mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 03:45:20 +00:00
Merge branch 'main' into fix/646-harden-hex-parsing
This commit is contained in:
@@ -1,50 +0,0 @@
|
|||||||
import Foundation
|
|
||||||
|
|
||||||
protocol KeychainHelperProtocol {
|
|
||||||
func save(key: String, data: Data, service: String, accessible: CFString?)
|
|
||||||
func load(key: String, service: String) -> Data?
|
|
||||||
func delete(key: String, service: String)
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Keychain helper for secure storage
|
|
||||||
struct KeychainHelper: KeychainHelperProtocol {
|
|
||||||
func save(key: String, data: Data, service: String, accessible: CFString? = nil) {
|
|
||||||
var query: [String: Any] = [
|
|
||||||
kSecClass as String: kSecClassGenericPassword,
|
|
||||||
kSecAttrService as String: service,
|
|
||||||
kSecAttrAccount as String: key,
|
|
||||||
kSecValueData as String: data
|
|
||||||
]
|
|
||||||
if let accessible = accessible {
|
|
||||||
query[kSecAttrAccessible as String] = accessible
|
|
||||||
}
|
|
||||||
|
|
||||||
SecItemDelete(query as CFDictionary)
|
|
||||||
SecItemAdd(query as CFDictionary, nil)
|
|
||||||
}
|
|
||||||
|
|
||||||
func load(key: String, service: String) -> Data? {
|
|
||||||
let query: [String: Any] = [
|
|
||||||
kSecClass as String: kSecClassGenericPassword,
|
|
||||||
kSecAttrService as String: service,
|
|
||||||
kSecAttrAccount as String: key,
|
|
||||||
kSecReturnData as String: true
|
|
||||||
]
|
|
||||||
|
|
||||||
var result: AnyObject?
|
|
||||||
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
|
||||||
|
|
||||||
guard status == errSecSuccess else { return nil }
|
|
||||||
return result as? Data
|
|
||||||
}
|
|
||||||
|
|
||||||
func delete(key: String, service: String) {
|
|
||||||
let query: [String: Any] = [
|
|
||||||
kSecClass as String: kSecClassGenericPassword,
|
|
||||||
kSecAttrService as String: service,
|
|
||||||
kSecAttrAccount as String: key
|
|
||||||
]
|
|
||||||
|
|
||||||
SecItemDelete(query as CFDictionary)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -12,9 +12,9 @@ final class NostrIdentityBridge {
|
|||||||
private var derivedIdentityCache: [String: NostrIdentity] = [:]
|
private var derivedIdentityCache: [String: NostrIdentity] = [:]
|
||||||
private let cacheLock = NSLock()
|
private let cacheLock = NSLock()
|
||||||
|
|
||||||
private let keychain: KeychainHelperProtocol
|
private let keychain: KeychainManagerProtocol
|
||||||
|
|
||||||
init(keychain: KeychainHelperProtocol = KeychainHelper()) {
|
init(keychain: KeychainManagerProtocol = KeychainManager()) {
|
||||||
self.keychain = keychain
|
self.keychain = keychain
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ final class FavoritesPersistenceService: ObservableObject {
|
|||||||
|
|
||||||
private static let storageKey = "chat.bitchat.favorites"
|
private static let storageKey = "chat.bitchat.favorites"
|
||||||
private static let keychainService = "chat.bitchat.favorites"
|
private static let keychainService = "chat.bitchat.favorites"
|
||||||
private let keychain: KeychainHelperProtocol
|
private let keychain: KeychainManagerProtocol
|
||||||
|
|
||||||
@Published private(set) var favorites: [Data: FavoriteRelationship] = [:] // Noise pubkey -> relationship
|
@Published private(set) var favorites: [Data: FavoriteRelationship] = [:] // Noise pubkey -> relationship
|
||||||
@Published private(set) var mutualFavorites: Set<Data> = []
|
@Published private(set) var mutualFavorites: Set<Data> = []
|
||||||
@@ -35,8 +35,8 @@ final class FavoritesPersistenceService: ObservableObject {
|
|||||||
private var cancellables = Set<AnyCancellable>()
|
private var cancellables = Set<AnyCancellable>()
|
||||||
|
|
||||||
static let shared = FavoritesPersistenceService()
|
static let shared = FavoritesPersistenceService()
|
||||||
|
|
||||||
init(keychain: KeychainHelperProtocol = KeychainHelper()) {
|
init(keychain: KeychainManagerProtocol = KeychainManager()) {
|
||||||
self.keychain = keychain
|
self.keychain = keychain
|
||||||
loadFavorites()
|
loadFavorites()
|
||||||
|
|
||||||
|
|||||||
@@ -15,11 +15,19 @@ protocol KeychainManagerProtocol {
|
|||||||
func getIdentityKey(forKey key: String) -> Data?
