Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fa45ee3aea | ||
|
|
e8fb4a6333 | ||
|
|
4cfcefcda6 | ||
|
|
3e137d784c | ||
|
|
452e9e74fd | ||
|
|
3afd74ffc8 | ||
|
|
951e056a55 | ||
|
|
d265cfc765 | ||
|
|
473f5c7cce | ||
|
|
b5834cfc76 | ||
|
|
097d916da7 | ||
|
|
4b000b0785 | ||
|
|
19437a0bc6 | ||
|
|
34bae4a89d | ||
|
|
0331871980 | ||
|
|
f9f6ac92b8 | ||
|
|
ca374fd823 | ||
|
|
96f2986d65 | ||
|
|
b6e45e3228 | ||
|
|
c88ab3dd05 | ||
|
|
7d83310bc2 | ||
|
|
264a95b61a | ||
|
|
8562a76367 | ||
|
|
7e86d2061f | ||
|
|
a136b5b7e9 | ||
|
|
c043cf6354 | ||
|
|
72093f9648 | ||
|
|
187a5c3195 | ||
|
|
02b2a006c5 | ||
|
|
2403a6eb90 | ||
|
|
e47c5ae7b3 | ||
|
|
c1f5868d2d | ||
|
|
0515f4c6e8 | ||
|
|
8c7e3e7b9b | ||
|
|
90a5e8ba9d | ||
|
|
6206184862 | ||
|
|
74cf0d89cc | ||
|
|
b4b6aa5ca6 | ||
|
|
1e5a52f39f | ||
|
|
3fc64f6168 | ||
|
|
9964710de2 | ||
|
|
806c420313 | ||
|
|
194dedac43 | ||
|
|
9af46a9ff8 | ||
|
|
da3fcd5a21 | ||
|
|
b282536080 | ||
|
|
e156356c71 | ||
|
|
81a6e18d04 | ||
|
|
4fbbd24021 | ||
|
|
ec54877140 | ||
|
|
293d627c28 | ||
|
|
0c3f84224c | ||
|
|
7323c0b96c | ||
|
|
7bb835ffc9 | ||
|
|
23d63ab4df | ||
|
|
fa3c74f941 | ||
|
|
9bac52051a | ||
|
|
7b9ffe464a | ||
|
|
7b940485d9 | ||
|
|
5a87ee3e62 | ||
|
|
342eabbc00 | ||
|
|
241ce2d52c | ||
|
|
18b56e7393 | ||
|
|
beb04fc887 | ||
|
|
5fcffefa28 | ||
|
|
46ae039587 | ||
|
|
917f7ebe5f | ||
|
|
b47fb736f4 | ||
|
|
ebb5bb6558 | ||
|
|
7cfdcfe174 | ||
|
|
21e0cbc607 | ||
|
|
1b439a543e | ||
|
|
d30a3b14cf | ||
|
|
d03128612d | ||
|
|
ae294aab6d | ||
|
|
07b0e146f2 | ||
|
|
cc5939cb13 | ||
|
|
cada784844 | ||
|
|
b1aeb931bc | ||
|
|
b675738664 | ||
|
|
4091a30f10 | ||
|
|
238311aefb | ||
|
|
6defae71c6 | ||
|
|
b533d9560d | ||
|
|
f41a390a94 | ||
|
|
f83316bd1f | ||
|
|
09818a02ed | ||
|
|
9cd955ae2f | ||
|
|
49b1413d85 | ||
|
|
31be6b83a7 | ||
|
|
1563209797 | ||
|
|
99896bcded | ||
|
|
4b3077169a | ||
|
|
b84c36c6fa | ||
|
|
3eac5858e4 | ||
|
|
10b7c1fd80 | ||
|
|
bf3249aef7 | ||
|
|
95a6ec7315 | ||
|
|
74864472c7 | ||
|
|
9404c03477 | ||
|
|
6faa46a22f | ||
|
|
e02f4327c0 | ||
|
|
ce31d85323 | ||
|
|
b6d8a5b758 | ||
|
|
6630f5a792 | ||
|
|
0f5299a0f5 | ||
|
|
eb3bbfd861 | ||
|
|
a37243e780 | ||
|
|
90b134186b | ||
|
|
3c7e14f49d | ||
|
|
31275856dd | ||
|
|
b6cf44a824 | ||
|
|
b6ae08be60 | ||
|
|
d469704c34 | ||
|
|
c975abf2ff | ||
|
|
aff700a15e | ||
|
|
869d766f8d | ||
|
|
1b4f120014 | ||
|
|
bc312e4aef | ||
|
|
6e7509f2be | ||
|
|
ca06f4d51d | ||
|
|
04f57e8713 | ||
|
|
59c3c4e236 | ||
|
|
e887e04f40 | ||
|
|
151b68a497 | ||
|
|
b4a3ee5777 | ||
|
|
8d19d6d62c | ||
|
|
84fd92ef4b | ||
|
|
f71bd506fd | ||
|
|
ddd7ef5668 | ||
|
|
548a20e77d | ||
|
|
6e231d10c5 | ||
|
|
4c9f6e689e | ||
|
|
7e73b65240 | ||
|
|
f5e5f7b98e | ||
|
|
b15d92ebb5 | ||
|
|
6efe9d02fb | ||
|
|
5a66f03400 | ||
|
|
a221b22691 | ||
|
|
4b38e9a23c | ||
|
|
2686d9c82c | ||
|
|
832e1f006c | ||
|
|
090c4cd919 | ||
|
|
37c2b3a8c2 | ||
|
|
6f1c879237 | ||
|
|
81f5101390 | ||
|
|
d56674706d | ||
|
|
33bcfa3147 | ||
|
|
3a54160793 | ||
|
|
5d2745eae6 | ||
|
|
5138ce4a33 | ||
|
|
07a4997192 | ||
|
|
2d703f4dd9 | ||
|
|
56b9457fcf | ||
|
|
9e57bce5c3 | ||
|
|
6eef030386 | ||
|
|
9d8754099d | ||
|
|
7fae4e71fb | ||
|
|
76d8b3fa7f | ||
|
|
b8a8b940b7 | ||
|
|
7a5ab52f4c | ||
|
|
d2edb651c1 | ||
|
|
858e878959 | ||
|
|
fa0a15cbcf | ||
|
|
3e680f40bf | ||
|
|
ec3c16176e | ||
|
|
2a8de7e048 | ||
|
|
e9dd30ccbf | ||
|
|
af28faa91d | ||
|
|
b33fe8086d | ||
|
|
5495874b5a | ||
|
|
0fca551966 | ||
|
|
0492480598 | ||
|
|
86f46c8b90 | ||
|
|
7057fe75b0 | ||
|
|
873788b24f | ||
|
|
b6dd31b285 | ||
|
|
ff7e5a2c2c | ||
|
|
708a5e33cd | ||
|
|
f893f0605a | ||
|
|
ce33132a0f | ||
|
|
c538837300 | ||
|
|
6888bfa351 | ||
|
|
2fed4b7c31 | ||
|
|
b956e407ff | ||
|
|
477cc7fa05 | ||
|
|
dffce9d63f | ||
|
|
792eaa3166 | ||
|
|
6ff9b59ff2 | ||
|
|
bc04cd0bde | ||
|
|
3fe417395e | ||
|
|
e35bd57c6e | ||
|
|
5aefb05a8b | ||
|
|
e4cbf382ce | ||
|
|
7609c6eeba | ||
|
|
f37acf7e4b | ||
|
|
cf528b0daf | ||
|
|
209ccb4ade | ||
|
|
1876e85f8b | ||
|
|
109b7d0e03 | ||
|
|
09a319fb0f | ||
|
|
97ca55cc54 | ||
|
|
394836f247 | ||
|
|
97fc21c23f | ||
|
|
79bd4af912 | ||
|
|
96c78ef5a2 | ||
|
|
01256f3041 | ||
|
|
2edbe2bbbd | ||
|
|
a91978c10e | ||
|
|
14c4e586fc | ||
|
|
83779240ae | ||
|
|
5034732515 | ||
|
|
b6ce4fae43 | ||
|
|
98fa02cc16 | ||
|
|
0812cafd55 | ||
|
|
450955525c | ||
|
|
475bc70c71 | ||
|
|
af6136c01c | ||
|
|
b839ce5f6c | ||
|
|
0776c9813c | ||
|
|
0dd999af6b | ||
|
|
c3a1af7023 | ||
|
|
880813f256 | ||
|
|
64fb634166 | ||
|
|
13b19fb8eb | ||
|
|
d4967ae9c3 | ||
|
|
435744a977 | ||
|
|
70caa9e24a | ||
|
|
5084f87fe5 | ||
|
|
8f56e4f0fb | ||
|
|
aca44f9f55 | ||
|
|
3f00cf9467 | ||
|
|
40e54a5120 | ||
|
|
7040d9ecb0 | ||
|
|
88bafb41cc | ||
|
|
fb43a8b0f5 | ||
|
|
eb35608fa1 | ||
|
|
b81ae0b4c0 | ||
|
|
b6d42261d0 | ||
|
|
3d914dcf46 | ||
|
|
b3ec5eeda0 | ||
|
|
47d75ab9d8 | ||
|
|
3479c7d5df | ||
|
|
8a0727fcf7 | ||
|
|
6588861e34 | ||
|
|
a1647901e5 | ||
|
|
23249f3e41 | ||
|
|
ad4103bacc | ||
|
|
e3149fa098 | ||
|
|
987ba2e694 | ||
|
|
615273a63e | ||
|
|
4563c22d2d | ||
|
|
9f74266527 | ||
|
|
239064e4eb | ||
|
|
d371131ad5 | ||
|
|
d994ccf012 | ||
|
|
302c741d58 | ||
|
|
7ec84857eb | ||
|
|
68482c67d7 | ||
|
|
551a843691 | ||
|
|
fbc15ea08f | ||
|
|
0f23ed0a99 | ||
|
|
c583949031 | ||
|
|
d75700fa2b | ||
|
|
7149182c56 | ||
|
|
13b58aeaa9 | ||
|
|
b5b05977fb | ||
|
|
af6703cf24 | ||
|
|
eb13eec4c5 | ||
|
|
81c90b2924 | ||
|
|
8c368233c4 | ||
|
|
13ebaad42f | ||
|
|
10e3f574ab | ||
|
|
5f44c56a90 | ||
|
|
01ec4573f8 | ||
|
|
f86ae5e2ea | ||
|
|
2673d28686 | ||
|
|
03c357f048 | ||
|
|
64f91bb1d6 | ||
|
|
9ecda048e7 | ||
|
|
bdc31d3be3 | ||
|
|
6846b19d83 | ||
|
|
524a7e916b | ||
|
|
f2473f857b | ||
|
|
8cfee095d3 | ||
|
|
e4ec2ef3fe | ||
|
|
bd11940151 | ||
|
|
90273cee2d | ||
|
|
faae625e53 | ||
|
|
3a35b3acc2 | ||
|
|
787386c66d | ||
|
|
aeec15f054 | ||
|
|
f004f3e7ea | ||
|
|
8d938e8518 | ||
|
|
ea72212f66 | ||
|
|
3183703a63 | ||
|
|
2ffa709cca | ||
|
|
bf712a0610 | ||
|
|
78fb3f1bf6 | ||
|
|
f5af00be88 | ||
|
|
b2214e30f5 | ||
|
|
85063e9359 | ||
|
|
f67f728d79 | ||
|
|
b873b19104 | ||
|
|
0f7bcf17ff | ||
|
|
da2a12296e | ||
|
|
56bd100944 | ||
|
|
eb5bc96a3c | ||
|
|
d01538a2ea | ||
|
|
9abfab3248 | ||
|
|
0ae09f73d8 | ||
|
|
56dd12f3b1 | ||
|
|
f5caa1751a | ||
|
|
de906cb97c | ||
|
|
a41ec65f58 | ||
|
|
1fd2da18f5 | ||
|
|
c49a1b264e | ||
|
|
10c0391eaf | ||
|
|
3a94b57341 | ||
|
|
f8f780d2d6 | ||
|
|
c837afb818 | ||
|
|
47ef82f01a | ||
|
|
d1e5ce21a7 | ||
|
|
f2c1bb2131 | ||
|
|
221819b591 | ||
|
|
4a21ab0531 | ||
|
|
50ae8da5f9 | ||
|
|
54bb812469 | ||
|
|
482fca81ef | ||
|
|
b2e7d2d26e | ||
|
|
6a2832d22b | ||
|
|
56e7324069 | ||
|
|
1733dda6cd | ||
|
|
00ff5fd31c | ||
|
|
f684c452b2 | ||
|
|
9cbdb0a764 | ||
|
|
d1682db79b | ||
|
|
6a6504c6f2 | ||
|
|
ea8d51a36b | ||
|
|
347ce5ece4 | ||
|
|
7c4bde59b9 | ||
|
|
2ac01db9c4 | ||
|
|
42cdc4c123 | ||
|
|
fb94e799a5 | ||
|
|
04671caeb8 | ||
|
|
a485335649 | ||
|
|
de2b5ed142 | ||
|
|
57cc9028cb | ||
|
|
b0a50c663f | ||
|
|
0a98844c1a | ||
|
|
efb9a5070d | ||
|
|
2870acdcc7 | ||
|
|
920dc31795 | ||
|
|
bb3d99bdca | ||
|
|
b01cac4649 | ||
|
|
4b0634d1d0 | ||
|
|
97cbe37f09 | ||
|
|
b5d6e4eeb5 | ||
|
|
a1edf29bd3 | ||
|
|
5f402698a1 | ||
|
|
1e997e1387 | ||
|
|
e602024617 | ||
|
|
deb464f5d8 | ||
|
|
e5a415d885 | ||
|
|
b5382b129e | ||
|
|
5d6aecfc83 | ||
|
|
5ca9222fc2 | ||
|
|
ee16ff5ff4 | ||
|
|
2f83433247 | ||
|
|
e72fe50ffa | ||
|
|
56f1c37129 | ||
|
|
2ade3a3300 | ||
|
|
5f44af19da | ||
|
|
6e1fb15edf | ||
|
|
9166c9e28b | ||
|
|
0ce68bc762 | ||
|
|
5273f13512 | ||
|
|
e79bcf531b | ||
|
|
3e5043f875 | ||
|
|
11cd5527ed | ||
|
|
cf1bfdac6b | ||
|
|
b63a595b04 | ||
|
|
d7b7f1f673 | ||
|
|
7aa3622349 | ||
|
|
96c6fc0c0d | ||
|
|
a7d5b2d7d9 | ||
|
|
680a390b2d | ||
|
|
60b0deee7b | ||
|
|
2f7c0aaaf7 | ||
|
|
7c4c3f1391 | ||
|
|
3c06bd6386 | ||
|
|
acc11101ad | ||
|
|
5fd9140ffa | ||
|
|
e6903456ab | ||
|
|
85f99984c4 | ||
|
|
75c8933091 | ||
|
|
d2bfbbcfd4 | ||
|
|
0260798712 | ||
|
|
2758afa126 | ||
|
|
2229a28bb4 | ||
|
|
dadc896ed8 | ||
|
|
b2504a7ff5 | ||
|
|
7f2cbd6621 | ||
|
|
60a42ffecb | ||
|
|
27e5e2962c | ||
|
|
9d5105a8bf | ||
|
|
d4b779080a | ||
|
|
4bfe9ac80d | ||
|
|
adffe7dfd6 | ||
|
|
16fdb7b49e | ||
|
|
ff5fd3f3fe | ||
|
|
f8a955214b | ||
|
|
d5e712e27f | ||
|
|
244c8cdf81 | ||
|
|
0d064084aa | ||
|
|
7b49268694 | ||
|
|
5650e1f2c2 | ||
|
|
c4b422ad3f | ||
|
|
e82fda1093 | ||
|
|
806d451135 | ||
|
|
13f8b0c636 | ||
|
|
2d0f9aff0a | ||
|
|
83ee5abb60 | ||
|
|
bc27e16899 | ||
|
|
d3d9a22757 | ||
|
|
8a269d4fec | ||
|
|
33fbca67d6 | ||
|
|
c63350a4d3 | ||
|
|
222854c60a | ||
|
|
c624611e7d | ||
|
|
eb0debd52a | ||
|
|
916f535503 | ||
|
|
de39ab6687 | ||
|
|
a0a973eb81 | ||
|
|
ba1dd100ec | ||
|
|
97b1463b30 | ||
|
|
28c87a41c1 | ||
|
|
68c61476d8 | ||
|
|
602e93d1b2 | ||
|
|
e7706fc9cb | ||
|
|
f30677403f | ||
|
|
b4fcea2672 | ||
|
|
43166bcd64 | ||
|
|
496972dcc9 | ||
|
|
3074fa0fcb | ||
|
|
bdbcbb5d2b | ||
|
|
ed4d8b667e | ||
|
|
a29f517783 | ||
|
|
78917fa7c9 | ||
|
|
eb16d128f2 | ||
|
|
b09710a7aa | ||
|
|
1c33a92765 | ||
|
|
a30b73dd99 | ||
|
|
4c0bb5f93a | ||
|
|
7836daa6d3 | ||
|
|
4f1ac30f12 | ||
|
|
6fbf7eee25 | ||
|
|
3ebfa85e90 | ||
|
|
fb1988ac27 | ||
|
|
845ffc601b | ||
|
|
47b0829685 | ||
|
|
030d6e0f11 | ||
|
|
db3c3b77f5 | ||
|
|
26bcdf72d7 | ||
|
|
275f0ebaaf | ||
|
|
f4b8168ef9 | ||
|
|
63f05b5d7e | ||
|
|
a36eda3fbe | ||
|
|
99c0f6523e | ||
|
|
7a7c89e689 | ||
|
|
3226b9cd14 | ||
|
|
04c2b0caa6 | ||
|
|
29f1308e37 | ||
|
|
c6c186c77b | ||
|
|
d4262fab6c | ||
|
|
7876c8d96f | ||
|
|
397c9f182b | ||
|
|
3ed37dfd0b | ||
|
|
327fca9cb1 | ||
|
|
871456896d | ||
|
|
b4b22e0e05 | ||
|
|
8ec39f566d | ||
|
|
172b06721b | ||
|
|
e2d50e3684 | ||
|
|
d605a0b6db | ||
|
|
1d698c2006 | ||
|
|
a92828471b | ||
|
|
69c8161cf8 | ||
|
|
aa1ecf40fc | ||
|
|
b004bfa4aa | ||
|
|
a6c2e751d2 | ||
|
|
8f32edaa64 | ||
|
|
5a44b32719 | ||
|
|
d85c9e226b | ||
|
|
f953c50565 | ||
|
|
2a081f65fc | ||
|
|
71b7f8edd3 | ||
|
|
46fd1d23d9 | ||
|
|
6a9a1cdb3b | ||
|
|
c74d6ad75e | ||
|
|
439fb59fdd | ||
|
|
0a5e4b248f |
@@ -0,0 +1,20 @@
|
||||
# Prevent Github Languages stats skewing:
|
||||
|
||||
# Binaries and assets
|
||||
**/*.xcframework/** linguist-vendored
|
||||
**/*.xcassets/** linguist-vendored
|
||||
|
||||
# Generated files
|
||||
**/*.pbxproj linguist-generated
|
||||
**/*.storyboard linguist-generated
|
||||
Package.resolved linguist-generated
|
||||
|
||||
# Downloaded CSVs
|
||||
relays/online_relays_gps.csv linguist-vendored
|
||||
|
||||
# Docs
|
||||
**/*.md linguist-documentation
|
||||
|
||||
# Configs
|
||||
Configs/*.xcconfig linguist-documentation
|
||||
**/*.plist linguist-documentation
|
||||
@@ -0,0 +1,42 @@
|
||||
name: Fetch GeoRelays Data
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '0 6 * * 0'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
update-relay-data:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Fetch GeoRelays
|
||||
run: |
|
||||
wget -q https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv
|
||||
mv nostr_relays.csv ./relays/online_relays_gps.csv
|
||||
|
||||
- name: Check for changes
|
||||
id: git-check
|
||||
run: |
|
||||
git diff --exit-code || echo "changes=true" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Commit and push changes
|
||||
if: steps.git-check.outputs.changes == 'true'
|
||||
run: |
|
||||
git config --local user.email "action@github.com"
|
||||
git config --local user.name "GitHub Action"
|
||||
git add relays/online_relays_gps.csv
|
||||
git commit -m "Automated update of relay data - $(date -u)"
|
||||
git push
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
@@ -0,0 +1,46 @@
|
||||
name: Build & Test
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: Run Swift Tests (${{ matrix.name }})
|
||||
runs-on: macos-latest
|
||||
|
||||
strategy:
|
||||
fail-fast: false # Don't cancel other matrix jobs when one fails
|
||||
matrix:
|
||||
include:
|
||||
- name: app
|
||||
path: .
|
||||
- name: BitLogger
|
||||
path: localPackages/BitLogger
|
||||
- name: BitFoundation
|
||||
path: localPackages/BitFoundation
|
||||
- name: Noise
|
||||
path: localPackages/Noise
|
||||
- name: Nostr
|
||||
path: localPackages/Nostr
|
||||
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@v5
|
||||
|
||||
- name: Set up Swift
|
||||
uses: swift-actions/setup-swift@v2
|
||||
|
||||
- name: Cache build artifacts
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: ${{ matrix.path }}/.build
|
||||
key: ${{ runner.os }}-${{ matrix.name }}-${{ hashFiles(format('{0}/**/*.swift', matrix.path), format('{0}/**/Package.resolved', matrix.path)) }}
|
||||
restore-keys: |
|
||||
${{ runner.os }}-${{ matrix.name }}-${{ hashFiles(format('{0}/**/Package.resolved', matrix.path)) }}
|
||||
${{ runner.os }}-${{ matrix.name }}-
|
||||
|
||||
- name: Run Tests
|
||||
run: swift test --parallel --quiet --package-path ${{ matrix.path }}
|
||||
@@ -5,8 +5,10 @@
|
||||
## implementation plans
|
||||
plans/
|
||||
|
||||
## User settings
|
||||
xcuserdata/
|
||||
## AI
|
||||
CLAUDE.md
|
||||
AGENTS.md
|
||||
.claude/
|
||||
|
||||
## compatibility with Xcode 8 and earlier (ignoring not required starting Xcode 9)
|
||||
*.xcscmblueprint
|
||||
@@ -15,6 +17,7 @@ xcuserdata/
|
||||
## compatibility with Xcode 3 and earlier (ignoring not required starting Xcode 4)
|
||||
build/
|
||||
DerivedData/
|
||||
.DerivedData/
|
||||
*.moved-aside
|
||||
*.pbxuser
|
||||
!default.pbxuser
|
||||
@@ -52,7 +55,8 @@ iOSInjectionProject/
|
||||
|
||||
## Xcode project
|
||||
*.xcodeproj/project.xcworkspace/
|
||||
*.xcodeproj/xcshareddata/
|
||||
## Xcode User settings
|
||||
xcuserdata/
|
||||
|
||||
## Python
|
||||
__pycache__/
|
||||
@@ -62,3 +66,17 @@ __pycache__/
|
||||
## Temporary files
|
||||
*.tmp
|
||||
*.temp
|
||||
|
||||
## Cache
|
||||
.cache/
|
||||
|
||||
# Local build results
|
||||
.Result*/
|
||||
.Result*.xcresult/
|
||||
TestResult.xcresult/
|
||||
*.xcresult/
|
||||
build.log
|
||||
*.log
|
||||
|
||||
# Local configs
|
||||
Local.xcconfig
|
||||
|
||||
@@ -1,472 +0,0 @@
|
||||
# AI Context for BitChat
|
||||
|
||||
This document provides essential context for AI assistants working on the BitChat codebase. Read this first to understand the project's architecture, design decisions, and key concepts.
|
||||
|
||||
## Project Overview
|
||||
|
||||
BitChat is a decentralized, peer-to-peer messaging application that works over Bluetooth mesh networks without requiring internet connectivity, servers, or phone numbers. It's designed for scenarios where traditional communication infrastructure is unavailable or untrusted.
|
||||
|
||||
### Key Features
|
||||
- **Bluetooth Mesh Networking**: Multi-hop message relay over BLE
|
||||
- **Privacy-First Design**: No accounts, no persistent identifiers
|
||||
- **End-to-End Encryption**: Uses Noise Protocol Framework for private messages
|
||||
- **Store & Forward**: Messages cached for offline peers
|
||||
- **IRC-Style Commands**: Familiar `/msg`, `/who` interface
|
||||
- **Cross-Platform**: Native iOS and macOS support
|
||||
- **Nostr Integration**: Seamless fallback for mutual favorites when out of Bluetooth range
|
||||
- **Hybrid Transport**: Automatic switching between Bluetooth and Nostr
|
||||
|
||||
## Architecture Overview
|
||||
|
||||
```
|
||||
┌─────────────────────────────────────────────────────────────────┐
|
||||
│ User Interface │
|
||||
│ (ContentView, ChatViewModel) │
|
||||
└─────────────────────────────────────────────────────────────────┘
|
||||
│
|
||||
┌─────────────────────────────────────────────────────────────────┐
|
||||
│ Application Services │
|
||||
│ (MessageRetryService, DeliveryTracker, NotificationService) │
|
||||
└─────────────────────────────────────────────────────────────────┘
|
||||
│
|
||||
┌─────────────────────────────────────────────────────────────────┐
|
||||
│ Message Router │
|
||||
│ (Transport selection, Favorites integration) │
|
||||
└─────────────────────────────────────────────────────────────────┘
|
||||
│ │
|
||||
┌───────────────────────────────┐ ┌────────────────────────────────┐
|
||||
│ Security Layer │ │ Nostr Protocol Layer │
|
||||
│ (NoiseEncryptionService, │ │ (NostrProtocol, NIP-17, │
|
||||
│ SecureIdentityStateManager) │ │ NostrRelayManager) │
|
||||
└───────────────────────────────┘ └────────────────────────────────┘
|
||||
│ │
|
||||
┌───────────────────────────────┐ ┌────────────────────────────────┐
|
||||
│ Protocol Layer │ │ Transport │
|
||||
│ (BitchatProtocol, Binary- │ │ (WebSocket to Nostr │
|
||||
│ Protocol, NoiseProtocol) │ │ relay servers) │
|
||||
└───────────────────────────────┘ └────────────────────────────────┘
|
||||
│
|
||||
┌─────────────────────────────────────────────────────────────────┐
|
||||
│ Bluetooth Transport Layer │
|
||||
│ (BluetoothMeshService) │
|
||||
└─────────────────────────────────────────────────────────────────┘
|
||||
```
|
||||
|
||||
## Core Components
|
||||
|
||||
### 1. BluetoothMeshService (Transport Layer)
|
||||
- **Location**: `bitchat/Services/BluetoothMeshService.swift`
|
||||
- **Purpose**: Manages BLE connections and implements mesh networking
|
||||
- **Key Responsibilities**:
|
||||
- Peer discovery (scanning and advertising simultaneously)
|
||||
- Connection management (acts as both central and peripheral)
|
||||
- Message routing and relay
|
||||
- Version negotiation with peers
|
||||
- Automatic reconnection and topology management
|
||||
|
||||
### 2. BitchatProtocol (Protocol Layer)
|
||||
- **Location**: `bitchat/Protocols/BitchatProtocol.swift`
|
||||
- **Purpose**: Defines the application-level messaging protocol
|
||||
- **Key Features**:
|
||||
- Binary packet format for efficiency
|
||||
- Message types: Chat, Announcement, PrivateMessage, etc.
|
||||
- TTL-based routing (max 7 hops)
|
||||
- Message deduplication via unique IDs
|
||||
- Privacy features: padding, timing obfuscation
|
||||
|
||||
### 3. NoiseProtocol Implementation
|
||||
- **Locations**:
|
||||
- `bitchat/Noise/NoiseProtocol.swift` - Core protocol implementation
|
||||
- `bitchat/Noise/NoiseSession.swift` - Session management
|
||||
- `bitchat/Services/NoiseEncryptionService.swift` - High-level encryption API
|
||||
- **Purpose**: Provides end-to-end encryption for private messages
|
||||
- **Implementation Details**:
|
||||
- Uses Noise_XX_25519_AESGCM_SHA256 pattern
|
||||
- Mutual authentication via static keys
|
||||
- Forward secrecy via ephemeral keys
|
||||
- Integrated with identity management
|
||||
|
||||
### 4. Identity System
|
||||
- **Location**: `bitchat/Identity/`
|
||||
- **Three-Layer Model**:
|
||||
1. **Ephemeral Identity**: Short-lived, rotates frequently
|
||||
2. **Cryptographic Identity**: Long-term Noise static keypair
|
||||
3. **Social Identity**: User-chosen nickname and metadata
|
||||
- **Trust Levels**: Untrusted → Verified → Trusted → Blocked
|
||||
|
||||
### 5. ChatViewModel
|
||||
- **Location**: `bitchat/ViewModels/ChatViewModel.swift`
|
||||
- **Purpose**: Central state management and business logic
|
||||
- **Responsibilities**:
|
||||
- Message handling and batching
|
||||
- Command processing (/msg, /who, etc.)
|
||||
- UI state management
|
||||
- Private chat coordination
|
||||
|
||||
### 6. Nostr Integration
|
||||
- **Locations**:
|
||||
- `bitchat/Nostr/NostrProtocol.swift` - NIP-17 private message implementation
|
||||
- `bitchat/Nostr/NostrRelayManager.swift` - WebSocket relay connections
|
||||
- `bitchat/Nostr/NostrIdentity.swift` - Nostr key management
|
||||
- `bitchat/Services/MessageRouter.swift` - Transport selection logic
|
||||
- **Purpose**: Enables communication with mutual favorites when out of Bluetooth range
|
||||
- **Key Features**:
|
||||
- NIP-17 gift-wrapped private messages for metadata privacy
|
||||
- Automatic relay connection management
|
||||
- Seamless transport switching between Bluetooth and Nostr
|
||||
- Integrated with favorites system for mutual authentication
|
||||
|
||||
### 7. MessageRouter
|
||||
- **Location**: `bitchat/Services/MessageRouter.swift`
|
||||
- **Purpose**: Intelligent routing between Bluetooth mesh and Nostr transports
|
||||
- **Transport Selection Logic**:
|
||||
1. Always prefer Bluetooth mesh when peer is connected
|
||||
2. Use Nostr for mutual favorites when peer is offline
|
||||
3. Fail gracefully when no transport is available
|
||||
- **Message Types Routed**:
|
||||
- Regular chat messages
|
||||
- Favorite/unfavorite notifications
|
||||
- Delivery acknowledgments
|
||||
- Read receipts
|
||||
|
||||
## Key Design Decisions
|
||||
|
||||
### 1. Protocol Design
|
||||
- **Binary Protocol**: Chosen for efficiency over BLE's limited bandwidth
|
||||
- **No JSON**: Reduces parsing overhead and message size
|
||||
- **Custom Framing**: Handles BLE's 512-byte MTU limitations
|
||||
|
||||
### 2. Security Architecture
|
||||
- **Noise Protocol**: Industry-standard, well-analyzed framework
|
||||
- **XX Pattern**: Provides mutual authentication and forward secrecy
|
||||
- **No Long-Term Identifiers**: Enhances privacy and deniability
|
||||
|
||||
### 3. Mesh Networking
|
||||
- **Store & Forward**: Essential for intermittent connectivity
|
||||
- **TTL-Based Routing**: Prevents infinite loops in mesh
|
||||
- **Bloom Filters**: Efficient duplicate detection
|
||||
|
||||
### 4. Privacy Features
|
||||
- **Message Padding**: Obscures message length
|
||||
- **Cover Traffic**: Optional dummy messages
|
||||
- **Timing Obfuscation**: Randomized delays
|
||||
- **Emergency Wipe**: Triple-tap to clear all data
|
||||
|
||||
### 5. Nostr Integration
|
||||
- **NIP-17 Gift Wraps**: Maximum metadata privacy
|
||||
- **Ephemeral Keys**: Each message uses unique ephemeral keys
|
||||
- **Mutual Favorites Only**: Requires bidirectional trust
|
||||
- **Transport Abstraction**: Users don't need to know about Nostr
|
||||
|
||||
## Code Organization
|
||||
|
||||
### Services (`/bitchat/Services/`)
|
||||
Application-level services that coordinate between layers:
|
||||
- `BluetoothMeshService`: Core networking
|
||||
- `NoiseEncryptionService`: Encryption coordination
|
||||
- `MessageRetryService`: Reliability layer
|
||||
- `DeliveryTracker`: Acknowledgment handling
|
||||
- `NotificationService`: System notifications
|
||||
|
||||
### Protocols (`/bitchat/Protocols/`)
|
||||
Protocol definitions and implementations:
|
||||
- `BitchatProtocol`: Application protocol
|
||||
- `BinaryProtocol`: Low-level encoding
|
||||
- `BinaryEncodingUtils`: Helper functions
|
||||
|
||||
### Noise (`/bitchat/Noise/`)
|
||||
Noise Protocol Framework implementation:
|
||||
- `NoiseProtocol`: Core cryptographic operations
|
||||
- `NoiseSession`: Session state management
|
||||
- `NoiseHandshakeCoordinator`: Handshake orchestration
|
||||
- `NoiseSecurityConsiderations`: Security validations
|
||||
|
||||
### Views & ViewModels
|
||||
MVVM architecture for UI:
|
||||
- `ContentView`: Main chat interface
|
||||
- `ChatViewModel`: Business logic and state
|
||||
- Supporting views for settings, identity, etc.
|
||||
|
||||
## Nostr Protocol Implementation
|
||||
|
||||
### Overview
|
||||
BitChat integrates Nostr as a secondary transport for communicating with mutual favorites when Bluetooth connectivity is unavailable. This integration is transparent to users - messages automatically route through Nostr when needed.
|
||||
|
||||
### NIP-17 Private Direct Messages
|
||||
BitChat implements NIP-17 (Private Direct Messages) for metadata-private communication:
|
||||
|
||||
1. **Gift Wrap Structure**:
|
||||
```
|
||||
Gift Wrap (kind 1059) → Seal (kind 13) → Rumor (kind 1)
|
||||
```
|
||||
- **Rumor**: The actual message content (unsigned)
|
||||
- **Seal**: Encrypted rumor, hides sender identity
|
||||
- **Gift Wrap**: Double-encrypted, tagged for recipient
|
||||
|
||||
2. **Ephemeral Keys**:
|
||||
- Each message uses TWO ephemeral key pairs
|
||||
- Seal uses one ephemeral key
|
||||
- Gift wrap uses a different ephemeral key
|
||||
- Provides sender anonymity and forward secrecy
|
||||
|
||||
3. **Timestamp Randomization**:
|
||||
- ±1 minute randomization (reduced from NIP-17's ±15 minutes)
|
||||
- Prevents timing correlation attacks
|
||||
- Configurable in `NostrProtocol.randomizedTimestamp()`
|
||||
|
||||
### Favorites Integration
|
||||
|
||||
The Nostr transport is only available for mutual favorites:
|
||||
|
||||
1. **Favorite Establishment**:
|
||||
- User favorites a peer via `/fav` command
|
||||
- Favorite notification sent via Bluetooth (if connected)
|
||||
- Peer's Nostr public key exchanged during favorite process
|
||||
- Stored in `FavoritesPersistenceService`
|
||||
|
||||
2. **Mutual Requirement**:
|
||||
- Both peers must favorite each other
|
||||
- Prevents spam and unwanted Nostr messages
|
||||
- Enforced by `MessageRouter` transport selection
|
||||
|
||||
3. **Nostr Key Management**:
|
||||
- Derived from Noise static key using BIP-32
|
||||
- Path: `m/44'/1237'/0'/0/0` (1237 = "NOSTR" in decimal)
|
||||
- Consistent npub across app reinstalls
|
||||
- Keys never leave the device
|
||||
|
||||
### Message Routing Logic
|
||||
|
||||
`MessageRouter` automatically selects transport:
|
||||
|
||||
```swift
|
||||
if peerAvailableOnMesh {
|
||||
transport = .bluetoothMesh // Always prefer mesh
|
||||
} else if isMutualFavorite {
|
||||
transport = .nostr // Use Nostr for offline favorites
|
||||
} else {
|
||||
throw MessageRouterError.peerNotReachable
|
||||
}
|
||||
```
|
||||
|
||||
### Relay Configuration
|
||||
|
||||
Default relays (hardcoded for reliability):
|
||||
- `wss://relay.damus.io`
|
||||
- `wss://relay.primal.net`
|
||||
- `wss://offchain.pub`
|
||||
- `wss://nostr21.com`
|
||||
|
||||
Relay selection criteria:
|
||||
- Geographic distribution
|
||||
- High uptime
|
||||
- No authentication required
|
||||
- Support for ephemeral events
|
||||
|
||||
### Message Format
|
||||
|
||||
Structured content for different message types:
|
||||
- Chat: `MSG:<messageID>:<content>`
|
||||
- Favorite: `FAVORITED:<senderNpub>` or `UNFAVORITED:<senderNpub>`
|
||||
- Delivery ACK: `DELIVERED:<messageID>`
|
||||
- Read Receipt: `READ:<base64EncodedReceipt>`
|
||||
|
||||
### Implementation Details
|
||||
|
||||
1. **NostrRelayManager**:
|
||||
- Manages WebSocket connections to relays
|
||||
- Handles reconnection logic
|
||||
- Processes EVENT, EOSE, OK, NOTICE messages
|
||||
- Implements NIP-01 relay protocol
|
||||
|
||||
2. **NostrProtocol**:
|
||||
- Implements NIP-17 encryption/decryption
|
||||
- Handles gift wrap creation/unwrapping
|
||||
- Manages ephemeral key generation
|
||||
- Provides Schnorr signatures
|
||||
|
||||
3. **ProcessedMessagesService**:
|
||||
- Prevents duplicate message processing
|
||||
- Tracks last subscription timestamp
|
||||
- Persists across app launches
|
||||
- 30-day retention window
|
||||
|
||||
### Security Considerations
|
||||
|
||||
1. **Metadata Protection**:
|
||||
- Sender identity hidden via ephemeral keys
|
||||
- Recipient only visible in gift wrap p-tag
|
||||
- Timing correlation prevented via randomization
|
||||
- Message content double-encrypted
|
||||
|
||||
2. **Relay Trust**:
|
||||
- Relays cannot read message content
|
||||
- Relays can see recipient pubkey (gift wrap)
|
||||
- Relays cannot determine sender
|
||||
- Multiple relays used for redundancy
|
||||
|
||||
3. **Key Hygiene**:
|
||||
- Ephemeral keys used once and discarded
|
||||
- Static Nostr key derived from Noise key
|
||||
- No key reuse between messages
|
||||
- Keys cleared from memory after use
|
||||
|
||||
### Debugging Nostr Issues
|
||||
|
||||
1. **Check relay connections**:
|
||||
- Look for "Connected to Nostr relay" in logs
|
||||
- Verify WebSocket state in NostrRelayManager
|
||||
- Check for relay errors/notices
|
||||
|
||||
2. **Verify gift wrap creation**:
|
||||
- Enable debug logging in NostrProtocol
|
||||
- Check ephemeral key generation
|
||||
- Verify encryption steps
|
||||
|
||||
3. **Message delivery**:
|
||||
- Check ProcessedMessagesService for duplicates
|
||||
- Verify subscription filters
|
||||
- Look for EVENT messages in relay responses
|
||||
|
||||
## Development Guidelines
|
||||
|
||||
### 1. Security First
|
||||
- Never log sensitive data (keys, message content)
|
||||
- Use `SecureLogger` for security-aware logging
|
||||
- Validate all inputs from network
|
||||
- Follow principle of least privilege
|
||||
|
||||
### 2. Performance Considerations
|
||||
- BLE has limited bandwidth (~20KB/s practical)
|
||||
- Minimize protocol overhead
|
||||
- Batch operations where possible
|
||||
- Use compression for large messages
|
||||
|
||||
### 3. Testing
|
||||
- Unit tests for protocol logic
|
||||
- Integration tests for service interactions
|
||||
- End-to-end tests for user flows
|
||||
- Mock objects for BLE testing
|
||||
|
||||
### 4. Error Handling
|
||||
- Graceful degradation for network issues
|
||||
- Clear error messages for users
|
||||
- Automatic retry with backoff
|
||||
- Never expose internal errors
|
||||
|
||||
## Common Tasks
|
||||
|
||||
### Adding a New Message Type
|
||||
1. Define in `MessageType` enum in `BitchatProtocol.swift`
|
||||
2. Implement encoding/decoding logic
|
||||
3. Add handling in `ChatViewModel`
|
||||
4. Update UI if needed
|
||||
5. Add tests
|
||||
|
||||
### Implementing a New Command
|
||||
1. Add to `ChatViewModel.processCommand()`
|
||||
2. Define any new message types needed
|
||||
3. Implement command logic
|
||||
4. Add autocomplete support
|
||||
5. Update help text
|
||||
|
||||
### Debugging Bluetooth Issues
|
||||
1. Check `BluetoothMeshService` logs
|
||||
2. Verify peer states and connections
|
||||
3. Monitor characteristic updates
|
||||
4. Use Bluetooth debugging tools
|
||||
|
||||
### Working with Nostr Transport
|
||||
1. Verify mutual favorite status in `FavoritesPersistenceService`
|
||||
2. Check Nostr key derivation in `NostrIdentity`
|
||||
3. Monitor relay connections in `NostrRelayManager`
|
||||
4. Test gift wrap encryption/decryption
|
||||
5. Verify transport selection in `MessageRouter`
|
||||
|
||||
### Adding Nostr Features
|
||||
1. Understand NIP-17 gift wrap structure
|
||||
2. Maintain ephemeral key hygiene
|
||||
3. Test with multiple relays
|
||||
4. Preserve metadata privacy
|
||||
5. Handle relay disconnections gracefully
|
||||
|
||||
## Security Threat Model
|
||||
|
||||
### Assumptions
|
||||
- Adversaries can intercept all Bluetooth traffic
|
||||
- Devices may be compromised
|
||||
- No trusted infrastructure available
|
||||
|
||||
### Protections
|
||||
- End-to-end encryption for private messages
|
||||
- Message authentication via HMAC
|
||||
- Forward secrecy via ephemeral keys
|
||||
- Deniability through lack of signatures
|
||||
|
||||
### Limitations
|
||||
- Public messages are unencrypted by design
|
||||
- Metadata (who talks to whom) partially visible
|
||||
- Timing attacks possible on mesh network
|
||||
- No protection against flooding/spam (yet)
|
||||
|
||||
## Performance Optimizations
|
||||
|
||||
### Implemented
|
||||
- LZ4 compression for messages
|
||||
- Adaptive duty cycling for battery
|
||||
- Connection caching and reuse
|
||||
- Bloom filters for deduplication
|
||||
|
||||
### Future Improvements
|
||||
- Protocol buffer encoding
|
||||
- Better mesh routing algorithms
|
||||
- Predictive pre-connection
|
||||
- Smarter retransmission
|
||||
|
||||
## Troubleshooting Guide
|
||||
|
||||
### Common Issues
|
||||
1. **Peers not discovering**: Check Bluetooth permissions, ensure app is in foreground
|
||||
2. **Messages not delivering**: Verify mesh connectivity, check TTL values
|
||||
3. **Handshake failures**: Ensure identity state is consistent, check key storage
|
||||
4. **Performance issues**: Monitor connection count, check for message loops
|
||||
|
||||
## External Dependencies
|
||||
|
||||
### Swift Packages
|
||||
- CryptoKit: Apple's crypto framework
|
||||
- Network.framework: For future internet support
|
||||
- No third-party dependencies (by design)
|
||||
|
||||
### System Requirements
|
||||
- iOS 14.0+ / macOS 11.0+
|
||||
- Bluetooth LE hardware
|
||||
- ~50MB storage for app + data
|
||||
|
||||
## Future Roadmap
|
||||
|
||||
### Planned Features
|
||||
- Internet bridging for hybrid networks
|
||||
- Group chat with forward secrecy
|
||||
- Voice messages with Opus codec
|
||||
- File transfer support
|
||||
|
||||
### Architecture Evolution
|
||||
- Plugin system for transports
|
||||
- Modular protocol stack
|
||||
- Cross-platform core library
|
||||
- Federation between networks
|
||||
|
||||
---
|
||||
|
||||
## Quick Start for AI Assistants
|
||||
|
||||
1. **Understand the layers**: Transport → Protocol → Security → Services → UI
|
||||
2. **Follow the data flow**: BLE/Nostr → Binary/JSON → Protocol → ViewModel → View
|
||||
3. **Respect security boundaries**: Never mix trusted and untrusted data
|
||||
4. **Test thoroughly**: This is critical infrastructure for users
|
||||
5. **Ask about design decisions**: Many choices have non-obvious reasons
|
||||
6. **Dual Transport**: Remember that messages can flow over Bluetooth OR Nostr
|
||||
7. **Favorites System**: Nostr only works between mutual favorites
|
||||
|
||||
When in doubt, prioritize security and privacy over features. BitChat users depend on this app in situations where traditional communication has failed them.
|
||||
@@ -37,7 +37,7 @@ This three-message pattern provides:
|
||||
#### NoiseEncryptionService
|
||||
The main service managing all Noise operations:
|
||||
```swift
|
||||
class NoiseEncryptionService {
|
||||
final class NoiseEncryptionService {
|
||||
private let staticIdentityKey: Curve25519.KeyAgreement.PrivateKey
|
||||
private let sessionManager: NoiseSessionManager
|
||||
private let channelEncryption = NoiseChannelEncryption()
|
||||
@@ -47,7 +47,7 @@ class NoiseEncryptionService {
|
||||
#### NoiseSession
|
||||
Individual session state for each peer:
|
||||
```swift
|
||||
class NoiseSession {
|
||||
final class NoiseSession {
|
||||
private var handshakeState: NoiseHandshakeState?
|
||||
private var sendCipher: NoiseCipherState?
|
||||
private var receiveCipher: NoiseCipherState?
|
||||
@@ -58,7 +58,7 @@ class NoiseSession {
|
||||
#### NoiseSessionManager
|
||||
Thread-safe session management:
|
||||
```swift
|
||||
class NoiseSessionManager {
|
||||
final class NoiseSessionManager {
|
||||
private var sessions: [String: NoiseSession] = [:]
|
||||
private let sessionsQueue = DispatchQueue(label: "noise.sessions", attributes: .concurrent)
|
||||
}
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
#include "Release.xcconfig"
|
||||
|
||||
// Optional include of local configs
|
||||
#include? "Local.xcconfig"
|
||||
@@ -0,0 +1,5 @@
|
||||
// Your Apple Developer Team ID - https://stackoverflow.com/a/18727947
|
||||
DEVELOPMENT_TEAM = ABC123
|
||||
|
||||
// Unique bundle id to be able to register and run locally
|
||||
PRODUCT_BUNDLE_IDENTIFIER = chat.bitchat.$(DEVELOPMENT_TEAM)
|
||||
@@ -0,0 +1,12 @@
|
||||
MARKETING_VERSION = 1.5.1
|
||||
CURRENT_PROJECT_VERSION = 1
|
||||
|
||||
IPHONEOS_DEPLOYMENT_TARGET = 16.0
|
||||
MACOSX_DEPLOYMENT_TARGET = 13.0
|
||||
SWIFT_VERSION = 5.0
|
||||
|
||||
DEVELOPMENT_TEAM = L3N5LHJD5Y
|
||||
CODE_SIGN_STYLE = Automatic
|
||||
|
||||
PRODUCT_BUNDLE_IDENTIFIER = chat.bitchat
|
||||
APP_GROUP_ID = group.chat.bitchat
|
||||
@@ -14,16 +14,16 @@ default:
|
||||
# Check prerequisites
|
||||
check:
|
||||
@echo "Checking prerequisites..."
|
||||
@command -v xcodegen >/dev/null 2>&1 || (echo "❌ XcodeGen not found. Install with: brew install xcodegen" && exit 1)
|
||||
@command -v xcodebuild >/dev/null 2>&1 || (echo "❌ Xcode not found. Install Xcode from App Store" && exit 1)
|
||||
@security find-identity -v -p codesigning | grep -q "Developer ID" || (echo "⚠️ No Developer ID found - code signing may fail" && exit 0)
|
||||
@command -v xcodebuild >/dev/null 2>&1 || (echo "❌ xcodebuild not found. Install Xcode from App Store" && exit 1)
|
||||
@xcode-select -p | grep -q "Xcode.app" || (echo "❌ Full Xcode required, not just command line tools. Install from App Store and run:\n sudo xcode-select -s /Applications/Xcode.app/Contents/Developer" && exit 1)
|
||||
@test -d "/Applications/Xcode.app" || (echo "❌ Xcode.app not found in Applications folder. Install from App Store" && exit 1)
|
||||
@xcodebuild -version >/dev/null 2>&1 || (echo "❌ Xcode not properly configured. Try:\n sudo xcode-select -s /Applications/Xcode.app/Contents/Developer" && exit 1)
|
||||
@security find-identity -v -p codesigning | grep -q "Apple Development\|Developer ID" || (echo "⚠️ No Developer ID found - code signing may fail" && exit 0)
|
||||
@echo "✅ All prerequisites met"
|
||||
|
||||
# Backup original files
|
||||
backup:
|
||||
@echo "Backing up original project configuration..."
|
||||
@cp project.yml project.yml.backup 2>/dev/null || true
|
||||
@# Backup other files that get modified by xcodegen
|
||||
@if [ -f bitchat.xcodeproj/project.pbxproj ]; then cp bitchat.xcodeproj/project.pbxproj bitchat.xcodeproj/project.pbxproj.backup; fi
|
||||
@if [ -f bitchat/Info.plist ]; then cp bitchat/Info.plist bitchat/Info.plist.backup; fi
|
||||
|
||||
@@ -44,20 +44,15 @@ patch-for-macos: backup
|
||||
@# Move iOS-specific files out of the way temporarily
|
||||
@if [ -f bitchat/LaunchScreen.storyboard ]; then mv bitchat/LaunchScreen.storyboard bitchat/LaunchScreen.storyboard.ios; fi
|
||||
|
||||
# Generate Xcode project with patches
|
||||
generate: patch-for-macos
|
||||
@echo "Generating Xcode project..."
|
||||
@xcodegen generate
|
||||
|
||||
# Build the macOS app
|
||||
build: check generate
|
||||
build: #check generate
|
||||
@echo "Building BitChat for macOS..."
|
||||
@xcodebuild -project bitchat.xcodeproj -scheme "bitchat (macOS)" -configuration Debug CODE_SIGN_IDENTITY="" CODE_SIGNING_REQUIRED=NO CODE_SIGN_ENTITLEMENTS="" build
|
||||
|
||||
# Run the macOS app
|
||||
run: build
|
||||
@echo "Launching BitChat..."
|
||||
@find ~/Library/Developer/Xcode/DerivedData -name "bitchat.app" -path "*/Debug/*" | head -1 | xargs -I {} open "{}"
|
||||
@find ~/Library/Developer/Xcode/DerivedData -name "bitchat.app" -path "*/Debug/*" -not -path "*/Index.noindex/*" | head -1 | xargs -I {} open "{}"
|
||||
|
||||
# Clean build artifacts and restore original files
|
||||
clean: restore
|
||||
@@ -75,10 +70,8 @@ clean: restore
|
||||
# Quick run without cleaning (for development)
|
||||
dev-run: check
|
||||
@echo "Quick development build..."
|
||||
@if [ ! -f project.yml.backup ]; then just patch-for-macos; fi
|
||||
@xcodegen generate
|
||||
@xcodebuild -project bitchat.xcodeproj -scheme "bitchat (macOS)" -configuration Debug CODE_SIGN_IDENTITY="" CODE_SIGNING_REQUIRED=NO CODE_SIGN_ENTITLEMENTS="" build
|
||||
@find ~/Library/Developer/Xcode/DerivedData -name "bitchat.app" -path "*/Debug/*" | head -1 | xargs -I {} open "{}"
|
||||
@xcodebuild -project bitchat.xcodeproj -scheme "bitchat_macOS" -configuration Debug CODE_SIGN_IDENTITY="" CODE_SIGNING_REQUIRED=NO CODE_SIGN_ENTITLEMENTS="" build
|
||||
@find ~/Library/Developer/Xcode/DerivedData -name "bitchat.app" -path "*/Debug/*" -not -path "*/Index.noindex/*" | head -1 | xargs -I {} open "{}"
|
||||
|
||||
# Show app info
|
||||
info:
|
||||
@@ -106,11 +99,9 @@ nuke:
|
||||
@echo "🧨 Nuclear clean - removing all build artifacts and backups..."
|
||||
@rm -rf ~/Library/Developer/Xcode/DerivedData/bitchat-* 2>/dev/null || true
|
||||
@rm -rf bitchat.xcodeproj 2>/dev/null || true
|
||||
@rm -f project.yml.backup 2>/dev/null || true
|
||||
@rm -f project-macos.yml 2>/dev/null || true
|
||||
@rm -f bitchat.xcodeproj/project.pbxproj.backup 2>/dev/null || true
|
||||
@rm -f bitchat/Info.plist.backup 2>/dev/null || true
|
||||
@# Restore iOS-specific files if they were moved
|
||||
@if [ -f bitchat/LaunchScreen.storyboard.ios ]; then mv bitchat/LaunchScreen.storyboard.ios bitchat/LaunchScreen.storyboard; fi
|
||||
@git checkout -- project.yml bitchat.xcodeproj/project.pbxproj bitchat/Info.plist 2>/dev/null || echo "⚠️ Not a git repo or no changes to restore"
|
||||
@git checkout bitchat.xcodeproj/project.pbxproj bitchat/Info.plist 2>/dev/null || echo "⚠️ Not a git repo or no changes to restore"
|
||||
@echo "✅ Nuclear clean complete"
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"pins" : [
|
||||
{
|
||||
"identity" : "swift-secp256k1",
|
||||
"kind" : "remoteSourceControl",
|
||||
"location" : "https://github.com/21-DOT-DEV/swift-secp256k1",
|
||||
"state" : {
|
||||
"revision" : "8c62aba8a3011c9bcea232e5ee007fb0b34a15e2",
|
||||
"version" : "0.21.1"
|
||||
}
|
||||
}
|
||||
],
|
||||
"version" : 2
|
||||
}
|
||||
@@ -4,6 +4,7 @@ import PackageDescription
|
||||
|
||||
let package = Package(
|
||||
name: "bitchat",
|
||||
defaultLocalization: "en",
|
||||
platforms: [
|
||||
.iOS(.v16),
|
||||
.macOS(.v13)
|
||||
@@ -14,17 +15,54 @@ let package = Package(
|
||||
targets: ["bitchat"]
|
||||
),
|
||||
],
|
||||
dependencies:[
|
||||
.package(path: "localPackages/Arti"),
|
||||
.package(path: "localPackages/Noise"),
|
||||
.package(path: "localPackages/BitFoundation"),
|
||||
.package(path: "localPackages/BitLogger"),
|
||||
.package(path: "localPackages/Nostr"),
|
||||
.package(url: "https://github.com/21-DOT-DEV/swift-secp256k1", exact: "0.21.1")
|
||||
],
|
||||
targets: [
|
||||
.executableTarget(
|
||||
name: "bitchat",
|
||||
dependencies: [
|
||||
.product(name: "P256K", package: "swift-secp256k1"),
|
||||
.product(name: "BitFoundation", package: "BitFoundation"),
|
||||
.product(name: "BitLogger", package: "BitLogger"),
|
||||
.product(name: "Noise", package: "Noise"),
|
||||
.product(name: "Nostr", package: "Nostr"),
|
||||
.product(name: "Tor", package: "Arti")
|
||||
],
|
||||
path: "bitchat",
|
||||
exclude: [
|
||||
"Info.plist",
|
||||
"Assets.xcassets",
|
||||
"_PreviewHelpers/PreviewAssets.xcassets",
|
||||
"bitchat.entitlements",
|
||||
"bitchat-macOS.entitlements",
|
||||
"LaunchScreen.storyboard"
|
||||
"LaunchScreen.storyboard",
|
||||
"ViewModels/Extensions/README.md"
|
||||
],
|
||||
resources: [
|
||||
.process("Localizable.xcstrings")
|
||||
]
|
||||
),
|
||||
.testTarget(
|
||||
name: "bitchatTests",
|
||||
dependencies: [
|
||||
"bitchat",
|
||||
.product(name: "BitFoundation", package: "BitFoundation"),
|
||||
.product(name: "Nostr", package: "Nostr")
|
||||
],
|
||||
path: "bitchatTests",
|
||||
exclude: [
|
||||
"Info.plist",
|
||||
"README.md"
|
||||
],
|
||||
resources: [
|
||||
.process("Localization")
|
||||
]
|
||||
)
|
||||
]
|
||||
)
|
||||
@@ -1,90 +1,122 @@
|
||||
<img height="300" alt="bitchat" src="https://github.com/user-attachments/assets/2660f828-49c7-444d-beca-d8b01854667a" />
|
||||
<img width="256" height="256" alt="icon_128x128@2x" src="https://github.com/user-attachments/assets/90133f83-b4f6-41c6-aab9-25d0859d2a47" />
|
||||
|
||||
## bitchat
|
||||
|
||||
A decentralized peer-to-peer messaging app that works over Bluetooth mesh networks. No internet required, no servers, no phone numbers. It's the side-groupchat.
|
||||
A decentralized peer-to-peer messaging app with dual transport architecture: local Bluetooth mesh networks for offline communication and internet-based Nostr protocol for global reach. No accounts, no phone numbers, no central servers. It's the side-groupchat.
|
||||
|
||||
[bitchat.free](http://bitchat.free)
|
||||
|
||||
📲 [App Store](https://apps.apple.com/us/app/bitchat-mesh/id6748219622)
|
||||
|
||||
> [!WARNING]
|
||||
> Private message and channel features have not received external security review and may contain vulnerabilities. Do not use for sensitive use cases, and do not rely on its security until it has been reviewed. Now uses the [Noise Protocol](http://www.noiseprotocol.org) for identity and encryption. Public local chat (the main feature) has no security concerns.
|
||||
|
||||
|
||||
## License
|
||||
|
||||
This project is released into the public domain. See the [LICENSE](LICENSE) file for details.
|
||||
|
||||
|
||||
## Features
|
||||
|
||||
- **Dual Transport Architecture**: Bluetooth mesh for offline + Nostr protocol for internet-based messaging
|
||||
- **Location-Based Channels**: Geographic chat rooms using geohash coordinates over global Nostr relays
|
||||
- **Intelligent Message Routing**: Automatically chooses best transport (Bluetooth → Nostr fallback)
|
||||
- **Decentralized Mesh Network**: Automatic peer discovery and multi-hop message relay over Bluetooth LE
|
||||
- **Privacy First**: No accounts, no phone numbers, no persistent identifiers
|
||||
- **Cover Traffic**: Timing obfuscation and dummy messages for enhanced privacy
|
||||
- **Private Message End-to-End Encryption**: [Noise Protocol](http://noiseprotocol.org)
|
||||
- **Store & Forward**: Messages cached for offline peers and delivered when they reconnect
|
||||
- **Private Message End-to-End Encryption**: [Noise Protocol](https://noiseprotocol.org) for mesh, NIP-17 for Nostr
|
||||
- **IRC-Style Commands**: Familiar `/slap`, `/msg`, `/who` style interface
|
||||
- **Universal App**: Native support for iOS and macOS
|
||||
- **Emergency Wipe**: Triple-tap to instantly clear all data
|
||||
- **Performance Optimizations**: LZ4 message compression, adaptive battery modes, and optimized networking
|
||||
|
||||
## [Technical Architecture](https://deepwiki.com/permissionlesstech/bitchat)
|
||||
|
||||
## Technical Architecture
|
||||
BitChat uses a **hybrid messaging architecture** with two complementary transport layers:
|
||||
|
||||
### Binary Protocol
|
||||
bitchat uses an efficient binary protocol optimized for Bluetooth LE:
|
||||
- Compact packet format with 1-byte type field
|
||||
- TTL-based message routing (max 7 hops)
|
||||
- Automatic fragmentation for large messages
|
||||
- Message deduplication via unique IDs
|
||||
### Bluetooth Mesh Network (Offline)
|
||||
|
||||
### Mesh Networking
|
||||
- Each device acts as both client and peripheral
|
||||
- Automatic peer discovery and connection management
|
||||
- Store-and-forward for offline message delivery
|
||||
- Adaptive duty cycling for battery optimization
|
||||
- **Local Communication**: Direct peer-to-peer within Bluetooth range
|
||||
- **Multi-hop Relay**: Messages route through nearby devices (max 7 hops)
|
||||
- **No Internet Required**: Works completely offline in disaster scenarios
|
||||
- **Noise Protocol Encryption**: End-to-end encryption with forward secrecy
|
||||
- **Binary Protocol**: Compact packet format optimized for Bluetooth LE constraints
|
||||
- **Automatic Discovery**: Peer discovery and connection management
|
||||
- **Adaptive Power**: Battery-optimized duty cycling
|
||||
|
||||
### Nostr Protocol (Internet)
|
||||
|
||||
- **Global Reach**: Connect with users worldwide via internet relays
|
||||
- **Location Channels**: Geographic chat rooms using geohash coordinates
|
||||
- **290+ Relay Network**: Distributed across the globe for reliability
|
||||
- **NIP-17 Encryption**: Gift-wrapped private messages for internet privacy
|
||||
- **Ephemeral Keys**: Fresh cryptographic identity per geohash area
|
||||
|
||||
### Channel Types
|
||||
|
||||
#### `mesh #bluetooth`
|
||||
|
||||
- **Transport**: Bluetooth Low Energy mesh network
|
||||
- **Scope**: Local devices within multi-hop range
|
||||
- **Internet**: Not required
|
||||
- **Use Case**: Offline communication, protests, disasters, remote areas
|
||||
|
||||
#### Location Channels (`block #dr5rsj7`, `neighborhood #dr5rs`, `country #dr`)
|
||||
|
||||
- **Transport**: Nostr protocol over internet
|
||||
- **Scope**: Geographic areas defined by geohash precision
|
||||
- `block` (7 chars): City block level
|
||||
- `neighborhood` (6 chars): District/neighborhood
|
||||
- `city` (5 chars): City level
|
||||
- `province` (4 chars): State/province
|
||||
- `region` (2 chars): Country/large region
|
||||
- **Internet**: Required (connects to Nostr relays)
|
||||
- **Use Case**: Location-based community chat, local events, regional discussions
|
||||
|
||||
### Direct Message Routing
|
||||
|
||||
Private messages use **intelligent transport selection**:
|
||||
|
||||
1. **Bluetooth First** (preferred when available)
|
||||
|
||||
- Direct connection with established Noise session
|
||||
- Fastest and most private option
|
||||
|
||||
2. **Nostr Fallback** (when Bluetooth unavailable)
|
||||
|
||||
- Uses recipient's Nostr public key
|
||||
- NIP-17 gift-wrapping for privacy
|
||||
- Routes through global relay network
|
||||
|
||||
3. **Smart Queuing** (when neither available)
|
||||
- Messages queued until transport becomes available
|
||||
- Automatic delivery when connection established
|
||||
|
||||
For detailed protocol documentation, see the [Technical Whitepaper](WHITEPAPER.md).
|
||||
|
||||
|
||||
## Setup
|
||||
|
||||
### Option 1: Using XcodeGen (Recommended)
|
||||
### Option 1: Using Xcode
|
||||
|
||||
1. Install XcodeGen if you haven't already:
|
||||
```bash
|
||||
brew install xcodegen
|
||||
```
|
||||
|
||||
2. Generate the Xcode project:
|
||||
```bash
|
||||
cd bitchat
|
||||
xcodegen generate
|
||||
```
|
||||
|
||||
3. Open the generated project:
|
||||
```bash
|
||||
open bitchat.xcodeproj
|
||||
```
|
||||
|
||||
### Option 2: Using Swift Package Manager
|
||||
To run on a device there're a few steps to prepare the code:
|
||||
- Clone the local configs: `cp Configs/Local.xcconfig.example Configs/Local.xcconfig`
|
||||
- Add your Developer Team ID into the newly created `Configs/Local.xcconfig`
|
||||
- Bundle ID would be set to `chat.bitchat.<team_id>` (unless you set to something else)
|
||||
- Entitlements need to be updated manually (TODO: Automate):
|
||||
- Search and replace `group.chat.bitchat` with `group.<your_bundle_id>` (e.g. `group.chat.bitchat.ABC123`)
|
||||
|
||||
### Option 2: Using `just`
|
||||
|
||||
1. Open the project in Xcode:
|
||||
```bash
|
||||
cd bitchat
|
||||
open Package.swift
|
||||
brew install just
|
||||
```
|
||||
|
||||
2. Select your target device and run
|
||||
|
||||
### Option 3: Manual Xcode Project
|
||||
|
||||
1. Open Xcode and create a new iOS/macOS App
|
||||
2. Copy all Swift files from the `bitchat` directory into your project
|
||||
3. Update Info.plist with Bluetooth permissions
|
||||
4. Set deployment target to iOS 16.0 / macOS 13.0
|
||||
|
||||
### Option 4: just
|
||||
|
||||
Want to try this on macos: `just run` will set it up and run from source.
|
||||
Run `just clean` afterwards to restore things to original state for mobile app building and development.
|
||||
|
||||
## Localization
|
||||
|
||||
- Base app resources live under `bitchat/Localization/Base.lproj/`. Add new copy to `Localizable.strings` and plural rules to `Localizable.stringsdict`.
|
||||
- Share extension strings are separate in `bitchatShareExtension/Localization/Base.lproj/Localizable.strings`.
|
||||
- Prefer keys that describe intent (`app_info.features.offline.title`) and reuse existing ones where possible.
|
||||
- Run `xcodebuild -project bitchat.xcodeproj -scheme "bitchat (macOS)" -configuration Debug CODE_SIGNING_ALLOWED=NO build` to compile-check any localization updates.
|
||||
|
||||
@@ -98,7 +98,7 @@ While the Noise handshake cryptographically authenticates a peer's key, it doesn
|
||||
### 4.2. Favorites and Blocking
|
||||
|
||||
To improve the user experience and provide control over interactions, the protocol supports:
|
||||
* **Favorites:** Users can mark trusted or frequently contacted peers as "favorites." This is a local designation that can be used by the application to prioritize notifications or display peers more prominently.
|
||||
* **Favorites:** Users can mark trusted or frequently contacted peers as "favorites". This is a local designation that can be used by the application to prioritize notifications or display peers more prominently.
|
||||
* **Blocking:** Users can block peers. When a peer is blocked, the application will discard any incoming packets from that peer's fingerprint at the earliest possible stage, effectively silencing them without notifying the blocked peer.
|
||||
|
||||
---
|
||||
@@ -184,6 +184,28 @@ To minimize bandwidth, `BitchatPacket`s are serialized into a compact binary for
|
||||
|
||||
**Padding:** All packets are padded to the next standard block size (256, 512, 1024, or 2048 bytes) using a PKCS#7-style scheme to obscure the true message length from network observers.
|
||||
|
||||
```mermaid
|
||||
---
|
||||
config:
|
||||
theme: dark
|
||||
---
|
||||
---
|
||||
title: "BitchatPacket"
|
||||
---
|
||||
packet
|
||||
+8: "Version"
|
||||
+8: "Type"
|
||||
+8: "TTL"
|
||||
+64: "Timestamp"
|
||||
+8: "Flags"
|
||||
+16: "Payload Length"
|
||||
+64: "Sender ID"
|
||||
+64: "Recipient ID (optional)"
|
||||
+48: "Payload (variable)"
|
||||
+64: "Signature (optional)"
|
||||
```
|
||||
_A representation of the sizes of the fields in `BitchatPacket`_
|
||||
|
||||
### 6.2. Application Message Format (`BitchatMessage`)
|
||||
|
||||
For packets of type `message`, the payload is a binary-serialized `BitchatMessage` containing the chat content.
|
||||
@@ -198,6 +220,25 @@ For packets of type `message`, the payload is a binary-serialized `BitchatMessag
|
||||
| Original Sender | 1 + len (opt)| Nickname of the original sender if the message is a relay. |
|
||||
| Recipient Nickname | 1 + len (opt)| Nickname of the recipient for private messages. |
|
||||
|
||||
```mermaid
|
||||
---
|
||||
config:
|
||||
theme: dark
|
||||
---
|
||||
---
|
||||
title: "BitchatMessage"
|
||||
---
|
||||
packet
|
||||
+8: "Flags"
|
||||
+64: "Timestamp"
|
||||
+24: "ID (variable)"
|
||||
+32: "Sender (variable)"
|
||||
+32: "Content (variable)"
|
||||
+32: "Original Sender (variable) (optional)"
|
||||
+32: "Recipient Nickname (variable) (optional)"
|
||||
```
|
||||
_A representation of the sizes of the fields in `BitchatMessage`_
|
||||
|
||||
---
|
||||
|
||||
## 7. Message Routing and Propagation
|
||||
@@ -215,7 +256,7 @@ To send messages to peers that are not directly connected, BitChat employs a "fl
|
||||
The logic is as follows:
|
||||
|
||||
1. A peer receives a packet.
|
||||
2. It checks the Bloom filter to see if the packet's ID has likely been seen before. If so, the packet is discarded. Bloom filters can have false positives (though they are rare), but they guarantee no false negatives. This means a new packet will never be accidentally discarded.
|
||||
2. It checks the Bloom filter to see if the packet's ID has likely been seen before. If so, the packet is discarded. Bloom filters can have false positives (though they are rare), but they guarantee no false negatives. This means that while some packets may be incorrectly discarded due to false positives, the gossip protocol's redundancy ensures these packets will eventually be received through subsequent exchanges with other peers.
|
||||
3. If the packet is new, its ID is added to the Bloom filter.
|
||||
4. The peer decrements the packet's Time-To-Live (TTL) field.
|
||||
5. If the TTL is greater than zero, the peer re-broadcasts the packet to all of its connected peers, *except* for the peer from which it received the packet.
|
||||
|
||||
@@ -0,0 +1,131 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<Scheme
|
||||
LastUpgradeVersion = "1640"
|
||||
version = "1.3">
|
||||
<BuildAction
|
||||
parallelizeBuildables = "YES"
|
||||
buildImplicitDependencies = "YES">
|
||||
<BuildActionEntries>
|
||||
<BuildActionEntry
|
||||
buildForTesting = "YES"
|
||||
buildForRunning = "YES"
|
||||
buildForProfiling = "YES"
|
||||
buildForArchiving = "YES"
|
||||
buildForAnalyzing = "YES">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "57CA17A36A2532A6CFF367BB"
|
||||
BuildableName = "bitchatShareExtension.appex"
|
||||
BlueprintName = "bitchatShareExtension"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildActionEntry>
|
||||
<BuildActionEntry
|
||||
buildForTesting = "YES"
|
||||
buildForRunning = "YES"
|
||||
buildForProfiling = "YES"
|
||||
buildForArchiving = "YES"
|
||||
buildForAnalyzing = "YES">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "AF077EA0474EDEDE2C72716C"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildActionEntry>
|
||||
</BuildActionEntries>
|
||||
</BuildAction>
|
||||
<TestAction
|
||||
buildConfiguration = "Debug"
|
||||
selectedDebuggerIdentifier = "Xcode.DebuggerFoundation.Debugger.LLDB"
|
||||
selectedLauncherIdentifier = "Xcode.DebuggerFoundation.Launcher.LLDB"
|
||||
shouldUseLaunchSchemeArgsEnv = "YES"
|
||||
codeCoverageEnabled = "YES"
|
||||
onlyGenerateCoverageForSpecifiedTargets = "YES">
|
||||
<MacroExpansion>
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "AF077EA0474EDEDE2C72716C"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</MacroExpansion>
|
||||
<CodeCoverageTargets>
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "AF077EA0474EDEDE2C72716C"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</CodeCoverageTargets>
|
||||
<Testables>
|
||||
<TestableReference
|
||||
skipped = "NO"
|
||||
parallelizable = "YES"
|
||||
testExecutionOrdering = "random">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "6CB97DF2EA57234CB3E563B8"
|
||||
BuildableName = "bitchatTests_iOS.xctest"
|
||||
BlueprintName = "bitchatTests_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</TestableReference>
|
||||
</Testables>
|
||||
</TestAction>
|
||||
<LaunchAction
|
||||
buildConfiguration = "Debug"
|
||||
selectedDebuggerIdentifier = "Xcode.DebuggerFoundation.Debugger.LLDB"
|
||||
selectedLauncherIdentifier = "Xcode.DebuggerFoundation.Launcher.LLDB"
|
||||
launchStyle = "0"
|
||||
useCustomWorkingDirectory = "NO"
|
||||
ignoresPersistentStateOnLaunch = "NO"
|
||||
debugDocumentVersioning = "YES"
|
||||
debugServiceExtension = "internal"
|
||||
allowLocationSimulation = "YES">
|
||||
<BuildableProductRunnable
|
||||
runnableDebuggingMode = "0">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "AF077EA0474EDEDE2C72716C"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildableProductRunnable>
|
||||
<EnvironmentVariables>
|
||||
<EnvironmentVariable
|
||||
key = "BITCHAT_LOG_LEVEL"
|
||||
value = "debug"
|
||||
isEnabled = "YES">
|
||||
</EnvironmentVariable>
|
||||
</EnvironmentVariables>
|
||||
</LaunchAction>
|
||||
<ProfileAction
|
||||
buildConfiguration = "Release"
|
||||
shouldUseLaunchSchemeArgsEnv = "YES"
|
||||
savedToolIdentifier = ""
|
||||
useCustomWorkingDirectory = "NO"
|
||||
debugDocumentVersioning = "YES">
|
||||
<BuildableProductRunnable
|
||||
runnableDebuggingMode = "0">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "AF077EA0474EDEDE2C72716C"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_iOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildableProductRunnable>
|
||||
</ProfileAction>
|
||||
<AnalyzeAction
|
||||
buildConfiguration = "Debug">
|
||||
</AnalyzeAction>
|
||||
<ArchiveAction
|
||||
buildConfiguration = "Release"
|
||||
revealArchiveInOrganizer = "YES">
|
||||
</ArchiveAction>
|
||||
</Scheme>
|
||||
@@ -0,0 +1,105 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<Scheme
|
||||
LastUpgradeVersion = "1640"
|
||||
version = "1.3">
|
||||
<BuildAction
|
||||
parallelizeBuildables = "YES"
|
||||
buildImplicitDependencies = "YES">
|
||||
<BuildActionEntries>
|
||||
<BuildActionEntry
|
||||
buildForTesting = "YES"
|
||||
buildForRunning = "YES"
|
||||
buildForProfiling = "YES"
|
||||
buildForArchiving = "YES"
|
||||
buildForAnalyzing = "YES">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "0576A29205865664C0937536"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_macOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildActionEntry>
|
||||
</BuildActionEntries>
|
||||
</BuildAction>
|
||||
<TestAction
|
||||
buildConfiguration = "Debug"
|
||||
selectedDebuggerIdentifier = "Xcode.DebuggerFoundation.Debugger.LLDB"
|
||||
selectedLauncherIdentifier = "Xcode.DebuggerFoundation.Launcher.LLDB"
|
||||
shouldUseLaunchSchemeArgsEnv = "YES">
|
||||
<MacroExpansion>
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "0576A29205865664C0937536"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_macOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</MacroExpansion>
|
||||
<Testables>
|
||||
<TestableReference
|
||||
skipped = "NO"
|
||||
parallelizable = "NO">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "47FF23248747DD7CB666CB91"
|
||||
BuildableName = "bitchatTests_macOS.xctest"
|
||||
BlueprintName = "bitchatTests_macOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</TestableReference>
|
||||
</Testables>
|
||||
</TestAction>
|
||||
<LaunchAction
|
||||
buildConfiguration = "Debug"
|
||||
selectedDebuggerIdentifier = "Xcode.DebuggerFoundation.Debugger.LLDB"
|
||||
selectedLauncherIdentifier = "Xcode.DebuggerFoundation.Launcher.LLDB"
|
||||
launchStyle = "0"
|
||||
useCustomWorkingDirectory = "NO"
|
||||
ignoresPersistentStateOnLaunch = "NO"
|
||||
debugDocumentVersioning = "YES"
|
||||
debugServiceExtension = "internal"
|
||||
allowLocationSimulation = "YES">
|
||||
<BuildableProductRunnable
|
||||
runnableDebuggingMode = "0">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "0576A29205865664C0937536"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_macOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildableProductRunnable>
|
||||
<EnvironmentVariables>
|
||||
<EnvironmentVariable
|
||||
key = "BITCHAT_LOG_LEVEL"
|
||||
value = "debug"
|
||||
isEnabled = "YES">
|
||||
</EnvironmentVariable>
|
||||
</EnvironmentVariables>
|
||||
</LaunchAction>
|
||||
<ProfileAction
|
||||
buildConfiguration = "Release"
|
||||
shouldUseLaunchSchemeArgsEnv = "YES"
|
||||
savedToolIdentifier = ""
|
||||
useCustomWorkingDirectory = "NO"
|
||||
debugDocumentVersioning = "YES">
|
||||
<BuildableProductRunnable
|
||||
runnableDebuggingMode = "0">
|
||||
<BuildableReference
|
||||
BuildableIdentifier = "primary"
|
||||
BlueprintIdentifier = "0576A29205865664C0937536"
|
||||
BuildableName = "bitchat.app"
|
||||
BlueprintName = "bitchat_macOS"
|
||||
ReferencedContainer = "container:bitchat.xcodeproj">
|
||||
</BuildableReference>
|
||||
</BuildableProductRunnable>
|
||||
</ProfileAction>
|
||||
<AnalyzeAction
|
||||
buildConfiguration = "Debug">
|
||||
</AnalyzeAction>
|
||||
<ArchiveAction
|
||||
buildConfiguration = "Release"
|
||||
revealArchiveInOrganizer = "YES">
|
||||
</ArchiveAction>
|
||||
</Scheme>
|
||||
@@ -1,111 +1,9 @@
|
||||
{
|
||||
"images" : [
|
||||
{
|
||||
"filename" : "icon_20x20@2x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "2x",
|
||||
"size" : "20x20"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_20x20@3x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "3x",
|
||||
"size" : "20x20"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_29x29@2x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "2x",
|
||||
"size" : "29x29"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_29x29@3x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "3x",
|
||||
"size" : "29x29"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_40x40@2x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "2x",
|
||||
"size" : "40x40"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_40x40@3x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "3x",
|
||||
"size" : "40x40"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_60x60@2x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "2x",
|
||||
"size" : "60x60"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_60x60@3x.png",
|
||||
"idiom" : "iphone",
|
||||
"scale" : "3x",
|
||||
"size" : "60x60"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_20x20.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "1x",
|
||||
"size" : "20x20"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_20x20@2x.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "2x",
|
||||
"size" : "20x20"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_29x29.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "1x",
|
||||
"size" : "29x29"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_29x29@2x.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "2x",
|
||||
"size" : "29x29"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_40x40.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "1x",
|
||||
"size" : "40x40"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_40x40@2x.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "2x",
|
||||
"size" : "40x40"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_76x76.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "1x",
|
||||
"size" : "76x76"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_76x76@2x.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "2x",
|
||||
"size" : "76x76"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_83.5x83.5@2x.png",
|
||||
"idiom" : "ipad",
|
||||
"scale" : "2x",
|
||||
"size" : "83.5x83.5"
|
||||
},
|
||||
{
|
||||
"filename" : "icon_1024x1024.png",
|
||||
"idiom" : "ios-marketing",
|
||||
"scale" : "1x",
|
||||
"idiom" : "universal",
|
||||
"platform" : "ios",
|
||||
"size" : "1024x1024"
|
||||
},
|
||||
{
|
||||
|
||||
|
Before Width: | Height: | Size: 378 B |
|
Before Width: | Height: | Size: 497 B |
|
Before Width: | Height: | Size: 570 B |
|
Before Width: | Height: | Size: 401 B |
|
Before Width: | Height: | Size: 564 B |
|
Before Width: | Height: | Size: 668 B |
|
Before Width: | Height: | Size: 497 B |
|
Before Width: | Height: | Size: 641 B |
|
Before Width: | Height: | Size: 765 B |
|
Before Width: | Height: | Size: 765 B |
|
Before Width: | Height: | Size: 1.0 KiB |
|
Before Width: | Height: | Size: 628 B |
|
Before Width: | Height: | Size: 930 B |
|
Before Width: | Height: | Size: 976 B |
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"images" : [
|
||||
{
|
||||
"filename" : "image-1024.png",
|
||||
"idiom" : "universal",
|
||||
"platform" : "ios",
|
||||
"size" : "1024x1024"
|
||||
},
|
||||
{
|
||||
"appearances" : [
|
||||
{
|
||||
"appearance" : "luminosity",
|
||||
"value" : "dark"
|
||||
}
|
||||
],
|
||||
"idiom" : "universal",
|
||||
"platform" : "ios",
|
||||
"size" : "1024x1024"
|
||||
},
|
||||
{
|
||||
"appearances" : [
|
||||
{
|
||||
"appearance" : "luminosity",
|
||||
"value" : "tinted"
|
||||
}
|
||||
],
|
||||
"idiom" : "universal",
|
||||
"platform" : "ios",
|
||||
"size" : "1024x1024"
|
||||
}
|
||||
],
|
||||
"info" : {
|
||||
"author" : "xcode",
|
||||
"version" : 1
|
||||
}
|
||||
}
|
||||
|
After Width: | Height: | Size: 11 KiB |
@@ -6,20 +6,46 @@
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Nostr
|
||||
import Tor
|
||||
import SwiftUI
|
||||
import BitFoundation
|
||||
import UserNotifications
|
||||
|
||||
@main
|
||||
struct BitchatApp: App {
|
||||
@StateObject private var chatViewModel = ChatViewModel()
|
||||
static let bundleID = Bundle.main.bundleIdentifier ?? "chat.bitchat"
|
||||
static let groupID = "group.\(bundleID)"
|
||||
|
||||
@StateObject private var chatViewModel: ChatViewModel
|
||||
#if os(iOS)
|
||||
@Environment(\.scenePhase) var scenePhase
|
||||
@UIApplicationDelegateAdaptor(AppDelegate.self) var appDelegate
|
||||
// Skip the very first .active-triggered Tor restart on cold launch
|
||||
@State private var didHandleInitialActive: Bool = false
|
||||
@State private var didEnterBackground: Bool = false
|
||||
#elseif os(macOS)
|
||||
@NSApplicationDelegateAdaptor(MacAppDelegate.self) var appDelegate
|
||||
#endif
|
||||
|
||||
private let idBridge = NostrIdentityBridge(keychain: KeychainManager())
|
||||
|
||||
init() {
|
||||
GeoRelayDirectory.setupShared(dependencies: .live())
|
||||
NostrRelayManager.setupShared(dependencies: .live())
|
||||
let keychain = KeychainManager()
|
||||
let idBridge = self.idBridge
|
||||
_chatViewModel = StateObject(
|
||||
wrappedValue: ChatViewModel(
|
||||
keychain: keychain,
|
||||
idBridge: idBridge,
|
||||
identityManager: SecureIdentityStateManager(keychain)
|
||||
)
|
||||
)
|
||||
|
||||
UNUserNotificationCenter.current().delegate = NotificationDelegate.shared
|
||||
// Warm up georelay directory and refresh if stale (once/day)
|
||||
GeoRelayDirectory.shared.prefetchIfNeeded()
|
||||
}
|
||||
|
||||
var body: some Scene {
|
||||
@@ -28,11 +54,23 @@ struct BitchatApp: App {
|
||||
.environmentObject(chatViewModel)
|
||||
.onAppear {
|
||||
NotificationDelegate.shared.chatViewModel = chatViewModel
|
||||
#if os(iOS)
|
||||
// Inject live Noise service into VerificationService to avoid creating new BLE instances
|
||||
VerificationService.shared.configure(with: chatViewModel.meshService.getNoiseService())
|
||||
// Prewarm Nostr identity and QR to make first VERIFY sheet fast
|
||||
let nickname = chatViewModel.nickname
|
||||
DispatchQueue.global(qos: .utility).async {
|
||||
let npub = try? idBridge.getCurrentNostrIdentity()?.npub
|
||||
_ = VerificationService.shared.buildMyQRString(nickname: nickname, npub: npub)
|
||||
}
|
||||
|
||||
appDelegate.chatViewModel = chatViewModel
|
||||
#elseif os(macOS)
|
||||
appDelegate.chatViewModel = chatViewModel
|
||||
#endif
|
||||
|
||||
// Initialize network activation policy; will start Tor/Nostr only when allowed
|
||||
NetworkActivationService.shared.start()
|
||||
|
||||
// Start presence service (will wait for Tor readiness)
|
||||
GeohashPresenceService.shared.start()
|
||||
|
||||
// Check for shared content
|
||||
checkForSharedContent()
|
||||
}
|
||||
@@ -40,16 +78,59 @@ struct BitchatApp: App {
|
||||
handleURL(url)
|
||||
}
|
||||
#if os(iOS)
|
||||
.onChange(of: scenePhase) { newPhase in
|
||||
switch newPhase {
|
||||
case .background:
|
||||
// Keep BLE mesh running in background; BLEService adapts scanning automatically
|
||||
// Always send Tor to dormant on background for a clean restart later.
