2026-09-13 14:14:38 -04:00
"use strict" ;
Object . defineProperty ( exports , "__esModule" , {
value : true
} ) ;
exports . CrossSigningIdentity = void 0 ;
var _logger = require ( "../logger" ) ;
2026-09-12 23:57:45 -04:00
/ *
Copyright 2023 The Matrix . org Foundation C . I . C .
Licensed under the Apache License , Version 2.0 ( the "License" ) ;
you may not use this file except in compliance with the License .
You may obtain a copy of the License at
http : //www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing , software
distributed under the License is distributed on an "AS IS" BASIS ,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND , either express or implied .
See the License for the specific language governing permissions and
limitations under the License .
* /
/ * * M a n a g e s t h e c r o s s - s i g n i n g k e y s f o r o u r o w n u s e r .
*
* @ internal
* /
2026-09-13 14:14:38 -04:00
class CrossSigningIdentity {
constructor ( olmMachine , outgoingRequestProcessor , secretStorage , /** Called if the cross signing keys are imported from the secret storage */
onCrossSigningKeysImport ) {
2026-09-12 23:57:45 -04:00
this . olmMachine = olmMachine ;
this . outgoingRequestProcessor = outgoingRequestProcessor ;
this . secretStorage = secretStorage ;
2026-09-13 14:14:38 -04:00
this . onCrossSigningKeysImport = onCrossSigningKeysImport ;
2026-09-12 23:57:45 -04:00
}
/ * *
* Initialise our cross - signing keys by creating new keys if they do not exist , and uploading to the server
* /
async bootstrapCrossSigning ( opts ) {
if ( opts . setupNewCrossSigning ) {
await this . resetCrossSigning ( opts . authUploadDeviceSigningKeys ) ;
return ;
}
const olmDeviceStatus = await this . olmMachine . crossSigningStatus ( ) ;
// Try to fetch cross signing keys from the secret storage
const masterKeyFromSecretStorage = await this . secretStorage . get ( "m.cross_signing.master" ) ;
const selfSigningKeyFromSecretStorage = await this . secretStorage . get ( "m.cross_signing.self_signing" ) ;
const userSigningKeyFromSecretStorage = await this . secretStorage . get ( "m.cross_signing.user_signing" ) ;
const privateKeysInSecretStorage = Boolean ( masterKeyFromSecretStorage && selfSigningKeyFromSecretStorage && userSigningKeyFromSecretStorage ) ;
const olmDeviceHasKeys = olmDeviceStatus . hasMaster && olmDeviceStatus . hasUserSigning && olmDeviceStatus . hasSelfSigning ;
// Log all relevant state for easier parsing of debug logs.
2026-09-13 14:14:38 -04:00
_logger . logger . log ( "bootStrapCrossSigning: starting" , {
2026-09-12 23:57:45 -04:00
setupNewCrossSigning : opts . setupNewCrossSigning ,
olmDeviceHasMaster : olmDeviceStatus . hasMaster ,
olmDeviceHasUserSigning : olmDeviceStatus . hasUserSigning ,
olmDeviceHasSelfSigning : olmDeviceStatus . hasSelfSigning ,
privateKeysInSecretStorage
} ) ;
2026-09-13 14:14:38 -04:00
if ( ! olmDeviceHasKeys && ! privateKeysInSecretStorage ) {
_logger . logger . log ( "bootStrapCrossSigning: Cross-signing private keys not found locally or in secret storage, creating new keys" ) ;
await this . resetCrossSigning ( opts . authUploadDeviceSigningKeys ) ;
} else if ( olmDeviceHasKeys ) {
_logger . logger . log ( "bootStrapCrossSigning: Olm device has private keys: exporting to secret storage" ) ;
await this . exportCrossSigningKeysToStorage ( ) ;
} else if ( privateKeysInSecretStorage ) {
_logger . logger . log ( "bootStrapCrossSigning: Cross-signing private keys not found locally, but they are available " + "in secret storage, reading storage and caching locally" ) ;
await this . olmMachine . importCrossSigningKeys ( masterKeyFromSecretStorage , selfSigningKeyFromSecretStorage , userSigningKeyFromSecretStorage ) ;
2026-09-12 23:57:45 -04:00
2026-09-13 14:14:38 -04:00
// Get the current device
const device = await this . olmMachine . getDevice ( this . olmMachine . userId , this . olmMachine . deviceId ) ;
2026-09-12 23:57:45 -04:00
2026-09-13 14:14:38 -04:00
// Sign the device with our cross-signing key and upload the signature
const request = await device . verify ( ) ;
await this . outgoingRequestProcessor . makeOutgoingRequest ( request ) ;
this . onCrossSigningKeysImport ( ) ;
2026-09-12 23:57:45 -04:00
}
// TODO: we might previously have bootstrapped cross-signing but not completed uploading the keys to the
// server -- in which case we should call OlmDevice.bootstrap_cross_signing. How do we know?
2026-09-13 14:14:38 -04:00
_logger . logger . log ( "bootStrapCrossSigning: complete" ) ;
2026-09-12 23:57:45 -04:00
}
/ * * R e s e t o u r c r o s s - s i g n i n g k e y s
*
* This method will :
* * Tell the OlmMachine to create new keys
* * Upload the new public keys and the device signature to the server
* * Upload the private keys to SSSS , if it is set up
* /
async resetCrossSigning ( authUploadDeviceSigningKeys ) {
const outgoingRequests = await this . olmMachine . bootstrapCrossSigning ( true ) ;
2026-09-13 14:14:38 -04:00
_logger . logger . log ( "bootStrapCrossSigning: publishing keys to server" ) ;
for ( const req of outgoingRequests ) {
await this . outgoingRequestProcessor . makeOutgoingRequest ( req , authUploadDeviceSigningKeys ) ;
2026-09-12 23:57:45 -04:00
}
2026-09-13 14:14:38 -04:00
await this . exportCrossSigningKeysToStorage ( ) ;
2026-09-12 23:57:45 -04:00
}
/ * *
* Extract the cross - signing keys from the olm machine and save them to secret storage , if it is configured
*
* ( If secret storage is * not * configured , we assume that the export will happen when it is set up )
* /
async exportCrossSigningKeysToStorage ( ) {
2026-09-13 14:14:38 -04:00
// TODO
2026-09-12 23:57:45 -04:00
}
}
2026-09-13 14:14:38 -04:00
exports . CrossSigningIdentity = CrossSigningIdentity ;
2026-09-12 23:57:45 -04:00
//# sourceMappingURL=CrossSigningIdentity.js.map