|
func getIdentityKey(forKey key: String) -> Data?
|
||||||
func deleteIdentityKey(forKey key: String) -> Bool
|
func deleteIdentityKey(forKey key: String) -> Bool
|
||||||
func deleteAllKeychainData() -> Bool
|
func deleteAllKeychainData() -> Bool
|
||||||
|
|
||||||
func secureClear(_ data: inout Data)
|
func secureClear(_ data: inout Data)
|
||||||
func secureClear(_ string: inout String)
|
func secureClear(_ string: inout String)
|
||||||
|
|
||||||
func verifyIdentityKeyExists() -> Bool
|
func verifyIdentityKeyExists() -> Bool
|
||||||
|
|
||||||
|
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||||
|
/// Save data with a custom service name
|
||||||
|
func save(key: String, data: Data, service: String, accessible: CFString?)
|
||||||
|
/// Load data from a custom service
|
||||||
|
func load(key: String, service: String) -> Data?
|
||||||
|
/// Delete data from a custom service
|
||||||
|
func delete(key: String, service: String)
|
||||||
}
|
}
|
||||||
|
|
||||||
final class KeychainManager: KeychainManagerProtocol {
|
final class KeychainManager: KeychainManagerProtocol {
|
||||||
@@ -309,9 +317,54 @@ final class KeychainManager: KeychainManagerProtocol {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// MARK: - Debug
|
// MARK: - Debug
|
||||||
|
|
||||||
func verifyIdentityKeyExists() -> Bool {
|
func verifyIdentityKeyExists() -> Bool {
|
||||||
let key = "identity_noiseStaticKey"
|
let key = "identity_noiseStaticKey"
|
||||||
return retrieveData(forKey: key) != nil
|
return retrieveData(forKey: key) != nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||||
|
|
||||||
|
/// Save data with a custom service name
|
||||||
|
func save(key: String, data: Data, service customService: String, accessible: CFString?) {
|
||||||
|
var query: [String: Any] = [
|
||||||
|
kSecClass as String: kSecClassGenericPassword,
|
||||||
|
kSecAttrService as String: customService,
|
||||||
|
kSecAttrAccount as String: key,
|
||||||
|
kSecValueData as String: data
|
||||||
|
]
|
||||||
|
if let accessible = accessible {
|
||||||
|
query[kSecAttrAccessible as String] = accessible
|
||||||
|
}
|
||||||
|
|
||||||
|
SecItemDelete(query as CFDictionary)
|
||||||
|
SecItemAdd(query as CFDictionary, nil)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Load data from a custom service
|
||||||
|
func load(key: String, service customService: String) -> Data? {
|
||||||
|
let query: [String: Any] = [
|
||||||
|
kSecClass as String: kSecClassGenericPassword,
|
||||||
|
kSecAttrService as String: customService,
|
||||||
|
kSecAttrAccount as String: key,
|
||||||
|
kSecReturnData as String: true
|
||||||
|
]
|
||||||
|
|
||||||
|
var result: AnyObject?
|
||||||
|
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
||||||
|
|
||||||
|
guard status == errSecSuccess else { return nil }
|
||||||
|
return result as? Data
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Delete data from a custom service
|
||||||
|
func delete(key: String, service customService: String) {
|
||||||
|
let query: [String: Any] = [
|
||||||
|
kSecClass as String: kSecClassGenericPassword,
|
||||||
|
kSecAttrService as String: customService,
|
||||||
|
kSecAttrAccount as String: key
|
||||||
|
]
|
||||||
|
|
||||||
|
SecItemDelete(query as CFDictionary)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -10,32 +10,51 @@ import Foundation
|
|||||||
|
|
||||||
final class PreviewKeychainManager: KeychainManagerProtocol {
|
final class PreviewKeychainManager: KeychainManagerProtocol {
|
||||||
private var storage: [String: Data] = [:]
|
private var storage: [String: Data] = [:]
|
||||||
|
private var serviceStorage: [String: [String: Data]] = [:]
|
||||||
init() {}
|
init() {}
|
||||||
|
|
||||||
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
|
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
|
||||||
storage[key] = keyData
|
storage[key] = keyData
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func getIdentityKey(forKey key: String) -> Data? {
|
func getIdentityKey(forKey key: String) -> Data? {
|
||||||
storage[key]
|
storage[key]
|
||||||
}
|
}
|
||||||
|
|
||||||
func deleteIdentityKey(forKey key: String) -> Bool {
|
func deleteIdentityKey(forKey key: String) -> Bool {
|
||||||
storage.removeValue(forKey: key)
|
storage.removeValue(forKey: key)