|
||||
TorManager.shared.setAppForeground(false)
|
||||
TorManager.shared.goDormantOnBackground()
|
||||
// Stop geohash sampling while backgrounded
|
||||
Task { @MainActor in
|
||||
chatViewModel.endGeohashSampling()
|
||||
}
|
||||
// Proactively disconnect Nostr to avoid spurious socket errors while Tor is down
|
||||
NostrRelayManager.shared.disconnect()
|
||||
didEnterBackground = true
|
||||
case .active:
|
||||
// Restart services when becoming active
|
||||
chatViewModel.meshService.startServices()
|
||||
TorManager.shared.setAppForeground(true)
|
||||
// On initial cold launch, Tor was just started in onAppear.
|
||||
// Skip the deterministic restart the first time we become active.
|
||||
if didHandleInitialActive && didEnterBackground {
|
||||
if TorManager.shared.isAutoStartAllowed() && !TorManager.shared.isReady {
|
||||
TorManager.shared.ensureRunningOnForeground()
|
||||
}
|
||||
} else {
|
||||
didHandleInitialActive = true
|
||||
}
|
||||
didEnterBackground = false
|
||||
if TorManager.shared.isAutoStartAllowed() {
|
||||
Task.detached {
|
||||
let _ = await TorManager.shared.awaitReady(timeout: 60)
|
||||
await MainActor.run {
|
||||
// Rebuild proxied sessions to bind to the live Tor after readiness
|
||||
TorURLSession.shared.rebuild()
|
||||
// Reconnect Nostr via fresh sessions; will gate until Tor 100%
|
||||
NostrRelayManager.shared.resetAllConnections()
|
||||
}
|
||||
}
|
||||
}
|
||||
checkForSharedContent()
|
||||
case .inactive:
|
||||
break
|
||||
@unknown default:
|
||||
break
|
||||
}
|
||||
}
|
||||
.onReceive(NotificationCenter.default.publisher(for: UIApplication.didBecomeActiveNotification)) { _ in
|
||||
// Check for shared content when app becomes active
|
||||
checkForSharedContent()
|
||||
// Notify MessageRouter to check for Nostr messages
|
||||
NotificationCenter.default.post(name: .appDidBecomeActive, object: nil)
|
||||
}
|
||||
#elseif os(macOS)
|
||||
.onReceive(NotificationCenter.default.publisher(for: NSApplication.didBecomeActiveNotification)) { _ in
|
||||
// Notify MessageRouter to check for Nostr messages
|
||||
NotificationCenter.default.post(name: .appDidBecomeActive, object: nil)
|
||||
// App became active
|
||||
}
|
||||
#endif
|
||||
}
|
||||
@@ -68,7 +149,7 @@ struct BitchatApp: App {
|
||||
|
||||
private func checkForSharedContent() {
|
||||
// Check app group for shared content from extension
|
||||
guard let userDefaults = UserDefaults(suiteName: "group.chat.bitchat") else {
|
||||
guard let userDefaults = UserDefaults(suiteName: BitchatApp.groupID) else {
|
||||
return
|
||||
}
|
||||
|
||||
@@ -77,30 +158,18 @@ struct BitchatApp: App {
|
||||
return
|
||||
}
|
||||
|
||||
// Only process if shared within last 30 seconds
|
||||
if Date().timeIntervalSince(sharedDate) < 30 {
|
||||
// Only process if shared within configured window
|
||||
if Date().timeIntervalSince(sharedDate) < TransportConfig.uiShareAcceptWindowSeconds {
|
||||
let contentType = userDefaults.string(forKey: "sharedContentType") ?? "text"
|
||||
|
||||
// Clear the shared content
|
||||
userDefaults.removeObject(forKey: "sharedContent")
|
||||
userDefaults.removeObject(forKey: "sharedContentType")
|
||||
userDefaults.removeObject(forKey: "sharedContentDate")
|
||||
userDefaults.synchronize()
|
||||
// No need to force synchronize here
|
||||
|
||||
// Show notification about shared content
|
||||
// Send the shared content immediately on the main queue
|
||||
DispatchQueue.main.async {
|
||||
// Add system message about sharing
|
||||
let systemMessage = BitchatMessage(
|
||||
sender: "system",
|
||||
content: "preparing to share \(contentType)...",
|
||||
timestamp: Date(),
|
||||
isRelay: false
|
||||
)
|
||||
self.chatViewModel.messages.append(systemMessage)
|
||||
}
|
||||
|
||||
// Send the shared content after a short delay
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 1.0) {
|
||||
if contentType == "url" {
|
||||
// Try to parse as JSON first
|
||||
if let data = sharedContent.data(using: .utf8),
|
||||
@@ -121,19 +190,23 @@ struct BitchatApp: App {
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
class AppDelegate: NSObject, UIApplicationDelegate {
|
||||
final class AppDelegate: NSObject, UIApplicationDelegate {
|
||||
weak var chatViewModel: ChatViewModel?
|
||||
|
||||
func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey : Any]? = nil) -> Bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func applicationWillTerminate(_ application: UIApplication) {
|
||||
chatViewModel?.applicationWillTerminate()
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
#if os(macOS)
|
||||
import AppKit
|
||||
|
||||
class MacAppDelegate: NSObject, NSApplicationDelegate {
|
||||
final class MacAppDelegate: NSObject, NSApplicationDelegate {
|
||||
weak var chatViewModel: ChatViewModel?
|
||||
|
||||
func applicationWillTerminate(_ notification: Notification) {
|
||||
@@ -146,7 +219,7 @@ class MacAppDelegate: NSObject, NSApplicationDelegate {
|
||||
}
|
||||
#endif
|
||||
|
||||
class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
|
||||
final class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
|
||||
static let shared = NotificationDelegate()
|
||||
weak var chatViewModel: ChatViewModel?
|
||||
|
||||
@@ -159,10 +232,18 @@ class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
|
||||
// Get peer ID from userInfo
|
||||
if let peerID = userInfo["peerID"] as? String {
|
||||
DispatchQueue.main.async {
|
||||
self.chatViewModel?.startPrivateChat(with: peerID)
|
||||
self.chatViewModel?.startPrivateChat(with: PeerID(str: peerID))
|
||||
}
|
||||
}
|
||||
}
|
||||
// Handle deeplink (e.g., geohash activity)
|
||||
if let deep = userInfo["deeplink"] as? String, let url = URL(string: deep) {
|
||||
#if os(iOS)
|
||||
DispatchQueue.main.async { UIApplication.shared.open(url) }
|
||||
#else
|
||||
DispatchQueue.main.async { NSWorkspace.shared.open(url) }
|
||||
#endif
|
||||
}
|
||||
|
||||
completionHandler()
|
||||
}
|
||||
@@ -176,10 +257,24 @@ class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
|
||||
// Get peer ID from userInfo
|
||||
if let peerID = userInfo["peerID"] as? String {
|
||||
// Don't show notification if the private chat is already open
|
||||
if chatViewModel?.selectedPrivateChatPeer == peerID {
|
||||
completionHandler([])
|
||||
return
|
||||
// Access main-actor-isolated property via Task
|
||||
Task { @MainActor in
|
||||
if self.chatViewModel?.selectedPrivateChatPeer == PeerID(str: peerID) {
|
||||
completionHandler([])
|
||||
} else {
|
||||
completionHandler([.banner, .sound])
|
||||
}
|
||||
}
|
||||
return
|
||||
}
|
||||
}
|
||||
// Suppress geohash activity notification if we're already in that geohash channel
|
||||
if identifier.hasPrefix("geo-activity-"),
|
||||
let deep = userInfo["deeplink"] as? String,
|
||||
let gh = deep.components(separatedBy: "/").last {
|
||||
if case .location(let ch) = LocationChannelManager.shared.selectedChannel, ch.geohash == gh {
|
||||
completionHandler([])
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
@@ -188,8 +283,3 @@ class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
|
||||
}
|
||||
}
|
||||
|
||||
extension String {
|
||||
var nilIfEmpty: String? {
|
||||
self.isEmpty ? nil : self
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,203 @@
|
||||
import Foundation
|
||||
import ImageIO
|
||||
import UniformTypeIdentifiers
|
||||
#if os(iOS)
|
||||
import UIKit
|
||||
#else
|
||||
import AppKit
|
||||
#endif
|
||||
|
||||
enum ImageUtilsError: Error {
|
||||
case invalidImage
|
||||
case encodingFailed
|
||||
}
|
||||
|
||||
enum ImageUtils {
|
||||
private static let compressionQuality: CGFloat = 0.82
|
||||
private static let targetImageBytes: Int = 45_000
|
||||
|
||||
static func processImage(at url: URL, maxDimension: CGFloat = 448) throws -> URL {
|
||||
// Security H1: Check file size BEFORE reading into memory
|
||||
let attrs = try FileManager.default.attributesOfItem(atPath: url.path)
|
||||
guard let fileSize = attrs[.size] as? Int else {
|
||||
throw ImageUtilsError.invalidImage
|
||||
}
|
||||
// Allow up to 10MB source images (will be scaled down)
|
||||
guard fileSize <= 10 * 1024 * 1024 else {
|
||||
throw ImageUtilsError.invalidImage
|
||||
}
|
||||
|
||||
let data = try Data(contentsOf: url)
|
||||
#if os(iOS)
|
||||
guard let image = UIImage(data: data) else { throw ImageUtilsError.invalidImage }
|
||||
return try processImage(image, maxDimension: maxDimension)
|
||||
#else
|
||||
guard let image = NSImage(data: data) else { throw ImageUtilsError.invalidImage }
|
||||
return try processImage(image, maxDimension: maxDimension)
|
||||
#endif
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
static func processImage(_ image: UIImage, maxDimension: CGFloat = 448) throws -> URL {
|
||||
return try autoreleasepool {
|
||||
// Scale the image first
|
||||
let scaled = scaledImage(image, maxDimension: maxDimension)
|
||||
|
||||
// Get CGImage from UIImage - this is the key to stripping metadata
|
||||
guard let cgImage = scaled.cgImage else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
|
||||
// Use CGImageDestination to encode without metadata (same as macOS)
|
||||
var quality = compressionQuality
|
||||
guard var jpegData = encodeJPEG(from: cgImage, quality: quality) else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
|
||||
// Compress to target size
|
||||
while jpegData.count > targetImageBytes && quality > 0.3 {
|
||||
quality -= 0.1
|
||||
autoreleasepool {
|
||||
if let next = encodeJPEG(from: cgImage, quality: quality) {
|
||||
jpegData = next
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let outputURL = try makeOutputURL()
|
||||
try jpegData.write(to: outputURL, options: .atomic)
|
||||
return outputURL
|
||||
}
|
||||
}
|
||||
|
||||
private static func scaledImage(_ image: UIImage, maxDimension: CGFloat) -> UIImage {
|
||||
let size = image.size
|
||||
let maxSide = max(size.width, size.height)
|
||||
guard maxSide > maxDimension else { return image }
|
||||
let scale = maxDimension / maxSide
|
||||
let newSize = CGSize(width: size.width * scale, height: size.height * scale)
|
||||
|
||||
// Draw into a new context to get a clean CGImage without metadata
|
||||
UIGraphicsBeginImageContextWithOptions(newSize, true, 1.0)
|
||||
image.draw(in: CGRect(origin: .zero, size: newSize))
|
||||
let rendered = UIGraphicsGetImageFromCurrentImageContext()
|
||||
UIGraphicsEndImageContext()
|
||||
return rendered ?? image
|
||||
}
|
||||
|
||||
// Shared EXIF-stripping JPEG encoder for both iOS and macOS
|
||||
private static func encodeJPEG(from cgImage: CGImage, quality: CGFloat) -> Data? {
|
||||
guard let data = CFDataCreateMutable(nil, 0) else {
|
||||
return nil
|
||||
}
|
||||
guard let destination = CGImageDestinationCreateWithData(data, UTType.jpeg.identifier as CFString, 1, nil) else {
|
||||
return nil
|
||||
}
|
||||
// Security: Strip ALL metadata (EXIF, GPS, TIFF, IPTC, XMP)
|
||||
// By only specifying compression quality and no metadata keys,
|
||||
// we ensure a clean JPEG with no privacy-leaking information
|
||||
let options: [CFString: Any] = [
|
||||
kCGImageDestinationLossyCompressionQuality: quality
|
||||
]
|
||||
CGImageDestinationAddImage(destination, cgImage, options as CFDictionary)
|
||||
guard CGImageDestinationFinalize(destination) else {
|
||||
return nil
|
||||
}
|
||||
return data as Data
|
||||
}
|
||||
#else
|
||||
static func processImage(_ image: NSImage, maxDimension: CGFloat = 448) throws -> URL {
|
||||
return try autoreleasepool {
|
||||
let scaled = scaledImage(image, maxDimension: maxDimension)
|
||||
guard let inputCG = scaled.cgImage(forProposedRect: nil, context: nil, hints: nil) else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
let width = inputCG.width
|
||||
let height = inputCG.height
|
||||
let colorSpace = CGColorSpace(name: CGColorSpace.sRGB) ?? CGColorSpaceCreateDeviceRGB()
|
||||
guard let context = CGContext(
|
||||
data: nil,
|
||||
width: width,
|
||||
height: height,
|
||||
bitsPerComponent: 8,
|
||||
bytesPerRow: 0,
|
||||
space: colorSpace,
|
||||
bitmapInfo: CGImageAlphaInfo.premultipliedLast.rawValue
|
||||
) else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
context.draw(inputCG, in: CGRect(x: 0, y: 0, width: width, height: height))
|
||||
guard let cgImage = context.makeImage() else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
var quality = compressionQuality
|
||||
guard var jpegData = encodeJPEG(from: cgImage, quality: quality) else {
|
||||
throw ImageUtilsError.encodingFailed
|
||||
}
|
||||
while jpegData.count > targetImageBytes && quality > 0.3 {
|
||||
quality -= 0.1
|
||||
autoreleasepool {
|
||||
if let next = encodeJPEG(from: cgImage, quality: quality) {
|
||||
jpegData = next
|
||||
}
|
||||
}
|
||||
}
|
||||
let outputURL = try makeOutputURL()
|
||||
try jpegData.write(to: outputURL, options: .atomic)
|
||||
return outputURL
|
||||
}
|
||||
}
|
||||
|
||||
private static func scaledImage(_ image: NSImage, maxDimension: CGFloat) -> NSImage {
|
||||
let size = image.size
|
||||
let maxSide = max(size.width, size.height)
|
||||
guard maxSide > maxDimension else { return image }
|
||||
let scale = maxDimension / maxSide
|
||||
let newSize = NSSize(width: size.width * scale, height: size.height * scale)
|
||||
let scaledImage = NSImage(size: newSize)
|
||||
scaledImage.lockFocus()
|
||||
image.draw(in: NSRect(origin: .zero, size: newSize),
|
||||
from: NSRect(origin: .zero, size: size),
|
||||
operation: .copy,
|
||||
fraction: 1.0)
|
||||
scaledImage.unlockFocus()
|
||||
return scaledImage
|
||||
}
|
||||
|
||||
// Shared EXIF-stripping JPEG encoder for both iOS and macOS
|
||||
private static func encodeJPEG(from cgImage: CGImage, quality: CGFloat) -> Data? {
|
||||
guard let data = CFDataCreateMutable(nil, 0) else {
|
||||
return nil
|
||||
}
|
||||
guard let destination = CGImageDestinationCreateWithData(data, UTType.jpeg.identifier as CFString, 1, nil) else {
|
||||
return nil
|
||||
}
|
||||
// Security: Strip ALL metadata (EXIF, GPS, TIFF, IPTC, XMP)
|
||||
// By only specifying compression quality and no metadata keys,
|
||||
// we ensure a clean JPEG with no privacy-leaking information
|
||||
let options: [CFString: Any] = [
|
||||
kCGImageDestinationLossyCompressionQuality: quality
|
||||
]
|
||||
CGImageDestinationAddImage(destination, cgImage, options as CFDictionary)
|
||||
guard CGImageDestinationFinalize(destination) else {
|
||||
return nil
|
||||
}
|
||||
return data as Data
|
||||
}
|
||||
#endif
|
||||
|
||||
private static func makeOutputURL() throws -> URL {
|
||||
let formatter = DateFormatter()
|
||||
formatter.dateFormat = "yyyyMMdd_HHmmss"
|
||||
let fileName = "img_\(formatter.string(from: Date())).jpg"
|
||||
|
||||
let directory = try applicationFilesDirectory().appendingPathComponent("images/outgoing", isDirectory: true)
|
||||
try FileManager.default.createDirectory(at: directory, withIntermediateDirectories: true, attributes: nil)
|
||||
return directory.appendingPathComponent(fileName)
|
||||
}
|
||||
|
||||
private static func applicationFilesDirectory() throws -> URL {
|
||||
let base = try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true)
|
||||
return base.appendingPathComponent("files", isDirectory: true)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,205 @@
|
||||
import Foundation
|
||||
import AVFoundation
|
||||
import BitLogger
|
||||
|
||||
/// Controls playback for a single voice note and coordinates exclusive playback across the app.
|
||||
final class VoiceNotePlaybackController: NSObject, ObservableObject, AVAudioPlayerDelegate {
|
||||
@Published private(set) var isPlaying: Bool = false
|
||||
@Published private(set) var currentTime: TimeInterval = 0
|
||||
@Published private(set) var duration: TimeInterval = 0
|
||||
@Published private(set) var progress: Double = 0
|
||||
|
||||
/// rounded so 4.9s shows "00:05"
|
||||
var roundedDuration: Int {
|
||||
guard duration.isFinite else { return 0 }
|
||||
return Int(duration.rounded())
|
||||
}
|
||||
|
||||
/// ceil so "00:01" stays visible until playback ends, capped to rounded duration
|
||||
var remainingSeconds: Int {
|
||||
let remaining = max(0, duration - currentTime)
|
||||
return min(roundedDuration, Int(ceil(remaining)))
|
||||
}
|
||||
|
||||
private var player: AVAudioPlayer?
|
||||
private var timer: Timer?
|
||||
private var url: URL
|
||||
|
||||
init(url: URL) {
|
||||
self.url = url
|
||||
super.init()
|
||||
// Don't load anything eagerly - wait until user interaction or view is fully displayed
|
||||
}
|
||||
|
||||
func loadDuration() {
|
||||
guard duration == 0 else { return }
|
||||
|
||||
DispatchQueue.global(qos: .utility).async { [weak self] in
|
||||
guard let self = self else { return }
|
||||
do {
|
||||
let player = try AVAudioPlayer(contentsOf: self.url)
|
||||
let loadedDuration = player.duration
|
||||
DispatchQueue.main.async { [weak self] in
|
||||
guard let self = self, self.duration == 0 else { return }
|
||||
self.duration = loadedDuration
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.error("Failed to load audio duration: \(error)", category: .session)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
deinit {
|
||||
timer?.invalidate()
|
||||
}
|
||||
|
||||
func replaceURL(_ url: URL) {
|
||||
guard url != self.url else { return }
|
||||
stop()
|
||||
self.url = url
|
||||
player = nil
|
||||
duration = 0
|
||||
// Duration will be loaded on demand when needed
|
||||
}
|
||||
|
||||
func togglePlayback() {
|
||||
isPlaying ? pause() : play()
|
||||
}
|
||||
|
||||
func play() {
|
||||
guard ensurePlayerReady() else { return }
|
||||
VoiceNotePlaybackCoordinator.shared.activate(self)
|
||||
player?.play()
|
||||
startTimer()
|
||||
updateProgress()
|
||||
isPlaying = true
|
||||
}
|
||||
|
||||
func pause() {
|
||||
player?.pause()
|
||||
stopTimer()
|
||||
updateProgress()
|
||||
isPlaying = false
|
||||
}
|
||||
|
||||
func stop() {
|
||||
player?.stop()
|
||||
player?.currentTime = 0
|
||||
stopTimer()
|
||||
updateProgress()
|
||||
isPlaying = false
|
||||
VoiceNotePlaybackCoordinator.shared.deactivate(self)
|
||||
}
|
||||
|
||||
func seek(to fraction: Double) {
|
||||
guard ensurePlayerReady() else { return }
|
||||
let clamped = max(0, min(1, fraction))
|
||||
if let player = player {
|
||||
player.currentTime = clamped * player.duration
|
||||
if isPlaying {
|
||||
player.play()
|
||||
}
|
||||
updateProgress()
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - AVAudioPlayerDelegate
|
||||
|
||||
func audioPlayerDidFinishPlaying(_ player: AVAudioPlayer, successfully flag: Bool) {
|
||||
// Delegate callback may be on background thread - ensure main thread for UI updates
|
||||
DispatchQueue.main.async { [weak self] in
|
||||
guard let self = self else { return }
|
||||
self.stopTimer()
|
||||
self.updateProgress()
|
||||
self.isPlaying = false
|
||||
VoiceNotePlaybackCoordinator.shared.deactivate(self)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers
|
||||
|
||||
private func preparePlayer(for url: URL) {
|
||||
// Prepare player synchronously (only called when playback is requested)
|
||||
do {
|
||||
let player = try AVAudioPlayer(contentsOf: url)
|
||||
player.delegate = self
|
||||
player.prepareToPlay()
|
||||
self.player = player
|
||||
duration = player.duration
|
||||
currentTime = player.currentTime
|
||||
progress = duration > 0 ? currentTime / duration : 0
|
||||
} catch {
|
||||
SecureLogger.error("Voice note playback failed for \(url.lastPathComponent): \(error)", category: .session)
|
||||
player = nil
|
||||
duration = 0
|
||||
currentTime = 0
|
||||
progress = 0
|
||||
}
|
||||
}
|
||||
|
||||
private func ensurePlayerReady() -> Bool {
|
||||
if player == nil {
|
||||
preparePlayer(for: url)
|
||||
}
|
||||
#if os(iOS)
|
||||
let session = AVAudioSession.sharedInstance()
|
||||
do {
|
||||
try session.setCategory(.playback, mode: .spokenAudio, options: [.mixWithOthers])
|
||||
try session.setActive(true, options: [])
|
||||
} catch {
|
||||
SecureLogger.error("Failed to activate audio session: \(error)", category: .session)
|
||||
}
|
||||
#endif
|
||||
return player != nil
|
||||
}
|
||||
|
||||
private func startTimer() {
|
||||
if timer != nil { return }
|
||||
timer = Timer.scheduledTimer(withTimeInterval: 0.05, repeats: true) { [weak self] _ in
|
||||
self?.updateProgress()
|
||||
}
|
||||
if let timer = timer {
|
||||
RunLoop.main.add(timer, forMode: .common)
|
||||
}
|
||||
}
|
||||
|
||||
private func stopTimer() {
|
||||
timer?.invalidate()
|
||||
timer = nil
|
||||
}
|
||||
|
||||
private func updateProgress() {
|
||||
guard let player = player else {
|
||||
currentTime = 0
|
||||
duration = 0
|
||||
progress = 0
|
||||
return
|
||||
}
|
||||
currentTime = player.currentTime
|
||||
duration = player.duration
|
||||
progress = duration > 0 ? currentTime / duration : 0
|
||||
}
|
||||
}
|
||||
|
||||
/// Ensures only one voice note plays at a time.
|
||||
final class VoiceNotePlaybackCoordinator {
|
||||
static let shared = VoiceNotePlaybackCoordinator()
|
||||
|
||||
private weak var activeController: VoiceNotePlaybackController?
|
||||
|
||||
private init() {}
|
||||
|
||||
func activate(_ controller: VoiceNotePlaybackController) {
|
||||
if activeController === controller {
|
||||
return
|
||||
}
|
||||
activeController?.pause()
|
||||
activeController = controller
|
||||
}
|
||||
|
||||
func deactivate(_ controller: VoiceNotePlaybackController) {
|
||||
if activeController === controller {
|
||||
activeController = nil
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,155 @@
|
||||
import Foundation
|
||||
import AVFoundation
|
||||
|
||||
/// Manages audio capture for mesh voice notes with predictable encoding settings.
|
||||
actor VoiceRecorder {
|
||||
enum RecorderError: Error {
|
||||
case microphoneAccessDenied
|
||||
case recorderInitializationFailed
|
||||
case recordingInProgress
|
||||
}
|
||||
|
||||
static let shared = VoiceRecorder()
|
||||
|
||||
private let paddingInterval: TimeInterval = 0.5
|
||||
private let maxRecordingDuration: TimeInterval = 120
|
||||
static let minRecordingDuration: TimeInterval = 1
|
||||
|
||||
private var recorder: AVAudioRecorder?
|
||||
private var currentURL: URL?
|
||||
|
||||
// MARK: - Permissions
|
||||
|
||||
nonisolated
|
||||
func requestPermission() async -> Bool {
|
||||
#if os(iOS)
|
||||
return await withCheckedContinuation { continuation in
|
||||
AVAudioSession.sharedInstance().requestRecordPermission { granted in
|
||||
continuation.resume(returning: granted)
|
||||
}
|
||||
}
|
||||
#elseif os(macOS)
|
||||
return await withCheckedContinuation { continuation in
|
||||
AVCaptureDevice.requestAccess(for: .audio) { granted in
|
||||
continuation.resume(returning: granted)
|
||||
}
|
||||
}
|
||||
#else
|
||||
return true
|
||||
#endif
|
||||
}
|
||||
|
||||
// MARK: - Recording Lifecycle
|
||||
|
||||
@discardableResult
|
||||
func startRecording() throws -> URL {
|
||||
if recorder?.isRecording == true {
|
||||
throw RecorderError.recordingInProgress
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
let session = AVAudioSession.sharedInstance()
|
||||
guard session.recordPermission == .granted else {
|
||||
throw RecorderError.microphoneAccessDenied
|
||||
}
|
||||
#if targetEnvironment(simulator)
|
||||
// allowBluetoothHFP is not available on iOS Simulator
|
||||
try session.setCategory(
|
||||
.playAndRecord,
|
||||
mode: .default,
|
||||
options: [.defaultToSpeaker, .allowBluetoothA2DP]
|
||||
)
|
||||
#else
|
||||
try session.setCategory(
|
||||
.playAndRecord,
|
||||
mode: .default,
|
||||
options: [.defaultToSpeaker, .allowBluetoothA2DP, .allowBluetoothHFP]
|
||||
)
|
||||
#endif
|
||||
try session.setActive(true, options: .notifyOthersOnDeactivation)
|
||||
#endif
|
||||
#if os(macOS)
|
||||
guard AVCaptureDevice.authorizationStatus(for: .audio) == .authorized else {
|
||||
throw RecorderError.microphoneAccessDenied
|
||||
}
|
||||
#endif
|
||||
|
||||
let outputURL = try makeOutputURL()
|
||||
let settings: [String: Any] = [
|
||||
AVFormatIDKey: kAudioFormatMPEG4AAC,
|
||||
AVSampleRateKey: 16_000,
|
||||
AVNumberOfChannelsKey: 1,
|
||||
AVEncoderBitRateKey: 16_000
|
||||
]
|
||||
|
||||
let audioRecorder = try AVAudioRecorder(url: outputURL, settings: settings)
|
||||
audioRecorder.isMeteringEnabled = true
|
||||
audioRecorder.prepareToRecord()
|
||||
audioRecorder.record(forDuration: maxRecordingDuration)
|
||||
|
||||
recorder = audioRecorder
|
||||
currentURL = outputURL
|
||||
return outputURL
|
||||
}
|
||||
|
||||
func stopRecording() async -> URL? {
|
||||
guard let recorder, recorder.isRecording else {
|
||||
return currentURL
|
||||
}
|
||||
|
||||
let sessionURL = currentURL
|
||||
|
||||
try? await Task.sleep(nanoseconds: UInt64(paddingInterval * 1_000_000_000))
|
||||
|
||||
recorder.stop()
|
||||
|
||||
// A new session may have started during the sleep — don't touch its state
|
||||
if self.recorder === recorder {
|
||||
cleanupSession()
|
||||
self.recorder = nil
|
||||
currentURL = nil
|
||||
}
|
||||
|
||||
return sessionURL
|
||||
}
|
||||
|
||||
func cancelRecording() {
|
||||
if let recorder, recorder.isRecording {
|
||||
recorder.stop()
|
||||
}
|
||||
cleanupSession()
|
||||
if let currentURL {
|
||||
try? FileManager.default.removeItem(at: currentURL)
|
||||
}
|
||||
recorder = nil
|
||||
currentURL = nil
|
||||
}
|
||||
|
||||
// MARK: - Helpers
|
||||
|
||||
private func makeOutputURL() throws -> URL {
|
||||
let formatter = DateFormatter()
|
||||
formatter.dateFormat = "yyyyMMdd_HHmmss"
|
||||
let fileName = "voice_\(formatter.string(from: Date())).m4a"
|
||||
|
||||
let baseDirectory = try applicationFilesDirectory().appendingPathComponent("voicenotes/outgoing", isDirectory: true)
|
||||
try FileManager.default.createDirectory(at: baseDirectory, withIntermediateDirectories: true, attributes: nil)
|
||||
return baseDirectory.appendingPathComponent(fileName)
|
||||
}
|
||||
|
||||
private func applicationFilesDirectory() throws -> URL {
|
||||
#if os(iOS)
|
||||
return try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true)
|
||||
.appendingPathComponent("files", isDirectory: true)
|
||||
#else
|
||||
let base = try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true)
|
||||
return base.appendingPathComponent("files", isDirectory: true)
|
||||
#endif
|
||||
}
|
||||
|
||||
private func cleanupSession() {
|
||||
#if os(iOS)
|
||||
try? AVAudioSession.sharedInstance().setActive(false, options: .notifyOthersOnDeactivation)
|
||||
#endif
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,113 @@
|
||||
import AVFoundation
|
||||
import Foundation
|
||||
import BitLogger
|
||||
|
||||
/// Generates and caches downsampled waveforms for audio files so UI rendering is cheap.
|
||||
final class WaveformCache {
|
||||
static let shared = WaveformCache()
|
||||
|
||||
private let queue = DispatchQueue(label: "com.bitchat.waveform-cache", attributes: .concurrent)
|
||||
private var cache: [URL: (waveform: [Float], lastAccess: Date)] = [:]
|
||||
private let maxCacheSize = 20 // Limit cache to prevent unbounded memory growth
|
||||
|
||||
private init() {}
|
||||
|
||||
func cachedWaveform(for url: URL) -> [Float]? {
|
||||
queue.sync {
|
||||
guard let entry = cache[url] else { return nil }
|
||||
return entry.waveform
|
||||
}
|
||||
}
|
||||
|
||||
func waveform(for url: URL, bins: Int = 120, completion: @escaping ([Float]) -> Void) {
|
||||
queue.async { [weak self] in
|
||||
guard let self = self else { return }
|
||||
|
||||
// Check cache (read-only, no update needed on cache hit for performance)
|
||||
if let entry = self.cache[url] {
|
||||
DispatchQueue.main.async { completion(entry.waveform) }
|
||||
return
|
||||
}
|
||||
|
||||
guard let computed = self.computeWaveform(url: url, bins: bins) else {
|
||||
DispatchQueue.main.async { completion([]) }
|
||||
return
|
||||
}
|
||||
|
||||
self.queue.async(flags: .barrier) { [weak self] in
|
||||
guard let self = self else { return }
|
||||
|
||||
// Evict oldest entry if cache is full
|
||||
if self.cache.count >= self.maxCacheSize {
|
||||
if let oldest = self.cache.min(by: { $0.value.lastAccess < $1.value.lastAccess }) {
|
||||
self.cache.removeValue(forKey: oldest.key)
|
||||
}
|
||||
}
|
||||
|
||||
self.cache[url] = (computed, Date())
|
||||
}
|
||||
DispatchQueue.main.async { completion(computed) }
|
||||
}
|
||||
}
|
||||
|
||||
func purge(url: URL) {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
self?.cache.removeValue(forKey: url)
|
||||
}
|
||||
}
|
||||
|
||||
func purgeAll() {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
self?.cache.removeAll()
|
||||
}
|
||||
}
|
||||
|
||||
private func computeWaveform(url: URL, bins: Int) -> [Float]? {
|
||||
guard bins > 0 else { return nil }
|
||||
// Use autoreleasepool to manage memory from audio buffer allocations
|
||||
return autoreleasepool {
|
||||
do {
|
||||
let audioFile = try AVAudioFile(forReading: url)
|
||||
let length = Int(audioFile.length)
|
||||
guard length > 0 else { return nil }
|
||||
|
||||
guard let buffer = AVAudioPCMBuffer(pcmFormat: audioFile.processingFormat, frameCapacity: AVAudioFrameCount(length)) else {
|
||||
return nil
|
||||
}
|
||||
try audioFile.read(into: buffer, frameCount: AVAudioFrameCount(length))
|
||||
guard let channelData = buffer.floatChannelData else { return nil }
|
||||
|
||||
let channelCount = Int(audioFile.processingFormat.channelCount)
|
||||
let frameLength = Int(buffer.frameLength)
|
||||
let samplesPerBin = max(1, frameLength / bins)
|
||||
|
||||
var magnitudes: [Float] = Array(repeating: 0, count: bins)
|
||||
for bin in 0..<bins {
|
||||
let start = bin * samplesPerBin
|
||||
let end = min(frameLength, start + samplesPerBin)
|
||||
if start >= end { break }
|
||||
|
||||
var sum: Float = 0
|
||||
var sampleCount = 0
|
||||
for frame in start..<end {
|
||||
var sampleValue: Float = 0
|
||||
for channel in 0..<channelCount {
|
||||
sampleValue += fabsf(channelData[channel][frame])
|
||||
}
|
||||
sum += sampleValue / Float(channelCount)
|
||||
sampleCount += 1
|
||||
}
|
||||
magnitudes[bin] = sampleCount > 0 ? sum / Float(sampleCount) : 0
|
||||
}
|
||||
|
||||
if let maxMagnitude = magnitudes.max(), maxMagnitude > 0 {
|
||||
magnitudes = magnitudes.map { min($0 / maxMagnitude, 1.0) }
|
||||
}
|
||||
return magnitudes
|
||||
} catch {
|
||||
SecureLogger.error("Waveform extraction failed for \(url.lastPathComponent): \(error)", category: .session)
|
||||
return nil
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -81,13 +81,14 @@
|
||||
///
|
||||
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
// MARK: - Three-Layer Identity Model
|
||||
|
||||
/// Represents the ephemeral layer of identity - short-lived peer IDs that provide network privacy.
|
||||
/// These IDs rotate periodically to prevent tracking while maintaining cryptographic relationships.
|
||||
struct EphemeralIdentity {
|
||||
let peerID: String // 8 random bytes
|
||||
let peerID: PeerID // 8 random bytes
|
||||
let sessionStart: Date
|
||||
var handshakeState: HandshakeState
|
||||
}
|
||||
@@ -106,6 +107,8 @@ enum HandshakeState {
|
||||
struct CryptographicIdentity: Codable {
|
||||
let fingerprint: String // SHA256 of public key
|
||||
let publicKey: Data // Noise static public key
|
||||
// Optional Ed25519 signing public key (used to authenticate public messages)
|
||||
var signingPublicKey: Data? = nil
|
||||
let firstSeen: Date
|
||||
let lastHandshake: Date?
|
||||
}
|
||||
@@ -149,77 +152,14 @@ struct IdentityCache: Codable {
|
||||
// Last interaction timestamps (privacy: optional)
|
||||
var lastInteractions: [String: Date] = [:]
|
||||
|
||||
// Blocked Nostr pubkeys (lowercased hex) for geohash chats
|
||||
var blockedNostrPubkeys: Set<String> = []
|
||||
|
||||
// Schema version for future migrations
|
||||
var version: Int = 1
|
||||
}
|
||||
|
||||
// MARK: - Identity Resolution
|
||||
|
||||
enum IdentityHint {
|
||||
case unknown
|
||||
case likelyKnown(fingerprint: String)
|
||||
case ambiguous(candidates: Set<String>)
|
||||
case verified(fingerprint: String)
|
||||
}
|
||||
|
||||
// MARK: - Pending Actions
|
||||
|
||||
struct PendingActions {
|
||||
var toggleFavorite: Bool?
|
||||
var setTrustLevel: TrustLevel?
|
||||
var setPetname: String?
|
||||
}
|
||||
|
||||
// MARK: - Privacy Settings
|
||||
|
||||
struct PrivacySettings: Codable {
|
||||
// Level 1: Maximum privacy (default)
|
||||
var persistIdentityCache = false
|
||||
var showLastSeen = false
|
||||
|
||||
// Level 2: Convenience
|
||||
var autoAcceptKnownFingerprints = false
|
||||
var rememberNicknameHistory = false
|
||||
|
||||
// Level 3: Social
|
||||
var shareTrustNetworkHints = false // "3 mutual contacts trust this person"
|
||||
}
|
||||
|
||||
// MARK: - Conflict Resolution
|
||||
|
||||
/// Strategies for resolving identity conflicts in the decentralized network.
|
||||
/// Handles cases where multiple peers claim the same nickname or when
|
||||
/// identity mappings become ambiguous due to network partitions.
|
||||
enum ConflictResolution {
|
||||
case acceptNew(petname: String) // "John (2)"
|
||||
case rejectNew
|
||||
case blockFingerprint(String)
|
||||
case alertUser(message: String)
|
||||
}
|
||||
|
||||
// MARK: - UI State
|
||||
|
||||
struct PeerUIState {
|
||||
let peerID: String
|
||||
let nickname: String
|
||||
var identityState: IdentityState
|
||||
var connectionQuality: ConnectionQuality
|
||||
|
||||
enum IdentityState {
|
||||
case unknown // Gray - No identity info
|
||||
case unverifiedKnown(String) // Blue - Handshake done, matches cache
|
||||
case verified(String) // Green - Cryptographically verified
|
||||
case conflict(String, String) // Red - Nickname doesn't match fingerprint
|
||||
case pending // Yellow - Handshake in progress
|
||||
}
|
||||
}
|
||||
|
||||
enum ConnectionQuality {
|
||||
case excellent
|
||||
case good
|
||||
case poor
|
||||
case disconnected
|
||||
}
|
||||
//
|
||||
|
||||
// MARK: - Migration Support
|
||||
// Removed LegacyFavorite - no longer needed
|
||||
//
|
||||
|
||||
@@ -90,27 +90,64 @@
|
||||
/// - Advanced conflict resolution
|
||||
///
|
||||
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
|
||||
protocol SecureIdentityStateManagerProtocol {
|
||||
// MARK: Secure Loading/Saving
|
||||
func forceSave()
|
||||
|
||||
// MARK: Social Identity Management
|
||||
func getSocialIdentity(for fingerprint: String) -> SocialIdentity?
|
||||
|
||||
// MARK: Cryptographic Identities
|
||||
func upsertCryptographicIdentity(fingerprint: String, noisePublicKey: Data, signingPublicKey: Data?, claimedNickname: String?)
|
||||
func getCryptoIdentitiesByPeerIDPrefix(_ peerID: PeerID) -> [CryptographicIdentity]
|
||||
func updateSocialIdentity(_ identity: SocialIdentity)
|
||||
|
||||
// MARK: Favorites Management
|
||||
func getFavorites() -> Set<String>
|
||||
func setFavorite(_ fingerprint: String, isFavorite: Bool)
|
||||
func isFavorite(fingerprint: String) -> Bool
|
||||
|
||||
// MARK: Blocked Users Management
|
||||
func isBlocked(fingerprint: String) -> Bool
|
||||
func setBlocked(_ fingerprint: String, isBlocked: Bool)
|
||||
|
||||
// MARK: Geohash (Nostr) Blocking
|
||||
func isNostrBlocked(pubkeyHexLowercased: String) -> Bool
|
||||
func setNostrBlocked(_ pubkeyHexLowercased: String, isBlocked: Bool)
|
||||
func getBlockedNostrPubkeys() -> Set<String>
|
||||
|
||||
// MARK: Ephemeral Session Management
|
||||
func registerEphemeralSession(peerID: PeerID, handshakeState: HandshakeState)
|
||||
func updateHandshakeState(peerID: PeerID, state: HandshakeState)
|
||||
|
||||
// MARK: Cleanup
|
||||
func clearAllIdentityData()
|
||||
func removeEphemeralSession(peerID: PeerID)
|
||||
|
||||
// MARK: Verification
|
||||
func setVerified(fingerprint: String, verified: Bool)
|
||||
func isVerified(fingerprint: String) -> Bool
|
||||
func getVerifiedFingerprints() -> Set<String>
|
||||
}
|
||||
|
||||
/// Singleton manager for secure identity state persistence and retrieval.
|
||||
/// Provides thread-safe access to identity mappings with encryption at rest.
|
||||
/// All identity data is stored encrypted in the device Keychain for security.
|
||||
class SecureIdentityStateManager {
|
||||
static let shared = SecureIdentityStateManager()
|
||||
|
||||
private let keychain = KeychainManager.shared
|
||||
final class SecureIdentityStateManager: SecureIdentityStateManagerProtocol {
|
||||
private let keychain: KeychainManagerProtocol
|
||||
private let cacheKey = "bitchat.identityCache.v2"
|
||||
private let encryptionKeyName = "identityCacheEncryptionKey"
|
||||
|
||||
// In-memory state
|
||||
private var ephemeralSessions: [String: EphemeralIdentity] = [:]
|
||||
private var ephemeralSessions: [PeerID: EphemeralIdentity] = [:]
|
||||
private var cryptographicIdentities: [String: CryptographicIdentity] = [:]
|
||||
private var cache: IdentityCache = IdentityCache()
|
||||
|
||||
// Pending actions before handshake
|
||||
private var pendingActions: [String: PendingActions] = [:]
|
||||
|
||||
// Thread safety
|
||||
private let queue = DispatchQueue(label: "bitchat.identity.state", attributes: .concurrent)
|
||||
|
||||
@@ -122,14 +159,16 @@ class SecureIdentityStateManager {
|
||||
// Encryption key
|
||||
private let encryptionKey: SymmetricKey
|
||||
|
||||
private init() {
|
||||
init(_ keychain: KeychainManagerProtocol) {
|
||||
self.keychain = keychain
|
||||
|
||||
// Generate or retrieve encryption key from keychain
|
||||
let loadedKey: SymmetricKey
|
||||
|
||||
// Try to load from keychain
|
||||
if let keyData = keychain.getIdentityKey(forKey: encryptionKeyName) {
|
||||
loadedKey = SymmetricKey(data: keyData)
|
||||
SecureLogger.logKeyOperation("load", keyType: "identity cache encryption key", success: true)
|
||||
SecureLogger.logKeyOperation(.load, keyType: "identity cache encryption key", success: true)
|
||||
}
|
||||
// Generate new key if needed
|
||||
else {
|
||||
@@ -137,7 +176,7 @@ class SecureIdentityStateManager {
|
||||
let keyData = loadedKey.withUnsafeBytes { Data($0) }
|
||||
// Save to keychain
|
||||
let saved = keychain.saveIdentityKey(keyData, forKey: encryptionKeyName)
|
||||
SecureLogger.logKeyOperation("generate", keyType: "identity cache encryption key", success: saved)
|
||||
SecureLogger.logKeyOperation(.generate, keyType: "identity cache encryption key", success: saved)
|
||||
}
|
||||
|
||||
self.encryptionKey = loadedKey
|
||||
@@ -146,9 +185,13 @@ class SecureIdentityStateManager {
|
||||
loadIdentityCache()
|
||||
}
|
||||
|
||||
deinit {
|
||||
forceSave()
|
||||
}
|
||||
|
||||
// MARK: - Secure Loading/Saving
|
||||
|
||||
func loadIdentityCache() {
|
||||
private func loadIdentityCache() {
|
||||
guard let encryptedData = keychain.getIdentityKey(forKey: cacheKey) else {
|
||||
// No existing cache, start fresh
|
||||
return
|
||||
@@ -160,16 +203,11 @@ class SecureIdentityStateManager {
|
||||
cache = try JSONDecoder().decode(IdentityCache.self, from: decryptedData)
|
||||
} catch {
|
||||
// Log error but continue with empty cache
|
||||
SecureLogger.logError(error, context: "Failed to load identity cache", category: SecureLogger.security)
|
||||
SecureLogger.error(error, context: "Failed to load identity cache", category: .security)
|
||||
}
|
||||
}
|
||||
|
||||
deinit {
|
||||
// Force save any pending changes
|
||||
forceSave()
|
||||
}
|
||||
|
||||
func saveIdentityCache() {
|
||||
private func saveIdentityCache() {
|
||||
// Mark that we need to save
|
||||
pendingSave = true
|
||||
|
||||
@@ -191,35 +229,17 @@ class SecureIdentityStateManager {
|
||||
let sealedBox = try AES.GCM.seal(data, using: encryptionKey)
|
||||
let saved = keychain.saveIdentityKey(sealedBox.combined!, forKey: cacheKey)
|
||||
if saved {
|
||||
SecureLogger.log("Identity cache saved to keychain", category: SecureLogger.security, level: .debug)
|
||||
SecureLogger.debug("Identity cache saved to keychain", category: .security)
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.logError(error, context: "Failed to save identity cache", category: SecureLogger.security)
|
||||
SecureLogger.error(error, context: "Failed to save identity cache", category: .security)
|
||||
}
|
||||
}
|
||||
|
||||
// Force immediate save (for app termination)
|
||||
func forceSave() {
|
||||
saveTimer?.invalidate()
|
||||
if pendingSave {
|
||||
performSave()
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Identity Resolution
|
||||
|
||||
func resolveIdentity(peerID: String, claimedNickname: String) -> IdentityHint {
|
||||
queue.sync {
|
||||
// Check if we have candidates based on nickname
|
||||
if let fingerprints = cache.nicknameIndex[claimedNickname] {
|
||||
if fingerprints.count == 1 {
|
||||
return .likelyKnown(fingerprint: fingerprints.first!)
|
||||
} else {
|
||||
return .ambiguous(candidates: fingerprints)
|
||||
}
|
||||
}
|
||||
return .unknown
|
||||
}
|
||||
performSave()
|
||||
}
|
||||
|
||||
// MARK: - Social Identity Management
|
||||
@@ -230,24 +250,97 @@ class SecureIdentityStateManager {
|
||||
}
|
||||
}
|
||||
|
||||
func getAllSocialIdentities() -> [SocialIdentity] {
|
||||
// MARK: - Cryptographic Identities
|
||||
|
||||
/// Insert or update a cryptographic identity and optionally persist its signing key and claimed nickname.
|
||||
/// - Parameters:
|
||||
/// - fingerprint: SHA-256 hex of the Noise static public key
|
||||
/// - noisePublicKey: Noise static public key data
|
||||
/// - signingPublicKey: Optional Ed25519 signing public key for authenticating public messages
|
||||
/// - claimedNickname: Optional latest claimed nickname to persist into social identity
|
||||
func upsertCryptographicIdentity(fingerprint: String, noisePublicKey: Data, signingPublicKey: Data?, claimedNickname: String? = nil) {
|
||||
queue.async(flags: .barrier) {
|
||||
let now = Date()
|
||||
if var existing = self.cryptographicIdentities[fingerprint] {
|
||||
// Update keys if changed
|
||||
if existing.publicKey != noisePublicKey {
|
||||
existing = CryptographicIdentity(
|
||||
fingerprint: fingerprint,
|
||||
publicKey: noisePublicKey,
|
||||
signingPublicKey: signingPublicKey ?? existing.signingPublicKey,
|
||||
firstSeen: existing.firstSeen,
|
||||
lastHandshake: now
|
||||
)
|
||||
self.cryptographicIdentities[fingerprint] = existing
|
||||
} else {
|
||||
// Update signing key and lastHandshake
|
||||
existing.signingPublicKey = signingPublicKey ?? existing.signingPublicKey
|
||||
let updated = CryptographicIdentity(
|
||||
fingerprint: existing.fingerprint,
|
||||
publicKey: existing.publicKey,
|
||||
signingPublicKey: existing.signingPublicKey,
|
||||
firstSeen: existing.firstSeen,
|
||||
lastHandshake: now
|
||||
)
|
||||
self.cryptographicIdentities[fingerprint] = updated
|
||||
}
|
||||
// Persist updated state (already assigned in branches above)
|
||||
} else {
|
||||
// New entry
|
||||
let entry = CryptographicIdentity(
|
||||
fingerprint: fingerprint,
|
||||
publicKey: noisePublicKey,
|
||||
signingPublicKey: signingPublicKey,
|
||||
firstSeen: now,
|
||||
lastHandshake: now
|
||||
)
|
||||
self.cryptographicIdentities[fingerprint] = entry
|
||||
}
|
||||
|
||||
// Optionally persist claimed nickname into social identity
|
||||
if let claimed = claimedNickname {
|
||||
var identity = self.cache.socialIdentities[fingerprint] ?? SocialIdentity(
|
||||
fingerprint: fingerprint,
|
||||
localPetname: nil,
|
||||
claimedNickname: claimed,
|
||||
trustLevel: .unknown,
|
||||
isFavorite: false,
|
||||
isBlocked: false,
|
||||
notes: nil
|
||||
)
|
||||
// Update claimed nickname if changed
|
||||
if identity.claimedNickname != claimed {
|
||||
identity.claimedNickname = claimed
|
||||
self.cache.socialIdentities[fingerprint] = identity
|
||||
} else if self.cache.socialIdentities[fingerprint] == nil {
|
||||
self.cache.socialIdentities[fingerprint] = identity
|
||||
}
|
||||
}
|
||||
|
||||
self.saveIdentityCache()
|
||||
}
|
||||
}
|
||||
|
||||
/// Find cryptographic identities whose fingerprint prefix matches a peerID (16-hex) short ID
|
||||
func getCryptoIdentitiesByPeerIDPrefix(_ peerID: PeerID) -> [CryptographicIdentity] {
|
||||
queue.sync {
|
||||
return Array(cache.socialIdentities.values)
|
||||
// Defensive: ensure hex and correct length
|
||||
guard peerID.isShort else { return [] }
|
||||
return cryptographicIdentities.values.filter { $0.fingerprint.hasPrefix(peerID.id) }
|
||||
}
|
||||
}
|
||||
|
||||
func updateSocialIdentity(_ identity: SocialIdentity) {
|
||||
queue.async(flags: .barrier) {
|
||||
let previousClaimedNickname = self.cache.socialIdentities[identity.fingerprint]?.claimedNickname
|
||||
self.cache.socialIdentities[identity.fingerprint] = identity
|
||||
|
||||
// Update nickname index
|
||||
if let existingIdentity = self.cache.socialIdentities[identity.fingerprint] {
|
||||
// Remove old nickname from index if changed
|
||||
if existingIdentity.claimedNickname != identity.claimedNickname {
|
||||
self.cache.nicknameIndex[existingIdentity.claimedNickname]?.remove(identity.fingerprint)
|
||||
if self.cache.nicknameIndex[existingIdentity.claimedNickname]?.isEmpty == true {
|
||||
self.cache.nicknameIndex.removeValue(forKey: existingIdentity.claimedNickname)
|
||||
}
|
||||
if let previousClaimedNickname,
|
||||
previousClaimedNickname != identity.claimedNickname {
|
||||
self.cache.nicknameIndex[previousClaimedNickname]?.remove(identity.fingerprint)
|
||||
if self.cache.nicknameIndex[previousClaimedNickname]?.isEmpty == true {
|
||||
self.cache.nicknameIndex.removeValue(forKey: previousClaimedNickname)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -310,7 +403,7 @@ class SecureIdentityStateManager {
|
||||
}
|
||||
|
||||
func setBlocked(_ fingerprint: String, isBlocked: Bool) {
|
||||
SecureLogger.log("User \(isBlocked ? "blocked" : "unblocked"): \(fingerprint)", category: SecureLogger.security, level: .info)
|
||||
SecureLogger.info("User \(isBlocked ? "blocked" : "unblocked"): \(fingerprint)", category: .security)
|
||||
|
||||
queue.async(flags: .barrier) {
|
||||
if var identity = self.cache.socialIdentities[fingerprint] {
|
||||
@@ -336,9 +429,33 @@ class SecureIdentityStateManager {
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Geohash (Nostr) Blocking
|
||||
|
||||
func isNostrBlocked(pubkeyHexLowercased: String) -> Bool {
|
||||
queue.sync {
|
||||
return cache.blockedNostrPubkeys.contains(pubkeyHexLowercased.lowercased())
|
||||
}
|
||||
}
|
||||
|
||||
func setNostrBlocked(_ pubkeyHexLowercased: String, isBlocked: Bool) {
|
||||
let key = pubkeyHexLowercased.lowercased()
|
||||
queue.async(flags: .barrier) {
|
||||
if isBlocked {
|
||||
self.cache.blockedNostrPubkeys.insert(key)
|
||||
} else {
|
||||
self.cache.blockedNostrPubkeys.remove(key)
|
||||
}
|
||||
self.saveIdentityCache()
|
||||
}
|
||||
}
|
||||
|
||||
func getBlockedNostrPubkeys() -> Set<String> {
|
||||
queue.sync { cache.blockedNostrPubkeys }
|
||||
}
|
||||
|
||||
// MARK: - Ephemeral Session Management
|
||||
|
||||
func registerEphemeralSession(peerID: String, handshakeState: HandshakeState = .none) {
|
||||
func registerEphemeralSession(peerID: PeerID, handshakeState: HandshakeState = .none) {
|
||||
queue.async(flags: .barrier) {
|
||||
self.ephemeralSessions[peerID] = EphemeralIdentity(
|
||||
peerID: peerID,
|
||||
@@ -348,7 +465,7 @@ class SecureIdentityStateManager {
|
||||
}
|
||||
}
|
||||
|
||||
func updateHandshakeState(peerID: String, state: HandshakeState) {
|
||||
func updateHandshakeState(peerID: PeerID, state: HandshakeState) {
|
||||
queue.async(flags: .barrier) {
|
||||
self.ephemeralSessions[peerID]?.handshakeState = state
|
||||
|
||||
@@ -360,81 +477,32 @@ class SecureIdentityStateManager {
|
||||
}
|
||||
}
|
||||
|
||||
func getHandshakeState(peerID: String) -> HandshakeState? {
|
||||
queue.sync {
|
||||
return ephemeralSessions[peerID]?.handshakeState
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Pending Actions
|
||||
|
||||
func setPendingAction(peerID: String, action: PendingActions) {
|
||||
queue.async(flags: .barrier) {
|
||||
self.pendingActions[peerID] = action
|
||||
}
|
||||
}
|
||||
|
||||
func applyPendingActions(peerID: String, fingerprint: String) {
|
||||
queue.async(flags: .barrier) {
|
||||
guard let actions = self.pendingActions[peerID] else { return }
|
||||
|
||||
// Get or create social identity
|
||||
var identity = self.cache.socialIdentities[fingerprint] ?? SocialIdentity(
|
||||
fingerprint: fingerprint,
|
||||
localPetname: nil,
|
||||
claimedNickname: "Unknown",
|
||||
trustLevel: .unknown,
|
||||
isFavorite: false,
|
||||
isBlocked: false,
|
||||
notes: nil
|
||||
)
|
||||
|
||||
// Apply pending actions
|
||||
if let toggleFavorite = actions.toggleFavorite {
|
||||
identity.isFavorite = toggleFavorite
|
||||
}
|
||||
if let trustLevel = actions.setTrustLevel {
|
||||
identity.trustLevel = trustLevel
|
||||
}
|
||||
if let petname = actions.setPetname {
|
||||
identity.localPetname = petname
|
||||
}
|
||||
|
||||
// Save updated identity
|
||||
self.cache.socialIdentities[fingerprint] = identity
|
||||
self.pendingActions.removeValue(forKey: peerID)
|
||||
self.saveIdentityCache()
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Cleanup
|
||||
|
||||
func clearAllIdentityData() {
|
||||
SecureLogger.log("Clearing all identity data", category: SecureLogger.security, level: .warning)
|
||||
SecureLogger.warning("Clearing all identity data", category: .security)
|
||||
|
||||
queue.async(flags: .barrier) {
|
||||
self.cache = IdentityCache()
|
||||
self.ephemeralSessions.removeAll()
|
||||
self.cryptographicIdentities.removeAll()
|
||||
self.pendingActions.removeAll()
|
||||
|
||||
// Delete from keychain
|
||||
let deleted = self.keychain.deleteIdentityKey(forKey: self.cacheKey)
|
||||
SecureLogger.logKeyOperation("delete", keyType: "identity cache", success: deleted)
|
||||
SecureLogger.logKeyOperation(.delete, keyType: "identity cache", success: deleted)
|
||||
}
|
||||
}
|
||||
|
||||
func removeEphemeralSession(peerID: String) {
|
||||
func removeEphemeralSession(peerID: PeerID) {
|
||||
queue.async(flags: .barrier) {
|
||||
self.ephemeralSessions.removeValue(forKey: peerID)
|
||||
self.pendingActions.removeValue(forKey: peerID)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Verification
|
||||
|
||||
func setVerified(fingerprint: String, verified: Bool) {
|
||||
SecureLogger.log("Fingerprint \(verified ? "verified" : "unverified"): \(fingerprint)", category: SecureLogger.security, level: .info)
|
||||
SecureLogger.info("Fingerprint \(verified ? "verified" : "unverified"): \(fingerprint)", category: .security)
|
||||
|
||||
queue.async(flags: .barrier) {
|
||||
if verified {
|
||||
@@ -464,4 +532,16 @@ class SecureIdentityStateManager {
|
||||
return cache.verifiedFingerprints
|
||||
}
|
||||
}
|
||||
|
||||
var debugNicknameIndex: [String: Set<String>] {
|
||||
queue.sync { cache.nicknameIndex }
|
||||
}
|
||||
|
||||
func debugEphemeralSession(for peerID: PeerID) -> EphemeralIdentity? {
|
||||
queue.sync { ephemeralSessions[peerID] }
|
||||
}
|
||||
|
||||
func debugLastInteraction(for fingerprint: String) -> Date? {
|
||||
queue.sync { cache.lastInteractions[fingerprint] }
|
||||
}
|
||||
}
|
||||
@@ -2,6 +2,8 @@
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>AppGroupID</key>
|
||||
<string>$(APP_GROUP_ID)</string>
|
||||
<key>CFBundleDevelopmentRegion</key>
|
||||
<string>$(DEVELOPMENT_LANGUAGE)</string>
|
||||
<key>CFBundleDisplayName</key>
|
||||
@@ -35,37 +37,26 @@
|
||||
<string>bitchat uses Bluetooth to create a secure mesh network for chatting with nearby users.</string>
|
||||
<key>NSBluetoothPeripheralUsageDescription</key>
|
||||
<string>bitchat uses Bluetooth to discover and connect with other bitchat users nearby.</string>
|
||||
<key>NSCameraUsageDescription</key>
|
||||
<string>bitchat uses the camera to scan QR codes to verify peers.</string>
|
||||
<key>NSLocationWhenInUseUsageDescription</key>
|
||||
<string>bitchat uses your approximate location to compute local geohash channels for optional public chats. Exact GPS is never shared.</string>
|
||||
<key>NSMicrophoneUsageDescription</key>
|
||||
<string>bitchat uses the microphone to record voice notes that relay across the mesh.</string>
|
||||
<key>NSPhotoLibraryUsageDescription</key>
|
||||
<string>bitchat lets you pick images from your photo library to share with nearby peers.</string>
|
||||
<key>UIBackgroundModes</key>
|
||||
<array>
|
||||
<string>bluetooth-central</string>
|
||||
<string>bluetooth-peripheral</string>
|
||||
<string>remote-notification</string>
|
||||
</array>
|
||||
<key>UILaunchStoryboardName</key>
|
||||
<string>LaunchScreen</string>
|
||||
<key>UIRequiresFullScreen</key>
|
||||
<true/>
|
||||
<key>UISupportedInterfaceOrientations</key>
|
||||
<array>
|
||||
<string>UIInterfaceOrientationPortrait</string>
|
||||
</array>
|
||||
<key>UISupportedInterfaceOrientations~ipad</key>
|
||||
<array>
|
||||
<string>UIInterfaceOrientationLandscapeLeft</string>
|
||||
<string>UIInterfaceOrientationLandscapeRight</string>
|
||||
<string>UIInterfaceOrientationPortrait</string>
|
||||
<string>UIInterfaceOrientationPortraitUpsideDown</string>
|
||||
</array>
|
||||
<key>NSAppTransportSecurity</key>
|
||||
<dict>
|
||||
<key>NSAllowsArbitraryLoads</key>
|
||||
<false/>
|
||||
<key>NSAllowsArbitraryLoadsForMedia</key>
|
||||
<false/>
|
||||
<key>NSAllowsArbitraryLoadsInWebContent</key>
|
||||
<false/>
|
||||
<key>NSAllowsLocalNetworking</key>
|
||||
<true/>
|
||||
</dict>
|
||||
<key>NSLocalNetworkUsageDescription</key>
|
||||
<string>bitchat uses local network access to discover and connect with other bitchat users on your network.</string>
|
||||
</dict>
|
||||
</plist>
|
||||
|
||||
@@ -0,0 +1,68 @@
|
||||
//
|
||||
// BitchatMessage+Media.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
extension BitchatMessage {
|
||||
enum Media {
|
||||
case voice(URL)
|
||||
case image(URL)
|
||||
|
||||
var url: URL {
|
||||
switch self {
|
||||
case .voice(let url), .image(let url):
|
||||
return url
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Cache the directory lookup to avoid repeated FileManager calls during view rendering
|
||||
private struct Cache {
|
||||
let filesDir: URL?
|
||||
|
||||
static let shared = Cache()
|
||||
private init() {
|
||||
do {
|
||||
let base = try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true)
|
||||
let filesDir = base.appendingPathComponent("files", isDirectory: true)
|
||||
try FileManager.default.createDirectory(at: filesDir, withIntermediateDirectories: true, attributes: nil)
|
||||
self.filesDir = filesDir
|
||||
} catch {
|
||||
filesDir = nil
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func mediaAttachment(for nickname: String) -> Media? {
|
||||
guard let baseDirectory = Cache.shared.filesDir else { return nil }
|
||||
|
||||
func url(for category: MimeType.Category) -> URL? {
|
||||
guard content.hasPrefix(category.messagePrefix),
|
||||
let filename = String(content.dropFirst(category.messagePrefix.count)).trimmedOrNilIfEmpty
|
||||
else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Check outgoing first for sent messages, incoming for received
|
||||
let subdir = sender == nickname ? "\(category.mediaDir)/outgoing" : "\(category.mediaDir)/incoming"
|
||||
|
||||
// Construct URL directly without fileExists check (avoids blocking disk I/O in view body)
|
||||
// Files are checked during playback/display, so missing files fail gracefully
|
||||
let directory = baseDirectory.appendingPathComponent(subdir, isDirectory: true)
|
||||
return directory.appendingPathComponent(filename)
|
||||
}
|
||||
|
||||
if let url = url(for: .audio) {
|
||||
return .voice(url)
|
||||
}
|
||||
if let url = url(for: .image) {
|
||||
return .image(url)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,356 @@
|
||||
//
|
||||
// BitchatMessage.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
/// Represents a user-visible message in the BitChat system.
|
||||
/// Handles both broadcast messages and private encrypted messages,
|
||||
/// with support for mentions, replies, and delivery tracking.
|
||||
/// - Note: This is the primary data model for chat messages
|
||||
final class BitchatMessage: Codable {
|
||||
let id: String
|
||||
let sender: String
|
||||
let content: String
|
||||
let timestamp: Date
|
||||
let isRelay: Bool
|
||||
let originalSender: String?
|
||||
let isPrivate: Bool
|
||||
let recipientNickname: String?
|
||||
let senderPeerID: PeerID?
|
||||
let mentions: [String]? // Array of mentioned nicknames
|
||||
var deliveryStatus: DeliveryStatus? // Delivery tracking
|
||||
|
||||
// Cached formatted text (not included in Codable)
|
||||
private var _cachedFormattedText: [String: AttributedString] = [:]
|
||||
|
||||
func getCachedFormattedText(isDark: Bool, isSelf: Bool) -> AttributedString? {
|
||||
return _cachedFormattedText["\(isDark)-\(isSelf)"]
|
||||
}
|
||||
|
||||
func setCachedFormattedText(_ text: AttributedString, isDark: Bool, isSelf: Bool) {
|
||||
_cachedFormattedText["\(isDark)-\(isSelf)"] = text
|
||||
}
|
||||
|
||||
// Codable implementation
|
||||
enum CodingKeys: String, CodingKey {
|
||||
case id, sender, content, timestamp, isRelay, originalSender
|
||||
case isPrivate, recipientNickname, senderPeerID, mentions, deliveryStatus
|
||||
}
|
||||
|
||||
init(
|
||||
id: String? = nil,
|
||||
sender: String,
|
||||
content: String,
|
||||
timestamp: Date,
|
||||
isRelay: Bool,
|
||||
originalSender: String? = nil,
|
||||
isPrivate: Bool = false,
|
||||
recipientNickname: String? = nil,
|
||||
senderPeerID: PeerID? = nil,
|
||||
mentions: [String]? = nil,
|
||||
deliveryStatus: DeliveryStatus? = nil
|
||||
) {
|
||||
self.id = id ?? UUID().uuidString
|
||||
self.sender = sender
|
||||
self.content = content
|
||||
self.timestamp = timestamp
|
||||
self.isRelay = isRelay
|
||||
self.originalSender = originalSender
|
||||
self.isPrivate = isPrivate
|
||||
self.recipientNickname = recipientNickname
|
||||
self.senderPeerID = senderPeerID
|
||||
self.mentions = mentions
|
||||
self.deliveryStatus = deliveryStatus ?? (isPrivate ? .sending : nil)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Equatable Conformance
|
||||
|
||||
extension BitchatMessage: Equatable {
|
||||
static func == (lhs: BitchatMessage, rhs: BitchatMessage) -> Bool {
|
||||
return lhs.id == rhs.id &&
|
||||
lhs.sender == rhs.sender &&
|
||||
lhs.content == rhs.content &&
|
||||
lhs.timestamp == rhs.timestamp &&
|
||||
lhs.isRelay == rhs.isRelay &&
|
||||
lhs.originalSender == rhs.originalSender &&
|
||||
lhs.isPrivate == rhs.isPrivate &&
|
||||
lhs.recipientNickname == rhs.recipientNickname &&
|
||||
lhs.senderPeerID == rhs.senderPeerID &&
|
||||
lhs.mentions == rhs.mentions &&
|
||||
lhs.deliveryStatus == rhs.deliveryStatus
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Binary encoding
|
||||
|
||||
extension BitchatMessage {
|
||||
func toBinaryPayload() -> Data? {
|
||||
var data = Data()
|
||||
|
||||
// Message format:
|
||||
// - Flags: 1 byte (bit 0: isRelay, bit 1: isPrivate, bit 2: hasOriginalSender, bit 3: hasRecipientNickname, bit 4: hasSenderPeerID, bit 5: hasMentions)
|
||||
// - Timestamp: 8 bytes (seconds since epoch)
|
||||
// - ID length: 1 byte
|
||||
// - ID: variable
|
||||
// - Sender length: 1 byte
|
||||
// - Sender: variable
|
||||
// - Content length: 2 bytes
|
||||
// - Content: variable
|
||||
// Optional fields based on flags:
|
||||
// - Original sender length + data
|
||||
// - Recipient nickname length + data
|
||||
// - Sender peer ID length + data
|
||||
// - Mentions array
|
||||
|
||||
var flags: UInt8 = 0
|
||||
if isRelay { flags |= 0x01 }
|
||||
if isPrivate { flags |= 0x02 }
|
||||
if originalSender != nil { flags |= 0x04 }
|
||||
if recipientNickname != nil { flags |= 0x08 }
|
||||
if senderPeerID != nil { flags |= 0x10 }
|
||||
if mentions != nil && !mentions!.isEmpty { flags |= 0x20 }
|
||||
|
||||
data.append(flags)
|
||||
|
||||
// Timestamp (in milliseconds)
|
||||
let timestampMillis = UInt64(timestamp.timeIntervalSince1970 * 1000)
|
||||
// Encode as 8 bytes, big-endian
|
||||
for i in (0..<8).reversed() {
|
||||
data.append(UInt8((timestampMillis >> (i * 8)) & 0xFF))
|
||||
}
|
||||
|
||||
// ID
|
||||
if let idData = id.data(using: .utf8) {
|
||||
data.append(UInt8(min(idData.count, 255)))
|
||||
data.append(idData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
|
||||
// Sender
|
||||
if let senderData = sender.data(using: .utf8) {
|
||||
data.append(UInt8(min(senderData.count, 255)))
|
||||
data.append(senderData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
|
||||
// Content
|
||||
if let contentData = content.data(using: .utf8) {
|
||||
let length = UInt16(min(contentData.count, 65535))
|
||||
// Encode length as 2 bytes, big-endian
|
||||
data.append(UInt8((length >> 8) & 0xFF))
|
||||
data.append(UInt8(length & 0xFF))
|
||||
data.append(contentData.prefix(Int(length)))
|
||||
} else {
|
||||
data.append(contentsOf: [0, 0])
|
||||
}
|
||||
|
||||
// Optional fields
|
||||
if let originalSender = originalSender, let origData = originalSender.data(using: .utf8) {
|
||||
data.append(UInt8(min(origData.count, 255)))
|
||||
data.append(origData.prefix(255))
|
||||
}
|
||||
|
||||
if let recipientNickname = recipientNickname, let recipData = recipientNickname.data(using: .utf8) {
|
||||
data.append(UInt8(min(recipData.count, 255)))
|
||||
data.append(recipData.prefix(255))
|
||||
}
|
||||
|
||||
if let peerData = senderPeerID?.id.data(using: .utf8) {
|
||||
data.append(UInt8(min(peerData.count, 255)))
|
||||
data.append(peerData.prefix(255))
|
||||
}
|
||||
|
||||
// Mentions array
|
||||
if let mentions = mentions {
|
||||
data.append(UInt8(min(mentions.count, 255))) // Number of mentions
|
||||
for mention in mentions.prefix(255) {
|
||||
if let mentionData = mention.data(using: .utf8) {
|
||||
data.append(UInt8(min(mentionData.count, 255)))
|
||||
data.append(mentionData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
return data
|
||||
}
|
||||
|
||||
convenience init?(_ data: Data) {
|
||||
// Create an immutable copy to prevent threading issues
|
||||
let dataCopy = Data(data)
|
||||
|
||||
|
||||
guard dataCopy.count >= 13 else {
|
||||
return nil
|
||||
}
|
||||
|
||||
var offset = 0
|
||||
|
||||
// Flags
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let flags = dataCopy[offset]; offset += 1
|
||||
let isRelay = (flags & 0x01) != 0
|
||||
let isPrivate = (flags & 0x02) != 0
|
||||
let hasOriginalSender = (flags & 0x04) != 0
|
||||
let hasRecipientNickname = (flags & 0x08) != 0
|
||||
let hasSenderPeerID = (flags & 0x10) != 0
|
||||
let hasMentions = (flags & 0x20) != 0
|
||||
|
||||
// Timestamp
|
||||
guard offset + 8 <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let timestampData = dataCopy[offset..<offset+8]
|
||||
let timestampMillis = timestampData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt64(byte)
|
||||
}
|
||||
offset += 8
|
||||
let timestamp = Date(timeIntervalSince1970: TimeInterval(timestampMillis) / 1000.0)
|
||||
|
||||
// ID
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let idLength = Int(dataCopy[offset]); offset += 1
|
||||
guard offset + idLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let id = String(data: dataCopy[offset..<offset+idLength], encoding: .utf8) ?? UUID().uuidString
|
||||
offset += idLength
|
||||
|
||||
// Sender
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let senderLength = Int(dataCopy[offset]); offset += 1
|
||||
guard offset + senderLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let sender = String(data: dataCopy[offset..<offset+senderLength], encoding: .utf8) ?? "unknown"
|
||||
offset += senderLength
|
||||
|
||||
// Content
|
||||
guard offset + 2 <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let contentLengthData = dataCopy[offset..<offset+2]
|
||||
let contentLength = Int(contentLengthData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt16(byte)
|
||||
})
|
||||
offset += 2
|
||||
guard offset + contentLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
|
||||
let content = String(data: dataCopy[offset..<offset+contentLength], encoding: .utf8) ?? ""
|
||||
offset += contentLength
|
||||
|
||||
// Optional fields
|
||||
var originalSender: String?
|
||||
if hasOriginalSender && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
originalSender = String(data: dataCopy[offset..<offset+length], encoding: .utf8)
|
||||
offset += length
|
||||
}
|
||||
}
|
||||
|
||||
var recipientNickname: String?
|
||||
if hasRecipientNickname && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
recipientNickname = String(data: dataCopy[offset..<offset+length], encoding: .utf8)
|
||||
offset += length
|
||||
}
|
||||
}
|
||||
|
||||
var senderPeerID: PeerID?
|
||||
if hasSenderPeerID && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
senderPeerID = PeerID(data: dataCopy[offset..<offset+length])
|
||||
offset += length
|
||||
}
|
||||
}
|
||||
|
||||
// Mentions array
|
||||
var mentions: [String]?
|
||||
if hasMentions && offset < dataCopy.count {
|
||||
let mentionCount = Int(dataCopy[offset]); offset += 1
|
||||
if mentionCount > 0 {
|
||||
mentions = []
|
||||
for _ in 0..<mentionCount {
|
||||
if offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
if let mention = String(data: dataCopy[offset..<offset+length], encoding: .utf8) {
|
||||
mentions?.append(mention)
|
||||
}
|
||||
offset += length
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
self.init(
|
||||
id: id,
|
||||
sender: sender,
|
||||
content: content,
|
||||
timestamp: timestamp,
|
||||
isRelay: isRelay,
|
||||
originalSender: originalSender,
|
||||
isPrivate: isPrivate,
|
||||
recipientNickname: recipientNickname,
|
||||
senderPeerID: senderPeerID,
|
||||
mentions: mentions
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Helpers
|
||||
|
||||
extension BitchatMessage {
|
||||
|
||||
private static let timestampFormatter: DateFormatter = {
|
||||
let formatter = DateFormatter()
|
||||
formatter.dateFormat = "HH:mm:ss"
|
||||
return formatter
|
||||
}()
|
||||
|
||||
var formattedTimestamp: String {
|
||||
Self.timestampFormatter.string(from: timestamp)
|
||||
}
|
||||
}
|
||||
|
||||
extension Array where Element == BitchatMessage {
|
||||
/// Filters out empty ones and deduplicate by ID while preserving order (from oldest to newest)
|
||||
func cleanedAndDeduped() -> [Element] {
|
||||
let arr = filter { $0.content.trimmed.isEmpty == false }
|
||||
guard arr.count > 1 else {
|
||||
return arr
|
||||
}
|
||||
var seen = Set<String>()
|
||||
var dedup: [BitchatMessage] = []
|
||||
for m in arr.sorted(by: { $0.timestamp < $1.timestamp }) {
|
||||
if !seen.contains(m.id) {
|
||||
dedup.append(m)
|
||||
seen.insert(m.id)
|
||||
}
|
||||
}
|
||||
return dedup
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,101 @@
|
||||
//
|
||||
// BitchatPacket.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
/// The core packet structure for all BitChat protocol messages.
|
||||
/// Encapsulates all data needed for routing through the mesh network,
|
||||
/// including TTL for hop limiting and optional encryption.
|
||||
/// - Note: Packets larger than BLE MTU (512 bytes) are automatically fragmented
|
||||
struct BitchatPacket: Codable {
|
||||
let version: UInt8
|
||||
let type: UInt8
|
||||
let senderID: Data
|
||||
let recipientID: Data?
|
||||
let timestamp: UInt64
|
||||
let payload: Data
|
||||
var signature: Data?
|
||||
var ttl: UInt8
|
||||
var route: [Data]?
|
||||
var isRSR: Bool
|
||||
|
||||
init(type: UInt8, senderID: Data, recipientID: Data?, timestamp: UInt64, payload: Data, signature: Data?, ttl: UInt8, version: UInt8 = 1, route: [Data]? = nil, isRSR: Bool = false) {
|
||||
self.version = version
|
||||
self.type = type
|
||||
self.senderID = senderID
|
||||
self.recipientID = recipientID
|
||||
self.timestamp = timestamp
|
||||
self.payload = payload
|
||||
self.signature = signature
|
||||
self.ttl = ttl
|
||||
self.route = route
|
||||
self.isRSR = isRSR
|
||||
}
|
||||
|
||||
// Convenience initializer for new binary format
|
||||
init(type: UInt8, ttl: UInt8, senderID: PeerID, payload: Data, isRSR: Bool = false) {
|
||||
self.version = 1
|
||||
self.type = type
|
||||
// Convert hex string peer ID to binary data (8 bytes)
|
||||
var senderData = Data()
|
||||
var tempID = senderID.id
|
||||
while tempID.count >= 2 {
|
||||
let hexByte = String(tempID.prefix(2))
|
||||
if let byte = UInt8(hexByte, radix: 16) {
|
||||
senderData.append(byte)
|
||||
}
|
||||
tempID = String(tempID.dropFirst(2))
|
||||
}
|
||||
self.senderID = senderData
|
||||
self.recipientID = nil
|
||||
self.timestamp = UInt64(Date().timeIntervalSince1970 * 1000) // milliseconds
|
||||
self.payload = payload
|
||||
self.signature = nil
|
||||
self.ttl = ttl
|
||||
self.route = nil
|
||||
self.isRSR = isRSR
|
||||
}
|
||||
|
||||
var data: Data? {
|
||||
BinaryProtocol.encode(self)
|
||||
}
|
||||
|
||||
func toBinaryData(padding: Bool = true) -> Data? {
|
||||
BinaryProtocol.encode(self, padding: padding)
|
||||
}
|
||||
|
||||
// Backward-compatible helper (defaults to padded encoding)
|
||||
func toBinaryData() -> Data? {
|
||||
toBinaryData(padding: true)
|
||||
}
|
||||
|
||||
/// Create binary representation for signing (without signature and TTL fields)
|
||||
/// TTL is excluded because it changes during packet relay operations
|
||||
func toBinaryDataForSigning() -> Data? {
|
||||
// Create a copy without signature and with fixed TTL for signing
|
||||
// TTL must be excluded because it changes during relay
|
||||
let unsignedPacket = BitchatPacket(
|
||||
type: type,
|
||||
senderID: senderID,
|
||||
recipientID: recipientID,
|
||||
timestamp: timestamp,
|
||||
payload: payload,
|
||||
signature: nil, // Remove signature for signing
|
||||
ttl: 0, // Use fixed TTL=0 for signing to ensure relay compatibility
|
||||
version: version,
|
||||
route: route,
|
||||
isRSR: false // RSR flag is mutable and not part of the signature
|
||||
)
|
||||
return BinaryProtocol.encode(unsignedPacket)
|
||||
}
|
||||
|
||||
static func from(_ data: Data) -> BitchatPacket? {
|
||||
BinaryProtocol.decode(data)
|
||||
}
|
||||
}
|
||||
@@ -1,13 +1,15 @@
|
||||
import Foundation
|
||||
import CoreBluetooth
|
||||
import BitFoundation
|
||||
|
||||
/// Represents a peer in the BitChat network with all associated metadata
|
||||
struct BitchatPeer: Identifiable, Equatable {
|
||||
let id: String // Hex-encoded peer ID
|
||||
struct BitchatPeer: Equatable {
|
||||
let peerID: PeerID // Hex-encoded peer ID
|
||||
let noisePublicKey: Data
|
||||
let nickname: String
|
||||
let lastSeen: Date
|
||||
let isConnected: Bool
|
||||
let isReachable: Bool
|
||||
|
||||
// Favorite-related properties
|
||||
var favoriteStatus: FavoritesPersistenceService.FavoriteRelationship?
