Repository navigation
feat(terminal): host wraps the session key per link guest - #98
Merged
Merged
Conversation
Invite-link sessions stored the raw session key and handed it to anyone
holding the link or a redeemed short code, so the database or the server
process could decrypt every link-shared terminal. The link now grants
admission only; the host's client wraps the key for each admitted guest,
through the same /invitees path People invites use.
- WS admission through a join grant records the guest in
terminal_session_link_guests and sends the host's socket
{"type":"key_request","user_id":...}.
- grant_invitee, for a user whose admitting grant is still live, stores
the wrapped key and sends that guest's socket {"type":"key_ready"}. No
stranger checks, no invitee row and no push: the guest asked to join,
and an invitee row would outlive a revoked grant.
- my-key answers 202 {"pending": true} to a grant holder with no wrapped
key yet, instead of raw_key. Sessions whose host still sends
session_key_bytes keep getting raw_key for one release.
- Ending a session (end_session, host disconnect, failed create) clears
session_key_bytes and the link-guest rows; migration 054 clears the key
on sessions that already ended.
Frames are key_request/key_ready, matching the other socket frames,
rather than the hyphenated names in the issue.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #96.
Invite-link sessions stored the raw 32-byte session key and
my-keyhanded it back asraw_keyto anyone holding the link token or a redeemed short code. The link now grants admission only. The host's client wraps the key for each admitted guest throughPOST /invitees, the path People invites already use.Flow
my-keywith a valid grant and has no wrapped key yet:202 {"pending": true}.terminal_session_link_guests, in Postgres rather than in process (CLAUDE.md), and sends the host's socket{"type":"key_request","user_id":…}./invitees.grant_inviteesees a live link grant, stores the key and sends that guest's socket{"type":"key_ready"}. It skips the stranger checks, the knock limit, the invitee row and the push, because the guest asked to join. An invitee row would also keep admitting them after their grant was revoked.my-keyagain and getswrapped_key+host_public_key.Users without a live link grant go through
/inviteesexactly as before.Compatibility
session_key_byteskeep gettingraw_keyfor one release. That case used to 500 when no bytes were stored.end_session, host disconnect, failed create) clearssession_key_bytesand the link-guest rows. Migration 054 clears the key on sessions that already ended.raw_keybranch.Note for the client (VoltiusApp/voltius#521)
The frames are
key_request/key_ready, matchingcontrol_update,session_endedand the others, not the hyphenated names in the issues.Frames for a single socket travel over a new per-user channel in
TerminalManager. That struct is already on the single-instance list, so this adds no item to it.Tests
my-keyreturns pending, notraw_key, for a new-style link session (with 202 status)/inviteesfor a link-grant holder creates the key row and the guest then getswrapped_key, even with stranger invites switched off, and no invitee row is written/inviteesfor a teammate with no grant, or whose grant was revoked, still creates an invitee row as beforeraw_keytests still passkey_request, the host wraps, and the guest getskey_ready; the guest never sees the requestcargo clippy --all-targets -- -D warningsandcargo test --all-targets(678) pass locally against Postgres.🤖 Generated with Claude Code