release(v4.6.0): broadcast channels — Signal sender-keys for one-to-many fan-out
Some checks failed
Test / test (push) Has been cancelled
Cross-platform vectors / TypeScript vectors (bun) (push) Has been cancelled
Cross-platform vectors / Kotlin vectors (gradle) (push) Has been cancelled
Docker build and publish / docker (push) Has been cancelled
Publish / publish (push) Has been cancelled
Some checks failed
Test / test (push) Has been cancelled
Cross-platform vectors / TypeScript vectors (bun) (push) Has been cancelled
Cross-platform vectors / Kotlin vectors (gradle) (push) Has been cancelled
Docker build and publish / docker (push) Has been cancelled
Publish / publish (push) Has been cancelled
Lands the broadcast-channel primitive Prism asked for in Docs/shade-feature-request-sender-keys.md. The crypto in @shade/core/sender-keys.ts was already in place; this release wires it up as a first-class app-facing API, adds the persistence schema across all six storage backends (memory, sqlite, indexeddb + encrypted variants), introduces wire type 0x21 in @shade/proto, and ships Prism's three acceptance tests verbatim. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
import { Database } from 'bun:sqlite';
|
||||
import type {
|
||||
BroadcastChannelRecord,
|
||||
BroadcastMemberRecord,
|
||||
IdentityKeyPair,
|
||||
OneTimePreKey,
|
||||
PeerVerification,
|
||||
@@ -13,10 +15,10 @@ import type {
|
||||
import { constantTimeEqual, toBase64 } from '@shade/core';
|
||||
import { KeyManager } from '../crypto/key-manager.js';
|
||||
import {
|
||||
openConfig, openIdentity, openOneTimePreKey, openRetired, openSession,
|
||||
openSignedPreKey, openStreamSensitive, openTrust, sealConfig, sealIdentity,
|
||||
sealOneTimePreKey, sealRetired, sealSession, sealSignedPreKey,
|
||||
sealStreamSensitive, sealTrust,
|
||||
openBroadcastChannelSensitive, openConfig, openIdentity, openOneTimePreKey, openRetired,
|
||||
openSession, openSignedPreKey, openStreamSensitive, openTrust,
|
||||
sealBroadcastChannelSensitive, sealConfig, sealIdentity, sealOneTimePreKey,
|
||||
sealRetired, sealSession, sealSignedPreKey, sealStreamSensitive, sealTrust,
|
||||
} from '../crypto/row-codec.js';
|
||||
|
||||
/**
|
||||
@@ -68,6 +70,14 @@ export class EncryptedSQLiteStorage implements StorageProvider {
|
||||
removePeerVerification: ReturnType<Database['prepare']>;
|
||||
getPeerIdentityVersion: ReturnType<Database['prepare']>;
|
||||
upsertPeerIdentityVersion: ReturnType<Database['prepare']>;
|
||||
saveBroadcastChannel: ReturnType<Database['prepare']>;
|
||||
getBroadcastChannel: ReturnType<Database['prepare']>;
|
||||
listBroadcastChannels: ReturnType<Database['prepare']>;
|
||||
removeBroadcastChannel: ReturnType<Database['prepare']>;
|
||||
removeBroadcastChannelMembers: ReturnType<Database['prepare']>;
|
||||
saveBroadcastMember: ReturnType<Database['prepare']>;
|
||||
getBroadcastMembers: ReturnType<Database['prepare']>;
|
||||
removeBroadcastMember: ReturnType<Database['prepare']>;
|
||||
};
|
||||
|
||||
private constructor(db: Database, km: KeyManager, ownsDb: boolean) {
|
||||
@@ -156,6 +166,24 @@ export class EncryptedSQLiteStorage implements StorageProvider {
|
||||
peer_address TEXT PRIMARY KEY,
|
||||
version INTEGER NOT NULL
|
||||
);
|
||||
CREATE TABLE IF NOT EXISTS broadcast_channels_enc (
|
||||
channel_id TEXT PRIMARY KEY,
|
||||
owner_role TEXT NOT NULL,
|
||||
owner_address TEXT NOT NULL,
|
||||
label TEXT,
|
||||
generation INTEGER NOT NULL,
|
||||
ciphertext BLOB NOT NULL,
|
||||
created_at INTEGER NOT NULL,
|
||||
updated_at INTEGER NOT NULL
|
||||
);
|
||||
CREATE TABLE IF NOT EXISTS broadcast_members_enc (
|
||||
channel_id TEXT NOT NULL,
|
||||
peer_address TEXT NOT NULL,
|
||||
joined_at INTEGER NOT NULL,
|
||||
removed_at INTEGER,
|
||||
PRIMARY KEY (channel_id, peer_address)
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_broadcast_members_enc_channel ON broadcast_members_enc(channel_id);
|
||||
`);
|
||||
}
|
||||
|
||||
@@ -212,6 +240,35 @@ export class EncryptedSQLiteStorage implements StorageProvider {
|
||||
`INSERT INTO peer_identity_versions_enc (peer_address, version) VALUES (?, ?)
