feat: complete Ancestor quote bot with production-ready Docker support

This commit is contained in:
unfunny
2026-09-13 14:14:38 -04:00
parent f2016da05a
commit fe7351a7dc
1145 changed files with 30890 additions and 97684 deletions

View File

@@ -1,3 +1,10 @@
"use strict";
Object.defineProperty(exports, "__esModule", {
value: true
});
exports.CrossSigningIdentity = void 0;
var _logger = require("../logger");
/*
Copyright 2023 The Matrix.org Foundation C.I.C.
@@ -18,12 +25,13 @@ limitations under the License.
*
* @internal
*/
export class CrossSigningIdentity {
constructor(logger, olmMachine, outgoingRequestProcessor, secretStorage) {
this.logger = logger;
class CrossSigningIdentity {
constructor(olmMachine, outgoingRequestProcessor, secretStorage, /** Called if the cross signing keys are imported from the secret storage */
onCrossSigningKeysImport) {
this.olmMachine = olmMachine;
this.outgoingRequestProcessor = outgoingRequestProcessor;
this.secretStorage = secretStorage;
this.onCrossSigningKeysImport = onCrossSigningKeysImport;
}
/**
@@ -44,54 +52,35 @@ export class CrossSigningIdentity {
const olmDeviceHasKeys = olmDeviceStatus.hasMaster && olmDeviceStatus.hasUserSigning && olmDeviceStatus.hasSelfSigning;
// Log all relevant state for easier parsing of debug logs.
this.logger.debug("bootstrapCrossSigning: starting", {
_logger.logger.log("bootStrapCrossSigning: starting", {
setupNewCrossSigning: opts.setupNewCrossSigning,
olmDeviceHasMaster: olmDeviceStatus.hasMaster,
olmDeviceHasUserSigning: olmDeviceStatus.hasUserSigning,
olmDeviceHasSelfSigning: olmDeviceStatus.hasSelfSigning,
privateKeysInSecretStorage
});
if (olmDeviceHasKeys) {
if (!(await this.secretStorage.hasKey())) {
this.logger.warn("bootstrapCrossSigning: Olm device has private keys, but secret storage is not yet set up; doing nothing for now.");
// the keys should get uploaded to 4S once that is set up.
} else if (!privateKeysInSecretStorage) {
// the device has the keys but they are not in 4S, so update it
this.logger.debug("bootstrapCrossSigning: Olm device has private keys: exporting to secret storage");
await this.exportCrossSigningKeysToStorage();
} else {
this.logger.debug("bootstrapCrossSigning: Olm device has private keys and they are saved in secret storage; doing nothing");
}
} /* (!olmDeviceHasKeys) */else {
if (privateKeysInSecretStorage) {
// they are in 4S, so import from there
this.logger.debug("bootstrapCrossSigning: Cross-signing private keys not found locally, but they are available " + "in secret storage, reading storage and caching locally");
const status = await this.olmMachine.importCrossSigningKeys(masterKeyFromSecretStorage, selfSigningKeyFromSecretStorage, userSigningKeyFromSecretStorage);
if (!olmDeviceHasKeys && !privateKeysInSecretStorage) {
_logger.logger.log("bootStrapCrossSigning: Cross-signing private keys not found locally or in secret storage, creating new keys");
await this.resetCrossSigning(opts.authUploadDeviceSigningKeys);
} else if (olmDeviceHasKeys) {
_logger.logger.log("bootStrapCrossSigning: Olm device has private keys: exporting to secret storage");
await this.exportCrossSigningKeysToStorage();
} else if (privateKeysInSecretStorage) {
_logger.logger.log("bootStrapCrossSigning: Cross-signing private keys not found locally, but they are available " + "in secret storage, reading storage and caching locally");
await this.olmMachine.importCrossSigningKeys(masterKeyFromSecretStorage, selfSigningKeyFromSecretStorage, userSigningKeyFromSecretStorage);
// Check that `importCrossSigningKeys` worked correctly (for example, it will fail silently if the
// public keys are not available).
if (!status.hasMaster || !status.hasSelfSigning || !status.hasUserSigning) {
throw new Error("importCrossSigningKeys failed to import the keys");
}
// Get the current device
const device = await this.olmMachine.getDevice(this.olmMachine.userId, this.olmMachine.deviceId);
