fix: add resolve_token to TokenStore for E2E handshake - #103
Merged
Conversation
The E2E handshake needs the raw pairing token to derive the HKDF handshake key, but TokenStore only stored SHA-256 hashes. This adds: - token field to _StoredRecord (Fernet-encrypted at rest) - resolve_token(name) method to retrieve raw token - Graceful fallback to legacy auth when token not available (nodes paired before this fix get plaintext auth until re-paired) Also fixes auth logic: E2E proof verification now correctly skips the legacy token_store.validate() call instead of overwriting is_valid=True with the (empty) auth.token. Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the
'TokenStore' object has no attribute 'resolve_token'crash that prevented E2E handshakes from completing. Node connections now work again.Root cause
The E2E handshake needs the raw pairing token to derive the HKDF handshake key, but
TokenStoreonly stored SHA-256 hashes. Two bugs:server.py:510calledtoken_store.resolve_token()— a method that didn't existtoken_store.validate()call (which fails becauseauth.tokenis empty in E2E mode)Changes
tokens.py: Addtokenfield to_StoredRecord(Fernet-encrypted at rest). Addresolve_token(name)method. Backward-compatible — old token stores without the field load fine.wsserver/server.py: Callresolve_tokento get the raw token for HKDF. Graceful fallback to legacy auth when token isn't available (nodes paired before this fix). Fix auth logic so E2E proof verification correctly skips the legacytoken_store.validate()call.Behavior
e2e_keypair_failed→ connection closed