Verify scoped peer identity proofs before restricted content access

This commit is contained in:
archipelago
2026-10-06 06:07:55 -04:00
parent 6fba95fe5a
commit a9edcd6b3e
10 changed files with 438 additions and 32 deletions
+23
View File
@@ -479,6 +479,29 @@ impl<'a> PeerRequest<'a> {
self
}
/// Authenticate peer content without granting trust to a caller-supplied DID.
/// Call after setting Range, since the exact range is signed too.
pub async fn authenticate_content(mut self, data_dir: &std::path::Path) -> Result<Self> {
anyhow::ensure!(
self.path == "/content" || self.path.starts_with("/content/"),
"Not a content route"
);
let range = self
.headers
.iter()
.find(|(name, _)| name.eq_ignore_ascii_case("range"))
.map(|(_, value)| value.as_str())
.unwrap_or("");
if let Some(proof) =
crate::content_auth::outgoing(data_dir, self.onion_host, self.path, range).await?
{
self.headers
.retain(|(name, _)| !name.eq_ignore_ascii_case(crate::content_auth::HEADER));
self.headers.push((crate::content_auth::HEADER, proof));
}
Ok(self)
}
pub fn header(mut self, name: &'a str, value: impl Into<String>) -> Self {
self.headers.push((name, value.into()));
self