// Get the current device
const device = await this.olmMachine.getDevice(this.olmMachine.userId, this.olmMachine.deviceId);
try {
// Sign the device with our cross-signing key and upload the signature
const request = await device.verify();
await this.outgoingRequestProcessor.makeOutgoingRequest(request);
} finally {
device.free();
}
} else {
this.logger.debug("bootstrapCrossSigning: Cross-signing private keys not found locally or in secret storage, creating new keys");
await this.resetCrossSigning(opts.authUploadDeviceSigningKeys);
}
// Sign the device with our cross-signing key and upload the signature
const request = await device.verify();
await this.outgoingRequestProcessor.makeOutgoingRequest(request);
this.onCrossSigningKeysImport();
}
// TODO: we might previously have bootstrapped cross-signing but not completed uploading the keys to the
// server -- in which case we should call OlmDevice.bootstrap_cross_signing. How do we know?
this.logger.debug("bootstrapCrossSigning: complete");
_logger.logger.log("bootStrapCrossSigning: complete");
}
/** Reset our cross-signing keys
@@ -102,27 +91,12 @@ export class CrossSigningIdentity {
* * Upload the private keys to SSSS, if it is set up
*/
async resetCrossSigning(authUploadDeviceSigningKeys) {
// XXX: We must find a way to make this atomic, currently if the user does not remember his account password
// or 4S passphrase/key the process will fail in a bad state, with keys rotated but not uploaded or saved in 4S.
const outgoingRequests = await this.olmMachine.bootstrapCrossSigning(true);
// If 4S is configured we need to update it.
if (!(await this.secretStorage.hasKey())) {
this.logger.warn("resetCrossSigning: Secret storage is not yet set up; not exporting keys to secret storage yet.");
// the keys should get uploaded to 4S once that is set up.
} else {
// Update 4S before uploading cross-signing keys, to stay consistent with legacy that asks
// 4S passphrase before asking for account password.
// Ultimately should be made atomic and resistant to forgotten password/passphrase.
this.logger.debug("resetCrossSigning: exporting private keys to secret storage");
await this.exportCrossSigningKeysToStorage();
}
this.logger.debug("resetCrossSigning: publishing public keys to server");
for (const req of [outgoingRequests.uploadKeysRequest, outgoingRequests.uploadSigningKeysRequest, outgoingRequests.uploadSignaturesRequest]) {
if (req) {
await this.outgoingRequestProcessor.makeOutgoingRequest(req, authUploadDeviceSigningKeys);
}
_logger.logger.log("bootStrapCrossSigning: publishing keys to server");
for (const req of outgoingRequests) {
await this.outgoingRequestProcessor.makeOutgoingRequest(req, authUploadDeviceSigningKeys);
}
await this.exportCrossSigningKeysToStorage();
}
/**
@@ -131,23 +105,8 @@ export class CrossSigningIdentity {
* (If secret storage is *not* configured, we assume that the export will happen when it is set up)
*/
async exportCrossSigningKeysToStorage() {
const exported = await this.olmMachine.exportCrossSigningKeys();
/* istanbul ignore else (this function is only called when we know the olm machine has keys) */
if (exported?.masterKey) {
await this.secretStorage.store("m.cross_signing.master", exported.masterKey);
} else {
this.logger.error(`Cannot export MSK to secret storage, private key unknown`);
}
if (exported?.self_signing_key) {
await this.secretStorage.store("m.cross_signing.self_signing", exported.self_signing_key);
} else {
this.logger.error(`Cannot export SSK to secret storage, private key unknown`);
}
if (exported?.userSigningKey) {
await this.secretStorage.store("m.cross_signing.user_signing", exported.userSigningKey);
} else {
this.logger.error(`Cannot export USK to secret storage, private key unknown`);
}
// TODO
}
}
exports.CrossSigningIdentity = CrossSigningIdentity;
//# sourceMappingURL=CrossSigningIdentity.js.map