|
||||
@@ -18,7 +20,7 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
// Connection state
|
||||
enum ConnectionState {
|
||||
case bluetoothConnected
|
||||
case relayConnected // Connected via mesh relay (another peer)
|
||||
case meshReachable // Seen via mesh recently, not directly connected
|
||||
case nostrAvailable // Mutual favorite, reachable via Nostr
|
||||
case offline // Not connected via any transport
|
||||
}
|
||||
@@ -26,8 +28,8 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
var connectionState: ConnectionState {
|
||||
if isConnected {
|
||||
return .bluetoothConnected
|
||||
} else if isRelayConnected {
|
||||
return .relayConnected
|
||||
} else if isReachable {
|
||||
return .meshReachable
|
||||
} else if favoriteStatus?.isMutual == true {
|
||||
// Mutual favorites can communicate via Nostr when offline
|
||||
return .nostrAvailable
|
||||
@@ -36,8 +38,6 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
}
|
||||
}
|
||||
|
||||
var isRelayConnected: Bool = false // Set by PeerManager based on session state
|
||||
|
||||
var isFavorite: Bool {
|
||||
favoriteStatus?.isFavorite ?? false
|
||||
}
|
||||
@@ -52,15 +52,15 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
|
||||
// Display helpers
|
||||
var displayName: String {
|
||||
nickname.isEmpty ? String(id.prefix(8)) : nickname
|
||||
nickname.isEmpty ? String(peerID.id.prefix(8)) : nickname
|
||||
}
|
||||
|
||||
var statusIcon: String {
|
||||
switch connectionState {
|
||||
case .bluetoothConnected:
|
||||
return "📻" // Radio icon for mesh connection
|
||||
case .relayConnected:
|
||||
return "🔗" // Chain link for relay connection
|
||||
case .meshReachable:
|
||||
return "📡" // Antenna for mesh reachable
|
||||
case .nostrAvailable:
|
||||
return "🌐" // Purple globe for Nostr
|
||||
case .offline:
|
||||
@@ -74,19 +74,19 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
|
||||
// Initialize from mesh service data
|
||||
init(
|
||||
id: String,
|
||||
peerID: PeerID,
|
||||
noisePublicKey: Data,
|
||||
nickname: String,
|
||||
lastSeen: Date = Date(),
|
||||
isConnected: Bool = false,
|
||||
isRelayConnected: Bool = false
|
||||
isReachable: Bool = false
|
||||
) {
|
||||
self.id = id
|
||||
self.peerID = peerID
|
||||
self.noisePublicKey = noisePublicKey
|
||||
self.nickname = nickname
|
||||
self.lastSeen = lastSeen
|
||||
self.isConnected = isConnected
|
||||
self.isRelayConnected = isRelayConnected
|
||||
self.isReachable = isReachable
|
||||
|
||||
// Load favorite status - will be set later by the manager
|
||||
self.favoriteStatus = nil
|
||||
@@ -94,243 +94,6 @@ struct BitchatPeer: Identifiable, Equatable {
|
||||
}
|
||||
|
||||
static func == (lhs: BitchatPeer, rhs: BitchatPeer) -> Bool {
|
||||
lhs.id == rhs.id
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Peer Manager
|
||||
|
||||
/// Manages the collection of peers and their states
|
||||
@MainActor
|
||||
class PeerManager: ObservableObject {
|
||||
@Published var peers: [BitchatPeer] = []
|
||||
@Published var favorites: [BitchatPeer] = []
|
||||
@Published var mutualFavorites: [BitchatPeer] = []
|
||||
|
||||
private let meshService: BluetoothMeshService
|
||||
private let favoritesService = FavoritesPersistenceService.shared
|
||||
|
||||
init(meshService: BluetoothMeshService) {
|
||||
self.meshService = meshService
|
||||
updatePeers()
|
||||
|
||||
// Listen for updates
|
||||
NotificationCenter.default.addObserver(
|
||||
self,
|
||||
selector: #selector(handleFavoriteChanged),
|
||||
name: .favoriteStatusChanged,
|
||||
object: nil
|
||||
)
|
||||
}
|
||||
|
||||
@objc private func handleFavoriteChanged() {
|
||||
SecureLogger.log("⭐ Favorite status changed notification received, updating peers",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
updatePeers()
|
||||
}
|
||||
|
||||
deinit {
|
||||
NotificationCenter.default.removeObserver(self)
|
||||
}
|
||||
|
||||
func updatePeers() {
|
||||
// Reduce log verbosity - only log when count changes
|
||||
let previousCount = peers.count
|
||||
|
||||
// Get current mesh peers
|
||||
let meshPeers = meshService.getPeerNicknames()
|
||||
|
||||
// Build peer list
|
||||
var allPeers: [BitchatPeer] = []
|
||||
var connectedNicknames: Set<String> = []
|
||||
|
||||
// Add connected mesh peers (only if actually connected or relay connected)
|
||||
for (peerID, nickname) in meshPeers {
|
||||
guard let noiseKey = Data(hexString: peerID) else { continue }
|
||||
|
||||
// Safety check: Never add our own peer ID
|
||||
if peerID == meshService.myPeerID {
|
||||
SecureLogger.log("⚠️ Skipping self peer ID \(peerID) in peer list",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
continue
|
||||
}
|
||||
|
||||
// Check if this peer is actually connected (not just known via relay)
|
||||
let isConnected = meshService.isPeerConnected(peerID)
|
||||
let isKnown = meshService.isPeerKnown(peerID)
|
||||
// In a mesh network, a peer can only be relay-connected if:
|
||||
// 1. We know about them (have received announce)
|
||||
// 2. We're not directly connected
|
||||
// 3. There are other peers that could relay (mesh peer count > 2)
|
||||
// For now, disable relay detection until we have proper relay tracking
|
||||
let isRelayConnected = false
|
||||
|
||||
// Debug logging for relay connection detection
|
||||
if isKnown && !isConnected {
|
||||
SecureLogger.log("Peer \(nickname) (\(peerID)): isConnected=\(isConnected), isKnown=\(isKnown), isRelayConnected=\(isRelayConnected)",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
}
|
||||
|
||||
// Skip disconnected peers unless they're favorites (handled later)
|
||||
if !isConnected && !isRelayConnected {
|
||||
continue
|
||||
}
|
||||
|
||||
if isConnected || isRelayConnected {
|
||||
connectedNicknames.insert(nickname)
|
||||
}
|
||||
|
||||
var peer = BitchatPeer(
|
||||
id: peerID,
|
||||
noisePublicKey: noiseKey,
|
||||
nickname: nickname,
|
||||
isConnected: isConnected,
|
||||
isRelayConnected: isRelayConnected
|
||||
)
|
||||
// Set favorite status - check both by current noise key and by nickname
|
||||
if let favoriteStatus = favoritesService.getFavoriteStatus(for: noiseKey) {
|
||||
peer.favoriteStatus = favoriteStatus
|
||||
peer.nostrPublicKey = favoriteStatus.peerNostrPublicKey
|
||||
} else {
|
||||
// Check if we have a favorite for this nickname (peer may have reconnected with new ID)
|
||||
let favoriteByNickname = favoritesService.favorites.values.first { $0.peerNickname == nickname }
|
||||
if let favorite = favoriteByNickname {
|
||||
SecureLogger.log("🔄 Found favorite for '\(nickname)' by nickname, updating noise key",
|
||||
category: SecureLogger.session, level: .info)
|
||||
// Update the favorite's noise key to match the current connection
|
||||
favoritesService.updateNoisePublicKey(from: favorite.peerNoisePublicKey, to: noiseKey, peerNickname: nickname)
|
||||
// Get the updated favorite with the new key
|
||||
peer.favoriteStatus = favoritesService.getFavoriteStatus(for: noiseKey)
|
||||
peer.nostrPublicKey = peer.favoriteStatus?.peerNostrPublicKey ?? favorite.peerNostrPublicKey
|
||||
}
|
||||
}
|
||||
allPeers.append(peer)
|
||||
}
|
||||
|
||||
// Add offline favorites (only those not currently connected/relay-connected AND that we actively favorite)
|
||||
SecureLogger.log("📋 Processing \(favoritesService.favorites.count) favorite relationships (connected/relay nicknames: \(connectedNicknames))",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
for (favoriteKey, favorite) in favoritesService.favorites {
|
||||
let favoriteID = favorite.peerNoisePublicKey.hexEncodedString()
|
||||
|
||||
// Skip if this peer is already connected or relay-connected (by nickname)
|
||||
if connectedNicknames.contains(favorite.peerNickname) {
|
||||
SecureLogger.log(" - Skipping '\(favorite.peerNickname)' (key: \(favoriteKey.hexEncodedString())) - already connected/relay-connected",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
continue
|
||||
}
|
||||
|
||||
// Only add peers that WE favorite (not just ones who favorite us)
|
||||
if !favorite.isFavorite {
|
||||
SecureLogger.log(" - Skipping '\(favorite.peerNickname)' - we don't favorite them (they favorite us: \(favorite.theyFavoritedUs))",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
continue
|
||||
}
|
||||
|
||||
// Add this favorite as an offline peer
|
||||
SecureLogger.log(" - Adding offline favorite '\(favorite.peerNickname)' (key: \(favoriteKey.hexEncodedString()), ID: \(favoriteID), mutual: \(favorite.isMutual))",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
var peer = BitchatPeer(
|
||||
id: favoriteID,
|
||||
noisePublicKey: favorite.peerNoisePublicKey,
|
||||
nickname: favorite.peerNickname,
|
||||
isConnected: false
|
||||
)
|
||||
// Set favorite status
|
||||
peer.favoriteStatus = favorite
|
||||
peer.nostrPublicKey = favorite.peerNostrPublicKey
|
||||
allPeers.append(peer)
|
||||
}
|
||||
|
||||
// Filter out "Unknown" peers unless they are favorites or have a favorite relationship
|
||||
allPeers = allPeers.filter { peer in
|
||||
!(peer.displayName == "Unknown" && peer.favoriteStatus == nil)
|
||||
}
|
||||
|
||||
// Sort: Connected first (direct then relay), then favorites, then alphabetical
|
||||
allPeers.sort { lhs, rhs in
|
||||
// Direct connections first
|
||||
if lhs.isConnected != rhs.isConnected {
|
||||
return lhs.isConnected
|
||||
}
|
||||
// Then relay connections
|
||||
if lhs.isRelayConnected != rhs.isRelayConnected {
|
||||
return lhs.isRelayConnected
|
||||
}
|
||||
// Then favorites
|
||||
if lhs.isFavorite != rhs.isFavorite {
|
||||
return lhs.isFavorite
|
||||
}
|
||||
// Finally alphabetical
|
||||
return lhs.displayName < rhs.displayName
|
||||
}
|
||||
|
||||
// Single pass to compute all subsets and counts
|
||||
var favorites: [BitchatPeer] = []
|
||||
var mutualFavorites: [BitchatPeer] = []
|
||||
var connectedCount = 0
|
||||
var offlineCount = 0
|
||||
|
||||
for peer in allPeers {
|
||||
if peer.isFavorite {
|
||||
favorites.append(peer)
|
||||
}
|
||||
if peer.isMutualFavorite {
|
||||
mutualFavorites.append(peer)
|
||||
}
|
||||
if peer.isConnected {
|
||||
connectedCount += 1
|
||||
} else {
|
||||
offlineCount += 1
|
||||
}
|
||||
}
|
||||
|
||||
self.peers = allPeers
|
||||
self.favorites = favorites
|
||||
self.mutualFavorites = mutualFavorites
|
||||
|
||||
// Always log favorites debug info when there are favorites
|
||||
if favoritesService.favorites.count > 0 {
|
||||
SecureLogger.log("📊 Peer list update: \(allPeers.count) total (\(connectedCount) connected, \(offlineCount) offline), \(favorites.count) favorites, \(mutualFavorites.count) mutual",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Log each peer's status
|
||||
for peer in allPeers {
|
||||
// Use the actual statusIcon from the peer which accounts for relay connections
|
||||
let statusIcon: String
|
||||
switch peer.connectionState {
|
||||
case .bluetoothConnected:
|
||||
statusIcon = "🟢"
|
||||
case .relayConnected:
|
||||
statusIcon = "🔗"
|
||||
case .nostrAvailable:
|
||||
statusIcon = "🌐"
|
||||
case .offline:
|
||||
statusIcon = "🔴"
|
||||
}
|
||||
let favoriteIcon = peer.isMutualFavorite ? "💕" : (peer.isFavorite ? "⭐" : (peer.theyFavoritedUs ? "🌙" : ""))
|
||||
SecureLogger.log(" \(statusIcon) \(peer.displayName) (ID: \(peer.id.prefix(8))...) \(favoriteIcon)",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
}
|
||||
} else if previousCount != allPeers.count {
|
||||
// Only log non-favorite updates if count changed
|
||||
SecureLogger.log("✅ Updated peer list: \(allPeers.count) total peers",
|
||||
category: SecureLogger.session, level: .info)
|
||||
}
|
||||
}
|
||||
|
||||
func toggleFavorite(_ peer: BitchatPeer) {
|
||||
if peer.isFavorite {
|
||||
favoritesService.removeFavorite(peerNoisePublicKey: peer.noisePublicKey)
|
||||
} else {
|
||||
favoritesService.addFavorite(
|
||||
peerNoisePublicKey: peer.noisePublicKey,
|
||||
peerNostrPublicKey: peer.nostrPublicKey,
|
||||
peerNickname: peer.nickname
|
||||
)
|
||||
}
|
||||
updatePeers()
|
||||
lhs.peerID == rhs.peerID
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
//
|
||||
// CommandsInfo.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
// MARK: - CommandInfo Enum
|
||||
|
||||
enum CommandInfo: String, Identifiable {
|
||||
case block
|
||||
case clear
|
||||
case hug
|
||||
case message = "dm"
|
||||
case slap
|
||||
case unblock
|
||||
case who
|
||||
case favorite
|
||||
case unfavorite
|
||||
|
||||
var id: String { rawValue }
|
||||
|
||||
var alias: String { "/" + rawValue }
|
||||
|
||||
var placeholder: String? {
|
||||
switch self {
|
||||
case .block, .hug, .message, .slap, .unblock, .favorite, .unfavorite:
|
||||
return "<" + String(localized: "content.input.nickname_placeholder") + ">"
|
||||
case .clear, .who:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
var description: String {
|
||||
switch self {
|
||||
case .block: String(localized: "content.commands.block")
|
||||
case .clear: String(localized: "content.commands.clear")
|
||||
case .hug: String(localized: "content.commands.hug")
|
||||
case .message: String(localized: "content.commands.message")
|
||||
case .slap: String(localized: "content.commands.slap")
|
||||
case .unblock: String(localized: "content.commands.unblock")
|
||||
case .who: String(localized: "content.commands.who")
|
||||
case .favorite: String(localized: "content.commands.favorite")
|
||||
case .unfavorite: String(localized: "content.commands.unfavorite")
|
||||
}
|
||||
}
|
||||
|
||||
static func all(isGeoPublic: Bool, isGeoDM: Bool) -> [CommandInfo] {
|
||||
let baseCommands: [CommandInfo] = [.block, .unblock, .clear, .hug, .message, .slap, .who]
|
||||
if isGeoPublic || isGeoDM {
|
||||
return baseCommands + [.favorite, .unfavorite]
|
||||
}
|
||||
return baseCommands
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,61 @@
|
||||
//
|
||||
// MessagePadding.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
/// Provides privacy-preserving message padding to obscure actual content length.
|
||||
/// Uses PKCS#7-style padding with random bytes to prevent traffic analysis.
|
||||
struct MessagePadding {
|
||||
// Standard block sizes for padding
|
||||
static let blockSizes = [256, 512, 1024, 2048]
|
||||
|
||||
// Add PKCS#7-style padding to reach target size
|
||||
static func pad(_ data: Data, toSize targetSize: Int) -> Data {
|
||||
guard data.count < targetSize else { return data }
|
||||
|
||||
let paddingNeeded = targetSize - data.count
|
||||
// Constrain to 255 to fit a single-byte pad length marker
|
||||
guard paddingNeeded > 0 && paddingNeeded <= 255 else { return data }
|
||||
|
||||
var padded = data
|
||||
// PKCS#7: All pad bytes are equal to the pad length
|
||||
padded.append(contentsOf: Array(repeating: UInt8(paddingNeeded), count: paddingNeeded))
|
||||
return padded
|
||||
}
|
||||
|
||||
// Remove padding from data
|
||||
static func unpad(_ data: Data) -> Data {
|
||||
guard !data.isEmpty else { return data }
|
||||
let last = data.last!
|
||||
let paddingLength = Int(last)
|
||||
// Must have at least 1 pad byte and not exceed data length
|
||||
guard paddingLength > 0 && paddingLength <= data.count else { return data }
|
||||
// Verify PKCS#7: all last N bytes equal to pad length
|
||||
let start = data.count - paddingLength
|
||||
let tail = data[start...]
|
||||
for b in tail { if b != last { return data } }
|
||||
return Data(data[..<start])
|
||||
}
|
||||
|
||||
// Find optimal block size for data
|
||||
static func optimalBlockSize(for dataSize: Int) -> Int {
|
||||
// Account for encryption overhead (~16 bytes for AES-GCM tag)
|
||||
let totalSize = dataSize + 16
|
||||
|
||||
// Find smallest block that fits
|
||||
for blockSize in blockSizes {
|
||||
if totalSize <= blockSize {
|
||||
return blockSize
|
||||
}
|
||||
}
|
||||
|
||||
// For very large messages, just use the original size
|
||||
// (will be fragmented anyway)
|
||||
return dataSize
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,41 @@
|
||||
//
|
||||
// NoisePayload.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
/// Helper to create typed Noise payloads
|
||||
struct NoisePayload {
|
||||
let type: NoisePayloadType
|
||||
let data: Data
|
||||
|
||||
/// Encode payload with type prefix
|
||||
func encode() -> Data {
|
||||
var encoded = Data()
|
||||
encoded.append(type.rawValue)
|
||||
encoded.append(data)
|
||||
return encoded
|
||||
}
|
||||
|
||||
/// Decode payload from data
|
||||
static func decode(_ data: Data) -> NoisePayload? {
|
||||
// Ensure we have at least 1 byte for the type
|
||||
guard !data.isEmpty else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Safely get the first byte
|
||||
let firstByte = data[data.startIndex]
|
||||
guard let type = NoisePayloadType(rawValue: firstByte) else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Create a proper Data copy (not a subsequence) for thread safety
|
||||
let payloadData = data.count > 1 ? Data(data.dropFirst()) : Data()
|
||||
return NoisePayload(type: type, data: payloadData)
|
||||
}
|
||||
}
|
||||
@@ -1,91 +0,0 @@
|
||||
import Foundation
|
||||
import CoreBluetooth
|
||||
|
||||
/// Unified model for tracking all peer session data
|
||||
/// Consolidates multiple redundant data structures into a single source of truth
|
||||
class PeerSession {
|
||||
// Core identification
|
||||
let peerID: String
|
||||
var nickname: String
|
||||
|
||||
// Bluetooth connection
|
||||
var peripheral: CBPeripheral?
|
||||
var peripheralID: String?
|
||||
var characteristic: CBCharacteristic?
|
||||
|
||||
// Authentication and encryption
|
||||
var isAuthenticated: Bool = false
|
||||
var hasEstablishedNoiseSession: Bool = false
|
||||
var fingerprint: String?
|
||||
|
||||
// Connection state
|
||||
var isConnected: Bool = false
|
||||
var lastSeen: Date
|
||||
|
||||
// Protocol state
|
||||
var hasAnnounced: Bool = false
|
||||
var hasReceivedAnnounce: Bool = false
|
||||
var isActivePeer: Bool = false
|
||||
|
||||
// Message tracking
|
||||
var lastMessageSent: Date?
|
||||
var lastMessageReceived: Date?
|
||||
var pendingMessages: [String] = []
|
||||
|
||||
// Connection timing
|
||||
var lastConnectionTime: Date?
|
||||
var lastSuccessfulMessageTime: Date?
|
||||
var lastHeardFromPeer: Date?
|
||||
|
||||
// Availability tracking
|
||||
var isAvailable: Bool = false
|
||||
|
||||
// Identity binding
|
||||
var identityBinding: PeerIdentityBinding?
|
||||
|
||||
init(peerID: String, nickname: String = "Unknown") {
|
||||
self.peerID = peerID
|
||||
self.nickname = nickname
|
||||
self.lastSeen = Date()
|
||||
}
|
||||
|
||||
/// Update Bluetooth connection info
|
||||
func updateBluetoothConnection(peripheral: CBPeripheral?, characteristic: CBCharacteristic?) {
|
||||
self.peripheral = peripheral
|
||||
self.peripheralID = peripheral?.identifier.uuidString
|
||||
self.characteristic = characteristic
|
||||
self.isConnected = (peripheral?.state == .connected)
|
||||
if isConnected {
|
||||
self.lastSeen = Date()
|
||||
}
|
||||
}
|
||||
|
||||
/// Update authentication state
|
||||
func updateAuthenticationState(authenticated: Bool, noiseSession: Bool) {
|
||||
self.isAuthenticated = authenticated
|
||||
self.hasEstablishedNoiseSession = noiseSession
|
||||
if authenticated {
|
||||
self.isActivePeer = true
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/// Check if session is stale
|
||||
var isStale: Bool {
|
||||
// Consider stale if not seen for more than 5 minutes and not connected
|
||||
return !isConnected && Date().timeIntervalSince(lastSeen) > 300
|
||||
}
|
||||
|
||||
/// Get display status for UI
|
||||
var displayStatus: String {
|
||||
if isConnected {
|
||||
if isAuthenticated {
|
||||
return "🟢" // Connected and authenticated
|
||||
} else {
|
||||
return "🟡" // Connected but not authenticated
|
||||
}
|
||||
} else {
|
||||
return "🔴" // Not connected
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,96 @@
|
||||
//
|
||||
// ReadReceipt.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
struct ReadReceipt: Codable {
|
||||
let originalMessageID: String
|
||||
let receiptID: String
|
||||
var readerID: PeerID // Who read it
|
||||
let readerNickname: String
|
||||
let timestamp: Date
|
||||
|
||||
init(originalMessageID: String, readerID: PeerID, readerNickname: String) {
|
||||
self.originalMessageID = originalMessageID
|
||||
self.receiptID = UUID().uuidString
|
||||
self.readerID = readerID
|
||||
self.readerNickname = readerNickname
|
||||
self.timestamp = Date()
|
||||
}
|
||||
|
||||
// For binary decoding
|
||||
private init(originalMessageID: String, receiptID: String, readerID: PeerID, readerNickname: String, timestamp: Date) {
|
||||
self.originalMessageID = originalMessageID
|
||||
self.receiptID = receiptID
|
||||
self.readerID = readerID
|
||||
self.readerNickname = readerNickname
|
||||
self.timestamp = timestamp
|
||||
}
|
||||
|
||||
func encode() -> Data? {
|
||||
try? JSONEncoder().encode(self)
|
||||
}
|
||||
|
||||
static func decode(from data: Data) -> ReadReceipt? {
|
||||
try? JSONDecoder().decode(ReadReceipt.self, from: data)
|
||||
}
|
||||
|
||||
// MARK: - Binary Encoding
|
||||
|
||||
func toBinaryData() -> Data {
|
||||
var data = Data()
|
||||
data.appendUUID(originalMessageID)
|
||||
data.appendUUID(receiptID)
|
||||
// ReaderID as 8-byte hex string
|
||||
var readerData = Data()
|
||||
var tempID = readerID.id
|
||||
while tempID.count >= 2 && readerData.count < 8 {
|
||||
let hexByte = String(tempID.prefix(2))
|
||||
if let byte = UInt8(hexByte, radix: 16) {
|
||||
readerData.append(byte)
|
||||
}
|
||||
tempID = String(tempID.dropFirst(2))
|
||||
}
|
||||
while readerData.count < 8 {
|
||||
readerData.append(0)
|
||||
}
|
||||
data.append(readerData)
|
||||
data.appendDate(timestamp)
|
||||
data.appendString(readerNickname)
|
||||
return data
|
||||
}
|
||||
|
||||
static func fromBinaryData(_ data: Data) -> ReadReceipt? {
|
||||
// Create defensive copy
|
||||
let dataCopy = Data(data)
|
||||
|
||||
// Minimum size: 2 UUIDs (32) + readerID (8) + timestamp (8) + min nickname
|
||||
guard dataCopy.count >= 49 else { return nil }
|
||||
|
||||
var offset = 0
|
||||
|
||||
guard let originalMessageID = dataCopy.readUUID(at: &offset),
|
||||
let receiptID = dataCopy.readUUID(at: &offset) else { return nil }
|
||||
|
||||
guard let readerIDData = dataCopy.readFixedBytes(at: &offset, count: 8) else { return nil }
|
||||
let readerID = PeerID(hexData: readerIDData)
|
||||
guard readerID.isValid else { return nil }
|
||||
|
||||
guard let timestamp = dataCopy.readDate(at: &offset),
|
||||
InputValidator.validateTimestamp(timestamp),
|
||||
let readerNicknameRaw = dataCopy.readString(at: &offset),
|
||||
let readerNickname = InputValidator.validateNickname(readerNicknameRaw) else { return nil }
|
||||
|
||||
return ReadReceipt(originalMessageID: originalMessageID,
|
||||
receiptID: receiptID,
|
||||
readerID: readerID,
|
||||
readerNickname: readerNickname,
|
||||
timestamp: timestamp)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
import Foundation
|
||||
|
||||
// REQUEST_SYNC payload TLV (type, length16, value)
|
||||
// - 0x01: P (uint8) — Golomb-Rice parameter
|
||||
// - 0x02: M (uint32, big-endian) — hash range (N * 2^P)
|
||||
// - 0x03: data (opaque) — GR bitstream bytes (MSB-first)
|
||||
struct RequestSyncPacket {
|
||||
let p: Int
|
||||
let m: UInt32
|
||||
let data: Data
|
||||
let types: SyncTypeFlags?
|
||||
let sinceTimestamp: UInt64?
|
||||
let fragmentIdFilter: String?
|
||||
|
||||
init(p: Int, m: UInt32, data: Data, types: SyncTypeFlags? = nil, sinceTimestamp: UInt64? = nil, fragmentIdFilter: String? = nil) {
|
||||
self.p = p
|
||||
self.m = m
|
||||
self.data = data
|
||||
self.types = types
|
||||
self.sinceTimestamp = sinceTimestamp
|
||||
self.fragmentIdFilter = fragmentIdFilter
|
||||
}
|
||||
|
||||
func encode() -> Data {
|
||||
var out = Data()
|
||||
func putTLV(_ t: UInt8, _ v: Data) {
|
||||
out.append(t)
|
||||
let len = UInt16(v.count)
|
||||
out.append(UInt8((len >> 8) & 0xFF))
|
||||
out.append(UInt8(len & 0xFF))
|
||||
out.append(v)
|
||||
}
|
||||
// P
|
||||
putTLV(0x01, Data([UInt8(p & 0xFF)]))
|
||||
// M (uint32)
|
||||
var mBE = m.bigEndian
|
||||
putTLV(0x02, withUnsafeBytes(of: &mBE) { Data($0) })
|
||||
// data
|
||||
putTLV(0x03, data)
|
||||
if let typesData = types?.toData() {
|
||||
putTLV(0x04, typesData)
|
||||
}
|
||||
if let ts = sinceTimestamp {
|
||||
var tsBE = ts.bigEndian
|
||||
putTLV(0x05, withUnsafeBytes(of: &tsBE) { Data($0) })
|
||||
}
|
||||
if let fid = fragmentIdFilter, let fidData = fid.data(using: .utf8) {
|
||||
putTLV(0x06, fidData)
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
static func decode(from data: Data, maxAcceptBytes: Int = 1024) -> RequestSyncPacket? {
|
||||
var off = 0
|
||||
var p: Int? = nil
|
||||
var m: UInt32? = nil
|
||||
var payload: Data? = nil
|
||||
var types: SyncTypeFlags? = nil
|
||||
var sinceTimestamp: UInt64? = nil
|
||||
var fragmentIdFilter: String? = nil
|
||||
|
||||
while off + 3 <= data.count {
|
||||
let t = Int(data[off]); off += 1
|
||||
guard off + 2 <= data.count else { return nil }
|
||||
let len = (Int(data[off]) << 8) | Int(data[off+1]); off += 2
|
||||
guard off + len <= data.count else { return nil }
|
||||
let v = data.subdata(in: off..<(off+len)); off += len
|
||||
switch t {
|
||||
case 0x01:
|
||||
if v.count == 1 { p = Int(v[0]) }
|
||||
case 0x02:
|
||||
if v.count == 4 {
|
||||
var mm: UInt32 = 0
|
||||
for b in v { mm = (mm << 8) | UInt32(b) }
|
||||
m = mm
|
||||
}
|
||||
case 0x03:
|
||||
if v.count > maxAcceptBytes { return nil }
|
||||
payload = v
|
||||
case 0x04:
|
||||
if let decoded = SyncTypeFlags.decode(v) {
|
||||
types = decoded
|
||||
}
|
||||
case 0x05:
|
||||
if v.count == 8 {
|
||||
var ts: UInt64 = 0
|
||||
for b in v { ts = (ts << 8) | UInt64(b) }
|
||||
sinceTimestamp = ts
|
||||
}
|
||||
case 0x06:
|
||||
if let fid = String(data: v, encoding: .utf8) {
|
||||
fragmentIdFilter = fid
|
||||
}
|
||||
default:
|
||||
break // forward compatible; ignore unknown TLVs
|
||||
}
|
||||
}
|
||||
|
||||
guard let pp = p, let mm = m, let dd = payload, pp >= 1, mm > 0 else { return nil }
|
||||
return RequestSyncPacket(p: pp, m: mm, data: dd, types: types, sinceTimestamp: sinceTimestamp, fragmentIdFilter: fragmentIdFilter)
|
||||
}
|
||||
}
|
||||
@@ -1,371 +0,0 @@
|
||||
//
|
||||
// NoiseHandshakeCoordinator.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
/// Coordinates Noise handshakes to prevent race conditions and ensure reliable encryption establishment
|
||||
class NoiseHandshakeCoordinator {
|
||||
|
||||
// MARK: - Handshake State
|
||||
|
||||
enum HandshakeState: Equatable {
|
||||
case idle
|
||||
case waitingToInitiate(since: Date)
|
||||
case initiating(attempt: Int, lastAttempt: Date)
|
||||
case responding(since: Date)
|
||||
case waitingForResponse(messagesSent: [Data], timeout: Date)
|
||||
case established(since: Date)
|
||||
case failed(reason: String, canRetry: Bool, lastAttempt: Date)
|
||||
|
||||
var isActive: Bool {
|
||||
switch self {
|
||||
case .idle, .established, .failed:
|
||||
return false
|
||||
default:
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Properties
|
||||
|
||||
private var handshakeStates: [String: HandshakeState] = [:]
|
||||
private var handshakeQueue = DispatchQueue(label: "chat.bitchat.noise.handshake", attributes: .concurrent)
|
||||
|
||||
// Configuration
|
||||
private let maxHandshakeAttempts = 3
|
||||
private let handshakeTimeout: TimeInterval = 10.0
|
||||
private let retryDelay: TimeInterval = 2.0
|
||||
private let minTimeBetweenHandshakes: TimeInterval = 1.0 // Reduced from 5.0 for faster recovery
|
||||
private let establishedSessionTTL: TimeInterval = 300.0 // 5 minutes - sessions older than this can be cleaned up
|
||||
private let maxEstablishedSessions = 50 // Limit total established sessions
|
||||
|
||||
// Track handshake messages to detect duplicates
|
||||
private var processedHandshakeMessages: Set<Data> = []
|
||||
private let messageHistoryLimit = 100
|
||||
|
||||
// MARK: - Role Determination
|
||||
|
||||
/// Deterministically determine who should initiate the handshake
|
||||
/// Lower peer ID becomes the initiator to prevent simultaneous attempts
|
||||
func determineHandshakeRole(myPeerID: String, remotePeerID: String) -> NoiseRole {
|
||||
// Use simple string comparison for deterministic ordering
|
||||
return myPeerID < remotePeerID ? .initiator : .responder
|
||||
}
|
||||
|
||||
/// Check if we should initiate handshake with a peer
|
||||
func shouldInitiateHandshake(myPeerID: String, remotePeerID: String, forceIfStale: Bool = false) -> Bool {
|
||||
return handshakeQueue.sync {
|
||||
// Check if we're already in an active handshake
|
||||
if let state = handshakeStates[remotePeerID], state.isActive {
|
||||
// Check if the handshake is stale and we should force a new one
|
||||
if forceIfStale {
|
||||
switch state {
|
||||
case .initiating(_, let lastAttempt):
|
||||
if Date().timeIntervalSince(lastAttempt) > handshakeTimeout {
|
||||
SecureLogger.log("Forcing new handshake with \(remotePeerID) - previous stuck in initiating",
|
||||
category: SecureLogger.handshake, level: .warning)
|
||||
return true
|
||||
}
|
||||
default:
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
SecureLogger.log("Already in active handshake with \(remotePeerID), state: \(state)",
|
||||
category: SecureLogger.handshake, level: .debug)
|
||||
return false
|
||||
}
|
||||
|
||||
// Check role
|
||||
let role = determineHandshakeRole(myPeerID: myPeerID, remotePeerID: remotePeerID)
|
||||
if role != .initiator {
|
||||
SecureLogger.log("Not initiator for handshake with \(remotePeerID) (my: \(myPeerID), their: \(remotePeerID))",
|
||||
category: SecureLogger.handshake, level: .debug)
|
||||
return false
|
||||
}
|
||||
|
||||
// Check if we've failed recently and can't retry yet
|
||||
if case .failed(_, let canRetry, let lastAttempt) = handshakeStates[remotePeerID] {
|
||||
if !canRetry {
|
||||
return false
|
||||
}
|
||||
if Date().timeIntervalSince(lastAttempt) < retryDelay {
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
/// Record that we're initiating a handshake
|
||||
func recordHandshakeInitiation(peerID: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
let attempt = self.getCurrentAttempt(for: peerID) + 1
|
||||
self.handshakeStates[peerID] = .initiating(attempt: attempt, lastAttempt: Date())
|
||||
SecureLogger.log("Recording handshake initiation with \(peerID), attempt \(attempt)",
|
||||
category: SecureLogger.handshake, level: .info)
|
||||
}
|
||||
}
|
||||
|
||||
/// Record that we're responding to a handshake
|
||||
func recordHandshakeResponse(peerID: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
self.handshakeStates[peerID] = .responding(since: Date())
|
||||
SecureLogger.log("Recording handshake response to \(peerID)",
|
||||
category: SecureLogger.handshake, level: .info)
|
||||
}
|
||||
}
|
||||
|
||||
/// Record successful handshake completion
|
||||
func recordHandshakeSuccess(peerID: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
self.handshakeStates[peerID] = .established(since: Date())
|
||||
SecureLogger.log("Handshake successfully established with \(peerID)",
|
||||
category: SecureLogger.handshake, level: .info)
|
||||
}
|
||||
}
|
||||
|
||||
/// Record handshake failure
|
||||
func recordHandshakeFailure(peerID: String, reason: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
let attempts = self.getCurrentAttempt(for: peerID)
|
||||
let canRetry = attempts < self.maxHandshakeAttempts
|
||||
self.handshakeStates[peerID] = .failed(reason: reason, canRetry: canRetry, lastAttempt: Date())
|
||||
SecureLogger.log("Handshake failed with \(peerID): \(reason), canRetry: \(canRetry)",
|
||||
category: SecureLogger.handshake, level: .warning)
|
||||
}
|
||||
}
|
||||
|
||||
/// Check if we should accept an incoming handshake initiation
|
||||
func shouldAcceptHandshakeInitiation(myPeerID: String, remotePeerID: String) -> Bool {
|
||||
return handshakeQueue.sync {
|
||||
// If we're already established, reject new handshakes
|
||||
if case .established = handshakeStates[remotePeerID] {
|
||||
SecureLogger.log("Rejecting handshake from \(remotePeerID) - already established",
|
||||
category: SecureLogger.handshake, level: .debug)
|
||||
return false
|
||||
}
|
||||
|
||||
let role = determineHandshakeRole(myPeerID: myPeerID, remotePeerID: remotePeerID)
|
||||
|
||||
// If we're the initiator and already initiating, this is a race condition
|
||||
if role == .initiator {
|
||||
if case .initiating = handshakeStates[remotePeerID] {
|
||||
// They shouldn't be initiating, but accept it to recover from race condition
|
||||
SecureLogger.log("Accepting handshake from \(remotePeerID) despite being initiator (race condition recovery)",
|
||||
category: SecureLogger.handshake, level: .warning)
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
// If we're the responder, we should accept
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
/// Check if this is a duplicate handshake message
|
||||
func isDuplicateHandshakeMessage(_ data: Data) -> Bool {
|
||||
return handshakeQueue.sync {
|
||||
if processedHandshakeMessages.contains(data) {
|
||||
return true
|
||||
}
|
||||
|
||||
// Add to processed messages with size limit
|
||||
if processedHandshakeMessages.count >= messageHistoryLimit {
|
||||
processedHandshakeMessages.removeAll()
|
||||
}
|
||||
processedHandshakeMessages.insert(data)
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
/// Get time to wait before next handshake attempt
|
||||
func getRetryDelay(for peerID: String) -> TimeInterval? {
|
||||
return handshakeQueue.sync {
|
||||
guard let state = handshakeStates[peerID] else { return nil }
|
||||
|
||||
switch state {
|
||||
case .failed(_, let canRetry, let lastAttempt):
|
||||
if !canRetry { return nil }
|
||||
let timeSinceFailure = Date().timeIntervalSince(lastAttempt)
|
||||
if timeSinceFailure >= retryDelay {
|
||||
return 0
|
||||
}
|
||||
return retryDelay - timeSinceFailure
|
||||
|
||||
case .initiating(_, let lastAttempt):
|
||||
let timeSinceAttempt = Date().timeIntervalSince(lastAttempt)
|
||||
if timeSinceAttempt >= minTimeBetweenHandshakes {
|
||||
return 0
|
||||
}
|
||||
return minTimeBetweenHandshakes - timeSinceAttempt
|
||||
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Reset handshake state for a peer
|
||||
func resetHandshakeState(for peerID: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
self.handshakeStates.removeValue(forKey: peerID)
|
||||
SecureLogger.log("Reset handshake state for \(peerID)",
|
||||
category: SecureLogger.handshake, level: .debug)
|
||||
}
|
||||
}
|
||||
|
||||
/// Clean up stale handshake states and old established sessions
|
||||
func cleanupStaleHandshakes(staleTimeout: TimeInterval = 30.0) -> [String] {
|
||||
return handshakeQueue.sync {
|
||||
let now = Date()
|
||||
var stalePeerIDs: [String] = []
|
||||
var establishedSessions: [(peerID: String, since: Date)] = []
|
||||
|
||||
for (peerID, state) in handshakeStates {
|
||||
var isStale = false
|
||||
|
||||
switch state {
|
||||
case .initiating(_, let lastAttempt):
|
||||
if now.timeIntervalSince(lastAttempt) > staleTimeout {
|
||||
isStale = true
|
||||
}
|
||||
case .responding(let since):
|
||||
if now.timeIntervalSince(since) > staleTimeout {
|
||||
isStale = true
|
||||
}
|
||||
case .waitingForResponse(_, let timeout):
|
||||
if now > timeout {
|
||||
isStale = true
|
||||
}
|
||||
case .established(let since):
|
||||
// Track established sessions for potential cleanup
|
||||
establishedSessions.append((peerID, since))
|
||||
// Clean up very old established sessions
|
||||
if now.timeIntervalSince(since) > establishedSessionTTL {
|
||||
isStale = true
|
||||
}
|
||||
default:
|
||||
break
|
||||
}
|
||||
|
||||
if isStale {
|
||||
stalePeerIDs.append(peerID)
|
||||
SecureLogger.log("Found stale handshake state for \(peerID): \(state)",
|
||||
category: SecureLogger.handshake, level: .warning)
|
||||
}
|
||||
}
|
||||
|
||||
// If we have too many established sessions, clean up the oldest ones
|
||||
if establishedSessions.count > maxEstablishedSessions {
|
||||
// Sort by age (oldest first)
|
||||
let sortedSessions = establishedSessions.sorted { $0.since < $1.since }
|
||||
let sessionsToRemove = sortedSessions.count - maxEstablishedSessions
|
||||
|
||||
for i in 0..<sessionsToRemove {
|
||||
let peerID = sortedSessions[i].peerID
|
||||
stalePeerIDs.append(peerID)
|
||||
SecureLogger.log("Removing old established session for \(peerID) to maintain session limit",
|
||||
category: SecureLogger.handshake, level: .info)
|
||||
}
|
||||
}
|
||||
|
||||
// Clean up stale states
|
||||
for peerID in stalePeerIDs {
|
||||
handshakeStates.removeValue(forKey: peerID)
|
||||
}
|
||||
|
||||
if !stalePeerIDs.isEmpty {
|
||||
SecureLogger.log("Cleaned up \(stalePeerIDs.count) stale handshake states",
|
||||
category: SecureLogger.handshake, level: .info)
|
||||
}
|
||||
|
||||
return stalePeerIDs
|
||||
}
|
||||
}
|
||||
|
||||
/// Get current handshake state
|
||||
func getHandshakeState(for peerID: String) -> HandshakeState {
|
||||
return handshakeQueue.sync {
|
||||
return handshakeStates[peerID] ?? .idle
|
||||
}
|
||||
}
|
||||
|
||||
/// Get current retry count for a peer
|
||||
func getRetryCount(for peerID: String) -> Int {
|
||||
return handshakeQueue.sync {
|
||||
switch handshakeStates[peerID] {
|
||||
case .initiating(let attempt, _):
|
||||
return attempt - 1 // Attempts start at 1, retries start at 0
|
||||
default:
|
||||
return 0
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Increment retry count for a peer
|
||||
func incrementRetryCount(for peerID: String) {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
let currentAttempt = self.getCurrentAttempt(for: peerID)
|
||||
self.handshakeStates[peerID] = .initiating(attempt: currentAttempt + 1, lastAttempt: Date())
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers
|
||||
|
||||
private func getCurrentAttempt(for peerID: String) -> Int {
|
||||
switch handshakeStates[peerID] {
|
||||
case .initiating(let attempt, _):
|
||||
return attempt
|
||||
case .failed(_, _, _):
|
||||
// Count previous attempts
|
||||
return 1 // Simplified for now
|
||||
default:
|
||||
return 0
|
||||
}
|
||||
}
|
||||
|
||||
/// Log current handshake states for debugging
|
||||
func logHandshakeStates() {
|
||||
handshakeQueue.sync {
|
||||
SecureLogger.log("=== Handshake States ===", category: SecureLogger.handshake, level: .debug)
|
||||
for (peerID, state) in handshakeStates {
|
||||
let stateDesc: String
|
||||
switch state {
|
||||
case .idle:
|
||||
stateDesc = "idle"
|
||||
case .waitingToInitiate(let since):
|
||||
stateDesc = "waiting to initiate (since \(since))"
|
||||
case .initiating(let attempt, let lastAttempt):
|
||||
stateDesc = "initiating (attempt \(attempt), last: \(lastAttempt))"
|
||||
case .responding(let since):
|
||||
stateDesc = "responding (since: \(since))"
|
||||
case .waitingForResponse(let messages, let timeout):
|
||||
stateDesc = "waiting for response (\(messages.count) messages, timeout: \(timeout))"
|
||||
case .established(let since):
|
||||
stateDesc = "established (since \(since))"
|
||||
case .failed(let reason, let canRetry, let lastAttempt):
|
||||
stateDesc = "failed: \(reason) (canRetry: \(canRetry), last: \(lastAttempt))"
|
||||
}
|
||||
SecureLogger.log(" \(peerID): \(stateDesc)", category: SecureLogger.handshake, level: .debug)
|
||||
}
|
||||
SecureLogger.log("========================", category: SecureLogger.handshake, level: .debug)
|
||||
}
|
||||
}
|
||||
|
||||
/// Clear all handshake states - used during panic mode
|
||||
func clearAllHandshakeStates() {
|
||||
handshakeQueue.async(flags: .barrier) {
|
||||
SecureLogger.log("Clearing all handshake states for panic mode", category: SecureLogger.handshake, level: .warning)
|
||||
self.handshakeStates.removeAll()
|
||||
self.processedHandshakeMessages.removeAll()
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,227 +0,0 @@
|
||||
//
|
||||
// NoiseSecurityConsiderations.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
|
||||
// MARK: - Security Constants
|
||||
|
||||
enum NoiseSecurityConstants {
|
||||
// Maximum message size to prevent memory exhaustion
|
||||
static let maxMessageSize = 65535 // 64KB as per Noise spec
|
||||
|
||||
// Maximum handshake message size
|
||||
static let maxHandshakeMessageSize = 2048 // 2KB to accommodate XX pattern
|
||||
|
||||
// Session timeout - sessions older than this should be renegotiated
|
||||
static let sessionTimeout: TimeInterval = 86400 // 24 hours
|
||||
|
||||
// Maximum number of messages before rekey (2^64 - 1 is the nonce limit)
|
||||
static let maxMessagesPerSession: UInt64 = 1_000_000_000 // 1 billion messages
|
||||
|
||||
// Handshake timeout - abandon incomplete handshakes
|
||||
static let handshakeTimeout: TimeInterval = 60 // 1 minute
|
||||
|
||||
// Maximum concurrent sessions per peer
|
||||
static let maxSessionsPerPeer = 3
|
||||
|
||||
// Rate limiting
|
||||
static let maxHandshakesPerMinute = 10
|
||||
static let maxMessagesPerSecond = 100
|
||||
|
||||
// Global rate limiting (across all peers)
|
||||
static let maxGlobalHandshakesPerMinute = 30
|
||||
static let maxGlobalMessagesPerSecond = 500
|
||||
}
|
||||
|
||||
// MARK: - Security Validations
|
||||
|
||||
struct NoiseSecurityValidator {
|
||||
|
||||
/// Validate message size
|
||||
static func validateMessageSize(_ data: Data) -> Bool {
|
||||
return data.count <= NoiseSecurityConstants.maxMessageSize
|
||||
}
|
||||
|
||||
/// Validate handshake message size
|
||||
static func validateHandshakeMessageSize(_ data: Data) -> Bool {
|
||||
return data.count <= NoiseSecurityConstants.maxHandshakeMessageSize
|
||||
}
|
||||
|
||||
/// Validate peer ID format
|
||||
static func validatePeerID(_ peerID: String) -> Bool {
|
||||
// Peer ID should be reasonable length and contain valid characters
|
||||
let validCharset = CharacterSet.alphanumerics.union(CharacterSet(charactersIn: "-_"))
|
||||
return peerID.count > 0 &&
|
||||
peerID.count <= 64 &&
|
||||
peerID.rangeOfCharacter(from: validCharset.inverted) == nil
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Enhanced Noise Session with Security
|
||||
|
||||
class SecureNoiseSession: NoiseSession {
|
||||
private(set) var messageCount: UInt64 = 0
|
||||
private let sessionStartTime = Date()
|
||||
private(set) var lastActivityTime = Date()
|
||||
|
||||
override func encrypt(_ plaintext: Data) throws -> Data {
|
||||
// Check session age
|
||||
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
|
||||
throw NoiseSecurityError.sessionExpired
|
||||
}
|
||||
|
||||
// Check message count
|
||||
if messageCount >= NoiseSecurityConstants.maxMessagesPerSession {
|
||||
throw NoiseSecurityError.sessionExhausted
|
||||
}
|
||||
|
||||
// Validate message size
|
||||
guard NoiseSecurityValidator.validateMessageSize(plaintext) else {
|
||||
throw NoiseSecurityError.messageTooLarge
|
||||
}
|
||||
|
||||
let encrypted = try super.encrypt(plaintext)
|
||||
messageCount += 1
|
||||
lastActivityTime = Date()
|
||||
|
||||
return encrypted
|
||||
}
|
||||
|
||||
override func decrypt(_ ciphertext: Data) throws -> Data {
|
||||
// Check session age
|
||||
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
|
||||
throw NoiseSecurityError.sessionExpired
|
||||
}
|
||||
|
||||
// Validate message size
|
||||
guard NoiseSecurityValidator.validateMessageSize(ciphertext) else {
|
||||
throw NoiseSecurityError.messageTooLarge
|
||||
}
|
||||
|
||||
let decrypted = try super.decrypt(ciphertext)
|
||||
lastActivityTime = Date()
|
||||
|
||||
return decrypted
|
||||
}
|
||||
|
||||
func needsRenegotiation() -> Bool {
|
||||
// Check if we've used more than 90% of message limit
|
||||
let messageThreshold = UInt64(Double(NoiseSecurityConstants.maxMessagesPerSession) * 0.9)
|
||||
if messageCount >= messageThreshold {
|
||||
return true
|
||||
}
|
||||
|
||||
// Check if last activity was more than 30 minutes ago
|
||||
if Date().timeIntervalSince(lastActivityTime) > NoiseSecurityConstants.sessionTimeout {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
// MARK: - Testing Support
|
||||
#if DEBUG
|
||||
func setLastActivityTimeForTesting(_ date: Date) {
|
||||
lastActivityTime = date
|
||||
}
|
||||
|
||||
func setMessageCountForTesting(_ count: UInt64) {
|
||||
messageCount = count
|
||||
}
|
||||
#endif
|
||||
}
|
||||
|
||||
// MARK: - Rate Limiter
|
||||
|
||||
class NoiseRateLimiter {
|
||||
private var handshakeTimestamps: [String: [Date]] = [:] // peerID -> timestamps
|
||||
private var messageTimestamps: [String: [Date]] = [:] // peerID -> timestamps
|
||||
|
||||
// Global rate limiting
|
||||
private var globalHandshakeTimestamps: [Date] = []
|
||||
private var globalMessageTimestamps: [Date] = []
|
||||
|
||||
private let queue = DispatchQueue(label: "chat.bitchat.noise.ratelimit", attributes: .concurrent)
|
||||
|
||||
func allowHandshake(from peerID: String) -> Bool {
|
||||
return queue.sync(flags: .barrier) {
|
||||
let now = Date()
|
||||
let oneMinuteAgo = now.addingTimeInterval(-60)
|
||||
|
||||
// Check global rate limit first
|
||||
globalHandshakeTimestamps = globalHandshakeTimestamps.filter { $0 > oneMinuteAgo }
|
||||
if globalHandshakeTimestamps.count >= NoiseSecurityConstants.maxGlobalHandshakesPerMinute {
|
||||
SecureLogger.log("Global handshake rate limit exceeded: \(globalHandshakeTimestamps.count)/\(NoiseSecurityConstants.maxGlobalHandshakesPerMinute) per minute", category: SecureLogger.security, level: .warning)
|
||||
return false
|
||||
}
|
||||
|
||||
// Check per-peer rate limit
|
||||
var timestamps = handshakeTimestamps[peerID] ?? []
|
||||
timestamps = timestamps.filter { $0 > oneMinuteAgo }
|
||||
|
||||
if timestamps.count >= NoiseSecurityConstants.maxHandshakesPerMinute {
|
||||
SecureLogger.log("Per-peer handshake rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxHandshakesPerMinute) per minute", category: SecureLogger.security, level: .warning)
|
||||
return false
|
||||
}
|
||||
|
||||
// Record new handshake
|
||||
timestamps.append(now)
|
||||
handshakeTimestamps[peerID] = timestamps
|
||||
globalHandshakeTimestamps.append(now)
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
func allowMessage(from peerID: String) -> Bool {
|
||||
return queue.sync(flags: .barrier) {
|
||||
let now = Date()
|
||||
let oneSecondAgo = now.addingTimeInterval(-1)
|
||||
|
||||
// Check global rate limit first
|
||||
globalMessageTimestamps = globalMessageTimestamps.filter { $0 > oneSecondAgo }
|
||||
if globalMessageTimestamps.count >= NoiseSecurityConstants.maxGlobalMessagesPerSecond {
|
||||
SecureLogger.log("Global message rate limit exceeded: \(globalMessageTimestamps.count)/\(NoiseSecurityConstants.maxGlobalMessagesPerSecond) per second", category: SecureLogger.security, level: .warning)
|
||||
return false
|
||||
}
|
||||
|
||||
// Check per-peer rate limit
|
||||
var timestamps = messageTimestamps[peerID] ?? []
|
||||
timestamps = timestamps.filter { $0 > oneSecondAgo }
|
||||
|
||||
if timestamps.count >= NoiseSecurityConstants.maxMessagesPerSecond {
|
||||
SecureLogger.log("Per-peer message rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxMessagesPerSecond) per second", category: SecureLogger.security, level: .warning)
|
||||
return false
|
||||
}
|
||||
|
||||
// Record new message
|
||||
timestamps.append(now)
|
||||
messageTimestamps[peerID] = timestamps
|
||||
globalMessageTimestamps.append(now)
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
||||
func reset(for peerID: String) {
|
||||
queue.async(flags: .barrier) {
|
||||
self.handshakeTimestamps.removeValue(forKey: peerID)
|
||||
self.messageTimestamps.removeValue(forKey: peerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Security Errors
|
||||
|
||||
enum NoiseSecurityError: Error {
|
||||
case sessionExpired
|
||||
case sessionExhausted
|
||||
case messageTooLarge
|
||||
case invalidPeerID
|
||||
case rateLimitExceeded
|
||||
case handshakeTimeout
|
||||
}
|
||||
@@ -1,471 +0,0 @@
|
||||
//
|
||||
// NoiseSession.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
import os.log
|
||||
|
||||
// MARK: - Noise Session State
|
||||
|
||||
enum NoiseSessionState: Equatable {
|
||||
case uninitialized
|
||||
case handshaking
|
||||
case established
|
||||
case failed(Error)
|
||||
|
||||
static func == (lhs: NoiseSessionState, rhs: NoiseSessionState) -> Bool {
|
||||
switch (lhs, rhs) {
|
||||
case (.uninitialized, .uninitialized),
|
||||
(.handshaking, .handshaking),
|
||||
(.established, .established):
|
||||
return true
|
||||
case (.failed, .failed):
|
||||
return true // We don't compare the errors
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Noise Session
|
||||
|
||||
class NoiseSession {
|
||||
let peerID: String
|
||||
let role: NoiseRole
|
||||
private var state: NoiseSessionState = .uninitialized
|
||||
private var handshakeState: NoiseHandshakeState?
|
||||
private var sendCipher: NoiseCipherState?
|
||||
private var receiveCipher: NoiseCipherState?
|
||||
|
||||
// Keys
|
||||
private let localStaticKey: Curve25519.KeyAgreement.PrivateKey
|
||||
private var remoteStaticPublicKey: Curve25519.KeyAgreement.PublicKey?
|
||||
|
||||
// Handshake messages for retransmission
|
||||
private var sentHandshakeMessages: [Data] = []
|
||||
private var handshakeHash: Data?
|
||||
|
||||
// Thread safety
|
||||
private let sessionQueue = DispatchQueue(label: "chat.bitchat.noise.session", attributes: .concurrent)
|
||||
|
||||
init(peerID: String, role: NoiseRole, localStaticKey: Curve25519.KeyAgreement.PrivateKey, remoteStaticKey: Curve25519.KeyAgreement.PublicKey? = nil) {
|
||||
self.peerID = peerID
|
||||
self.role = role
|
||||
self.localStaticKey = localStaticKey
|
||||
self.remoteStaticPublicKey = remoteStaticKey
|
||||
}
|
||||
|
||||
// MARK: - Handshake
|
||||
|
||||
func startHandshake() throws -> Data {
|
||||
return try sessionQueue.sync(flags: .barrier) {
|
||||
guard case .uninitialized = state else {
|
||||
throw NoiseSessionError.invalidState
|
||||
}
|
||||
|
||||
// For XX pattern, we don't need remote static key upfront
|
||||
handshakeState = NoiseHandshakeState(
|
||||
role: role,
|
||||
pattern: .XX,
|
||||
localStaticKey: localStaticKey,
|
||||
remoteStaticKey: nil
|
||||
)
|
||||
|
||||
state = .handshaking
|
||||
|
||||
// Only initiator writes the first message
|
||||
if role == .initiator {
|
||||
let message = try handshakeState!.writeMessage()
|
||||
sentHandshakeMessages.append(message)
|
||||
return message
|
||||
} else {
|
||||
// Responder doesn't send first message in XX pattern
|
||||
return Data()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func processHandshakeMessage(_ message: Data) throws -> Data? {
|
||||
return try sessionQueue.sync(flags: .barrier) {
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Processing handshake message, current state: \(state), role: \(role)", category: SecureLogger.noise, level: .info)
|
||||
|
||||
// Initialize handshake state if needed (for responders)
|
||||
if state == .uninitialized && role == .responder {
|
||||
handshakeState = NoiseHandshakeState(
|
||||
role: role,
|
||||
pattern: .XX,
|
||||
localStaticKey: localStaticKey,
|
||||
remoteStaticKey: nil
|
||||
)
|
||||
state = .handshaking
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Initialized handshake state for responder", category: SecureLogger.noise, level: .info)
|
||||
}
|
||||
|
||||
guard case .handshaking = state, let handshake = handshakeState else {
|
||||
throw NoiseSessionError.invalidState
|
||||
}
|
||||
|
||||
// Process incoming message
|
||||
_ = try handshake.readMessage(message)
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Read handshake message, checking if complete", category: SecureLogger.noise, level: .info)
|
||||
|
||||
// Check if handshake is complete
|
||||
if handshake.isHandshakeComplete() {
|
||||
// Get transport ciphers
|
||||
let (send, receive) = try handshake.getTransportCiphers()
|
||||
sendCipher = send
|
||||
receiveCipher = receive
|
||||
|
||||
// Store remote static key
|
||||
remoteStaticPublicKey = handshake.getRemoteStaticPublicKey()
|
||||
|
||||
// Store handshake hash for channel binding
|
||||
handshakeHash = handshake.getHandshakeHash()
|
||||
|
||||
state = .established
|
||||
handshakeState = nil // Clear handshake state
|
||||
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Handshake complete (no response needed), transitioning to established", category: SecureLogger.noise, level: .info)
|
||||
SecureLogger.logSecurityEvent(.handshakeCompleted(peerID: peerID))
|
||||
|
||||
return nil
|
||||
} else {
|
||||
// Generate response
|
||||
let response = try handshake.writeMessage()
|
||||
sentHandshakeMessages.append(response)
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Generated handshake response of size \(response.count)", category: SecureLogger.noise, level: .info)
|
||||
|
||||
// Check if handshake is complete after writing
|
||||
if handshake.isHandshakeComplete() {
|
||||
// Get transport ciphers
|
||||
let (send, receive) = try handshake.getTransportCiphers()
|
||||
sendCipher = send
|
||||
receiveCipher = receive
|
||||
|
||||
// Store remote static key
|
||||
remoteStaticPublicKey = handshake.getRemoteStaticPublicKey()
|
||||
|
||||
// Store handshake hash for channel binding
|
||||
handshakeHash = handshake.getHandshakeHash()
|
||||
|
||||
state = .established
|
||||
handshakeState = nil // Clear handshake state
|
||||
|
||||
SecureLogger.log("NoiseSession[\(peerID)]: Handshake complete after writing response, transitioning to established", category: SecureLogger.noise, level: .info)
|
||||
SecureLogger.logSecurityEvent(.handshakeCompleted(peerID: peerID))
|
||||
}
|
||||
|
||||
return response
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Transport
|
||||
|
||||
func encrypt(_ plaintext: Data) throws -> Data {
|
||||
return try sessionQueue.sync(flags: .barrier) {
|
||||
guard case .established = state, let cipher = sendCipher else {
|
||||
throw NoiseSessionError.notEstablished
|
||||
}
|
||||
|
||||
return try cipher.encrypt(plaintext: plaintext)
|
||||
}
|
||||
}
|
||||
|
||||
func decrypt(_ ciphertext: Data) throws -> Data {
|
||||
return try sessionQueue.sync(flags: .barrier) {
|
||||
guard case .established = state, let cipher = receiveCipher else {
|
||||
throw NoiseSessionError.notEstablished
|
||||
}
|
||||
|
||||
return try cipher.decrypt(ciphertext: ciphertext)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - State Management
|
||||
|
||||
func getState() -> NoiseSessionState {
|
||||
return sessionQueue.sync {
|
||||
return state
|
||||
}
|
||||
}
|
||||
|
||||
func isEstablished() -> Bool {
|
||||
return sessionQueue.sync {
|
||||
if case .established = state {
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
func getRemoteStaticPublicKey() -> Curve25519.KeyAgreement.PublicKey? {
|
||||
return sessionQueue.sync {
|
||||
return remoteStaticPublicKey
|
||||
}
|
||||
}
|
||||
|
||||
func getHandshakeHash() -> Data? {
|
||||
return sessionQueue.sync {
|
||||
return handshakeHash
|
||||
}
|
||||
}
|
||||
|
||||
func reset() {
|
||||
sessionQueue.sync(flags: .barrier) {
|
||||
let wasEstablished = state == .established
|
||||
state = .uninitialized
|
||||
handshakeState = nil
|
||||
sendCipher = nil
|
||||
receiveCipher = nil
|
||||
sentHandshakeMessages.removeAll()
|
||||
handshakeHash = nil
|
||||
|
||||
if wasEstablished {
|
||||
SecureLogger.logSecurityEvent(.sessionExpired(peerID: peerID))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Session Manager
|
||||
|
||||
class NoiseSessionManager {
|
||||
private var sessions: [String: NoiseSession] = [:]
|
||||
private let localStaticKey: Curve25519.KeyAgreement.PrivateKey
|
||||
private let managerQueue = DispatchQueue(label: "chat.bitchat.noise.manager", attributes: .concurrent)
|
||||
|
||||
// Callbacks
|
||||
var onSessionEstablished: ((String, Curve25519.KeyAgreement.PublicKey) -> Void)?
|
||||
var onSessionFailed: ((String, Error) -> Void)?
|
||||
|
||||
init(localStaticKey: Curve25519.KeyAgreement.PrivateKey) {
|
||||
self.localStaticKey = localStaticKey
|
||||
}
|
||||
|
||||
// MARK: - Session Management
|
||||
|
||||
func createSession(for peerID: String, role: NoiseRole) -> NoiseSession {
|
||||
return managerQueue.sync(flags: .barrier) {
|
||||
let session = SecureNoiseSession(
|
||||
peerID: peerID,
|
||||
role: role,
|
||||
localStaticKey: localStaticKey
|
||||
)
|
||||
sessions[peerID] = session
|
||||
return session
|
||||
}
|
||||
}
|
||||
|
||||
func getSession(for peerID: String) -> NoiseSession? {
|
||||
return managerQueue.sync {
|
||||
return sessions[peerID]
|
||||
}
|
||||
}
|
||||
|
||||
func removeSession(for peerID: String) {
|
||||
managerQueue.sync(flags: .barrier) {
|
||||
if let session = sessions[peerID], session.isEstablished() {
|
||||
SecureLogger.logSecurityEvent(.sessionExpired(peerID: peerID))
|
||||
}
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
}
|
||||
}
|
||||
|
||||
func migrateSession(from oldPeerID: String, to newPeerID: String) {
|
||||
managerQueue.sync(flags: .barrier) {
|
||||
// Check if we have a session for the old peer ID
|
||||
if let session = sessions[oldPeerID] {
|
||||
// Move the session to the new peer ID
|
||||
sessions[newPeerID] = session
|
||||
_ = sessions.removeValue(forKey: oldPeerID)
|
||||
|
||||
SecureLogger.log("Migrated Noise session from \(oldPeerID) to \(newPeerID)", category: SecureLogger.noise, level: .info)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func getEstablishedSessions() -> [String: NoiseSession] {
|
||||
return managerQueue.sync {
|
||||
return sessions.filter { $0.value.isEstablished() }
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Handshake Helpers
|
||||
|
||||
func initiateHandshake(with peerID: String) throws -> Data {
|
||||
return try managerQueue.sync(flags: .barrier) {
|
||||
// Check if we already have an established session
|
||||
if let existingSession = sessions[peerID], existingSession.isEstablished() {
|
||||
// Session already established, don't recreate
|
||||
throw NoiseSessionError.alreadyEstablished
|
||||
}
|
||||
|
||||
// Remove any existing non-established session
|
||||
if let existingSession = sessions[peerID], !existingSession.isEstablished() {
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
}
|
||||
|
||||
// Create new initiator session
|
||||
let session = SecureNoiseSession(
|
||||
peerID: peerID,
|
||||
role: .initiator,
|
||||
localStaticKey: localStaticKey
|
||||
)
|
||||
sessions[peerID] = session
|
||||
|
||||
do {
|
||||
let handshakeData = try session.startHandshake()
|
||||
return handshakeData
|
||||
} catch {
|
||||
// Clean up failed session
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
SecureLogger.logSecurityEvent(.handshakeFailed(peerID: peerID, error: error.localizedDescription), level: .error)
|
||||
throw error
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func handleIncomingHandshake(from peerID: String, message: Data) throws -> Data? {
|
||||
// Process everything within the synchronized block to prevent race conditions
|
||||
return try managerQueue.sync(flags: .barrier) {
|
||||
var shouldCreateNew = false
|
||||
var existingSession: NoiseSession? = nil
|
||||
|
||||
if let existing = sessions[peerID] {
|
||||
// If we have an established session, the peer must have cleared their session
|
||||
// for a good reason (e.g., decryption failure, restart, etc.)
|
||||
// We should accept the new handshake to re-establish encryption
|
||||
if existing.isEstablished() {
|
||||
SecureLogger.log("Accepting handshake from \(peerID) despite existing session - peer likely cleared their session",
|
||||
category: SecureLogger.session, level: .info)
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
shouldCreateNew = true
|
||||
} else {
|
||||
// If we're in the middle of a handshake and receive a new initiation,
|
||||
// reset and start fresh (the other side may have restarted)
|
||||
if existing.getState() == .handshaking && message.count == 32 {
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
shouldCreateNew = true
|
||||
} else {
|
||||
existingSession = existing
|
||||
}
|
||||
}
|
||||
} else {
|
||||
shouldCreateNew = true
|
||||
}
|
||||
|
||||
// Get or create session
|
||||
let session: NoiseSession
|
||||
if shouldCreateNew {
|
||||
let newSession = SecureNoiseSession(
|
||||
peerID: peerID,
|
||||
role: .responder,
|
||||
localStaticKey: localStaticKey
|
||||
)
|
||||
sessions[peerID] = newSession
|
||||
session = newSession
|
||||
} else {
|
||||
session = existingSession!
|
||||
}
|
||||
|
||||
// Process the handshake message within the synchronized block
|
||||
do {
|
||||
let response = try session.processHandshakeMessage(message)
|
||||
|
||||
// Check if session is established after processing
|
||||
if session.isEstablished() {
|
||||
if let remoteKey = session.getRemoteStaticPublicKey() {
|
||||
// Schedule callback outside the synchronized block to prevent deadlock
|
||||
DispatchQueue.global().async { [weak self] in
|
||||
self?.onSessionEstablished?(peerID, remoteKey)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return response
|
||||
} catch {
|
||||
// Reset the session on handshake failure so next attempt can start fresh
|
||||
_ = sessions.removeValue(forKey: peerID)
|
||||
|
||||
// Schedule callback outside the synchronized block to prevent deadlock
|
||||
DispatchQueue.global().async { [weak self] in
|
||||
self?.onSessionFailed?(peerID, error)
|
||||
}
|
||||
|
||||
SecureLogger.logSecurityEvent(.handshakeFailed(peerID: peerID, error: error.localizedDescription), level: .error)
|
||||
throw error
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Encryption/Decryption
|
||||
|
||||
func encrypt(_ plaintext: Data, for peerID: String) throws -> Data {
|
||||
guard let session = getSession(for: peerID) else {
|
||||
throw NoiseSessionError.sessionNotFound
|
||||
}
|
||||
|
||||
return try session.encrypt(plaintext)
|
||||
}
|
||||
|
||||
func decrypt(_ ciphertext: Data, from peerID: String) throws -> Data {
|
||||
guard let session = getSession(for: peerID) else {
|
||||
throw NoiseSessionError.sessionNotFound
|
||||
}
|
||||
|
||||
return try session.decrypt(ciphertext)
|
||||
}
|
||||
|
||||
// MARK: - Key Management
|
||||
|
||||
func getRemoteStaticKey(for peerID: String) -> Curve25519.KeyAgreement.PublicKey? {
|
||||
return getSession(for: peerID)?.getRemoteStaticPublicKey()
|
||||
}
|
||||
|
||||
func getHandshakeHash(for peerID: String) -> Data? {
|
||||
return getSession(for: peerID)?.getHandshakeHash()
|
||||
}
|
||||
|
||||
// MARK: - Session Rekeying
|
||||
|
||||
func getSessionsNeedingRekey() -> [(peerID: String, needsRekey: Bool)] {
|
||||
return managerQueue.sync {
|
||||
var needingRekey: [(peerID: String, needsRekey: Bool)] = []
|
||||
|
||||
for (peerID, session) in sessions {
|
||||
if let secureSession = session as? SecureNoiseSession,
|
||||
secureSession.isEstablished(),
|
||||
secureSession.needsRenegotiation() {
|
||||
needingRekey.append((peerID: peerID, needsRekey: true))
|
||||
}
|
||||
}
|
||||
|
||||
return needingRekey
|
||||
}
|
||||
}
|
||||
|
||||
func initiateRekey(for peerID: String) throws {
|
||||
// Remove old session
|
||||
removeSession(for: peerID)
|
||||
|
||||
// Initiate new handshake
|
||||
_ = try initiateHandshake(with: peerID)
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Errors
|
||||
|
||||
enum NoiseSessionError: Error {
|
||||
case invalidState
|
||||
case notEstablished
|
||||
case sessionNotFound
|
||||
case handshakeFailed(Error)
|
||||
case alreadyEstablished
|
||||
}
|
||||
@@ -0,0 +1,122 @@
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
// MARK: - BitChat-over-Nostr Adapter
|
||||
|
||||
struct NostrEmbeddedBitChat {
|
||||
/// Build a `bitchat1:` base64url-encoded BitChat packet carrying a private message for Nostr DMs.
|
||||
static func encodePMForNostr(content: String, messageID: String, recipientPeerID: PeerID, senderPeerID: PeerID) -> String? {
|
||||
// TLV-encode the private message
|
||||
let pm = PrivateMessagePacket(messageID: messageID, content: content)
|
||||
guard let tlv = pm.encode() else { return nil }
|
||||
|
||||
// Prefix with NoisePayloadType
|
||||
var payload = Data([NoisePayloadType.privateMessage.rawValue])
|
||||
payload.append(tlv)
|
||||
|
||||
// Determine 8-byte recipient ID to embed
|
||||
let recipientID = normalizeRecipientPeerID(recipientPeerID)
|
||||
|
||||
let packet = BitchatPacket(
|
||||
type: MessageType.noiseEncrypted.rawValue,
|
||||
senderID: Data(hexString: senderPeerID.id) ?? Data(),
|
||||
recipientID: Data(hexString: recipientID.id),
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
|
||||
guard let data = packet.toBinaryData() else { return nil }
|
||||
return "bitchat1:" + base64URLEncode(data)
|
||||
}
|
||||
|
||||
/// Build a `bitchat1:` base64url-encoded BitChat packet carrying a delivery/read ack for Nostr DMs.
|
||||
static func encodeAckForNostr(type: NoisePayloadType, messageID: String, recipientPeerID: PeerID, senderPeerID: PeerID) -> String? {
|
||||
guard type == .delivered || type == .readReceipt else { return nil }
|
||||
|
||||
var payload = Data([type.rawValue])
|
||||
payload.append(Data(messageID.utf8))
|
||||
|
||||
let recipientID = normalizeRecipientPeerID(recipientPeerID)
|
||||
|
||||
let packet = BitchatPacket(
|
||||
type: MessageType.noiseEncrypted.rawValue,
|
||||
senderID: Data(hexString: senderPeerID.id) ?? Data(),
|
||||
recipientID: Data(hexString: recipientID.id),
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
|
||||
guard let data = packet.toBinaryData() else { return nil }
|
||||
return "bitchat1:" + base64URLEncode(data)
|
||||
}
|
||||
|
||||
/// Build a `bitchat1:` ACK (delivered/read) without an embedded recipient peer ID (geohash DMs).
|
||||
static func encodeAckForNostrNoRecipient(type: NoisePayloadType, messageID: String, senderPeerID: PeerID) -> String? {
|
||||
guard type == .delivered || type == .readReceipt else { return nil }
|
||||
|
||||
var payload = Data([type.rawValue])
|
||||
payload.append(Data(messageID.utf8))
|
||||
|
||||
let packet = BitchatPacket(
|
||||
type: MessageType.noiseEncrypted.rawValue,
|
||||
senderID: Data(hexString: senderPeerID.id) ?? Data(),
|
||||
recipientID: nil,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
|
||||
guard let data = packet.toBinaryData() else { return nil }
|
||||
return "bitchat1:" + base64URLEncode(data)
|
||||
}
|
||||
|
||||
/// Build a `bitchat1:` payload without an embedded recipient peer ID (used for geohash DMs).
|
||||
static func encodePMForNostrNoRecipient(content: String, messageID: String, senderPeerID: PeerID) -> String? {
|
||||
let pm = PrivateMessagePacket(messageID: messageID, content: content)
|
||||
guard let tlv = pm.encode() else { return nil }
|
||||
|
||||
var payload = Data([NoisePayloadType.privateMessage.rawValue])
|
||||
payload.append(tlv)
|
||||
|
||||
let packet = BitchatPacket(
|
||||
type: MessageType.noiseEncrypted.rawValue,
|
||||
senderID: Data(hexString: senderPeerID.id) ?? Data(),
|
||||
recipientID: nil,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
|
||||
guard let data = packet.toBinaryData() else { return nil }
|
||||
return "bitchat1:" + base64URLEncode(data)
|
||||
}
|
||||
|
||||
private static func normalizeRecipientPeerID(_ recipientPeerID: PeerID) -> PeerID {
|
||||
if let maybeData = Data(hexString: recipientPeerID.id) {
|
||||
if maybeData.count == 32 {
|
||||
// Treat as Noise static public key; derive peerID from fingerprint
|
||||
return PeerID(publicKey: maybeData)
|
||||
} else if maybeData.count == 8 {
|
||||
// Already an 8-byte peer ID
|
||||
return recipientPeerID
|
||||
}
|
||||
}
|
||||
// Fallback: return as-is (expecting 16 hex chars) – caller should pass a valid peer ID
|
||||
return recipientPeerID
|
||||
}
|
||||
|
||||
/// Base64url encode without padding
|
||||
private static func base64URLEncode(_ data: Data) -> String {
|
||||
let b64 = data.base64EncodedString()
|
||||
return b64
|
||||
.replacingOccurrences(of: "+", with: "-")
|
||||
.replacingOccurrences(of: "/", with: "_")
|
||||
.replacingOccurrences(of: "=", with: "")
|
||||
}
|
||||
}
|
||||
@@ -1,265 +0,0 @@
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
import P256K
|
||||
|
||||
// Keychain helper for secure storage
|
||||
struct KeychainHelper {
|
||||
static func save(key: String, data: Data, service: String) {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecValueData as String: data
|
||||
]
|
||||
|
||||
SecItemDelete(query as CFDictionary)
|
||||
SecItemAdd(query as CFDictionary, nil)
|
||||
}
|
||||
|
||||
static func load(key: String, service: String) -> Data? {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecReturnData as String: true
|
||||
]
|
||||
|
||||
var result: AnyObject?
|
||||
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
||||
|
||||
guard status == errSecSuccess else { return nil }
|
||||
return result as? Data
|
||||
}
|
||||
|
||||
static func delete(key: String, service: String) {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: key
|
||||
]
|
||||
|
||||
SecItemDelete(query as CFDictionary)
|
||||
}
|
||||
}
|
||||
|
||||
/// Manages Nostr identity (secp256k1 keypair) for NIP-17 private messaging
|
||||
struct NostrIdentity: Codable {
|
||||
let privateKey: Data
|
||||
let publicKey: Data
|
||||
let npub: String // Bech32-encoded public key
|
||||
let createdAt: Date
|
||||
|
||||
/// Memberwise initializer
|
||||
init(privateKey: Data, publicKey: Data, npub: String, createdAt: Date) {
|
||||
self.privateKey = privateKey
|
||||
self.publicKey = publicKey
|
||||
self.npub = npub
|
||||
self.createdAt = createdAt
|
||||
}
|
||||
|
||||
/// Generate a new Nostr identity
|
||||
static func generate() throws -> NostrIdentity {
|
||||
// Generate Schnorr key for Nostr
|
||||
let schnorrKey = try P256K.Schnorr.PrivateKey()
|
||||
let xOnlyPubkey = Data(schnorrKey.xonly.bytes)
|
||||
let npub = try Bech32.encode(hrp: "npub", data: xOnlyPubkey)
|
||||
|
||||
return NostrIdentity(
|
||||
privateKey: schnorrKey.dataRepresentation,
|
||||
publicKey: xOnlyPubkey, // Store x-only public key
|
||||
npub: npub,
|
||||
createdAt: Date()
|
||||
)
|
||||
}
|
||||
|
||||
/// Initialize from existing private key data
|
||||
init(privateKeyData: Data) throws {
|
||||
let schnorrKey = try P256K.Schnorr.PrivateKey(dataRepresentation: privateKeyData)
|
||||
let xOnlyPubkey = Data(schnorrKey.xonly.bytes)
|
||||
|
||||
self.privateKey = privateKeyData
|
||||
self.publicKey = xOnlyPubkey
|
||||
self.npub = try Bech32.encode(hrp: "npub", data: xOnlyPubkey)
|
||||
self.createdAt = Date()
|
||||
}
|
||||
|
||||
/// Get signing key for event signatures
|
||||
func signingKey() throws -> P256K.Signing.PrivateKey {
|
||||
try P256K.Signing.PrivateKey(dataRepresentation: privateKey)
|
||||
}
|
||||
|
||||
/// Get Schnorr signing key for Nostr event signatures
|
||||
func schnorrSigningKey() throws -> P256K.Schnorr.PrivateKey {
|
||||
try P256K.Schnorr.PrivateKey(dataRepresentation: privateKey)
|
||||
}
|
||||
|
||||
/// Get hex-encoded public key (for Nostr events)
|
||||
var publicKeyHex: String {
|
||||
// Public key is already stored as x-only (32 bytes)
|
||||
return publicKey.hexEncodedString()
|
||||
}
|
||||
}
|
||||
|
||||
/// Bridge between Noise and Nostr identities
|
||||
struct NostrIdentityBridge {
|
||||
private static let keychainService = "chat.bitchat.nostr"
|
||||
private static let currentIdentityKey = "nostr-current-identity"
|
||||
|
||||
/// Get or create the current Nostr identity
|
||||
static func getCurrentNostrIdentity() throws -> NostrIdentity? {
|
||||
// Check if we already have a Nostr identity
|
||||
if let existingData = KeychainHelper.load(key: currentIdentityKey, service: keychainService),
|
||||
let identity = try? JSONDecoder().decode(NostrIdentity.self, from: existingData) {
|
||||
return identity
|
||||
}
|
||||
|
||||
// Generate new Nostr identity
|
||||
let nostrIdentity = try NostrIdentity.generate()
|
||||
|
||||
// Store it
|
||||
let data = try JSONEncoder().encode(nostrIdentity)
|
||||
KeychainHelper.save(key: currentIdentityKey, data: data, service: keychainService)
|
||||
|
||||
return nostrIdentity
|
||||
}
|
||||
|
||||
/// Associate a Nostr identity with a Noise public key (for favorites)
|
||||
static func associateNostrIdentity(_ nostrPubkey: String, with noisePublicKey: Data) {
|
||||
let key = "nostr-noise-\(noisePublicKey.base64EncodedString())"
|
||||
if let data = nostrPubkey.data(using: .utf8) {
|
||||
KeychainHelper.save(key: key, data: data, service: keychainService)
|
||||
}
|
||||
}
|
||||
|
||||
/// Get Nostr public key associated with a Noise public key
|
||||
static func getNostrPublicKey(for noisePublicKey: Data) -> String? {
|
||||
let key = "nostr-noise-\(noisePublicKey.base64EncodedString())"
|
||||
guard let data = KeychainHelper.load(key: key, service: keychainService),
|
||||
let pubkey = String(data: data, encoding: .utf8) else {
|
||||
return nil
|
||||
}
|
||||
return pubkey
|
||||
}
|
||||
}
|
||||
|
||||
// Bech32 encoding for Nostr (minimal implementation)
|
||||
enum Bech32 {
|
||||
private static let charset = "qpzry9x8gf2tvdw0s3jn54khce6mua7l"
|
||||
private static let generator = [0x3b6a57b2, 0x26508e6d, 0x1ea119fa, 0x3d4233dd, 0x2a1462b3]
|
||||
|
||||
static func encode(hrp: String, data: Data) throws -> String {
|
||||
let values = convertBits(from: 8, to: 5, pad: true, data: Array(data))
|
||||
let checksum = createChecksum(hrp: hrp, values: values)
|
||||
let combined = values + checksum
|
||||
|
||||
return hrp + "1" + combined.map {
|
||||
let index = charset.index(charset.startIndex, offsetBy: Int($0))
|
||||
return String(charset[index])
|
||||
}.joined()
|
||||
}
|
||||
|
||||
static func decode(_ bech32String: String) throws -> (hrp: String, data: Data) {
|
||||
// Find the last occurrence of '1'
|
||||
guard let separatorIndex = bech32String.lastIndex(of: "1") else {
|
||||
throw Bech32Error.invalidFormat
|
||||
}
|
||||
|
||||
let hrp = String(bech32String[..<separatorIndex])
|
||||
let dataString = String(bech32String[bech32String.index(after: separatorIndex)...])
