This commit is contained in:
root committed 2025-08-18 13:55:35 +00:00
1 parent 8f2efee524
commit b7d1ff5637
3 files changed
+27 -6

No files matched your search

+4 -1
View File
@@ -100,7 +100,10 @@ async def v1_node():
async def v1_node_friendly():
from app.core.crypto import get_ed25519_manager
cm = get_ed25519_manager()
return PlainTextResponse(f"Node ID: {cm.node_id}\nIndexer height: 0\nServices: none\n")
return PlainTextResponse(f"Node ID: {cm.node_id}
Indexer height: 0
Services: none
")
@router.post("/api/v1/auth.twa")
+18
View File
@@ -38,6 +38,24 @@ async def validate_node_request(request: Request) -> Dict[str, Any]:
raise HTTPException(status_code=400, detail="Empty message body")
try:
message_data = json.loads(body.decode())
# Anti-replay: validate timestamp and nonce
try:
ts = message_data.get("timestamp")
nonce = message_data.get("nonce")
if ts:
from datetime import datetime, timezone
now = datetime.now(timezone.utc).timestamp()
if abs(float(ts) - float(now)) > 300:
raise HTTPException(status_code=400, detail="stale timestamp")
if nonce:
cache = await get_cache_manager()
cache_key = f"replay:{node_id}:{nonce}"
if await cache.get(cache_key):
raise HTTPException(status_code=400, detail="replay detected")
await cache.set(cache_key, True, ttl=600)
except Exception as _e:
# For backward compatibility, do not fail hard if fields missing
pass
except json.JSONDecodeError:
raise HTTPException(status_code=400, detail="Invalid JSON in request body")