mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-02 17:31:39 +00:00
feature/1121 implement ucan validation (#1176)
- **refactor: remove unused auth components** - **refactor: improve devbox configuration and deployment process** - **refactor: improve devnet and testnet setup** - **fix: update templ version to v0.2.778** - **refactor: rename pkl/net.matrix to pkl/matrix.net** - **refactor: migrate webapp components to nebula** - **refactor: protobuf types** - **chore: update dependencies for improved security and stability** - **feat: implement landing page and vault gateway servers** - **refactor: Migrate data models to new module structure and update related files** - **feature/1121-implement-ucan-validation** - **refactor: Replace hardcoded constants with model types in attns.go** - **feature/1121-implement-ucan-validation** - **chore: add origin Host struct and update main function to handle multiple hosts** - **build: remove unused static files from dwn module** - **build: remove unused static files from dwn module** - **refactor: Move DWN models to common package** - **refactor: move models to pkg/common** - **refactor: move vault web app assets to embed module** - **refactor: update session middleware import path** - **chore: configure port labels and auto-forwarding behavior** - **feat: enhance devcontainer configuration** - **feat: Add UCAN middleware for Echo with flexible token validation** - **feat: add JWT middleware for UCAN authentication** - **refactor: update package URI and versioning in PklProject files** - **fix: correct sonr.pkl import path** - **refactor: move JWT related code to auth package** - **feat: introduce vault configuration retrieval and management** - **refactor: Move vault components to gateway module and update file paths** - **refactor: remove Dexie and SQLite database implementations** - **feat: enhance frontend with PWA features and WASM integration** - **feat: add Devbox features and streamline Dockerfile** - **chore: update dependencies to include TigerBeetle** - **chore(deps): update go version to 1.23** - **feat: enhance devnet setup with PATH environment variable and updated PWA manifest** - **fix: upgrade tigerbeetle-go dependency and remove indirect dependency** - **feat: add PostgreSQL support to devnet and testnet deployments** - **refactor: rename keyshare cookie to token cookie** - **feat: upgrade Go version to 1.23.3 and update dependencies** - **refactor: update devnet and testnet configurations** - **feat: add IPFS configuration for devnet** - **I'll help you update the ipfs.config.pkl to include all the peers from the shell script. Here's the updated configuration:** - **refactor: move mpc package to crypto directory** - **feat: add BIP32 support for various cryptocurrencies** - **feat: enhance ATN.pkl with additional capabilities** - **refactor: simplify smart account and vault attenuation creation** - **feat: add new capabilities to the Attenuation type** - **refactor: Rename MPC files for clarity and consistency** - **feat: add DIDKey support for cryptographic operations** - **feat: add devnet and testnet deployment configurations** - **fix: correct key derivation in bip32 package** - **refactor: rename crypto/bip32 package to crypto/accaddr** - **fix: remove duplicate indirect dependency** - **refactor: move vault package to root directory** - **refactor: update routes for gateway and vault** - **refactor: remove obsolete web configuration file** - **refactor: remove unused TigerBeetle imports and update host configuration** - **refactor: adjust styles directory path** - **feat: add broadcastTx and simulateTx functions to gateway** - **feat: add PinVault handler**
This commit is contained in:
@@ -0,0 +1,187 @@
|
||||
package mpc
|
||||
|
||||
import (
|
||||
"crypto/ecdsa"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
"github.com/onsonr/sonr/crypto/core/protocol"
|
||||
"github.com/onsonr/sonr/crypto/tecdsa/dklsv1"
|
||||
"golang.org/x/crypto/sha3"
|
||||
)
|
||||
|
||||
var ErrInvalidKeyshareRole = errors.New("invalid keyshare role")
|
||||
|
||||
type Role int
|
||||
|
||||
const (
|
||||
RoleUnknown Role = iota
|
||||
RoleUser
|
||||
RoleValidator
|
||||
)
|
||||
|
||||
func (r Role) IsUser() bool {
|
||||
return r == RoleUser
|
||||
}
|
||||
|
||||
func (r Role) IsValidator() bool {
|
||||
return r == RoleValidator
|
||||
}
|
||||
|
||||
// Message is the protocol.Message that is used for MPC
|
||||
type Message *protocol.Message
|
||||
|
||||
type Signature *curves.EcdsaSignature
|
||||
|
||||
// RefreshFunc is the type for the refresh function
