mirror of
https://github.com/status-im/status-go.git
synced 2025-01-10 06:36:32 +00:00
605fe40e32
This commit fixes a few issues with communities encryption: Key distribution was disconnected from the community description, this created a case where the key would arrive after the community description and that would result in the client thinking that it was kicked. To overcome this, we added a message that signals the user that is kicked. Also, we distribute the key with the community description so that there's no more issues with timing. This is a bit expensive for large communities, and it will require some further optimizations. Key distribution is now also connected to the request to join response, so there are no timing issues. Fixes an issue with key distribution (race condition) where the community would be modified before being compared, resulting in a comparison of two identical communities, which would result in no key being distributed. This commit only partially address the issue.
112 lines
3.7 KiB
Go
112 lines
3.7 KiB
Go
package communities
|
|
|
|
import (
|
|
"github.com/golang/protobuf/proto"
|
|
|
|
"go.uber.org/zap"
|
|
|
|
"github.com/status-im/status-go/eth-node/types"
|
|
"github.com/status-im/status-go/protocol/protobuf"
|
|
)
|
|
|
|
type DescriptionEncryptor interface {
|
|
encryptCommunityDescription(community *Community, d *protobuf.CommunityDescription) (string, []byte, error)
|
|
encryptCommunityDescriptionChannel(community *Community, channelID string, d *protobuf.CommunityDescription) (string, []byte, error)
|
|
decryptCommunityDescription(keyIDSeqNo string, d []byte) (*DecryptCommunityResponse, error)
|
|
}
|
|
|
|
// Encrypts members and chats
|
|
func encryptDescription(encryptor DescriptionEncryptor, community *Community, description *protobuf.CommunityDescription) error {
|
|
description.PrivateData = make(map[string][]byte)
|
|
|
|
for channelID, channel := range description.Chats {
|
|
if !community.channelEncrypted(channelID) {
|
|
continue
|
|
}
|
|
|
|
descriptionToEncrypt := &protobuf.CommunityDescription{
|
|
Chats: map[string]*protobuf.CommunityChat{
|
|
channelID: proto.Clone(channel).(*protobuf.CommunityChat),
|
|
},
|
|
}
|
|
|
|
keyIDSeqNo, encryptedDescription, err := encryptor.encryptCommunityDescriptionChannel(community, channelID, descriptionToEncrypt)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Set private data and cleanup unencrypted channel's members
|
|
description.PrivateData[keyIDSeqNo] = encryptedDescription
|
|
channel.Members = make(map[string]*protobuf.CommunityMember)
|
|
}
|
|
|
|
if community.Encrypted() {
|
|
descriptionToEncrypt := &protobuf.CommunityDescription{
|
|
Members: description.Members,
|
|
Chats: description.Chats,
|
|
}
|
|
|
|
keyIDSeqNo, encryptedDescription, err := encryptor.encryptCommunityDescription(community, descriptionToEncrypt)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Set private data and cleanup unencrypted members and chats
|
|
description.PrivateData[keyIDSeqNo] = encryptedDescription
|
|
description.Members = make(map[string]*protobuf.CommunityMember)
|
|
description.Chats = make(map[string]*protobuf.CommunityChat)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
type CommunityPrivateDataFailedToDecrypt struct {
|
|
GroupID []byte
|
|
KeyID []byte
|
|
}
|
|
|
|
// Decrypts members and chats
|
|
func decryptDescription(id types.HexBytes, encryptor DescriptionEncryptor, description *protobuf.CommunityDescription, logger *zap.Logger) ([]*CommunityPrivateDataFailedToDecrypt, error) {
|
|
if len(description.PrivateData) == 0 {
|
|
return nil, nil
|
|
}
|
|
|
|
var failedToDecrypt []*CommunityPrivateDataFailedToDecrypt
|
|
|
|
for keyIDSeqNo, encryptedDescription := range description.PrivateData {
|
|
decryptedDescriptionResponse, err := encryptor.decryptCommunityDescription(keyIDSeqNo, encryptedDescription)
|
|
if decryptedDescriptionResponse != nil && !decryptedDescriptionResponse.Decrypted {
|
|
failedToDecrypt = append(failedToDecrypt, &CommunityPrivateDataFailedToDecrypt{GroupID: id, KeyID: decryptedDescriptionResponse.KeyID})
|
|
}
|
|
if err != nil {
|
|
// ignore error, try to decrypt next data
|
|
logger.Debug("failed to decrypt community private data", zap.String("keyIDSeqNo", keyIDSeqNo), zap.Error(err))
|
|
continue
|
|
}
|
|
decryptedDescription := decryptedDescriptionResponse.Description
|
|
|
|
for pk, member := range decryptedDescription.Members {
|
|
if description.Members == nil {
|
|
description.Members = make(map[string]*protobuf.CommunityMember)
|
|
}
|
|
description.Members[pk] = member
|
|
}
|
|
|
|
for id, decryptedChannel := range decryptedDescription.Chats {
|
|
if description.Chats == nil {
|
|
description.Chats = make(map[string]*protobuf.CommunityChat)
|
|
}
|
|
|
|
if channel := description.Chats[id]; channel != nil {
|
|
if len(channel.Members) == 0 {
|
|
channel.Members = decryptedChannel.Members
|
|
}
|
|
} else {
|
|
description.Chats[id] = decryptedChannel
|
|
}
|
|
}
|
|
}
|
|
|
|
return failedToDecrypt, nil
|
|
}
|