|
||||
|
||||
// Convert characters to values
|
||||
var values = [UInt8]()
|
||||
for char in dataString {
|
||||
guard let index = charset.firstIndex(of: char) else {
|
||||
throw Bech32Error.invalidCharacter
|
||||
}
|
||||
values.append(UInt8(charset.distance(from: charset.startIndex, to: index)))
|
||||
}
|
||||
|
||||
// Verify checksum
|
||||
guard values.count >= 6 else {
|
||||
throw Bech32Error.invalidChecksum
|
||||
}
|
||||
|
||||
let payloadValues = Array(values.dropLast(6))
|
||||
let checksum = Array(values.suffix(6))
|
||||
let expectedChecksum = createChecksum(hrp: hrp, values: payloadValues)
|
||||
|
||||
guard checksum == expectedChecksum else {
|
||||
throw Bech32Error.invalidChecksum
|
||||
}
|
||||
|
||||
// Convert back to bytes
|
||||
let bytes = convertBits(from: 5, to: 8, pad: false, data: payloadValues)
|
||||
return (hrp: hrp, data: Data(bytes))
|
||||
}
|
||||
|
||||
enum Bech32Error: Error {
|
||||
case invalidFormat
|
||||
case invalidCharacter
|
||||
case invalidChecksum
|
||||
}
|
||||
|
||||
private static func convertBits(from: Int, to: Int, pad: Bool, data: [UInt8]) -> [UInt8] {
|
||||
var acc = 0
|
||||
var bits = 0
|
||||
var result = [UInt8]()
|
||||
let maxv = (1 << to) - 1
|
||||
|
||||
for value in data {
|
||||
acc = (acc << from) | Int(value)
|
||||
bits += from
|
||||
|
||||
while bits >= to {
|
||||
bits -= to
|
||||
result.append(UInt8((acc >> bits) & maxv))
|
||||
}
|
||||
}
|
||||
|
||||
if pad && bits > 0 {
|
||||
result.append(UInt8((acc << (to - bits)) & maxv))
|
||||
}
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
private static func createChecksum(hrp: String, values: [UInt8]) -> [UInt8] {
|
||||
let checksumValues = hrpExpand(hrp) + values + [0, 0, 0, 0, 0, 0]
|
||||
let polymod = polymod(checksumValues) ^ 1
|
||||
var checksum = [UInt8]()
|
||||
|
||||
for i in 0..<6 {
|
||||
checksum.append(UInt8((polymod >> (5 * (5 - i))) & 31))
|
||||
}
|
||||
|
||||
return checksum
|
||||
}
|
||||
|
||||
private static func hrpExpand(_ hrp: String) -> [UInt8] {
|
||||
var result = [UInt8]()
|
||||
for c in hrp {
|
||||
result.append(UInt8(c.asciiValue! >> 5))
|
||||
}
|
||||
result.append(0)
|
||||
for c in hrp {
|
||||
result.append(UInt8(c.asciiValue! & 31))
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
private static func polymod(_ values: [UInt8]) -> Int {
|
||||
var chk = 1
|
||||
for value in values {
|
||||
let b = chk >> 25
|
||||
chk = (chk & 0x1ffffff) << 5 ^ Int(value)
|
||||
for i in 0..<5 {
|
||||
if (b >> i) & 1 == 1 {
|
||||
chk ^= generator[i]
|
||||
}
|
||||
}
|
||||
}
|
||||
return chk
|
||||
}
|
||||
}
|
||||
|
||||
// Data hex encoding extension moved to BinaryEncodingUtils.swift to avoid duplication
|
||||
@@ -0,0 +1,118 @@
|
||||
import Nostr
|
||||
import Combine
|
||||
import Foundation
|
||||
import Tor
|
||||
#if os(iOS)
|
||||
import UIKit
|
||||
#elseif os(macOS)
|
||||
import AppKit
|
||||
#endif
|
||||
|
||||
// MARK: - GeoRelayDirectory Live Dependencies
|
||||
|
||||
extension GeoRelayDirectoryDependencies {
|
||||
@MainActor
|
||||
static func live() -> Self {
|
||||
#if os(iOS)
|
||||
let activeNotificationName: Notification.Name? = UIApplication.didBecomeActiveNotification
|
||||
#elseif os(macOS)
|
||||
let activeNotificationName: Notification.Name? = NSApplication.didBecomeActiveNotification
|
||||
#else
|
||||
let activeNotificationName: Notification.Name? = nil
|
||||
#endif
|
||||
|
||||
return Self(
|
||||
userDefaults: .standard,
|
||||
notificationCenter: .default,
|
||||
now: Date.init,
|
||||
remoteURL: URL(string: "https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv")!,
|
||||
fetchInterval: TransportConfig.geoRelayFetchIntervalSeconds,
|
||||
refreshCheckInterval: TransportConfig.geoRelayRefreshCheckIntervalSeconds,
|
||||
retryInitialSeconds: TransportConfig.geoRelayRetryInitialSeconds,
|
||||
retryMaxSeconds: TransportConfig.geoRelayRetryMaxSeconds,
|
||||
awaitTorReady: { await TorManager.shared.awaitReady() },
|
||||
makeFetchData: {
|
||||
let session = TorURLSession.shared.session
|
||||
return { request in
|
||||
let (data, _) = try await session.data(for: request)
|
||||
return data
|
||||
}
|
||||
},
|
||||
readData: { try? Data(contentsOf: $0) },
|
||||
writeData: { data, url in
|
||||
try data.write(to: url, options: .atomic)
|
||||
},
|
||||
cacheURL: {
|
||||
do {
|
||||
let base = try FileManager.default.url(
|
||||
for: .applicationSupportDirectory,
|
||||
in: .userDomainMask,
|
||||
appropriateFor: nil,
|
||||
create: true
|
||||
)
|
||||
let dir = base.appendingPathComponent("bitchat", isDirectory: true)
|
||||
try? FileManager.default.createDirectory(at: dir, withIntermediateDirectories: true)
|
||||
return dir.appendingPathComponent("georelays_cache.csv")
|
||||
} catch {
|
||||
return nil
|
||||
}
|
||||
},
|
||||
bundledCSVURLs: {
|
||||
[
|
||||
Bundle.main.url(forResource: "nostr_relays", withExtension: "csv"),
|
||||
Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv"),
|
||||
Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv", subdirectory: "relays")
|
||||
].compactMap { $0 }
|
||||
},
|
||||
currentDirectoryPath: { FileManager.default.currentDirectoryPath },
|
||||
retrySleep: { delay in
|
||||
let nanoseconds = UInt64(delay * 1_000_000_000)
|
||||
try? await Task.sleep(nanoseconds: nanoseconds)
|
||||
},
|
||||
torReadyNotificationName: .TorDidBecomeReady,
|
||||
activeNotificationName: activeNotificationName,
|
||||
autoStart: true
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - NostrRelayManager Live Dependencies
|
||||
|
||||
extension NostrRelayManagerDependencies {
|
||||
@MainActor
|
||||
static func live() -> Self {
|
||||
Self(
|
||||
activationAllowed: { NetworkActivationService.shared.activationAllowed },
|
||||
userTorEnabled: { NetworkActivationService.shared.userTorEnabled },
|
||||
hasMutualFavorites: { !FavoritesPersistenceService.shared.mutualFavorites.isEmpty },
|
||||
hasLocationPermission: { LocationChannelManager.shared.permissionState == .authorized },
|
||||
mutualFavoritesPublisher: FavoritesPersistenceService.shared.$mutualFavorites.eraseToAnyPublisher(),
|
||||
locationPermissionPublisher: LocationChannelManager.shared.$permissionState
|
||||
.map { state -> LocationPermissionState in
|
||||
switch state {
|
||||
case .notDetermined:.notDetermined
|
||||
case .authorized: .authorized
|
||||
case .denied: .denied
|
||||
case .restricted: .denied
|
||||
}
|
||||
}
|
||||
.eraseToAnyPublisher(),
|
||||
torEnforced: { TorManager.shared.torEnforced },
|
||||
torIsReady: { TorManager.shared.isReady },
|
||||
torIsForeground: { TorManager.shared.isForeground() },
|
||||
awaitTorReady: { completion in
|
||||
Task.detached {
|
||||
let ready = await TorManager.shared.awaitReady()
|
||||
await MainActor.run {
|
||||
completion(ready)
|
||||
}
|
||||
}
|
||||
},
|
||||
makeSession: { NostrRelayManager.makeURLSession(TorURLSession.shared.session) },
|
||||
scheduleAfter: { delay, action in
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + delay, execute: action)
|
||||
},
|
||||
now: Date.init
|
||||
)
|
||||
}
|
||||
}
|
||||
@@ -1,560 +0,0 @@
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
import P256K
|
||||
|
||||
// Note: This file depends on Data extension from BinaryEncodingUtils.swift
|
||||
// Make sure BinaryEncodingUtils.swift is included in the target
|
||||
|
||||
/// NIP-17 Protocol Implementation for Private Direct Messages
|
||||
struct NostrProtocol {
|
||||
|
||||
/// Nostr event kinds
|
||||
enum EventKind: Int {
|
||||
case metadata = 0
|
||||
case textNote = 1
|
||||
case seal = 13 // NIP-17 sealed event
|
||||
case giftWrap = 1059 // NIP-17 gift wrap
|
||||
case ephemeralEvent = 20000
|
||||
}
|
||||
|
||||
/// Create a NIP-17 private message
|
||||
static func createPrivateMessage(
|
||||
content: String,
|
||||
recipientPubkey: String,
|
||||
senderIdentity: NostrIdentity
|
||||
) throws -> NostrEvent {
|
||||
|
||||
// Creating private message
|
||||
|
||||
// 1. Create the rumor (unsigned event)
|
||||
let rumor = NostrEvent(
|
||||
pubkey: senderIdentity.publicKeyHex,
|
||||
createdAt: Date(),
|
||||
kind: .textNote,
|
||||
tags: [],
|
||||
content: content
|
||||
)
|
||||
|
||||
// 2. Create ephemeral key for this message
|
||||
let ephemeralKey = try P256K.Schnorr.PrivateKey()
|
||||
let _ = Data(ephemeralKey.xonly.bytes).hexEncodedString()
|
||||
// Created ephemeral key for seal
|
||||
|
||||
// 3. Seal the rumor (encrypt to recipient)
|
||||
let sealedEvent = try createSeal(
|
||||
rumor: rumor,
|
||||
recipientPubkey: recipientPubkey,
|
||||
senderKey: ephemeralKey
|
||||
)
|
||||
|
||||
// 4. Gift wrap the sealed event (encrypt to recipient again)
|
||||
let giftWrap = try createGiftWrap(
|
||||
seal: sealedEvent,
|
||||
recipientPubkey: recipientPubkey,
|
||||
senderKey: ephemeralKey
|
||||
)
|
||||
|
||||
// Created gift wrap
|
||||
|
||||
return giftWrap
|
||||
}
|
||||
|
||||
/// Decrypt a received NIP-17 message
|
||||
static func decryptPrivateMessage(
|
||||
giftWrap: NostrEvent,
|
||||
recipientIdentity: NostrIdentity
|
||||
) throws -> (content: String, senderPubkey: String) {
|
||||
|
||||
// Starting decryption
|
||||
|
||||
// 1. Unwrap the gift wrap
|
||||
let seal: NostrEvent
|
||||
do {
|
||||
seal = try unwrapGiftWrap(
|
||||
giftWrap: giftWrap,
|
||||
recipientKey: recipientIdentity.schnorrSigningKey()
|
||||
)
|
||||
// Successfully unwrapped gift wrap
|
||||
} catch {
|
||||
SecureLogger.log("❌ Failed to unwrap gift wrap: \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw error
|
||||
}
|
||||
|
||||
// 2. Open the seal
|
||||
let rumor: NostrEvent
|
||||
do {
|
||||
rumor = try openSeal(
|
||||
seal: seal,
|
||||
recipientKey: recipientIdentity.schnorrSigningKey()
|
||||
)
|
||||
// Successfully opened seal
|
||||
} catch {
|
||||
SecureLogger.log("❌ Failed to open seal: \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw error
|
||||
}
|
||||
|
||||
return (content: rumor.content, senderPubkey: rumor.pubkey)
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private static func createSeal(
|
||||
rumor: NostrEvent,
|
||||
recipientPubkey: String,
|
||||
senderKey: P256K.Schnorr.PrivateKey
|
||||
) throws -> NostrEvent {
|
||||
|
||||
let rumorJSON = try rumor.jsonString()
|
||||
let encrypted = try encrypt(
|
||||
plaintext: rumorJSON,
|
||||
recipientPubkey: recipientPubkey,
|
||||
senderKey: senderKey
|
||||
)
|
||||
|
||||
let seal = NostrEvent(
|
||||
pubkey: Data(senderKey.xonly.bytes).hexEncodedString(),
|
||||
createdAt: randomizedTimestamp(),
|
||||
kind: .seal,
|
||||
tags: [],
|
||||
content: encrypted
|
||||
)
|
||||
|
||||
// Convert to P256K.Signing.PrivateKey for signing (temporary until we update sign method)
|
||||
let signingKey = try P256K.Signing.PrivateKey(dataRepresentation: senderKey.dataRepresentation)
|
||||
return try seal.sign(with: signingKey)
|
||||
}
|
||||
|
||||
private static func createGiftWrap(
|
||||
seal: NostrEvent,
|
||||
recipientPubkey: String,
|
||||
senderKey: P256K.Schnorr.PrivateKey // This is the ephemeral key used for the seal
|
||||
) throws -> NostrEvent {
|
||||
|
||||
let sealJSON = try seal.jsonString()
|
||||
|
||||
// Create new ephemeral key for gift wrap
|
||||
let wrapKey = try P256K.Schnorr.PrivateKey()
|
||||
// Creating gift wrap with ephemeral key
|
||||
|
||||
// Encrypt the seal with the new ephemeral key (not the seal's key)
|
||||
let encrypted = try encrypt(
|
||||
plaintext: sealJSON,
|
||||
recipientPubkey: recipientPubkey,
|
||||
senderKey: wrapKey // Use the gift wrap ephemeral key
|
||||
)
|
||||
|
||||
let giftWrap = NostrEvent(
|
||||
pubkey: Data(wrapKey.xonly.bytes).hexEncodedString(),
|
||||
createdAt: randomizedTimestamp(),
|
||||
kind: .giftWrap,
|
||||
tags: [["p", recipientPubkey]], // Tag recipient
|
||||
content: encrypted
|
||||
)
|
||||
|
||||
// Convert to P256K.Signing.PrivateKey for signing (temporary until we update sign method)
|
||||
let signingKey = try P256K.Signing.PrivateKey(dataRepresentation: wrapKey.dataRepresentation)
|
||||
return try giftWrap.sign(with: signingKey)
|
||||
}
|
||||
|
||||
private static func unwrapGiftWrap(
|
||||
giftWrap: NostrEvent,
|
||||
recipientKey: P256K.Schnorr.PrivateKey
|
||||
) throws -> NostrEvent {
|
||||
|
||||
// Unwrapping gift wrap
|
||||
|
||||
let decrypted = try decrypt(
|
||||
ciphertext: giftWrap.content,
|
||||
senderPubkey: giftWrap.pubkey,
|
||||
recipientKey: recipientKey
|
||||
)
|
||||
|
||||
guard let data = decrypted.data(using: .utf8),
|
||||
let sealDict = try JSONSerialization.jsonObject(with: data) as? [String: Any] else {
|
||||
throw NostrError.invalidEvent
|
||||
}
|
||||
|
||||
let seal = try NostrEvent(from: sealDict)
|
||||
// Unwrapped seal
|
||||
|
||||
return seal
|
||||
}
|
||||
|
||||
private static func openSeal(
|
||||
seal: NostrEvent,
|
||||
recipientKey: P256K.Schnorr.PrivateKey
|
||||
) throws -> NostrEvent {
|
||||
|
||||
let decrypted = try decrypt(
|
||||
ciphertext: seal.content,
|
||||
senderPubkey: seal.pubkey,
|
||||
recipientKey: recipientKey
|
||||
)
|
||||
|
||||
guard let data = decrypted.data(using: .utf8),
|
||||
let rumorDict = try JSONSerialization.jsonObject(with: data) as? [String: Any] else {
|
||||
throw NostrError.invalidEvent
|
||||
}
|
||||
|
||||
return try NostrEvent(from: rumorDict)
|
||||
}
|
||||
|
||||
// MARK: - Encryption (NIP-44 style)
|
||||
|
||||
private static func encrypt(
|
||||
plaintext: String,
|
||||
recipientPubkey: String,
|
||||
senderKey: P256K.Schnorr.PrivateKey
|
||||
) throws -> String {
|
||||
|
||||
guard let recipientPubkeyData = Data(hexString: recipientPubkey) else {
|
||||
throw NostrError.invalidPublicKey
|
||||
}
|
||||
|
||||
let _ = Data(senderKey.xonly.bytes).hexEncodedString()
|
||||
// Encrypting message
|
||||
|
||||
// Derive shared secret
|
||||
let sharedSecret = try deriveSharedSecret(
|
||||
privateKey: senderKey,
|
||||
publicKey: recipientPubkeyData
|
||||
)
|
||||
|
||||
// Derived shared secret
|
||||
|
||||
// Generate nonce
|
||||
let nonce = AES.GCM.Nonce()
|
||||
|
||||
// Encrypt
|
||||
let sealed = try AES.GCM.seal(
|
||||
plaintext.data(using: .utf8)!,
|
||||
using: SymmetricKey(data: sharedSecret),
|
||||
nonce: nonce
|
||||
)
|
||||
|
||||
// Combine nonce + ciphertext + tag
|
||||
var result = Data()
|
||||
result.append(nonce.withUnsafeBytes { Data($0) })
|
||||
result.append(sealed.ciphertext)
|
||||
result.append(sealed.tag)
|
||||
|
||||
return result.base64EncodedString()
|
||||
}
|
||||
|
||||
private static func decrypt(
|
||||
ciphertext: String,
|
||||
senderPubkey: String,
|
||||
recipientKey: P256K.Schnorr.PrivateKey
|
||||
) throws -> String {
|
||||
|
||||
// Decrypting message
|
||||
|
||||
guard let data = Data(base64Encoded: ciphertext),
|
||||
let senderPubkeyData = Data(hexString: senderPubkey) else {
|
||||
SecureLogger.log("❌ Invalid ciphertext or sender pubkey format",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw NostrError.invalidCiphertext
|
||||
}
|
||||
|
||||
// Ciphertext data parsed
|
||||
|
||||
// Extract components
|
||||
let nonceData = data.prefix(12)
|
||||
let ciphertextData = data.dropFirst(12).dropLast(16)
|
||||
let tagData = data.suffix(16)
|
||||
|
||||
// Components parsed
|
||||
|
||||
// Derive shared secret - try with default Y coordinate first
|
||||
var sharedSecret: Data
|
||||
var decrypted: Data? = nil
|
||||
|
||||
do {
|
||||
sharedSecret = try deriveSharedSecret(
|
||||
privateKey: recipientKey,
|
||||
publicKey: senderPubkeyData
|
||||
)
|
||||
// Derived shared secret with first Y coordinate
|
||||
|
||||
// Try to decrypt
|
||||
let sealedBox = try AES.GCM.SealedBox(
|
||||
nonce: AES.GCM.Nonce(data: nonceData),
|
||||
ciphertext: ciphertextData,
|
||||
tag: tagData
|
||||
)
|
||||
|
||||
do {
|
||||
decrypted = try AES.GCM.open(
|
||||
sealedBox,
|
||||
using: SymmetricKey(data: sharedSecret)
|
||||
)
|
||||
// AES-GCM decryption successful
|
||||
} catch {
|
||||
// AES-GCM decryption failed, trying alternate
|
||||
|
||||
// If the sender pubkey is x-only (32 bytes), try the other Y coordinate
|
||||
if senderPubkeyData.count == 32 {
|
||||
// Trying alternate Y coordinate
|
||||
|
||||
// Force deriveSharedSecret to use odd Y by manipulating the data
|
||||
var altPubkey = Data()
|
||||
altPubkey.append(0x03) // Force odd Y
|
||||
altPubkey.append(senderPubkeyData)
|
||||
|
||||
sharedSecret = try deriveSharedSecretDirect(
|
||||
privateKey: recipientKey,
|
||||
publicKey: altPubkey
|
||||
)
|
||||
|
||||
decrypted = try AES.GCM.open(
|
||||
sealedBox,
|
||||
using: SymmetricKey(data: sharedSecret)
|
||||
)
|
||||
// AES-GCM decryption successful with alternate Y
|
||||
} else {
|
||||
throw error
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.log("❌ Failed to derive shared secret or decrypt: \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw error
|
||||
}
|
||||
|
||||
guard let finalDecrypted = decrypted else {
|
||||
throw NostrError.encryptionFailed
|
||||
}
|
||||
|
||||
return String(data: finalDecrypted, encoding: .utf8) ?? ""
|
||||
}
|
||||
|
||||
private static func deriveSharedSecret(
|
||||
privateKey: P256K.Schnorr.PrivateKey,
|
||||
publicKey: Data
|
||||
) throws -> Data {
|
||||
// Deriving shared secret
|
||||
|
||||
// Convert Schnorr private key to KeyAgreement private key
|
||||
let keyAgreementPrivateKey = try P256K.KeyAgreement.PrivateKey(
|
||||
dataRepresentation: privateKey.dataRepresentation
|
||||
)
|
||||
|
||||
// Create KeyAgreement public key from the public key data
|
||||
// For ECDH, we need the full 33-byte compressed public key (with 0x02 or 0x03 prefix)
|
||||
var fullPublicKey = Data()
|
||||
if publicKey.count == 32 { // X-only key, need to add prefix
|
||||
// For x-only keys in Nostr/Bitcoin, we need to try both possible Y coordinates
|
||||
// First try with even Y (0x02 prefix)
|
||||
fullPublicKey.append(0x02)
|
||||
fullPublicKey.append(publicKey)
|
||||
// Trying with even Y coordinate
|
||||
} else {
|
||||
fullPublicKey = publicKey
|
||||
}
|
||||
|
||||
// Try to create public key, if it fails with even Y, try odd Y
|
||||
let keyAgreementPublicKey: P256K.KeyAgreement.PublicKey
|
||||
do {
|
||||
keyAgreementPublicKey = try P256K.KeyAgreement.PublicKey(
|
||||
dataRepresentation: fullPublicKey,
|
||||
format: .compressed
|
||||
)
|
||||
} catch {
|
||||
if publicKey.count == 32 {
|
||||
// Try with odd Y (0x03 prefix)
|
||||
// Even Y failed, trying odd Y
|
||||
fullPublicKey = Data()
|
||||
fullPublicKey.append(0x03)
|
||||
fullPublicKey.append(publicKey)
|
||||
keyAgreementPublicKey = try P256K.KeyAgreement.PublicKey(
|
||||
dataRepresentation: fullPublicKey,
|
||||
format: .compressed
|
||||
)
|
||||
} else {
|
||||
throw error
|
||||
}
|
||||
}
|
||||
|
||||
// Perform ECDH
|
||||
let sharedSecret = try keyAgreementPrivateKey.sharedSecretFromKeyAgreement(
|
||||
with: keyAgreementPublicKey,
|
||||
format: .compressed
|
||||
)
|
||||
|
||||
// Convert SharedSecret to Data
|
||||
let sharedSecretData = sharedSecret.withUnsafeBytes { Data($0) }
|
||||
// ECDH shared secret derived
|
||||
|
||||
// Derive key using HKDF for NIP-44 v2
|
||||
let derivedKey = HKDF<CryptoKit.SHA256>.deriveKey(
|
||||
inputKeyMaterial: SymmetricKey(data: sharedSecretData),
|
||||
salt: "nip44-v2".data(using: .utf8)!,
|
||||
info: Data(),
|
||||
outputByteCount: 32
|
||||
)
|
||||
|
||||
let result = derivedKey.withUnsafeBytes { Data($0) }
|
||||
// Final derived key ready
|
||||
return result
|
||||
}
|
||||
|
||||
// Direct version that doesn't try to add prefixes
|
||||
private static func deriveSharedSecretDirect(
|
||||
privateKey: P256K.Schnorr.PrivateKey,
|
||||
publicKey: Data
|
||||
) throws -> Data {
|
||||
// Direct shared secret calculation
|
||||
|
||||
// Convert Schnorr private key to KeyAgreement private key
|
||||
let keyAgreementPrivateKey = try P256K.KeyAgreement.PrivateKey(
|
||||
dataRepresentation: privateKey.dataRepresentation
|
||||
)
|
||||
|
||||
// Use the public key as-is (should already have prefix)
|
||||
let keyAgreementPublicKey = try P256K.KeyAgreement.PublicKey(
|
||||
dataRepresentation: publicKey,
|
||||
format: .compressed
|
||||
)
|
||||
|
||||
// Perform ECDH
|
||||
let sharedSecret = try keyAgreementPrivateKey.sharedSecretFromKeyAgreement(
|
||||
with: keyAgreementPublicKey,
|
||||
format: .compressed
|
||||
)
|
||||
|
||||
// Convert SharedSecret to Data
|
||||
let sharedSecretData = sharedSecret.withUnsafeBytes { Data($0) }
|
||||
|
||||
// Derive key using HKDF for NIP-44 v2
|
||||
let derivedKey = HKDF<CryptoKit.SHA256>.deriveKey(
|
||||
inputKeyMaterial: SymmetricKey(data: sharedSecretData),
|
||||
salt: "nip44-v2".data(using: .utf8)!,
|
||||
info: Data(),
|
||||
outputByteCount: 32
|
||||
)
|
||||
|
||||
return derivedKey.withUnsafeBytes { Data($0) }
|
||||
}
|
||||
|
||||
private static func randomizedTimestamp() -> Date {
|
||||
// Add random offset to current time for privacy
|
||||
// TEMPORARY: Reduced range to debug timestamp issue
|
||||
let offset = TimeInterval.random(in: -60...60) // +/- 1 minute (was +/- 15 minutes)
|
||||
let now = Date()
|
||||
let randomized = now.addingTimeInterval(offset)
|
||||
|
||||
// Log with explicit UTC and local time for debugging
|
||||
let formatter = DateFormatter()
|
||||
formatter.dateFormat = "yyyy-MM-dd HH:mm:ss"
|
||||
formatter.timeZone = TimeZone(abbreviation: "UTC")
|
||||
let _ = formatter.string(from: now)
|
||||
let _ = formatter.string(from: randomized)
|
||||
|
||||
formatter.timeZone = TimeZone.current
|
||||
let _ = formatter.string(from: now)
|
||||
let _ = formatter.string(from: randomized)
|
||||
|
||||
// Timestamp randomized for privacy
|
||||
|
||||
return randomized
|
||||
}
|
||||
}
|
||||
|
||||
/// Nostr Event structure
|
||||
struct NostrEvent: Codable {
|
||||
var id: String
|
||||
let pubkey: String
|
||||
let created_at: Int
|
||||
let kind: Int
|
||||
let tags: [[String]]
|
||||
let content: String
|
||||
var sig: String?
|
||||
|
||||
init(
|
||||
pubkey: String,
|
||||
createdAt: Date,
|
||||
kind: NostrProtocol.EventKind,
|
||||
tags: [[String]],
|
||||
content: String
|
||||
) {
|
||||
self.pubkey = pubkey
|
||||
self.created_at = Int(createdAt.timeIntervalSince1970)
|
||||
self.kind = kind.rawValue
|
||||
self.tags = tags
|
||||
self.content = content
|
||||
self.sig = nil
|
||||
self.id = "" // Will be set during signing
|
||||
}
|
||||
|
||||
init(from dict: [String: Any]) throws {
|
||||
guard let pubkey = dict["pubkey"] as? String,
|
||||
let createdAt = dict["created_at"] as? Int,
|
||||
let kind = dict["kind"] as? Int,
|
||||
let tags = dict["tags"] as? [[String]],
|
||||
let content = dict["content"] as? String else {
|
||||
throw NostrError.invalidEvent
|
||||
}
|
||||
|
||||
self.id = dict["id"] as? String ?? ""
|
||||
self.pubkey = pubkey
|
||||
self.created_at = createdAt
|
||||
self.kind = kind
|
||||
self.tags = tags
|
||||
self.content = content
|
||||
self.sig = dict["sig"] as? String
|
||||
}
|
||||
|
||||
func sign(with key: P256K.Signing.PrivateKey) throws -> NostrEvent {
|
||||
let (eventId, eventIdHash) = try calculateEventId()
|
||||
|
||||
// Convert to Schnorr key for Nostr signing
|
||||
let schnorrKey = try P256K.Schnorr.PrivateKey(dataRepresentation: key.dataRepresentation)
|
||||
|
||||
// Sign with Schnorr
|
||||
var messageBytes = [UInt8](eventIdHash)
|
||||
var auxRand = [UInt8](repeating: 0, count: 32) // Zero auxiliary randomness for deterministic signing
|
||||
let schnorrSignature = try schnorrKey.signature(message: &messageBytes, auxiliaryRand: &auxRand)
|
||||
|
||||
let signatureHex = schnorrSignature.dataRepresentation.hexEncodedString()
|
||||
|
||||
var signed = self
|
||||
signed.id = eventId
|
||||
signed.sig = signatureHex
|
||||
return signed
|
||||
}
|
||||
|
||||
private func calculateEventId() throws -> (String, Data) {
|
||||
let serialized = [
|
||||
0,
|
||||
pubkey,
|
||||
created_at,
|
||||
kind,
|
||||
tags,
|
||||
content
|
||||
] as [Any]
|
||||
|
||||
let data = try JSONSerialization.data(withJSONObject: serialized, options: [.withoutEscapingSlashes])
|
||||
let hash = CryptoKit.SHA256.hash(data: data)
|
||||
let hashData = Data(hash)
|
||||
let hashHex = hash.compactMap { String(format: "%02x", $0) }.joined()
|
||||
return (hashHex, hashData)
|
||||
}
|
||||
|
||||
func jsonString() throws -> String {
|
||||
let encoder = JSONEncoder()
|
||||
encoder.outputFormatting = [.withoutEscapingSlashes]
|
||||
let data = try encoder.encode(self)
|
||||
return String(data: data, encoding: .utf8) ?? ""
|
||||
}
|
||||
}
|
||||
|
||||
enum NostrError: Error {
|
||||
case invalidPublicKey
|
||||
case invalidPrivateKey
|
||||
case invalidEvent
|
||||
case invalidCiphertext
|
||||
case signingFailed
|
||||
case encryptionFailed
|
||||
}
|
||||
@@ -1,552 +0,0 @@
|
||||
import Foundation
|
||||
import Network
|
||||
import Combine
|
||||
|
||||
/// Manages WebSocket connections to Nostr relays
|
||||
@MainActor
|
||||
class NostrRelayManager: ObservableObject {
|
||||
static let shared = NostrRelayManager()
|
||||
|
||||
struct Relay: Identifiable {
|
||||
let id = UUID()
|
||||
let url: String
|
||||
var isConnected: Bool = false
|
||||
var lastError: Error?
|
||||
var lastConnectedAt: Date?
|
||||
var messagesSent: Int = 0
|
||||
var messagesReceived: Int = 0
|
||||
var reconnectAttempts: Int = 0
|
||||
var lastDisconnectedAt: Date?
|
||||
var nextReconnectTime: Date?
|
||||
}
|
||||
|
||||
// Default relay list (can be customized)
|
||||
private static let defaultRelays = [
|
||||
"wss://relay.damus.io",
|
||||
"wss://relay.primal.net",
|
||||
"wss://offchain.pub",
|
||||
"wss://nostr21.com"
|
||||
// For local testing, you can add: "ws://localhost:8080"
|
||||
]
|
||||
|
||||
@Published private(set) var relays: [Relay] = []
|
||||
@Published private(set) var isConnected = false
|
||||
|
||||
private var connections: [String: URLSessionWebSocketTask] = [:]
|
||||
private var subscriptions: [String: Set<String>] = [:] // relay URL -> subscription IDs
|
||||
private var messageHandlers: [String: (NostrEvent) -> Void] = [:]
|
||||
private var cancellables = Set<AnyCancellable>()
|
||||
|
||||
// Message queue for reliability
|
||||
private var messageQueue: [(event: NostrEvent, relayUrls: [String])] = []
|
||||
private let messageQueueLock = NSLock()
|
||||
|
||||
// Exponential backoff configuration
|
||||
private let initialBackoffInterval: TimeInterval = 1.0 // Start with 1 second
|
||||
private let maxBackoffInterval: TimeInterval = 300.0 // Max 5 minutes
|
||||
private let backoffMultiplier: Double = 2.0 // Double each time
|
||||
private let maxReconnectAttempts = 10 // Stop after 10 attempts
|
||||
|
||||
// Reconnection timer
|
||||
private var reconnectionTimer: Timer?
|
||||
|
||||
init() {
|
||||
// Initialize with default relays
|
||||
self.relays = Self.defaultRelays.map { Relay(url: $0) }
|
||||
}
|
||||
|
||||
/// Connect to all configured relays
|
||||
func connect() {
|
||||
for relay in relays {
|
||||
connectToRelay(relay.url)
|
||||
}
|
||||
}
|
||||
|
||||
/// Disconnect from all relays
|
||||
func disconnect() {
|
||||
for (_, task) in connections {
|
||||
task.cancel(with: .goingAway, reason: nil)
|
||||
}
|
||||
connections.removeAll()
|
||||
updateConnectionStatus()
|
||||
}
|
||||
|
||||
/// Send an event to specified relays (or all if none specified)
|
||||
func sendEvent(_ event: NostrEvent, to relayUrls: [String]? = nil) {
|
||||
let targetRelays = relayUrls ?? relays.map { $0.url }
|
||||
|
||||
// Add to queue for reliability
|
||||
messageQueueLock.lock()
|
||||
messageQueue.append((event, targetRelays))
|
||||
messageQueueLock.unlock()
|
||||
|
||||
// Attempt immediate send
|
||||
for relayUrl in targetRelays {
|
||||
if let connection = connections[relayUrl] {
|
||||
sendToRelay(event: event, connection: connection, relayUrl: relayUrl)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Subscribe to events matching a filter
|
||||
func subscribe(
|
||||
filter: NostrFilter,
|
||||
id: String = UUID().uuidString,
|
||||
handler: @escaping (NostrEvent) -> Void
|
||||
) {
|
||||
messageHandlers[id] = handler
|
||||
|
||||
let req = NostrRequest.subscribe(id: id, filters: [filter])
|
||||
|
||||
do {
|
||||
let encoder = JSONEncoder()
|
||||
encoder.outputFormatting = .sortedKeys // For consistent output
|
||||
let message = try encoder.encode(req)
|
||||
guard let messageString = String(data: message, encoding: .utf8) else {
|
||||
SecureLogger.log("❌ Failed to encode subscription request", category: SecureLogger.session, level: .error)
|
||||
return
|
||||
}
|
||||
|
||||
// Sending subscription to relays
|
||||
// Filter JSON prepared
|
||||
// Full filter JSON logged
|
||||
|
||||
// Send subscription to all connected relays
|
||||
for (relayUrl, connection) in connections {
|
||||
connection.send(.string(messageString)) { error in
|
||||
if let error = error {
|
||||
SecureLogger.log("❌ Failed to send subscription to \(relayUrl): \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
} else {
|
||||
// Subscription sent successfully
|
||||
Task { @MainActor in
|
||||
var subs = self.subscriptions[relayUrl] ?? Set<String>()
|
||||
subs.insert(id)
|
||||
self.subscriptions[relayUrl] = subs
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if connections.isEmpty {
|
||||
SecureLogger.log("⚠️ No relay connections available for subscription",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.log("❌ Failed to encode subscription request: \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
}
|
||||
}
|
||||
|
||||
/// Unsubscribe from a subscription
|
||||
func unsubscribe(id: String) {
|
||||
messageHandlers.removeValue(forKey: id)
|
||||
|
||||
let req = NostrRequest.close(id: id)
|
||||
let message = try? JSONEncoder().encode(req)
|
||||
|
||||
guard let messageData = message,
|
||||
let messageString = String(data: messageData, encoding: .utf8) else { return }
|
||||
|
||||
// Send unsubscribe to all relays
|
||||
for (relayUrl, connection) in connections {
|
||||
if subscriptions[relayUrl]?.contains(id) == true {
|
||||
connection.send(.string(messageString)) { _ in
|
||||
Task { @MainActor in
|
||||
self.subscriptions[relayUrl]?.remove(id)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func connectToRelay(_ urlString: String) {
|
||||
guard let url = URL(string: urlString) else {
|
||||
SecureLogger.log("Invalid relay URL: \(urlString)", category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
// Attempting to connect to Nostr relay
|
||||
|
||||
let session = URLSession(configuration: .default)
|
||||
let task = session.webSocketTask(with: url)
|
||||
|
||||
connections[urlString] = task
|
||||
task.resume()
|
||||
|
||||
// Start receiving messages
|
||||
receiveMessage(from: task, relayUrl: urlString)
|
||||
|
||||
// Send initial ping to verify connection
|
||||
task.sendPing { [weak self] error in
|
||||
DispatchQueue.main.async {
|
||||
if error == nil {
|
||||
// Successfully connected to Nostr relay
|
||||
self?.updateRelayStatus(urlString, isConnected: true)
|
||||
SecureLogger.log("Successfully connected to Nostr relay \(urlString)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
} else {
|
||||
SecureLogger.log("Failed to connect to Nostr relay \(urlString): \(error?.localizedDescription ?? "Unknown error")",
|
||||
category: SecureLogger.session, level: .error)
|
||||
self?.updateRelayStatus(urlString, isConnected: false, error: error)
|
||||
// Trigger disconnection handler for proper backoff
|
||||
self?.handleDisconnection(relayUrl: urlString, error: error ?? NSError(domain: "NostrRelay", code: -1, userInfo: nil))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private func receiveMessage(from task: URLSessionWebSocketTask, relayUrl: String) {
|
||||
task.receive { [weak self] result in
|
||||
guard let self = self else { return }
|
||||
|
||||
switch result {
|
||||
case .success(let message):
|
||||
switch message {
|
||||
case .string(let text):
|
||||
Task { @MainActor in
|
||||
self.handleMessage(text, from: relayUrl)
|
||||
}
|
||||
case .data(let data):
|
||||
if let text = String(data: data, encoding: .utf8) {
|
||||
Task { @MainActor in
|
||||
self.handleMessage(text, from: relayUrl)
|
||||
}
|
||||
}
|
||||
@unknown default:
|
||||
break
|
||||
}
|
||||
|
||||
// Continue receiving
|
||||
Task { @MainActor in
|
||||
self.receiveMessage(from: task, relayUrl: relayUrl)
|
||||
}
|
||||
|
||||
case .failure(let error):
|
||||
DispatchQueue.main.async {
|
||||
self.handleDisconnection(relayUrl: relayUrl, error: error)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private func handleMessage(_ message: String, from relayUrl: String) {
|
||||
guard let data = message.data(using: .utf8) else { return }
|
||||
|
||||
do {
|
||||
// Try to decode as an array first
|
||||
if let array = try JSONSerialization.jsonObject(with: data) as? [Any],
|
||||
array.count >= 2,
|
||||
let type = array[0] as? String {
|
||||
|
||||
// Received message from relay
|
||||
|
||||
switch type {
|
||||
case "EVENT":
|
||||
if array.count >= 3,
|
||||
let subId = array[1] as? String,
|
||||
let eventDict = array[2] as? [String: Any] {
|
||||
|
||||
let event = try NostrEvent(from: eventDict)
|
||||
|
||||
// Processing event
|
||||
|
||||
DispatchQueue.main.async {
|
||||
// Update relay stats
|
||||
if let index = self.relays.firstIndex(where: { $0.url == relayUrl }) {
|
||||
self.relays[index].messagesReceived += 1
|
||||
}
|
||||
|
||||
// Call handler
|
||||
if let handler = self.messageHandlers[subId] {
|
||||
handler(event)
|
||||
} else {
|
||||
SecureLogger.log("⚠️ No handler for subscription \(subId)",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
case "EOSE":
|
||||
if array.count >= 2,
|
||||
let _ = array[1] as? String {
|
||||
// End of stored events
|
||||
}
|
||||
|
||||
case "OK":
|
||||
if array.count >= 3,
|
||||
let eventId = array[1] as? String,
|
||||
let success = array[2] as? Bool {
|
||||
let reason = array.count >= 4 ? (array[3] as? String ?? "no reason given") : "no reason given"
|
||||
if !success {
|
||||
SecureLogger.log("📮 Event \(eventId) rejected by relay: \(reason)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
}
|
||||
}
|
||||
|
||||
case "NOTICE":
|
||||
if array.count >= 2,
|
||||
let notice = array[1] as? String {
|
||||
SecureLogger.log("📢 Relay notice: \(notice)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
}
|
||||
|
||||
default:
|
||||
break // Unknown message type
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.log("Failed to parse Nostr message: \(error)", category: SecureLogger.session, level: .error)
|
||||
}
|
||||
}
|
||||
|
||||
private func sendToRelay(event: NostrEvent, connection: URLSessionWebSocketTask, relayUrl: String) {
|
||||
let req = NostrRequest.event(event)
|
||||
|
||||
do {
|
||||
let encoder = JSONEncoder()
|
||||
encoder.outputFormatting = .sortedKeys
|
||||
let data = try encoder.encode(req)
|
||||
let message = String(data: data, encoding: .utf8) ?? ""
|
||||
|
||||
// Sending event to relay
|
||||
// Event JSON prepared
|
||||
|
||||
connection.send(.string(message)) { [weak self] error in
|
||||
DispatchQueue.main.async {
|
||||
if let error = error {
|
||||
SecureLogger.log("❌ Failed to send event to \(relayUrl): \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
} else {
|
||||
// Update relay stats
|
||||
if let index = self?.relays.firstIndex(where: { $0.url == relayUrl }) {
|
||||
self?.relays[index].messagesSent += 1
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.log("Failed to encode event: \(error)", category: SecureLogger.session, level: .error)
|
||||
}
|
||||
}
|
||||
|
||||
private func updateRelayStatus(_ url: String, isConnected: Bool, error: Error? = nil) {
|
||||
if let index = relays.firstIndex(where: { $0.url == url }) {
|
||||
relays[index].isConnected = isConnected
|
||||
relays[index].lastError = error
|
||||
if isConnected {
|
||||
relays[index].lastConnectedAt = Date()
|
||||
relays[index].reconnectAttempts = 0 // Reset on successful connection
|
||||
relays[index].nextReconnectTime = nil
|
||||
} else {
|
||||
relays[index].lastDisconnectedAt = Date()
|
||||
}
|
||||
}
|
||||
updateConnectionStatus()
|
||||
}
|
||||
|
||||
private func updateConnectionStatus() {
|
||||
isConnected = relays.contains { $0.isConnected }
|
||||
}
|
||||
|
||||
private func handleDisconnection(relayUrl: String, error: Error) {
|
||||
connections.removeValue(forKey: relayUrl)
|
||||
subscriptions.removeValue(forKey: relayUrl)
|
||||
updateRelayStatus(relayUrl, isConnected: false, error: error)
|
||||
|
||||
// Check if this is a DNS error
|
||||
let errorDescription = error.localizedDescription.lowercased()
|
||||
if errorDescription.contains("hostname could not be found") ||
|
||||
errorDescription.contains("dns") {
|
||||
// Only log once for DNS failures
|
||||
if relays.first(where: { $0.url == relayUrl })?.lastError == nil {
|
||||
SecureLogger.log("Nostr relay DNS failure for \(relayUrl) - not retrying", category: SecureLogger.session, level: .warning)
|
||||
}
|
||||
// Mark relay as permanently failed
|
||||
if let index = relays.firstIndex(where: { $0.url == relayUrl }) {
|
||||
relays[index].lastError = error
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// Implement exponential backoff for non-DNS errors
|
||||
guard let index = relays.firstIndex(where: { $0.url == relayUrl }) else { return }
|
||||
|
||||
relays[index].reconnectAttempts += 1
|
||||
|
||||
// Stop attempting after max attempts
|
||||
if relays[index].reconnectAttempts >= maxReconnectAttempts {
|
||||
SecureLogger.log("Max reconnection attempts (\(maxReconnectAttempts)) reached for \(relayUrl)",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
// Calculate backoff interval
|
||||
let backoffInterval = min(
|
||||
initialBackoffInterval * pow(backoffMultiplier, Double(relays[index].reconnectAttempts - 1)),
|
||||
maxBackoffInterval
|
||||
)
|
||||
|
||||
let nextReconnectTime = Date().addingTimeInterval(backoffInterval)
|
||||
relays[index].nextReconnectTime = nextReconnectTime
|
||||
|
||||
SecureLogger.log("Scheduling reconnection to \(relayUrl) in \(Int(backoffInterval))s (attempt \(relays[index].reconnectAttempts))",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Schedule reconnection with exponential backoff
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + backoffInterval) { [weak self] in
|
||||
guard let self = self else { return }
|
||||
|
||||
// Check if we should still reconnect (relay might have been removed)
|
||||
if self.relays.contains(where: { $0.url == relayUrl }) {
|
||||
self.connectToRelay(relayUrl)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Public Utility Methods
|
||||
|
||||
/// Manually retry connection to a specific relay
|
||||
func retryConnection(to relayUrl: String) {
|
||||
guard let index = relays.firstIndex(where: { $0.url == relayUrl }) else { return }
|
||||
|
||||
// Reset reconnection attempts
|
||||
relays[index].reconnectAttempts = 0
|
||||
relays[index].nextReconnectTime = nil
|
||||
|
||||
// Disconnect if connected
|
||||
if let connection = connections[relayUrl] {
|
||||
connection.cancel(with: .goingAway, reason: nil)
|
||||
connections.removeValue(forKey: relayUrl)
|
||||
}
|
||||
|
||||
// Attempt immediate reconnection
|
||||
connectToRelay(relayUrl)
|
||||
}
|
||||
|
||||
/// Get detailed status for all relays
|
||||
func getRelayStatuses() -> [(url: String, isConnected: Bool, reconnectAttempts: Int, nextReconnectTime: Date?)] {
|
||||
return relays.map { relay in
|
||||
(url: relay.url,
|
||||
isConnected: relay.isConnected,
|
||||
reconnectAttempts: relay.reconnectAttempts,
|
||||
nextReconnectTime: relay.nextReconnectTime)
|
||||
}
|
||||
}
|
||||
|
||||
/// Reset all relay connections
|
||||
func resetAllConnections() {
|
||||
disconnect()
|
||||
|
||||
// Reset all relay states
|
||||
for index in relays.indices {
|
||||
relays[index].reconnectAttempts = 0
|
||||
relays[index].nextReconnectTime = nil
|
||||
relays[index].lastError = nil
|
||||
}
|
||||
|
||||
// Reconnect
|
||||
connect()
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Nostr Protocol Types
|
||||
|
||||
enum NostrRequest: Encodable {
|
||||
case event(NostrEvent)
|
||||
case subscribe(id: String, filters: [NostrFilter])
|
||||
case close(id: String)
|
||||
|
||||
func encode(to encoder: Encoder) throws {
|
||||
var container = encoder.unkeyedContainer()
|
||||
|
||||
switch self {
|
||||
case .event(let event):
|
||||
try container.encode("EVENT")
|
||||
try container.encode(event)
|
||||
|
||||
case .subscribe(let id, let filters):
|
||||
try container.encode("REQ")
|
||||
try container.encode(id)
|
||||
for filter in filters {
|
||||
try container.encode(filter)
|
||||
}
|
||||
|
||||
case .close(let id):
|
||||
try container.encode("CLOSE")
|
||||
try container.encode(id)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
struct NostrFilter: Encodable {
|
||||
var ids: [String]?
|
||||
var authors: [String]?
|
||||
var kinds: [Int]?
|
||||
var since: Int?
|
||||
var until: Int?
|
||||
var limit: Int?
|
||||
|
||||
// Tag filters - stored internally but encoded specially
|
||||
fileprivate var tagFilters: [String: [String]]?
|
||||
|
||||
init() {
|
||||
// Default initializer
|
||||
}
|
||||
|
||||
// Custom encoding to handle tag filters properly
|
||||
enum CodingKeys: String, CodingKey {
|
||||
case ids, authors, kinds, since, until, limit
|
||||
}
|
||||
|
||||
func encode(to encoder: Encoder) throws {
|
||||
var container = encoder.container(keyedBy: DynamicCodingKey.self)
|
||||
|
||||
// Encode standard fields
|
||||
if let ids = ids { try container.encode(ids, forKey: DynamicCodingKey(stringValue: "ids")) }
|
||||
if let authors = authors { try container.encode(authors, forKey: DynamicCodingKey(stringValue: "authors")) }
|
||||
if let kinds = kinds { try container.encode(kinds, forKey: DynamicCodingKey(stringValue: "kinds")) }
|
||||
if let since = since { try container.encode(since, forKey: DynamicCodingKey(stringValue: "since")) }
|
||||
if let until = until { try container.encode(until, forKey: DynamicCodingKey(stringValue: "until")) }
|
||||
if let limit = limit { try container.encode(limit, forKey: DynamicCodingKey(stringValue: "limit")) }
|
||||
|
||||
// Encode tag filters with # prefix
|
||||
if let tagFilters = tagFilters {
|
||||
for (tag, values) in tagFilters {
|
||||
try container.encode(values, forKey: DynamicCodingKey(stringValue: "#\(tag)"))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// For NIP-17 gift wraps
|
||||
static func giftWrapsFor(pubkey: String, since: Date? = nil) -> NostrFilter {
|
||||
var filter = NostrFilter()
|
||||
filter.kinds = [1059] // Gift wrap kind
|
||||
filter.since = since?.timeIntervalSince1970.toInt()
|
||||
filter.tagFilters = ["p": [pubkey]]
|
||||
filter.limit = 100 // Add a reasonable limit
|
||||
return filter
|
||||
}
|
||||
}
|
||||
|
||||
// Dynamic coding key for tag filters
|
||||
private struct DynamicCodingKey: CodingKey {
|
||||
var stringValue: String
|
||||
var intValue: Int? { nil }
|
||||
|
||||
init(stringValue: String) {
|
||||
self.stringValue = stringValue
|
||||
}
|
||||
|
||||
init?(intValue: Int) {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
private extension TimeInterval {
|
||||
func toInt() -> Int {
|
||||
return Int(self)
|
||||
}
|
||||
}
|
||||
@@ -6,57 +6,30 @@
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
// MARK: - Hex Encoding/Decoding
|
||||
|
||||
extension Data {
|
||||
func hexEncodedString() -> String {
|
||||
if self.isEmpty {
|
||||
return ""
|
||||
}
|
||||
return self.map { String(format: "%02x", $0) }.joined()
|
||||
}
|
||||
|
||||
init?(hexString: String) {
|
||||
let len = hexString.count / 2
|
||||
var data = Data(capacity: len)
|
||||
var index = hexString.startIndex
|
||||
|
||||
for _ in 0..<len {
|
||||
let nextIndex = hexString.index(index, offsetBy: 2)
|
||||
guard let byte = UInt8(String(hexString[index..<nextIndex]), radix: 16) else {
|
||||
return nil
|
||||
}
|
||||
data.append(byte)
|
||||
index = nextIndex
|
||||
}
|
||||
|
||||
self = data
|
||||
}
|
||||
}
|
||||
import BitFoundation
|
||||
|
||||
// MARK: - Binary Encoding Utilities
|
||||
|
||||
extension Data {
|
||||
// MARK: Writing
|
||||
|
||||
mutating func appendUInt8(_ value: UInt8) {
|
||||
@inlinable mutating func appendUInt8(_ value: UInt8) {
|
||||
self.append(value)
|
||||
}
|
||||
|
||||
mutating func appendUInt16(_ value: UInt16) {
|
||||
@inlinable mutating func appendUInt16(_ value: UInt16) {
|
||||
self.append(UInt8((value >> 8) & 0xFF))
|
||||
self.append(UInt8(value & 0xFF))
|
||||
}
|
||||
|
||||
mutating func appendUInt32(_ value: UInt32) {
|
||||
@inlinable mutating func appendUInt32(_ value: UInt32) {
|
||||
self.append(UInt8((value >> 24) & 0xFF))
|
||||
self.append(UInt8((value >> 16) & 0xFF))
|
||||
self.append(UInt8((value >> 8) & 0xFF))
|
||||
self.append(UInt8(value & 0xFF))
|
||||
}
|
||||
|
||||
mutating func appendUInt64(_ value: UInt64) {
|
||||
@inlinable mutating func appendUInt64(_ value: UInt64) {
|
||||
for i in (0..<8).reversed() {
|
||||
self.append(UInt8((value >> (i * 8)) & 0xFF))
|
||||
}
|
||||
@@ -113,21 +86,21 @@ extension Data {
|
||||
|
||||
// MARK: Reading
|
||||
|
||||
func readUInt8(at offset: inout Int) -> UInt8? {
|
||||
@inlinable func readUInt8(at offset: inout Int) -> UInt8? {
|
||||
guard offset >= 0 && offset < self.count else { return nil }
|
||||
let value = self[offset]
|
||||
offset += 1
|
||||
return value
|
||||
}
|
||||
|
||||
func readUInt16(at offset: inout Int) -> UInt16? {
|
||||
@inlinable func readUInt16(at offset: inout Int) -> UInt16? {
|
||||
guard offset + 2 <= self.count else { return nil }
|
||||
let value = UInt16(self[offset]) << 8 | UInt16(self[offset + 1])
|
||||
offset += 2
|
||||
return value
|
||||
}
|
||||
|
||||
func readUInt32(at offset: inout Int) -> UInt32? {
|
||||
@inlinable func readUInt32(at offset: inout Int) -> UInt32? {
|
||||
guard offset + 4 <= self.count else { return nil }
|
||||
let value = UInt32(self[offset]) << 24 |
|
||||
UInt32(self[offset + 1]) << 16 |
|
||||
@@ -137,7 +110,7 @@ extension Data {
|
||||
return value
|
||||
}
|
||||
|
||||
func readUInt64(at offset: inout Int) -> UInt64? {
|
||||
@inlinable func readUInt64(at offset: inout Int) -> UInt64? {
|
||||
guard offset + 8 <= self.count else { return nil }
|
||||
var value: UInt64 = 0
|
||||
for i in 0..<8 {
|
||||
@@ -197,7 +170,7 @@ extension Data {
|
||||
offset += 16
|
||||
|
||||
// Convert 16 bytes to UUID string format
|
||||
let uuid = uuidData.map { String(format: "%02x", $0) }.joined()
|
||||
let uuid = uuidData.hexEncodedString()
|
||||
|
||||
// Insert hyphens at proper positions: 8-4-4-4-12
|
||||
var result = ""
|
||||
@@ -220,21 +193,3 @@ extension Data {
|
||||
return data
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Binary Message Protocol
|
||||
|
||||
protocol BinaryEncodable {
|
||||
func toBinaryData() -> Data
|
||||
static func fromBinaryData(_ data: Data) -> Self?
|
||||
}
|
||||
|
||||
// MARK: - Message Type Registry
|
||||
|
||||
enum BinaryMessageType: UInt8 {
|
||||
case deliveryAck = 0x01
|
||||
case readReceipt = 0x02
|
||||
case versionHello = 0x07
|
||||
case versionAck = 0x08
|
||||
case noiseIdentityAnnouncement = 0x09
|
||||
case noiseMessage = 0x0A
|
||||
}
|
||||
@@ -22,11 +22,11 @@
|
||||
///
|
||||
/// ## Wire Format
|
||||
/// ```
|
||||
/// Header (Fixed 13 bytes):
|
||||
/// +--------+------+-----+-----------+-------+----------------+
|
||||
/// |Version | Type | TTL | Timestamp | Flags | PayloadLength |
|
||||
/// |1 byte |1 byte|1byte| 8 bytes | 1 byte| 2 bytes |
|
||||
/// +--------+------+-----+-----------+-------+----------------+
|
||||
/// Header (Fixed 14 bytes for v1, 16 bytes for v2):
|
||||
/// +--------+------+-----+-----------+-------+------------------+
|
||||
/// |Version | Type | TTL | Timestamp | Flags | PayloadLength |
|
||||
/// |1 byte |1 byte|1byte| 8 bytes | 1 byte| 2 or 4 bytes |
|
||||
/// +--------+------+-----+-----------+-------+------------------+
|
||||
///
|
||||
/// Variable sections:
|
||||
/// +----------+-------------+---------+------------+
|
||||
@@ -45,14 +45,14 @@
|
||||
///
|
||||
/// ## Compression Strategy
|
||||
/// - Automatic compression for payloads > 256 bytes
|
||||
/// - LZ4 algorithm for speed over ratio
|
||||
/// - zlib compression for broad compatibility on Apple platforms
|
||||
/// - Original size stored for decompression
|
||||
/// - Flag bit indicates compressed payload
|
||||
///
|
||||
/// ## Flag Bits
|
||||
/// - Bit 0: Has recipient ID (directed message)
|
||||
/// - Bit 1: Has signature (authenticated message)
|
||||
/// - Bit 2: Is compressed (LZ4 compression applied)
|
||||
/// - Bit 2: Is compressed (zlib compression applied)
|
||||
/// - Bits 3-7: Reserved for future use
|
||||
///
|
||||
/// ## Size Constraints
|
||||
@@ -89,6 +89,7 @@
|
||||
///
|
||||
|
||||
import Foundation
|
||||
import BitLogger
|
||||
|
||||
extension Data {
|
||||
func trimmingNullBytes() -> Data {
|
||||
@@ -105,78 +106,125 @@ extension Data {
|
||||
/// their binary wire format representation.
|
||||
/// - Note: All multi-byte values use network byte order (big-endian)
|
||||
struct BinaryProtocol {
|
||||
static let headerSize = 13
|
||||
static let v1HeaderSize = 14
|
||||
static let v2HeaderSize = 16
|
||||
static let senderIDSize = 8
|
||||
static let recipientIDSize = 8
|
||||
static let signatureSize = 64
|
||||
|
||||
// Field offsets within packet header
|
||||
struct Offsets {
|
||||
static let version = 0
|
||||
static let type = 1
|
||||
static let ttl = 2
|
||||
static let timestamp = 3
|
||||
static let flags = 11 // After version(1) + type(1) + ttl(1) + timestamp(8)
|
||||
}
|
||||
|
||||
static func headerSize(for version: UInt8) -> Int? {
|
||||
switch version {
|
||||
case 1: return v1HeaderSize
|
||||
case 2: return v2HeaderSize
|
||||
default: return nil
|
||||
}
|
||||
}
|
||||
|
||||
private static func lengthFieldSize(for version: UInt8) -> Int {
|
||||
return version == 2 ? 4 : 2
|
||||
}
|
||||
|
||||
struct Flags {
|
||||
static let hasRecipient: UInt8 = 0x01
|
||||
static let hasSignature: UInt8 = 0x02
|
||||
static let isCompressed: UInt8 = 0x04
|
||||
static let hasRoute: UInt8 = 0x08
|
||||
static let isRSR: UInt8 = 0x10
|
||||
}
|
||||
|
||||
// Encode BitchatPacket to binary format
|
||||
static func encode(_ packet: BitchatPacket) -> Data? {
|
||||
var data = Data()
|
||||
static func encode(_ packet: BitchatPacket, padding: Bool = true) -> Data? {
|
||||
let version = packet.version
|
||||
guard version == 1 || version == 2 else { return nil }
|
||||
|
||||
|
||||
// Try to compress payload if beneficial
|
||||
// Try to compress payload when beneficial, keeping original size for later decoding
|
||||
var payload = packet.payload
|
||||
var originalPayloadSize: UInt16? = nil
|
||||
var isCompressed = false
|
||||
|
||||
var originalPayloadSize: Int?
|
||||
if CompressionUtil.shouldCompress(payload) {
|
||||
if let compressedPayload = CompressionUtil.compress(payload) {
|
||||
// Store original size for decompression (2 bytes after payload)
|
||||
originalPayloadSize = UInt16(payload.count)
|
||||
// Only compress when we can represent the original length in the outbound frame
|
||||
let maxRepresentable = version == 2 ? Int(UInt32.max) : Int(UInt16.max)
|
||||
if payload.count <= maxRepresentable,
|
||||
let compressedPayload = CompressionUtil.compress(payload) {
|
||||
originalPayloadSize = payload.count
|
||||
payload = compressedPayload
|
||||
isCompressed = true
|
||||
|
||||
} else {
|
||||
}
|
||||
} else {
|
||||
}
|
||||
|
||||
// Header
|
||||
data.append(packet.version)
|
||||
let lengthFieldBytes = lengthFieldSize(for: version)
|
||||
|
||||
// Route is only supported for v2+ packets (per SOURCE_ROUTING.md spec)
|
||||
let originalRoute = (version >= 2) ? (packet.route ?? []) : []
|
||||
if originalRoute.contains(where: { $0.isEmpty }) { return nil }
|
||||
let sanitizedRoute: [Data] = originalRoute.map { hop in
|
||||
if hop.count == senderIDSize { return hop }
|
||||
if hop.count > senderIDSize { return Data(hop.prefix(senderIDSize)) }
|
||||
var padded = hop
|
||||
padded.append(Data(repeating: 0, count: senderIDSize - hop.count))
|
||||
return padded
|
||||
}
|
||||
guard sanitizedRoute.count <= 255 else { return nil }
|
||||
|
||||
let hasRoute = !sanitizedRoute.isEmpty
|
||||
let routeLength = hasRoute ? 1 + sanitizedRoute.count * senderIDSize : 0
|
||||
let originalSizeFieldBytes = isCompressed ? lengthFieldBytes : 0
|
||||
// payloadLength in header is payload-only (does NOT include route bytes)
|
||||
let payloadDataSize = payload.count + originalSizeFieldBytes
|
||||
|
||||
if version == 1 && payloadDataSize > Int(UInt16.max) { return nil }
|
||||
if version == 2 && payloadDataSize > Int(UInt32.max) { return nil }
|
||||
|
||||
guard let headerSize = headerSize(for: version) else { return nil }
|
||||
let estimatedHeader = headerSize + senderIDSize + (packet.recipientID == nil ? 0 : recipientIDSize) + routeLength
|
||||
let estimatedPayload = payloadDataSize
|
||||
let estimatedSignature = (packet.signature == nil ? 0 : signatureSize)
|
||||
var data = Data()
|
||||
data.reserveCapacity(estimatedHeader + estimatedPayload + estimatedSignature + 255)
|
||||
|
||||
data.append(version)
|
||||
data.append(packet.type)
|
||||
data.append(packet.ttl)
|
||||
|
||||
// Timestamp (8 bytes, big-endian)
|
||||
for i in (0..<8).reversed() {
|
||||
data.append(UInt8((packet.timestamp >> (i * 8)) & 0xFF))
|
||||
for shift in stride(from: 56, through: 0, by: -8) {
|
||||
data.append(UInt8((packet.timestamp >> UInt64(shift)) & 0xFF))
|
||||
}
|
||||
|
||||
// Flags
|
||||
var flags: UInt8 = 0
|
||||
if packet.recipientID != nil {
|
||||
flags |= Flags.hasRecipient
|
||||
}
|
||||
if packet.signature != nil {
|
||||
flags |= Flags.hasSignature
|
||||
}
|
||||
if isCompressed {
|
||||
flags |= Flags.isCompressed
|
||||
}
|
||||
if packet.recipientID != nil { flags |= Flags.hasRecipient }
|
||||
if packet.signature != nil { flags |= Flags.hasSignature }
|
||||
if isCompressed { flags |= Flags.isCompressed }
|
||||
// HAS_ROUTE is only valid for v2+ packets
|
||||
if hasRoute && version >= 2 { flags |= Flags.hasRoute }
|
||||
if packet.isRSR { flags |= Flags.isRSR }
|
||||
data.append(flags)
|
||||
|
||||
// Payload length (2 bytes, big-endian) - includes original size if compressed
|
||||
let payloadDataSize = payload.count + (isCompressed ? 2 : 0)
|
||||
let payloadLength = UInt16(payloadDataSize)
|
||||
if version == 2 {
|
||||
let length = UInt32(payloadDataSize)
|
||||
for shift in stride(from: 24, through: 0, by: -8) {
|
||||
data.append(UInt8((length >> UInt32(shift)) & 0xFF))
|
||||
}
|
||||
} else {
|
||||
let length = UInt16(payloadDataSize)
|
||||
data.append(UInt8((length >> 8) & 0xFF))
|
||||
data.append(UInt8(length & 0xFF))
|
||||
}
|
||||
|
||||
|
||||
data.append(UInt8((payloadLength >> 8) & 0xFF))
|
||||
data.append(UInt8(payloadLength & 0xFF))
|
||||
|
||||
// SenderID (exactly 8 bytes)
|
||||
let senderBytes = packet.senderID.prefix(senderIDSize)
|
||||
data.append(senderBytes)
|
||||
if senderBytes.count < senderIDSize {
|
||||
data.append(Data(repeating: 0, count: senderIDSize - senderBytes.count))
|
||||
}
|
||||
|
||||
// RecipientID (if present)
|
||||
if let recipientID = packet.recipientID {
|
||||
let recipientBytes = recipientID.prefix(recipientIDSize)
|
||||
data.append(recipientBytes)
|
||||
@@ -185,366 +233,190 @@ struct BinaryProtocol {
|
||||
}
|
||||
}
|
||||
|
||||
// Payload (with original size prepended if compressed)
|
||||
if hasRoute {
|
||||
data.append(UInt8(sanitizedRoute.count))
|
||||
for hop in sanitizedRoute {
|
||||
data.append(hop)
|
||||
}
|
||||
}
|
||||
|
||||
if isCompressed, let originalSize = originalPayloadSize {
|
||||
// Prepend original size (2 bytes, big-endian)
|
||||
data.append(UInt8((originalSize >> 8) & 0xFF))
|
||||
data.append(UInt8(originalSize & 0xFF))
|
||||
if version == 2 {
|
||||
let value = UInt32(originalSize)
|
||||
for shift in stride(from: 24, through: 0, by: -8) {
|
||||
data.append(UInt8((value >> UInt32(shift)) & 0xFF))
|
||||
}
|
||||
} else {
|
||||
let value = UInt16(originalSize)
|
||||
data.append(UInt8((value >> 8) & 0xFF))
|
||||
data.append(UInt8(value & 0xFF))
|
||||
}
|
||||
}
|
||||
data.append(payload)
|
||||
|
||||
// Signature (if present)
|
||||
if let signature = packet.signature {
|
||||
data.append(signature.prefix(signatureSize))
|
||||
}
|
||||
|
||||
|
||||
// Apply padding to standard block sizes for traffic analysis resistance
|
||||
let optimalSize = MessagePadding.optimalBlockSize(for: data.count)
|
||||
let paddedData = MessagePadding.pad(data, toSize: optimalSize)
|
||||
|
||||
|
||||
return paddedData
|
||||
if padding {
|
||||
let optimalSize = MessagePadding.optimalBlockSize(for: data.count)
|
||||
return MessagePadding.pad(data, toSize: optimalSize)
|
||||
}
|
||||
return data
|
||||
}
|
||||
|
||||
// Decode binary data to BitchatPacket
|
||||
static func decode(_ data: Data) -> BitchatPacket? {
|
||||
// Remove padding first
|
||||
let unpaddedData = MessagePadding.unpad(data)
|
||||
|
||||
|
||||
guard unpaddedData.count >= headerSize + senderIDSize else {
|
||||
return nil
|
||||
}
|
||||
|
||||
var offset = 0
|
||||
|
||||
// Header
|
||||
let version = unpaddedData[offset]; offset += 1
|
||||
// Check if version is supported
|
||||
guard ProtocolVersion.isSupported(version) else {
|
||||
// Log unsupported version for debugging
|
||||
return nil
|
||||
}
|
||||
let type = unpaddedData[offset]; offset += 1
|
||||
let ttl = unpaddedData[offset]; offset += 1
|
||||
|
||||
// Timestamp
|
||||
let timestampData = unpaddedData[offset..<offset+8]
|
||||
let timestamp = timestampData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt64(byte)
|
||||
}
|
||||
offset += 8
|
||||
|
||||
// Flags
|
||||
let flags = unpaddedData[offset]; offset += 1
|
||||
let hasRecipient = (flags & Flags.hasRecipient) != 0
|
||||
let hasSignature = (flags & Flags.hasSignature) != 0
|
||||
let isCompressed = (flags & Flags.isCompressed) != 0
|
||||
|
||||
// Payload length
|
||||
let payloadLengthData = unpaddedData[offset..<offset+2]
|
||||
let payloadLength = payloadLengthData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt16(byte)
|
||||
}
|
||||
offset += 2
|
||||
|
||||
// Calculate expected total size
|
||||
var expectedSize = headerSize + senderIDSize + Int(payloadLength)
|
||||
if hasRecipient {
|
||||
expectedSize += recipientIDSize
|
||||
}
|
||||
if hasSignature {
|
||||
expectedSize += signatureSize
|
||||
}
|
||||
|
||||
guard unpaddedData.count >= expectedSize else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// SenderID
|
||||
let senderID = unpaddedData[offset..<offset+senderIDSize]
|
||||
offset += senderIDSize
|
||||
|
||||
// RecipientID
|
||||
var recipientID: Data?
|
||||
if hasRecipient {
|
||||
recipientID = unpaddedData[offset..<offset+recipientIDSize]
|
||||
offset += recipientIDSize
|
||||
}
|
||||
|
||||
// Payload
|
||||
let payload: Data
|
||||
if isCompressed {
|
||||
// First 2 bytes are original size
|
||||
guard Int(payloadLength) >= 2 else { return nil }
|
||||
let originalSizeData = unpaddedData[offset..<offset+2]
|
||||
let originalSize = Int(originalSizeData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt16(byte)
|
||||
})
|
||||
offset += 2
|
||||
|
||||
// Compressed payload
|
||||
let compressedPayload = unpaddedData[offset..<offset+Int(payloadLength)-2]
|
||||
offset += Int(payloadLength) - 2
|
||||
|
||||
// Decompress
|
||||
guard let decompressedPayload = CompressionUtil.decompress(compressedPayload, originalSize: originalSize) else {
|
||||
return nil
|
||||
}
|
||||
payload = decompressedPayload
|
||||
} else {
|
||||
payload = unpaddedData[offset..<offset+Int(payloadLength)]
|
||||
offset += Int(payloadLength)
|
||||
}
|
||||
|
||||
// Signature
|
||||
var signature: Data?
|
||||
if hasSignature {
|
||||
signature = unpaddedData[offset..<offset+signatureSize]
|
||||
}
|
||||
|
||||
return BitchatPacket(
|
||||
type: type,
|
||||
senderID: senderID,
|
||||
recipientID: recipientID,
|
||||
timestamp: timestamp,
|
||||
payload: payload,
|
||||
signature: signature,
|
||||
ttl: ttl
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// Binary encoding for BitchatMessage
|
||||
extension BitchatMessage {
|
||||
func toBinaryPayload() -> Data? {
|
||||
var data = Data()
|
||||
|
||||
// Message format:
|
||||
// - Flags: 1 byte (bit 0: isRelay, bit 1: isPrivate, bit 2: hasOriginalSender, bit 3: hasRecipientNickname, bit 4: hasSenderPeerID, bit 5: hasMentions)
|
||||
// - Timestamp: 8 bytes (seconds since epoch)
|
||||
// - ID length: 1 byte
|
||||
// - ID: variable
|
||||
// - Sender length: 1 byte
|
||||
// - Sender: variable
|
||||
// - Content length: 2 bytes
|
||||
// - Content: variable
|
||||
// Optional fields based on flags:
|
||||
// - Original sender length + data
|
||||
// - Recipient nickname length + data
|
||||
// - Sender peer ID length + data
|
||||
// - Mentions array
|
||||
|
||||
var flags: UInt8 = 0
|
||||
if isRelay { flags |= 0x01 }
|
||||
if isPrivate { flags |= 0x02 }
|
||||
if originalSender != nil { flags |= 0x04 }
|
||||
if recipientNickname != nil { flags |= 0x08 }
|
||||
if senderPeerID != nil { flags |= 0x10 }
|
||||
if mentions != nil && !mentions!.isEmpty { flags |= 0x20 }
|
||||
|
||||
data.append(flags)
|
||||
|
||||
// Timestamp (in milliseconds)
|
||||
let timestampMillis = UInt64(timestamp.timeIntervalSince1970 * 1000)
|
||||
// Encode as 8 bytes, big-endian
|
||||
for i in (0..<8).reversed() {
|
||||
data.append(UInt8((timestampMillis >> (i * 8)) & 0xFF))
|
||||
}
|
||||
|
||||
// ID
|
||||
if let idData = id.data(using: .utf8) {
|
||||
data.append(UInt8(min(idData.count, 255)))
|
||||
data.append(idData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
|
||||
// Sender
|
||||
if let senderData = sender.data(using: .utf8) {
|
||||
data.append(UInt8(min(senderData.count, 255)))
|
||||
data.append(senderData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
|
||||
// Content
|
||||
if let contentData = content.data(using: .utf8) {
|
||||
let length = UInt16(min(contentData.count, 65535))
|
||||
// Encode length as 2 bytes, big-endian
|
||||
data.append(UInt8((length >> 8) & 0xFF))
|
||||
data.append(UInt8(length & 0xFF))
|
||||
data.append(contentData.prefix(Int(length)))
|
||||
} else {
|
||||
data.append(contentsOf: [0, 0])
|
||||
}
|
||||
|
||||
// Optional fields
|
||||
if let originalSender = originalSender, let origData = originalSender.data(using: .utf8) {
|
||||
data.append(UInt8(min(origData.count, 255)))
|
||||
data.append(origData.prefix(255))
|
||||
}
|
||||
|
||||
if let recipientNickname = recipientNickname, let recipData = recipientNickname.data(using: .utf8) {
|
||||
data.append(UInt8(min(recipData.count, 255)))
|
||||
data.append(recipData.prefix(255))
|
||||
}
|
||||
|
||||
if let senderPeerID = senderPeerID, let peerData = senderPeerID.data(using: .utf8) {
|
||||
data.append(UInt8(min(peerData.count, 255)))
|
||||
data.append(peerData.prefix(255))
|
||||
}
|
||||
|
||||
// Mentions array
|
||||
if let mentions = mentions {
|
||||
data.append(UInt8(min(mentions.count, 255))) // Number of mentions
|
||||
for mention in mentions.prefix(255) {
|
||||
if let mentionData = mention.data(using: .utf8) {
|
||||
data.append(UInt8(min(mentionData.count, 255)))
|
||||
data.append(mentionData.prefix(255))
|
||||
} else {
|
||||
data.append(0)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
return data
|
||||
// Try decode as-is first (robust when padding wasn't applied)
|
||||
if let pkt = decodeCore(data) { return pkt }
|
||||
// If that fails, try after removing padding
|
||||
let unpadded = MessagePadding.unpad(data)
|
||||
if unpadded as NSData === data as NSData { return nil }
|
||||
return decodeCore(unpadded)
|
||||
}
|
||||
|
||||
static func fromBinaryPayload(_ data: Data) -> BitchatMessage? {
|
||||
// Create an immutable copy to prevent threading issues
|
||||
let dataCopy = Data(data)
|
||||
// Core decoding implementation used by decode(_:) with and without padding removal
|
||||
private static func decodeCore(_ raw: Data) -> BitchatPacket? {
|
||||
guard raw.count >= v1HeaderSize + senderIDSize else { return nil }
|
||||
|
||||
|
||||
guard dataCopy.count >= 13 else {
|
||||
return nil
|
||||
}
|
||||
|
||||
var offset = 0
|
||||
|
||||
// Flags
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let flags = dataCopy[offset]; offset += 1
|
||||
let isRelay = (flags & 0x01) != 0
|
||||
let isPrivate = (flags & 0x02) != 0
|
||||
let hasOriginalSender = (flags & 0x04) != 0
|
||||
let hasRecipientNickname = (flags & 0x08) != 0
|
||||
let hasSenderPeerID = (flags & 0x10) != 0
|
||||
let hasMentions = (flags & 0x20) != 0
|
||||
|
||||
// Timestamp
|
||||
guard offset + 8 <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let timestampData = dataCopy[offset..<offset+8]
|
||||
let timestampMillis = timestampData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt64(byte)
|
||||
}
|
||||
offset += 8
|
||||
let timestamp = Date(timeIntervalSince1970: TimeInterval(timestampMillis) / 1000.0)
|
||||
|
||||
// ID
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let idLength = Int(dataCopy[offset]); offset += 1
|
||||
guard offset + idLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let id = String(data: dataCopy[offset..<offset+idLength], encoding: .utf8) ?? UUID().uuidString
|
||||
offset += idLength
|
||||
|
||||
// Sender
|
||||
guard offset < dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let senderLength = Int(dataCopy[offset]); offset += 1
|
||||
guard offset + senderLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let sender = String(data: dataCopy[offset..<offset+senderLength], encoding: .utf8) ?? "unknown"
|
||||
offset += senderLength
|
||||
|
||||
// Content
|
||||
guard offset + 2 <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
let contentLengthData = dataCopy[offset..<offset+2]
|
||||
let contentLength = Int(contentLengthData.reduce(0) { result, byte in
|
||||
(result << 8) | UInt16(byte)
|
||||
})
|
||||
offset += 2
|
||||
guard offset + contentLength <= dataCopy.count else {
|
||||
return nil
|
||||
}
|
||||
|
||||
let content = String(data: dataCopy[offset..<offset+contentLength], encoding: .utf8) ?? ""
|
||||
offset += contentLength
|
||||
|
||||
// Optional fields
|
||||
var originalSender: String?
|
||||
if hasOriginalSender && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
originalSender = String(data: dataCopy[offset..<offset+length], encoding: .utf8)
|
||||
offset += length
|
||||
return raw.withUnsafeBytes { (buf: UnsafeRawBufferPointer) -> BitchatPacket? in
|
||||
guard let base = buf.baseAddress else { return nil }
|
||||
var offset = 0
|
||||
func require(_ n: Int) -> Bool { offset + n <= buf.count }
|
||||
func read8() -> UInt8? {
|
||||
guard require(1) else { return nil }
|
||||
let value = base.advanced(by: offset).assumingMemoryBound(to: UInt8.self).pointee
|
||||
offset += 1
|
||||
return value
|
||||
}
|
||||
}
|
||||
|
||||
var recipientNickname: String?
|
||||
if hasRecipientNickname && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
recipientNickname = String(data: dataCopy[offset..<offset+length], encoding: .utf8)
|
||||
offset += length
|
||||
func read16() -> UInt16? {
|
||||
guard require(2) else { return nil }
|
||||
let ptr = base.advanced(by: offset).assumingMemoryBound(to: UInt8.self)
|
||||
let value = (UInt16(ptr[0]) << 8) | UInt16(ptr[1])
|
||||
offset += 2
|
||||
return value
|
||||
}
|
||||
}
|
||||
|
||||
var senderPeerID: String?
|
||||
if hasSenderPeerID && offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
senderPeerID = String(data: dataCopy[offset..<offset+length], encoding: .utf8)
|
||||
offset += length
|
||||
func read32() -> UInt32? {
|
||||
guard require(4) else { return nil }
|
||||
let ptr = base.advanced(by: offset).assumingMemoryBound(to: UInt8.self)
|
||||
let value = (UInt32(ptr[0]) << 24) | (UInt32(ptr[1]) << 16) | (UInt32(ptr[2]) << 8) | UInt32(ptr[3])
|
||||
offset += 4
|
||||
return value
|
||||
}
|
||||
func readData(_ n: Int) -> Data? {
|
||||
guard require(n) else { return nil }
|
||||
let ptr = base.advanced(by: offset)
|
||||
let data = Data(bytes: ptr, count: n)
|
||||
offset += n
|
||||
return data
|
||||
}
|
||||
}
|
||||
|
||||
// Mentions array
|
||||
var mentions: [String]?
|
||||
if hasMentions && offset < dataCopy.count {
|
||||
let mentionCount = Int(dataCopy[offset]); offset += 1
|
||||
if mentionCount > 0 {
|
||||
mentions = []
|
||||
for _ in 0..<mentionCount {
|
||||
if offset < dataCopy.count {
|
||||
let length = Int(dataCopy[offset]); offset += 1
|
||||
if offset + length <= dataCopy.count {
|
||||
if let mention = String(data: dataCopy[offset..<offset+length], encoding: .utf8) {
|
||||
mentions?.append(mention)
|
||||
}
|
||||
offset += length
|
||||
}
|
||||
guard let version = read8(), version == 1 || version == 2 else { return nil }
|
||||
let lengthFieldBytes = lengthFieldSize(for: version)
|
||||
guard let headerSize = headerSize(for: version) else { return nil }
|
||||
let minimumRequired = headerSize + senderIDSize
|
||||
guard raw.count >= minimumRequired else { return nil }
|
||||
|
||||
guard let type = read8(), let ttl = read8() else { return nil }
|
||||
|
||||
var timestamp: UInt64 = 0
|
||||
for _ in 0..<8 {
|
||||
guard let byte = read8() else { return nil }
|
||||
timestamp = (timestamp << 8) | UInt64(byte)
|
||||
}
|
||||
|
||||
guard let flags = read8() else { return nil }
|
||||
let hasRecipient = (flags & Flags.hasRecipient) != 0
|
||||
let hasSignature = (flags & Flags.hasSignature) != 0
|
||||
let isCompressed = (flags & Flags.isCompressed) != 0
|
||||
// HAS_ROUTE is only valid for v2+ packets; ignore the flag for v1
|
||||
let hasRoute = (version >= 2) && (flags & Flags.hasRoute) != 0
|
||||
let isRSR = (flags & Flags.isRSR) != 0
|
||||
|
||||
let payloadLength: Int
|
||||
if version == 2 {
|
||||
guard let len = read32() else { return nil }
|
||||
payloadLength = Int(len)
|
||||
} else {
|
||||
guard let len = read16() else { return nil }
|
||||
payloadLength = Int(len)
|
||||
}
|
||||
|
||||
guard payloadLength >= 0 else { return nil }
|
||||
guard payloadLength <= FileTransferLimits.maxFramedFileBytes else { return nil }
|
||||
|
||||
guard let senderID = readData(senderIDSize) else { return nil }
|
||||
|
||||
var recipientID: Data? = nil
|
||||
if hasRecipient {
|
||||
recipientID = readData(recipientIDSize)
|
||||
if recipientID == nil { return nil }
|
||||
}
|
||||
|
||||
// Route (optional, v2+ only): route bytes are NOT included in payloadLength
|
||||
var route: [Data]? = nil
|
||||
if hasRoute {
|
||||
guard let routeCount = read8() else { return nil }
|
||||
if routeCount > 0 {
|
||||
var hops: [Data] = []
|
||||
for _ in 0..<Int(routeCount) {
|
||||
guard let hop = readData(senderIDSize) else { return nil }
|
||||
hops.append(hop)
|
||||
}
|
||||
route = hops
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let message = BitchatMessage(
|
||||
id: id,
|
||||
sender: sender,
|
||||
content: content,
|
||||
timestamp: timestamp,
|
||||
isRelay: isRelay,
|
||||
originalSender: originalSender,
|
||||
isPrivate: isPrivate,
|
||||
recipientNickname: recipientNickname,
|
||||
senderPeerID: senderPeerID,
|
||||
mentions: mentions
|
||||
)
|
||||
return message
|
||||
// Payload: payloadLength is exactly the payload size (+ compression preamble if compressed)
|
||||
let payload: Data
|
||||
if isCompressed {
|
||||
guard payloadLength >= lengthFieldBytes else { return nil }
|
||||
let originalSize: Int
|
||||
if version == 2 {
|
||||
guard let rawSize = read32() else { return nil }
|
||||
originalSize = Int(rawSize)
|
||||
} else {
|
||||
guard let rawSize = read16() else { return nil }
|
||||
originalSize = Int(rawSize)
|
||||
}
|
||||
guard originalSize >= 0 && originalSize <= FileTransferLimits.maxFramedFileBytes else { return nil }
|
||||
let compressedSize = payloadLength - lengthFieldBytes
|
||||
guard compressedSize > 0, let compressed = readData(compressedSize) else { return nil }
|
||||
|
||||
let compressionRatio = Double(originalSize) / Double(compressedSize)
|
||||
guard compressionRatio <= 50_000.0 else {
|
||||
SecureLogger.warning("🚫 Suspicious compression ratio: \(String(format: "%.0f", compressionRatio)):1", category: .security)
|
||||
return nil
|
||||
}
|
||||
|
||||
guard let decompressed = CompressionUtil.decompress(compressed, originalSize: originalSize),
|
||||
decompressed.count == originalSize else { return nil }
|
||||
payload = decompressed
|
||||
} else {
|
||||
guard let rawPayload = readData(payloadLength) else { return nil }
|
||||
payload = rawPayload
|
||||
}
|
||||
|
||||
var signature: Data? = nil
|
||||
if hasSignature {
|
||||
signature = readData(signatureSize)
|
||||
if signature == nil { return nil }
|
||||
}
|
||||
|
||||
guard offset <= buf.count else { return nil }
|
||||
|
||||
return BitchatPacket(
|
||||
type: type,
|
||||
senderID: senderID,
|
||||
recipientID: recipientID,
|
||||
timestamp: timestamp,
|
||||
payload: payload,
|
||||
signature: signature,
|
||||
ttl: ttl,
|
||||
version: version,
|
||||
route: route,
|
||||
isRSR: isRSR
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,155 @@
|
||||
//
|
||||
// BitchatFilePacket.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import BitLogger
|
||||
|
||||
/// TLV payload for Bluetooth mesh file transfers (voice notes, images, generic files).
|
||||
/// Mirrors the Android client specification to ensure cross-platform interoperability.
|
||||
struct BitchatFilePacket {
|
||||
var fileName: String?
|
||||
var fileSize: UInt64?
|
||||
var mimeType: String?
|
||||
var content: Data
|
||||
|
||||
/// Canonical TLV tags defined by the Android implementation.
|
||||
private enum TLVType: UInt8 {
|
||||
case fileName = 0x01
|
||||
case fileSize = 0x02
|
||||
case mimeType = 0x03
|
||||
case content = 0x04
|
||||
}
|
||||
|
||||
/// Encodes the packet using v2 canonical TLVs (4-byte FILE_SIZE, 4-byte CONTENT length).
|
||||
/// Returns `nil` when fields exceed protocol limits (e.g., content > UInt32.max).
|
||||
func encode() -> Data? {
|
||||
let resolvedSize = fileSize ?? UInt64(content.count)
|
||||
guard resolvedSize <= UInt64(UInt32.max) else { return nil }
|
||||
guard resolvedSize <= UInt64(FileTransferLimits.maxPayloadBytes) else { return nil }
|
||||
guard content.count <= Int(UInt32.max) else { return nil }
|
||||
guard FileTransferLimits.isValidPayload(content.count) else { return nil }
|
||||
|
||||
func appendBE<T: FixedWidthInteger>(_ value: T, into data: inout Data) {
|
||||
var big = value.bigEndian
|
||||
withUnsafeBytes(of: &big) { data.append(contentsOf: $0) }
|
||||
}
|
||||
|
||||
var encoded = Data()
|
||||
|
||||
if let name = fileName, let nameData = name.data(using: .utf8), nameData.count <= Int(UInt16.max) {
|
||||
encoded.append(TLVType.fileName.rawValue)
|
||||
appendBE(UInt16(nameData.count), into: &encoded)
|
||||
encoded.append(nameData)
|
||||
}
|
||||
|
||||
encoded.append(TLVType.fileSize.rawValue)
|
||||
appendBE(UInt16(4), into: &encoded)
|
||||
appendBE(UInt32(resolvedSize), into: &encoded)
|
||||
|
||||
if let mime = mimeType, let mimeData = mime.data(using: .utf8), mimeData.count <= Int(UInt16.max) {
|
||||
encoded.append(TLVType.mimeType.rawValue)
|
||||
appendBE(UInt16(mimeData.count), into: &encoded)
|
||||
encoded.append(mimeData)
|
||||
}
|
||||
|
||||
encoded.append(TLVType.content.rawValue)
|
||||
appendBE(UInt32(content.count), into: &encoded)
|
||||
encoded.append(content)
|
||||
|
||||
return encoded
|
||||
}
|
||||
|
||||
/// Decodes TLV payloads, tolerating legacy encodings (FILE_SIZE len=8, CONTENT len=2) when possible.
