add files

This commit is contained in:
root committed 2025-08-16 15:08:00 +00:00
1 parent 4b06cd8a77
commit 8f2efee524
8 files changed
+291 -92

No files matched your search

-4
View File
@@ -81,7 +81,6 @@ async def platform_metadata():
}
# Legacy index and favicon
@router.get("/")
async def index_root():
return PlainTextResponse("MY Network Node", status_code=200)
@@ -91,7 +90,6 @@ async def favicon():
return PlainTextResponse("", status_code=204)
# Legacy node endpoints
@router.get("/api/v1/node")
async def v1_node():
from app.core.crypto import get_ed25519_manager
@@ -105,7 +103,6 @@ async def v1_node_friendly():
return PlainTextResponse(f"Node ID: {cm.node_id}\nIndexer height: 0\nServices: none\n")
# Legacy auth endpoints
@router.post("/api/v1/auth.twa")
async def v1_auth_twa(payload: dict):
user_ref = payload.get("user") or {}
@@ -141,7 +138,6 @@ async def v1_storage_upload(file: UploadFile = File(...)):
file_path = os.path.join(backend.files_path, file_hash)
async with aiofiles.open(file_path, 'wb') as f:
await f.write(data)
# Возвращаем hash без записи ORM, чтобы избежать конфликтов схем
return {"hash": file_hash}
except HTTPException:
raise
+1 -8
View File
@@ -20,12 +20,10 @@ router = APIRouter(prefix="/api/node", tags=["node-communication"])
async def validate_node_request(request: Request) -> Dict[str, Any]:
"""Валидация межузлового запроса с обязательной проверкой подписи"""
# Заголовки
required_headers = ["x-node-communication", "x-node-id", "x-node-public-key", "x-node-signature"]
for header in required_headers:
if header not in request.headers:
raise HTTPException(status_code=400, detail=f"Missing required header: {header}")
if request.headers.get("x-node-communication") != "true":
raise HTTPException(status_code=400, detail="Not a valid inter-node communication")
@@ -35,18 +33,15 @@ async def validate_node_request(request: Request) -> Dict[str, Any]:
node_id = request.headers.get("x-node-id")
public_key = request.headers.get("x-node-public-key")
# Тело запроса
body = await request.body()
if not body:
raise HTTPException(status_code=400, detail="Empty message body")
# JSON
try:
message_data = json.loads(body.decode())
except json.JSONDecodeError:
raise HTTPException(status_code=400, detail="Invalid JSON in request body")
# Anti-replay (необязательно для обратной совместимости)
# Optional anti-replay
try:
ts = message_data.get("timestamp")
nonce = message_data.get("nonce")
@@ -62,10 +57,8 @@ async def validate_node_request(request: Request) -> Dict[str, Any]:
raise HTTPException(status_code=400, detail="replay detected")
await cache.set(cache_key, True, ttl=600)
except Exception:
# ignore for backward compatibility
pass
# Подпись
is_valid = crypto_manager.verify_signature(message_data, signature, public_key)
if not is_valid:
logger.warning(f"Invalid signature from node {node_id}")