Qualify durable purchase and media primitives and preserve app launch paths
This commit is contained in:
@@ -20,6 +20,7 @@ pub(crate) use invites::notify_join;
|
||||
// Crate-internal: peer-joined resolves the granted trust level by matching
|
||||
// the acceptor's invite_token against our stored outgoing invites.
|
||||
pub(crate) use storage::load_invites;
|
||||
pub(crate) use storage::load_unique_payment_peer;
|
||||
#[allow(unused_imports)]
|
||||
pub use storage::{
|
||||
add_node, fips_npub_for_onion, load_nodes, load_removed_dids, record_peer_transport,
|
||||
|
||||
@@ -71,6 +71,36 @@ pub async fn load_nodes(data_dir: &Path) -> Result<Vec<FederatedNode>> {
|
||||
load_nodes_inner(data_dir).await
|
||||
}
|
||||
|
||||
/// Resolve payment identity from persisted records before display deduplication
|
||||
/// can merge fields from different identities sharing an address.
|
||||
pub(crate) async fn load_unique_payment_peer(
|
||||
data_dir: &Path,
|
||||
onion: &str,
|
||||
) -> Result<FederatedNode> {
|
||||
let _guard = FEDERATION_STORE_LOCK.lock().await;
|
||||
let content = fs::read(data_dir.join(FEDERATION_DIR).join(NODES_FILE))
|
||||
.await
|
||||
.context("Could not read payment peer bindings")?;
|
||||
let file: NodesFile =
|
||||
serde_json::from_slice(&content).context("Invalid payment peer bindings")?;
|
||||
let target = onion.strip_suffix(".onion").unwrap_or(onion);
|
||||
anyhow::ensure!(!target.is_empty(), "Missing payment peer address");
|
||||
let mut matches = file
|
||||
.nodes
|
||||
.into_iter()
|
||||
.filter(|peer| peer.onion.strip_suffix(".onion").unwrap_or(&peer.onion) == target);
|
||||
let peer = matches.next().context("Payment peer binding is missing")?;
|
||||
anyhow::ensure!(
|
||||
matches.next().is_none(),
|
||||
"Payment peer binding is ambiguous"
|
||||
);
|
||||
anyhow::ensure!(
|
||||
crate::identity::did_key_from_pubkey_hex(&peer.pubkey)? == peer.did,
|
||||
"Payment peer identity does not match its public key"
|
||||
);
|
||||
Ok(peer)
|
||||
}
|
||||
|
||||
/// Lock-free body of `load_nodes`. Callers that already hold
|
||||
/// `FEDERATION_STORE_LOCK` (i.e. other functions in this module composing a
|
||||
/// multi-step critical section) must call this instead of `load_nodes` to
|
||||
|
||||
Reference in New Issue
Block a user