|
||||
static func decode(_ data: Data) -> BitchatFilePacket? {
|
||||
var cursor = data.startIndex
|
||||
let end = data.endIndex
|
||||
|
||||
var fileName: String?
|
||||
var fileSize: UInt64?
|
||||
var mimeType: String?
|
||||
var content = Data()
|
||||
|
||||
while cursor < end {
|
||||
let typeRaw = data[cursor]
|
||||
cursor = data.index(after: cursor)
|
||||
|
||||
guard cursor <= end else { return nil }
|
||||
let tlvType = TLVType(rawValue: typeRaw)
|
||||
|
||||
func readBigEndianLength(bytes: Int) -> Int? {
|
||||
guard data.distance(from: cursor, to: end) >= bytes else { return nil }
|
||||
// Use UInt64 to prevent integer overflow during shift operations
|
||||
var result: UInt64 = 0
|
||||
for _ in 0..<bytes {
|
||||
result = (result << 8) | UInt64(data[cursor])
|
||||
cursor = data.index(after: cursor)
|
||||
}
|
||||
// Safely convert to Int with overflow check
|
||||
guard result <= Int.max else { return nil }
|
||||
return Int(result)
|
||||
}
|
||||
|
||||
let length: Int?
|
||||
if tlvType == .content {
|
||||
let snapshot = cursor
|
||||
let canonical = readBigEndianLength(bytes: 4)
|
||||
if let canonical = canonical,
|
||||
canonical <= data.distance(from: cursor, to: end) {
|
||||
length = canonical
|
||||
} else {
|
||||
cursor = snapshot
|
||||
length = readBigEndianLength(bytes: 2)
|
||||
}
|
||||
} else {
|
||||
length = readBigEndianLength(bytes: 2)
|
||||
}
|
||||
|
||||
guard let tlvLength = length, tlvLength >= 0 else { return nil }
|
||||
guard data.distance(from: cursor, to: end) >= tlvLength else { return nil }
|
||||
|
||||
let valueStart = cursor
|
||||
cursor = data.index(cursor, offsetBy: tlvLength)
|
||||
let value = data[valueStart..<cursor]
|
||||
|
||||
switch tlvType {
|
||||
case .fileName:
|
||||
fileName = String(data: Data(value), encoding: .utf8)
|
||||
case .fileSize:
|
||||
if tlvLength == 4 || tlvLength == 8 {
|
||||
var size: UInt64 = 0
|
||||
for byte in value {
|
||||
size = (size << 8) | UInt64(byte)
|
||||
}
|
||||
if size > UInt64(FileTransferLimits.maxPayloadBytes) {
|
||||
return nil
|
||||
}
|
||||
fileSize = size
|
||||
}
|
||||
case .mimeType:
|
||||
mimeType = String(data: Data(value), encoding: .utf8)
|
||||
case .content:
|
||||
let proposedSize = content.count + value.count
|
||||
if proposedSize > FileTransferLimits.maxPayloadBytes {
|
||||
return nil
|
||||
}
|
||||
content.append(contentsOf: value)
|
||||
case nil:
|
||||
continue
|
||||
}
|
||||
}
|
||||
|
||||
guard !content.isEmpty else { return nil }
|
||||
guard FileTransferLimits.isValidPayload(content.count) else { return nil }
|
||||
return BitchatFilePacket(
|
||||
fileName: fileName,
|
||||
fileSize: fileSize ?? UInt64(content.count),
|
||||
mimeType: mimeType,
|
||||
content: content
|
||||
)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,175 @@
|
||||
import Foundation
|
||||
|
||||
/// Lightweight Geohash encoder used for Location Channels.
|
||||
/// Encodes latitude/longitude to base32 geohash with a fixed precision.
|
||||
enum Geohash {
|
||||
private static let base32Chars = Array("0123456789bcdefghjkmnpqrstuvwxyz")
|
||||
private static let base32Map: [Character: Int] = {
|
||||
var map: [Character: Int] = [:]
|
||||
for (i, c) in base32Chars.enumerated() { map[c] = i }
|
||||
return map
|
||||
}()
|
||||
|
||||
/// Validates a geohash string for building-level precision (8 characters).
|
||||
/// - Parameter geohash: The geohash string to validate
|
||||
/// - Returns: true if valid 8-character base32 geohash, false otherwise
|
||||
static func isValidBuildingGeohash(_ geohash: String) -> Bool {
|
||||
guard geohash.count == 8 else { return false }
|
||||
return geohash.lowercased().allSatisfy { base32Map[$0] != nil }
|
||||
}
|
||||
|
||||
/// Encodes the provided coordinates into a geohash string.
|
||||
/// - Parameters:
|
||||
/// - latitude: Latitude in degrees (-90...90)
|
||||
/// - longitude: Longitude in degrees (-180...180)
|
||||
/// - precision: Number of geohash characters (2-12 typical). Values <= 0 return an empty string.
|
||||
/// - Returns: Base32 geohash string of length `precision`.
|
||||
static func encode(latitude: Double, longitude: Double, precision: Int) -> String {
|
||||
guard precision > 0 else { return "" }
|
||||
|
||||
var latInterval: (Double, Double) = (-90.0, 90.0)
|
||||
var lonInterval: (Double, Double) = (-180.0, 180.0)
|
||||
|
||||
var isEven = true
|
||||
var bit = 0
|
||||
var ch = 0
|
||||
var geohash: [Character] = []
|
||||
|
||||
let lat = max(-90.0, min(90.0, latitude))
|
||||
let lon = max(-180.0, min(180.0, longitude))
|
||||
|
||||
while geohash.count < precision {
|
||||
if isEven {
|
||||
let mid = (lonInterval.0 + lonInterval.1) / 2
|
||||
if lon >= mid {
|
||||
ch |= (1 << (4 - bit))
|
||||
lonInterval.0 = mid
|
||||
} else {
|
||||
lonInterval.1 = mid
|
||||
}
|
||||
} else {
|
||||
let mid = (latInterval.0 + latInterval.1) / 2
|
||||
if lat >= mid {
|
||||
ch |= (1 << (4 - bit))
|
||||
latInterval.0 = mid
|
||||
} else {
|
||||
latInterval.1 = mid
|
||||
}
|
||||
}
|
||||
|
||||
isEven.toggle()
|
||||
if bit < 4 {
|
||||
bit += 1
|
||||
} else {
|
||||
geohash.append(base32Chars[ch])
|
||||
bit = 0
|
||||
ch = 0
|
||||
}
|
||||
}
|
||||
|
||||
return String(geohash)
|
||||
}
|
||||
|
||||
/// Decodes a geohash into the center latitude/longitude of its bounding box.
|
||||
/// - Parameter geohash: Base32 geohash string.
|
||||
/// - Returns: (lat, lon) center coordinate.
|
||||
static func decodeCenter(_ geohash: String) -> (lat: Double, lon: Double) {
|
||||
var latInterval: (Double, Double) = (-90.0, 90.0)
|
||||
var lonInterval: (Double, Double) = (-180.0, 180.0)
|
||||
|
||||
var isEven = true
|
||||
for ch in geohash.lowercased() {
|
||||
guard let cd = base32Map[ch] else { continue }
|
||||
for mask in [16, 8, 4, 2, 1] {
|
||||
if isEven {
|
||||
let mid = (lonInterval.0 + lonInterval.1) / 2
|
||||
if (cd & mask) != 0 { lonInterval.0 = mid } else { lonInterval.1 = mid }
|
||||
} else {
|
||||
let mid = (latInterval.0 + latInterval.1) / 2
|
||||
if (cd & mask) != 0 { latInterval.0 = mid } else { latInterval.1 = mid }
|
||||
}
|
||||
isEven.toggle()
|
||||
}
|
||||
}
|
||||
let lat = (latInterval.0 + latInterval.1) / 2
|
||||
let lon = (lonInterval.0 + lonInterval.1) / 2
|
||||
return (lat, lon)
|
||||
}
|
||||
|
||||
/// Decodes a geohash into its latitude and longitude bounds.
|
||||
/// - Parameter geohash: Base32 geohash string.
|
||||
/// - Returns: (latMin, latMax, lonMin, lonMax)
|
||||
static func decodeBounds(_ geohash: String) -> (latMin: Double, latMax: Double, lonMin: Double, lonMax: Double) {
|
||||
var latInterval: (Double, Double) = (-90.0, 90.0)
|
||||
var lonInterval: (Double, Double) = (-180.0, 180.0)
|
||||
|
||||
var isEven = true
|
||||
for ch in geohash.lowercased() {
|
||||
guard let cd = base32Map[ch] else { continue }
|
||||
for mask in [16, 8, 4, 2, 1] {
|
||||
if isEven {
|
||||
let mid = (lonInterval.0 + lonInterval.1) / 2
|
||||
if (cd & mask) != 0 { lonInterval.0 = mid } else { lonInterval.1 = mid }
|
||||
} else {
|
||||
let mid = (latInterval.0 + latInterval.1) / 2
|
||||
if (cd & mask) != 0 { latInterval.0 = mid } else { latInterval.1 = mid }
|
||||
}
|
||||
isEven.toggle()
|
||||
}
|
||||
}
|
||||
return (latInterval.0, latInterval.1, lonInterval.0, lonInterval.1)
|
||||
}
|
||||
|
||||
/// Returns all 8 neighboring geohash cells at the same precision.
|
||||
/// - Parameter geohash: Base32 geohash string.
|
||||
/// - Returns: Array of 8 neighboring geohashes (N, NE, E, SE, S, SW, W, NW order).
|
||||
static func neighbors(of geohash: String) -> [String] {
|
||||
guard !geohash.isEmpty else { return [] }
|
||||
|
||||
let precision = geohash.count
|
||||
let bounds = decodeBounds(geohash)
|
||||
let center = decodeCenter(geohash)
|
||||
|
||||
// Calculate cell dimensions
|
||||
let latHeight = bounds.latMax - bounds.latMin
|
||||
let lonWidth = bounds.lonMax - bounds.lonMin
|
||||
|
||||
// Helper to wrap longitude around ±180
|
||||
func wrapLongitude(_ lon: Double) -> Double {
|
||||
var wrapped = lon
|
||||
while wrapped > 180.0 { wrapped -= 360.0 }
|
||||
while wrapped < -180.0 { wrapped += 360.0 }
|
||||
return wrapped
|
||||
}
|
||||
|
||||
// Helper to clamp latitude to ±90
|
||||
func clampLatitude(_ lat: Double) -> Double {
|
||||
return max(-90.0, min(90.0, lat))
|
||||
}
|
||||
|
||||
// Calculate 8 neighbor centers
|
||||
let neighbors: [(lat: Double, lon: Double)] = [
|
||||
(center.lat + latHeight, center.lon), // N
|
||||
(center.lat + latHeight, center.lon + lonWidth), // NE
|
||||
(center.lat, center.lon + lonWidth), // E
|
||||
(center.lat - latHeight, center.lon + lonWidth), // SE
|
||||
(center.lat - latHeight, center.lon), // S
|
||||
(center.lat - latHeight, center.lon - lonWidth), // SW
|
||||
(center.lat, center.lon - lonWidth), // W
|
||||
(center.lat + latHeight, center.lon - lonWidth) // NW
|
||||
]
|
||||
|
||||
// Encode each neighbor, handling boundary conditions
|
||||
return neighbors.compactMap { neighbor in
|
||||
let lat = clampLatitude(neighbor.lat)
|
||||
let lon = wrapLongitude(neighbor.lon)
|
||||
|
||||
// Skip if we've crossed a pole (latitude clamped to boundary)
|
||||
if (neighbor.lat > 90.0 || neighbor.lat < -90.0) {
|
||||
return nil
|
||||
}
|
||||
|
||||
return encode(latitude: lat, longitude: lon, precision: precision)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,133 @@
|
||||
import Foundation
|
||||
|
||||
/// Levels of location channels mapped to geohash precisions.
|
||||
enum GeohashChannelLevel: CaseIterable, Codable, Equatable {
|
||||
case building
|
||||
case block
|
||||
case neighborhood
|
||||
case city
|
||||
case province // previously .region
|
||||
case region // previously .country
|
||||
|
||||
/// Geohash length used for this level.
|
||||
var precision: Int {
|
||||
switch self {
|
||||
case .building: return 8
|
||||
case .block: return 7
|
||||
case .neighborhood: return 6
|
||||
case .city: return 5
|
||||
case .province: return 4
|
||||
case .region: return 2
|
||||
}
|
||||
}
|
||||
|
||||
var displayName: String {
|
||||
switch self {
|
||||
case .building:
|
||||
return String(localized: "location_levels.building", comment: "Name for building-level location channel")
|
||||
case .block:
|
||||
return String(localized: "location_levels.block", comment: "Name for block-level location channel")
|
||||
case .neighborhood:
|
||||
return String(localized: "location_levels.neighborhood", comment: "Name for neighborhood-level location channel")
|
||||
case .city:
|
||||
return String(localized: "location_levels.city", comment: "Name for city-level location channel")
|
||||
case .province:
|
||||
return String(localized: "location_levels.province", comment: "Name for province-level location channel")
|
||||
case .region:
|
||||
return String(localized: "location_levels.region", comment: "Name for region-level location channel")
|
||||
}
|
||||
}
|
||||
}
|
||||
// Backward-compatible Codable for renamed cases
|
||||
extension GeohashChannelLevel {
|
||||
init(from decoder: Decoder) throws {
|
||||
let container = try decoder.singleValueContainer()
|
||||
if let raw = try? container.decode(String.self) {
|
||||
switch raw {
|
||||
case "building": self = .building
|
||||
case "block": self = .block
|
||||
case "neighborhood": self = .neighborhood
|
||||
case "city": self = .city
|
||||
case "region": self = .province // old "region" maps to new .province
|
||||
case "country": self = .region // old "country" maps to new .region
|
||||
case "province": self = .province
|
||||
default:
|
||||
self = .block
|
||||
}
|
||||
} else if let precision = try? container.decode(Int.self) {
|
||||
switch precision {
|
||||
case 8: self = .building
|
||||
case 7: self = .block
|
||||
case 6: self = .neighborhood
|
||||
case 5: self = .city
|
||||
case 4: self = .province
|
||||
case 0...3: self = .region
|
||||
default: self = .block
|
||||
}
|
||||
} else {
|
||||
self = .block
|
||||
}
|
||||
}
|
||||
|
||||
func encode(to encoder: Encoder) throws {
|
||||
var container = encoder.singleValueContainer()
|
||||
switch self {
|
||||
case .building: try container.encode("building")
|
||||
case .block: try container.encode("block")
|
||||
case .neighborhood: try container.encode("neighborhood")
|
||||
case .city: try container.encode("city")
|
||||
case .province: try container.encode("province")
|
||||
case .region: try container.encode("region")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// A computed geohash channel option.
|
||||
struct GeohashChannel: Codable, Equatable, Hashable, Identifiable {
|
||||
let level: GeohashChannelLevel
|
||||
let geohash: String
|
||||
|
||||
var id: String { "\(level)-\(geohash)" }
|
||||
|
||||
var displayName: String {
|
||||
"\(level.displayName) • \(geohash)"
|
||||
}
|
||||
}
|
||||
|
||||
/// Identifier for current public chat channel (mesh or a location geohash).
|
||||
enum ChannelID: Equatable, Codable {
|
||||
case mesh
|
||||
case location(GeohashChannel)
|
||||
|
||||
/// Human readable name for UI.
|
||||
var displayName: String {
|
||||
switch self {
|
||||
case .mesh:
|
||||
return "Mesh"
|
||||
case .location(let ch):
|
||||
return ch.displayName
|
||||
}
|
||||
}
|
||||
|
||||
/// Nostr tag value for scoping (geohash), if applicable.
|
||||
var nostrGeohashTag: String? {
|
||||
switch self {
|
||||
case .mesh: return nil
|
||||
case .location(let ch): return ch.geohash
|
||||
}
|
||||
}
|
||||
|
||||
var isMesh: Bool {
|
||||
switch self {
|
||||
case .mesh: true
|
||||
case .location: false
|
||||
}
|
||||
}
|
||||
|
||||
var isLocation: Bool {
|
||||
switch self {
|
||||
case .mesh: false
|
||||
case .location: true
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,162 @@
|
||||
import Foundation
|
||||
|
||||
// MARK: - Protocol TLV Packets
|
||||
|
||||
struct AnnouncementPacket {
|
||||
let nickname: String
|
||||
let noisePublicKey: Data // Noise static public key (Curve25519.KeyAgreement)
|
||||
let signingPublicKey: Data // Ed25519 public key for signing
|
||||
let directNeighbors: [Data]? // 8-byte peer IDs
|
||||
|
||||
private enum TLVType: UInt8 {
|
||||
case nickname = 0x01
|
||||
case noisePublicKey = 0x02
|
||||
case signingPublicKey = 0x03
|
||||
case directNeighbors = 0x04
|
||||
}
|
||||
|
||||
func encode() -> Data? {
|
||||
var data = Data()
|
||||
// Reserve: TLVs for nickname (2 + n), noise key (2 + 32), signing key (2 + 32)
|
||||
data.reserveCapacity(2 + min(nickname.count, 255) + 2 + noisePublicKey.count + 2 + signingPublicKey.count)
|
||||
|
||||
// TLV for nickname
|
||||
guard let nicknameData = nickname.data(using: .utf8), nicknameData.count <= 255 else { return nil }
|
||||
data.append(TLVType.nickname.rawValue)
|
||||
data.append(UInt8(nicknameData.count))
|
||||
data.append(nicknameData)
|
||||
|
||||
// TLV for noise public key
|
||||
guard noisePublicKey.count <= 255 else { return nil }
|
||||
data.append(TLVType.noisePublicKey.rawValue)
|
||||
data.append(UInt8(noisePublicKey.count))
|
||||
data.append(noisePublicKey)
|
||||
|
||||
// TLV for signing public key
|
||||
guard signingPublicKey.count <= 255 else { return nil }
|
||||
data.append(TLVType.signingPublicKey.rawValue)
|
||||
data.append(UInt8(signingPublicKey.count))
|
||||
data.append(signingPublicKey)
|
||||
|
||||
// TLV for direct neighbors (optional)
|
||||
if let neighbors = directNeighbors, !neighbors.isEmpty {
|
||||
let neighborsData = neighbors.prefix(10).reduce(Data()) { $0 + $1 }
|
||||
if !neighborsData.isEmpty && neighborsData.count % 8 == 0 {
|
||||
data.append(TLVType.directNeighbors.rawValue)
|
||||
data.append(UInt8(neighborsData.count))
|
||||
data.append(neighborsData)
|
||||
}
|
||||
}
|
||||
|
||||
return data
|
||||
}
|
||||
|
||||
static func decode(from data: Data) -> AnnouncementPacket? {
|
||||
var offset = 0
|
||||
var nickname: String?
|
||||
var noisePublicKey: Data?
|
||||
var signingPublicKey: Data?
|
||||
var directNeighbors: [Data]?
|
||||
|
||||
while offset + 2 <= data.count {
|
||||
let typeRaw = data[offset]
|
||||
offset += 1
|
||||
let length = Int(data[offset])
|
||||
offset += 1
|
||||
|
||||
guard offset + length <= data.count else { return nil }
|
||||
let value = data[offset..<offset + length]
|
||||
offset += length
|
||||
|
||||
if let type = TLVType(rawValue: typeRaw) {
|
||||
switch type {
|
||||
case .nickname:
|
||||
nickname = String(data: value, encoding: .utf8)
|
||||
case .noisePublicKey:
|
||||
noisePublicKey = Data(value)
|
||||
case .signingPublicKey:
|
||||
signingPublicKey = Data(value)
|
||||
case .directNeighbors:
|
||||
if length > 0 && length % 8 == 0 {
|
||||
var neighbors = [Data]()
|
||||
let count = length / 8
|
||||
for i in 0..<count {
|
||||
let start = value.startIndex + i * 8
|
||||
let end = start + 8
|
||||
neighbors.append(Data(value[start..<end]))
|
||||
}
|
||||
directNeighbors = neighbors
|
||||
}
|
||||
}
|
||||
} else {
|
||||
// Unknown TLV; skip (tolerant decoder for forward compatibility)
|
||||
continue
|
||||
}
|
||||
}
|
||||
|
||||
guard let nickname = nickname, let noisePublicKey = noisePublicKey, let signingPublicKey = signingPublicKey else { return nil }
|
||||
return AnnouncementPacket(
|
||||
nickname: nickname,
|
||||
noisePublicKey: noisePublicKey,
|
||||
signingPublicKey: signingPublicKey,
|
||||
directNeighbors: directNeighbors
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
struct PrivateMessagePacket {
|
||||
let messageID: String
|
||||
let content: String
|
||||
|
||||
private enum TLVType: UInt8 {
|
||||
case messageID = 0x00
|
||||
case content = 0x01
|
||||
}
|
||||
|
||||
func encode() -> Data? {
|
||||
var data = Data()
|
||||
data.reserveCapacity(2 + min(messageID.count, 255) + 2 + min(content.count, 255))
|
||||
|
||||
// TLV for messageID
|
||||
guard let messageIDData = messageID.data(using: .utf8), messageIDData.count <= 255 else { return nil }
|
||||
data.append(TLVType.messageID.rawValue)
|
||||
data.append(UInt8(messageIDData.count))
|
||||
data.append(messageIDData)
|
||||
|
||||
// TLV for content
|
||||
guard let contentData = content.data(using: .utf8), contentData.count <= 255 else { return nil }
|
||||
data.append(TLVType.content.rawValue)
|
||||
data.append(UInt8(contentData.count))
|
||||
data.append(contentData)
|
||||
|
||||
return data
|
||||
}
|
||||
|
||||
static func decode(from data: Data) -> PrivateMessagePacket? {
|
||||
var offset = 0
|
||||
var messageID: String?
|
||||
var content: String?
|
||||
|
||||
while offset + 2 <= data.count {
|
||||
guard let type = TLVType(rawValue: data[offset]) else { return nil }
|
||||
offset += 1
|
||||
|
||||
let length = Int(data[offset])
|
||||
offset += 1
|
||||
|
||||
guard offset + length <= data.count else { return nil }
|
||||
let value = data[offset..<offset + length]
|
||||
offset += length
|
||||
|
||||
switch type {
|
||||
case .messageID:
|
||||
messageID = String(data: value, encoding: .utf8)
|
||||
case .content:
|
||||
content = String(data: value, encoding: .utf8)
|
||||
}
|
||||
}
|
||||
|
||||
guard let messageID = messageID, let content = content else { return nil }
|
||||
return PrivateMessagePacket(messageID: messageID, content: content)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,104 @@
|
||||
//
|
||||
// AutocompleteService.swift
|
||||
// bitchat
|
||||
//
|
||||
// Handles autocomplete suggestions for mentions and commands
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
/// Manages autocomplete functionality for chat
|
||||
final class AutocompleteService {
|
||||
private let mentionRegex = try? NSRegularExpression(pattern: "@([\\p{L}0-9_]*)$", options: [])
|
||||
private let commandRegex = try? NSRegularExpression(pattern: "^/([a-z]*)$", options: [])
|
||||
|
||||
private let commands = [
|
||||
"/msg", "/who", "/clear",
|
||||
"/hug", "/slap", "/fav", "/unfav",
|
||||
"/block", "/unblock"
|
||||
]
|
||||
|
||||
/// Get autocomplete suggestions for current text
|
||||
func getSuggestions(for text: String, peers: [String], cursorPosition: Int) -> (suggestions: [String], range: NSRange?) {
|
||||
let textToPosition = String(text.prefix(cursorPosition))
|
||||
|
||||
// Check for mention autocomplete
|
||||
if let (mentionSuggestions, mentionRange) = getMentionSuggestions(textToPosition, peers: peers) {
|
||||
return (mentionSuggestions, mentionRange)
|
||||
}
|
||||
|
||||
// Don't handle command autocomplete here - ContentView handles it with better UI
|
||||
// if let (commandSuggestions, commandRange) = getCommandSuggestions(textToPosition) {
|
||||
// return (commandSuggestions, commandRange)
|
||||
// }
|
||||
|
||||
return ([], nil)
|
||||
}
|
||||
|
||||
/// Apply selected suggestion to text
|
||||
func applySuggestion(_ suggestion: String, to text: String, range: NSRange) -> String {
|
||||
guard let textRange = Range(range, in: text) else { return text }
|
||||
|
||||
var replacement = suggestion
|
||||
|
||||
// Add space after command if it takes arguments
|
||||
if suggestion.hasPrefix("/") && needsArgument(command: suggestion) {
|
||||
replacement += " "
|
||||
}
|
||||
|
||||
return text.replacingCharacters(in: textRange, with: replacement)
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func getMentionSuggestions(_ text: String, peers: [String]) -> ([String], NSRange)? {
|
||||
guard let regex = mentionRegex else { return nil }
|
||||
|
||||
let nsText = text as NSString
|
||||
let matches = regex.matches(in: text, options: [], range: NSRange(location: 0, length: nsText.length))
|
||||
|
||||
guard let match = matches.last else { return nil }
|
||||
|
||||
let fullRange = match.range(at: 0)
|
||||
let captureRange = match.range(at: 1)
|
||||
let prefix = nsText.substring(with: captureRange).lowercased()
|
||||
|
||||
let suggestions = peers
|
||||
.filter { $0.lowercased().hasPrefix(prefix) }
|
||||
.sorted()
|
||||
.prefix(5)
|
||||
.map { "@\($0)" }
|
||||
|
||||
return suggestions.isEmpty ? nil : (Array(suggestions), fullRange)
|
||||
}
|
||||
|
||||
private func getCommandSuggestions(_ text: String) -> ([String], NSRange)? {
|
||||
guard let regex = commandRegex else { return nil }
|
||||
|
||||
let nsText = text as NSString
|
||||
let matches = regex.matches(in: text, options: [], range: NSRange(location: 0, length: nsText.length))
|
||||
|
||||
guard let match = matches.last else { return nil }
|
||||
|
||||
let fullRange = match.range(at: 0)
|
||||
let captureRange = match.range(at: 1)
|
||||
let prefix = nsText.substring(with: captureRange).lowercased()
|
||||
|
||||
let suggestions = commands
|
||||
.filter { $0.hasPrefix("/\(prefix)") }
|
||||
.sorted()
|
||||
.prefix(5)
|
||||
|
||||
return suggestions.isEmpty ? nil : (Array(suggestions), fullRange)
|
||||
}
|
||||
|
||||
private func needsArgument(command: String) -> Bool {
|
||||
switch command {
|
||||
case "/who", "/clear":
|
||||
return false
|
||||
default:
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,212 @@
|
||||
//
|
||||
// MimeType.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import UniformTypeIdentifiers
|
||||
|
||||
// MARK: - Extensions for missing UTTypes
|
||||
|
||||
extension UTType {
|
||||
static let webP = UTType(importedAs: "image/webp")
|
||||
static let aac = UTType(importedAs: "audio/aac")
|
||||
static let m4a = UTType(importedAs: "audio/m4a")
|
||||
static let ogg = UTType(importedAs: "audio/ogg")
|
||||
}
|
||||
|
||||
// MARK: - MimeType Enum
|
||||
|
||||
enum MimeType: CaseIterable, Hashable {
|
||||
case jpeg
|
||||
case jpg
|
||||
case png
|
||||
case gif
|
||||
case webp
|
||||
case mp4Audio
|
||||
case m4a
|
||||
case aac
|
||||
case mpeg
|
||||
case mp3
|
||||
case wav
|
||||
case xWav
|
||||
case ogg
|
||||
case pdf
|
||||
case octetStream
|
||||
|
||||
var utType: UTType {
|
||||
switch self {
|
||||
case .jpeg, .jpg: .jpeg
|
||||
case .png: .png
|
||||
case .gif: .gif
|
||||
case .webp: .webP
|
||||
case .aac: .aac
|
||||
case .m4a: .m4a
|
||||
case .mp4Audio: .mpeg4Audio
|
||||
case .mp3, .mpeg: .mp3
|
||||
case .wav, .xWav: .wav
|
||||
case .ogg: .ogg
|
||||
case .pdf: .pdf
|
||||
case .octetStream: .data
|
||||
}
|
||||
}
|
||||
|
||||
var category: Category {
|
||||
switch self {
|
||||
case .jpeg, .jpg, .png, .gif, .webp:
|
||||
return .image
|
||||
case .aac, .m4a, .mp4Audio, .mpeg, .mp3, .wav, .xWav, .ogg:
|
||||
return .audio
|
||||
case .pdf, .octetStream:
|
||||
return .file
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
var mimeString: String {
|
||||
switch self {
|
||||
case .jpeg, .jpg: "image/jpeg"
|
||||
case .png: "image/png"
|
||||
case .gif: "image/gif"
|
||||
case .webp: "image/webp"
|
||||
case .mp4Audio: "audio/mp4"
|
||||
case .m4a: "audio/m4a"
|
||||
case .aac: "audio/aac"
|
||||
case .mpeg: "audio/mpeg"
|
||||
case .mp3: "audio/mp3"
|
||||
case .wav: "audio/wav"
|
||||
case .xWav: "audio/x-wav"
|
||||
case .ogg: "audio/ogg"
|
||||
case .pdf: "application/pdf"
|
||||
case .octetStream: "application/octet-stream"
|
||||
}
|
||||
}
|
||||
|
||||
var defaultExtension: String {
|
||||
switch self {
|
||||
case .jpeg, .jpg: "jpg"
|
||||
case .png: "png"
|
||||
case .webp: "webp"
|
||||
case .gif: "gif"
|
||||
case .mp4Audio, .m4a, .aac: "m4a"
|
||||
case .mpeg, .mp3: "mp3"
|
||||
case .wav, .xWav: "wav"
|
||||
case .ogg: "ogg"
|
||||
case .pdf: "pdf"
|
||||
case .octetStream: "bin"
|
||||
}
|
||||
}
|
||||
|
||||
static var allowed: Set<MimeType> = [
|
||||
.jpeg, .jpg, .png, .gif, .webp,
|
||||
.mp4Audio, .m4a, .aac, .mpeg, .mp3,
|
||||
.wav, .xWav, .ogg,
|
||||
.pdf, .octetStream
|
||||
]
|
||||
|
||||
var isAllowed: Bool {
|
||||
Self.allowed.contains(self)
|
||||
}
|
||||
|
||||
// MARK: - Byte signature validation
|
||||
func matches(data: Data) -> Bool {
|
||||
guard !data.isEmpty else { return false }
|
||||
|
||||
// Generic type → skip validation
|
||||
if self == .octetStream { return true }
|
||||
|
||||
switch self {
|
||||
case .jpeg, .jpg:
|
||||
return data.count >= 3 && data[0] == 0xFF && data[1] == 0xD8 && data[2] == 0xFF
|
||||
|
||||
case .png:
|
||||
return data.count >= 8 &&
|
||||
data[0] == 0x89 && data[1] == 0x50 && data[2] == 0x4E && data[3] == 0x47 &&
|
||||
data[4] == 0x0D && data[5] == 0x0A && data[6] == 0x1A && data[7] == 0x0A
|
||||
|
||||
case .gif:
|
||||
return data.count >= 6 && data[0] == 0x47 && data[1] == 0x49 && data[2] == 0x46 &&
|
||||
data[3] == 0x38 && (data[4] == 0x37 || data[4] == 0x39) && data[5] == 0x61
|
||||
|
||||
case .webp:
|
||||
return data.count >= 12 &&
|
||||
data[0] == 0x52 && data[1] == 0x49 && data[2] == 0x46 && data[3] == 0x46 &&
|
||||
data[8] == 0x57 && data[9] == 0x45 && data[10] == 0x42 && data[11] == 0x50
|
||||
|
||||
case .m4a, .mp4Audio, .aac:
|
||||
// AVAudioRecorder output varies by platform - be lenient
|
||||
// Security: size already capped + sandboxed execution
|
||||
return data.count > 100
|
||||
|
||||
case .mpeg, .mp3:
|
||||
if data.count >= 3 && data[0] == 0x49 && data[1] == 0x44 && data[2] == 0x33 {
|
||||
return true // ID3 header
|
||||
}
|
||||
return data.count >= 2 && data[0] == 0xFF && (data[1] & 0xE0) == 0xE0
|
||||
|
||||
case .wav, .xWav:
|
||||
return data.count >= 12 &&
|
||||
data[0] == 0x52 && data[1] == 0x49 && data[2] == 0x46 && data[3] == 0x46 &&
|
||||
data[8] == 0x57 && data[9] == 0x41 && data[10] == 0x56 && data[11] == 0x45
|
||||
|
||||
case .ogg:
|
||||
return data.count >= 4 &&
|
||||
data[0] == 0x4F && data[1] == 0x67 && data[2] == 0x67 && data[3] == 0x53
|
||||
|
||||
case .pdf:
|
||||
return data.count >= 4 &&
|
||||
data[0] == 0x25 && data[1] == 0x50 && data[2] == 0x44 && data[3] == 0x46
|
||||
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Convenience Initializers
|
||||
|
||||
init?(_ mimeString: String?) {
|
||||
guard let mimeString else { return nil }
|
||||
|
||||
let normalized = mimeString.lowercased()
|
||||
|
||||
// Direct match with our canonical list
|
||||
if let match = MimeType.allCases.first(where: { $0.mimeString == normalized }) {
|
||||
self = match
|
||||
return
|
||||
}
|
||||
|
||||
// Let UTType normalize aliases like "image/jpg", "audio/x-wav", etc.
|
||||
if let type = UTType(mimeType: normalized),
|
||||
let match = MimeType.allCases.first(where: { type.conforms(to: $0.utType) }) {
|
||||
self = match
|
||||
return
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
extension MimeType {
|
||||
enum Category: String {
|
||||
case audio, image, file
|
||||
|
||||
/// Ends with a space
|
||||
var messagePrefix: String {
|
||||
switch self {
|
||||
case .audio: "[voice] "
|
||||
case .image: "[image] "
|
||||
case .file: "[file] "
|
||||
}
|
||||
}
|
||||
|
||||
var mediaDir: String {
|
||||
switch self {
|
||||
case .audio: "voicenotes"
|
||||
case .image: "images"
|
||||
case .file: "files"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,350 @@
|
||||
//
|
||||
// CommandProcessor.swift
|
||||
// bitchat
|
||||
//
|
||||
// Handles command parsing and execution for BitChat
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import Nostr
|
||||
import Foundation
|
||||
import BitFoundation
|
||||
|
||||
/// Result of command processing
|
||||
enum CommandResult {
|
||||
case success(message: String?)
|
||||
case error(message: String)
|
||||
case handled // Command handled, no message needed
|
||||
}
|
||||
|
||||
/// Simple struct for geo participant info used by CommandProcessor
|
||||
struct CommandGeoParticipant {
|
||||
let id: String // pubkey hex (lowercased)
|
||||
let displayName: String
|
||||
}
|
||||
|
||||
/// Protocol defining what CommandProcessor needs from its context.
|
||||
/// This breaks the circular dependency between CommandProcessor and ChatViewModel.
|
||||
@MainActor
|
||||
protocol CommandContextProvider: AnyObject {
|
||||
// MARK: - State Properties
|
||||
var nickname: String { get }
|
||||
var selectedPrivateChatPeer: PeerID? { get }
|
||||
var blockedUsers: Set<String> { get }
|
||||
var privateChats: [PeerID: [BitchatMessage]] { get set }
|
||||
var idBridge: NostrIdentityBridge { get }
|
||||
|
||||
// MARK: - Peer Lookup
|
||||
func getPeerIDForNickname(_ nickname: String) -> PeerID?
|
||||
func getVisibleGeoParticipants() -> [CommandGeoParticipant]
|
||||
func nostrPubkeyForDisplayName(_ displayName: String) -> String?
|
||||
|
||||
// MARK: - Chat Actions
|
||||
func startPrivateChat(with peerID: PeerID)
|
||||
func sendPrivateMessage(_ content: String, to peerID: PeerID)
|
||||
func clearCurrentPublicTimeline()
|
||||
func sendPublicRaw(_ content: String)
|
||||
|
||||
// MARK: - System Messages
|
||||
func addLocalPrivateSystemMessage(_ content: String, to peerID: PeerID)
|
||||
func addPublicSystemMessage(_ content: String)
|
||||
|
||||
// MARK: - Favorites
|
||||
func toggleFavorite(peerID: PeerID)
|
||||
func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool)
|
||||
}
|
||||
|
||||
/// Processes chat commands in a focused, efficient way
|
||||
@MainActor
|
||||
final class CommandProcessor {
|
||||
weak var contextProvider: CommandContextProvider?
|
||||
weak var meshService: Transport?
|
||||
private let identityManager: SecureIdentityStateManagerProtocol
|
||||
|
||||
init(contextProvider: CommandContextProvider? = nil, meshService: Transport? = nil, identityManager: SecureIdentityStateManagerProtocol) {
|
||||
self.contextProvider = contextProvider
|
||||
self.meshService = meshService
|
||||
self.identityManager = identityManager
|
||||
}
|
||||
|
||||
/// Process a command string
|
||||
@MainActor
|
||||
func process(_ command: String) -> CommandResult {
|
||||
let parts = command.split(separator: " ", maxSplits: 1, omittingEmptySubsequences: false)
|
||||
guard let cmd = parts.first else { return .error(message: "Invalid command") }
|
||||
let args = parts.count > 1 ? String(parts[1]) : ""
|
||||
|
||||
// Geohash context: disable favoriting in public geohash or GeoDM
|
||||
let inGeoPublic: Bool = {
|
||||
switch LocationChannelManager.shared.selectedChannel {
|
||||
case .mesh: return false
|
||||
case .location: return true
|
||||
}
|
||||
}()
|
||||
let inGeoDM = contextProvider?.selectedPrivateChatPeer?.isGeoDM == true
|
||||
|
||||
switch cmd {
|
||||
case "/m", "/msg":
|
||||
return handleMessage(args)
|
||||
case "/w", "/who":
|
||||
return handleWho()
|
||||
case "/clear":
|
||||
return handleClear()
|
||||
case "/hug":
|
||||
return handleEmote(args, command: "hug", action: "hugs", emoji: "🫂")
|
||||
case "/slap":
|
||||
return handleEmote(args, command: "slap", action: "slaps", emoji: "🐟", suffix: " around a bit with a large trout")
|
||||
case "/block":
|
||||
return handleBlock(args)
|
||||
case "/unblock":
|
||||
return handleUnblock(args)
|
||||
case "/fav":
|
||||
if inGeoPublic || inGeoDM { return .error(message: "favorites are only for mesh peers in #mesh") }
|
||||
return handleFavorite(args, add: true)
|
||||
case "/unfav":
|
||||
if inGeoPublic || inGeoDM { return .error(message: "favorites are only for mesh peers in #mesh") }
|
||||
return handleFavorite(args, add: false)
|
||||
default:
|
||||
return .error(message: "unknown command: \(cmd)")
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Command Handlers
|
||||
|
||||
private func handleMessage(_ args: String) -> CommandResult {
|
||||
let parts = args.split(separator: " ", maxSplits: 1, omittingEmptySubsequences: false)
|
||||
guard !parts.isEmpty else {
|
||||
return .error(message: "usage: /msg @nickname [message]")
|
||||
}
|
||||
|
||||
let targetName = String(parts[0])
|
||||
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
|
||||
|
||||
guard let peerID = contextProvider?.getPeerIDForNickname(nickname) else {
|
||||
return .error(message: "'\(nickname)' not found")
|
||||
}
|
||||
|
||||
contextProvider?.startPrivateChat(with: peerID)
|
||||
|
||||
if parts.count > 1 {
|
||||
let message = String(parts[1])
|
||||
contextProvider?.sendPrivateMessage(message, to: peerID)
|
||||
}
|
||||
|
||||
return .success(message: "started private chat with \(nickname)")
|
||||
}
|
||||
|
||||
private func handleWho() -> CommandResult {
|
||||
// Show geohash participants when in a geohash channel; otherwise mesh peers
|
||||
switch LocationChannelManager.shared.selectedChannel {
|
||||
case .location(let ch):
|
||||
// Geohash context: show visible geohash participants (exclude self)
|
||||
guard let vm = contextProvider else { return .success(message: "nobody around") }
|
||||
let myHex = (try? vm.idBridge.deriveIdentity(forGeohash: ch.geohash))?.publicKeyHex.lowercased()
|
||||
let people = vm.getVisibleGeoParticipants().filter { person in
|
||||
if let me = myHex { return person.id.lowercased() != me }
|
||||
return true
|
||||
}
|
||||
let names = people.map { $0.displayName }
|
||||
if names.isEmpty { return .success(message: "no one else is online right now") }
|
||||
return .success(message: "online: " + names.sorted().joined(separator: ", "))
|
||||
case .mesh:
|
||||
// Mesh context: show connected peer nicknames
|
||||
guard let peers = meshService?.getPeerNicknames(), !peers.isEmpty else {
|
||||
return .success(message: "no one else is online right now")
|
||||
}
|
||||
let onlineList = peers.values.sorted().joined(separator: ", ")
|
||||
return .success(message: "online: \(onlineList)")
|
||||
}
|
||||
}
|
||||
|
||||
private func handleClear() -> CommandResult {
|
||||
if let peerID = contextProvider?.selectedPrivateChatPeer {
|
||||
contextProvider?.privateChats[peerID]?.removeAll()
|
||||
} else {
|
||||
contextProvider?.clearCurrentPublicTimeline()
|
||||
}
|
||||
return .handled
|
||||
}
|
||||
|
||||
private func handleEmote(_ args: String, command: String, action: String, emoji: String, suffix: String = "") -> CommandResult {
|
||||
let targetName = args.trimmed
|
||||
guard !targetName.isEmpty else {
|
||||
return .error(message: "usage: /\(command) <nickname>")
|
||||
}
|
||||
|
||||
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
|
||||
|
||||
guard let targetPeerID = contextProvider?.getPeerIDForNickname(nickname),
|
||||
let myNickname = contextProvider?.nickname else {
|
||||
return .error(message: "cannot \(command) \(nickname): not found")
|
||||
}
|
||||
|
||||
let emoteContent = "* \(emoji) \(myNickname) \(action) \(nickname)\(suffix) *"
|
||||
|
||||
if contextProvider?.selectedPrivateChatPeer != nil {
|
||||
// In private chat
|
||||
if let peerNickname = meshService?.peerNickname(peerID: targetPeerID) {
|
||||
let personalMessage = "* \(emoji) \(myNickname) \(action) you\(suffix) *"
|
||||
meshService?.sendPrivateMessage(personalMessage, to: targetPeerID,
|
||||
recipientNickname: peerNickname,
|
||||
messageID: UUID().uuidString)
|
||||
// Also add a local system message so the sender sees a natural-language confirmation
|
||||
let pastAction: String = {
|
||||
switch action {
|
||||
case "hugs": return "hugged"
|
||||
case "slaps": return "slapped"
|
||||
default: return action.hasSuffix("e") ? action + "d" : action + "ed"
|
||||
}
|
||||
}()
|
||||
let localText = "\(emoji) you \(pastAction) \(nickname)\(suffix)"
|
||||
contextProvider?.addLocalPrivateSystemMessage(localText, to: targetPeerID)
|
||||
}
|
||||
} else {
|
||||
// In public chat: send to active public channel (mesh or geohash)
|
||||
contextProvider?.sendPublicRaw(emoteContent)
|
||||
let publicEcho = "\(emoji) \(myNickname) \(action) \(nickname)\(suffix)"
|
||||
contextProvider?.addPublicSystemMessage(publicEcho)
|
||||
}
|
||||
|
||||
return .handled
|
||||
}
|
||||
|
||||
private func handleBlock(_ args: String) -> CommandResult {
|
||||
let targetName = args.trimmed
|
||||
|
||||
if targetName.isEmpty {
|
||||
// List blocked users (mesh) and geohash (Nostr) blocks
|
||||
let meshBlocked = contextProvider?.blockedUsers ?? []
|
||||
var blockedNicknames: [String] = []
|
||||
if let peers = meshService?.getPeerNicknames() {
|
||||
for (peerID, nickname) in peers {
|
||||
if let fingerprint = meshService?.getFingerprint(for: peerID),
|
||||
meshBlocked.contains(fingerprint) {
|
||||
blockedNicknames.append(nickname)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Geohash blocked names (prefer visible display names; fallback to #suffix)
|
||||
let geoBlocked = Array(identityManager.getBlockedNostrPubkeys())
|
||||
var geoNames: [String] = []
|
||||
if let vm = contextProvider {
|
||||
let visible = vm.getVisibleGeoParticipants()
|
||||
let visibleIndex = Dictionary(uniqueKeysWithValues: visible.map { ($0.id.lowercased(), $0.displayName) })
|
||||
for pk in geoBlocked {
|
||||
if let name = visibleIndex[pk.lowercased()] {
|
||||
geoNames.append(name)
|
||||
} else {
|
||||
let suffix = String(pk.suffix(4))
|
||||
geoNames.append("anon#\(suffix)")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let meshList = blockedNicknames.isEmpty ? "none" : blockedNicknames.sorted().joined(separator: ", ")
|
||||
let geoList = geoNames.isEmpty ? "none" : geoNames.sorted().joined(separator: ", ")
|
||||
return .success(message: "blocked peers: \(meshList) | geohash blocks: \(geoList)")
|
||||
}
|
||||
|
||||
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
|
||||
|
||||
if let peerID = contextProvider?.getPeerIDForNickname(nickname),
|
||||
let fingerprint = meshService?.getFingerprint(for: peerID) {
|
||||
if identityManager.isBlocked(fingerprint: fingerprint) {
|
||||
return .success(message: "\(nickname) is already blocked")
|
||||
}
|
||||
// Block the user (mesh/noise identity)
|
||||
if var identity = identityManager.getSocialIdentity(for: fingerprint) {
|
||||
identity.isBlocked = true
|
||||
identity.isFavorite = false
|
||||
identityManager.updateSocialIdentity(identity)
|
||||
} else {
|
||||
let blockedIdentity = SocialIdentity(
|
||||
fingerprint: fingerprint,
|
||||
localPetname: nil,
|
||||
claimedNickname: nickname,
|
||||
trustLevel: .unknown,
|
||||
isFavorite: false,
|
||||
isBlocked: true,
|
||||
notes: nil
|
||||
)
|
||||
identityManager.updateSocialIdentity(blockedIdentity)
|
||||
}
|
||||
return .success(message: "blocked \(nickname). you will no longer receive messages from them")
|
||||
}
|
||||
// Mesh lookup failed; try geohash (Nostr) participant by display name
|
||||
if let pub = contextProvider?.nostrPubkeyForDisplayName(nickname) {
|
||||
if identityManager.isNostrBlocked(pubkeyHexLowercased: pub) {
|
||||
return .success(message: "\(nickname) is already blocked")
|
||||
}
|
||||
identityManager.setNostrBlocked(pub, isBlocked: true)
|
||||
return .success(message: "blocked \(nickname) in geohash chats")
|
||||
}
|
||||
|
||||
return .error(message: "cannot block \(nickname): not found or unable to verify identity")
|
||||
}
|
||||
|
||||
private func handleUnblock(_ args: String) -> CommandResult {
|
||||
let targetName = args.trimmed
|
||||
guard !targetName.isEmpty else {
|
||||
return .error(message: "usage: /unblock <nickname>")
|
||||
}
|
||||
|
||||
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
|
||||
|
||||
if let peerID = contextProvider?.getPeerIDForNickname(nickname),
|
||||
let fingerprint = meshService?.getFingerprint(for: peerID) {
|
||||
if !identityManager.isBlocked(fingerprint: fingerprint) {
|
||||
return .success(message: "\(nickname) is not blocked")
|
||||
}
|
||||
identityManager.setBlocked(fingerprint, isBlocked: false)
|
||||
return .success(message: "unblocked \(nickname)")
|
||||
}
|
||||
// Try geohash unblock
|
||||
if let pub = contextProvider?.nostrPubkeyForDisplayName(nickname) {
|
||||
if !identityManager.isNostrBlocked(pubkeyHexLowercased: pub) {
|
||||
return .success(message: "\(nickname) is not blocked")
|
||||
}
|
||||
identityManager.setNostrBlocked(pub, isBlocked: false)
|
||||
return .success(message: "unblocked \(nickname) in geohash chats")
|
||||
}
|
||||
return .error(message: "cannot unblock \(nickname): not found")
|
||||
}
|
||||
|
||||
private func handleFavorite(_ args: String, add: Bool) -> CommandResult {
|
||||
let targetName = args.trimmed
|
||||
guard !targetName.isEmpty else {
|
||||
return .error(message: "usage: /\(add ? "fav" : "unfav") <nickname>")
|
||||
}
|
||||
|
||||
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
|
||||
|
||||
guard let peerID = contextProvider?.getPeerIDForNickname(nickname),
|
||||
let noisePublicKey = Data(hexString: peerID.id) else {
|
||||
return .error(message: "can't find peer: \(nickname)")
|
||||
}
|
||||
|
||||
if add {
|
||||
let existingFavorite = FavoritesPersistenceService.shared.getFavoriteStatus(for: noisePublicKey)
|
||||
FavoritesPersistenceService.shared.addFavorite(
|
||||
peerNoisePublicKey: noisePublicKey,
|
||||
peerNostrPublicKey: existingFavorite?.peerNostrPublicKey,
|
||||
peerNickname: nickname
|
||||
)
|
||||
|
||||
contextProvider?.toggleFavorite(peerID: peerID)
|
||||
contextProvider?.sendFavoriteNotification(to: peerID, isFavorite: true)
|
||||
|
||||
return .success(message: "added \(nickname) to favorites")
|
||||
} else {
|
||||
FavoritesPersistenceService.shared.removeFavorite(peerNoisePublicKey: noisePublicKey)
|
||||
|
||||
contextProvider?.toggleFavorite(peerID: peerID)
|
||||
contextProvider?.sendFavoriteNotification(to: peerID, isFavorite: false)
|
||||
|
||||
return .success(message: "removed \(nickname) from favorites")
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -1,294 +0,0 @@
|
||||
//
|
||||
// DeliveryTracker.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
class DeliveryTracker {
|
||||
static let shared = DeliveryTracker()
|
||||
|
||||
// Track pending deliveries
|
||||
private var pendingDeliveries: [String: PendingDelivery] = [:]
|
||||
private let pendingLock = NSLock()
|
||||
|
||||
// Track received ACKs to prevent duplicates
|
||||
private var receivedAckIDs = Set<String>()
|
||||
private var sentAckIDs = Set<String>()
|
||||
|
||||
// Timeout configuration
|
||||
private let privateMessageTimeout: TimeInterval = 120 // 2 minutes
|
||||
private let roomMessageTimeout: TimeInterval = 180 // 3 minutes
|
||||
private let favoriteTimeout: TimeInterval = 600 // 10 minutes for favorites
|
||||
|
||||
// Retry configuration
|
||||
private let maxRetries = 3
|
||||
private let retryDelay: TimeInterval = 5 // Base retry delay
|
||||
|
||||
// Publishers for UI updates
|
||||
let deliveryStatusUpdated = PassthroughSubject<(messageID: String, status: DeliveryStatus), Never>()
|
||||
|
||||
// Cleanup timer
|
||||
private var cleanupTimer: Timer?
|
||||
|
||||
struct PendingDelivery {
|
||||
let messageID: String
|
||||
let sentAt: Date
|
||||
let recipientID: String
|
||||
let recipientNickname: String
|
||||
let retryCount: Int
|
||||
let isFavorite: Bool
|
||||
var timeoutTimer: Timer?
|
||||
|
||||
var isTimedOut: Bool {
|
||||
let timeout: TimeInterval = isFavorite ? 300 : 30
|
||||
return Date().timeIntervalSince(sentAt) > timeout
|
||||
}
|
||||
|
||||
var shouldRetry: Bool {
|
||||
return retryCount < 3 && isFavorite
|
||||
}
|
||||
}
|
||||
|
||||
private init() {
|
||||
startCleanupTimer()
|
||||
}
|
||||
|
||||
deinit {
|
||||
cleanupTimer?.invalidate()
|
||||
}
|
||||
|
||||
// MARK: - Public Methods
|
||||
|
||||
func trackMessage(_ message: BitchatMessage, recipientID: String, recipientNickname: String, isFavorite: Bool = false, expectedRecipients: Int = 1) {
|
||||
// Only track private messages
|
||||
guard message.isPrivate else { return }
|
||||
|
||||
SecureLogger.log("Tracking message \(message.id) - private: \(message.isPrivate), recipient: \(recipientNickname)", category: SecureLogger.session, level: .info)
|
||||
|
||||
|
||||
let delivery = PendingDelivery(
|
||||
messageID: message.id,
|
||||
sentAt: Date(),
|
||||
recipientID: recipientID,
|
||||
recipientNickname: recipientNickname,
|
||||
retryCount: 0,
|
||||
isFavorite: isFavorite,
|
||||
timeoutTimer: nil
|
||||
)
|
||||
|
||||
// Store the delivery with lock
|
||||
pendingLock.lock()
|
||||
pendingDeliveries[message.id] = delivery
|
||||
pendingLock.unlock()
|
||||
|
||||
// Update status to sent (only if not already delivered)
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 0.1) { [weak self] in
|
||||
guard let self = self else { return }
|
||||
|
||||
self.pendingLock.lock()
|
||||
let stillPending = self.pendingDeliveries[message.id] != nil
|
||||
self.pendingLock.unlock()
|
||||
|
||||
// Only update to sent if still pending (not already delivered)
|
||||
if stillPending {
|
||||
SecureLogger.log("Updating message \(message.id) to sent status (still pending)", category: SecureLogger.session, level: .debug)
|
||||
self.updateDeliveryStatus(message.id, status: .sent)
|
||||
} else {
|
||||
SecureLogger.log("Skipping sent status update for \(message.id) - already delivered", category: SecureLogger.session, level: .debug)
|
||||
}
|
||||
}
|
||||
|
||||
// Schedule timeout (outside of lock)
|
||||
scheduleTimeout(for: message.id)
|
||||
}
|
||||
|
||||
func processDeliveryAck(_ ack: DeliveryAck) {
|
||||
pendingLock.lock()
|
||||
defer { pendingLock.unlock() }
|
||||
|
||||
SecureLogger.log("Processing delivery ACK for message \(ack.originalMessageID) from \(ack.recipientNickname)", category: SecureLogger.session, level: .info)
|
||||
|
||||
// Prevent duplicate ACK processing
|
||||
guard !receivedAckIDs.contains(ack.ackID) else {
|
||||
SecureLogger.log("Duplicate ACK \(ack.ackID) - ignoring", category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
receivedAckIDs.insert(ack.ackID)
|
||||
|
||||
// Find the pending delivery
|
||||
guard let delivery = pendingDeliveries[ack.originalMessageID] else {
|
||||
// Message might have already been delivered or timed out
|
||||
SecureLogger.log("No pending delivery found for message \(ack.originalMessageID)", category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
// Cancel timeout timer
|
||||
delivery.timeoutTimer?.invalidate()
|
||||
|
||||
// Direct message - mark as delivered
|
||||
SecureLogger.log("Marking private message \(ack.originalMessageID) as delivered to \(ack.recipientNickname)", category: SecureLogger.session, level: .info)
|
||||
updateDeliveryStatus(ack.originalMessageID, status: .delivered(to: ack.recipientNickname, at: Date()))
|
||||
pendingDeliveries.removeValue(forKey: ack.originalMessageID)
|
||||
}
|
||||
|
||||
func generateAck(for message: BitchatMessage, myPeerID: String, myNickname: String, hopCount: UInt8) -> DeliveryAck? {
|
||||
// Don't ACK our own messages
|
||||
guard message.senderPeerID != myPeerID else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Only ACK private messages
|
||||
guard message.isPrivate else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Don't ACK if we've already sent an ACK for this message
|
||||
guard !sentAckIDs.contains(message.id) else {
|
||||
return nil
|
||||
}
|
||||
sentAckIDs.insert(message.id)
|
||||
|
||||
|
||||
return DeliveryAck(
|
||||
originalMessageID: message.id,
|
||||
recipientID: myPeerID,
|
||||
recipientNickname: myNickname,
|
||||
hopCount: hopCount
|
||||
)
|
||||
}
|
||||
|
||||
func clearDeliveryStatus(for messageID: String) {
|
||||
pendingLock.lock()
|
||||
defer { pendingLock.unlock() }
|
||||
|
||||
if let delivery = pendingDeliveries[messageID] {
|
||||
delivery.timeoutTimer?.invalidate()
|
||||
}
|
||||
pendingDeliveries.removeValue(forKey: messageID)
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func updateDeliveryStatus(_ messageID: String, status: DeliveryStatus) {
|
||||
SecureLogger.log("Updating delivery status for message \(messageID): \(status)", category: SecureLogger.session, level: .debug)
|
||||
DispatchQueue.main.async { [weak self] in
|
||||
self?.deliveryStatusUpdated.send((messageID: messageID, status: status))
|
||||
}
|
||||
}
|
||||
|
||||
private func scheduleTimeout(for messageID: String) {
|
||||
// Get delivery info with lock
|
||||
pendingLock.lock()
|
||||
guard let delivery = pendingDeliveries[messageID] else {
|
||||
pendingLock.unlock()
|
||||
return
|
||||
}
|
||||
let isFavorite = delivery.isFavorite
|
||||
pendingLock.unlock()
|
||||
|
||||
let timeout = isFavorite ? favoriteTimeout : privateMessageTimeout
|
||||
|
||||
let timer = Timer.scheduledTimer(withTimeInterval: timeout, repeats: false) { [weak self] _ in
|
||||
self?.handleTimeout(messageID: messageID)
|
||||
}
|
||||
|
||||
pendingLock.lock()
|
||||
if var updatedDelivery = pendingDeliveries[messageID] {
|
||||
updatedDelivery.timeoutTimer = timer
|
||||
pendingDeliveries[messageID] = updatedDelivery
|
||||
}
|
||||
pendingLock.unlock()
|
||||
}
|
||||
|
||||
private func handleTimeout(messageID: String) {
|
||||
pendingLock.lock()
|
||||
guard let delivery = pendingDeliveries[messageID] else {
|
||||
pendingLock.unlock()
|
||||
return
|
||||
}
|
||||
|
||||
let shouldRetry = delivery.shouldRetry
|
||||
|
||||
if shouldRetry {
|
||||
pendingLock.unlock()
|
||||
// Retry for favorites (outside of lock)
|
||||
retryDelivery(messageID: messageID)
|
||||
} else {
|
||||
// Mark as failed
|
||||
let reason = "Message not delivered"
|
||||
pendingDeliveries.removeValue(forKey: messageID)
|
||||
pendingLock.unlock()
|
||||
updateDeliveryStatus(messageID, status: .failed(reason: reason))
|
||||
}
|
||||
}
|
||||
|
||||
private func retryDelivery(messageID: String) {
|
||||
pendingLock.lock()
|
||||
guard let delivery = pendingDeliveries[messageID] else {
|
||||
pendingLock.unlock()
|
||||
return
|
||||
}
|
||||
|
||||
// Increment retry count
|
||||
let newDelivery = PendingDelivery(
|
||||
messageID: delivery.messageID,
|
||||
sentAt: delivery.sentAt,
|
||||
recipientID: delivery.recipientID,
|
||||
recipientNickname: delivery.recipientNickname,
|
||||
retryCount: delivery.retryCount + 1,
|
||||
isFavorite: delivery.isFavorite,
|
||||
timeoutTimer: nil
|
||||
)
|
||||
|
||||
pendingDeliveries[messageID] = newDelivery
|
||||
let retryCount = delivery.retryCount
|
||||
pendingLock.unlock()
|
||||
|
||||
// Exponential backoff for retry
|
||||
let delay = retryDelay * pow(2, Double(retryCount))
|
||||
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + delay) { [weak self] in
|
||||
// Trigger resend through delegate or notification
|
||||
NotificationCenter.default.post(
|
||||
name: Notification.Name("bitchat.retryMessage"),
|
||||
object: nil,
|
||||
userInfo: ["messageID": messageID]
|
||||
)
|
||||
|
||||
// Schedule new timeout
|
||||
self?.scheduleTimeout(for: messageID)
|
||||
}
|
||||
}
|
||||
|
||||
private func startCleanupTimer() {
|
||||
cleanupTimer = Timer.scheduledTimer(withTimeInterval: 60, repeats: true) { [weak self] _ in
|
||||
self?.cleanupOldDeliveries()
|
||||
}
|
||||
}
|
||||
|
||||
private func cleanupOldDeliveries() {
|
||||
pendingLock.lock()
|
||||
defer { pendingLock.unlock() }
|
||||
|
||||
let now = Date()
|
||||
let maxAge: TimeInterval = 3600 // 1 hour
|
||||
|
||||
// Clean up old pending deliveries
|
||||
pendingDeliveries = pendingDeliveries.filter { (_, delivery) in
|
||||
now.timeIntervalSince(delivery.sentAt) < maxAge
|
||||
}
|
||||
|
||||
// Clean up old ACK IDs (keep last 1000)
|
||||
if receivedAckIDs.count > 1000 {
|
||||
receivedAckIDs.removeAll()
|
||||
}
|
||||
if sentAckIDs.count > 1000 {
|
||||
sentAckIDs.removeAll()
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,9 +1,11 @@
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
/// Manages persistent favorite relationships between peers
|
||||
@MainActor
|
||||
class FavoritesPersistenceService: ObservableObject {
|
||||
final class FavoritesPersistenceService: ObservableObject {
|
||||
|
||||
struct FavoriteRelationship: Codable {
|
||||
let peerNoisePublicKey: Data
|
||||
@@ -13,24 +15,27 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
let theyFavoritedUs: Bool
|
||||
let favoritedAt: Date
|
||||
let lastUpdated: Date
|
||||
// Track what we last sent as OUR npub to this peer, to avoid resending unless it changes
|
||||
// Note: we do not track which npub we last sent to them; sending happens only on favorite toggle
|
||||
|
||||
var isMutual: Bool {
|
||||
isFavorite && theyFavoritedUs
|
||||
}
|
||||
}
|
||||
|
||||
// We intentionally do not track when we last sent our npub; sending happens only on favorite toggle.
|
||||
|
||||
private static let storageKey = "chat.bitchat.favorites"
|
||||
private static let keychainService = "chat.bitchat.favorites"
|
||||
private let keychain: KeychainManagerProtocol
|
||||
|
||||
@Published private(set) var favorites: [Data: FavoriteRelationship] = [:] // Noise pubkey -> relationship
|
||||
@Published private(set) var mutualFavorites: Set<Data> = []
|
||||
|
||||
private let userDefaults = UserDefaults.standard
|
||||
private var cancellables = Set<AnyCancellable>()
|
||||
|
||||
static let shared = FavoritesPersistenceService()
|
||||
|
||||
private init() {
|
||||
init(keychain: KeychainManagerProtocol = KeychainManager()) {
|
||||
self.keychain = keychain
|
||||
loadFavorites()
|
||||
|
||||
// Update mutual favorites when favorites change
|
||||
@@ -47,8 +52,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
peerNostrPublicKey: String? = nil,
|
||||
peerNickname: String
|
||||
) {
|
||||
SecureLogger.log("⭐️ Adding favorite: \(peerNickname) (\(peerNoisePublicKey.hexEncodedString()))",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("⭐️ Adding favorite: \(peerNickname) (\(peerNoisePublicKey.hexEncodedString()))", category: .session)
|
||||
|
||||
let existing = favorites[peerNoisePublicKey]
|
||||
|
||||
@@ -64,8 +68,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
|
||||
// Log if this creates a mutual favorite
|
||||
if relationship.isMutual {
|
||||
SecureLogger.log("💕 Mutual favorite relationship established with \(peerNickname)!",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("💕 Mutual favorite relationship established with \(peerNickname)!", category: .session)
|
||||
}
|
||||
|
||||
favorites[peerNoisePublicKey] = relationship
|
||||
@@ -83,8 +86,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
func removeFavorite(peerNoisePublicKey: Data) {
|
||||
guard let existing = favorites[peerNoisePublicKey] else { return }
|
||||
|
||||
SecureLogger.log("⭐️ Removing favorite: \(existing.peerNickname) (\(peerNoisePublicKey.hexEncodedString()))",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("⭐️ Removing favorite: \(existing.peerNickname) (\(peerNoisePublicKey.hexEncodedString()))", category: .session)
|
||||
|
||||
// If they still favorite us, keep the record but mark us as not favoriting
|
||||
if existing.theyFavoritedUs {
|
||||
@@ -125,8 +127,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
let existing = favorites[peerNoisePublicKey]
|
||||
let displayName = peerNickname ?? existing?.peerNickname ?? "Unknown"
|
||||
|
||||
SecureLogger.log("📨 Received favorite notification: \(displayName) \(favorited ? "favorited" : "unfavorited") us",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("📨 Received favorite notification: \(displayName) \(favorited ? "favorited" : "unfavorited") us", category: .session)
|
||||
|
||||
let relationship = FavoriteRelationship(
|
||||
peerNoisePublicKey: peerNoisePublicKey,
|
||||
@@ -147,8 +148,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
|
||||
// Check if this creates a mutual favorite
|
||||
if relationship.isMutual {
|
||||
SecureLogger.log("💕 Mutual favorite relationship established with \(displayName)!",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("💕 Mutual favorite relationship established with \(displayName)!", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -177,126 +177,26 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
favorites[peerNoisePublicKey]
|
||||
}
|
||||
|
||||
/// Update Nostr public key for a peer
|
||||
func updateNostrPublicKey(for peerNoisePublicKey: Data, nostrPubkey: String) {
|
||||
guard let existing = favorites[peerNoisePublicKey] else { return }
|
||||
|
||||
let updated = FavoriteRelationship(
|
||||
peerNoisePublicKey: existing.peerNoisePublicKey,
|
||||
peerNostrPublicKey: nostrPubkey,
|
||||
peerNickname: existing.peerNickname,
|
||||
isFavorite: existing.isFavorite,
|
||||
theyFavoritedUs: existing.theyFavoritedUs,
|
||||
favoritedAt: existing.favoritedAt,
|
||||
lastUpdated: Date()
|
||||
)
|
||||
|
||||
favorites[peerNoisePublicKey] = updated
|
||||
saveFavorites()
|
||||
}
|
||||
|
||||
/// Update nickname for an existing favorite
|
||||
func updateNickname(for peerNoisePublicKey: Data, newNickname: String) {
|
||||
guard let existing = favorites[peerNoisePublicKey] else { return }
|
||||
|
||||
// Skip if nickname hasn't changed
|
||||
if existing.peerNickname == newNickname { return }
|
||||
|
||||
// Updating nickname for favorite
|
||||
|
||||
let updated = FavoriteRelationship(
|
||||
peerNoisePublicKey: existing.peerNoisePublicKey,
|
||||
peerNostrPublicKey: existing.peerNostrPublicKey,
|
||||
peerNickname: newNickname,
|
||||
isFavorite: existing.isFavorite,
|
||||
theyFavoritedUs: existing.theyFavoritedUs,
|
||||
favoritedAt: existing.favoritedAt,
|
||||
lastUpdated: Date()
|
||||
)
|
||||
|
||||
favorites[peerNoisePublicKey] = updated
|
||||
saveFavorites()
|
||||
|
||||
// Notify observers
|
||||
NotificationCenter.default.post(
|
||||
name: .favoriteStatusChanged,
|
||||
object: nil,
|
||||
userInfo: ["peerPublicKey": peerNoisePublicKey]
|
||||
)
|
||||
}
|
||||
|
||||
/// Update noise public key when peer reconnects with new ID
|
||||
func updateNoisePublicKey(from oldKey: Data, to newKey: Data, peerNickname: String) {
|
||||
guard let existing = favorites[oldKey] else {
|
||||
SecureLogger.log("⚠️ Cannot update noise key - no favorite found for \(oldKey.hexEncodedString())",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
/// Resolve favorite status by short peer ID (16-hex derived from Noise pubkey)
|
||||
/// Falls back to scanning favorites and matching on derived peer ID.
|
||||
func getFavoriteStatus(forPeerID peerID: PeerID) -> FavoriteRelationship? {
|
||||
// Quick sanity: peerID should be 16 hex chars (8 bytes)
|
||||
guard peerID.isShort else { return nil }
|
||||
for (pubkey, rel) in favorites where PeerID(publicKey: pubkey) == peerID {
|
||||
return rel
|
||||
}
|
||||
|
||||
// Check if we already have a favorite with the new key
|
||||
if favorites[newKey] != nil {
|
||||
SecureLogger.log("⚠️ Favorite already exists with new key \(newKey.hexEncodedString()), removing old entry",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
favorites.removeValue(forKey: oldKey)
|
||||
saveFavorites()
|
||||
return
|
||||
}
|
||||
|
||||
// Updating noise public key
|
||||
|
||||
// Remove old entry
|
||||
favorites.removeValue(forKey: oldKey)
|
||||
|
||||
// Add with new key
|
||||
let updated = FavoriteRelationship(
|
||||
peerNoisePublicKey: newKey,
|
||||
peerNostrPublicKey: existing.peerNostrPublicKey,
|
||||
peerNickname: peerNickname,
|
||||
isFavorite: existing.isFavorite,
|
||||
theyFavoritedUs: existing.theyFavoritedUs,
|
||||
favoritedAt: existing.favoritedAt,
|
||||
lastUpdated: Date()
|
||||
)
|
||||
|
||||
favorites[newKey] = updated
|
||||
saveFavorites()
|
||||
|
||||
// Notify observers with both old and new keys
|
||||
NotificationCenter.default.post(
|
||||
name: .favoriteStatusChanged,
|
||||
object: nil,
|
||||
userInfo: [
|
||||
"peerPublicKey": newKey,
|
||||
"oldPeerPublicKey": oldKey,
|
||||
"isKeyUpdate": true
|
||||
]
|
||||
)
|
||||
}
|
||||
|
||||
/// Get all favorites (including non-mutual)
|
||||
func getAllFavorites() -> [FavoriteRelationship] {
|
||||
favorites.values.filter { $0.isFavorite }
|
||||
}
|
||||
|
||||
/// Get only mutual favorites
|
||||
func getMutualFavorites() -> [FavoriteRelationship] {
|
||||
favorites.values.filter { $0.isMutual }
|
||||
}
|
||||
|
||||
/// Get all favorite relationships (including where they favorited us)
|
||||
func getAllRelationships() -> [FavoriteRelationship] {
|
||||
Array(favorites.values)
|
||||
return nil
|
||||
}
|
||||
|
||||
/// Clear all favorites - used for panic mode
|
||||
func clearAllFavorites() {
|
||||
SecureLogger.log("🧹 Clearing all favorites (panic mode)", category: SecureLogger.session, level: .warning)
|
||||
SecureLogger.warning("🧹 Clearing all favorites (panic mode)", category: .session)
|
||||
|
||||
favorites.removeAll()
|
||||
saveFavorites()
|
||||
|
||||
// Delete from keychain directly
|
||||
KeychainHelper.delete(
|
||||
keychain.delete(
|
||||
key: Self.storageKey,
|
||||
service: Self.keychainService
|
||||
)
|
||||
@@ -316,26 +216,26 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
let data = try encoder.encode(relationships)
|
||||
|
||||
// Store in keychain for security
|
||||
KeychainHelper.save(
|
||||
keychain.save(
|
||||
key: Self.storageKey,
|
||||
data: data,
|
||||
service: Self.keychainService
|
||||
service: Self.keychainService,
|
||||
accessible: nil
|
||||
)
|
||||
|
||||
// Successfully saved favorites
|
||||
} catch {
|
||||
SecureLogger.log("Failed to save favorites: \(error)", category: SecureLogger.session, level: .error)
|
||||
SecureLogger.error("Failed to save favorites: \(error)", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
private func loadFavorites() {
|
||||
// Loading favorites from keychain
|
||||
|
||||
guard let data = KeychainHelper.load(
|
||||
guard let data = keychain.load(
|
||||
key: Self.storageKey,
|
||||
service: Self.keychainService
|
||||
) else {
|
||||
SecureLogger.log("📭 No existing favorites found in keychain", category: SecureLogger.session, level: .info)
|
||||
return
|
||||
}
|
||||
|
||||
@@ -343,14 +243,12 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
let decoder = JSONDecoder()
|
||||
let relationships = try decoder.decode([FavoriteRelationship].self, from: data)
|
||||
|
||||
SecureLogger.log("✅ Loaded \(relationships.count) favorite relationships",
|
||||
category: SecureLogger.session, level: .info)
|
||||
SecureLogger.info("✅ Loaded \(relationships.count) favorite relationships", category: .session)
|
||||
|
||||
// Log Nostr public key info
|
||||
for relationship in relationships {
|
||||
if relationship.peerNostrPublicKey == nil {
|
||||
SecureLogger.log("⚠️ No Nostr public key stored for '\(relationship.peerNickname)'",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
SecureLogger.warning("⚠️ No Nostr public key stored for '\(relationship.peerNickname)'", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -361,8 +259,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
for relationship in relationships {
|
||||
// Check for duplicates by public key (the actual unique identifier)
|
||||
if let existing = seenPublicKeys[relationship.peerNoisePublicKey] {
|
||||
SecureLogger.log("⚠️ Duplicate favorite found for public key \(relationship.peerNoisePublicKey.hexEncodedString()) - nicknames: '\(existing.peerNickname)' vs '\(relationship.peerNickname)'",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
SecureLogger.warning("⚠️ Duplicate favorite found for public key \(relationship.peerNoisePublicKey.hexEncodedString()) - nicknames: '\(existing.peerNickname)' vs '\(relationship.peerNickname)'", category: .session)
|
||||
|
||||
// Keep the most recent or most complete relationship
|
||||
if relationship.lastUpdated > existing.lastUpdated ||
|
||||
@@ -403,7 +300,7 @@ class FavoritesPersistenceService: ObservableObject {
|
||||
// Log loaded relationships
|
||||
// Loaded relationships successfully
|
||||
} catch {
|
||||
SecureLogger.log("Failed to load favorites: \(error)", category: SecureLogger.session, level: .error)
|
||||
SecureLogger.error("Failed to load favorites: \(error)", category: .session)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,162 @@
|
||||
//
|
||||
// GeohashParticipantTracker.swift
|
||||
// bitchat
|
||||
//
|
||||
// Tracks participants in geohash-based location channels.
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
/// Represents a participant in a geohash channel
|
||||
public struct GeoPerson: Identifiable, Equatable, Sendable {
|
||||
public let id: String // pubkey hex (lowercased)
|
||||
public let displayName: String
|
||||
public let lastSeen: Date
|
||||
|
||||
public init(id: String, displayName: String, lastSeen: Date) {
|
||||
self.id = id
|
||||
self.displayName = displayName
|
||||
self.lastSeen = lastSeen
|
||||
}
|
||||
}
|
||||
|
||||
/// Protocol for resolving display names and checking block status
|
||||
@MainActor
|
||||
public protocol GeohashParticipantContext: AnyObject {
|
||||
/// Returns display name for a Nostr pubkey (e.g., "alice#a1b2" or "anon#c3d4")
|
||||
func displayNameForPubkey(_ pubkeyHex: String) -> String
|
||||
/// Returns true if the pubkey is blocked
|
||||
func isBlocked(_ pubkeyHexLowercased: String) -> Bool
|
||||
}
|
||||
|
||||
/// Tracks participants across multiple geohash channels
|
||||
@MainActor
|
||||
public final class GeohashParticipantTracker: ObservableObject {
|
||||
|
||||
/// Activity cutoff duration (defaults to 5 minutes)
|
||||
public let activityCutoff: TimeInterval
|
||||
|
||||
/// Per-geohash participant map: [geohash: [pubkeyHex: lastSeen]]
|
||||
private var participants: [String: [String: Date]] = [:]
|
||||
|
||||
/// Currently visible people for the active geohash
|
||||
@Published public private(set) var visiblePeople: [GeoPerson] = []
|
||||
|
||||
/// The currently active geohash (if any)
|
||||
private var activeGeohash: String?
|
||||
|
||||
/// Context for display name resolution and block checking
|
||||
private weak var context: GeohashParticipantContext?
|
||||
|
||||
/// Timer for periodic refresh
|
||||
private var refreshTimer: Timer?
|
||||
|
||||
public init(activityCutoff: TimeInterval = -300) { // default 5 minutes
|
||||
self.activityCutoff = activityCutoff
|
||||
}
|
||||
|
||||
/// Configure with a context provider
|
||||
public func configure(context: GeohashParticipantContext) {
|
||||
self.context = context
|
||||
}
|
||||
|
||||
/// Set the currently active geohash
|
||||
public func setActiveGeohash(_ geohash: String?) {
|
||||
activeGeohash = geohash
|
||||
if geohash == nil {
|
||||
visiblePeople = []
|
||||
} else {
|
||||
refresh()
|
||||
}
|
||||
}
|
||||
|
||||
/// Record activity from a participant in the current active geohash
|
||||
public func recordParticipant(pubkeyHex: String) {
|
||||
guard let gh = activeGeohash else { return }
|
||||
recordParticipant(pubkeyHex: pubkeyHex, geohash: gh)
|
||||
}
|
||||
|
||||
/// Record activity from a participant in a specific geohash
|
||||
public func recordParticipant(pubkeyHex: String, geohash: String) {
|
||||
let key = pubkeyHex.lowercased()
|
||||
var map = participants[geohash] ?? [:]
|
||||
map[key] = Date()
|
||||
participants[geohash] = map
|
||||
|
||||
// Always notify observers that state has changed so counts in UI update
|
||||
objectWillChange.send()
|
||||
|
||||
// Only refresh visible list if this geohash is currently active
|
||||
if activeGeohash == geohash {
|
||||
refresh()
|
||||
}
|
||||
}
|
||||
|
||||
/// Remove a participant from all geohashes (used when blocking)
|
||||
public func removeParticipant(pubkeyHex: String) {
|
||||
let key = pubkeyHex.lowercased()
|
||||
for (gh, var map) in participants {
|
||||
map.removeValue(forKey: key)
|
||||
participants[gh] = map
|
||||
}
|
||||
refresh()
|
||||
}
|
||||
|
||||
/// Get participant count for a specific geohash
|
||||
public func participantCount(for geohash: String) -> Int {
|
||||
let cutoff = Date().addingTimeInterval(activityCutoff)
|
||||
let map = participants[geohash] ?? [:]
|
||||
return map.values.filter { $0 >= cutoff }.count
|
||||
}
|
||||
|
||||
/// Get the visible people list for the active geohash (read-only query)
|
||||
public func getVisiblePeople() -> [GeoPerson] {
|
||||
guard let gh = activeGeohash, let context = context else { return [] }
|
||||
let cutoff = Date().addingTimeInterval(activityCutoff)
|
||||
let map = (participants[gh] ?? [:])
|
||||
.filter { $0.value >= cutoff }
|
||||
.filter { !context.isBlocked($0.key) }
|
||||
|
||||
return map
|
||||
.map { (pub, seen) in
|
||||
GeoPerson(id: pub, displayName: context.displayNameForPubkey(pub), lastSeen: seen)
|
||||
}
|
||||
.sorted { $0.lastSeen > $1.lastSeen }
|
||||
}
|
||||
|
||||
/// Refresh the visible people list
|
||||
public func refresh() {
|
||||
visiblePeople = getVisiblePeople()
|
||||
}
|
||||
|
||||
/// Start the periodic refresh timer
|
||||
public func startRefreshTimer(interval: TimeInterval = 30.0) {
|
||||
stopRefreshTimer()
|
||||
refreshTimer = Timer.scheduledTimer(withTimeInterval: interval, repeats: true) { [weak self] _ in
|
||||
Task { @MainActor in
|
||||
self?.refresh()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Stop the periodic refresh timer
|
||||
public func stopRefreshTimer() {
|
||||
refreshTimer?.invalidate()
|
||||
refreshTimer = nil
|
||||
}
|
||||
|
||||
/// Clear all participant data
|
||||
public func clear() {
|
||||
participants.removeAll()
|
||||
visiblePeople = []
|
||||
}
|
||||
|
||||
/// Clear participant data for a specific geohash
|
||||
public func clear(geohash: String) {
|
||||
participants.removeValue(forKey: geohash)
|
||||
if activeGeohash == geohash {
|
||||
visiblePeople = []
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,265 @@
|
||||
//
|
||||
// GeohashPresenceService.swift
|
||||
// bitchat
|
||||
//
|
||||
// Manages the broadcasting of ephemeral presence heartbeats (Kind 20001)
|
||||
// to geohash location channels.
