An enrolling node signs its request with the identity it just generated, so the mesh can tell it from anyone who knows its public key (novox/hq issue 083)

This commit is contained in:
2026-09-22 14:33:31 +02:00
parent eaebae7b36
commit 406a5559b0
3 changed files with 34 additions and 3 deletions
+13
View File
@@ -0,0 +1,13 @@
package link
import "testing"
// The bytes a node signs when it enrols. The mesh builds the same bytes to check the signature, in
// another repository; this known answer is repeated in its test, so the two cannot drift apart
// without one of them failing (novox/hq issue 083).
func TestWhatAnEnrollingNodeSignsIsFixed(t *testing.T) {
got := string(EnrolProof("s", []byte{1, 2, 3}, "o", "e", "v"))
if want := "novox-mesh-enrol\x00s\x00AQID\x00o\x00e\x00v"; got != want {
t.Fatalf("the enrolment proof's message changed: %q, want %q", got, want)
}
}