feat: complete Ancestor quote bot with production-ready Docker support

This commit is contained in:
unfunny
2026-09-13 14:14:38 -04:00
parent f2016da05a
commit fe7351a7dc
1145 changed files with 30890 additions and 97684 deletions

View File

@@ -1,3 +1,9 @@
"use strict";
Object.defineProperty(exports, "__esModule", {
value: true
});
exports.secretStorageContainsCrossSigningKeys = secretStorageContainsCrossSigningKeys;
/*
Copyright 2023 The Matrix.org Foundation C.I.C.
@@ -15,36 +21,26 @@ limitations under the License.
*/
/**
* Check that the private cross signing keys (master, self signing, user signing) are stored in the secret storage and encrypted with the default secret storage key.
* Check that the private cross signing keys (master, self signing, user signing) are stored in the secret storage and encrypted with the same secret storage key.
*
* @param secretStorage - The secret store using account data
* @returns True if the cross-signing keys are all stored and encrypted with the same secret storage key.
*
* @internal
*/
export async function secretStorageContainsCrossSigningKeys(secretStorage) {
return secretStorageCanAccessSecrets(secretStorage, ["m.cross_signing.master", "m.cross_signing.user_signing", "m.cross_signing.self_signing"]);
}
async function secretStorageContainsCrossSigningKeys(secretStorage) {
// Check if the master cross-signing key is stored in secret storage
const secretStorageMasterKeys = await secretStorage.isStored("m.cross_signing.master");
/**
*
* Check that the secret storage can access the given secrets using the default key.
*
* @param secretStorage - The secret store using account data
* @param secretNames - The secret names to check
* @returns True if all the given secrets are accessible and encrypted with the given key.
*
* @internal
*/
export async function secretStorageCanAccessSecrets(secretStorage, secretNames) {
const defaultKeyId = await secretStorage.getDefaultKeyId();
if (!defaultKeyId) return false;
for (const secretName of secretNames) {
// check which keys this particular secret is encrypted with
const record = (await secretStorage.isStored(secretName)) || {};
// if it's not encrypted with the right key, there is no point continuing
if (!(defaultKeyId in record)) return false;
}
return true;
// Master key not stored
if (!secretStorageMasterKeys) return false;
// Get the user signing keys stored into the secret storage
const secretStorageUserSigningKeys = (await secretStorage.isStored(`m.cross_signing.user_signing`)) || {};
// Get the self signing keys stored into the secret storage
const secretStorageSelfSigningKeys = (await secretStorage.isStored(`m.cross_signing.self_signing`)) || {};
// Check that one of the secret storage keys used to encrypt the master key was also used to encrypt the user-signing and self-signing keys
return Object.keys(secretStorageMasterKeys).some(secretStorageKey => secretStorageUserSigningKeys[secretStorageKey] && secretStorageSelfSigningKeys[secretStorageKey]);
}
//# sourceMappingURL=secret-storage.js.map