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import Nostr
|
||||
import Foundation
|
||||
import Combine
|
||||
import BitLogger
|
||||
import Tor
|
||||
|
||||
protocol GeohashPresenceTimerProtocol: AnyObject {
|
||||
var isValid: Bool { get }
|
||||
func invalidate()
|
||||
}
|
||||
|
||||
private final class GeohashPresenceTimerAdapter: GeohashPresenceTimerProtocol {
|
||||
private let base: Timer
|
||||
|
||||
init(base: Timer) {
|
||||
self.base = base
|
||||
}
|
||||
|
||||
var isValid: Bool { base.isValid }
|
||||
|
||||
func invalidate() {
|
||||
base.invalidate()
|
||||
}
|
||||
}
|
||||
|
||||
/// Service that coordinates the broadcasting of presence heartbeats.
|
||||
///
|
||||
/// Behavior:
|
||||
/// - Monitors location changes via LocationStateManager
|
||||
/// - Broadcasts Kind 20001 events to low-precision geohash channels
|
||||
/// - Uses randomized timing (40-80s loop) and decorrelated bursts
|
||||
/// - Respects privacy by NOT broadcasting to Neighborhood/Block/Building levels
|
||||
@MainActor
|
||||
final class GeohashPresenceService: ObservableObject {
|
||||
static let shared = GeohashPresenceService()
|
||||
|
||||
private var subscriptions = Set<AnyCancellable>()
|
||||
private var heartbeatTimer: GeohashPresenceTimerProtocol?
|
||||
private let availableChannelsProvider: () -> [GeohashChannel]
|
||||
private let locationChanges: AnyPublisher<[GeohashChannel], Never>
|
||||
private let torReadyPublisher: AnyPublisher<Void, Never>
|
||||
private let torIsReady: () -> Bool
|
||||
private let torIsForeground: () -> Bool
|
||||
private let deriveIdentity: (String) throws -> NostrIdentity
|
||||
private let relayLookup: (String, Int) -> [String]
|
||||
private let relaySender: (NostrEvent, [String]) -> Void
|
||||
private let sleeper: (UInt64) async -> Void
|
||||
private let scheduleTimer: (TimeInterval, @escaping () -> Void) -> GeohashPresenceTimerProtocol
|
||||
|
||||
// MARK: - Constants
|
||||
|
||||
// Loop interval range in seconds
|
||||
private let loopMinInterval: TimeInterval
|
||||
private let loopMaxInterval: TimeInterval
|
||||
|
||||
// Per-broadcast decorrelation delay range in seconds
|
||||
private let burstMinDelay: TimeInterval
|
||||
private let burstMaxDelay: TimeInterval
|
||||
|
||||
// Privacy: Only broadcast to these levels
|
||||
private let allowedPrecisions: Set<Int> = [
|
||||
GeohashChannelLevel.region.precision, // 2
|
||||
GeohashChannelLevel.province.precision, // 4
|
||||
GeohashChannelLevel.city.precision // 5
|
||||
]
|
||||
|
||||
private init() {
|
||||
let idBridge = NostrIdentityBridge(keychain: KeychainManager())
|
||||
self.availableChannelsProvider = { LocationStateManager.shared.availableChannels }
|
||||
self.locationChanges = LocationStateManager.shared.$availableChannels.eraseToAnyPublisher()
|
||||
self.torReadyPublisher = NotificationCenter.default.publisher(for: .TorDidBecomeReady)
|
||||
.map { _ in () }
|
||||
.eraseToAnyPublisher()
|
||||
self.torIsReady = { TorManager.shared.isReady }
|
||||
self.torIsForeground = { TorManager.shared.isForeground() }
|
||||
self.deriveIdentity = { try idBridge.deriveIdentity(forGeohash: $0) }
|
||||
self.relayLookup = { geohash, count in
|
||||
GeoRelayDirectory.shared.closestRelays(toGeohash: geohash, count: count)
|
||||
}
|
||||
self.relaySender = { event, relays in
|
||||
NostrRelayManager.shared.sendEvent(event, to: relays)
|
||||
}
|
||||
self.sleeper = { nanoseconds in
|
||||
try? await Task.sleep(nanoseconds: nanoseconds)
|
||||
}
|
||||
self.scheduleTimer = { interval, action in
|
||||
GeohashPresenceTimerAdapter(
|
||||
base: Timer.scheduledTimer(withTimeInterval: interval, repeats: false) { _ in
|
||||
action()
|
||||
}
|
||||
)
|
||||
}
|
||||
self.loopMinInterval = 40.0
|
||||
self.loopMaxInterval = 80.0
|
||||
self.burstMinDelay = 2.0
|
||||
self.burstMaxDelay = 5.0
|
||||
setupObservers()
|
||||
}
|
||||
|
||||
internal init(
|
||||
availableChannelsProvider: @escaping () -> [GeohashChannel],
|
||||
locationChanges: AnyPublisher<[GeohashChannel], Never>,
|
||||
torReadyPublisher: AnyPublisher<Void, Never>,
|
||||
torIsReady: @escaping () -> Bool,
|
||||
torIsForeground: @escaping () -> Bool,
|
||||
deriveIdentity: @escaping (String) throws -> NostrIdentity,
|
||||
relayLookup: @escaping (String, Int) -> [String],
|
||||
relaySender: @escaping (NostrEvent, [String]) -> Void,
|
||||
sleeper: @escaping (UInt64) async -> Void = { nanoseconds in try? await Task.sleep(nanoseconds: nanoseconds) },
|
||||
scheduleTimer: @escaping (TimeInterval, @escaping () -> Void) -> GeohashPresenceTimerProtocol = { interval, action in
|
||||
GeohashPresenceTimerAdapter(
|
||||
base: Timer.scheduledTimer(withTimeInterval: interval, repeats: false) { _ in
|
||||
action()
|
||||
}
|
||||
)
|
||||
},
|
||||
loopMinInterval: TimeInterval = 40.0,
|
||||
loopMaxInterval: TimeInterval = 80.0,
|
||||
burstMinDelay: TimeInterval = 2.0,
|
||||
burstMaxDelay: TimeInterval = 5.0
|
||||
) {
|
||||
self.availableChannelsProvider = availableChannelsProvider
|
||||
self.locationChanges = locationChanges
|
||||
self.torReadyPublisher = torReadyPublisher
|
||||
self.torIsReady = torIsReady
|
||||
self.torIsForeground = torIsForeground
|
||||
self.deriveIdentity = deriveIdentity
|
||||
self.relayLookup = relayLookup
|
||||
self.relaySender = relaySender
|
||||
self.sleeper = sleeper
|
||||
self.scheduleTimer = scheduleTimer
|
||||
self.loopMinInterval = loopMinInterval
|
||||
self.loopMaxInterval = loopMaxInterval
|
||||
self.burstMinDelay = burstMinDelay
|
||||
self.burstMaxDelay = burstMaxDelay
|
||||
setupObservers()
|
||||
}
|
||||
|
||||
/// Start the service (safe to call multiple times)
|
||||
func start() {
|
||||
SecureLogger.info("Presence: service starting...", category: .session)
|
||||
scheduleNextHeartbeat()
|
||||
}
|
||||
|
||||
private func setupObservers() {
|
||||
// Monitor location channel changes
|
||||
locationChanges
|
||||
.dropFirst()
|
||||
.sink { [weak self] _ in
|
||||
self?.handleLocationChange()
|
||||
}
|
||||
.store(in: &subscriptions)
|
||||
|
||||
// Monitor Tor readiness to kick off heartbeat if it was stalled
|
||||
torReadyPublisher
|
||||
.sink { [weak self] _ in
|
||||
self?.handleConnectivityChange()
|
||||
}
|
||||
.store(in: &subscriptions)
|
||||
}
|
||||
|
||||
func handleLocationChange() {
|
||||
// When location changes, we trigger an immediate (but slightly delayed) heartbeat
|
||||
// to announce presence in the new zone, then reset the loop.
|
||||
SecureLogger.debug("Presence: location changed, scheduling update", category: .session)
|
||||
heartbeatTimer?.invalidate()
|
||||
|
||||
// Small delay to allow location state to settle
|
||||
heartbeatTimer = scheduleTimer(5.0) { [weak self] in
|
||||
Task { @MainActor [weak self] in
|
||||
self?.performHeartbeat()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func handleConnectivityChange() {
|
||||
SecureLogger.debug("Presence: connectivity restored, triggering heartbeat", category: .session)
|
||||
// If we were waiting for network, do it now
|
||||
if heartbeatTimer == nil || !heartbeatTimer!.isValid {
|
||||
scheduleNextHeartbeat()
|
||||
}
|
||||
}
|
||||
|
||||
func scheduleNextHeartbeat() {
|
||||
heartbeatTimer?.invalidate()
|
||||
let interval = TimeInterval.random(in: loopMinInterval...loopMaxInterval)
|
||||
heartbeatTimer = scheduleTimer(interval) { [weak self] in
|
||||
Task { @MainActor [weak self] in
|
||||
self?.performHeartbeat()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func performHeartbeat() {
|
||||
// Always schedule next loop first ensures continuity even if this one fails/skips
|
||||
defer { scheduleNextHeartbeat() }
|
||||
|
||||
// 1. Check preconditions
|
||||
guard torIsReady() else {
|
||||
SecureLogger.debug("Presence: skipping heartbeat (Tor not ready)", category: .session)
|
||||
return
|
||||
}
|
||||
|
||||
// App must be active (or at least we shouldn't broadcast if in background, usually)
|
||||
if !torIsForeground() {
|
||||
return
|
||||
}
|
||||
|
||||
// 2. Get channels
|
||||
let channels = availableChannelsProvider()
|
||||
guard !channels.isEmpty else { return }
|
||||
|
||||
// 3. Filter and broadcast
|
||||
// We use Task + sleep for decorrelation to allow the main runloop to proceed
|
||||
for channel in channels {
|
||||
// Check privacy restriction
|
||||
if !self.allowedPrecisions.contains(channel.geohash.count) {
|
||||
continue
|
||||
}
|
||||
|
||||
// Launch independent task for each channel's delay
|
||||
Task { @MainActor in
|
||||
// Random delay for decorrelation
|
||||
let delay = TimeInterval.random(in: self.burstMinDelay...self.burstMaxDelay)
|
||||
let nanoseconds = UInt64(delay * 1_000_000_000)
|
||||
await self.sleeper(nanoseconds)
|
||||
|
||||
self.broadcastPresence(for: channel.geohash)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func broadcastPresence(for geohash: String) {
|
||||
do {
|
||||
guard let identity = try? deriveIdentity(geohash) else {
|
||||
return
|
||||
}
|
||||
|
||||
let event = try NostrProtocol.createGeohashPresenceEvent(
|
||||
geohash: geohash,
|
||||
senderIdentity: identity
|
||||
)
|
||||
|
||||
// Send via RelayManager
|
||||
let targetRelays = relayLookup(geohash, TransportConfig.nostrGeoRelayCount)
|
||||
|
||||
if !targetRelays.isEmpty {
|
||||
relaySender(event, targetRelays)
|
||||
SecureLogger.debug("Presence: sent heartbeat for \(geohash) (pub=\(identity.publicKeyHex.prefix(6))...)", category: .session)
|
||||
}
|
||||
} catch {
|
||||
SecureLogger.error("Presence: failed to create event for \(geohash): \(error)", category: .session)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -6,101 +6,90 @@
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import BitLogger
|
||||
import protocol Nostr.NostrKeychainStoring
|
||||
import protocol Noise.SecureMemoryCleaner
|
||||
import Foundation
|
||||
import Security
|
||||
import os.log
|
||||
|
||||
class KeychainManager {
|
||||
static let shared = KeychainManager()
|
||||
// MARK: - Keychain Error Types
|
||||
// BCH-01-009: Proper error classification to distinguish expected states from critical failures
|
||||
|
||||
/// Result of a keychain read operation with proper error classification
|
||||
enum KeychainReadResult {
|
||||
case success(Data)
|
||||
case itemNotFound // Expected: key doesn't exist yet
|
||||
case accessDenied // Critical: app lacks keychain access
|
||||
case deviceLocked // Recoverable: device is locked
|
||||
case authenticationFailed // Recoverable: biometric/passcode failed
|
||||
case otherError(OSStatus) // Unexpected error
|
||||
|
||||
var isRecoverableError: Bool {
|
||||
switch self {
|
||||
case .deviceLocked, .authenticationFailed:
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Result of a keychain save operation with proper error classification
|
||||
enum KeychainSaveResult {
|
||||
case success
|
||||
case duplicateItem // Can retry with update
|
||||
case accessDenied // Critical: app lacks keychain access
|
||||
case deviceLocked // Recoverable: device is locked
|
||||
case storageFull // Critical: no space available
|
||||
case otherError(OSStatus)
|
||||
|
||||
var isRecoverableError: Bool {
|
||||
switch self {
|
||||
case .duplicateItem, .deviceLocked:
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
protocol KeychainManagerProtocol: SecureMemoryCleaner, NostrKeychainStoring {
|
||||
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool
|
||||
func getIdentityKey(forKey key: String) -> Data?
|
||||
func deleteIdentityKey(forKey key: String) -> Bool
|
||||
func deleteAllKeychainData() -> Bool
|
||||
|
||||
func secureClear(_ data: inout Data)
|
||||
func secureClear(_ string: inout String)
|
||||
|
||||
func verifyIdentityKeyExists() -> Bool
|
||||
|
||||
// BCH-01-009: Methods with proper error classification
|
||||
/// Get identity key with detailed result for error handling
|
||||
func getIdentityKeyWithResult(forKey key: String) -> KeychainReadResult
|
||||
/// Save identity key with detailed result for error handling
|
||||
func saveIdentityKeyWithResult(_ keyData: Data, forKey key: String) -> KeychainSaveResult
|
||||
|
||||
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||
/// Save data with a custom service name
|
||||
func save(key: String, data: Data, service: String, accessible: CFString?)
|
||||
/// Load data from a custom service
|
||||
func load(key: String, service: String) -> Data?
|
||||
/// Delete data from a custom service
|
||||
func delete(key: String, service: String)
|
||||
}
|
||||
|
||||
final class KeychainManager: KeychainManagerProtocol {
|
||||
// Use consistent service name for all keychain items
|
||||
private let service = "chat.bitchat"
|
||||
private let appGroup = "group.chat.bitchat"
|
||||
|
||||
private init() {
|
||||
// Clean up legacy keychain items on first run
|
||||
cleanupLegacyKeychainItems()
|
||||
}
|
||||
|
||||
private func cleanupLegacyKeychainItems() {
|
||||
// Check if we've already done cleanup
|
||||
let cleanupKey = "bitchat.keychain.cleanup.v2"
|
||||
if UserDefaults.standard.bool(forKey: cleanupKey) {
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
// List of old service names to migrate from
|
||||
let legacyServices = [
|
||||
"com.bitchat.passwords",
|
||||
"com.bitchat.deviceidentity",
|
||||
"com.bitchat.noise.identity",
|
||||
"chat.bitchat.passwords",
|
||||
"bitchat.keychain"
|
||||
]
|
||||
|
||||
var migratedItems = 0
|
||||
|
||||
// Try to migrate identity keys
|
||||
for oldService in legacyServices {
|
||||
// Check for noise identity key
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: oldService,
|
||||
kSecAttrAccount as String: "identity_noiseStaticKey",
|
||||
kSecReturnData as String: true
|
||||
]
|
||||
|
||||
var result: AnyObject?
|
||||
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
||||
|
||||
if status == errSecSuccess, let data = result as? Data {
|
||||
// Save to new service
|
||||
if saveIdentityKey(data, forKey: "noiseStaticKey") {
|
||||
migratedItems += 1
|
||||
SecureLogger.logKeyOperation("migrate", keyType: "noiseStaticKey", success: true)
|
||||
}
|
||||
// Delete from old service
|
||||
let deleteQuery: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: oldService,
|
||||
kSecAttrAccount as String: "identity_noiseStaticKey"
|
||||
]
|
||||
SecItemDelete(deleteQuery as CFDictionary)
|
||||
}
|
||||
}
|
||||
|
||||
// Clean up all other legacy items
|
||||
for oldService in legacyServices {
|
||||
let deleteQuery: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: oldService
|
||||
]
|
||||
|
||||
SecItemDelete(deleteQuery as CFDictionary)
|
||||
}
|
||||
|
||||
|
||||
// Mark cleanup as done
|
||||
UserDefaults.standard.set(true, forKey: cleanupKey)
|
||||
}
|
||||
|
||||
|
||||
private func isSandboxed() -> Bool {
|
||||
#if os(macOS)
|
||||
let environment = ProcessInfo.processInfo.environment
|
||||
return environment["APP_SANDBOX_CONTAINER_ID"] != nil
|
||||
#else
|
||||
return false
|
||||
#endif
|
||||
}
|
||||
private let service = BitchatApp.bundleID
|
||||
private let appGroup = "group.\(BitchatApp.bundleID)"
|
||||
|
||||
// MARK: - Identity Keys
|
||||
|
||||
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
|
||||
let fullKey = "identity_\(key)"
|
||||
let result = saveData(keyData, forKey: fullKey)
|
||||
SecureLogger.logKeyOperation("save", keyType: key, success: result)
|
||||
SecureLogger.logKeyOperation(.save, keyType: key, success: result)
|
||||
return result
|
||||
}
|
||||
|
||||
@@ -111,10 +100,184 @@ class KeychainManager {
|
||||
|
||||
func deleteIdentityKey(forKey key: String) -> Bool {
|
||||
let result = delete(forKey: "identity_\(key)")
|
||||
SecureLogger.logKeyOperation("delete", keyType: key, success: result)
|
||||
SecureLogger.logKeyOperation(.delete, keyType: key, success: result)
|
||||
return result
|
||||
}
|
||||
|
||||
// MARK: - BCH-01-009: Methods with Proper Error Classification
|
||||
|
||||
/// Get identity key with detailed result for proper error handling
|
||||
/// Distinguishes between missing keys (expected) and critical failures
|
||||
func getIdentityKeyWithResult(forKey key: String) -> KeychainReadResult {
|
||||
let fullKey = "identity_\(key)"
|
||||
return retrieveDataWithResult(forKey: fullKey)
|
||||
}
|
||||
|
||||
/// Save identity key with detailed result and retry logic for transient errors
|
||||
func saveIdentityKeyWithResult(_ keyData: Data, forKey key: String) -> KeychainSaveResult {
|
||||
let fullKey = "identity_\(key)"
|
||||
return saveDataWithResult(keyData, forKey: fullKey)
|
||||
}
|
||||
|
||||
/// Internal method to save data with detailed result and retry for transient errors
|
||||
private func saveDataWithResult(_ data: Data, forKey key: String, retryCount: Int = 2) -> KeychainSaveResult {
|
||||
// Delete any existing item first to ensure clean state
|
||||
_ = delete(forKey: key)
|
||||
|
||||
// Build base query
|
||||
var base: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecValueData as String: data,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccessible as String: kSecAttrAccessibleWhenUnlocked,
|
||||
kSecAttrLabel as String: "bitchat-\(key)"
|
||||
]
|
||||
#if os(macOS)
|
||||
base[kSecAttrSynchronizable as String] = false
|
||||
#endif
|
||||
|
||||
func attempt(addAccessGroup: Bool) -> OSStatus {
|
||||
var query = base
|
||||
if addAccessGroup { query[kSecAttrAccessGroup as String] = appGroup }
|
||||
return SecItemAdd(query as CFDictionary, nil)
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
var status = attempt(addAccessGroup: true)
|
||||
if status == -34018 { // Missing entitlement, retry without access group
|
||||
status = attempt(addAccessGroup: false)
|
||||
}
|
||||
#else
|
||||
let status = attempt(addAccessGroup: false)
|
||||
#endif
|
||||
|
||||
// Classify the result
|
||||
let result = classifySaveStatus(status)
|
||||
|
||||
// Log all outcomes consistently
|
||||
switch result {
|
||||
case .success:
|
||||
SecureLogger.debug("Keychain save succeeded for key: \(key)", category: .keychain)
|
||||
case .duplicateItem:
|
||||
SecureLogger.warning("Keychain save found duplicate for key: \(key)", category: .keychain)
|
||||
case .accessDenied:
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)),
|
||||
context: "Keychain access denied for key: \(key)", category: .keychain)
|
||||
case .deviceLocked:
|
||||
SecureLogger.warning("Device locked during keychain save for key: \(key)", category: .keychain)
|
||||
case .storageFull:
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)),
|
||||
context: "Keychain storage full for key: \(key)", category: .keychain)
|
||||
case .otherError(let code):
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(code)),
|
||||
context: "Keychain save failed for key: \(key)", category: .keychain)
|
||||
}
|
||||
|
||||
// Retry transient errors with exponential backoff
|
||||
if result.isRecoverableError && retryCount > 0 {
|
||||
let delayMs = UInt32((3 - retryCount) * 100) // 100ms, 200ms backoff
|
||||
usleep(delayMs * 1000)
|
||||
SecureLogger.debug("Retrying keychain save for key: \(key), attempts remaining: \(retryCount)", category: .keychain)
|
||||
return saveDataWithResult(data, forKey: key, retryCount: retryCount - 1)
|
||||
}
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
/// Internal method to retrieve data with detailed result
|
||||
private func retrieveDataWithResult(forKey key: String) -> KeychainReadResult {
|
||||
let base: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecAttrService as String: service,
|
||||
kSecReturnData as String: true,
|
||||
kSecMatchLimit as String: kSecMatchLimitOne
|
||||
]
|
||||
|
||||
var result: AnyObject?
|
||||
func attempt(withAccessGroup: Bool) -> OSStatus {
|
||||
var q = base
|
||||
if withAccessGroup { q[kSecAttrAccessGroup as String] = appGroup }
|
||||
return SecItemCopyMatching(q as CFDictionary, &result)
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
var status = attempt(withAccessGroup: true)
|
||||
if status == -34018 { status = attempt(withAccessGroup: false) }
|
||||
#else
|
||||
let status = attempt(withAccessGroup: false)
|
||||
#endif
|
||||
|
||||
// Classify the result
|
||||
let readResult = classifyReadStatus(status, data: result as? Data)
|
||||
|
||||
// Log all outcomes consistently
|
||||
switch readResult {
|
||||
case .success:
|
||||
SecureLogger.debug("Keychain read succeeded for key: \(key)", category: .keychain)
|
||||
case .itemNotFound:
|
||||
// Expected case - no logging needed for missing keys
|
||||
break
|
||||
case .accessDenied:
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)),
|
||||
context: "Keychain access denied for key: \(key)", category: .keychain)
|
||||
case .deviceLocked:
|
||||
SecureLogger.warning("Device locked during keychain read for key: \(key)", category: .keychain)
|
||||
case .authenticationFailed:
|
||||
SecureLogger.warning("Authentication failed for keychain read of key: \(key)", category: .keychain)
|
||||
case .otherError(let code):
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(code)),
|
||||
context: "Keychain read failed for key: \(key)", category: .keychain)
|
||||
}
|
||||
|
||||
return readResult
|
||||
}
|
||||
|
||||
/// Classify keychain read status into meaningful categories
|
||||
private func classifyReadStatus(_ status: OSStatus, data: Data?) -> KeychainReadResult {
|
||||
switch status {
|
||||
case errSecSuccess:
|
||||
if let data = data {
|
||||
return .success(data)
|
||||
}
|
||||
return .otherError(status)
|
||||
case errSecItemNotFound:
|
||||
return .itemNotFound
|
||||
case errSecInteractionNotAllowed:
|
||||
// Device is locked or in a state that doesn't allow keychain access
|
||||
return .deviceLocked
|
||||
case errSecAuthFailed:
|
||||
return .authenticationFailed
|
||||
case -34018: // errSecMissingEntitlement
|
||||
return .accessDenied
|
||||
case errSecNotAvailable:
|
||||
return .accessDenied
|
||||
default:
|
||||
return .otherError(status)
|
||||
}
|
||||
}
|
||||
|
||||
/// Classify keychain save status into meaningful categories
|
||||
private func classifySaveStatus(_ status: OSStatus) -> KeychainSaveResult {
|
||||
switch status {
|
||||
case errSecSuccess:
|
||||
return .success
|
||||
case errSecDuplicateItem:
|
||||
return .duplicateItem
|
||||
case errSecInteractionNotAllowed:
|
||||
return .deviceLocked
|
||||
case -34018: // errSecMissingEntitlement
|
||||
return .accessDenied
|
||||
case errSecNotAvailable:
|
||||
return .accessDenied
|
||||
case errSecDiskFull:
|
||||
return .storageFull
|
||||
default:
|
||||
return .otherError(status)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Generic Operations
|
||||
|
||||
private func save(_ value: String, forKey key: String) -> Bool {
|
||||
@@ -126,39 +289,44 @@ class KeychainManager {
|
||||
// Delete any existing item first to ensure clean state
|
||||
_ = delete(forKey: key)
|
||||
|
||||
// Build query with all necessary attributes for sandboxed apps
|
||||
var query: [String: Any] = [
|
||||
// Build base query
|
||||
var base: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecValueData as String: data,
|
||||
kSecAttrService as String: service,
|
||||
// Important for sandboxed apps: make it accessible when unlocked
|
||||
kSecAttrAccessible as String: kSecAttrAccessibleWhenUnlocked
|
||||
kSecAttrAccessible as String: kSecAttrAccessibleWhenUnlocked,
|
||||
kSecAttrLabel as String: "bitchat-\(key)"
|
||||
]
|
||||
|
||||
// Add a label for easier debugging
|
||||
query[kSecAttrLabel as String] = "bitchat-\(key)"
|
||||
|
||||
// For sandboxed apps, use the app group for sharing between app instances
|
||||
if isSandboxed() {
|
||||
query[kSecAttrAccessGroup as String] = appGroup
|
||||
}
|
||||
|
||||
// For sandboxed macOS apps, we need to ensure the item is NOT synchronized
|
||||
#if os(macOS)
|
||||
query[kSecAttrSynchronizable as String] = false
|
||||
base[kSecAttrSynchronizable as String] = false
|
||||
#endif
|
||||
|
||||
let status = SecItemAdd(query as CFDictionary, nil)
|
||||
|
||||
if status == errSecSuccess {
|
||||
return true
|
||||
} else if status == -34018 {
|
||||
SecureLogger.logError(NSError(domain: "Keychain", code: -34018), context: "Missing keychain entitlement", category: SecureLogger.keychain)
|
||||
} else if status != errSecDuplicateItem {
|
||||
SecureLogger.logError(NSError(domain: "Keychain", code: Int(status)), context: "Error saving to keychain", category: SecureLogger.keychain)
|
||||
// Try with access group where it is expected to work (iOS app builds)
|
||||
var triedWithoutGroup = false
|
||||
func attempt(addAccessGroup: Bool) -> OSStatus {
|
||||
var query = base
|
||||
if addAccessGroup { query[kSecAttrAccessGroup as String] = appGroup }
|
||||
return SecItemAdd(query as CFDictionary, nil)
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
var status = attempt(addAccessGroup: true)
|
||||
if status == -34018 { // Missing entitlement, retry without access group
|
||||
triedWithoutGroup = true
|
||||
status = attempt(addAccessGroup: false)
|
||||
}
|
||||
#else
|
||||
// On macOS dev/simulator default to no access group to avoid -34018
|
||||
let status = attempt(addAccessGroup: false)
|
||||
#endif
|
||||
|
||||
if status == errSecSuccess { return true }
|
||||
if status == -34018 && !triedWithoutGroup {
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -34018), context: "Missing keychain entitlement", category: .keychain)
|
||||
} else if status != errSecDuplicateItem {
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)), context: "Error saving to keychain", category: .keychain)
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
@@ -168,7 +336,8 @@ class KeychainManager {
|
||||
}
|
||||
|
||||
private func retrieveData(forKey key: String) -> Data? {
|
||||
var query: [String: Any] = [
|
||||
// Base query
|
||||
let base: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecAttrService as String: service,
|
||||
@@ -176,37 +345,47 @@ class KeychainManager {
|
||||
kSecMatchLimit as String: kSecMatchLimitOne
|
||||
]
|
||||
|
||||
// For sandboxed apps, use the app group
|
||||
if isSandboxed() {
|
||||
query[kSecAttrAccessGroup as String] = appGroup
|
||||
}
|
||||
|
||||
var result: AnyObject?
|
||||
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
||||
|
||||
if status == errSecSuccess {
|
||||
return result as? Data
|
||||
} else if status == -34018 {
|
||||
SecureLogger.logError(NSError(domain: "Keychain", code: -34018), context: "Missing keychain entitlement", category: SecureLogger.keychain)
|
||||
func attempt(withAccessGroup: Bool) -> OSStatus {
|
||||
var q = base
|
||||
if withAccessGroup { q[kSecAttrAccessGroup as String] = appGroup }
|
||||
return SecItemCopyMatching(q as CFDictionary, &result)
|
||||
}
|
||||
|
||||
#if os(iOS)
|
||||
var status = attempt(withAccessGroup: true)
|
||||
if status == -34018 { status = attempt(withAccessGroup: false) }
|
||||
#else
|
||||
let status = attempt(withAccessGroup: false)
|
||||
#endif
|
||||
|
||||
if status == errSecSuccess { return result as? Data }
|
||||
if status == -34018 {
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -34018), context: "Missing keychain entitlement", category: .keychain)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
private func delete(forKey key: String) -> Bool {
|
||||
// Build basic query
|
||||
var query: [String: Any] = [
|
||||
// Base delete query
|
||||
let base: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecAttrService as String: service
|
||||
]
|
||||
|
||||
// For sandboxed apps, use the app group
|
||||
if isSandboxed() {
|
||||
query[kSecAttrAccessGroup as String] = appGroup
|
||||
func attempt(withAccessGroup: Bool) -> OSStatus {
|
||||
var q = base
|
||||
if withAccessGroup { q[kSecAttrAccessGroup as String] = appGroup }
|
||||
return SecItemDelete(q as CFDictionary)
|
||||
}
|
||||
|
||||
let status = SecItemDelete(query as CFDictionary)
|
||||
#if os(iOS)
|
||||
var status = attempt(withAccessGroup: true)
|
||||
if status == -34018 { status = attempt(withAccessGroup: false) }
|
||||
#else
|
||||
let status = attempt(withAccessGroup: false)
|
||||
#endif
|
||||
return status == errSecSuccess || status == errSecItemNotFound
|
||||
}
|
||||
|
||||
@@ -226,15 +405,10 @@ class KeychainManager {
|
||||
return status == errSecSuccess || status == errSecItemNotFound
|
||||
}
|
||||
|
||||
// Force cleanup to run again (for development/testing)
|
||||
func resetCleanupFlag() {
|
||||
UserDefaults.standard.removeObject(forKey: "bitchat.keychain.cleanup.v2")
|
||||
}
|
||||
|
||||
|
||||
// Delete ALL keychain data for panic mode
|
||||
func deleteAllKeychainData() -> Bool {
|
||||
SecureLogger.log("Panic mode - deleting all keychain data", category: SecureLogger.security, level: .warning)
|
||||
SecureLogger.warning("Panic mode - deleting all keychain data", category: .security)
|
||||
|
||||
var totalDeleted = 0
|
||||
|
||||
@@ -253,10 +427,25 @@ class KeychainManager {
|
||||
var shouldDelete = false
|
||||
let account = item[kSecAttrAccount as String] as? String ?? ""
|
||||
let service = item[kSecAttrService as String] as? String ?? ""
|
||||
let accessGroup = item[kSecAttrAccessGroup as String] as? String
|
||||
|
||||
// ONLY delete if service name contains "bitchat"
|
||||
// This is the safest approach - we only touch items we know are ours
|
||||
if service.lowercased().contains("bitchat") {
|
||||
// More precise deletion criteria:
|
||||
// 1. Check for our specific app group
|
||||
// 2. OR check for our exact service name
|
||||
// 3. OR check for known legacy service names
|
||||
if accessGroup == appGroup {
|
||||
shouldDelete = true
|
||||
} else if service == self.service {
|
||||
shouldDelete = true
|
||||
} else if [
|
||||
"com.bitchat.passwords",
|
||||
"com.bitchat.deviceidentity",
|
||||
"com.bitchat.noise.identity",
|
||||
"chat.bitchat.passwords",
|
||||
"bitchat.keychain",
|
||||
"bitchat",
|
||||
"com.bitchat"
|
||||
].contains(service) {
|
||||
shouldDelete = true
|
||||
}
|
||||
|
||||
@@ -282,19 +471,21 @@ class KeychainManager {
|
||||
let deleteStatus = SecItemDelete(deleteQuery as CFDictionary)
|
||||
if deleteStatus == errSecSuccess {
|
||||
totalDeleted += 1
|
||||
SecureLogger.log("Deleted keychain item: \(account) from \(service)", category: SecureLogger.keychain, level: .info)
|
||||
SecureLogger.info("Deleted keychain item: \(account) from \(service)", category: .keychain)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Also try to delete by known service names (in case we missed any)
|
||||
// Also try to delete by known service names and app group
|
||||
// This catches any items that might have been missed above
|
||||
let knownServices = [
|
||||
"chat.bitchat",
|
||||
self.service, // Current service name
|
||||
"com.bitchat.passwords",
|
||||
"com.bitchat.deviceidentity",
|
||||
"com.bitchat.noise.identity",
|
||||
"chat.bitchat.passwords",
|
||||
"chat.bitchat.nostr",
|
||||
"bitchat.keychain",
|
||||
"bitchat",
|
||||
"com.bitchat"
|
||||
@@ -312,11 +503,42 @@ class KeychainManager {
|
||||
}
|
||||
}
|
||||
|
||||
SecureLogger.log("Panic mode cleanup completed. Total items deleted: \(totalDeleted)", category: SecureLogger.keychain, level: .warning)
|
||||
// Also delete by app group to ensure complete cleanup
|
||||
let groupQuery: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrAccessGroup as String: appGroup
|
||||
]
|
||||
|
||||
let groupStatus = SecItemDelete(groupQuery as CFDictionary)
|
||||
if groupStatus == errSecSuccess {
|
||||
totalDeleted += 1
|
||||
}
|
||||
|
||||
SecureLogger.warning("Panic mode cleanup completed. Total items deleted: \(totalDeleted)", category: .keychain)
|
||||
|
||||
return totalDeleted > 0
|
||||
}
|
||||
|
||||
// MARK: - Security Utilities
|
||||
|
||||
/// Securely clear sensitive data from memory
|
||||
func secureClear(_ data: inout Data) {
|
||||
_ = data.withUnsafeMutableBytes { bytes in
|
||||
// Use volatile memset to prevent compiler optimization
|
||||
memset_s(bytes.baseAddress, bytes.count, 0, bytes.count)
|
||||
}
|
||||
data = Data() // Clear the data object
|
||||
}
|
||||
|
||||
/// Securely clear sensitive string from memory
|
||||
func secureClear(_ string: inout String) {
|
||||
// Convert to mutable data and clear
|
||||
if var data = string.data(using: .utf8) {
|
||||
secureClear(&data)
|
||||
}
|
||||
string = "" // Clear the string object
|
||||
}
|
||||
|
||||
// MARK: - Debug
|
||||
|
||||
func verifyIdentityKeyExists() -> Bool {
|
||||
@@ -324,75 +546,48 @@ class KeychainManager {
|
||||
return retrieveData(forKey: key) != nil
|
||||
}
|
||||
|
||||
// Aggressive cleanup for legacy items - can be called manually
|
||||
func aggressiveCleanupLegacyItems() -> Int {
|
||||
var deletedCount = 0
|
||||
// MARK: - Generic Data Storage (consolidated from KeychainHelper)
|
||||
|
||||
// List of KNOWN bitchat service names from our development history
|
||||
let knownBitchatServices = [
|
||||
"com.bitchat.passwords",
|
||||
"com.bitchat.deviceidentity",
|
||||
"com.bitchat.noise.identity",
|
||||
"chat.bitchat.passwords",
|
||||
"bitchat.keychain",
|
||||
"Bitchat",
|
||||
"BitChat"
|
||||
/// Save data with a custom service name
|
||||
func save(key: String, data: Data, service customService: String, accessible: CFString?) {
|
||||
var query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: customService,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecValueData as String: data
|
||||
]
|
||||
|
||||
// First, delete all items from known legacy services
|
||||
for legacyService in knownBitchatServices {
|
||||
let deleteQuery: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: legacyService
|
||||
]
|
||||
|
||||
let status = SecItemDelete(deleteQuery as CFDictionary)
|
||||
if status == errSecSuccess {
|
||||
deletedCount += 1
|
||||
}
|
||||
if let accessible = accessible {
|
||||
query[kSecAttrAccessible as String] = accessible
|
||||
}
|
||||
|
||||
// Now search for items that have our specific account patterns with bitchat service names
|
||||
let searchQuery: [String: Any] = [
|
||||
SecItemDelete(query as CFDictionary)
|
||||
SecItemAdd(query as CFDictionary, nil)
|
||||
}
|
||||
|
||||
/// Load data from a custom service
|
||||
func load(key: String, service customService: String) -> Data? {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecMatchLimit as String: kSecMatchLimitAll,
|
||||
kSecReturnAttributes as String: true
|
||||
kSecAttrService as String: customService,
|
||||
kSecAttrAccount as String: key,
|
||||
kSecReturnData as String: true
|
||||
]
|
||||
|
||||
var result: AnyObject?
|
||||
let status = SecItemCopyMatching(searchQuery as CFDictionary, &result)
|
||||
let status = SecItemCopyMatching(query as CFDictionary, &result)
|
||||
|
||||
if status == errSecSuccess, let items = result as? [[String: Any]] {
|
||||
for item in items {
|
||||
let account = item[kSecAttrAccount as String] as? String ?? ""
|
||||
let service = item[kSecAttrService as String] as? String ?? ""
|
||||
guard status == errSecSuccess else { return nil }
|
||||
return result as? Data
|
||||
}
|
||||
|
||||
// ONLY delete if service name contains "bitchat" somewhere
|
||||
// This ensures we never touch other apps' keychain items
|
||||
var shouldDelete = false
|
||||
/// Delete data from a custom service
|
||||
func delete(key: String, service customService: String) {
|
||||
let query: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: customService,
|
||||
kSecAttrAccount as String: key
|
||||
]
|
||||
|
||||
// Check if service contains "bitchat" (case insensitive) but NOT our current service
|
||||
let serviceLower = service.lowercased()
|
||||
if service != self.service && serviceLower.contains("bitchat") {
|
||||
shouldDelete = true
|
||||
}
|
||||
|
||||
if shouldDelete {
|
||||
// Build precise delete query
|
||||
let deleteQuery: [String: Any] = [
|
||||
kSecClass as String: kSecClassGenericPassword,
|
||||
kSecAttrService as String: service,
|
||||
kSecAttrAccount as String: account
|
||||
]
|
||||
|
||||
let deleteStatus = SecItemDelete(deleteQuery as CFDictionary)
|
||||
if deleteStatus == errSecSuccess {
|
||||
deletedCount += 1
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return deletedCount
|
||||
SecItemDelete(query as CFDictionary)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,257 @@
|
||||
import BitLogger
|
||||
import Nostr
|
||||
import Foundation
|
||||
|
||||
/// Dependencies for location notes, allowing tests to stub relay/identity behavior.
|
||||
struct LocationNotesDependencies {
|
||||
typealias RelayLookup = @MainActor (_ geohash: String, _ count: Int) -> [String]
|
||||
typealias Subscribe = @MainActor (_ filter: NostrFilter, _ id: String, _ relays: [String], _ handler: @escaping (NostrEvent) -> Void, _ onEOSE: (() -> Void)?) -> Void
|
||||
typealias Unsubscribe = @MainActor (_ id: String) -> Void
|
||||
typealias SendEvent = @MainActor (_ event: NostrEvent, _ relayUrls: [String]) -> Void
|
||||
|
||||
var relayLookup: RelayLookup
|
||||
var subscribe: Subscribe
|
||||
var unsubscribe: Unsubscribe
|
||||
var sendEvent: SendEvent
|
||||
var deriveIdentity: (_ geohash: String) throws -> NostrIdentity
|
||||
var now: () -> Date
|
||||
|
||||
private static let idBridge = NostrIdentityBridge(keychain: KeychainManager())
|
||||
|
||||
static let live = LocationNotesDependencies(
|
||||
relayLookup: { geohash, count in
|
||||
GeoRelayDirectory.shared.closestRelays(toGeohash: geohash, count: count)
|
||||
},
|
||||
subscribe: { filter, id, relays, handler, onEOSE in
|
||||
NostrRelayManager.shared.subscribe(
|
||||
filter: filter,
|
||||
id: id,
|
||||
relayUrls: relays,
|
||||
handler: handler,
|
||||
onEOSE: onEOSE
|
||||
)
|
||||
},
|
||||
unsubscribe: { id in
|
||||
NostrRelayManager.shared.unsubscribe(id: id)
|
||||
},
|
||||
sendEvent: { event, relays in
|
||||
NostrRelayManager.shared.sendEvent(event, to: relays)
|
||||
},
|
||||
deriveIdentity: { geohash in
|
||||
try idBridge.deriveIdentity(forGeohash: geohash)
|
||||
},
|
||||
now: { Date() }
|
||||
)
|
||||
}
|
||||
|
||||
/// Persistent location notes (Nostr kind 1) scoped to a building-level geohash (precision 8).
|
||||
/// Subscribes to and publishes notes for a given geohash and provides a send API.
|
||||
@MainActor
|
||||
final class LocationNotesManager: ObservableObject {
|
||||
enum State: Equatable {
|
||||
case idle
|
||||
case loading
|
||||
case ready
|
||||
case noRelays
|
||||
}
|
||||
|
||||
struct Note: Identifiable, Equatable {
|
||||
let id: String
|
||||
let pubkey: String
|
||||
let content: String
|
||||
let createdAt: Date
|
||||
let nickname: String?
|
||||
|
||||
var displayName: String {
|
||||
let suffix = String(pubkey.suffix(4))
|
||||
if let nick = nickname?.trimmedOrNilIfEmpty {
|
||||
return "\(nick)#\(suffix)"
|
||||
}
|
||||
return "anon#\(suffix)"
|
||||
}
|
||||
}
|
||||
|
||||
@Published private(set) var notes: [Note] = [] // reverse-chron sorted
|
||||
@Published private(set) var geohash: String
|
||||
@Published private(set) var initialLoadComplete: Bool = false
|
||||
@Published private(set) var state: State = .loading
|
||||
@Published private(set) var errorMessage: String?
|
||||
private var subscriptionID: String?
|
||||
private var noteIDs = Set<String>() // O(1) duplicate detection
|
||||
private let dependencies: LocationNotesDependencies
|
||||
private let maxNotesInMemory = 500 // Defensive cap (relay limit is 200)
|
||||
|
||||
private enum Strings {
|
||||
static let noRelays = String(localized: "location_notes.error.no_relays", comment: "Shown when no geo relays are available near the selected location")
|
||||
|
||||
static func failedToSend(_ detail: String) -> String {
|
||||
String(
|
||||
format: String(localized: "location_notes.error.failed_to_send", comment: "Shown when a location note fails to send"),
|
||||
locale: .current,
|
||||
detail
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
init(geohash: String, dependencies: LocationNotesDependencies = .live) {
|
||||
let norm = geohash.lowercased()
|
||||
self.geohash = norm
|
||||
self.dependencies = dependencies
|
||||
// Validate geohash (building-level precision: 8 chars)
|
||||
if !Geohash.isValidBuildingGeohash(norm) {
|
||||
SecureLogger.warning("LocationNotesManager: invalid geohash '\(norm)' (expected 8 valid base32 chars)", category: .session)
|
||||
}
|
||||
subscribe()
|
||||
}
|
||||
|
||||
func setGeohash(_ newGeohash: String) {
|
||||
let norm = newGeohash.lowercased()
|
||||
guard norm != geohash else { return }
|
||||
// Validate geohash (building-level precision: 8 chars)
|
||||
guard Geohash.isValidBuildingGeohash(norm) else {
|
||||
SecureLogger.warning("LocationNotesManager: rejecting invalid geohash '\(norm)' (expected 8 valid base32 chars)", category: .session)
|
||||
return
|
||||
}
|
||||
if let sub = subscriptionID {
|
||||
dependencies.unsubscribe(sub)
|
||||
subscriptionID = nil
|
||||
}
|
||||
// Set loading state before clearing to prevent empty state flicker
|
||||
state = .loading
|
||||
initialLoadComplete = false
|
||||
errorMessage = nil
|
||||
geohash = norm
|
||||
notes.removeAll()
|
||||
noteIDs.removeAll()
|
||||
subscribe()
|
||||
}
|
||||
|
||||
func refresh() {
|
||||
if let sub = subscriptionID {
|
||||
dependencies.unsubscribe(sub)
|
||||
subscriptionID = nil
|
||||
}
|
||||
// Set loading state before clearing to prevent empty state flicker
|
||||
state = .loading
|
||||
initialLoadComplete = false
|
||||
errorMessage = nil
|
||||
notes.removeAll()
|
||||
noteIDs.removeAll()
|
||||
subscribe()
|
||||
}
|
||||
|
||||
func clearError() {
|
||||
errorMessage = nil
|
||||
}
|
||||
|
||||
private func subscribe() {
|
||||
state = .loading
|
||||
errorMessage = nil
|
||||
if let sub = subscriptionID {
|
||||
dependencies.unsubscribe(sub)
|
||||
subscriptionID = nil
|
||||
}
|
||||
let subID = "locnotes-\(geohash)-\(UUID().uuidString.prefix(8))"
|
||||
let relays = dependencies.relayLookup(geohash, TransportConfig.nostrGeoRelayCount)
|
||||
guard !relays.isEmpty else {
|
||||
subscriptionID = nil
|
||||
initialLoadComplete = true
|
||||
state = .noRelays
|
||||
errorMessage = Strings.noRelays
|
||||
SecureLogger.warning("LocationNotesManager: no geo relays for geohash=\(geohash)", category: .session)
|
||||
return
|
||||
}
|
||||
|
||||
subscriptionID = subID
|
||||
initialLoadComplete = false
|
||||
|
||||
// Subscribe to center + 8 neighbors (± 1 grid)
|
||||
let neighbors = Geohash.neighbors(of: geohash)
|
||||
let allGeohashes = [geohash] + neighbors
|
||||
let filter = NostrFilter.geohashNotes(allGeohashes, since: nil, limit: 200)
|
||||
|
||||
// Build a set of valid geohashes for tag matching (includes all 9 cells)
|
||||
let validGeohashes = Set(allGeohashes.map { $0.lowercased() })
|
||||
|
||||
dependencies.subscribe(filter, subID, relays, { [weak self] event in
|
||||
guard let self = self else { return }
|
||||
guard event.kind == NostrProtocol.EventKind.textNote.rawValue else { return }
|
||||
// Ensure matching tag - accept any of our 9 geohashes
|
||||
guard event.tags.contains(where: { tag in
|
||||
tag.count >= 2 && tag[0].lowercased() == "g" && validGeohashes.contains(tag[1].lowercased())
|
||||
}) else { return }
|
||||
guard !self.noteIDs.contains(event.id) else { return }
|
||||
self.noteIDs.insert(event.id)
|
||||
let nick = event.tags.first(where: { $0.first?.lowercased() == "n" && $0.count >= 2 })?.dropFirst().first
|
||||
let ts = Date(timeIntervalSince1970: TimeInterval(event.created_at))
|
||||
let note = Note(id: event.id, pubkey: event.pubkey, content: event.content, createdAt: ts, nickname: nick)
|
||||
self.notes.append(note)
|
||||
self.notes.sort { $0.createdAt > $1.createdAt }
|
||||
self.enforceMemoryCap()
|
||||
self.state = .ready
|
||||
}, { [weak self] in
|
||||
guard let self = self else { return }
|
||||
self.initialLoadComplete = true
|
||||
if self.state != .noRelays {
|
||||
self.state = .ready
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
/// Send a location note for the current geohash using the per-geohash identity.
|
||||
func send(content: String, nickname: String) {
|
||||
guard let trimmed = content.trimmedOrNilIfEmpty else { return }
|
||||
let relays = dependencies.relayLookup(geohash, TransportConfig.nostrGeoRelayCount)
|
||||
guard !relays.isEmpty else {
|
||||
state = .noRelays
|
||||
errorMessage = Strings.noRelays
|
||||
SecureLogger.warning("LocationNotesManager: send blocked, no geo relays for geohash=\(geohash)", category: .session)
|
||||
return
|
||||
}
|
||||
do {
|
||||
let id = try dependencies.deriveIdentity(geohash)
|
||||
let event = try NostrProtocol.createGeohashTextNote(
|
||||
content: trimmed,
|
||||
geohash: geohash,
|
||||
senderIdentity: id,
|
||||
nickname: nickname
|
||||
)
|
||||
dependencies.sendEvent(event, relays)
|
||||
// Optimistic local-echo
|
||||
let echo = Note(
|
||||
id: event.id,
|
||||
pubkey: id.publicKeyHex,
|
||||
content: trimmed,
|
||||
createdAt: Date(timeIntervalSince1970: TimeInterval(event.created_at)),
|
||||
nickname: nickname
|
||||
)
|
||||
self.noteIDs.insert(event.id)
|
||||
self.notes.insert(echo, at: 0)
|
||||
self.enforceMemoryCap()
|
||||
self.state = .ready
|
||||
self.errorMessage = nil
|
||||
} catch {
|
||||
SecureLogger.error("LocationNotesManager: failed to send note: \(error)", category: .session)
|
||||
errorMessage = Strings.failedToSend(error.localizedDescription)
|
||||
}
|
||||
}
|
||||
|
||||
/// Enforces defensive memory cap on notes array (keeps newest).
|
||||
private func enforceMemoryCap() {
|
||||
if notes.count > maxNotesInMemory {
|
||||
let removed = notes.count - maxNotesInMemory
|
||||
notes = Array(notes.prefix(maxNotesInMemory))
|
||||
SecureLogger.debug("LocationNotesManager: trimmed \(removed) old notes (cap: \(maxNotesInMemory))", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
/// Explicitly cancel subscription and release resources.
|
||||
func cancel() {
|
||||
if let sub = subscriptionID {
|
||||
dependencies.unsubscribe(sub)
|
||||
subscriptionID = nil
|
||||
}
|
||||
state = .idle
|
||||
errorMessage = nil
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,630 @@
|
||||
import BitLogger
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
#if os(iOS) || os(macOS)
|
||||
import CoreLocation
|
||||
|
||||
protocol LocationStateManaging: AnyObject {
|
||||
var delegate: CLLocationManagerDelegate? { get set }
|
||||
var desiredAccuracy: CLLocationAccuracy { get set }
|
||||
var distanceFilter: CLLocationDistance { get set }
|
||||
var authorizationStatus: CLAuthorizationStatus { get }
|
||||
func requestWhenInUseAuthorization()
|
||||
func requestLocation()
|
||||
func startUpdatingLocation()
|
||||
func stopUpdatingLocation()
|
||||
}
|
||||
|
||||
protocol LocationStateGeocoding: AnyObject {
|
||||
func cancelGeocode()
|
||||
func reverseGeocodeLocation(
|
||||
_ location: CLLocation,
|
||||
completionHandler: @escaping ([CLPlacemark]?, Error?) -> Void
|
||||
)
|
||||
}
|
||||
|
||||
private final class CLLocationManagerAdapter: NSObject, LocationStateManaging {
|
||||
private let base = CLLocationManager()
|
||||
|
||||
var delegate: CLLocationManagerDelegate? {
|
||||
get { base.delegate }
|
||||
set { base.delegate = newValue }
|
||||
}
|
||||
|
||||
var desiredAccuracy: CLLocationAccuracy {
|
||||
get { base.desiredAccuracy }
|
||||
set { base.desiredAccuracy = newValue }
|
||||
}
|
||||
|
||||
var distanceFilter: CLLocationDistance {
|
||||
get { base.distanceFilter }
|
||||
set { base.distanceFilter = newValue }
|
||||
}
|
||||
|
||||
var authorizationStatus: CLAuthorizationStatus {
|
||||
base.authorizationStatus
|
||||
}
|
||||
|
||||
func requestWhenInUseAuthorization() {
|
||||
base.requestWhenInUseAuthorization()
|
||||
}
|
||||
|
||||
func requestLocation() {
|
||||
base.requestLocation()
|
||||
}
|
||||
|
||||
func startUpdatingLocation() {
|
||||
base.startUpdatingLocation()
|
||||
}
|
||||
|
||||
func stopUpdatingLocation() {
|
||||
base.stopUpdatingLocation()
|
||||
}
|
||||
}
|
||||
|
||||
private final class CLGeocoderAdapter: LocationStateGeocoding {
|
||||
private let base = CLGeocoder()
|
||||
|
||||
func cancelGeocode() {
|
||||
base.cancelGeocode()
|
||||
}
|
||||
|
||||
func reverseGeocodeLocation(
|
||||
_ location: CLLocation,
|
||||
completionHandler: @escaping ([CLPlacemark]?, Error?) -> Void
|
||||
) {
|
||||
base.reverseGeocodeLocation(location, completionHandler: completionHandler)
|
||||
}
|
||||
}
|
||||
|
||||
/// Unified manager for location-based channel state including:
|
||||
/// - CoreLocation permissions and one-shot location retrieval
|
||||
/// - Geohash channel computation from coordinates
|
||||
/// - Channel selection and teleport state
|
||||
/// - Bookmark persistence and friendly name resolution
|
||||
///
|
||||
/// Consolidates LocationChannelManager + GeohashBookmarksStore into a single source of truth.
|
||||
final class LocationStateManager: NSObject, CLLocationManagerDelegate, ObservableObject {
|
||||
static let shared = LocationStateManager()
|
||||
|
||||
// MARK: - Permission State
|
||||
|
||||
enum PermissionState: Equatable {
|
||||
case notDetermined
|
||||
case denied
|
||||
case restricted
|
||||
case authorized
|
||||
}
|
||||
|
||||
// MARK: - Private Properties (CoreLocation)
|
||||
|
||||
private let cl: LocationStateManaging
|
||||
private let geocoder: LocationStateGeocoding
|
||||
private var lastLocation: CLLocation?
|
||||
private var refreshTimer: Timer?
|
||||
private var isGeocoding: Bool = false
|
||||
|
||||
// MARK: - Persistence Keys
|
||||
|
||||
private let selectedChannelKey = "locationChannel.selected"
|
||||
private let teleportedStoreKey = "locationChannel.teleportedSet"
|
||||
private let bookmarksKey = "locationChannel.bookmarks"
|
||||
private let bookmarkNamesKey = "locationChannel.bookmarkNames"
|
||||
|
||||
// MARK: - Published State (Channel)
|
||||
|
||||
@Published private(set) var permissionState: PermissionState = .notDetermined
|
||||
@Published private(set) var availableChannels: [GeohashChannel] = []
|
||||
@Published private(set) var selectedChannel: ChannelID = .mesh
|
||||
@Published var teleported: Bool = false
|
||||
@Published private(set) var locationNames: [GeohashChannelLevel: String] = [:]
|
||||
|
||||
// MARK: - Published State (Bookmarks)
|
||||
|
||||
@Published private(set) var bookmarks: [String] = []
|
||||
@Published private(set) var bookmarkNames: [String: String] = [:]
|
||||
|
||||
// MARK: - Private State
|
||||
|
||||
private var teleportedSet: Set<String> = []
|
||||
private var bookmarkMembership: Set<String> = []
|
||||
private var resolvingNames: Set<String> = []
|
||||
private let storage: UserDefaults
|
||||
|
||||
/// Returns true if running in test environment
|
||||
private static var isRunningTests: Bool {
|
||||
let env = ProcessInfo.processInfo.environment
|
||||
return NSClassFromString("XCTestCase") != nil ||
|
||||
env["XCTestConfigurationFilePath"] != nil ||
|
||||
env["XCTestBundlePath"] != nil ||
|
||||
env["GITHUB_ACTIONS"] != nil ||
|
||||
env["CI"] != nil
|
||||
}
|
||||
|
||||
// MARK: - Initialization
|
||||
|
||||
private override init() {
|
||||
self.storage = .standard
|
||||
self.cl = CLLocationManagerAdapter()
|
||||
self.geocoder = CLGeocoderAdapter()
|
||||
super.init()
|
||||
|
||||
// Skip CoreLocation setup in test environments
|
||||
guard !Self.isRunningTests else {
|
||||
loadPersistedState()
|
||||
return
|
||||
}
|
||||
|
||||
cl.delegate = self
|
||||
cl.desiredAccuracy = kCLLocationAccuracyHundredMeters
|
||||
cl.distanceFilter = TransportConfig.locationDistanceFilterMeters
|
||||
|
||||
loadPersistedState()
|
||||
initializePermissionState()
|
||||
}
|
||||
|
||||
/// Internal initializer for testing with custom storage
|
||||
init(storage: UserDefaults) {
|
||||
self.storage = storage
|
||||
self.cl = CLLocationManagerAdapter()
|
||||
self.geocoder = CLGeocoderAdapter()
|
||||
super.init()
|
||||
loadPersistedState()
|
||||
}
|
||||
|
||||
internal init(
|
||||
storage: UserDefaults,
|
||||
locationManager: LocationStateManaging,
|
||||
geocoder: LocationStateGeocoding,
|
||||
shouldInitializeCoreLocation: Bool
|
||||
) {
|
||||
self.storage = storage
|
||||
self.cl = locationManager
|
||||
self.geocoder = geocoder
|
||||
super.init()
|
||||
loadPersistedState()
|
||||
guard shouldInitializeCoreLocation else { return }
|
||||
cl.delegate = self
|
||||
cl.desiredAccuracy = kCLLocationAccuracyHundredMeters
|
||||
cl.distanceFilter = TransportConfig.locationDistanceFilterMeters
|
||||
initializePermissionState()
|
||||
}
|
||||
|
||||
private func loadPersistedState() {
|
||||
// Load selected channel
|
||||
if let data = storage.data(forKey: selectedChannelKey),
|
||||
let channel = try? JSONDecoder().decode(ChannelID.self, from: data) {
|
||||
selectedChannel = channel
|
||||
}
|
||||
|
||||
// Load teleported set
|
||||
if let data = storage.data(forKey: teleportedStoreKey),
|
||||
let arr = try? JSONDecoder().decode([String].self, from: data) {
|
||||
teleportedSet = Set(arr)
|
||||
}
|
||||
|
||||
// Load bookmarks
|
||||
if let data = storage.data(forKey: bookmarksKey),
|
||||
let arr = try? JSONDecoder().decode([String].self, from: data) {
|
||||
var seen = Set<String>()
|
||||
var list: [String] = []
|
||||
for raw in arr {
|
||||
let gh = Self.normalizeGeohash(raw)
|
||||
guard !gh.isEmpty, !seen.contains(gh) else { continue }
|
||||
seen.insert(gh)
|
||||
list.append(gh)
|
||||
}
|
||||
bookmarks = list
|
||||
bookmarkMembership = seen
|
||||
}
|
||||
|
||||
// Load bookmark names
|
||||
if let data = storage.data(forKey: bookmarkNamesKey),
|
||||
let dict = try? JSONDecoder().decode([String: String].self, from: data) {
|
||||
bookmarkNames = dict
|
||||
}
|
||||
}
|
||||
|
||||
private func initializePermissionState() {
|
||||
let status = cl.authorizationStatus
|
||||
updatePermissionState(from: status)
|
||||
|
||||
// Fall back to persisted teleport state if no location authorization
|
||||
switch status {
|
||||
case .authorizedAlways, .authorizedWhenInUse, .authorized:
|
||||
break
|
||||
case .notDetermined, .restricted, .denied:
|
||||
fallthrough
|
||||
@unknown default:
|
||||
if case .location(let ch) = selectedChannel {
|
||||
teleported = teleportedSet.contains(ch.geohash)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Public API (Permissions & Location)
|
||||
|
||||
func enableLocationChannels() {
|
||||
let status = cl.authorizationStatus
|
||||
switch status {
|
||||
case .notDetermined:
|
||||
cl.requestWhenInUseAuthorization()
|
||||
case .restricted:
|
||||
Task { @MainActor in self.permissionState = .restricted }
|
||||
case .denied:
|
||||
Task { @MainActor in self.permissionState = .denied }
|
||||
case .authorizedAlways, .authorizedWhenInUse, .authorized:
|
||||
Task { @MainActor in self.permissionState = .authorized }
|
||||
requestOneShotLocation()
|
||||
@unknown default:
|
||||
Task { @MainActor in self.permissionState = .restricted }
|
||||
}
|
||||
}
|
||||
|
||||
func refreshChannels() {
|
||||
if permissionState == .authorized {
|
||||
requestOneShotLocation()
|
||||
}
|
||||
}
|
||||
|
||||
func beginLiveRefresh(interval: TimeInterval = TransportConfig.locationLiveRefreshInterval) {
|
||||
guard permissionState == .authorized else { return }
|
||||
refreshTimer?.invalidate()
|
||||
refreshTimer = nil
|
||||
cl.desiredAccuracy = kCLLocationAccuracyNearestTenMeters
|
||||
cl.distanceFilter = TransportConfig.locationDistanceFilterLiveMeters
|
||||
cl.startUpdatingLocation()
|
||||
requestOneShotLocation()
|
||||
}
|
||||
|
||||
func endLiveRefresh() {
|
||||
refreshTimer?.invalidate()
|
||||
refreshTimer = nil
|
||||
cl.stopUpdatingLocation()
|
||||
cl.desiredAccuracy = kCLLocationAccuracyHundredMeters
|
||||
cl.distanceFilter = TransportConfig.locationDistanceFilterMeters
|
||||
}
|
||||
|
||||
// MARK: - Public API (Channel Selection)
|
||||
|
||||
func select(_ channel: ChannelID) {
|
||||
Task { @MainActor in
|
||||
self.selectedChannel = channel
|
||||
if let data = try? JSONEncoder().encode(channel) {
|
||||
self.storage.set(data, forKey: self.selectedChannelKey)
|
||||
}
|
||||
|
||||
switch channel {
|
||||
case .mesh:
|
||||
self.teleported = false
|
||||
case .location(let ch):
|
||||
let inRegional = self.availableChannels.contains { $0.geohash == ch.geohash }
|
||||
if inRegional {
|
||||
self.teleported = false
|
||||
if self.teleportedSet.contains(ch.geohash) {
|
||||
self.teleportedSet.remove(ch.geohash)
|
||||
self.persistTeleportedSet()
|
||||
}
|
||||
} else {
|
||||
self.teleported = self.teleportedSet.contains(ch.geohash)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func markTeleported(for geohash: String, _ flag: Bool) {
|
||||
if flag {
|
||||
teleportedSet.insert(geohash)
|
||||
} else {
|
||||
teleportedSet.remove(geohash)
|
||||
}
|
||||
persistTeleportedSet()
|
||||
if case .location(let ch) = selectedChannel, ch.geohash == geohash {
|
||||
Task { @MainActor in self.teleported = flag }
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Public API (Bookmarks)
|
||||
|
||||
func isBookmarked(_ geohash: String) -> Bool {
|
||||
bookmarkMembership.contains(Self.normalizeGeohash(geohash))
|
||||
}
|
||||
|
||||
func toggleBookmark(_ geohash: String) {
|
||||
let gh = Self.normalizeGeohash(geohash)
|
||||
if bookmarkMembership.contains(gh) {
|
||||
removeBookmark(gh)
|
||||
} else {
|
||||
addBookmark(gh)
|
||||
}
|
||||
}
|
||||
|
||||
func addBookmark(_ geohash: String) {
|
||||
let gh = Self.normalizeGeohash(geohash)
|
||||
guard !gh.isEmpty, !bookmarkMembership.contains(gh) else { return }
|
||||
bookmarks.insert(gh, at: 0)
|
||||
bookmarkMembership.insert(gh)
|
||||
persistBookmarks()
|
||||
resolveBookmarkNameIfNeeded(for: gh)
|
||||
}
|
||||
|
||||
func removeBookmark(_ geohash: String) {
|
||||
let gh = Self.normalizeGeohash(geohash)
|
||||
guard bookmarkMembership.contains(gh) else { return }
|
||||
if let idx = bookmarks.firstIndex(of: gh) {
|
||||
bookmarks.remove(at: idx)
|
||||
}
|
||||
bookmarkMembership.remove(gh)
|
||||
if bookmarkNames.removeValue(forKey: gh) != nil {
|
||||
persistBookmarkNames()
|
||||
}
|
||||
persistBookmarks()
|
||||
}
|
||||
|
||||
// MARK: - CLLocationManagerDelegate
|
||||
|
||||
private func requestOneShotLocation() {
|
||||
cl.requestLocation()
|
||||
}
|
||||
|
||||
func locationManager(_ manager: CLLocationManager, didChangeAuthorization status: CLAuthorizationStatus) {
|
||||
updatePermissionState(from: status)
|
||||
if case .authorized = permissionState {
|
||||
requestOneShotLocation()
|
||||
}
|
||||
}
|
||||
|
||||
@available(iOS 14.0, macOS 11.0, *)
|
||||
func locationManagerDidChangeAuthorization(_ manager: CLLocationManager) {
|
||||
updatePermissionState(from: manager.authorizationStatus)
|
||||
if case .authorized = permissionState {
|
||||
requestOneShotLocation()
|
||||
}
|
||||
}
|
||||
|
||||
func locationManager(_ manager: CLLocationManager, didUpdateLocations locations: [CLLocation]) {
|
||||
guard let loc = locations.last else { return }
|
||||
lastLocation = loc
|
||||
computeChannels(from: loc.coordinate)
|
||||
reverseGeocodeLocation(loc)
|
||||
}
|
||||
|
||||
func locationManager(_ manager: CLLocationManager, didFailWithError error: Error) {
|
||||
SecureLogger.error("LocationStateManager: location error: \(error.localizedDescription)", category: .session)
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers (Permission)
|
||||
|
||||
private func updatePermissionState(from status: CLAuthorizationStatus) {
|
||||
let newState: PermissionState
|
||||
switch status {
|
||||
case .notDetermined: newState = .notDetermined
|
||||
case .restricted: newState = .restricted
|
||||
case .denied: newState = .denied
|
||||
case .authorizedAlways, .authorizedWhenInUse, .authorized: newState = .authorized
|
||||
@unknown default: newState = .restricted
|
||||
}
|
||||
Task { @MainActor in self.permissionState = newState }
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers (Channel Computation)
|
||||
|
||||
private func computeChannels(from coord: CLLocationCoordinate2D) {
|
||||
let levels = GeohashChannelLevel.allCases
|
||||
var result: [GeohashChannel] = []
|
||||
for level in levels {
|
||||
let gh = Geohash.encode(latitude: coord.latitude, longitude: coord.longitude, precision: level.precision)
|
||||
result.append(GeohashChannel(level: level, geohash: gh))
|
||||
}
|
||||
Task { @MainActor in
|
||||
self.availableChannels = result
|
||||
switch self.selectedChannel {
|
||||
case .mesh:
|
||||
self.teleported = false
|
||||
case .location(let ch):
|
||||
let inRegional = result.contains { $0.geohash == ch.geohash }
|
||||
if inRegional {
|
||||
self.teleported = false
|
||||
if self.teleportedSet.contains(ch.geohash) {
|
||||
self.teleportedSet.remove(ch.geohash)
|
||||
self.persistTeleportedSet()
|
||||
}
|
||||
} else {
|
||||
self.teleported = true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers (Geocoding)
|
||||
|
||||
private func reverseGeocodeLocation(_ location: CLLocation) {
|
||||
geocoder.cancelGeocode()
|
||||
isGeocoding = true
|
||||
geocoder.reverseGeocodeLocation(location) { [weak self] placemarks, _ in
|
||||
guard let self = self else { return }
|
||||
self.isGeocoding = false
|
||||
if let pm = placemarks?.first {
|
||||
let names = self.locationNamesByLevel(from: pm)
|
||||
Task { @MainActor in self.locationNames = names }
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private func locationNamesByLevel(from pm: CLPlacemark) -> [GeohashChannelLevel: String] {
|
||||
var dict: [GeohashChannelLevel: String] = [:]
|
||||
if let country = pm.country, !country.isEmpty {
|
||||
dict[.region] = country
|
||||
}
|
||||
if let admin = pm.administrativeArea, !admin.isEmpty {
|
||||
dict[.province] = admin
|
||||
} else if let subAdmin = pm.subAdministrativeArea, !subAdmin.isEmpty {
|
||||
dict[.province] = subAdmin
|
||||
}
|
||||
if let locality = pm.locality, !locality.isEmpty {
|
||||
dict[.city] = locality
|
||||
} else if let subAdmin = pm.subAdministrativeArea, !subAdmin.isEmpty {
|
||||
dict[.city] = subAdmin
|
||||
} else if let admin = pm.administrativeArea, !admin.isEmpty {
|
||||
dict[.city] = admin
|
||||
}
|
||||
if let subLocality = pm.subLocality, !subLocality.isEmpty {
|
||||
dict[.neighborhood] = subLocality
|
||||
} else if let locality = pm.locality, !locality.isEmpty {
|
||||
dict[.neighborhood] = locality
|
||||
}
|
||||
if let subLocality = pm.subLocality, !subLocality.isEmpty {
|
||||
dict[.block] = subLocality
|
||||
} else if let locality = pm.locality, !locality.isEmpty {
|
||||
dict[.block] = locality
|
||||
}
|
||||
if let name = pm.name, !name.isEmpty {
|
||||
dict[.building] = name
|
||||
} else if let thoroughfare = pm.thoroughfare, !thoroughfare.isEmpty {
|
||||
dict[.building] = thoroughfare
|
||||
}
|
||||
return dict
|
||||
}
|
||||
|
||||
func resolveBookmarkNameIfNeeded(for geohash: String) {
|
||||
let gh = Self.normalizeGeohash(geohash)
|
||||
guard !gh.isEmpty, bookmarkNames[gh] == nil, !resolvingNames.contains(gh) else { return }
|
||||
resolvingNames.insert(gh)
|
||||
|
||||
if gh.count <= 2 {
|
||||
let b = Geohash.decodeBounds(gh)
|
||||
let pts: [CLLocation] = [
|
||||
CLLocation(latitude: (b.latMin + b.latMax) / 2, longitude: (b.lonMin + b.lonMax) / 2),
|
||||
CLLocation(latitude: b.latMin, longitude: b.lonMin),
|
||||
CLLocation(latitude: b.latMin, longitude: b.lonMax),
|
||||
CLLocation(latitude: b.latMax, longitude: b.lonMin),
|
||||
CLLocation(latitude: b.latMax, longitude: b.lonMax)
|
||||
]
|
||||
resolveCompositeAdminName(geohash: gh, points: pts)
|
||||
} else {
|
||||
let center = Geohash.decodeCenter(gh)
|
||||
let loc = CLLocation(latitude: center.lat, longitude: center.lon)
|
||||
geocoder.reverseGeocodeLocation(loc) { [weak self] placemarks, _ in
|
||||
guard let self = self else { return }
|
||||
defer { self.resolvingNames.remove(gh) }
|
||||
if let pm = placemarks?.first,
|
||||
let name = Self.nameForGeohashLength(gh.count, from: pm),
|
||||
!name.isEmpty {
|
||||
DispatchQueue.main.async {
|
||||
self.bookmarkNames[gh] = name
|
||||
self.persistBookmarkNames()
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private func resolveCompositeAdminName(geohash gh: String, points: [CLLocation]) {
|
||||
var uniqueAdmins: [String] = []
|
||||
var seenAdmins = Set<String>()
|
||||
var idx = 0
|
||||
|
||||
func step() {
|
||||
if idx >= points.count {
|
||||
let finalName: String? = {
|
||||
if uniqueAdmins.count >= 2 { return uniqueAdmins[0] + " and " + uniqueAdmins[1] }
|
||||
return uniqueAdmins.first
|
||||
}()
|
||||
if let finalName = finalName, !finalName.isEmpty {
|
||||
DispatchQueue.main.async {
|
||||
self.bookmarkNames[gh] = finalName
|
||||
self.persistBookmarkNames()
|
||||
}
|
||||
}
|
||||
self.resolvingNames.remove(gh)
|
||||
return
|
||||
}
|
||||
let loc = points[idx]
|
||||
idx += 1
|
||||
geocoder.reverseGeocodeLocation(loc) { [weak self] placemarks, _ in
|
||||
guard self != nil else { return }
|
||||
if let pm = placemarks?.first {
|
||||
if let admin = pm.administrativeArea, !admin.isEmpty, !seenAdmins.contains(admin) {
|
||||
seenAdmins.insert(admin)
|
||||
uniqueAdmins.append(admin)
|
||||
} else if let country = pm.country, !country.isEmpty, !seenAdmins.contains(country) {
|
||||
seenAdmins.insert(country)
|
||||
uniqueAdmins.append(country)
|
||||
}
|
||||
}
|
||||
step()
|
||||
}
|
||||
}
|
||||
step()
|
||||
}
|
||||
|
||||
private static func nameForGeohashLength(_ len: Int, from pm: CLPlacemark) -> String? {
|
||||
switch len {
|
||||
case 0...2:
|
||||
return pm.administrativeArea ?? pm.country
|
||||
case 3...4:
|
||||
return pm.administrativeArea ?? pm.subAdministrativeArea ?? pm.country
|
||||
case 5:
|
||||
return pm.locality ?? pm.subAdministrativeArea ?? pm.administrativeArea
|
||||
case 6...7:
|
||||
return pm.subLocality ?? pm.locality ?? pm.administrativeArea
|
||||
default:
|
||||
return pm.subLocality ?? pm.locality ?? pm.administrativeArea ?? pm.country
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers (Persistence)
|
||||
|
||||
private func persistTeleportedSet() {
|
||||
if let data = try? JSONEncoder().encode(Array(teleportedSet)) {
|
||||
storage.set(data, forKey: teleportedStoreKey)
|
||||
}
|
||||
}
|
||||
|
||||
private func persistBookmarks() {
|
||||
if let data = try? JSONEncoder().encode(bookmarks) {
|
||||
storage.set(data, forKey: bookmarksKey)
|
||||
}
|
||||
}
|
||||
|
||||
private func persistBookmarkNames() {
|
||||
if let data = try? JSONEncoder().encode(bookmarkNames) {
|
||||
storage.set(data, forKey: bookmarkNamesKey)
|
||||
}
|
||||
}
|
||||
|
||||
private static func normalizeGeohash(_ s: String) -> String {
|
||||
let allowed = Set("0123456789bcdefghjkmnpqrstuvwxyz")
|
||||
return s
|
||||
.trimmed
|
||||
.lowercased()
|
||||
.replacingOccurrences(of: "#", with: "")
|
||||
.filter { allowed.contains($0) }
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Backward Compatibility Typealiases
|
||||
|
||||
typealias LocationChannelManager = LocationStateManager
|
||||
typealias GeohashBookmarksStore = LocationStateManager
|
||||
|
||||
// MARK: - Backward Compatibility Extensions
|
||||
|
||||
extension LocationStateManager {
|
||||
/// Backward compatibility: toggle bookmark (was GeohashBookmarksStore.toggle)
|
||||
func toggle(_ geohash: String) {
|
||||
toggleBookmark(geohash)
|
||||
}
|
||||
|
||||
/// Backward compatibility: add bookmark (was GeohashBookmarksStore.add)
|
||||
func add(_ geohash: String) {
|
||||
addBookmark(geohash)
|
||||
}
|
||||
|
||||
/// Backward compatibility: remove bookmark (was GeohashBookmarksStore.remove)
|
||||
func remove(_ geohash: String) {
|
||||
removeBookmark(geohash)
|
||||
}
|
||||
}
|
||||
#endif
|
||||
@@ -0,0 +1,130 @@
|
||||
import Foundation
|
||||
|
||||
/// Tracks observed mesh topology and computes hop-by-hop routes.
|
||||
final class MeshTopologyTracker {
|
||||
private typealias RoutingID = Data
|
||||
|
||||
private let queue = DispatchQueue(label: "mesh.topology", attributes: .concurrent)
|
||||
private let hopSize = 8
|
||||
// Directed claims: Key claims to see Value (neighbors)
|
||||
private var claims: [RoutingID: Set<RoutingID>] = [:]
|
||||
// Last time we received an update from a node
|
||||
private var lastSeen: [RoutingID: Date] = [:]
|
||||
|
||||
// Maximum age for topology claims to be considered fresh for routing
|
||||
// Routes computed using stale topology can fail when the network has changed
|
||||
private static let routeFreshnessThreshold: TimeInterval = 60 // 60 seconds
|
||||
|
||||
func reset() {
|
||||
queue.sync(flags: .barrier) {
|
||||
self.claims.removeAll()
|
||||
self.lastSeen.removeAll()
|
||||
}
|
||||
}
|
||||
|
||||
/// Update the topology with a node's self-reported neighbor list
|
||||
func updateNeighbors(for sourceData: Data?, neighbors: [Data]) {
|
||||
guard let source = sanitize(sourceData) else { return }
|
||||
// Sanitize neighbors and exclude self-loops
|
||||
let validNeighbors = Set(neighbors.compactMap { sanitize($0) }).subtracting([source])
|
||||
|
||||
queue.sync(flags: .barrier) {
|
||||
self.claims[source] = validNeighbors
|
||||
self.lastSeen[source] = Date()
|
||||
}
|
||||
}
|
||||
|
||||
func removePeer(_ data: Data?) {
|
||||
guard let peer = sanitize(data) else { return }
|
||||
queue.sync(flags: .barrier) {
|
||||
self.claims.removeValue(forKey: peer)
|
||||
self.lastSeen.removeValue(forKey: peer)
|
||||
}
|
||||
}
|
||||
|
||||
/// Prune nodes that haven't updated their topology in `age` seconds
|
||||
func prune(olderThan age: TimeInterval) {
|
||||
let deadline = Date().addingTimeInterval(-age)
|
||||
queue.sync(flags: .barrier) {
|
||||
let stale = self.lastSeen.filter { $0.value < deadline }
|
||||
for (peer, _) in stale {
|
||||
self.claims.removeValue(forKey: peer)
|
||||
self.lastSeen.removeValue(forKey: peer)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func computeRoute(from start: Data?, to goal: Data?, maxHops: Int = 10) -> [Data]? {
|
||||
guard let source = sanitize(start), let target = sanitize(goal) else { return nil }
|
||||
if source == target { return [] } // Direct connection, no intermediate hops
|
||||
|
||||
return queue.sync {
|
||||
let now = Date()
|
||||
let freshnessDeadline = now.addingTimeInterval(-Self.routeFreshnessThreshold)
|
||||
|
||||
// BFS
|
||||
var visited: Set<RoutingID> = [source]
|
||||
// Queue stores paths: [Start, Hop1, Hop2, ..., Current]
|
||||
var queuePaths: [[RoutingID]] = [[source]]
|
||||
|
||||
while !queuePaths.isEmpty {
|
||||
let path = queuePaths.removeFirst()
|
||||
// Limit path length (path contains source + maxHops + target) -> maxHops intermediate
|
||||
// If maxHops = 10, max edges = 11, max nodes = 12.
|
||||
if path.count > maxHops + 1 { continue }
|
||||
|
||||
guard let last = path.last else { continue }
|
||||
|
||||
// Get neighbors that 'last' claims to see
|
||||
guard let neighbors = claims[last] else { continue }
|
||||
|
||||
// Check if 'last' node's topology info is fresh
|
||||
guard let lastSeenTime = lastSeen[last], lastSeenTime > freshnessDeadline else {
|
||||
continue // Skip stale nodes
|
||||
}
|
||||
|
||||
for neighbor in neighbors {
|
||||
if visited.contains(neighbor) { continue }
|
||||
|
||||
// CONFIRMED EDGE CHECK:
|
||||
// 'last' claims 'neighbor' (checked above)
|
||||
// Does 'neighbor' claim 'last'?
|
||||
guard let neighborClaims = claims[neighbor],
|
||||
neighborClaims.contains(last) else {
|
||||
continue
|
||||
}
|
||||
|
||||
// Check if 'neighbor' node's topology info is fresh
|
||||
guard let neighborSeenTime = lastSeen[neighbor], neighborSeenTime > freshnessDeadline else {
|
||||
continue // Skip edges to stale nodes
|
||||
}
|
||||
|
||||
var nextPath = path
|
||||
nextPath.append(neighbor)
|
||||
|
||||
if neighbor == target {
|
||||
// Return only intermediate hops
|
||||
// Path: [Source, I1, I2, Target] -> [I1, I2]
|
||||
return Array(nextPath.dropFirst().dropLast())
|
||||
}
|
||||
|
||||
visited.insert(neighbor)
|
||||
queuePaths.append(nextPath)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Helpers
|
||||
|
||||
private func sanitize(_ data: Data?) -> Data? {
|
||||
guard var value = data, !value.isEmpty else { return nil }
|
||||
if value.count > hopSize {
|
||||
value = Data(value.prefix(hopSize))
|
||||
} else if value.count < hopSize {
|
||||
value.append(Data(repeating: 0, count: hopSize - value.count))
|
||||
}
|
||||
return value
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,278 @@
|
||||
//
|
||||
// MessageDeduplicationService.swift
|
||||
// bitchat
|
||||
//
|
||||
// Handles message deduplication using LRU caches.
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import Foundation
|
||||
|
||||
// MARK: - LRU Deduplication Cache
|
||||
|
||||
/// Generic LRU (Least Recently Used) cache for deduplication.
|
||||
/// Uses an efficient O(1) lookup with periodic compaction.
|
||||
/// Thread-safe via @MainActor - all callers are already on main actor.
|
||||
@MainActor
|
||||
final class LRUDeduplicationCache<Value> {
|
||||
private var map: [String: Value] = [:]
|
||||
private var order: [String] = []
|
||||
private var head: Int = 0
|
||||
private let capacity: Int
|
||||
|
||||
/// Creates a new LRU cache with the specified capacity.
|
||||
/// - Parameter capacity: Maximum number of entries before eviction
|
||||
init(capacity: Int) {
|
||||
precondition(capacity > 0, "LRU cache capacity must be positive")
|
||||
self.capacity = capacity
|
||||
}
|
||||
|
||||
/// Number of active entries in the cache
|
||||
var count: Int {
|
||||
order.count - head
|
||||
}
|
||||
|
||||
/// Checks if a key exists in the cache
|
||||
func contains(_ key: String) -> Bool {
|
||||
map[key] != nil
|
||||
}
|
||||
|
||||
/// Gets the value for a key, or nil if not present
|
||||
func value(for key: String) -> Value? {
|
||||
map[key]
|
||||
}
|
||||
|
||||
/// Records a key-value pair, updating if exists or inserting if new
|
||||
func record(_ key: String, value: Value) {
|
||||
if map[key] == nil {
|
||||
order.append(key)
|
||||
}
|
||||
map[key] = value
|
||||
trimIfNeeded()
|
||||
}
|
||||
|
||||
/// Removes a specific key from the cache
|
||||
func remove(_ key: String) {
|
||||
map.removeValue(forKey: key)
|
||||
// Note: key remains in order array but will be skipped during eviction
|
||||
}
|
||||
|
||||
/// Clears all entries from the cache
|
||||
func clear() {
|
||||
map.removeAll()
|
||||
order.removeAll()
|
||||
head = 0
|
||||
}
|
||||
|
||||
// MARK: - Private
|
||||
|
||||
private func trimIfNeeded() {
|
||||
let activeCount = order.count - head
|
||||
guard activeCount > capacity else { return }
|
||||
|
||||
let overflow = activeCount - capacity
|
||||
for _ in 0..<overflow {
|
||||
guard let victim = popOldest() else { break }
|
||||
map.removeValue(forKey: victim)
|
||||
}
|
||||
}
|
||||
|
||||
private func popOldest() -> String? {
|
||||
// Skip keys that were already removed from map
|
||||
while head < order.count {
|
||||
let key = order[head]
|
||||
head += 1
|
||||
|
||||
// Periodically compact the backing storage
|
||||
if head >= 32 && head * 2 >= order.count {
|
||||
order.removeFirst(head)
|
||||
head = 0
|
||||
}
|
||||
|
||||
// Only return if key is still in map
|
||||
if map[key] != nil {
|
||||
return key
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Content Normalizer
|
||||
|
||||
/// Normalizes message content for near-duplicate detection.
|
||||
enum ContentNormalizer {
|
||||
|
||||
/// Regex to simplify HTTP URLs by stripping query strings and fragments
|
||||
private static let simplifyHTTPURL: NSRegularExpression = {
|
||||
try! NSRegularExpression(
|
||||
pattern: "https?://[^\\s?#]+(?:[?#][^\\s]*)?",
|
||||
options: [.caseInsensitive]
|
||||
)
|
||||
}()
|
||||
|
||||
/// Normalizes content for deduplication comparison.
|
||||
/// - Parameters:
|
||||
/// - content: The raw message content
|
||||
/// - prefixLength: Maximum characters to consider (default from TransportConfig)
|
||||
/// - Returns: A hash-based key for comparison
|
||||
static func normalizedKey(
|
||||
_ content: String,
|
||||
prefixLength: Int = TransportConfig.contentKeyPrefixLength
|
||||
) -> String {
|
||||
// Lowercase for case-insensitive comparison
|
||||
let lowered = content.lowercased()
|
||||
let ns = lowered as NSString
|
||||
let range = NSRange(location: 0, length: ns.length)
|
||||
|
||||
// Simplify URLs by stripping query/fragment
|
||||
var simplified = ""
|
||||
var last = 0
|
||||
for match in simplifyHTTPURL.matches(in: lowered, options: [], range: range) {
|
||||
if match.range.location > last {
|
||||
simplified += ns.substring(with: NSRange(location: last, length: match.range.location - last))
|
||||
}
|
||||
let url = ns.substring(with: match.range)
|
||||
if let queryIndex = url.firstIndex(where: { $0 == "?" || $0 == "#" }) {
|
||||
simplified += String(url[..<queryIndex])
|
||||
} else {
|
||||
simplified += url
|
||||
}
|
||||
last = match.range.location + match.range.length
|
||||
}
|
||||
if last < ns.length {
|
||||
simplified += ns.substring(with: NSRange(location: last, length: ns.length - last))
|
||||
}
|
||||
|
||||
// Trim and collapse whitespace
|
||||
let trimmed = simplified.trimmed
|
||||
let collapsed = trimmed.replacingOccurrences(of: "\\s+", with: " ", options: .regularExpression)
|
||||
|
||||
// Take prefix and hash
|
||||
let prefix = String(collapsed.prefix(prefixLength))
|
||||
let hash = prefix.djb2()
|
||||
return String(format: "h:%016llx", hash)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Message Deduplication Service
|
||||
|
||||
/// Service that manages message deduplication using LRU caches.
|
||||
/// Provides separate caches for content-based dedup and Nostr event ID dedup.
|
||||
/// Thread-safe via @MainActor - all callers are already on main actor.
|
||||
@MainActor
|
||||
final class MessageDeduplicationService {
|
||||
|
||||
/// Cache for content-based near-duplicate detection
|
||||
private let contentCache: LRUDeduplicationCache<Date>
|
||||
|
||||
/// Cache for Nostr event ID deduplication
|
||||
private let nostrEventCache: LRUDeduplicationCache<Bool>
|
||||
|
||||
/// Cache for Nostr ACK deduplication (messageId:ackType:senderPubkey format)
|
||||
private let nostrAckCache: LRUDeduplicationCache<Bool>
|
||||
|
||||
/// Creates a new deduplication service with specified capacities.
|
||||
/// - Parameters:
|
||||
/// - contentCapacity: Max entries for content cache
|
||||
/// - nostrEventCapacity: Max entries for Nostr event cache
|
||||
init(
|
||||
contentCapacity: Int = TransportConfig.contentLRUCap,
|
||||
nostrEventCapacity: Int = TransportConfig.uiProcessedNostrEventsCap
|
||||
) {
|
||||
self.contentCache = LRUDeduplicationCache(capacity: contentCapacity)
|
||||
self.nostrEventCache = LRUDeduplicationCache(capacity: nostrEventCapacity)
|
||||
self.nostrAckCache = LRUDeduplicationCache(capacity: nostrEventCapacity)
|
||||
}
|
||||
|
||||
// MARK: - Content Deduplication
|
||||
|
||||
/// Records content with its timestamp for near-duplicate detection.
|
||||
/// - Parameters:
|
||||
/// - content: The message content
|
||||
/// - timestamp: When the content was received
|
||||
func recordContent(_ content: String, timestamp: Date) {
|
||||
let key = ContentNormalizer.normalizedKey(content)
|
||||
contentCache.record(key, value: timestamp)
|
||||
}
|
||||
|
||||
/// Records a pre-normalized content key with its timestamp.
|
||||
/// - Parameters:
|
||||
/// - key: The normalized content key
|
||||
/// - timestamp: When the content was received
|
||||
func recordContentKey(_ key: String, timestamp: Date) {
|
||||
contentCache.record(key, value: timestamp)
|
||||
}
|
||||
|
||||
/// Gets the timestamp for previously seen content.
|
||||
/// - Parameter content: The message content
|
||||
/// - Returns: The timestamp when first seen, or nil if not seen
|
||||
func contentTimestamp(for content: String) -> Date? {
|
||||
let key = ContentNormalizer.normalizedKey(content)
|
||||
return contentCache.value(for: key)
|
||||
}
|
||||
|
||||
/// Gets the timestamp for a pre-normalized content key.
|
||||
/// - Parameter key: The normalized content key
|
||||
/// - Returns: The timestamp when first seen, or nil if not seen
|
||||
func contentTimestamp(forKey key: String) -> Date? {
|
||||
contentCache.value(for: key)
|
||||
}
|
||||
|
||||
/// Normalizes content to a deduplication key.
|
||||
/// - Parameter content: The raw content
|
||||
/// - Returns: A normalized hash key
|
||||
func normalizedContentKey(_ content: String) -> String {
|
||||
ContentNormalizer.normalizedKey(content)
|
||||
}
|
||||
|
||||
// MARK: - Nostr Event Deduplication
|
||||
|
||||
/// Checks if a Nostr event has already been processed.
|
||||
/// - Parameter eventId: The event ID
|
||||
/// - Returns: true if already processed
|
||||
func hasProcessedNostrEvent(_ eventId: String) -> Bool {
|
||||
nostrEventCache.contains(eventId)
|
||||
}
|
||||
|
||||
/// Records a Nostr event as processed.
|
||||
/// - Parameter eventId: The event ID
|
||||
func recordNostrEvent(_ eventId: String) {
|
||||
nostrEventCache.record(eventId, value: true)
|
||||
}
|
||||
|
||||
// MARK: - Nostr ACK Deduplication
|
||||
|
||||
/// Checks if a Nostr ACK has already been processed.
|
||||
/// - Parameter ackKey: The ACK key in format "messageId:ackType:senderPubkey"
|
||||
/// - Returns: true if already processed
|
||||
func hasProcessedNostrAck(_ ackKey: String) -> Bool {
|
||||
nostrAckCache.contains(ackKey)
|
||||
}
|
||||
|
||||
/// Records a Nostr ACK as processed.
|
||||
/// - Parameter ackKey: The ACK key in format "messageId:ackType:senderPubkey"
|
||||
func recordNostrAck(_ ackKey: String) {
|
||||
nostrAckCache.record(ackKey, value: true)
|
||||
}
|
||||
|
||||
/// Creates an ACK key from components.
|
||||
static func ackKey(messageId: String, ackType: String, senderPubkey: String) -> String {
|
||||
"\(messageId):\(ackType):\(senderPubkey)"
|
||||
}
|
||||
|
||||
// MARK: - Clear
|
||||
|
||||
/// Clears all caches
|
||||
func clearAll() {
|
||||
contentCache.clear()
|
||||
nostrEventCache.clear()
|
||||
nostrAckCache.clear()
|
||||
}
|
||||
|
||||
/// Clears only the Nostr caches (events and ACKs)
|
||||
func clearNostrCaches() {
|
||||
nostrEventCache.clear()
|
||||
nostrAckCache.clear()
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,472 @@
|
||||
//
|
||||
// MessageFormattingEngine.swift
|
||||
// bitchat
|
||||
//
|
||||
// Handles message text formatting, including mentions, hashtags, URLs, and tokens.