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func deleteAllKeychainData() -> Bool {
|
func deleteAllKeychainData() -> Bool {
|
||||||
storage.removeAll()
|
storage.removeAll()
|
||||||
|
serviceStorage.removeAll()
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func secureClear(_ data: inout Data) {}
|
func secureClear(_ data: inout Data) {}
|
||||||
|
|
||||||
func secureClear(_ string: inout String) {}
|
func secureClear(_ string: inout String) {}
|
||||||
|
|
||||||
func verifyIdentityKeyExists() -> Bool {
|
func verifyIdentityKeyExists() -> Bool {
|
||||||
storage["identity_noiseStaticKey"] != nil
|
storage["identity_noiseStaticKey"] != nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||||
|
|
||||||
|
func save(key: String, data: Data, service: String, accessible: CFString?) {
|
||||||
|
if serviceStorage[service] == nil {
|
||||||
|
serviceStorage[service] = [:]
|
||||||
|
}
|
||||||
|
serviceStorage[service]?[key] = data
|
||||||
|
}
|
||||||
|
|
||||||
|
func load(key: String, service: String) -> Data? {
|
||||||
|
serviceStorage[service]?[key]
|
||||||
|
}
|
||||||
|
|
||||||
|
func delete(key: String, service: String) {
|
||||||
|
serviceStorage[service]?.removeValue(forKey: key)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,54 +11,57 @@ import Foundation
|
|||||||
|
|
||||||
final class MockKeychain: KeychainManagerProtocol {
|
final class MockKeychain: KeychainManagerProtocol {
|
||||||
private var storage: [String: Data] = [:]
|
private var storage: [String: Data] = [:]
|
||||||
|
private var serviceStorage: [String: [String: Data]] = [:]
|
||||||
|
|
||||||
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
|
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
|
||||||
storage[key] = keyData
|
storage[key] = keyData
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func getIdentityKey(forKey key: String) -> Data? {
|
func getIdentityKey(forKey key: String) -> Data? {
|
||||||
storage[key]
|
storage[key]
|
||||||
}
|
}
|
||||||
|
|
||||||
func deleteIdentityKey(forKey key: String) -> Bool {
|
func deleteIdentityKey(forKey key: String) -> Bool {
|
||||||
storage.removeValue(forKey: key)
|
storage.removeValue(forKey: key)
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func deleteAllKeychainData() -> Bool {
|
func deleteAllKeychainData() -> Bool {
|
||||||
storage.removeAll()
|
storage.removeAll()
|
||||||
|
serviceStorage.removeAll()
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func secureClear(_ data: inout Data) {
|
func secureClear(_ data: inout Data) {
|
||||||
//
|
|
||||||
data = Data()
|
data = Data()
|
||||||
}
|
}
|
||||||
|
|
||||||
func secureClear(_ string: inout String) {
|
func secureClear(_ string: inout String) {
|
||||||
string = ""
|
string = ""
|
||||||
}
|
}
|
||||||
|
|
||||||
func verifyIdentityKeyExists() -> Bool {
|
func verifyIdentityKeyExists() -> Bool {
|
||||||
storage["identity_noiseStaticKey"] != nil
|
storage["identity_noiseStaticKey"] != nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||||
|
|
||||||
|
func save(key: String, data: Data, service: String, accessible: CFString?) {
|
||||||
|
if serviceStorage[service] == nil {
|
||||||
|
serviceStorage[service] = [:]
|
||||||
|
}
|
||||||
|
serviceStorage[service]?[key] = data
|
||||||
|
}
|
||||||
|
|
||||||
|
func load(key: String, service: String) -> Data? {
|
||||||
|
serviceStorage[service]?[key]
|
||||||
|
}
|
||||||
|
|
||||||
|
func delete(key: String, service: String) {
|
||||||
|
serviceStorage[service]?.removeValue(forKey: key)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
final class MockKeychainHelper: KeychainHelperProtocol {
|
/// Typealias for backwards compatibility with tests using MockKeychainHelper
|
||||||
private typealias Service = String
|
typealias MockKeychainHelper = MockKeychain
|
||||||
private typealias Key = String
|
|
||||||
private var storage: [Service: [Key: Data]] = [:]
|
|
||||||
|
|
||||||
func save(key: String, data: Data, service: String, accessible: CFString?) {
|
|
||||||
storage[service]?[key] = data
|
|
||||||
}
|
|
||||||
|
|
||||||
func load(key: String, service: String) -> Data? {
|
|
||||||
storage[service]?[key]
|
|
||||||
}
|
|
||||||
|
|
||||||
func delete(key: String, service: String) {
|
|
||||||
storage[service]?.removeValue(forKey: key)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user