mirror of
https://github.com/jcreek/CosmicClash.git
synced 2026-09-11 00:14:00 +00:00
feat: verify allocated join authorisations with hmac
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
package domain
|
||||
|
||||
import (
|
||||
"crypto/hmac"
|
||||
"crypto/sha256"
|
||||
"fmt"
|
||||
"time"
|
||||
)
|
||||
@@ -29,6 +31,18 @@ func SignJoinAuthorisation(auth JoinAuthorisation, sign func([]byte) ([]byte, er
|
||||
return SignedJoinAuthorisation{Authorisation: auth, Signature: append([]byte(nil), signature...)}, nil
|
||||
}
|
||||
|
||||
// SignJoinAuthorisationHMAC is the interoperable production profile used by
|
||||
// the Godot allocated server. The key is mounted out-of-band; the signed
|
||||
// bytes remain the same canonical claim bytes used by the generic signer.
|
||||
func SignJoinAuthorisationHMAC(auth JoinAuthorisation, key []byte) (SignedJoinAuthorisation, error) {
|
||||
if len(key) == 0 {
|
||||
return SignedJoinAuthorisation{}, ErrJoinAuthorisation
|
||||
}
|
||||
mac := hmac.New(sha256.New, key)
|
||||
_, _ = mac.Write(JoinAuthorisationBytes(auth))
|
||||
return SignedJoinAuthorisation{Authorisation: auth, Signature: mac.Sum(nil)}, nil
|
||||
}
|
||||
|
||||
func (r *RankedConnections) AdmitSigned(signed SignedJoinAuthorisation, verify func([]byte, []byte) bool, now time.Time) (uint64, error) {
|
||||
if len(signed.Signature) == 0 || verify == nil || !verify(JoinAuthorisationBytes(signed.Authorisation), signed.Signature) {
|
||||
return 0, ErrJoinAuthorisation
|
||||
|
||||
Reference in New Issue
Block a user