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import SwiftUI
|
||||
|
||||
// MARK: - Formatting Context Protocol
|
||||
|
||||
/// Protocol defining the context needed for message formatting.
|
||||
/// Implemented by ChatViewModel to provide runtime state.
|
||||
@MainActor
|
||||
protocol MessageFormattingContext: AnyObject {
|
||||
/// The user's current nickname
|
||||
var nickname: String { get }
|
||||
|
||||
/// Determines if a message was sent by the current user
|
||||
func isSelfMessage(_ message: BitchatMessage) -> Bool
|
||||
|
||||
/// Gets the color for a message's sender
|
||||
func senderColor(for message: BitchatMessage, isDark: Bool) -> Color
|
||||
|
||||
/// Resolves a peer ID to a clickable URL
|
||||
func peerURL(for peerID: PeerID) -> URL?
|
||||
}
|
||||
|
||||
// MARK: - Formatting Engine
|
||||
|
||||
/// Handles rich text formatting for chat messages.
|
||||
/// Extracts mentions, hashtags, URLs, Lightning invoices, and Cashu tokens.
|
||||
final class MessageFormattingEngine {
|
||||
|
||||
// MARK: - Precompiled Regexes
|
||||
|
||||
/// Precompiled regex patterns for message content parsing
|
||||
enum Patterns {
|
||||
static let hashtag: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "#([a-zA-Z0-9_]+)", options: [])
|
||||
}()
|
||||
|
||||
static let mention: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "@([\\p{L}0-9_]+(?:#[a-fA-F0-9]{4})?)", options: [])
|
||||
}()
|
||||
|
||||
static let cashu: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "\\bcashu[AB][A-Za-z0-9._-]{40,}\\b", options: [])
|
||||
}()
|
||||
|
||||
static let bolt11: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "(?i)\\bln(bc|tb|bcrt)[0-9][a-z0-9]{50,}\\b", options: [])
|
||||
}()
|
||||
|
||||
static let lnurl: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "(?i)\\blnurl1[a-z0-9]{20,}\\b", options: [])
|
||||
}()
|
||||
|
||||
static let lightningScheme: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "(?i)\\blightning:[^\\s]+", options: [])
|
||||
}()
|
||||
|
||||
static let linkDetector: NSDataDetector? = {
|
||||
try? NSDataDetector(types: NSTextCheckingResult.CheckingType.link.rawValue)
|
||||
}()
|
||||
|
||||
static let quickCashuPresence: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "\\bcashu[AB][A-Za-z0-9._-]{40,}\\b", options: [])
|
||||
}()
|
||||
|
||||
static let simplifyHTTPURL: NSRegularExpression = {
|
||||
try! NSRegularExpression(pattern: "https?://[^\\s?#]+(?:[?#][^\\s]*)?", options: [.caseInsensitive])
|
||||
}()
|
||||
}
|
||||
|
||||
// MARK: - Match Types
|
||||
|
||||
/// Types of matches found in message content
|
||||
enum MatchType: String {
|
||||
case hashtag
|
||||
case mention
|
||||
case url
|
||||
case cashu
|
||||
case lightning
|
||||
case bolt11
|
||||
case lnurl
|
||||
}
|
||||
|
||||
/// A match found in message content
|
||||
struct ContentMatch {
|
||||
let range: NSRange
|
||||
let type: MatchType
|
||||
}
|
||||
|
||||
// MARK: - Public API
|
||||
|
||||
/// Formats a message with rich text styling
|
||||
@MainActor
|
||||
static func formatMessage(
|
||||
_ message: BitchatMessage,
|
||||
context: MessageFormattingContext,
|
||||
colorScheme: ColorScheme
|
||||
) -> AttributedString {
|
||||
let isDark = colorScheme == .dark
|
||||
let isSelf = context.isSelfMessage(message)
|
||||
|
||||
// Check cache first
|
||||
if let cached = message.getCachedFormattedText(isDark: isDark, isSelf: isSelf) {
|
||||
return cached
|
||||
}
|
||||
|
||||
var result = AttributedString()
|
||||
let baseColor: Color = isSelf ? .orange : context.senderColor(for: message, isDark: isDark)
|
||||
|
||||
// Format system messages differently
|
||||
if message.sender == "system" {
|
||||
result = formatSystemMessage(message, isDark: isDark)
|
||||
} else {
|
||||
// Format sender header
|
||||
result = formatSenderHeader(
|
||||
message: message,
|
||||
baseColor: baseColor,
|
||||
isSelf: isSelf,
|
||||
context: context
|
||||
)
|
||||
|
||||
// Format content
|
||||
let contentResult = formatContent(
|
||||
message.content,
|
||||
baseColor: baseColor,
|
||||
isSelf: isSelf,
|
||||
isMentioned: message.mentions?.contains(context.nickname) ?? false
|
||||
)
|
||||
result.append(contentResult)
|
||||
|
||||
// Add timestamp
|
||||
result.append(formatTimestamp(message.formattedTimestamp))
|
||||
}
|
||||
|
||||
// Cache the result
|
||||
message.setCachedFormattedText(result, isDark: isDark, isSelf: isSelf)
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
/// Formats just the message header (sender portion)
|
||||
@MainActor
|
||||
static func formatHeader(
|
||||
_ message: BitchatMessage,
|
||||
context: MessageFormattingContext,
|
||||
colorScheme: ColorScheme
|
||||
) -> AttributedString {
|
||||
let isDark = colorScheme == .dark
|
||||
let isSelf = context.isSelfMessage(message)
|
||||
let baseColor: Color = isSelf ? .orange : context.senderColor(for: message, isDark: isDark)
|
||||
|
||||
if message.sender == "system" {
|
||||
var style = AttributeContainer()
|
||||
style.foregroundColor = baseColor
|
||||
style.font = .bitchatSystem(size: 14, weight: .medium, design: .monospaced)
|
||||
return AttributedString(message.sender).mergingAttributes(style)
|
||||
}
|
||||
|
||||
return formatSenderHeader(
|
||||
message: message,
|
||||
baseColor: baseColor,
|
||||
isSelf: isSelf,
|
||||
context: context
|
||||
)
|
||||
}
|
||||
|
||||
/// Extracts mentions from message content
|
||||
static func extractMentions(from content: String) -> [String] {
|
||||
let nsContent = content as NSString
|
||||
let range = NSRange(location: 0, length: nsContent.length)
|
||||
let matches = Patterns.mention.matches(in: content, options: [], range: range)
|
||||
|
||||
return matches.compactMap { match -> String? in
|
||||
guard match.numberOfRanges > 1 else { return nil }
|
||||
let captureRange = match.range(at: 1)
|
||||
guard let swiftRange = Range(captureRange, in: content) else { return nil }
|
||||
return String(content[swiftRange])
|
||||
}
|
||||
}
|
||||
|
||||
/// Checks if content contains a Cashu token
|
||||
static func containsCashuToken(_ content: String) -> Bool {
|
||||
let nsContent = content as NSString
|
||||
let range = NSRange(location: 0, length: nsContent.length)
|
||||
return Patterns.quickCashuPresence.numberOfMatches(in: content, options: [], range: range) > 0
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers
|
||||
|
||||
private static func formatSystemMessage(_ message: BitchatMessage, isDark: Bool) -> AttributedString {
|
||||
var result = AttributedString()
|
||||
|
||||
let content = AttributedString("* \(message.content) *")
|
||||
var contentStyle = AttributeContainer()
|
||||
contentStyle.foregroundColor = Color.gray
|
||||
contentStyle.font = .bitchatSystem(size: 12, design: .monospaced).italic()
|
||||
result.append(content.mergingAttributes(contentStyle))
|
||||
|
||||
// Add timestamp
|
||||
let timestamp = AttributedString(" [\(message.formattedTimestamp)]")
|
||||
var timestampStyle = AttributeContainer()
|
||||
timestampStyle.foregroundColor = Color.gray.opacity(0.5)
|
||||
timestampStyle.font = .bitchatSystem(size: 10, design: .monospaced)
|
||||
result.append(timestamp.mergingAttributes(timestampStyle))
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
@MainActor
|
||||
private static func formatSenderHeader(
|
||||
message: BitchatMessage,
|
||||
baseColor: Color,
|
||||
isSelf: Bool,
|
||||
context: MessageFormattingContext
|
||||
) -> AttributedString {
|
||||
var result = AttributedString()
|
||||
|
||||
let (baseName, suffix) = message.sender.splitSuffix()
|
||||
var senderStyle = AttributeContainer()
|
||||
senderStyle.foregroundColor = baseColor
|
||||
let fontWeight: Font.Weight = isSelf ? .bold : .medium
|
||||
senderStyle.font = .bitchatSystem(size: 14, weight: fontWeight, design: .monospaced)
|
||||
|
||||
// Make sender clickable
|
||||
if let spid = message.senderPeerID, let url = context.peerURL(for: spid) {
|
||||
senderStyle.link = url
|
||||
}
|
||||
|
||||
// Build: "<@baseName#suffix> "
|
||||
result.append(AttributedString("<@").mergingAttributes(senderStyle))
|
||||
result.append(AttributedString(baseName).mergingAttributes(senderStyle))
|
||||
|
||||
if !suffix.isEmpty {
|
||||
var suffixStyle = senderStyle
|
||||
suffixStyle.foregroundColor = baseColor.opacity(0.6)
|
||||
result.append(AttributedString(suffix).mergingAttributes(suffixStyle))
|
||||
}
|
||||
|
||||
result.append(AttributedString("> ").mergingAttributes(senderStyle))
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
private static func formatContent(
|
||||
_ content: String,
|
||||
baseColor: Color,
|
||||
isSelf: Bool,
|
||||
isMentioned: Bool
|
||||
) -> AttributedString {
|
||||
// For very long content without special tokens, use plain formatting
|
||||
let containsCashu = containsCashuToken(content)
|
||||
if (content.count > 4000 || content.hasVeryLongToken(threshold: 1024)) && !containsCashu {
|
||||
return formatPlainContent(content, baseColor: baseColor, isSelf: isSelf)
|
||||
}
|
||||
|
||||
// Find all matches
|
||||
let matches = findAllMatches(in: content)
|
||||
|
||||
// Build formatted content
|
||||
var result = AttributedString()
|
||||
var lastEnd = content.startIndex
|
||||
|
||||
for match in matches {
|
||||
guard let swiftRange = Range(match.range, in: content) else { continue }
|
||||
|
||||
// Add text before match
|
||||
if lastEnd < swiftRange.lowerBound {
|
||||
let beforeText = String(content[lastEnd..<swiftRange.lowerBound])
|
||||
result.append(formatPlainText(beforeText, baseColor: baseColor, isSelf: isSelf, isMentioned: isMentioned))
|
||||
}
|
||||
|
||||
// Add styled match
|
||||
let matchText = String(content[swiftRange])
|
||||
result.append(formatMatch(matchText, type: match.type, baseColor: baseColor, isSelf: isSelf))
|
||||
|
||||
lastEnd = swiftRange.upperBound
|
||||
}
|
||||
|
||||
// Add remaining text
|
||||
if lastEnd < content.endIndex {
|
||||
let remainingText = String(content[lastEnd...])
|
||||
result.append(formatPlainText(remainingText, baseColor: baseColor, isSelf: isSelf, isMentioned: isMentioned))
|
||||
}
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
private static func findAllMatches(in content: String) -> [ContentMatch] {
|
||||
let nsContent = content as NSString
|
||||
let nsLen = nsContent.length
|
||||
let fullRange = NSRange(location: 0, length: nsLen)
|
||||
|
||||
// Quick hints to avoid unnecessary regex work
|
||||
let hasMentions = content.contains("@")
|
||||
let hasHashtags = content.contains("#")
|
||||
let hasURLs = content.contains("://") || content.contains("www.") || content.contains("http")
|
||||
let hasLightning = content.lowercased().contains("ln") || content.lowercased().contains("lightning:")
|
||||
let hasCashu = content.lowercased().contains("cashu")
|
||||
|
||||
// Collect matches
|
||||
let mentionMatches = hasMentions ? Patterns.mention.matches(in: content, options: [], range: fullRange) : []
|
||||
let hashtagMatches = hasHashtags ? Patterns.hashtag.matches(in: content, options: [], range: fullRange) : []
|
||||
let urlMatches = hasURLs ? (Patterns.linkDetector?.matches(in: content, options: [], range: fullRange) ?? []) : []
|
||||
let cashuMatches = hasCashu ? Patterns.cashu.matches(in: content, options: [], range: fullRange) : []
|
||||
let lightningMatches = hasLightning ? Patterns.lightningScheme.matches(in: content, options: [], range: fullRange) : []
|
||||
let bolt11Matches = hasLightning ? Patterns.bolt11.matches(in: content, options: [], range: fullRange) : []
|
||||
let lnurlMatches = hasLightning ? Patterns.lnurl.matches(in: content, options: [], range: fullRange) : []
|
||||
|
||||
// Build mention ranges for overlap checking
|
||||
let mentionRanges = mentionMatches.map { $0.range(at: 0) }
|
||||
|
||||
func overlapsMention(_ r: NSRange) -> Bool {
|
||||
mentionRanges.contains { NSIntersectionRange(r, $0).length > 0 }
|
||||
}
|
||||
|
||||
func isStandaloneHashtag(_ r: NSRange) -> Bool {
|
||||
guard let swiftRange = Range(r, in: content) else { return false }
|
||||
if swiftRange.lowerBound == content.startIndex { return true }
|
||||
let prev = content.index(before: swiftRange.lowerBound)
|
||||
return content[prev].isWhitespace || content[prev].isNewline
|
||||
}
|
||||
|
||||
func attachedToMention(_ r: NSRange) -> Bool {
|
||||
guard let swiftRange = Range(r, in: content), swiftRange.lowerBound > content.startIndex else { return false }
|
||||
var i = content.index(before: swiftRange.lowerBound)
|
||||
while true {
|
||||
let ch = content[i]
|
||||
if ch.isWhitespace || ch.isNewline { break }
|
||||
if ch == "@" { return true }
|
||||
if i == content.startIndex { break }
|
||||
i = content.index(before: i)
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
var allMatches: [ContentMatch] = []
|
||||
|
||||
// Add hashtags (excluding those attached to mentions)
|
||||
for match in hashtagMatches {
|
||||
let range = match.range(at: 0)
|
||||
if !overlapsMention(range) && !attachedToMention(range) && isStandaloneHashtag(range) {
|
||||
allMatches.append(ContentMatch(range: range, type: .hashtag))
|
||||
}
|
||||
}
|
||||
|
||||
// Add mentions
|
||||
for match in mentionMatches {
|
||||
allMatches.append(ContentMatch(range: match.range(at: 0), type: .mention))
|
||||
}
|
||||
|
||||
// Add URLs
|
||||
for match in urlMatches where !overlapsMention(match.range) {
|
||||
allMatches.append(ContentMatch(range: match.range, type: .url))
|
||||
}
|
||||
|
||||
// Add Cashu tokens
|
||||
for match in cashuMatches where !overlapsMention(match.range(at: 0)) {
|
||||
allMatches.append(ContentMatch(range: match.range(at: 0), type: .cashu))
|
||||
}
|
||||
|
||||
// Add Lightning scheme URLs
|
||||
for match in lightningMatches where !overlapsMention(match.range(at: 0)) {
|
||||
allMatches.append(ContentMatch(range: match.range(at: 0), type: .lightning))
|
||||
}
|
||||
|
||||
// Add bolt11/lnurl (avoiding overlaps with lightning scheme and URLs)
|
||||
let occupied = urlMatches.map { $0.range } + lightningMatches.map { $0.range(at: 0) }
|
||||
func overlapsOccupied(_ r: NSRange) -> Bool {
|
||||
occupied.contains { NSIntersectionRange(r, $0).length > 0 }
|
||||
}
|
||||
|
||||
for match in bolt11Matches where !overlapsMention(match.range(at: 0)) && !overlapsOccupied(match.range(at: 0)) {
|
||||
allMatches.append(ContentMatch(range: match.range(at: 0), type: .bolt11))
|
||||
}
|
||||
|
||||
for match in lnurlMatches where !overlapsMention(match.range(at: 0)) && !overlapsOccupied(match.range(at: 0)) {
|
||||
allMatches.append(ContentMatch(range: match.range(at: 0), type: .lnurl))
|
||||
}
|
||||
|
||||
// Sort by position
|
||||
return allMatches.sorted { $0.range.location < $1.range.location }
|
||||
}
|
||||
|
||||
private static func formatPlainContent(_ content: String, baseColor: Color, isSelf: Bool) -> AttributedString {
|
||||
var style = AttributeContainer()
|
||||
style.foregroundColor = baseColor
|
||||
style.font = isSelf
|
||||
? .bitchatSystem(size: 14, weight: .bold, design: .monospaced)
|
||||
: .bitchatSystem(size: 14, design: .monospaced)
|
||||
return AttributedString(content).mergingAttributes(style)
|
||||
}
|
||||
|
||||
private static func formatPlainText(_ text: String, baseColor: Color, isSelf: Bool, isMentioned: Bool) -> AttributedString {
|
||||
guard !text.isEmpty else { return AttributedString() }
|
||||
|
||||
var style = AttributeContainer()
|
||||
style.foregroundColor = baseColor
|
||||
style.font = isSelf
|
||||
? .bitchatSystem(size: 14, weight: .bold, design: .monospaced)
|
||||
: .bitchatSystem(size: 14, design: .monospaced)
|
||||
|
||||
if isMentioned {
|
||||
style.font = style.font?.bold()
|
||||
}
|
||||
|
||||
return AttributedString(text).mergingAttributes(style)
|
||||
}
|
||||
|
||||
private static func formatMatch(_ text: String, type: MatchType, baseColor: Color, isSelf: Bool) -> AttributedString {
|
||||
var style = AttributeContainer()
|
||||
|
||||
switch type {
|
||||
case .mention:
|
||||
// Split optional '#abcd' suffix
|
||||
let (baseName, suffix) = text.splitSuffix()
|
||||
var result = AttributedString()
|
||||
|
||||
var mentionStyle = AttributeContainer()
|
||||
mentionStyle.foregroundColor = .blue
|
||||
mentionStyle.font = .bitchatSystem(size: 14, weight: .semibold, design: .monospaced)
|
||||
result.append(AttributedString(baseName).mergingAttributes(mentionStyle))
|
||||
|
||||
if !suffix.isEmpty {
|
||||
var suffixStyle = mentionStyle
|
||||
suffixStyle.foregroundColor = Color.gray.opacity(0.7)
|
||||
result.append(AttributedString(suffix).mergingAttributes(suffixStyle))
|
||||
}
|
||||
|
||||
return result
|
||||
|
||||
case .hashtag:
|
||||
style.foregroundColor = .purple
|
||||
style.font = .bitchatSystem(size: 14, weight: .medium, design: .monospaced)
|
||||
|
||||
case .url:
|
||||
style.foregroundColor = .blue
|
||||
style.font = .bitchatSystem(size: 14, design: .monospaced)
|
||||
style.underlineStyle = .single
|
||||
if let url = URL(string: text) {
|
||||
style.link = url
|
||||
}
|
||||
|
||||
case .cashu:
|
||||
style.foregroundColor = .green
|
||||
style.font = .bitchatSystem(size: 14, weight: .medium, design: .monospaced)
|
||||
style.backgroundColor = Color.green.opacity(0.1)
|
||||
|
||||
case .lightning, .bolt11, .lnurl:
|
||||
style.foregroundColor = .yellow
|
||||
style.font = .bitchatSystem(size: 14, weight: .medium, design: .monospaced)
|
||||
style.backgroundColor = Color.yellow.opacity(0.1)
|
||||
}
|
||||
|
||||
return AttributedString(text).mergingAttributes(style)
|
||||
}
|
||||
|
||||
private static func formatTimestamp(_ timestamp: String) -> AttributedString {
|
||||
let text = AttributedString(" [\(timestamp)]")
|
||||
var style = AttributeContainer()
|
||||
style.foregroundColor = Color.gray.opacity(0.5)
|
||||
style.font = .bitchatSystem(size: 10, design: .monospaced)
|
||||
return text.mergingAttributes(style)
|
||||
}
|
||||
}
|
||||
@@ -1,212 +0,0 @@
|
||||
//
|
||||
// MessageRetryService.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import Foundation
|
||||
import Combine
|
||||
import CryptoKit
|
||||
|
||||
struct RetryableMessage {
|
||||
let id: String
|
||||
let originalMessageID: String?
|
||||
let originalTimestamp: Date?
|
||||
let content: String
|
||||
let mentions: [String]?
|
||||
let isPrivate: Bool
|
||||
let recipientPeerID: String?
|
||||
let recipientNickname: String?
|
||||
let retryCount: Int
|
||||
let maxRetries: Int = 3
|
||||
let nextRetryTime: Date
|
||||
}
|
||||
|
||||
class MessageRetryService {
|
||||
static let shared = MessageRetryService()
|
||||
|
||||
private var retryQueue: [RetryableMessage] = []
|
||||
private var retryTimer: Timer?
|
||||
private let retryInterval: TimeInterval = 2.0 // Retry every 2 seconds for faster sync
|
||||
private let maxQueueSize = 50
|
||||
|
||||
weak var meshService: BluetoothMeshService?
|
||||
|
||||
private init() {
|
||||
startRetryTimer()
|
||||
}
|
||||
|
||||
deinit {
|
||||
retryTimer?.invalidate()
|
||||
}
|
||||
|
||||
private func startRetryTimer() {
|
||||
retryTimer = Timer.scheduledTimer(withTimeInterval: retryInterval, repeats: true) { [weak self] _ in
|
||||
self?.processRetryQueue()
|
||||
}
|
||||
}
|
||||
|
||||
func addMessageForRetry(
|
||||
content: String,
|
||||
mentions: [String]? = nil,
|
||||
isPrivate: Bool = false,
|
||||
recipientPeerID: String? = nil,
|
||||
recipientNickname: String? = nil,
|
||||
originalMessageID: String? = nil,
|
||||
originalTimestamp: Date? = nil
|
||||
) {
|
||||
// Don't queue empty or whitespace-only messages
|
||||
guard !content.trimmingCharacters(in: .whitespacesAndNewlines).isEmpty else {
|
||||
return
|
||||
}
|
||||
|
||||
// Don't queue if we're at capacity
|
||||
guard retryQueue.count < maxQueueSize else {
|
||||
return
|
||||
}
|
||||
|
||||
// Check if this message is already in the queue
|
||||
if let messageID = originalMessageID {
|
||||
let alreadyQueued = retryQueue.contains { msg in
|
||||
msg.originalMessageID == messageID
|
||||
}
|
||||
if alreadyQueued {
|
||||
return // Don't add duplicate
|
||||
}
|
||||
}
|
||||
|
||||
let retryMessage = RetryableMessage(
|
||||
id: UUID().uuidString,
|
||||
originalMessageID: originalMessageID,
|
||||
originalTimestamp: originalTimestamp,
|
||||
content: content,
|
||||
mentions: mentions,
|
||||
isPrivate: isPrivate,
|
||||
recipientPeerID: recipientPeerID,
|
||||
recipientNickname: recipientNickname,
|
||||
retryCount: 0,
|
||||
nextRetryTime: Date().addingTimeInterval(retryInterval)
|
||||
)
|
||||
|
||||
retryQueue.append(retryMessage)
|
||||
|
||||
// Sort the queue by original timestamp to maintain message order
|
||||
retryQueue.sort { (msg1, msg2) in
|
||||
let time1 = msg1.originalTimestamp ?? Date.distantPast
|
||||
let time2 = msg2.originalTimestamp ?? Date.distantPast
|
||||
return time1 < time2
|
||||
}
|
||||
}
|
||||
|
||||
private func processRetryQueue() {
|
||||
guard meshService != nil else { return }
|
||||
|
||||
let now = Date()
|
||||
var messagesToRetry: [RetryableMessage] = []
|
||||
var updatedQueue: [RetryableMessage] = []
|
||||
|
||||
for message in retryQueue {
|
||||
if message.nextRetryTime <= now {
|
||||
messagesToRetry.append(message)
|
||||
} else {
|
||||
updatedQueue.append(message)
|
||||
}
|
||||
}
|
||||
|
||||
retryQueue = updatedQueue
|
||||
|
||||
// Sort messages by original timestamp to maintain order
|
||||
messagesToRetry.sort { (msg1, msg2) in
|
||||
let time1 = msg1.originalTimestamp ?? Date.distantPast
|
||||
let time2 = msg2.originalTimestamp ?? Date.distantPast
|
||||
return time1 < time2
|
||||
}
|
||||
|
||||
// Send messages with delay to maintain order
|
||||
for (index, message) in messagesToRetry.enumerated() {
|
||||
// Check if we should still retry
|
||||
if message.retryCount >= message.maxRetries {
|
||||
continue
|
||||
}
|
||||
|
||||
// Add delay between messages to ensure proper ordering
|
||||
let delay = Double(index) * 0.05 // 50ms between messages
|
||||
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + delay) { [weak self] in
|
||||
guard let self = self,
|
||||
let meshService = self.meshService else { return }
|
||||
|
||||
// Check connectivity before retrying
|
||||
let viewModel = meshService.delegate as? ChatViewModel
|
||||
let connectedPeers = viewModel?.connectedPeers ?? []
|
||||
|
||||
if message.isPrivate {
|
||||
// For private messages, check if recipient is connected
|
||||
if let recipientID = message.recipientPeerID,
|
||||
connectedPeers.contains(recipientID) {
|
||||
// Retry private message
|
||||
meshService.sendPrivateMessage(
|
||||
message.content,
|
||||
to: recipientID,
|
||||
recipientNickname: message.recipientNickname ?? "unknown",
|
||||
messageID: message.originalMessageID
|
||||
)
|
||||
} else {
|
||||
// Recipient not connected, keep in queue with updated retry time
|
||||
var updatedMessage = message
|
||||
updatedMessage = RetryableMessage(
|
||||
id: message.id,
|
||||
originalMessageID: message.originalMessageID,
|
||||
originalTimestamp: message.originalTimestamp,
|
||||
content: message.content,
|
||||
mentions: message.mentions,
|
||||
isPrivate: message.isPrivate,
|
||||
recipientPeerID: message.recipientPeerID,
|
||||
recipientNickname: message.recipientNickname,
|
||||
retryCount: message.retryCount + 1,
|
||||
nextRetryTime: Date().addingTimeInterval(self.retryInterval * Double(message.retryCount + 2))
|
||||
)
|
||||
self.retryQueue.append(updatedMessage)
|
||||
}
|
||||
} else {
|
||||
// Regular message
|
||||
if !connectedPeers.isEmpty {
|
||||
meshService.sendMessage(
|
||||
message.content,
|
||||
mentions: message.mentions ?? [],
|
||||
to: nil,
|
||||
messageID: message.originalMessageID,
|
||||
timestamp: message.originalTimestamp
|
||||
)
|
||||
} else {
|
||||
// No peers connected, keep in queue
|
||||
var updatedMessage = message
|
||||
updatedMessage = RetryableMessage(
|
||||
id: message.id,
|
||||
originalMessageID: message.originalMessageID,
|
||||
originalTimestamp: message.originalTimestamp,
|
||||
content: message.content,
|
||||
mentions: message.mentions,
|
||||
isPrivate: message.isPrivate,
|
||||
recipientPeerID: message.recipientPeerID,
|
||||
recipientNickname: message.recipientNickname,
|
||||
retryCount: message.retryCount + 1,
|
||||
nextRetryTime: Date().addingTimeInterval(self.retryInterval * Double(message.retryCount + 2))
|
||||
)
|
||||
self.retryQueue.append(updatedMessage)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func clearRetryQueue() {
|
||||
retryQueue.removeAll()
|
||||
}
|
||||
|
||||
func getRetryQueueCount() -> Int {
|
||||
return retryQueue.count
|
||||
}
|
||||
}
|
||||
@@ -1,671 +1,153 @@
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
/// Routes messages through the appropriate transport (Bluetooth mesh or Nostr)
|
||||
/// Routes messages using available transports (Mesh, Nostr, etc.)
|
||||
@MainActor
|
||||
class MessageRouter: ObservableObject {
|
||||
final class MessageRouter {
|
||||
private let transports: [Transport]
|
||||
|
||||
enum Transport {
|
||||
case bluetoothMesh
|
||||
case nostr
|
||||
}
|
||||
|
||||
enum DeliveryStatus {
|
||||
case pending
|
||||
case sent
|
||||
case delivered
|
||||
case failed(Error)
|
||||
}
|
||||
|
||||
struct RoutedMessage {
|
||||
let id: String
|
||||
// Outbox entry with timestamp for TTL-based eviction
|
||||
private struct QueuedMessage {
|
||||
let content: String
|
||||
let recipientNoisePublicKey: Data
|
||||
let transport: Transport
|
||||
let nickname: String
|
||||
let messageID: String
|
||||
let timestamp: Date
|
||||
var status: DeliveryStatus
|
||||
}
|
||||
|
||||
@Published private(set) var pendingMessages: [String: RoutedMessage] = [:]
|
||||
|
||||
private let meshService: BluetoothMeshService
|
||||
private let nostrRelay: NostrRelayManager
|
||||
private let favoritesService: FavoritesPersistenceService
|
||||
private let processedMessagesService = ProcessedMessagesService.shared
|
||||
|
||||
private var cancellables = Set<AnyCancellable>()
|
||||
private let messageDeduplication = LRUCache<String, Date>(maxSize: 1000)
|
||||
|
||||
init(
|
||||
meshService: BluetoothMeshService,
|
||||
nostrRelay: NostrRelayManager
|
||||
) {
|
||||
self.meshService = meshService
|
||||
self.nostrRelay = nostrRelay
|
||||
self.favoritesService = FavoritesPersistenceService.shared
|
||||
|
||||
setupBindings()
|
||||
}
|
||||
|
||||
/// Send a message to a peer, automatically selecting the best transport
|
||||
func sendMessage(
|
||||
_ content: String,
|
||||
to recipientNoisePublicKey: Data,
|
||||
preferredTransport: Transport? = nil,
|
||||
messageId: String? = nil
|
||||
) async throws {
|
||||
|
||||
let finalMessageId = messageId ?? UUID().uuidString
|
||||
|
||||
// Check if peer is available on mesh (actually connected, not just known)
|
||||
let recipientHexID = recipientNoisePublicKey.hexEncodedString()
|
||||
let peerAvailableOnMesh = meshService.isPeerConnected(recipientHexID)
|
||||
|
||||
// Check if this is a mutual favorite
|
||||
let isMutualFavorite = favoritesService.isMutualFavorite(recipientNoisePublicKey)
|
||||
|
||||
// Determine transport
|
||||
let transport: Transport
|
||||
if let preferred = preferredTransport {
|
||||
transport = preferred
|
||||
} else if peerAvailableOnMesh {
|
||||
// Always prefer mesh when available
|
||||
transport = .bluetoothMesh
|
||||
} else if isMutualFavorite {
|
||||
// Use Nostr for mutual favorites when not on mesh
|
||||
transport = .nostr
|
||||
} else {
|
||||
throw MessageRouterError.peerNotReachable
|
||||
}
|
||||
|
||||
// Create routed message
|
||||
let routedMessage = RoutedMessage(
|
||||
id: finalMessageId,
|
||||
content: content,
|
||||
recipientNoisePublicKey: recipientNoisePublicKey,
|
||||
transport: transport,
|
||||
timestamp: Date(),
|
||||
status: .pending
|
||||
)
|
||||
|
||||
pendingMessages[finalMessageId] = routedMessage
|
||||
|
||||
// Route based on transport
|
||||
switch transport {
|
||||
case .bluetoothMesh:
|
||||
try await sendViaMesh(routedMessage)
|
||||
|
||||
case .nostr:
|
||||
try await sendViaNostr(routedMessage)
|
||||
}
|
||||
}
|
||||
|
||||
/// Send a favorite/unfavorite notification
|
||||
func sendFavoriteNotification(
|
||||
to recipientNoisePublicKey: Data,
|
||||
isFavorite: Bool
|
||||
) async throws {
|
||||
|
||||
// messageType is used for logging below
|
||||
// let messageType: MessageType = isFavorite ? .favorited : .unfavorited
|
||||
let recipientHexID = recipientNoisePublicKey.hexEncodedString()
|
||||
let action = isFavorite ? "favorite" : "unfavorite"
|
||||
|
||||
SecureLogger.log("📤 Sending \(action) notification to \(recipientHexID)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Try mesh first
|
||||
if meshService.getPeerNicknames()[recipientHexID] != nil {
|
||||
SecureLogger.log("📡 Sending \(action) notification via Bluetooth mesh",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Send via mesh as a system message
|
||||
meshService.sendFavoriteNotification(to: recipientHexID, isFavorite: isFavorite)
|
||||
|
||||
} else if let favoriteStatus = favoritesService.getFavoriteStatus(for: recipientNoisePublicKey),
|
||||
let recipientNostrPubkey = favoriteStatus.peerNostrPublicKey {
|
||||
|
||||
SecureLogger.log("🌐 Sending \(action) notification via Nostr to \(favoriteStatus.peerNickname)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Send via Nostr as a special message
|
||||
guard let senderIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
throw MessageRouterError.noNostrIdentity
|
||||
}
|
||||
|
||||
// Include our npub in the content
|
||||
let content = isFavorite ? "FAVORITED:\(senderIdentity.npub)" : "UNFAVORITED:\(senderIdentity.npub)"
|
||||
let event = try NostrProtocol.createPrivateMessage(
|
||||
content: content,
|
||||
recipientPubkey: recipientNostrPubkey,
|
||||
senderIdentity: senderIdentity
|
||||
)
|
||||
|
||||
nostrRelay.sendEvent(event)
|
||||
} else {
|
||||
SecureLogger.log("⚠️ Cannot send \(action) notification - peer not reachable via mesh or Nostr",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func sendViaMesh(_ message: RoutedMessage) async throws {
|
||||
// Send the message through mesh - using sendPrivateMessage for now
|
||||
let recipientHexID = message.recipientNoisePublicKey.hexEncodedString()
|
||||
if let recipientNickname = meshService.getPeerNicknames()[recipientHexID] {
|
||||
meshService.sendPrivateMessage(message.content, to: recipientHexID, recipientNickname: recipientNickname, messageID: message.id)
|
||||
}
|
||||
|
||||
// Update status
|
||||
pendingMessages[message.id]?.status = .sent
|
||||
}
|
||||
|
||||
private func sendViaNostr(_ message: RoutedMessage) async throws {
|
||||
// Get recipient's Nostr public key
|
||||
let favoriteStatus = favoritesService.getFavoriteStatus(for: message.recipientNoisePublicKey)
|
||||
|
||||
// Looking up Nostr key for recipient
|
||||
|
||||
if favoriteStatus != nil {
|
||||
// Found favorite relationship
|
||||
} else {
|
||||
SecureLogger.log("❌ No favorite relationship found",
|
||||
category: SecureLogger.session, level: .error)
|
||||
}
|
||||
|
||||
guard let favoriteStatus = favoriteStatus,
|
||||
let recipientNostrPubkey = favoriteStatus.peerNostrPublicKey else {
|
||||
throw MessageRouterError.noNostrPublicKey
|
||||
}
|
||||
|
||||
// Get sender's Nostr identity
|
||||
guard let senderIdentity = try NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
throw MessageRouterError.noNostrIdentity
|
||||
}
|
||||
|
||||
// Create NIP-17 encrypted message with structured content
|
||||
let structuredContent = "MSG:\(message.id):\(message.content)"
|
||||
let event = try NostrProtocol.createPrivateMessage(
|
||||
content: structuredContent,
|
||||
recipientPubkey: recipientNostrPubkey,
|
||||
senderIdentity: senderIdentity
|
||||
)
|
||||
|
||||
// Created gift wrap event
|
||||
|
||||
// Send via relay
|
||||
nostrRelay.sendEvent(event)
|
||||
|
||||
// Update status
|
||||
pendingMessages[message.id]?.status = .sent
|
||||
}
|
||||
|
||||
private func setupBindings() {
|
||||
// Monitor Nostr messages
|
||||
setupNostrMessageHandling()
|
||||
|
||||
// Clean up old pending messages periodically
|
||||
Timer.publish(every: 60, on: .main, in: .common)
|
||||
.autoconnect()
|
||||
.sink { [weak self] _ in
|
||||
self?.cleanupOldMessages()
|
||||
}
|
||||
.store(in: &cancellables)
|
||||
|
||||
// Listen for app becoming active to check for messages
|
||||
NotificationCenter.default.publisher(for: .appDidBecomeActive)
|
||||
.sink { [weak self] _ in
|
||||
self?.checkForNostrMessages()
|
||||
}
|
||||
.store(in: &cancellables)
|
||||
}
|
||||
|
||||
private func setupNostrMessageHandling() {
|
||||
guard let currentIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
SecureLogger.log("⚠️ No Nostr identity available for initial setup", category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
SecureLogger.log("🚀 Setting up Nostr message handling for \(currentIdentity.npub)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Connect to relays if not already connected
|
||||
if !nostrRelay.isConnected {
|
||||
nostrRelay.connect()
|
||||
|
||||
// Wait for connections to establish before subscribing
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 2.0) { [weak self] in
|
||||
self?.subscribeToNostrMessages()
|
||||
}
|
||||
} else {
|
||||
// Already connected, subscribe immediately
|
||||
subscribeToNostrMessages()
|
||||
}
|
||||
}
|
||||
|
||||
/// Check for Nostr messages when app becomes active
|
||||
func checkForNostrMessages() {
|
||||
// Checking for Nostr messages
|
||||
|
||||
guard (try? NostrIdentityBridge.getCurrentNostrIdentity()) != nil else {
|
||||
SecureLogger.log("⚠️ No Nostr identity available for message check", category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
// Ensure we're connected to relays first
|
||||
if !nostrRelay.isConnected {
|
||||
// Connecting to Nostr relays
|
||||
nostrRelay.connect()
|
||||
|
||||
// Wait a bit for connections to establish before subscribing
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + 1.0) { [weak self] in
|
||||
self?.subscribeToNostrMessages()
|
||||
}
|
||||
} else {
|
||||
// Already connected, subscribe immediately
|
||||
subscribeToNostrMessages()
|
||||
}
|
||||
}
|
||||
|
||||
private func subscribeToNostrMessages() {
|
||||
guard let currentIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else { return }
|
||||
|
||||
// Subscribing to Nostr messages
|
||||
// Full pubkey recorded
|
||||
// Pubkey length verified
|
||||
|
||||
// Unsubscribe existing subscription to refresh
|
||||
nostrRelay.unsubscribe(id: "router-messages")
|
||||
|
||||
// Create a new subscription for recent messages
|
||||
let sinceDate = processedMessagesService.getSubscriptionSinceDate()
|
||||
let filter = NostrFilter.giftWrapsFor(
|
||||
pubkey: currentIdentity.publicKeyHex,
|
||||
since: sinceDate
|
||||
)
|
||||
|
||||
// Subscribing to messages since date
|
||||
|
||||
// Subscribing to gift wraps
|
||||
|
||||
nostrRelay.subscribe(filter: filter, id: "router-messages") { [weak self] event in
|
||||
// Received Nostr event
|
||||
self?.handleNostrMessage(event)
|
||||
}
|
||||
}
|
||||
|
||||
private func handleNostrMessage(_ giftWrap: NostrEvent) {
|
||||
// Check if we've already processed this event
|
||||
if processedMessagesService.isMessageProcessed(giftWrap.id) {
|
||||
// Skipping already processed event
|
||||
return
|
||||
}
|
||||
|
||||
// Attempting to decrypt gift wrap
|
||||
// Full event ID recorded
|
||||
// Event timestamp recorded
|
||||
// Event tags recorded
|
||||
|
||||
// Decrypt the message
|
||||
guard let currentIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
SecureLogger.log("❌ No current Nostr identity available",
|
||||
category: SecureLogger.session, level: .error)
|
||||
return
|
||||
}
|
||||
|
||||
// Check if this event is actually tagged for us
|
||||
let ourPubkey = currentIdentity.publicKeyHex
|
||||
let isTaggedForUs = giftWrap.tags.contains { tag in
|
||||
tag.count >= 2 && tag[0] == "p" && tag[1] == ourPubkey
|
||||
}
|
||||
|
||||
if !isTaggedForUs {
|
||||
SecureLogger.log("⚠️ Gift wrap not tagged for us! Our pubkey: \(ourPubkey.prefix(8))..., Event tags: \(giftWrap.tags)",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
}
|
||||
|
||||
do {
|
||||
let (content, senderPubkey) = try NostrProtocol.decryptPrivateMessage(
|
||||
giftWrap: giftWrap,
|
||||
recipientIdentity: currentIdentity
|
||||
)
|
||||
|
||||
SecureLogger.log("✅ Successfully decrypted message from \(senderPubkey.prefix(8))...: \(content)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Mark this event as processed to avoid duplicates on app restart
|
||||
let eventTimestamp = Date(timeIntervalSince1970: TimeInterval(giftWrap.created_at))
|
||||
processedMessagesService.markMessageAsProcessed(giftWrap.id, timestamp: eventTimestamp)
|
||||
|
||||
// Check for deduplication within current session
|
||||
let messageHash = "\(senderPubkey)-\(content)-\(giftWrap.created_at)"
|
||||
if messageDeduplication.get(messageHash) != nil {
|
||||
return // Already processed in this session
|
||||
}
|
||||
messageDeduplication.set(messageHash, value: Date())
|
||||
|
||||
// Handle special messages
|
||||
if content.hasPrefix("FAVORITED") || content.hasPrefix("UNFAVORITED") {
|
||||
let parts = content.split(separator: ":")
|
||||
let isFavorite = parts.first == "FAVORITED"
|
||||
let nostrNpub = parts.count > 1 ? String(parts[1]) : nil
|
||||
handleFavoriteNotification(from: senderPubkey, isFavorite: isFavorite, nostrNpub: nostrNpub)
|
||||
return
|
||||
}
|
||||
|
||||
// Handle delivery acknowledgments
|
||||
if content.hasPrefix("DELIVERED:") {
|
||||
let parts = content.split(separator: ":")
|
||||
if parts.count > 1 {
|
||||
let messageId = String(parts[1])
|
||||
handleDeliveryAcknowledgment(messageId: messageId, from: senderPubkey)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// Handle read receipts
|
||||
if content.hasPrefix("READ:") {
|
||||
let parts = content.split(separator: ":", maxSplits: 1)
|
||||
if parts.count > 1 {
|
||||
let receiptDataString = String(parts[1])
|
||||
if let receiptData = Data(base64Encoded: receiptDataString),
|
||||
let receipt = ReadReceipt.fromBinaryData(receiptData) {
|
||||
handleReadReceipt(receipt, from: senderPubkey)
|
||||
private var outbox: [PeerID: [QueuedMessage]] = [:]
|
||||
|
||||
// Outbox limits to prevent unbounded memory growth
|
||||
private static let maxMessagesPerPeer = 100
|
||||
private static let messageTTLSeconds: TimeInterval = 24 * 60 * 60 // 24 hours
|
||||
|
||||
init(transports: [Transport]) {
|
||||
self.transports = transports
|
||||
|
||||
// Observe favorites changes to learn Nostr mapping and flush queued messages
|
||||
NotificationCenter.default.addObserver(
|
||||
forName: .favoriteStatusChanged,
|
||||
object: nil,
|
||||
queue: .main
|
||||
) { [weak self] note in
|
||||
guard let self = self else { return }
|
||||
if let data = note.userInfo?["peerPublicKey"] as? Data {
|
||||
let peerID = PeerID(publicKey: data)
|
||||
Task { @MainActor in
|
||||
self.flushOutbox(for: peerID)
|
||||
}
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// Find the sender's Noise public key
|
||||
guard let senderNoiseKey = findNoisePublicKey(for: senderPubkey) else { return }
|
||||
|
||||
// Parse structured message content
|
||||
var messageId = UUID().uuidString
|
||||
var messageContent = content
|
||||
|
||||
if content.hasPrefix("MSG:") {
|
||||
let parts = content.split(separator: ":", maxSplits: 2)
|
||||
if parts.count >= 3 {
|
||||
messageId = String(parts[1])
|
||||
messageContent = String(parts[2])
|
||||
}
|
||||
}
|
||||
|
||||
// Create a BitchatMessage and inject into the stream
|
||||
let chatMessage = BitchatMessage(
|
||||
id: messageId,
|
||||
sender: favoritesService.getFavoriteStatus(for: senderNoiseKey)?.peerNickname ?? "Unknown",
|
||||
content: messageContent,
|
||||
timestamp: Date(timeIntervalSince1970: TimeInterval(giftWrap.created_at)),
|
||||
isRelay: false,
|
||||
originalSender: nil,
|
||||
isPrivate: true,
|
||||
recipientNickname: nil,
|
||||
senderPeerID: senderNoiseKey.hexEncodedString(),
|
||||
mentions: nil,
|
||||
deliveryStatus: .delivered(to: "nostr", at: Date())
|
||||
)
|
||||
|
||||
// Post notification for ChatViewModel to handle
|
||||
NotificationCenter.default.post(
|
||||
name: .nostrMessageReceived,
|
||||
object: nil,
|
||||
userInfo: ["message": chatMessage]
|
||||
)
|
||||
|
||||
// Send delivery acknowledgment back to sender
|
||||
sendDeliveryAcknowledgment(for: chatMessage.id, to: senderPubkey)
|
||||
|
||||
} catch {
|
||||
SecureLogger.log("❌ Failed to decrypt gift wrap: \(error)",
|
||||
category: SecureLogger.session, level: .error)
|
||||
}
|
||||
}
|
||||
|
||||
private func handleFavoriteNotification(from nostrPubkey: String, isFavorite: Bool, nostrNpub: String? = nil) {
|
||||
// Find the sender's Noise public key
|
||||
guard let senderNoiseKey = findNoisePublicKey(for: nostrPubkey) else { return }
|
||||
|
||||
// Update favorites service - nostrPubkey is already the hex public key
|
||||
favoritesService.updatePeerFavoritedUs(
|
||||
peerNoisePublicKey: senderNoiseKey,
|
||||
favorited: isFavorite,
|
||||
peerNostrPublicKey: nostrPubkey
|
||||
)
|
||||
|
||||
// Post notification for UI update
|
||||
NotificationCenter.default.post(
|
||||
name: .favoriteStatusChanged,
|
||||
object: nil,
|
||||
userInfo: [
|
||||
"peerPublicKey": senderNoiseKey,
|
||||
"isFavorite": isFavorite
|
||||
]
|
||||
)
|
||||
}
|
||||
|
||||
private func findNoisePublicKey(for nostrPubkey: String) -> Data? {
|
||||
// Search through favorites for matching Nostr pubkey
|
||||
for (noiseKey, relationship) in favoritesService.favorites {
|
||||
if relationship.peerNostrPublicKey == nostrPubkey {
|
||||
return noiseKey
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
private func handleDeliveryAcknowledgment(messageId: String, from senderPubkey: String) {
|
||||
SecureLogger.log("✅ Received delivery acknowledgment for message \(messageId) from \(senderPubkey)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Find the sender's Noise public key
|
||||
guard let senderNoiseKey = findNoisePublicKey(for: senderPubkey) else { return }
|
||||
|
||||
// Post notification for ChatViewModel to update delivery status
|
||||
NotificationCenter.default.post(
|
||||
name: .messageDeliveryAcknowledged,
|
||||
object: nil,
|
||||
userInfo: [
|
||||
"messageId": messageId,
|
||||
"senderNoiseKey": senderNoiseKey
|
||||
]
|
||||
)
|
||||
}
|
||||
|
||||
private func handleReadReceipt(_ receipt: ReadReceipt, from senderPubkey: String) {
|
||||
SecureLogger.log("📖 Received read receipt for message \(receipt.originalMessageID) from \(senderPubkey)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Find the sender's Noise public key
|
||||
guard let senderNoiseKey = findNoisePublicKey(for: senderPubkey) else { return }
|
||||
let senderHexID = senderNoiseKey.hexEncodedString()
|
||||
|
||||
// Update the receipt with the correct sender ID
|
||||
var updatedReceipt = receipt
|
||||
updatedReceipt.readerID = senderHexID
|
||||
|
||||
// Post notification for ChatViewModel to process
|
||||
NotificationCenter.default.post(
|
||||
name: .readReceiptReceived,
|
||||
object: nil,
|
||||
userInfo: ["receipt": updatedReceipt]
|
||||
)
|
||||
}
|
||||
|
||||
func sendReadReceipt(
|
||||
for originalMessageID: String,
|
||||
to recipientNoisePublicKey: Data,
|
||||
preferredTransport: Transport? = nil
|
||||
) async throws {
|
||||
SecureLogger.log("📖 Sending read receipt for message \(originalMessageID)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
|
||||
// Get nickname from delegate or use default
|
||||
let nickname = (meshService.delegate as? ChatViewModel)?.nickname ?? "Anonymous"
|
||||
|
||||
// Create read receipt
|
||||
let receipt = ReadReceipt(
|
||||
originalMessageID: originalMessageID,
|
||||
readerID: meshService.myPeerID,
|
||||
readerNickname: nickname
|
||||
)
|
||||
|
||||
// Encode receipt
|
||||
let receiptData = receipt.toBinaryData()
|
||||
let content = "READ:\(receiptData.base64EncodedString())"
|
||||
|
||||
// Check if peer is connected via mesh (mesh takes precedence)
|
||||
let recipientHexID = recipientNoisePublicKey.hexEncodedString()
|
||||
|
||||
// First check if the peer is currently connected with the given ID
|
||||
var actualRecipientHexID = recipientHexID
|
||||
var actualRecipientNoiseKey = recipientNoisePublicKey
|
||||
|
||||
// Always check if they reconnected with a new ID, even if preferredTransport is specified
|
||||
if let favoriteStatus = favoritesService.getFavoriteStatus(for: recipientNoisePublicKey) {
|
||||
let peerNickname = favoriteStatus.peerNickname
|
||||
|
||||
// Search through all current peers to find one with the same nickname
|
||||
for (currentPeerID, currentNickname) in meshService.getPeerNicknames() {
|
||||
if currentNickname == peerNickname,
|
||||
currentPeerID != recipientHexID,
|
||||
let currentNoiseKey = Data(hexString: currentPeerID) {
|
||||
SecureLogger.log("🔄 Found updated peer ID for \(peerNickname): \(recipientHexID) -> \(currentPeerID)",
|
||||
category: SecureLogger.session, level: .info)
|
||||
actualRecipientHexID = currentPeerID
|
||||
actualRecipientNoiseKey = currentNoiseKey
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
// If still not found in connected peers, check all favorites for the current key
|
||||
if meshService.getPeerNicknames()[actualRecipientHexID] == nil {
|
||||
// Search through all favorites to find the current noise key for this nickname
|
||||
for (noiseKey, relationship) in favoritesService.favorites {
|
||||
if relationship.peerNickname == peerNickname && relationship.peerNostrPublicKey != nil {
|
||||
SecureLogger.log("🔄 Using current favorite key for \(peerNickname): \(recipientHexID) -> \(noiseKey.hexEncodedString())",
|
||||
category: SecureLogger.session, level: .info)
|
||||
actualRecipientHexID = noiseKey.hexEncodedString()
|
||||
actualRecipientNoiseKey = noiseKey
|
||||
break
|
||||
}
|
||||
// Handle key updates
|
||||
if let newKey = note.userInfo?["peerPublicKey"] as? Data,
|
||||
let _ = note.userInfo?["isKeyUpdate"] as? Bool {
|
||||
let peerID = PeerID(publicKey: newKey)
|
||||
Task { @MainActor in
|
||||
self.flushOutbox(for: peerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let isConnectedOnMesh = meshService.isPeerConnected(actualRecipientHexID)
|
||||
// MARK: - Transport Selection
|
||||
|
||||
if isConnectedOnMesh && preferredTransport != .nostr {
|
||||
// Send via mesh
|
||||
SecureLogger.log("📡 Sending read receipt via mesh to \(actualRecipientHexID)",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
meshService.sendReadReceipt(receipt, to: actualRecipientHexID)
|
||||
private func reachableTransport(for peerID: PeerID) -> Transport? {
|
||||
transports.first { $0.isPeerReachable(peerID) }
|
||||
}
|
||||
|
||||
private func connectedTransport(for peerID: PeerID) -> Transport? {
|
||||
transports.first { $0.isPeerConnected(peerID) }
|
||||
}
|
||||
|
||||
// MARK: - Message Sending
|
||||
|
||||
func sendPrivate(_ content: String, to peerID: PeerID, recipientNickname: String, messageID: String) {
|
||||
if let transport = reachableTransport(for: peerID) {
|
||||
SecureLogger.debug("Routing PM via \(type(of: transport)) to \(peerID.id.prefix(8))… id=\(messageID.prefix(8))…", category: .session)
|
||||
transport.sendPrivateMessage(content, to: peerID, recipientNickname: recipientNickname, messageID: messageID)
|
||||
} else {
|
||||
// Send via Nostr
|
||||
SecureLogger.log("🌐 Sending read receipt via Nostr to \(actualRecipientHexID)",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
// Queue for later with timestamp for TTL tracking
|
||||
if outbox[peerID] == nil { outbox[peerID] = [] }
|
||||
|
||||
// Get recipient's Nostr public key using the actual current noise key
|
||||
let favoriteStatus = favoritesService.getFavoriteStatus(for: actualRecipientNoiseKey)
|
||||
guard let recipientNostrPubkey = favoriteStatus?.peerNostrPublicKey else {
|
||||
SecureLogger.log("❌ Cannot send read receipt - no Nostr key for recipient",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw MessageRouterError.noNostrKey
|
||||
let message = QueuedMessage(content: content, nickname: recipientNickname, messageID: messageID, timestamp: Date())
|
||||
outbox[peerID]?.append(message)
|
||||
|
||||
// Enforce per-peer size limit with FIFO eviction
|
||||
if let count = outbox[peerID]?.count, count > Self.maxMessagesPerPeer {
|
||||
let evicted = outbox[peerID]?.removeFirst()
|
||||
SecureLogger.warning("📤 Outbox overflow for \(peerID.id.prefix(8))… - evicted oldest message: \(evicted?.messageID.prefix(8) ?? "?")…", category: .session)
|
||||
}
|
||||
|
||||
guard let senderIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
SecureLogger.log("⚠️ No Nostr identity available for read receipt",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
throw MessageRouterError.noIdentity
|
||||
}
|
||||
|
||||
// Create read receipt message
|
||||
guard let event = try? NostrProtocol.createPrivateMessage(
|
||||
content: content,
|
||||
recipientPubkey: recipientNostrPubkey,
|
||||
senderIdentity: senderIdentity
|
||||
) else {
|
||||
SecureLogger.log("❌ Failed to create read receipt",
|
||||
category: SecureLogger.session, level: .error)
|
||||
throw MessageRouterError.encryptionFailed
|
||||
}
|
||||
|
||||
// Send via relay
|
||||
nostrRelay.sendEvent(event)
|
||||
SecureLogger.debug("Queued PM for \(peerID.id.prefix(8))… (no reachable transport) id=\(messageID.prefix(8))… queue=\(outbox[peerID]?.count ?? 0)", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
private func sendDeliveryAcknowledgment(for messageId: String, to recipientNostrPubkey: String) {
|
||||
SecureLogger.log("📤 Sending delivery acknowledgment for message \(messageId)",
|
||||
category: SecureLogger.session, level: .debug)
|
||||
|
||||
guard let senderIdentity = try? NostrIdentityBridge.getCurrentNostrIdentity() else {
|
||||
SecureLogger.log("⚠️ No Nostr identity available for acknowledgment",
|
||||
category: SecureLogger.session, level: .warning)
|
||||
return
|
||||
func sendReadReceipt(_ receipt: ReadReceipt, to peerID: PeerID) {
|
||||
if let transport = reachableTransport(for: peerID) {
|
||||
SecureLogger.debug("Routing READ ack via \(type(of: transport)) to \(peerID.id.prefix(8))… id=\(receipt.originalMessageID.prefix(8))…", category: .session)
|
||||
transport.sendReadReceipt(receipt, to: peerID)
|
||||
} else if !transports.isEmpty {
|
||||
SecureLogger.debug("No reachable transport for READ ack to \(peerID.id.prefix(8))…", category: .session)
|
||||
}
|
||||
|
||||
// Create acknowledgment message
|
||||
let content = "DELIVERED:\(messageId)"
|
||||
guard let event = try? NostrProtocol.createPrivateMessage(
|
||||
content: content,
|
||||
recipientPubkey: recipientNostrPubkey,
|
||||
senderIdentity: senderIdentity
|
||||
) else {
|
||||
SecureLogger.log("❌ Failed to create delivery acknowledgment",
|
||||
category: SecureLogger.session, level: .error)
|
||||
return
|
||||
}
|
||||
|
||||
// Send via relay
|
||||
nostrRelay.sendEvent(event)
|
||||
}
|
||||
|
||||
private func cleanupOldMessages() {
|
||||
let cutoff = Date().addingTimeInterval(-300) // 5 minutes
|
||||
pendingMessages = pendingMessages.filter { $0.value.timestamp > cutoff }
|
||||
func sendDeliveryAck(_ messageID: String, to peerID: PeerID) {
|
||||
if let transport = reachableTransport(for: peerID) {
|
||||
SecureLogger.debug("Routing DELIVERED ack via \(type(of: transport)) to \(peerID.id.prefix(8))… id=\(messageID.prefix(8))…", category: .session)
|
||||
transport.sendDeliveryAck(for: messageID, to: peerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Errors
|
||||
func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool) {
|
||||
if let transport = connectedTransport(for: peerID) {
|
||||
transport.sendFavoriteNotification(to: peerID, isFavorite: isFavorite)
|
||||
} else if let transport = reachableTransport(for: peerID) {
|
||||
transport.sendFavoriteNotification(to: peerID, isFavorite: isFavorite)
|
||||
}
|
||||
}
|
||||
|
||||
enum MessageRouterError: LocalizedError {
|
||||
case peerNotReachable
|
||||
case noNostrPublicKey
|
||||
case noNostrIdentity
|
||||
case transportFailed
|
||||
case noNostrKey
|
||||
case noIdentity
|
||||
case encryptionFailed
|
||||
// MARK: - Outbox Management
|
||||
|
||||
var errorDescription: String? {
|
||||
switch self {
|
||||
case .peerNotReachable:
|
||||
return "Peer is not reachable via mesh or Nostr"
|
||||
case .noNostrPublicKey:
|
||||
return "Peer's Nostr public key is unknown"
|
||||
case .noNostrIdentity:
|
||||
return "No Nostr identity available"
|
||||
case .transportFailed:
|
||||
return "Failed to send message"
|
||||
case .noNostrKey:
|
||||
return "No Nostr key available for recipient"
|
||||
case .noIdentity:
|
||||
return "No identity available"
|
||||
case .encryptionFailed:
|
||||
return "Failed to encrypt message"
|
||||
func flushOutbox(for peerID: PeerID) {
|
||||
guard let queued = outbox[peerID], !queued.isEmpty else { return }
|
||||
SecureLogger.debug("Flushing outbox for \(peerID.id.prefix(8))… count=\(queued.count)", category: .session)
|
||||
|
||||
let now = Date()
|
||||
var remaining: [QueuedMessage] = []
|
||||
|
||||
for message in queued {
|
||||
// Skip expired messages (TTL exceeded)
|
||||
if now.timeIntervalSince(message.timestamp) > Self.messageTTLSeconds {
|
||||
SecureLogger.debug("⏰ Expired queued message for \(peerID.id.prefix(8))… id=\(message.messageID.prefix(8))… (age: \(Int(now.timeIntervalSince(message.timestamp)))s)", category: .session)
|
||||
continue
|
||||
}
|
||||
|
||||
if let transport = reachableTransport(for: peerID) {
|
||||
SecureLogger.debug("Outbox -> \(type(of: transport)) for \(peerID.id.prefix(8))… id=\(message.messageID.prefix(8))…", category: .session)
|
||||
transport.sendPrivateMessage(message.content, to: peerID, recipientNickname: message.nickname, messageID: message.messageID)
|
||||
} else {
|
||||
remaining.append(message)
|
||||
}
|
||||
}
|
||||
|
||||
if remaining.isEmpty {
|
||||
outbox.removeValue(forKey: peerID)
|
||||
} else {
|
||||
outbox[peerID] = remaining
|
||||
}
|
||||
}
|
||||
|
||||
func flushAllOutbox() {
|
||||
for key in Array(outbox.keys) { flushOutbox(for: key) }
|
||||
}
|
||||
|
||||
/// Periodically clean up expired messages from all outboxes
|
||||
func cleanupExpiredMessages() {
|
||||
let now = Date()
|
||||
for peerID in Array(outbox.keys) {
|
||||
outbox[peerID]?.removeAll { now.timeIntervalSince($0.timestamp) > Self.messageTTLSeconds }
|
||||
if outbox[peerID]?.isEmpty == true {
|
||||
outbox.removeValue(forKey: peerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Notification Names
|
||||
|
||||
extension Notification.Name {
|
||||
static let nostrMessageReceived = Notification.Name("NostrMessageReceived")
|
||||
static let messageDeliveryAcknowledged = Notification.Name("MessageDeliveryAcknowledged")
|
||||
static let readReceiptReceived = Notification.Name("ReadReceiptReceived")
|
||||
static let appDidBecomeActive = Notification.Name("AppDidBecomeActive")
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,177 @@
|
||||
import Nostr
|
||||
import Foundation
|
||||
import BitLogger
|
||||
import Combine
|
||||
import Tor
|
||||
|
||||
@MainActor
|
||||
protocol NetworkActivationTorControlling: AnyObject {
|
||||
func setAutoStartAllowed(_ allowed: Bool)
|
||||
func startIfNeeded()
|
||||
func shutdownCompletely()
|
||||
}
|
||||
|
||||
@MainActor
|
||||
protocol NetworkActivationRelayControlling: AnyObject {
|
||||
func connect()
|
||||
func disconnect()
|
||||
}
|
||||
|
||||
protocol NetworkActivationProxyControlling: AnyObject {
|
||||
func setProxyMode(useTor: Bool)
|
||||
}
|
||||
|
||||
extension TorManager: NetworkActivationTorControlling {}
|
||||
extension NostrRelayManager: NetworkActivationRelayControlling {}
|
||||
extension TorURLSession: NetworkActivationProxyControlling {}
|
||||
|
||||
/// Coordinates when the app is allowed to start Tor and connect to Nostr relays.
|
||||
/// Policy: permit start when either location permissions are authorized OR
|
||||
/// there exists at least one mutual favorite. Otherwise, do not start.
|
||||
@MainActor
|
||||
final class NetworkActivationService: ObservableObject {
|
||||
static let shared = NetworkActivationService()
|
||||
|
||||
@Published private(set) var activationAllowed: Bool = false
|
||||
@Published private(set) var userTorEnabled: Bool = true
|
||||
|
||||
private var cancellables = Set<AnyCancellable>()
|
||||
private var started = false
|
||||
private let torPreferenceKey = "networkActivationService.userTorEnabled"
|
||||
private var torAutoStartDesired: Bool = false
|
||||
private let storage: UserDefaults
|
||||
private let locationPermissionPublisher: AnyPublisher<LocationChannelManager.PermissionState, Never>
|
||||
private let mutualFavoritesPublisher: AnyPublisher<Set<Data>, Never>
|
||||
private let permissionProvider: () -> LocationChannelManager.PermissionState
|
||||
private let mutualFavoritesProvider: () -> Set<Data>
|
||||
private let torController: NetworkActivationTorControlling
|
||||
private let relayController: NetworkActivationRelayControlling
|
||||
private let proxyController: NetworkActivationProxyControlling
|
||||
private let notificationCenter: NotificationCenter
|
||||
|
||||
private init() {
|
||||
storage = .standard
|
||||
locationPermissionPublisher = LocationChannelManager.shared.$permissionState.eraseToAnyPublisher()
|
||||
mutualFavoritesPublisher = FavoritesPersistenceService.shared.$mutualFavorites.eraseToAnyPublisher()
|
||||
permissionProvider = { LocationChannelManager.shared.permissionState }
|
||||
mutualFavoritesProvider = { FavoritesPersistenceService.shared.mutualFavorites }
|
||||
torController = TorManager.shared
|
||||
relayController = NostrRelayManager.shared
|
||||
proxyController = TorURLSession.shared
|
||||
notificationCenter = .default
|
||||
}
|
||||
|
||||
internal init(
|
||||
storage: UserDefaults,
|
||||
locationPermissionPublisher: AnyPublisher<LocationChannelManager.PermissionState, Never>,
|
||||
mutualFavoritesPublisher: AnyPublisher<Set<Data>, Never>,
|
||||
permissionProvider: @escaping () -> LocationChannelManager.PermissionState,
|
||||
mutualFavoritesProvider: @escaping () -> Set<Data>,
|
||||
torController: NetworkActivationTorControlling,
|
||||
relayController: NetworkActivationRelayControlling,
|
||||
proxyController: NetworkActivationProxyControlling,
|
||||
notificationCenter: NotificationCenter = .default
|
||||
) {
|
||||
self.storage = storage
|
||||
self.locationPermissionPublisher = locationPermissionPublisher
|
||||
self.mutualFavoritesPublisher = mutualFavoritesPublisher
|
||||
self.permissionProvider = permissionProvider
|
||||
self.mutualFavoritesProvider = mutualFavoritesProvider
|
||||
self.torController = torController
|
||||
self.relayController = relayController
|
||||
self.proxyController = proxyController
|
||||
self.notificationCenter = notificationCenter
|
||||
}
|
||||
|
||||
func start() {
|
||||
guard !started else { return }
|
||||
started = true
|
||||
|
||||
if let stored = storage.object(forKey: torPreferenceKey) as? Bool {
|
||||
userTorEnabled = stored
|
||||
} else {
|
||||
userTorEnabled = true
|
||||
}
|
||||
|
||||
// Initial compute
|
||||
let allowed = basePolicyAllowed()
|
||||
activationAllowed = allowed
|
||||
torAutoStartDesired = allowed && userTorEnabled
|
||||
torController.setAutoStartAllowed(torAutoStartDesired)
|
||||
applyTorState(torDesired: torAutoStartDesired)
|
||||
if allowed {
|
||||
relayController.connect()
|
||||
} else {
|
||||
relayController.disconnect()
|
||||
}
|
||||
|
||||
// React to location permission changes
|
||||
locationPermissionPublisher
|
||||
.receive(on: DispatchQueue.main)
|
||||
.sink { [weak self] _ in
|
||||
self?.reevaluate()
|
||||
}
|
||||
.store(in: &cancellables)
|
||||
|
||||
// React to mutual favorites changes
|
||||
mutualFavoritesPublisher
|
||||
.receive(on: DispatchQueue.main)
|
||||
.sink { [weak self] _ in
|
||||
self?.reevaluate()
|
||||
}
|
||||
.store(in: &cancellables)
|
||||
}
|
||||
|
||||
func setUserTorEnabled(_ enabled: Bool) {
|
||||
guard enabled != userTorEnabled else { return }
|
||||
userTorEnabled = enabled
|
||||
storage.set(enabled, forKey: torPreferenceKey)
|
||||
notificationCenter.post(
|
||||
name: .TorUserPreferenceChanged,
|
||||
object: nil,
|
||||
userInfo: ["enabled": enabled]
|
||||
)
|
||||
reevaluate()
|
||||
}
|
||||
|
||||
private func reevaluate() {
|
||||
let allowed = basePolicyAllowed()
|
||||
let torDesired = allowed && userTorEnabled
|
||||
let statusChanged = allowed != activationAllowed
|
||||
let torChanged = torDesired != torAutoStartDesired
|
||||
if statusChanged {
|
||||
SecureLogger.info("NetworkActivationService: activationAllowed -> \(allowed)", category: .session)
|
||||
activationAllowed = allowed
|
||||
}
|
||||
if statusChanged || torChanged {
|
||||
torAutoStartDesired = torDesired
|
||||
torController.setAutoStartAllowed(torDesired)
|
||||
applyTorState(torDesired: torDesired)
|
||||
}
|
||||
|
||||
if allowed {
|
||||
if torChanged {
|
||||
// Reset relay sockets when switching transport path (Tor ↔︎ direct)
|
||||
relayController.disconnect()
|
||||
}
|
||||
relayController.connect()
|
||||
} else if statusChanged {
|
||||
relayController.disconnect()
|
||||
}
|
||||
}
|
||||
|
||||
private func basePolicyAllowed() -> Bool {
|
||||
let permOK = permissionProvider() == .authorized
|
||||
let hasMutual = !mutualFavoritesProvider().isEmpty
|
||||
return permOK || hasMutual
|
||||
}
|
||||
|
||||
private func applyTorState(torDesired: Bool) {
|
||||
proxyController.setProxyMode(useTor: torDesired)
|
||||
if torDesired {
|
||||
torController.startIfNeeded()
|
||||
} else {
|
||||
torController.shutdownCompletely()
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -11,7 +11,7 @@
|
||||
///
|
||||
/// High-level encryption service that manages Noise Protocol sessions for secure
|
||||
/// peer-to-peer communication in BitChat. Acts as the bridge between the transport
|
||||
/// layer (BluetoothMeshService) and the cryptographic layer (NoiseProtocol).
|
||||
/// layer (BLEService) and the cryptographic layer (NoiseProtocol).
|
||||
///
|
||||
/// ## Overview
|
||||
/// This service provides a simplified API for establishing and managing encrypted
|
||||
@@ -60,9 +60,8 @@
|
||||
/// ```
|
||||
///
|
||||
/// ## Integration Points
|
||||
/// - **BluetoothMeshService**: Calls this service for all private messages
|
||||
/// - **BLEService**: Calls this service for all private messages
|
||||
/// - **ChatViewModel**: Monitors encryption status for UI indicators
|
||||
/// - **NoiseHandshakeCoordinator**: Prevents handshake race conditions
|
||||
/// - **KeychainManager**: Secure storage for identity keys
|
||||
///
|
||||
/// ## Thread Safety
|
||||
@@ -83,9 +82,11 @@
|
||||
/// - Background queue for CPU-intensive operations
|
||||
///
|
||||
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Noise
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
import os.log
|
||||
|
||||
// MARK: - Encryption Status
|
||||
|
||||
@@ -116,15 +117,30 @@ enum EncryptionStatus: Equatable {
|
||||
var description: String {
|
||||
switch self {
|
||||
case .none:
|
||||
return "Encryption failed"
|
||||
return String(localized: "encryption.status.failed", comment: "Status text when encryption failed")
|
||||
case .noHandshake:
|
||||
return "Not encrypted"
|
||||
return String(localized: "encryption.status.not_encrypted", comment: "Status text when no encryption handshake happened")
|
||||
case .noiseHandshaking:
|
||||
return "Establishing encryption..."
|
||||
return String(localized: "encryption.status.establishing", comment: "Status text when encryption is being established")
|
||||
case .noiseSecured:
|
||||
return "Encrypted"
|
||||
return String(localized: "encryption.status.secured", comment: "Status text when encryption is secured but not verified")
|
||||
case .noiseVerified:
|
||||
return "Encrypted & Verified"
|
||||
return String(localized: "encryption.status.verified", comment: "Status text when encryption is verified")
|
||||
}
|
||||
}
|
||||
|
||||
var accessibilityDescription: String {
|
||||
switch self {
|
||||
case .none:
|
||||
return String(localized: "encryption.accessibility.failed", comment: "Accessibility text when encryption failed")
|
||||
case .noHandshake:
|
||||
return String(localized: "encryption.accessibility.not_encrypted", comment: "Accessibility text when encryption is not established")
|
||||
case .noiseHandshaking:
|
||||
return String(localized: "encryption.accessibility.establishing", comment: "Accessibility text when encryption is being established")
|
||||
case .noiseSecured:
|
||||
return String(localized: "encryption.accessibility.secured", comment: "Accessibility text when encryption is secured")
|
||||
case .noiseVerified:
|
||||
return String(localized: "encryption.accessibility.verified", comment: "Accessibility text when encryption is verified")
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -135,7 +151,7 @@ enum EncryptionStatus: Equatable {
|
||||
/// Provides a high-level API for establishing secure channels between peers,
|
||||
/// handling all cryptographic operations transparently.
|
||||
/// - Important: This service maintains the device's cryptographic identity
|
||||
class NoiseEncryptionService {
|
||||
final class NoiseEncryptionService {
|
||||
// Static identity key (persistent across sessions)
|
||||
private let staticIdentityKey: Curve25519.KeyAgreement.PrivateKey
|
||||
public let staticIdentityPublicKey: Curve25519.KeyAgreement.PublicKey
|
||||
@@ -148,64 +164,123 @@ class NoiseEncryptionService {
|
||||
private let sessionManager: NoiseSessionManager
|
||||
|
||||
// Peer fingerprints (SHA256 hash of static public key)
|
||||
private var peerFingerprints: [String: String] = [:] // peerID -> fingerprint
|
||||
private var fingerprintToPeerID: [String: String] = [:] // fingerprint -> peerID
|
||||
private var peerFingerprints: [PeerID: String] = [:]
|
||||
private var fingerprintToPeerID: [String: PeerID] = [:]
|
||||
|
||||
// Thread safety
|
||||
private let serviceQueue = DispatchQueue(label: "chat.bitchat.noise.service", attributes: .concurrent)
|
||||
|
||||
// Security components
|
||||
private let rateLimiter = NoiseRateLimiter()
|
||||
private let keychain: KeychainManagerProtocol
|
||||
|
||||
// Session maintenance
|
||||
private var rekeyTimer: Timer?
