feat(wire-format): per-document XChaCha announce and lock (TEC-2936) - #32
Merged
Merged
Conversation
Clients declare the wire ciphers they can read on auth. With WIRE_FORMAT_TARGET set to xchacha the server announces xchacha for a room once every socket in it can read it, locks the document (a DocumentWireFormat row, kept separate from DocumentMeta so that row's $setOnInsert fields are never stranded by an auth-time upsert), sweeps any socket that cannot read it, and tells the incumbents over /document/wire_format so a long-lived tab converts without a re-auth. A locked document refuses a non-capable client with 426 WIRE_FORMAT_UNSUPPORTED before any session bookkeeping, including on a rotation-cutover re-auth, where the prior room is left explicitly. The disconnect handler ratchets a room whose last ECIES-only socket just left. With the target unset the server announces ECIES everywhere and never locks; existing locks keep refusing. Infrastructure failures degrade instead of failing the auth: a rejected cross-instance enumeration or lock write announces ECIES and takes no lock, and a failed post-lock sweep is logged without suppressing the event. Refusals are logged once per document per minute with a capped view of the declared list. The ratchet is skipped while the process is draining, since io.close() fires disconnecting for every socket and the reconnect auth after the restart resolves the same state.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clients declare the wire ciphers they can read on auth. With WIRE_FORMAT_TARGET set to xchacha the server announces xchacha for a room once every socket in it can read it, locks the document (a DocumentWireFormat row, kept separate from DocumentMeta so that row's $setOnInsert fields are never stranded by an auth-time upsert), sweeps any socket that cannot read it, and tells the incumbents over /document/wire_format so a long-lived tab converts without a re-auth. A locked document refuses a non-capable client with 426 WIRE_FORMAT_UNSUPPORTED before any session bookkeeping, including on a rotation-cutover re-auth, where the prior room is left explicitly. The disconnect handler ratchets a room whose last ECIES-only socket just left. With the target unset the server announces ECIES everywhere and never locks; existing locks keep refusing.
Infrastructure failures degrade instead of failing the auth: a rejected cross-instance enumeration or lock write announces ECIES and takes no lock, and a failed post-lock sweep is logged without suppressing the event. Refusals are logged once per document per minute with a capped view of the declared list. The ratchet is skipped while the process is draining, since io.close() fires disconnecting for every socket and the reconnect auth after the restart resolves the same state.