_socket(
|
send_socket(
|
||||||
&mut socket,
|
&mut socket,
|
||||||
&ClientMethod::Initialized {
|
&ClientMethod::Initialized {
|
||||||
@@ -79,7 +105,7 @@ impl UserConnections {
|
|||||||
.sign(format!("{timestamp}@{hostname}@{public_key_string}").as_bytes())
|
.sign(format!("{timestamp}@{hostname}@{public_key_string}").as_bytes())
|
||||||
.to_string(),
|
.to_string(),
|
||||||
|
|
||||||
timestamp,
|
timestamp: server_timestamp,
|
||||||
hostname,
|
hostname,
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user