fix: E2E fallback to legacy auth when token unavailable - #104
Merged
Conversation
The E2E handshake needs the raw pairing token to derive the HKDF handshake key, but TokenStore only stored SHA-256 hashes. This adds: - token field to _StoredRecord (Fernet-encrypted at rest) - resolve_token(name) method to retrieve raw token - Graceful fallback to legacy auth when token not available (nodes paired before this fix get plaintext auth until re-paired) Also fixes auth logic: E2E proof verification now correctly skips the legacy token_store.validate() call instead of overwriting is_valid=True with the (empty) auth.token. Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add
resolve_token()toTokenStorefor E2E handshake key derivation, and gracefully fall back to legacy auth when a pre-v0.1.2 paired node has no stored raw token.Why
The E2E PAKE handshake (PR #102) mixes the raw pairing token into the HKDF. Nodes paired before v0.1.2 only have a token hash stored — no raw token. Without this fix, those nodes get
TokenStoreError→hello_err→ disconnected. Now they silently fall back to legacy plaintext-token auth instead.Changes
tokens.py—_StoredRecordgets optionaltokenfield;create_token()stores the raw token; newresolve_token()returns itwsserver/server.py— catchTokenStoreErrorin E2E key exchange → fall back to legacy auth; conditional hello_ack (ECDH params only when E2E is active)