Review of 083: finishing an enrolment whose token was spent takes proof of the key's private half, a live lease and a first delivery — a public key alone cannot replay a spent token; shutdown leaves held messages for the broker; identical builds supersede; what is held leaves room in the prefetch
This commit is contained in:
@@ -60,8 +60,20 @@ func (e Enrolment) Enrol(ctx context.Context, request EnrolRequest) (reply Enrol
|
||||
// token, so the two cannot be one transaction; a failure between them used to leave a spent
|
||||
// token and a node with no key, which the host — making new keys on every attempt — could not
|
||||
// recover from. Every write below overwrites, so an attempt made again is safe.
|
||||
// A proof that does not verify is refused outright: it was made with another key, or for
|
||||
// another request. One that verifies lets this presenter finish an enrolment whose token it
|
||||
// already spent — never a request the broker handed over a second time, which may already
|
||||
// have been answered.
|
||||
proven := false
|
||||
if len(request.Proof) > 0 {
|
||||
if !ed25519.Verify(public, EnrolProof(secret, public, request.OverlayKey, request.SealingKey,
|
||||
request.ServingKey), request.Proof) {
|
||||
return EnrolReply{}, errors.New("the enrolment's proof does not match the key it presents")
|
||||
}
|
||||
proven = true
|
||||
}
|
||||
by := claimant(public)
|
||||
node, err := e.Inventory.Claim(ctx, secret, by)
|
||||
node, err := e.Inventory.Claim(ctx, secret, by, proven && !request.Redelivered)
|
||||
if err != nil {
|
||||
return EnrolReply{}, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user