new fixes
This commit is contained in:
1 parent
075a35b441
commit
ae14782da4
12 files changed
+412
-23
No files matched your search
@@ -2,6 +2,7 @@ from __future__ import annotations
|
||||
|
||||
import base64
|
||||
import json
|
||||
import os
|
||||
from datetime import datetime
|
||||
from typing import Dict, Any
|
||||
|
||||
@@ -15,6 +16,7 @@ from app.core.models.content_v3 import EncryptedContent, ContentKey, KeyGrant
|
||||
from app.core.network.nodesig import verify_request
|
||||
from app.core.network.guard import check_rate_limit
|
||||
from app.core.models.my_network import KnownNode
|
||||
from app.core.crypto.keywrap import unwrap_dek, KeyWrapError
|
||||
|
||||
|
||||
def _b64(b: bytes) -> str:
|
||||
@@ -60,11 +62,15 @@ async def s_api_v1_keys_request(request):
|
||||
|
||||
# Seal the DEK for recipient using libsodium sealed box
|
||||
try:
|
||||
dek_plain = unwrap_dek(ck.key_ciphertext_b64)
|
||||
import nacl.public
|
||||
pk = nacl.public.PublicKey(base64.b64decode(recipient_box_pub_b64))
|
||||
box = nacl.public.SealedBox(pk)
|
||||
sealed = box.encrypt(base64.b64decode(ck.key_ciphertext_b64))
|
||||
sealed = box.encrypt(dek_plain)
|
||||
sealed_b64 = _b64(sealed)
|
||||
except KeyWrapError as e:
|
||||
make_log("keys", f"unwrap failed: {e}", level="error")
|
||||
return response.json({"error": "KEY_UNWRAP_FAILED"}, status=500)
|
||||
except Exception as e:
|
||||
make_log("keys", f"seal failed: {e}", level="error")
|
||||
return response.json({"error": "SEAL_FAILED"}, status=500)
|
||||
|
||||
@@ -10,8 +10,8 @@ from base58 import b58encode
|
||||
from sanic import response
|
||||
|
||||
from app.core._secrets import hot_pubkey
|
||||
from app.core.crypto.aes_gcm_siv_stream import encrypt_file_to_encf
|
||||
from app.core.crypto.aesgcm_stream import CHUNK_BYTES
|
||||
from app.core.crypto.aes_gcm_stream import encrypt_file_to_encf, CHUNK_BYTES
|
||||
from app.core.crypto.keywrap import wrap_dek, KeyWrapError
|
||||
from app.core.ipfs_client import add_streamed_file
|
||||
from app.core.logger import make_log
|
||||
from app.core.models.content_v3 import EncryptedContent, ContentKey, IpfsSync, ContentIndexItem, UploadSession
|
||||
@@ -79,13 +79,26 @@ async def s_api_v1_upload_tus_hook(request):
|
||||
session.add(us)
|
||||
await session.commit()
|
||||
|
||||
# Read & encrypt by streaming (ENCF v1 / AES-SIV)
|
||||
# Read & encrypt by streaming (ENCF v1 / AES-GCM)
|
||||
# Generate per-content random DEK and salt
|
||||
dek = os.urandom(32)
|
||||
salt = os.urandom(16)
|
||||
key_fpr = b58encode(hot_pubkey).decode() # fingerprint as our node id for now
|
||||
|
||||
# Stream encrypt into IPFS add
|
||||
try:
|
||||
wrapped_dek = wrap_dek(dek)
|
||||
except KeyWrapError as e:
|
||||
make_log("tus-hook", f"Key wrap failed: {e}", level="error")
|
||||
async with db_session() as session:
|
||||
if upload_id:
|
||||
us = await session.get(UploadSession, upload_id)
|
||||
if us:
|
||||
us.state = 'failed'
|
||||
us.error = str(e)
|
||||
await session.commit()
|
||||
return response.json({"ok": False, "error": "KEY_WRAP_FAILED"}, status=500)
|
||||
|
||||
try:
|
||||
with open(file_path, 'rb') as f:
|
||||
result = await add_streamed_file(
|
||||
@@ -122,7 +135,7 @@ async def s_api_v1_upload_tus_hook(request):
|
||||
plain_size_bytes=os.path.getsize(file_path),
|
||||
preview_enabled=preview_enabled,
|
||||
preview_conf=({"duration_ms": dur_ms, "intervals": [[start_ms, start_ms + dur_ms]]} if preview_enabled else {}),
|
||||
aead_scheme="AES_GCM_SIV",
|
||||
aead_scheme="AES_GCM",
|
||||
chunk_bytes=CHUNK_BYTES,
|
||||
salt_b64=_b64(salt),
|
||||
)
|
||||
@@ -131,7 +144,7 @@ async def s_api_v1_upload_tus_hook(request):
|
||||
|
||||
ck = ContentKey(
|
||||
content_id=ec.id,
|
||||
key_ciphertext_b64=_b64(dek), # NOTE: should be wrapped by local KEK; simplified for PoC
|
||||
key_ciphertext_b64=wrapped_dek,
|
||||
key_fingerprint=key_fpr,
|
||||
issuer_node_id=key_fpr,
|
||||
allow_auto_grant=True,
|
||||
|
||||
Reference in new issue
Block a user