Compare commits
3 Commits
main
...
encryption
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9957f2a7a9 | ||
|
|
cbc23c0325 | ||
|
|
bfe7cb2790 |
@@ -5,5 +5,9 @@ MATRIX_HOME_SERVER=https://matrix.org
|
||||
MATRIX_ACCESS_TOKEN=your_real_access_token_here
|
||||
BOT_COMMAND=!quote
|
||||
|
||||
# Stable device ID for the bot's E2EE identity. Keep this consistent
|
||||
# across restarts so the bot reuses its encryption keys.
|
||||
MATRIX_DEVICE_ID=ANCESTORBOT
|
||||
|
||||
# If you want debug logging, set DEBUG=true
|
||||
DEBUG=false
|
||||
|
||||
51
index.js
51
index.js
@@ -1,18 +1,47 @@
|
||||
import * as dotenv from 'dotenv';
|
||||
import { MatrixClient } from 'matrix-js-sdk';
|
||||
import { MemoryStore } from 'matrix-js-sdk/lib/store/memory.js';
|
||||
import fs from 'fs';
|
||||
|
||||
dotenv.config();
|
||||
|
||||
console.log('🚀 Starting Ancestor Quote Bot...\n');
|
||||
|
||||
const deviceId = process.env.MATRIX_DEVICE_ID || 'ANCESTORBOT';
|
||||
|
||||
const client = new MatrixClient({
|
||||
accessToken: process.env.MATRIX_ACCESS_TOKEN,
|
||||
baseUrl: process.env.MATRIX_HOME_SERVER,
|
||||
store: new MemoryStore(),
|
||||
deviceId,
|
||||
});
|
||||
|
||||
// The Rust crypto backend uses an in-memory store here (no IndexedDB in Node),
|
||||
// so after a restart it 'forgets' one-time keys it already uploaded. Re-uploading
|
||||
// an existing OTK id makes Synapse reject the request with a 400, the SDK never
|
||||
// marks it as sent, and it retries forever — which blocks decryption entirely.
|
||||
// Rewrite that specific 400 into a synthetic success: the empty count makes the
|
||||
// Rust machine mint fresh OTK ids on the next tick, which then upload cleanly.
|
||||
function installOtkCollisionWorkaround(client) {
|
||||
const http = client.http;
|
||||
const authedRequest = http.authedRequest.bind(http);
|
||||
http.authedRequest = async function (method, path, queryParams, body, opts) {
|
||||
try {
|
||||
return await authedRequest(method, path, queryParams, body, opts);
|
||||
} catch (err) {
|
||||
if (
|
||||
method === 'POST' &&
|
||||
/\/keys\/upload$/.test(path) &&
|
||||
err?.httpStatus === 400 &&
|
||||
/already exists/.test(err?.message || '')
|
||||
) {
|
||||
console.warn('⚙️ One-time-key collision on keys/upload; telling Rust crypto to mint fresh keys');
|
||||
return '{"one_time_key_counts":{}}';
|
||||
}
|
||||
throw err;
|
||||
}
|
||||
};
|
||||
}
|
||||
installOtkCollisionWorkaround(client);
|
||||
|
||||
function loadQuotes() {
|
||||
try {
|
||||
const quotesFile = './quotes.json';
|
||||
@@ -56,7 +85,14 @@ function loadQuotes() {
|
||||
}
|
||||
|
||||
client.credentials.userId = userId;
|
||||
console.log(`👤 Bot Identity: ${userId}`);
|
||||
console.log(`👤 Bot Identity: ${userId} (device ${deviceId})`);
|
||||
|
||||
// Enable end-to-end encryption so the bot can read and reply in
|
||||
// encrypted rooms. The Rust/Olm WASM backend needs no native
|
||||
// compile. useIndexedDB=false keeps everything in memory (no
|
||||
// IndexedDB in Node).
|
||||
await client.initRustCrypto({ useIndexedDB: false });
|
||||
console.log('🔐 E2EE crypto initialised (Rust/Olm WASM)');
|
||||
|
||||
await client.startClient();
|
||||
console.log('✅ MatrixClient connected and authenticated\n');
|
||||
@@ -87,11 +123,12 @@ function loadQuotes() {
|
||||
const type = event.getType();
|
||||
const eventRoomId = event.getRoomId();
|
||||
|
||||
// Encrypted rooms: the bot has no E2EE support, so command text
|
||||
// never arrives as plaintext and cannot be read or answered.
|
||||
// If an event still arrives encrypted, decryption failed — the
|
||||
// room is likely set to only share keys with verified sessions.
|
||||
if (type === 'm.room.encrypted') {
|
||||
console.log(`🔒 [${eventRoomId}] encrypted message received. ` +
|
||||
`The bot cannot read E2EE rooms; invite it to an unencrypted room instead.`);
|
||||
console.log(`🔒 [${eventRoomId}] could not decrypt message. ` +
|
||||
`The room may be set to share keys only with verified sessions; ` +
|
||||
`change room encryption settings to include this bot's device, or verify it.`);
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user