Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
29 lines
1.3 KiB
Rust
29 lines
1.3 KiB
Rust
use ed25519_dalek::{Signature, VerifyingKey};
|
|
use shared::protocol::HeartbeatRequest;
|
|
use std::collections::BTreeMap;
|
|
|
|
pub fn verify_signature(
|
|
pub_key_bytes: &[u8],
|
|
req: &HeartbeatRequest,
|
|
) -> Result<(), Box<dyn std::error::Error>> {
|
|
let pk = VerifyingKey::from_bytes(
|
|
&pub_key_bytes.try_into().map_err(|_| "invalid pubkey")?,
|
|
)?;
|
|
let sig_bytes = hex::decode(&req.signature)?;
|
|
let sig = Signature::from_slice(&sig_bytes)?;
|
|
|
|
// Build canonical JSON with BTreeMap so keys are sorted alphabetically,
|
|
// matching the JS client's JSON.stringify(obj, Object.keys(obj).sort()).
|
|
// Sorted order: entropyData, fingerprint, prevHash, sessionId, stackState, timestamp
|
|
let mut payload: BTreeMap<&str, serde_json::Value> = BTreeMap::new();
|
|
payload.insert("entropyData", serde_json::to_value(&req.entropy_data)?);
|
|
payload.insert("fingerprint", serde_json::to_value(&req.fingerprint)?);
|
|
payload.insert("prevHash", serde_json::json!(req.prev_hash));
|
|
payload.insert("sessionId", serde_json::json!(req.session_id));
|
|
payload.insert("stackState", serde_json::to_value(&req.stack_state)?);
|
|
payload.insert("timestamp", serde_json::json!(req.timestamp));
|
|
let message = serde_json::to_string(&payload)?;
|
|
|
|
pk.verify_strict(message.as_bytes(), &sig)?;
|
|
Ok(())
|
|
} |