|
||||
ON CONFLICT(peer_address) DO UPDATE SET version = excluded.version`,
|
||||
),
|
||||
saveBroadcastChannel: this.db.prepare(
|
||||
`INSERT OR REPLACE INTO broadcast_channels_enc
|
||||
(channel_id, owner_role, owner_address, label, generation,
|
||||
ciphertext, created_at, updated_at)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?)`,
|
||||
),
|
||||
getBroadcastChannel: this.db.prepare(
|
||||
'SELECT * FROM broadcast_channels_enc WHERE channel_id = ?',
|
||||
),
|
||||
listBroadcastChannels: this.db.prepare(
|
||||
'SELECT * FROM broadcast_channels_enc ORDER BY created_at ASC',
|
||||
),
|
||||
removeBroadcastChannel: this.db.prepare(
|
||||
'DELETE FROM broadcast_channels_enc WHERE channel_id = ?',
|
||||
),
|
||||
removeBroadcastChannelMembers: this.db.prepare(
|
||||
'DELETE FROM broadcast_members_enc WHERE channel_id = ?',
|
||||
),
|
||||
saveBroadcastMember: this.db.prepare(
|
||||
`INSERT OR REPLACE INTO broadcast_members_enc
|
||||
(channel_id, peer_address, joined_at, removed_at)
|
||||
VALUES (?, ?, ?, ?)`,
|
||||
),
|
||||
getBroadcastMembers: this.db.prepare(
|
||||
'SELECT channel_id, peer_address, joined_at, removed_at FROM broadcast_members_enc WHERE channel_id = ? ORDER BY joined_at ASC',
|
||||
),
|
||||
removeBroadcastMember: this.db.prepare(
|
||||
'DELETE FROM broadcast_members_enc WHERE channel_id = ? AND peer_address = ?',
|
||||
),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -432,6 +489,88 @@ export class EncryptedSQLiteStorage implements StorageProvider {
|
||||
return next;
|
||||
}
|
||||
|
||||
// ─── Broadcast channels (V4.6) ────────────────────────────
|
||||
|
||||
async saveBroadcastChannel(channel: BroadcastChannelRecord): Promise<void> {
|
||||
const sealed = await sealBroadcastChannelSensitive(this.km, channel.channelId, {
|
||||
chainKey: channel.chainKey,
|
||||
iteration: channel.iteration,
|
||||
signingPublicKey: channel.signingPublicKey,
|
||||
...(channel.signingPrivateKey !== undefined ? { signingPrivateKey: channel.signingPrivateKey } : {}),
|
||||
});
|
||||
this.stmts.saveBroadcastChannel.run(
|
||||
channel.channelId,
|
||||
channel.ownerRole,
|
||||
channel.ownerAddress,
|
||||
channel.label ?? null,
|
||||
channel.generation,
|
||||
sealed,
|
||||
channel.createdAt,
|
||||
channel.updatedAt,
|
||||
);
|
||||
}
|
||||
|
||||
async getBroadcastChannel(channelId: string): Promise<BroadcastChannelRecord | null> {
|
||||
const row = this.stmts.getBroadcastChannel.get(channelId) as BroadcastChannelEncRow | undefined;
|
||||
if (!row) return null;
|
||||
return this.encRowToChannel(row);
|
||||
}
|
||||
|
||||
async listBroadcastChannels(): Promise<BroadcastChannelRecord[]> {
|
||||
const rows = this.stmts.listBroadcastChannels.all() as BroadcastChannelEncRow[];
|
||||
return Promise.all(rows.map((r) => this.encRowToChannel(r)));
|
||||
}
|
||||
|
||||
async removeBroadcastChannel(channelId: string): Promise<void> {
|
||||
this.stmts.removeBroadcastChannelMembers.run(channelId);