|
||||
type RefreshFunc interface {
|
||||
protocol.Iterator
|
||||
}
|
||||
|
||||
// SignFunc is the type for the sign function
|
||||
type SignFunc interface {
|
||||
protocol.Iterator
|
||||
}
|
||||
|
||||
type ValKeyshare struct {
|
||||
Message Message `json:"message"`
|
||||
Role int `json:"role"` // 1 for validator, 2 for user
|
||||
PublicKey []byte `json:"public-key"`
|
||||
}
|
||||
|
||||
func NewValKeyshare(msg Message) (*ValKeyshare, error) {
|
||||
valShare, err := dklsv1.DecodeAliceDkgResult(msg)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &ValKeyshare{
|
||||
Message: msg,
|
||||
Role: 1,
|
||||
PublicKey: valShare.PublicKey.ToAffineUncompressed(),
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetPayloads() map[string][]byte {
|
||||
return v.Message.Payloads
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetMetadata() map[string]string {
|
||||
return v.Message.Metadata
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetPublicKey() []byte {
|
||||
return v.PublicKey
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetProtocol() string {
|
||||
return v.Message.Protocol
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetRole() int32 {
|
||||
return int32(v.Role)
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) GetVersion() uint32 {
|
||||
return uint32(v.Message.Version)
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) ECDSAPublicKey() (*ecdsa.PublicKey, error) {
|
||||
return ComputeEcdsaPublicKey(v.PublicKey)
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) ExtractMessage() *protocol.Message {
|
||||
return &protocol.Message{
|
||||
Payloads: v.GetPayloads(),
|
||||
Metadata: v.GetMetadata(),
|
||||
Protocol: v.GetProtocol(),
|
||||
Version: uint(v.GetVersion()),
|
||||
}
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) RefreshFunc() (RefreshFunc, error) {
|
||||
curve := curves.K256()
|
||||
return dklsv1.NewAliceRefresh(curve, v.ExtractMessage(), protocol.Version1)
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) SignFunc(msg []byte) (SignFunc, error) {
|
||||
curve := curves.K256()
|
||||
return dklsv1.NewAliceSign(curve, sha3.New256(), msg, v.ExtractMessage(), protocol.Version1)
|
||||
}
|
||||
|
||||
func (v *ValKeyshare) Marshal() ([]byte, error) {
|
||||
return json.Marshal(v.Message)
|
||||
}
|
||||
|
||||
type UserKeyshare struct {
|
||||
Message Message `json:"message"` // BobOutput
|
||||
Role int `json:"role"` // 2 for user, 1 for validator
|
||||
PublicKey []byte `json:"public-key"`
|
||||
}
|
||||
|
||||
func NewUserKeyshare(msg Message) (*UserKeyshare, error) {
|
||||
out, err := dklsv1.DecodeBobDkgResult(msg)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &UserKeyshare{
|
||||
Message: msg,
|
||||
Role: 2,
|
||||
PublicKey: out.PublicKey.ToAffineUncompressed(),
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetPayloads() map[string][]byte {
|
||||
return u.Message.Payloads
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetMetadata() map[string]string {
|
||||
return u.Message.Metadata
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetPublicKey() []byte {
|
||||
return u.PublicKey
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetProtocol() string {
|
||||
return u.Message.Protocol
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetRole() int32 {
|
||||
return int32(u.Role)
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) GetVersion() uint32 {
|
||||
return uint32(u.Message.Version)
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) ECDSAPublicKey() (*ecdsa.PublicKey, error) {
|
||||
return ComputeEcdsaPublicKey(u.PublicKey)
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) ExtractMessage() *protocol.Message {
|
||||
return &protocol.Message{
|
||||
Payloads: u.GetPayloads(),
|
||||
Metadata: u.GetMetadata(),
|
||||
Protocol: u.GetProtocol(),
|
||||
Version: uint(u.GetVersion()),
|
||||
}
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) RefreshFunc() (RefreshFunc, error) {
|
||||
curve := curves.K256()
|
||||
return dklsv1.NewBobRefresh(curve, u.ExtractMessage(), protocol.Version1)
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) SignFunc(msg []byte) (SignFunc, error) {
|
||||
curve := curves.K256()
|
||||
return dklsv1.NewBobSign(curve, sha3.New256(), msg, u.ExtractMessage(), protocol.Version1)
|
||||
}
|
||||
|
||||
func (u *UserKeyshare) Marshal() ([]byte, error) {
|
||||
jsonBytes, err := json.Marshal(u.Message)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return jsonBytes, nil
|
||||
}
|
||||
Reference in New Issue
Block a user