Closes F-01 (Critical) of docs/security/ENTROPY-SEED-AUDIT-2026-07-31.md.
seed.generate/seed.restore/seed.save-encrypted/backup.restore-identity/
auth.setup are all in UNAUTHENTICATED_METHODS, and several reach
NodeIdentity::from_seed or restore_encrypted_backup, which overwrite
identity/node_key unconditionally. One unauthenticated POST from the LAN or
from any FIPS mesh peer hijacked a live node's Ed25519 identity, Nostr node
key and FIPS transport key.
- new api::rpc::onboarding_gate::ensure_onboarding_open: refuses once ANY of
is_setup() / is_onboarding_complete() / seed_exists() says provisioned,
failing safe on I/O errors. NodeIdentity::key_exists is deliberately NOT a
signal — server.rs:63-71 writes a temporary key on every boot, so a gate
keyed on it would refuse seed.generate on a never-onboarded node. Pinned by
allows_on_fresh_temp_dir_even_though_node_key_exists.
- ensure_user_account_exists: the inverse guard for auth.onboardingComplete,
which is unauthenticated and sets the flag the gate reads — without it, one
call locks a fresh node out of its own onboarding.
- seed.restore body extracted to restore_node_identity_from_words so the
regression suite drives the real path; seed.verify left open with a written
verdict (non-mutating).
- refusal text begins "Not supported:" so it survives sanitize_error_message
and names the authenticated system.factory-reset recovery path.
- per-method rate limits for the four onboarding mutators, sized ~6x the
measured client retry budget so a 429 cannot reintroduce the error at the
DID-creation screen.
First-boot onboarding is untouched: all three signals are false throughout the
seed steps, and auth.setup runs last (Login.vue:405-425).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>