|
||||
this.stmts.removeBroadcastChannel.run(channelId);
|
||||
}
|
||||
|
||||
async saveBroadcastMember(member: BroadcastMemberRecord): Promise<void> {
|
||||
this.stmts.saveBroadcastMember.run(
|
||||
member.channelId,
|
||||
member.peerAddress,
|
||||
member.joinedAt,
|
||||
member.removedAt,
|
||||
);
|
||||
}
|
||||
|
||||
async getBroadcastMembers(channelId: string): Promise<BroadcastMemberRecord[]> {
|
||||
const rows = this.stmts.getBroadcastMembers.all(channelId) as BroadcastMemberEncRow[];
|
||||
return rows.map((r) => ({
|
||||
channelId: r.channel_id,
|
||||
peerAddress: r.peer_address,
|
||||
joinedAt: Number(r.joined_at),
|
||||
removedAt: r.removed_at === null || r.removed_at === undefined ? null : Number(r.removed_at),
|
||||
}));
|
||||
}
|
||||
|
||||
async removeBroadcastMember(channelId: string, peerAddress: string): Promise<void> {
|
||||
this.stmts.removeBroadcastMember.run(channelId, peerAddress);
|
||||
}
|
||||
|
||||
private async encRowToChannel(row: BroadcastChannelEncRow): Promise<BroadcastChannelRecord> {
|
||||
const sensitive = await openBroadcastChannelSensitive(
|
||||
this.km,
|
||||
row.channel_id,
|
||||
toBytes(row.ciphertext),
|
||||
);
|
||||
const out: BroadcastChannelRecord = {
|
||||
channelId: row.channel_id,
|
||||
ownerRole: row.owner_role,
|
||||
ownerAddress: row.owner_address,
|
||||
generation: Number(row.generation),
|
||||
chainKey: sensitive.chainKey,
|
||||
iteration: sensitive.iteration,
|
||||
signingPublicKey: sensitive.signingPublicKey,
|
||||
createdAt: Number(row.created_at),
|
||||
updatedAt: Number(row.updated_at),
|
||||
};
|
||||
if (row.label !== null && row.label !== undefined) out.label = row.label;
|
||||
if (sensitive.signingPrivateKey !== undefined) out.signingPrivateKey = sensitive.signingPrivateKey;
|
||||
return out;
|
||||
}
|
||||
|
||||
private async rowToStreamState(row: StreamRow): Promise<PersistedStreamState> {
|
||||
const sensitive = await openStreamSensitive(this.km, row.stream_id, toBytes(row.ciphertext));
|
||||
const out: PersistedStreamState = {
|
||||
@@ -463,6 +602,24 @@ interface StreamRow {
|
||||
updated_at: number | bigint;
|
||||
}
|
||||
|
||||
interface BroadcastChannelEncRow {
|
||||
channel_id: string;
|
||||
owner_role: 'sender' | 'receiver';
|
||||
owner_address: string;
|
||||
label: string | null;
|
||||
generation: number | bigint;
|
||||
ciphertext: Uint8Array | ArrayBuffer;
|
||||
created_at: number | bigint;
|
||||
updated_at: number | bigint;
|
||||
}
|
||||
|
||||
interface BroadcastMemberEncRow {
|
||||
channel_id: string;
|
||||
peer_address: string;
|
||||
joined_at: number | bigint;
|
||||
removed_at: number | bigint | null;
|
||||
}
|
||||
|
||||
function toBytes(value: Uint8Array | ArrayBuffer | unknown): Uint8Array {
|
||||
if (value instanceof Uint8Array) return value;
|
||||
if (value instanceof ArrayBuffer) return new Uint8Array(value);
|
||||
|
||||
Reference in New Issue
Block a user