|
||||
private let rekeyCheckInterval: TimeInterval = 60.0 // Check every minute
|
||||
|
||||
// Callbacks
|
||||
var onPeerAuthenticated: ((String, String) -> Void)? // peerID, fingerprint
|
||||
var onHandshakeRequired: ((String) -> Void)? // peerID needs handshake
|
||||
private var onPeerAuthenticatedHandlers: [((PeerID, String) -> Void)] = [] // Array of handlers for peer authentication
|
||||
var onHandshakeRequired: ((PeerID) -> Void)? // peerID needs handshake
|
||||
|
||||
init() {
|
||||
// Load or create static identity key (ONLY from keychain)
|
||||
// Add a handler for peer authentication
|
||||
func addOnPeerAuthenticatedHandler(_ handler: @escaping (PeerID, String) -> Void) {
|
||||
serviceQueue.async(flags: .barrier) { [weak self] in
|
||||
self?.onPeerAuthenticatedHandlers.append(handler)
|
||||
}
|
||||
}
|
||||
|
||||
// Legacy support - setting this will add to the handlers array
|
||||
var onPeerAuthenticated: ((PeerID, String) -> Void)? {
|
||||
get { nil } // Always return nil for backward compatibility
|
||||
set {
|
||||
if let handler = newValue {
|
||||
addOnPeerAuthenticatedHandler(handler)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
init(keychain: KeychainManagerProtocol) {
|
||||
self.keychain = keychain
|
||||
|
||||
// BCH-01-009: Load or create static identity key with proper error handling
|
||||
let loadedKey: Curve25519.KeyAgreement.PrivateKey
|
||||
|
||||
// Try to load from keychain
|
||||
if let identityData = KeychainManager.shared.getIdentityKey(forKey: "noiseStaticKey"),
|
||||
let key = try? Curve25519.KeyAgreement.PrivateKey(rawRepresentation: identityData) {
|
||||
loadedKey = key
|
||||
SecureLogger.logKeyOperation("load", keyType: "noiseStaticKey", success: true)
|
||||
}
|
||||
// If no identity exists, create new one
|
||||
else {
|
||||
loadedKey = Curve25519.KeyAgreement.PrivateKey()
|
||||
let keyData = loadedKey.rawRepresentation
|
||||
// Try to load from keychain with proper error classification
|
||||
let noiseKeyResult = keychain.getIdentityKeyWithResult(forKey: "noiseStaticKey")
|
||||
|
||||
// Save to keychain
|
||||
let saved = KeychainManager.shared.saveIdentityKey(keyData, forKey: "noiseStaticKey")
|
||||
SecureLogger.logKeyOperation("create", keyType: "noiseStaticKey", success: saved)
|
||||
switch noiseKeyResult {
|
||||
case .success(let identityData):
|
||||
if let key = try? Curve25519.KeyAgreement.PrivateKey(rawRepresentation: identityData) {
|
||||
loadedKey = key
|
||||
SecureLogger.logKeyOperation(.load, keyType: "noiseStaticKey", success: true)
|
||||
} else {
|
||||
// Data corrupted, regenerate
|
||||
SecureLogger.warning("Noise static key data corrupted, regenerating", category: .keychain)
|
||||
loadedKey = Self.generateAndSaveNoiseKey(keychain: keychain)
|
||||
}
|
||||
|
||||
case .itemNotFound:
|
||||
// Expected case: no key exists yet, create new one
|
||||
loadedKey = Self.generateAndSaveNoiseKey(keychain: keychain)
|
||||
|
||||
case .accessDenied:
|
||||
// Critical error - log but proceed with ephemeral key (will be lost on restart)
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -1),
|
||||
context: "Keychain access denied - using ephemeral identity", category: .keychain)
|
||||
loadedKey = Curve25519.KeyAgreement.PrivateKey()
|
||||
|
||||
case .deviceLocked, .authenticationFailed:
|
||||
// Recoverable error - use ephemeral key and warn
|
||||
SecureLogger.warning("Device locked or auth failed - using ephemeral identity until unlocked", category: .keychain)
|
||||
loadedKey = Curve25519.KeyAgreement.PrivateKey()
|
||||
|
||||
case .otherError(let status):
|
||||
// Unexpected error - log and use ephemeral key
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)),
|
||||
context: "Unexpected keychain error - using ephemeral identity", category: .keychain)
|
||||
loadedKey = Curve25519.KeyAgreement.PrivateKey()
|
||||
}
|
||||
|
||||
// Now assign the final value
|
||||
self.staticIdentityKey = loadedKey
|
||||
self.staticIdentityPublicKey = staticIdentityKey.publicKey
|
||||
|
||||
// Load or create signing key pair
|
||||
// BCH-01-009: Load or create signing key pair with proper error handling
|
||||
let loadedSigningKey: Curve25519.Signing.PrivateKey
|
||||
|
||||
// Try to load from keychain
|
||||
if let signingData = KeychainManager.shared.getIdentityKey(forKey: "ed25519SigningKey"),
|
||||
let key = try? Curve25519.Signing.PrivateKey(rawRepresentation: signingData) {
|
||||
loadedSigningKey = key
|
||||
SecureLogger.logKeyOperation("load", keyType: "ed25519SigningKey", success: true)
|
||||
}
|
||||
// If no signing key exists, create new one
|
||||
else {
|
||||
loadedSigningKey = Curve25519.Signing.PrivateKey()
|
||||
let keyData = loadedSigningKey.rawRepresentation
|
||||
let signingKeyResult = keychain.getIdentityKeyWithResult(forKey: "ed25519SigningKey")
|
||||
|
||||
// Save to keychain
|
||||
let saved = KeychainManager.shared.saveIdentityKey(keyData, forKey: "ed25519SigningKey")
|
||||
SecureLogger.logKeyOperation("create", keyType: "ed25519SigningKey", success: saved)
|
||||
switch signingKeyResult {
|
||||
case .success(let signingData):
|
||||
if let key = try? Curve25519.Signing.PrivateKey(rawRepresentation: signingData) {
|
||||
loadedSigningKey = key
|
||||
SecureLogger.logKeyOperation(.load, keyType: "ed25519SigningKey", success: true)
|
||||
} else {
|
||||
// Data corrupted, regenerate
|
||||
SecureLogger.warning("Ed25519 signing key data corrupted, regenerating", category: .keychain)
|
||||
loadedSigningKey = Self.generateAndSaveSigningKey(keychain: keychain)
|
||||
}
|
||||
|
||||
case .itemNotFound:
|
||||
// Expected case: no key exists yet, create new one
|
||||
loadedSigningKey = Self.generateAndSaveSigningKey(keychain: keychain)
|
||||
|
||||
case .accessDenied:
|
||||
// Critical error - log but proceed with ephemeral key
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -1),
|
||||
context: "Keychain access denied - using ephemeral signing key", category: .keychain)
|
||||
loadedSigningKey = Curve25519.Signing.PrivateKey()
|
||||
|
||||
case .deviceLocked, .authenticationFailed:
|
||||
// Recoverable error - use ephemeral key and warn
|
||||
SecureLogger.warning("Device locked or auth failed - using ephemeral signing key until unlocked", category: .keychain)
|
||||
loadedSigningKey = Curve25519.Signing.PrivateKey()
|
||||
|
||||
case .otherError(let status):
|
||||
// Unexpected error - log and use ephemeral key
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: Int(status)),
|
||||
context: "Unexpected keychain error - using ephemeral signing key", category: .keychain)
|
||||
loadedSigningKey = Curve25519.Signing.PrivateKey()
|
||||
}
|
||||
|
||||
// Now assign the signing keys
|
||||
@@ -213,7 +288,7 @@ class NoiseEncryptionService {
|
||||
self.signingPublicKey = signingKey.publicKey
|
||||
|
||||
// Initialize session manager
|
||||
self.sessionManager = NoiseSessionManager(localStaticKey: staticIdentityKey)
|
||||
self.sessionManager = NoiseSessionManager(localStaticKey: staticIdentityKey, keychain: keychain)
|
||||
|
||||
// Set up session callbacks
|
||||
sessionManager.onSessionEstablished = { [weak self] peerID, remoteStaticKey in
|
||||
@@ -224,6 +299,56 @@ class NoiseEncryptionService {
|
||||
startRekeyTimer()
|
||||
}
|
||||
|
||||
// MARK: - BCH-01-009: Key Generation Helpers with Save Verification
|
||||
|
||||
/// Generate and save a new Noise static key, verifying the save succeeds
|
||||
private static func generateAndSaveNoiseKey(keychain: KeychainManagerProtocol) -> Curve25519.KeyAgreement.PrivateKey {
|
||||
let newKey = Curve25519.KeyAgreement.PrivateKey()
|
||||
let keyData = newKey.rawRepresentation
|
||||
|
||||
// Save to keychain and verify success
|
||||
let saveResult = keychain.saveIdentityKeyWithResult(keyData, forKey: "noiseStaticKey")
|
||||
|
||||
switch saveResult {
|
||||
case .success:
|
||||
SecureLogger.logKeyOperation(.create, keyType: "noiseStaticKey", success: true)
|
||||
case .duplicateItem:
|
||||
// This shouldn't happen since we just tried to load, but handle it
|
||||
SecureLogger.warning("Noise key already exists (race condition?)", category: .keychain)
|
||||
default:
|
||||
// Save failed - log but continue with the key (it will be ephemeral)
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -1),
|
||||
context: "Failed to persist noise static key - identity will be lost on restart",
|
||||
category: .keychain)
|
||||
}
|
||||
|
||||
return newKey
|
||||
}
|
||||
|
||||
/// Generate and save a new Ed25519 signing key, verifying the save succeeds
|
||||
private static func generateAndSaveSigningKey(keychain: KeychainManagerProtocol) -> Curve25519.Signing.PrivateKey {
|
||||
let newKey = Curve25519.Signing.PrivateKey()
|
||||
let keyData = newKey.rawRepresentation
|
||||
|
||||
// Save to keychain and verify success
|
||||
let saveResult = keychain.saveIdentityKeyWithResult(keyData, forKey: "ed25519SigningKey")
|
||||
|
||||
switch saveResult {
|
||||
case .success:
|
||||
SecureLogger.logKeyOperation(.create, keyType: "ed25519SigningKey", success: true)
|
||||
case .duplicateItem:
|
||||
// This shouldn't happen since we just tried to load, but handle it
|
||||
SecureLogger.warning("Signing key already exists (race condition?)", category: .keychain)
|
||||
default:
|
||||
// Save failed - log but continue with the key (it will be ephemeral)
|
||||
SecureLogger.error(NSError(domain: "Keychain", code: -1),
|
||||
context: "Failed to persist signing key - identity will be lost on restart",
|
||||
category: .keychain)
|
||||
}
|
||||
|
||||
return newKey
|
||||
}
|
||||
|
||||
// MARK: - Public Interface
|
||||
|
||||
/// Get our static public key for sharing
|
||||
@@ -238,22 +363,21 @@ class NoiseEncryptionService {
|
||||
|
||||
/// Get our identity fingerprint
|
||||
func getIdentityFingerprint() -> String {
|
||||
let hash = SHA256.hash(data: staticIdentityPublicKey.rawRepresentation)
|
||||
return hash.map { String(format: "%02x", $0) }.joined()
|
||||
staticIdentityPublicKey.rawRepresentation.sha256Fingerprint()
|
||||
}
|
||||
|
||||
/// Get peer's public key data
|
||||
func getPeerPublicKeyData(_ peerID: String) -> Data? {
|
||||
func getPeerPublicKeyData(_ peerID: PeerID) -> Data? {
|
||||
return sessionManager.getRemoteStaticKey(for: peerID)?.rawRepresentation
|
||||
}
|
||||
|
||||
/// Clear persistent identity (for panic mode)
|
||||
func clearPersistentIdentity() {
|
||||
// Clear from keychain
|
||||
let deletedStatic = KeychainManager.shared.deleteIdentityKey(forKey: "noiseStaticKey")
|
||||
let deletedSigning = KeychainManager.shared.deleteIdentityKey(forKey: "ed25519SigningKey")
|
||||
SecureLogger.logKeyOperation("delete", keyType: "identity keys", success: deletedStatic && deletedSigning)
|
||||
SecureLogger.log("Panic mode activated - identity cleared", category: SecureLogger.security, level: .warning)
|
||||
let deletedStatic = keychain.deleteIdentityKey(forKey: "noiseStaticKey")
|
||||
let deletedSigning = keychain.deleteIdentityKey(forKey: "ed25519SigningKey")
|
||||
SecureLogger.logKeyOperation(.delete, keyType: "identity keys", success: deletedStatic && deletedSigning)
|
||||
SecureLogger.warning("Panic mode activated - identity cleared", category: .security)
|
||||
// Stop rekey timer
|
||||
stopRekeyTimer()
|
||||
}
|
||||
@@ -264,7 +388,7 @@ class NoiseEncryptionService {
|
||||
let signature = try signingKey.signature(for: data)
|
||||
return signature
|
||||
} catch {
|
||||
SecureLogger.logError(error, context: "Failed to sign data", category: SecureLogger.noise)
|
||||
SecureLogger.error(error, context: "Failed to sign data")
|
||||
return nil
|
||||
}
|
||||
}
|
||||
@@ -275,29 +399,117 @@ class NoiseEncryptionService {
|
||||
let signingPublicKey = try Curve25519.Signing.PublicKey(rawRepresentation: publicKey)
|
||||
return signingPublicKey.isValidSignature(signature, for: data)
|
||||
} catch {
|
||||
SecureLogger.logError(error, context: "Failed to verify signature", category: SecureLogger.noise)
|
||||
SecureLogger.error(error, context: "Failed to verify signature")
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Announce Signature Helpers
|
||||
|
||||
/// Build the canonical announce binding message bytes and sign with our Ed25519 key
|
||||
/// - Parameters:
|
||||
/// - peerID: 8-byte routing ID (as in packet header)
|
||||
/// - noiseKey: 32-byte Curve25519.KeyAgreement public key
|
||||
/// - ed25519Key: 32-byte Ed25519 public key (self)
|
||||
/// - nickname: UTF-8 nickname (<=255 bytes)
|
||||
/// - timestampMs: UInt64 milliseconds since epoch
|
||||
/// - Returns: Ed25519 signature over the canonical bytes, or nil on failure
|
||||
func buildAnnounceSignature(peerID: Data, noiseKey: Data, ed25519Key: Data, nickname: String, timestampMs: UInt64) -> Data? {
|
||||
let message = canonicalAnnounceBytes(peerID: peerID, noiseKey: noiseKey, ed25519Key: ed25519Key, nickname: nickname, timestampMs: timestampMs)
|
||||
return signData(message)
|
||||
}
|
||||
|
||||
/// Verify an announce signature
|
||||
func verifyAnnounceSignature(signature: Data, peerID: Data, noiseKey: Data, ed25519Key: Data, nickname: String, timestampMs: UInt64, publicKey: Data) -> Bool {
|
||||
let message = canonicalAnnounceBytes(peerID: peerID, noiseKey: noiseKey, ed25519Key: ed25519Key, nickname: nickname, timestampMs: timestampMs)
|
||||
return verifySignature(signature, for: message, publicKey: publicKey)
|
||||
}
|
||||
|
||||
/// Build canonical bytes for announce signing.
|
||||
private func canonicalAnnounceBytes(peerID: Data, noiseKey: Data, ed25519Key: Data, nickname: String, timestampMs: UInt64) -> Data {
|
||||
var out = Data()
|
||||
// context
|
||||
let context = "bitchat-announce-v1".data(using: .utf8) ?? Data()
|
||||
out.append(UInt8(min(context.count, 255)))
|
||||
out.append(context.prefix(255))
|
||||
// peerID (expect 8 bytes; pad/truncate to 8 for canonicalization)
|
||||
let peerID8 = peerID.prefix(8)
|
||||
out.append(peerID8)
|
||||
if peerID8.count < 8 { out.append(Data(repeating: 0, count: 8 - peerID8.count)) }
|
||||
// noise static key (expect 32)
|
||||
let noise32 = noiseKey.prefix(32)
|
||||
out.append(noise32)
|
||||
if noise32.count < 32 { out.append(Data(repeating: 0, count: 32 - noise32.count)) }
|
||||
// ed25519 public key (expect 32)
|
||||
let ed32 = ed25519Key.prefix(32)
|
||||
out.append(ed32)
|
||||
if ed32.count < 32 { out.append(Data(repeating: 0, count: 32 - ed32.count)) }
|
||||
// nickname length + bytes
|
||||
let nickData = nickname.data(using: .utf8) ?? Data()
|
||||
out.append(UInt8(min(nickData.count, 255)))
|
||||
out.append(nickData.prefix(255))
|
||||
// timestamp
|
||||
var ts = timestampMs.bigEndian
|
||||
withUnsafeBytes(of: &ts) { raw in out.append(contentsOf: raw) }
|
||||
return out
|
||||
}
|
||||
|
||||
// MARK: - Packet Signing/Verification
|
||||
|
||||
/// Sign a BitchatPacket using the noise private key
|
||||
func signPacket(_ packet: BitchatPacket) -> BitchatPacket? {
|
||||
// Create canonical packet bytes for signing
|
||||
guard let packetData = packet.toBinaryDataForSigning() else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Sign with the noise private key (converted to Ed25519 for signing)
|
||||
guard let signature = signData(packetData) else {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Return new packet with signature
|
||||
var signedPacket = packet
|
||||
signedPacket.signature = signature
|
||||
return signedPacket
|
||||
}
|
||||
|
||||
/// Verify a BitchatPacket signature using the provided public key
|
||||
func verifyPacketSignature(_ packet: BitchatPacket, publicKey: Data) -> Bool {
|
||||
guard let signature = packet.signature else {
|
||||
return false
|
||||
}
|
||||
|
||||
// Create canonical packet bytes for verification (without signature)
|
||||
|
||||
guard let packetData = packet.toBinaryDataForSigning() else {
|
||||
return false
|
||||
}
|
||||
|
||||
// For noise public keys, we need to derive the Ed25519 key for verification
|
||||
// This assumes the noise key can be used for Ed25519 signing
|
||||
return verifySignature(signature, for: packetData, publicKey: publicKey)
|
||||
}
|
||||
|
||||
|
||||
// MARK: - Handshake Management
|
||||
|
||||
/// Initiate a Noise handshake with a peer
|
||||
func initiateHandshake(with peerID: String) throws -> Data {
|
||||
func initiateHandshake(with peerID: PeerID) throws -> Data {
|
||||
|
||||
// Validate peer ID
|
||||
guard NoiseSecurityValidator.validatePeerID(peerID) else {
|
||||
SecureLogger.logSecurityEvent(.authenticationFailed(peerID: peerID), level: .warning)
|
||||
guard peerID.isValid else {
|
||||
SecureLogger.warning(.authenticationFailed(peerID: peerID.id))
|
||||
throw NoiseSecurityError.invalidPeerID
|
||||
}
|
||||
|
||||
// Check rate limit
|
||||
guard rateLimiter.allowHandshake(from: peerID) else {
|
||||
SecureLogger.logSecurityEvent(.authenticationFailed(peerID: "Rate limited: \(peerID)"), level: .warning)
|
||||
SecureLogger.warning(.authenticationFailed(peerID: "Rate limited: \(peerID)"))
|
||||
throw NoiseSecurityError.rateLimitExceeded
|
||||
}
|
||||
|
||||
SecureLogger.logSecurityEvent(.handshakeStarted(peerID: peerID))
|
||||
SecureLogger.info(.handshakeStarted(peerID: peerID.id))
|
||||
|
||||
// Return raw handshake data without wrapper
|
||||
// The Noise protocol handles its own message format
|
||||
@@ -306,23 +518,23 @@ class NoiseEncryptionService {
|
||||
}
|
||||
|
||||
/// Process an incoming handshake message
|
||||
func processHandshakeMessage(from peerID: String, message: Data) throws -> Data? {
|
||||
func processHandshakeMessage(from peerID: PeerID, message: Data) throws -> Data? {
|
||||
|
||||
// Validate peer ID
|
||||
guard NoiseSecurityValidator.validatePeerID(peerID) else {
|
||||
SecureLogger.logSecurityEvent(.authenticationFailed(peerID: peerID), level: .warning)
|
||||
guard peerID.isValid else {
|
||||
SecureLogger.warning(.authenticationFailed(peerID: peerID.id))
|
||||
throw NoiseSecurityError.invalidPeerID
|
||||
}
|
||||
|
||||
// Validate message size
|
||||
guard NoiseSecurityValidator.validateHandshakeMessageSize(message) else {
|
||||
SecureLogger.logSecurityEvent(.handshakeFailed(peerID: peerID, error: "Message too large"), level: .warning)
|
||||
SecureLogger.warning(.handshakeFailed(peerID: peerID.id, error: "Message too large"))
|
||||
throw NoiseSecurityError.messageTooLarge
|
||||
}
|
||||
|
||||
// Check rate limit
|
||||
guard rateLimiter.allowHandshake(from: peerID) else {
|
||||
SecureLogger.logSecurityEvent(.authenticationFailed(peerID: "Rate limited: \(peerID)"), level: .warning)
|
||||
SecureLogger.warning(.authenticationFailed(peerID: "Rate limited: \(peerID)"))
|
||||
throw NoiseSecurityError.rateLimitExceeded
|
||||
}
|
||||
|
||||
@@ -336,19 +548,19 @@ class NoiseEncryptionService {
|
||||
}
|
||||
|
||||
/// Check if we have an established session with a peer
|
||||
func hasEstablishedSession(with peerID: String) -> Bool {
|
||||
func hasEstablishedSession(with peerID: PeerID) -> Bool {
|
||||
return sessionManager.getSession(for: peerID)?.isEstablished() ?? false
|
||||
}
|
||||
|
||||
/// Check if we have a session (established or handshaking) with a peer
|
||||
func hasSession(with peerID: String) -> Bool {
|
||||
func hasSession(with peerID: PeerID) -> Bool {
|
||||
return sessionManager.getSession(for: peerID) != nil
|
||||
}
|
||||
|
||||
// MARK: - Encryption/Decryption
|
||||
|
||||
/// Encrypt data for a specific peer
|
||||
func encrypt(_ data: Data, for peerID: String) throws -> Data {
|
||||
func encrypt(_ data: Data, for peerID: PeerID) throws -> Data {
|
||||
// Validate message size
|
||||
guard NoiseSecurityValidator.validateMessageSize(data) else {
|
||||
throw NoiseSecurityError.messageTooLarge
|
||||
@@ -370,7 +582,7 @@ class NoiseEncryptionService {
|
||||
}
|
||||
|
||||
/// Decrypt data from a specific peer
|
||||
func decrypt(_ data: Data, from peerID: String) throws -> Data {
|
||||
func decrypt(_ data: Data, from peerID: PeerID) throws -> Data {
|
||||
// Validate message size
|
||||
guard NoiseSecurityValidator.validateMessageSize(data) else {
|
||||
throw NoiseSecurityError.messageTooLarge
|
||||
@@ -392,56 +604,37 @@ class NoiseEncryptionService {
|
||||
// MARK: - Peer Management
|
||||
|
||||
/// Get fingerprint for a peer
|
||||
func getPeerFingerprint(_ peerID: String) -> String? {
|
||||
func getPeerFingerprint(_ peerID: PeerID) -> String? {
|
||||
return serviceQueue.sync {
|
||||
return peerFingerprints[peerID]
|
||||
}
|
||||
}
|
||||
|
||||
/// Get peer ID for a fingerprint
|
||||
func getPeerID(for fingerprint: String) -> String? {
|
||||
return serviceQueue.sync {
|
||||
return fingerprintToPeerID[fingerprint]
|
||||
func clearEphemeralStateForPanic() {
|
||||
sessionManager.removeAllSessions()
|
||||
serviceQueue.sync(flags: .barrier) {
|
||||
peerFingerprints.removeAll()
|
||||
fingerprintToPeerID.removeAll()
|
||||
}
|
||||
rateLimiter.resetAll()
|
||||
}
|
||||
|
||||
/// Remove a peer session
|
||||
func removePeer(_ peerID: String) {
|
||||
/// Clear session for a specific peer (e.g., on decryption failure to allow re-handshake)
|
||||
func clearSession(for peerID: PeerID) {
|
||||
sessionManager.removeSession(for: peerID)
|
||||
|
||||
serviceQueue.sync(flags: .barrier) {
|
||||
if let fingerprint = peerFingerprints[peerID] {
|
||||
if let fingerprint = peerFingerprints.removeValue(forKey: peerID) {
|
||||
fingerprintToPeerID.removeValue(forKey: fingerprint)
|
||||
}
|
||||
peerFingerprints.removeValue(forKey: peerID)
|
||||
}
|
||||
|
||||
SecureLogger.logSecurityEvent(.sessionExpired(peerID: peerID))
|
||||
}
|
||||
|
||||
/// Migrate session when peer ID changes
|
||||
func migratePeerSession(from oldPeerID: String, to newPeerID: String, fingerprint: String) {
|
||||
// First update the fingerprint mappings
|
||||
serviceQueue.sync(flags: .barrier) {
|
||||
// Remove old mapping
|
||||
if let oldFingerprint = peerFingerprints[oldPeerID], oldFingerprint == fingerprint {
|
||||
peerFingerprints.removeValue(forKey: oldPeerID)
|
||||
}
|
||||
|
||||
// Add new mapping
|
||||
peerFingerprints[newPeerID] = fingerprint
|
||||
fingerprintToPeerID[fingerprint] = newPeerID
|
||||
}
|
||||
|
||||
// Migrate the session in session manager
|
||||
sessionManager.migrateSession(from: oldPeerID, to: newPeerID)
|
||||
SecureLogger.debug("🔓 Cleared Noise session for \(peerID)", category: .session)
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers
|
||||
|
||||
private func handleSessionEstablished(peerID: String, remoteStaticKey: Curve25519.KeyAgreement.PublicKey) {
|
||||
private func handleSessionEstablished(peerID: PeerID, remoteStaticKey: Curve25519.KeyAgreement.PublicKey) {
|
||||
// Calculate fingerprint
|
||||
let fingerprint = calculateFingerprint(for: remoteStaticKey)
|
||||
let fingerprint = remoteStaticKey.rawRepresentation.sha256Fingerprint()
|
||||
|
||||
// Store fingerprint mapping
|
||||
serviceQueue.sync(flags: .barrier) {
|
||||
@@ -450,15 +643,14 @@ class NoiseEncryptionService {
|
||||
}
|
||||
|
||||
// Log security event
|
||||
SecureLogger.logSecurityEvent(.handshakeCompleted(peerID: peerID))
|
||||
SecureLogger.info(.handshakeCompleted(peerID: peerID.id))
|
||||
|
||||
// Notify about authentication
|
||||
onPeerAuthenticated?(peerID, fingerprint)
|
||||
}
|
||||
|
||||
private func calculateFingerprint(for publicKey: Curve25519.KeyAgreement.PublicKey) -> String {
|
||||
let hash = SHA256.hash(data: publicKey.rawRepresentation)
|
||||
return hash.map { String(format: "%02x", $0) }.joined()
|
||||
// Notify all handlers about authentication
|
||||
serviceQueue.async { [weak self] in
|
||||
self?.onPeerAuthenticatedHandlers.forEach { handler in
|
||||
handler(peerID, fingerprint)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Session Maintenance
|
||||
@@ -482,12 +674,12 @@ class NoiseEncryptionService {
|
||||
// Attempt to rekey the session
|
||||
do {
|
||||
try sessionManager.initiateRekey(for: peerID)
|
||||
SecureLogger.log("Key rotation initiated for peer: \(peerID)", category: SecureLogger.security, level: .info)
|
||||
SecureLogger.debug("Key rotation initiated for peer: \(peerID)", category: .security)
|
||||
|
||||
// Signal that handshake is needed
|
||||
onHandshakeRequired?(peerID)
|
||||
} catch {
|
||||
SecureLogger.logError(error, context: "Failed to initiate rekey for peer: \(peerID)", category: SecureLogger.session)
|
||||
SecureLogger.error(error, context: "Failed to initiate rekey for peer: \(peerID)", category: .session)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,326 @@
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Nostr
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
// Minimal Nostr transport conforming to Transport for offline sending
|
||||
final class NostrTransport: Transport, @unchecked Sendable {
|
||||
struct Dependencies {
|
||||
let notificationCenter: NotificationCenter
|
||||
let loadFavorites: @MainActor () -> [Data: FavoritesPersistenceService.FavoriteRelationship]
|
||||
let favoriteStatusForNoiseKey: @MainActor (Data) -> FavoritesPersistenceService.FavoriteRelationship?
|
||||
let favoriteStatusForPeerID: @MainActor (PeerID) -> FavoritesPersistenceService.FavoriteRelationship?
|
||||
let currentIdentity: @MainActor () throws -> NostrIdentity?
|
||||
let registerPendingGiftWrap: @MainActor (String) -> Void
|
||||
let sendEvent: @MainActor (NostrEvent) -> Void
|
||||
let scheduleAfter: @Sendable (TimeInterval, @escaping @Sendable () -> Void) -> Void
|
||||
|
||||
static func live(idBridge: NostrIdentityBridge) -> Dependencies {
|
||||
Dependencies(
|
||||
notificationCenter: .default,
|
||||
loadFavorites: { FavoritesPersistenceService.shared.favorites },
|
||||
favoriteStatusForNoiseKey: { FavoritesPersistenceService.shared.getFavoriteStatus(for: $0) },
|
||||
favoriteStatusForPeerID: { FavoritesPersistenceService.shared.getFavoriteStatus(forPeerID: $0) },
|
||||
currentIdentity: { try idBridge.getCurrentNostrIdentity() },
|
||||
registerPendingGiftWrap: { NostrRelayManager.registerPendingGiftWrap(id: $0) },
|
||||
sendEvent: { NostrRelayManager.shared.sendEvent($0) },
|
||||
scheduleAfter: { delay, action in
|
||||
DispatchQueue.main.asyncAfter(deadline: .now() + delay, execute: action)
|
||||
}
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// Provide BLE short peer ID for BitChat embedding
|
||||
var senderPeerID = PeerID(str: "")
|
||||
|
||||
// Throttle READ receipts to avoid relay rate limits
|
||||
private struct QueuedRead {
|
||||
let receipt: ReadReceipt
|
||||
let peerID: PeerID
|
||||
}
|
||||
private var readQueue: [QueuedRead] = []
|
||||
private var isSendingReadAcks = false
|
||||
private let readAckInterval: TimeInterval = TransportConfig.nostrReadAckInterval
|
||||
private let keychain: KeychainManagerProtocol
|
||||
private let idBridge: NostrIdentityBridge
|
||||
private let dependencies: Dependencies
|
||||
private var favoriteStatusObserver: NSObjectProtocol?
|
||||
|
||||
// Reachability Cache (thread-safe)
|
||||
private var reachablePeers: Set<PeerID> = []
|
||||
private let queue = DispatchQueue(label: "nostr.transport.state", attributes: .concurrent)
|
||||
|
||||
@MainActor
|
||||
init(
|
||||
keychain: KeychainManagerProtocol,
|
||||
idBridge: NostrIdentityBridge,
|
||||
dependencies: Dependencies? = nil
|
||||
) {
|
||||
self.keychain = keychain
|
||||
self.idBridge = idBridge
|
||||
self.dependencies = dependencies ?? .live(idBridge: idBridge)
|
||||
|
||||
setupObservers()
|
||||
|
||||
// Synchronously warm the cache to avoid startup race
|
||||
let favorites = self.dependencies.loadFavorites()
|
||||
let reachable = favorites.values
|
||||
.filter { $0.peerNostrPublicKey != nil }
|
||||
.map { PeerID(publicKey: $0.peerNoisePublicKey) }
|
||||
|
||||
queue.sync(flags: .barrier) {
|
||||
self.reachablePeers = Set(reachable)
|
||||
}
|
||||
}
|
||||
|
||||
deinit {
|
||||
if let favoriteStatusObserver {
|
||||
dependencies.notificationCenter.removeObserver(favoriteStatusObserver)
|
||||
}
|
||||
}
|
||||
|
||||
private func setupObservers() {
|
||||
favoriteStatusObserver = dependencies.notificationCenter.addObserver(
|
||||
forName: .favoriteStatusChanged,
|
||||
object: nil,
|
||||
queue: nil
|
||||
) { [weak self] _ in
|
||||
self?.refreshReachablePeers()
|
||||
}
|
||||
}
|
||||
|
||||
private func refreshReachablePeers() {
|
||||
Task { @MainActor in
|
||||
let favorites = dependencies.loadFavorites()
|
||||
let reachable = favorites.values
|
||||
.filter { $0.peerNostrPublicKey != nil }
|
||||
.map { PeerID(publicKey: $0.peerNoisePublicKey) }
|
||||
|
||||
self.queue.async(flags: .barrier) { [weak self] in
|
||||
self?.reachablePeers = Set(reachable)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Transport Protocol Conformance
|
||||
|
||||
weak var delegate: BitchatDelegate?
|
||||
weak var peerEventsDelegate: TransportPeerEventsDelegate?
|
||||
|
||||
var peerSnapshotPublisher: AnyPublisher<[TransportPeerSnapshot], Never> {
|
||||
Just([]).eraseToAnyPublisher()
|
||||
}
|
||||
func currentPeerSnapshots() -> [TransportPeerSnapshot] { [] }
|
||||
|
||||
var myPeerID: PeerID { senderPeerID }
|
||||
var myNickname: String { "" }
|
||||
func setNickname(_ nickname: String) { /* not used for Nostr */ }
|
||||
|
||||
func startServices() { /* no-op */ }
|
||||
func stopServices() { /* no-op */ }
|
||||
func emergencyDisconnectAll() { /* no-op */ }
|
||||
|
||||
func isPeerConnected(_ peerID: PeerID) -> Bool { false }
|
||||
|
||||
func isPeerReachable(_ peerID: PeerID) -> Bool {
|
||||
queue.sync {
|
||||
// Check if exact match
|
||||
if reachablePeers.contains(peerID) { return true }
|
||||
// Check for short ID match
|
||||
if peerID.isShort {
|
||||
return reachablePeers.contains(where: { $0.toShort() == peerID })
|
||||
}
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
func peerNickname(peerID: PeerID) -> String? { nil }
|
||||
func getPeerNicknames() -> [PeerID : String] { [:] }
|
||||
|
||||
func getFingerprint(for peerID: PeerID) -> String? { nil }
|
||||
func getNoiseSessionState(for peerID: PeerID) -> LazyHandshakeState { .none }
|
||||
func triggerHandshake(with peerID: PeerID) { /* no-op */ }
|
||||
|
||||
// Nostr does not use Noise sessions here; return a cached placeholder to avoid reallocation
|
||||
private static var cachedNoiseService: NoiseEncryptionService?
|
||||
func getNoiseService() -> NoiseEncryptionService {
|
||||
if let noiseService = Self.cachedNoiseService {
|
||||
return noiseService
|
||||
}
|
||||
let noiseService = NoiseEncryptionService(keychain: keychain)
|
||||
Self.cachedNoiseService = noiseService
|
||||
return noiseService
|
||||
}
|
||||
|
||||
// Public broadcast not supported over Nostr here
|
||||
func sendMessage(_ content: String, mentions: [String]) { /* no-op */ }
|
||||
|
||||
func sendPrivateMessage(_ content: String, to peerID: PeerID, recipientNickname: String, messageID: String) {
|
||||
Task { @MainActor in
|
||||
guard let recipientNpub = resolveRecipientNpub(for: peerID),
|
||||
let recipientHex = npubToHex(recipientNpub),
|
||||
let senderIdentity = try? dependencies.currentIdentity() else { return }
|
||||
SecureLogger.debug("NostrTransport: preparing PM to \(recipientNpub.prefix(16))… id=\(messageID.prefix(8))…", category: .session)
|
||||
guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: messageID, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
|
||||
SecureLogger.error("NostrTransport: failed to embed PM packet", category: .session)
|
||||
return
|
||||
}
|
||||
sendWrappedMessage(content: embedded, recipientHex: recipientHex, senderIdentity: senderIdentity)
|
||||
}
|
||||
}
|
||||
|
||||
func sendReadReceipt(_ receipt: ReadReceipt, to peerID: PeerID) {
|
||||
// Enqueue and process with throttling to avoid relay rate limits
|
||||
// Use barrier to synchronize access to readQueue
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
self?.readQueue.append(QueuedRead(receipt: receipt, peerID: peerID))
|
||||
self?.processReadQueueIfNeeded()
|
||||
}
|
||||
}
|
||||
|
||||
func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool) {
|
||||
Task { @MainActor in
|
||||
guard let recipientNpub = resolveRecipientNpub(for: peerID),
|
||||
let recipientHex = npubToHex(recipientNpub),
|
||||
let senderIdentity = try? dependencies.currentIdentity() else { return }
|
||||
let content = isFavorite ? "[FAVORITED]:\(senderIdentity.npub)" : "[UNFAVORITED]:\(senderIdentity.npub)"
|
||||
SecureLogger.debug("NostrTransport: preparing FAVORITE(\(isFavorite)) to \(recipientNpub.prefix(16))…", category: .session)
|
||||
guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: UUID().uuidString, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
|
||||
SecureLogger.error("NostrTransport: failed to embed favorite notification", category: .session)
|
||||
return
|
||||
}
|
||||
sendWrappedMessage(content: embedded, recipientHex: recipientHex, senderIdentity: senderIdentity)
|
||||
}
|
||||
}
|
||||
|
||||
func sendBroadcastAnnounce() { /* no-op for Nostr */ }
|
||||
func sendDeliveryAck(for messageID: String, to peerID: PeerID) {
|
||||
Task { @MainActor in
|
||||
guard let recipientNpub = resolveRecipientNpub(for: peerID),
|
||||
let recipientHex = npubToHex(recipientNpub),
|
||||
let senderIdentity = try? dependencies.currentIdentity() else { return }
|
||||
SecureLogger.debug("NostrTransport: preparing DELIVERED ack id=\(messageID.prefix(8))…", category: .session)
|
||||
guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .delivered, messageID: messageID, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
|
||||
SecureLogger.error("NostrTransport: failed to embed DELIVERED ack", category: .session)
|
||||
return
|
||||
}
|
||||
sendWrappedMessage(content: ack, recipientHex: recipientHex, senderIdentity: senderIdentity)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Geohash Helpers
|
||||
|
||||
extension NostrTransport {
|
||||
|
||||
// MARK: Geohash ACK helpers
|
||||
func sendDeliveryAckGeohash(for messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) {
|
||||
Task { @MainActor in
|
||||
SecureLogger.debug("GeoDM: send DELIVERED mid=\(messageID.prefix(8))…", category: .session)
|
||||
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .delivered, messageID: messageID, senderPeerID: senderPeerID) else { return }
|
||||
sendWrappedMessage(content: embedded, recipientHex: recipientHex, senderIdentity: identity, registerPending: true)
|
||||
}
|
||||
}
|
||||
|
||||
func sendReadReceiptGeohash(_ messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) {
|
||||
Task { @MainActor in
|
||||
SecureLogger.debug("GeoDM: send READ mid=\(messageID.prefix(8))…", category: .session)
|
||||
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .readReceipt, messageID: messageID, senderPeerID: senderPeerID) else { return }
|
||||
sendWrappedMessage(content: embedded, recipientHex: recipientHex, senderIdentity: identity, registerPending: true)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: Geohash DMs (per-geohash identity)
|
||||
func sendPrivateMessageGeohash(content: String, toRecipientHex recipientHex: String, from identity: NostrIdentity, messageID: String) {
|
||||
Task { @MainActor in
|
||||
guard !recipientHex.isEmpty else { return }
|
||||
SecureLogger.debug("GeoDM: send PM mid=\(messageID.prefix(8))…", category: .session)
|
||||
guard let embedded = NostrEmbeddedBitChat.encodePMForNostrNoRecipient(content: content, messageID: messageID, senderPeerID: senderPeerID) else {
|
||||
SecureLogger.error("NostrTransport: failed to embed geohash PM packet", category: .session)
|
||||
return
|
||||
}
|
||||
sendWrappedMessage(content: embedded, recipientHex: recipientHex, senderIdentity: identity, registerPending: true)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Helpers
|
||||
|
||||
extension NostrTransport {
|
||||
/// Converts npub bech32 string to hex pubkey
|
||||
@MainActor
|
||||
private func npubToHex(_ npub: String) -> String? {
|
||||
do {
|
||||
let (hrp, data) = try Bech32.decode(npub)
|
||||
guard hrp == "npub" else { return nil }
|
||||
return data.hexEncodedString()
|
||||
} catch {
|
||||
SecureLogger.error("NostrTransport: failed to decode npub -> hex: \(error)", category: .session)
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
/// Creates and sends a gift-wrapped private message event
|
||||
@MainActor
|
||||
private func sendWrappedMessage(content: String, recipientHex: String, senderIdentity: NostrIdentity, registerPending: Bool = false) {
|
||||
guard let event = try? NostrProtocol.createPrivateMessage(content: content, recipientPubkey: recipientHex, senderIdentity: senderIdentity) else {
|
||||
SecureLogger.error("NostrTransport: failed to build Nostr event", category: .session)
|
||||
return
|
||||
}
|
||||
if registerPending {
|
||||
dependencies.registerPendingGiftWrap(event.id)
|
||||
}
|
||||
dependencies.sendEvent(event)
|
||||
}
|
||||
|
||||
/// Must be called within a barrier on `queue`
|
||||
private func processReadQueueIfNeeded() {
|
||||
guard !isSendingReadAcks else { return }
|
||||
guard !readQueue.isEmpty else { return }
|
||||
isSendingReadAcks = true
|
||||
let item = readQueue.removeFirst()
|
||||
sendReadAckItem(item)
|
||||
}
|
||||
|
||||
/// Sends a single read ack item (called after extraction from queue within barrier)
|
||||
private func sendReadAckItem(_ item: QueuedRead) {
|
||||
Task { @MainActor in
|
||||
defer { scheduleNextReadAck() }
|
||||
guard let recipientNpub = resolveRecipientNpub(for: item.peerID),
|
||||
let recipientHex = npubToHex(recipientNpub),
|
||||
let senderIdentity = try? dependencies.currentIdentity() else { return }
|
||||
SecureLogger.debug("NostrTransport: preparing READ ack id=\(item.receipt.originalMessageID.prefix(8))…", category: .session)
|
||||
guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .readReceipt, messageID: item.receipt.originalMessageID, recipientPeerID: item.peerID, senderPeerID: senderPeerID) else {
|
||||
SecureLogger.error("NostrTransport: failed to embed READ ack", category: .session)
|
||||
return
|
||||
}
|
||||
sendWrappedMessage(content: ack, recipientHex: recipientHex, senderIdentity: senderIdentity)
|
||||
}
|
||||
}
|
||||
|
||||
private func scheduleNextReadAck() {
|
||||
dependencies.scheduleAfter(readAckInterval) { [weak self] in
|
||||
self?.queue.async(flags: .barrier) { [weak self] in
|
||||
self?.isSendingReadAcks = false
|
||||
self?.processReadQueueIfNeeded()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@MainActor
|
||||
private func resolveRecipientNpub(for peerID: PeerID) -> String? {
|
||||
if let noiseKey = Data(hexString: peerID.id),
|
||||
let fav = dependencies.favoriteStatusForNoiseKey(noiseKey),
|
||||
let npub = fav.peerNostrPublicKey {
|
||||
return npub
|
||||
}
|
||||
if peerID.id.count == 16,
|
||||
let fav = dependencies.favoriteStatusForPeerID(peerID),
|
||||
let npub = fav.peerNostrPublicKey {
|
||||
return npub
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
@@ -6,6 +6,7 @@
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import UserNotifications
|
||||
#if os(iOS)
|
||||
@@ -14,13 +15,103 @@ import UIKit
|
||||
import AppKit
|
||||
#endif
|
||||
|
||||
class NotificationService {
|
||||
protocol NotificationAuthorizing {
|
||||
func requestAuthorization(
|
||||
options: UNAuthorizationOptions,
|
||||
completionHandler: @escaping (Bool, Error?) -> Void
|
||||
)
|
||||
}
|
||||
|
||||
protocol NotificationRequestDelivering {
|
||||
func add(_ request: UNNotificationRequest)
|
||||
}
|
||||
|
||||
private final class NotificationCenterAuthorizerAdapter: NotificationAuthorizing {
|
||||
private let center: UNUserNotificationCenter
|
||||
|
||||
init(center: UNUserNotificationCenter) {
|
||||
self.center = center
|
||||
}
|
||||
|
||||
func requestAuthorization(
|
||||
options: UNAuthorizationOptions,
|
||||
completionHandler: @escaping (Bool, Error?) -> Void
|
||||
) {
|
||||
center.requestAuthorization(options: options, completionHandler: completionHandler)
|
||||
}
|
||||
}
|
||||
|
||||
private final class NotificationCenterRequestDelivererAdapter: NotificationRequestDelivering {
|
||||
private let center: UNUserNotificationCenter
|
||||
|
||||
init(center: UNUserNotificationCenter) {
|
||||
self.center = center
|
||||
}
|
||||
|
||||
func add(_ request: UNNotificationRequest) {
|
||||
Task {
|
||||
try? await center.add(request)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private struct NoopNotificationAuthorizer: NotificationAuthorizing {
|
||||
func requestAuthorization(
|
||||
options: UNAuthorizationOptions,
|
||||
completionHandler: @escaping (Bool, Error?) -> Void
|
||||
) {
|
||||
completionHandler(false, nil)
|
||||
}
|
||||
}
|
||||
|
||||
private struct NoopNotificationRequestDeliverer: NotificationRequestDelivering {
|
||||
func add(_ request: UNNotificationRequest) {}
|
||||
}
|
||||
|
||||
final class NotificationService {
|
||||
static let shared = NotificationService()
|
||||
|
||||
private init() {}
|
||||
private let isRunningTestsProvider: () -> Bool
|
||||
private let authorizer: NotificationAuthorizing
|
||||
private let requestDeliverer: NotificationRequestDelivering
|
||||
|
||||
/// Returns true if running in test environment (XCTest, Swift Testing, or CI)
|
||||
private var isRunningTests: Bool {
|
||||
isRunningTestsProvider()
|
||||
}
|
||||
|
||||
private init() {
|
||||
self.isRunningTestsProvider = {
|
||||
let env = ProcessInfo.processInfo.environment
|
||||
return NSClassFromString("XCTestCase") != nil ||
|
||||
env["XCTestConfigurationFilePath"] != nil ||
|
||||
env["XCTestBundlePath"] != nil ||
|
||||
env["GITHUB_ACTIONS"] != nil ||
|
||||
env["CI"] != nil
|
||||
}
|
||||
if isRunningTestsProvider() {
|
||||
self.authorizer = NoopNotificationAuthorizer()
|
||||
self.requestDeliverer = NoopNotificationRequestDeliverer()
|
||||
} else {
|
||||
let center = UNUserNotificationCenter.current()
|
||||
self.authorizer = NotificationCenterAuthorizerAdapter(center: center)
|
||||
self.requestDeliverer = NotificationCenterRequestDelivererAdapter(center: center)
|
||||
}
|
||||
}
|
||||
|
||||
internal init(
|
||||
isRunningTestsProvider: @escaping () -> Bool,
|
||||
authorizer: NotificationAuthorizing,
|
||||
requestDeliverer: NotificationRequestDelivering
|
||||
) {
|
||||
self.isRunningTestsProvider = isRunningTestsProvider
|
||||
self.authorizer = authorizer
|
||||
self.requestDeliverer = requestDeliverer
|
||||
}
|
||||
|
||||
func requestAuthorization() {
|
||||
UNUserNotificationCenter.current().requestAuthorization(options: [.alert, .sound, .badge]) { granted, error in
|
||||
guard !isRunningTests else { return }
|
||||
authorizer.requestAuthorization(options: [.alert, .sound, .badge]) { granted, error in
|
||||
if granted {
|
||||
// Permission granted
|
||||
} else {
|
||||
@@ -29,90 +120,70 @@ class NotificationService {
|
||||
}
|
||||
}
|
||||
|
||||
func sendLocalNotification(title: String, body: String, identifier: String, userInfo: [String: Any]? = nil) {
|
||||
// For now, skip app state check entirely to avoid thread issues
|
||||
// The NotificationDelegate will handle foreground presentation
|
||||
DispatchQueue.main.async {
|
||||
let content = UNMutableNotificationContent()
|
||||
content.title = title
|
||||
content.body = body
|
||||
content.sound = .default
|
||||
if let userInfo = userInfo {
|
||||
content.userInfo = userInfo
|
||||
}
|
||||
func sendLocalNotification(
|
||||
title: String,
|
||||
body: String,
|
||||
identifier: String,
|
||||
userInfo: [String: Any]? = nil,
|
||||
interruptionLevel: UNNotificationInterruptionLevel = .active
|
||||
) {
|
||||
guard !isRunningTests else { return }
|
||||
let content = UNMutableNotificationContent()
|
||||
content.title = title
|
||||
content.body = body
|
||||
content.sound = .default
|
||||
content.interruptionLevel = interruptionLevel
|
||||
|
||||
let request = UNNotificationRequest(
|
||||
identifier: identifier,
|
||||
content: content,
|
||||
trigger: nil // Deliver immediately
|
||||
)
|
||||
|
||||
UNUserNotificationCenter.current().add(request) { _ in
|
||||
// Notification added
|
||||
}
|
||||
if let userInfo = userInfo {
|
||||
content.userInfo = userInfo
|
||||
}
|
||||
|
||||
let request = UNNotificationRequest(
|
||||
identifier: identifier,
|
||||
content: content,
|
||||
trigger: nil // Deliver immediately
|
||||
)
|
||||
|
||||
requestDeliverer.add(request)
|
||||
}
|
||||
|
||||
func sendMentionNotification(from sender: String, message: String) {
|
||||
let title = "@🫵 you were mentioned by \(sender)"
|
||||
let title = "🫵 you were mentioned by \(sender)"
|
||||
let body = message
|
||||
let identifier = "mention-\(UUID().uuidString)"
|
||||
|
||||
sendLocalNotification(title: title, body: body, identifier: identifier)
|
||||
}
|
||||
|
||||
func sendPrivateMessageNotification(from sender: String, message: String, peerID: String) {
|
||||
let title = "🔒 private message from \(sender)"
|
||||
func sendPrivateMessageNotification(from sender: String, message: String, peerID: PeerID) {
|
||||
let title = "🔒 DM from \(sender)"
|
||||
let body = message
|
||||
let identifier = "private-\(UUID().uuidString)"
|
||||
let userInfo = ["peerID": peerID, "senderName": sender]
|
||||
let userInfo = ["peerID": peerID.id, "senderName": sender]
|
||||
|
||||
sendLocalNotification(title: title, body: body, identifier: identifier, userInfo: userInfo)
|
||||
}
|
||||
|
||||
func sendFavoriteOnlineNotification(nickname: String) {
|
||||
// Send directly without checking app state for favorites
|
||||
DispatchQueue.main.async {
|
||||
let content = UNMutableNotificationContent()
|
||||
content.title = "⭐ \(nickname) is online!"
|
||||
content.body = "wanna get in there?"
|
||||
content.sound = .default
|
||||
|
||||
let request = UNNotificationRequest(
|
||||
identifier: "favorite-online-\(UUID().uuidString)",
|
||||
content: content,
|
||||
trigger: nil
|
||||
)
|
||||
|
||||
UNUserNotificationCenter.current().add(request) { _ in
|
||||
// Notification added
|
||||
}
|
||||
}
|
||||
// Geohash public chat notification with deep link to a specific geohash
|
||||
func sendGeohashActivityNotification(geohash: String, titlePrefix: String = "#", bodyPreview: String) {
|
||||
let title = "\(titlePrefix)\(geohash)"
|
||||
let identifier = "geo-activity-\(geohash)-\(Date().timeIntervalSince1970)"
|
||||
let deeplink = "bitchat://geohash/\(geohash)"
|
||||
let userInfo: [String: Any] = ["deeplink": deeplink]
|
||||
sendLocalNotification(title: title, body: bodyPreview, identifier: identifier, userInfo: userInfo)
|
||||
}
|
||||
|
||||
func sendNetworkAvailableNotification(peerCount: Int) {
|
||||
let title = "👥 bitchatters nearby!"
|
||||
let body = peerCount == 1 ? "1 person around" : "\(peerCount) people around"
|
||||
let identifier = "network-available-\(Date().timeIntervalSince1970)"
|
||||
// Fixed identifier so iOS updates the existing notification instead of creating new ones
|
||||
let identifier = "network-available"
|
||||
|
||||
// For network notifications, we want to show them even in foreground
|
||||
// No app state check - let the notification delegate handle presentation
|
||||
DispatchQueue.main.async {
|
||||
let content = UNMutableNotificationContent()
|
||||
content.title = title
|
||||
content.body = body
|
||||
content.sound = .default
|
||||
content.interruptionLevel = .timeSensitive // Make it more prominent
|
||||
|
||||
let request = UNNotificationRequest(
|
||||
identifier: identifier,
|
||||
content: content,
|
||||
trigger: nil // Deliver immediately
|
||||
)
|
||||
|
||||
UNUserNotificationCenter.current().add(request) { _ in
|
||||
// Notification added
|
||||
}
|
||||
}
|
||||
sendLocalNotification(
|
||||
title: title,
|
||||
body: body,
|
||||
identifier: identifier,
|
||||
interruptionLevel: .timeSensitive
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,143 @@
|
||||
//
|
||||
// NotificationStreamAssembler.swift
|
||||
// bitchat
|
||||
//
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
// For more information, see <https://unlicense.org>
|
||||
//
|
||||
|
||||
import BitLogger
|
||||
import Foundation
|
||||
|
||||
struct NotificationStreamAssembler {
|
||||
private var buffer = Data()
|
||||
private var pendingFrameStartedAt: DispatchTime?
|
||||
private var pendingFrameExpectedLength: Int = 0
|
||||
|
||||
private mutating func resetState() {
|
||||
buffer.removeAll(keepingCapacity: false)
|
||||
pendingFrameStartedAt = nil
|
||||
pendingFrameExpectedLength = 0
|
||||
}
|
||||
|
||||
mutating func append(_ chunk: Data) -> (frames: [Data], droppedPrefixes: [UInt8], reset: Bool) {
|
||||
guard !chunk.isEmpty else { return ([], [], false) }
|
||||
|
||||
buffer.append(chunk)
|
||||
|
||||
var frames: [Data] = []
|
||||
var dropped: [UInt8] = []
|
||||
var didReset = false
|
||||
let now = DispatchTime.now()
|
||||
let maxFrameLength = TransportConfig.bleNotificationAssemblerHardCapBytes
|
||||
let minimumFramePrefix = BinaryProtocol.v1HeaderSize + BinaryProtocol.senderIDSize
|
||||
|
||||
if buffer.count > TransportConfig.bleNotificationAssemblerHardCapBytes {
|
||||
SecureLogger.error("❌ Notification assembler overflow (\(buffer.count) bytes); dropping partial frame", category: .session)
|
||||
resetState()
|
||||
return ([], [], true)
|
||||
}
|
||||
|
||||
while buffer.count >= minimumFramePrefix {
|
||||
guard let version = buffer.first else { break }
|
||||
guard version == 1 || version == 2 else {
|
||||
dropped.append(buffer.removeFirst())
|
||||
pendingFrameStartedAt = nil
|
||||
pendingFrameExpectedLength = 0
|
||||
continue
|
||||
}
|
||||
|
||||
guard let headerSize = BinaryProtocol.headerSize(for: version) else {
|
||||
dropped.append(buffer.removeFirst())
|
||||
pendingFrameStartedAt = nil
|
||||
pendingFrameExpectedLength = 0
|
||||
continue
|
||||
}
|
||||
let framePrefix = headerSize + BinaryProtocol.senderIDSize
|
||||
guard buffer.count >= framePrefix else { break }
|
||||
|
||||
let flagsIndex = buffer.startIndex + BinaryProtocol.Offsets.flags
|
||||
guard flagsIndex < buffer.endIndex else { break }
|
||||
let flags = buffer[flagsIndex]
|
||||
let hasRecipient = (flags & BinaryProtocol.Flags.hasRecipient) != 0
|
||||
let hasSignature = (flags & BinaryProtocol.Flags.hasSignature) != 0
|
||||
let isCompressed = (flags & BinaryProtocol.Flags.isCompressed) != 0
|
||||
let hasRoute = (version >= 2) && (flags & BinaryProtocol.Flags.hasRoute) != 0
|
||||
|
||||
let lengthOffset = 12
|
||||
let payloadLength: Int
|
||||
if version == 2 {
|
||||
let lengthIndex = buffer.startIndex + lengthOffset
|
||||
payloadLength =
|
||||
(Int(buffer[lengthIndex]) << 24) |
|
||||
(Int(buffer[lengthIndex + 1]) << 16) |
|
||||
(Int(buffer[lengthIndex + 2]) << 8) |
|
||||
Int(buffer[lengthIndex + 3])
|
||||
} else {
|
||||
let lengthIndex = buffer.startIndex + lengthOffset
|
||||
payloadLength = (Int(buffer[lengthIndex]) << 8) | Int(buffer[lengthIndex + 1])
|
||||
}
|
||||
|
||||
var frameLength = framePrefix + payloadLength
|
||||
if hasRecipient { frameLength += BinaryProtocol.recipientIDSize }
|
||||
if hasSignature { frameLength += BinaryProtocol.signatureSize }
|
||||
|
||||
if hasRoute {
|
||||
let routeCountOffset = framePrefix + (hasRecipient ? BinaryProtocol.recipientIDSize : 0)
|
||||
let routeCountIndex = buffer.startIndex + routeCountOffset
|
||||
guard buffer.count > routeCountOffset else { break }
|
||||
let routeCount = Int(buffer[routeCountIndex])
|
||||
frameLength += 1 + (routeCount * BinaryProtocol.senderIDSize)
|
||||
}
|
||||
|
||||
if isCompressed {
|
||||
let rawLengthFieldBytes = (version == 2) ? 4 : 2
|
||||
if payloadLength < rawLengthFieldBytes {
|
||||
SecureLogger.error("❌ Invalid compressed payload length (\(payloadLength))", category: .session)
|
||||
resetState()
|
||||
didReset = true
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
guard frameLength > 0, frameLength <= maxFrameLength else {
|
||||
SecureLogger.error("❌ Notification frame length \(frameLength) invalid (cap=\(maxFrameLength)); resetting stream", category: .session)
|
||||
resetState()
|
||||
didReset = true
|
||||
break
|
||||
}
|
||||
|
||||
if buffer.count < frameLength {
|
||||
let remaining = frameLength - buffer.count
|
||||
if pendingFrameStartedAt == nil || frameLength != pendingFrameExpectedLength {
|
||||
pendingFrameStartedAt = now
|
||||
pendingFrameExpectedLength = frameLength
|
||||
} else if let started = pendingFrameStartedAt {
|
||||
let elapsed = now.uptimeNanoseconds - started.uptimeNanoseconds
|
||||
let threshold = UInt64(TransportConfig.bleAssemblerStallResetMs) * 1_000_000
|
||||
if elapsed >= threshold {
|
||||
SecureLogger.debug("📉 Resetting notification assembler after waiting \(remaining)B for \(TransportConfig.bleAssemblerStallResetMs)ms", category: .session)
|
||||
resetState()
|
||||
didReset = true
|
||||
} else {
|
||||
SecureLogger.debug("⌛ Waiting for remaining \(remaining)B to complete BLE frame", category: .session)
|
||||
}
|
||||
}
|
||||
break
|
||||
}
|
||||
|
||||
pendingFrameStartedAt = nil
|
||||
pendingFrameExpectedLength = 0
|
||||
|
||||
let frame = Data(buffer.prefix(frameLength))
|
||||
frames.append(frame)
|
||||
buffer.removeFirst(frameLength)
|
||||
}
|
||||
|
||||
if !buffer.isEmpty, buffer.allSatisfy({ $0 == 0 }) {
|
||||
resetState()
|
||||
}
|
||||
|
||||
return (frames, dropped, didReset)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,278 @@
|
||||
//
|
||||
// PrivateChatManager.swift
|
||||
// bitchat
|
||||
//
|
||||
// Manages private chat sessions and messages
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import SwiftUI
|
||||
|
||||
/// Manages all private chat functionality
|
||||
final class PrivateChatManager: ObservableObject {
|
||||
@Published var privateChats: [PeerID: [BitchatMessage]] = [:]
|
||||
@Published var selectedPeer: PeerID? = nil
|
||||
@Published var unreadMessages: Set<PeerID> = []
|
||||
|
||||
private var selectedPeerFingerprint: String? = nil
|
||||
var sentReadReceipts: Set<String> = [] // Made accessible for ChatViewModel
|
||||
|
||||
weak var meshService: Transport?
|
||||
// Route acks/receipts via MessageRouter (chooses mesh or Nostr)
|
||||
weak var messageRouter: MessageRouter?
|
||||
// Peer service for looking up peer info during consolidation
|
||||
weak var unifiedPeerService: UnifiedPeerService?
|
||||
|
||||
init(meshService: Transport? = nil) {
|
||||
self.meshService = meshService
|
||||
}
|
||||
|
||||
// Cap for messages stored per private chat
|
||||
private let privateChatCap = TransportConfig.privateChatCap
|
||||
|
||||
// MARK: - Message Consolidation
|
||||
|
||||
/// Consolidates messages from different peer ID representations into a single chat.
|
||||
/// This ensures messages from stable Noise keys and temporary Nostr peer IDs are merged.
|
||||
/// - Parameters:
|
||||
/// - peerID: The target peer ID to consolidate messages into
|
||||
/// - peerNickname: The peer's display name (lowercased for matching)
|
||||
/// - persistedReadReceipts: The persisted read receipts set from ChatViewModel (UserDefaults-backed)
|
||||
/// - Returns: True if any unread messages were found during consolidation
|
||||
@MainActor
|
||||
func consolidateMessages(for peerID: PeerID, peerNickname: String, persistedReadReceipts: Set<String>) -> Bool {
|
||||
guard let meshService = meshService else { return false }
|
||||
var hasUnreadMessages = false
|
||||
|
||||
// 1. Consolidate from stable Noise key (64-char hex)
|
||||
if let peer = unifiedPeerService?.getPeer(by: peerID) {
|
||||
let noiseKeyHex = PeerID(hexData: peer.noisePublicKey)
|
||||
|
||||
if noiseKeyHex != peerID, let nostrMessages = privateChats[noiseKeyHex], !nostrMessages.isEmpty {
|
||||
if privateChats[peerID] == nil {
|
||||
privateChats[peerID] = []
|
||||
}
|
||||
|
||||
let existingMessageIds = Set(privateChats[peerID]?.map { $0.id } ?? [])
|
||||
for message in nostrMessages {
|
||||
if !existingMessageIds.contains(message.id) {
|
||||
// Update senderPeerID for correct read receipts
|
||||
let updatedMessage = BitchatMessage(
|
||||
id: message.id,
|
||||
sender: message.sender,
|
||||
content: message.content,
|
||||
timestamp: message.timestamp,
|
||||
isRelay: message.isRelay,
|
||||
originalSender: message.originalSender,
|
||||
isPrivate: message.isPrivate,
|
||||
recipientNickname: message.recipientNickname,
|
||||
senderPeerID: message.senderPeerID == meshService.myPeerID ? meshService.myPeerID : peerID,
|
||||
mentions: message.mentions,
|
||||
deliveryStatus: message.deliveryStatus
|
||||
)
|
||||
privateChats[peerID]?.append(updatedMessage)
|
||||
|
||||
// Check for recent unread messages (< 60s, not sent by us, not already read)
|
||||
// Use persistedReadReceipts to correctly identify already-read messages after app restart
|
||||
if message.senderPeerID != meshService.myPeerID {
|
||||
let messageAge = Date().timeIntervalSince(message.timestamp)
|
||||
if messageAge < 60 && !persistedReadReceipts.contains(message.id) {
|
||||
hasUnreadMessages = true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
privateChats[peerID]?.sort { $0.timestamp < $1.timestamp }
|
||||
|
||||
if hasUnreadMessages {
|
||||
unreadMessages.insert(peerID)
|
||||
} else if unreadMessages.contains(noiseKeyHex) {
|
||||
unreadMessages.remove(noiseKeyHex)
|
||||
}
|
||||
|
||||
privateChats.removeValue(forKey: noiseKeyHex)
|
||||
}
|
||||
}
|
||||
|
||||
// 2. Consolidate from temporary Nostr peer IDs (nostr_* prefixed)
|
||||
let normalizedNickname = peerNickname.lowercased()
|
||||
var tempPeerIDsToConsolidate: [PeerID] = []
|
||||
|
||||
for (storedPeerID, messages) in privateChats {
|
||||
if storedPeerID.isGeoDM && storedPeerID != peerID {
|
||||
let nicknamesMatch = messages.allSatisfy { $0.sender.lowercased() == normalizedNickname }
|
||||
if nicknamesMatch && !messages.isEmpty {
|
||||
tempPeerIDsToConsolidate.append(storedPeerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if !tempPeerIDsToConsolidate.isEmpty {
|
||||
if privateChats[peerID] == nil {
|
||||
privateChats[peerID] = []
|
||||
}
|
||||
|
||||
let existingMessageIds = Set(privateChats[peerID]?.map { $0.id } ?? [])
|
||||
var consolidatedCount = 0
|
||||
var hadUnreadTemp = false
|
||||
|
||||
for tempPeerID in tempPeerIDsToConsolidate {
|
||||
if unreadMessages.contains(tempPeerID) {
|
||||
hadUnreadTemp = true
|
||||
}
|
||||
|
||||
if let tempMessages = privateChats[tempPeerID] {
|
||||
for message in tempMessages {
|
||||
if !existingMessageIds.contains(message.id) {
|
||||
let updatedMessage = BitchatMessage(
|
||||
id: message.id,
|
||||
sender: message.sender,
|
||||
content: message.content,
|
||||
timestamp: message.timestamp,
|
||||
isRelay: message.isRelay,
|
||||
originalSender: message.originalSender,
|
||||
isPrivate: message.isPrivate,
|
||||
recipientNickname: message.recipientNickname,
|
||||
senderPeerID: peerID,
|
||||
mentions: message.mentions,
|
||||
deliveryStatus: message.deliveryStatus
|
||||
)
|
||||
privateChats[peerID]?.append(updatedMessage)
|
||||
consolidatedCount += 1
|
||||
}
|
||||
}
|
||||
privateChats.removeValue(forKey: tempPeerID)
|
||||
unreadMessages.remove(tempPeerID)
|
||||
}
|
||||
}
|
||||
|
||||
if hadUnreadTemp {
|
||||
unreadMessages.insert(peerID)
|
||||
hasUnreadMessages = true
|
||||
SecureLogger.debug("📬 Transferred unread status from temp peer IDs to \(peerID)", category: .session)
|
||||
}
|
||||
|
||||
if consolidatedCount > 0 {
|
||||
privateChats[peerID]?.sort { $0.timestamp < $1.timestamp }
|
||||
SecureLogger.info("📥 Consolidated \(consolidatedCount) Nostr messages from temporary peer IDs to \(peerNickname)", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
return hasUnreadMessages
|
||||
}
|
||||
|
||||
/// Syncs the read receipt tracking between manager and view model for sent messages
|
||||
@MainActor
|
||||
func syncReadReceiptsForSentMessages(peerID: PeerID, nickname: String, externalReceipts: inout Set<String>) {
|
||||
guard let messages = privateChats[peerID] else { return }
|
||||
|
||||
for message in messages {
|
||||
if message.sender == nickname {
|
||||
if let status = message.deliveryStatus {
|
||||
switch status {
|
||||
case .read, .delivered:
|
||||
externalReceipts.insert(message.id)
|
||||
sentReadReceipts.insert(message.id)
|
||||
case .failed, .partiallyDelivered, .sending, .sent:
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Start a private chat with a peer
|
||||
func startChat(with peerID: PeerID) {
|
||||
selectedPeer = peerID
|
||||
|
||||
// Store fingerprint for persistence across reconnections
|
||||
if let fingerprint = meshService?.getFingerprint(for: peerID) {
|
||||
selectedPeerFingerprint = fingerprint
|
||||
}
|
||||
|
||||
// Mark messages as read
|
||||
markAsRead(from: peerID)
|
||||
|
||||
// Initialize chat if needed
|
||||
if privateChats[peerID] == nil {
|
||||
privateChats[peerID] = []
|
||||
}
|
||||
}
|
||||
|
||||
/// End the current private chat
|
||||
func endChat() {
|
||||
selectedPeer = nil
|
||||
selectedPeerFingerprint = nil
|
||||
}
|
||||
|
||||
/// Remove duplicate messages by ID and keep chronological order
|
||||
func sanitizeChat(for peerID: PeerID) {
|
||||
guard let arr = privateChats[peerID] else { return }
|
||||
if arr.count <= 1 {
|
||||
return
|
||||
}
|
||||
|
||||
var indexByID: [String: Int] = [:]
|
||||
indexByID.reserveCapacity(arr.count)
|
||||
var deduped: [BitchatMessage] = []
|
||||
deduped.reserveCapacity(arr.count)
|
||||
|
||||
for msg in arr.sorted(by: { $0.timestamp < $1.timestamp }) {
|
||||
if let existing = indexByID[msg.id] {
|
||||
deduped[existing] = msg
|
||||
} else {
|
||||
indexByID[msg.id] = deduped.count
|
||||
deduped.append(msg)
|
||||
}
|
||||
}
|
||||
|
||||
privateChats[peerID] = deduped
|
||||
}
|
||||
|
||||
/// Mark messages from a peer as read
|
||||
func markAsRead(from peerID: PeerID) {
|
||||
unreadMessages.remove(peerID)
|
||||
|
||||
// Send read receipts for unread messages that haven't been sent yet
|
||||
if let messages = privateChats[peerID] {
|
||||
for message in messages {
|
||||
if message.senderPeerID == peerID && !message.isRelay && !sentReadReceipts.contains(message.id) {
|
||||
sendReadReceipt(for: message)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func sendReadReceipt(for message: BitchatMessage) {
|
||||
guard !sentReadReceipts.contains(message.id),
|
||||
let senderPeerID = message.senderPeerID else {
|
||||
return
|
||||
}
|
||||
|
||||
sentReadReceipts.insert(message.id)
|
||||
|
||||
// Create read receipt using the simplified method
|
||||
let receipt = ReadReceipt(
|
||||
originalMessageID: message.id,
|
||||
readerID: meshService?.myPeerID ?? PeerID(str: ""),
|
||||
readerNickname: meshService?.myNickname ?? ""
|
||||
)
|
||||
|
||||
// Route via MessageRouter to avoid handshakeRequired spam when session isn't established
|
||||
if let router = messageRouter {
|
||||
SecureLogger.debug("PrivateChatManager: sending READ ack for \(message.id.prefix(8))… to \(senderPeerID.id.prefix(8))… via router", category: .session)
|
||||
Task { @MainActor in
|
||||
router.sendReadReceipt(receipt, to: senderPeerID)
|
||||
}
|
||||
} else {
|
||||
// Fallback: preserve previous behavior
|
||||
meshService?.sendReadReceipt(receipt, to: senderPeerID)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,108 +0,0 @@
|
||||
import Foundation
|
||||
|
||||
/// Service to track processed messages across app restarts to prevent duplicates
|
||||
@MainActor
|
||||
final class ProcessedMessagesService {
|
||||
static let shared = ProcessedMessagesService()
|
||||
|
||||
private let userDefaults = UserDefaults.standard
|
||||
private let processedMessagesKey = "ProcessedNostrMessages"
|
||||
private let lastProcessedTimestampKey = "LastProcessedNostrTimestamp"
|
||||
private let maxStoredMessages = 1000 // Keep last 1000 message IDs
|
||||
|
||||
private var processedMessageIDs: Set<String> = []
|
||||
private var lastProcessedTimestamp: Date?
|
||||
|
||||
private init() {
|
||||
loadProcessedMessages()
|
||||
}
|
||||
|
||||
/// Check if a message has already been processed
|
||||
func isMessageProcessed(_ messageID: String) -> Bool {
|
||||
return processedMessageIDs.contains(messageID)
|
||||
}
|
||||
|
||||
/// Mark a message as processed
|
||||
func markMessageAsProcessed(_ messageID: String, timestamp: Date) {
|
||||
processedMessageIDs.insert(messageID)
|
||||
|
||||
// Update last processed timestamp if this message is newer
|
||||
if let lastTimestamp = lastProcessedTimestamp {
|
||||
if timestamp > lastTimestamp {
|
||||
lastProcessedTimestamp = timestamp
|
||||
}
|
||||
} else {
|
||||
lastProcessedTimestamp = timestamp
|
||||
}
|
||||
|
||||
// Trim if we have too many stored IDs
|
||||
if processedMessageIDs.count > maxStoredMessages {
|
||||
trimOldestMessages()
|
||||
}
|
||||
|
||||
saveProcessedMessages()
|
||||
}
|
||||
|
||||
/// Get the timestamp to use for Nostr subscription filters
|
||||
func getSubscriptionSinceDate() -> Date {
|
||||
// If we have a last processed timestamp, use it minus a small buffer
|
||||
if let lastTimestamp = lastProcessedTimestamp {
|
||||
// Go back 1 hour before last processed message for safety
|
||||
return lastTimestamp.addingTimeInterval(-3600)
|
||||
}
|
||||
|
||||
// Default: look back 24 hours on first run
|
||||
return Date().addingTimeInterval(-86400)
|
||||
}
|
||||
|
||||
/// Clear all processed messages (useful for debugging)
|
||||
func clearProcessedMessages() {
|
||||
processedMessageIDs.removeAll()
|
||||
lastProcessedTimestamp = nil
|
||||
saveProcessedMessages()
|
||||
}
|
||||
|
||||
// MARK: - Private Methods
|
||||
|
||||
private func loadProcessedMessages() {
|
||||
if let data = userDefaults.data(forKey: processedMessagesKey),
|
||||
let decoded = try? JSONDecoder().decode([String].self, from: data) {
|
||||
processedMessageIDs = Set(decoded)
|
||||
}
|
||||
|
||||
if let timestampInterval = userDefaults.object(forKey: lastProcessedTimestampKey) as? TimeInterval {
|
||||
lastProcessedTimestamp = Date(timeIntervalSince1970: timestampInterval)
|
||||
}
|
||||
|
||||
SecureLogger.log("📋 Loaded \(processedMessageIDs.count) processed message IDs, last timestamp: \(lastProcessedTimestamp?.description ?? "nil")",
|
||||
category: SecureLogger.session, level: .info)
|
||||
}
|
||||
|
||||
private func saveProcessedMessages() {
|
||||
// Convert Set to Array for encoding
|
||||
let messageArray = Array(processedMessageIDs)
|
||||
if let encoded = try? JSONEncoder().encode(messageArray) {
|
||||
userDefaults.set(encoded, forKey: processedMessagesKey)
|
||||
}
|
||||
|
||||
if let timestamp = lastProcessedTimestamp {
|
||||
userDefaults.set(timestamp.timeIntervalSince1970, forKey: lastProcessedTimestampKey)
|
||||
}
|
||||
|
||||
userDefaults.synchronize()
|
||||
}
|
||||
|
||||
private func trimOldestMessages() {
|
||||
// Since we don't track insertion order, we'll just keep the most recent N messages
|
||||
// In a production app, you might want to track timestamps for each message
|
||||
let excess = processedMessageIDs.count - maxStoredMessages
|
||||
if excess > 0 {
|
||||
// Remove random excess messages (not ideal, but simple)
|
||||
for _ in 0..<excess {
|
||||
if let first = processedMessageIDs.first {
|
||||
processedMessageIDs.remove(first)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,73 @@
|
||||
import Foundation
|
||||
|
||||
// RelayDecision encapsulates a single relay scheduling choice.
|
||||
struct RelayDecision {
|
||||
let shouldRelay: Bool
|
||||
let newTTL: UInt8
|
||||
let delayMs: Int
|
||||
}
|
||||
|
||||
// RelayController centralizes flood control policy for relays.
|
||||
struct RelayController {
|
||||
static func decide(ttl: UInt8,
|
||||
senderIsSelf: Bool,
|
||||
isEncrypted: Bool,
|
||||
isDirectedEncrypted: Bool,
|
||||
isFragment: Bool,
|
||||
isDirectedFragment: Bool,
|
||||
isHandshake: Bool,
|
||||
isAnnounce: Bool,
|
||||
degree: Int,
|
||||
highDegreeThreshold: Int) -> RelayDecision {
|
||||
let ttlCap = min(ttl, TransportConfig.messageTTLDefault)
|
||||
|
||||
// Suppress obvious non-relays
|
||||
if ttlCap <= 1 || senderIsSelf {
|
||||
return RelayDecision(shouldRelay: false, newTTL: ttlCap, delayMs: 0)
|
||||
}
|
||||
|
||||
// For session-critical or directed traffic, be deterministic and reliable
|
||||
if isHandshake || isDirectedFragment || isDirectedEncrypted {
|
||||
// Always relay with no TTL cap for these types
|
||||
let newTTL = ttlCap &- 1
|
||||
// Slight jitter to desynchronize without adding too much latency
|
||||
// Tighter for faster multi-hop handshakes and directed DMs
|
||||
let delayRange: ClosedRange<Int> = isHandshake ? 10...35 : 20...60
|
||||
let delayMs = Int.random(in: delayRange)
|
||||
return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs)
|
||||
}
|
||||
|
||||
if isFragment {
|
||||
let ttlLimit = min(ttlCap, TransportConfig.bleFragmentRelayTtlCap)
|
||||
guard ttlLimit > 1 else {
|
||||
return RelayDecision(shouldRelay: false, newTTL: ttlLimit, delayMs: 0)
|
||||
}
|
||||
let newTTL = ttlLimit &- 1
|
||||
let delayMs = Int.random(in: TransportConfig.bleFragmentRelayMinDelayMs...TransportConfig.bleFragmentRelayMaxDelayMs)
|
||||
return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs)
|
||||
}
|
||||
|
||||
// TTL clamping for broadcast
|
||||
// - Dense graphs: keep lower but still allow multi-hop bridging
|
||||
// - Announces get a bit more headroom
|
||||
let ttlLimit: UInt8 = {
|
||||
if degree >= highDegreeThreshold {
|
||||
return max(UInt8(2), min(ttlCap, UInt8(5)))
|
||||
}
|
||||
let preferred = UInt8(isAnnounce ? 7 : 6)
|
||||
return max(UInt8(2), min(ttlCap, preferred))
|
||||
}()
|
||||
let newTTL = ttlLimit &- 1
|
||||
|
||||
// Wider jitter window to allow duplicate suppression to win more often
|
||||
// For sparse graphs (<=2), relay quickly to avoid cancellation races
|
||||
let delayMs: Int
|
||||
switch degree {
|
||||
case 0...2: delayMs = Int.random(in: 10...40)
|
||||
case 3...5: delayMs = Int.random(in: 60...150)
|
||||
case 6...9: delayMs = Int.random(in: 80...180)
|
||||
default: delayMs = Int.random(in: 100...220)
|
||||
}
|
||||
return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
/// Centralized progress bus for Bluetooth file transfers.
|
||||
/// Emits Combine events consumed by ChatViewModel to update UI progress indicators.
|
||||
final class TransferProgressManager {
|
||||
static let shared = TransferProgressManager()
|
||||
|
||||
enum Event {
|
||||
case started(id: String, totalFragments: Int)
|
||||
case updated(id: String, sentFragments: Int, totalFragments: Int)
|
||||
case completed(id: String, totalFragments: Int)
|
||||
case cancelled(id: String, sentFragments: Int, totalFragments: Int)
|
||||
}
|
||||
|
||||
private let subject = PassthroughSubject<Event, Never>()
|
||||
private let queue = DispatchQueue(label: "com.bitchat.transfer-progress", attributes: .concurrent)
|
||||
private var states: [String: (sent: Int, total: Int)] = [:]
|
||||
|
||||
var publisher: AnyPublisher<Event, Never> {
|
||||
subject.eraseToAnyPublisher()
|
||||
}
|
||||
|
||||
func start(id: String, totalFragments: Int) {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
guard let self = self else { return }
|
||||
self.states[id] = (sent: 0, total: totalFragments)
|
||||
self.subject.send(.started(id: id, totalFragments: totalFragments))
|
||||
}
|
||||
}
|
||||
|
||||
func recordFragmentSent(id: String) {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
guard let self = self, var state = self.states[id] else { return }
|
||||
state.sent = min(state.sent + 1, state.total)
|
||||
self.states[id] = state
|
||||
self.subject.send(.updated(id: id, sentFragments: state.sent, totalFragments: state.total))
|
||||
if state.sent >= state.total {
|
||||
self.states.removeValue(forKey: id)
|
||||
self.subject.send(.completed(id: id, totalFragments: state.total))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func cancel(id: String) {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
guard let self = self, let state = self.states.removeValue(forKey: id) else { return }
|
||||
self.subject.send(.cancelled(id: id, sentFragments: state.sent, totalFragments: state.total))
|
||||
}
|
||||
}
|
||||
|
||||
func reset(id: String) {
|
||||
queue.async(flags: .barrier) { [weak self] in
|
||||
self?.states.removeValue(forKey: id)
|
||||
}
|
||||
}
|
||||
|
||||
func snapshot(id: String) -> (sent: Int, total: Int)? {
|
||||
var result: (sent: Int, total: Int)?
|
||||
queue.sync {
|
||||
result = states[id]
|
||||
}
|
||||
return result
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,87 @@
|
||||
import BitFoundation
|
||||
import Foundation
|
||||
import Combine
|
||||
|
||||
/// Abstract transport interface used by ChatViewModel and services.
|
||||
/// BLEService implements this protocol; a future Nostr transport can too.
|
||||
struct TransportPeerSnapshot: Equatable, Hashable {
|
||||
let peerID: PeerID
|
||||
let nickname: String
|
||||
let isConnected: Bool
|
||||
let noisePublicKey: Data?
|
||||
let lastSeen: Date
|
||||
}
|
||||
|
||||
protocol Transport: AnyObject {
|
||||
// Event sink
|
||||
var delegate: BitchatDelegate? { get set }
|
||||
// Peer events (preferred over publishers for UI)
|
||||
var peerEventsDelegate: TransportPeerEventsDelegate? { get set }
|
||||
|
||||
// Peer snapshots (for non-UI services)
|
||||
var peerSnapshotPublisher: AnyPublisher<[TransportPeerSnapshot], Never> { get }
|
||||
func currentPeerSnapshots() -> [TransportPeerSnapshot]
|
||||
|
||||
// Identity
|
||||
var myPeerID: PeerID { get }
|
||||
var myNickname: String { get }
|
||||
func setNickname(_ nickname: String)
|
||||
|
||||
// Lifecycle
|
||||
func startServices()
|
||||
func stopServices()
|
||||
func emergencyDisconnectAll()
|
||||
|
||||
// Connectivity and peers
|
||||
func isPeerConnected(_ peerID: PeerID) -> Bool
|
||||
func isPeerReachable(_ peerID: PeerID) -> Bool
|
||||
func peerNickname(peerID: PeerID) -> String?
|
||||
func getPeerNicknames() -> [PeerID: String]
|
||||
|
||||
// Protocol utilities
|
||||
func getFingerprint(for peerID: PeerID) -> String?
|
||||
func getNoiseSessionState(for peerID: PeerID) -> LazyHandshakeState
|
||||
func triggerHandshake(with peerID: PeerID)
|
||||
func getNoiseService() -> NoiseEncryptionService
|
||||
|
||||
// Messaging
|
||||
func sendMessage(_ content: String, mentions: [String])
|
||||
func sendMessage(_ content: String, mentions: [String], messageID: String, timestamp: Date)
|
||||
func sendPrivateMessage(_ content: String, to peerID: PeerID, recipientNickname: String, messageID: String)
|
||||
func sendReadReceipt(_ receipt: ReadReceipt, to peerID: PeerID)
|
||||
func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool)
|
||||
func sendBroadcastAnnounce()
|
||||
func sendDeliveryAck(for messageID: String, to peerID: PeerID)
|
||||
func sendFileBroadcast(_ packet: BitchatFilePacket, transferId: String)
|
||||
func sendFilePrivate(_ packet: BitchatFilePacket, to peerID: PeerID, transferId: String)
|
||||
func cancelTransfer(_ transferId: String)
|
||||
|
||||
// QR verification (optional for transports)
|
||||
func sendVerifyChallenge(to peerID: PeerID, noiseKeyHex: String, nonceA: Data)
|
||||
func sendVerifyResponse(to peerID: PeerID, noiseKeyHex: String, nonceA: Data)
|
||||
|
||||
// Pending file management (BCH-01-002: files held in memory until user accepts)
|
||||
func acceptPendingFile(id: String) -> URL?
|
||||
func declinePendingFile(id: String)
|
||||
}
|
||||
|
||||
extension Transport {
|
||||
func sendVerifyChallenge(to peerID: PeerID, noiseKeyHex: String, nonceA: Data) {}
|
||||
func sendVerifyResponse(to peerID: PeerID, noiseKeyHex: String, nonceA: Data) {}
|
||||
func sendFileBroadcast(_ packet: BitchatFilePacket, transferId: String) {}
|
||||
func sendFilePrivate(_ packet: BitchatFilePacket, to peerID: PeerID, transferId: String) {}
|
||||
func cancelTransfer(_ transferId: String) {}
|
||||
|
||||
func sendMessage(_ content: String, mentions: [String], messageID: String, timestamp: Date) {
|
||||
sendMessage(content, mentions: mentions)
|
||||
}
|
||||
|
||||
func acceptPendingFile(id: String) -> URL? { nil }
|
||||
func declinePendingFile(id: String) {}
|
||||
}
|
||||
|
||||
protocol TransportPeerEventsDelegate: AnyObject {
|
||||
@MainActor func didUpdatePeerSnapshots(_ peers: [TransportPeerSnapshot])
|
||||
}
|
||||
|
||||
extension BLEService: Transport {}
|
||||
@@ -0,0 +1,230 @@
|
||||
import Foundation
|
||||
|
||||
/// Centralized knobs for transport- and UI-related limits.
|
||||
/// Keep values aligned with existing behavior when replacing magic numbers.
|
||||
enum TransportConfig {
|
||||
// BLE / Protocol
|
||||
static let bleDefaultFragmentSize: Int = 469 // ~512 MTU minus protocol overhead
|
||||
static let messageTTLDefault: UInt8 = 7 // Default TTL for mesh flooding
|
||||
static let bleMaxInFlightAssemblies: Int = 128 // Cap concurrent fragment assemblies
|
||||
static let bleHighDegreeThreshold: Int = 6 // For adaptive TTL/probabilistic relays
|
||||
static let bleMaxConcurrentTransfers: Int = 2 // Limit simultaneous large media sends
|
||||
static let bleFragmentRelayMinDelayMs: Int = 8 // Faster forwarding for media fragments
|
||||
static let bleFragmentRelayMaxDelayMs: Int = 25 // Upper jitter bound for fragment relays
|
||||
static let bleFragmentRelayTtlCap: UInt8 = 5 // Clamp fragment TTL to contain floods
|
||||
|
||||
// UI / Storage Caps
|
||||
static let privateChatCap: Int = 1337
|
||||
static let meshTimelineCap: Int = 1337
|
||||
static let geoTimelineCap: Int = 1337
|
||||
static let contentLRUCap: Int = 2000
|
||||
|
||||
// Timers
|
||||
static let networkResetGraceSeconds: TimeInterval = 600 // 10 minutes
|
||||
static let networkNotificationCooldownSeconds: TimeInterval = 300 // 5 minutes
|
||||
static let basePublicFlushInterval: TimeInterval = 0.08 // ~12.5 fps batching
|
||||
|
||||
// BLE duty/announce/connect
|
||||
static let bleConnectRateLimitInterval: TimeInterval = 0.5
|
||||
static let bleMaxCentralLinks: Int = 6
|
||||
static let bleDutyOnDuration: TimeInterval = 5.0
|
||||
static let bleDutyOffDuration: TimeInterval = 10.0
|
||||
static let bleAnnounceMinInterval: TimeInterval = 1.0
|
||||
|
||||
// BLE discovery/quality thresholds
|
||||
static let bleDynamicRSSIThresholdDefault: Int = -90
|
||||
static let bleConnectionCandidatesMax: Int = 100
|
||||
static let blePendingWriteBufferCapBytes: Int = 1_000_000
|
||||
static let bleNotificationAssemblerHardCapBytes: Int = 8 * 1024 * 1024
|
||||
static let bleAssemblerStallResetMs: Int = 250
|
||||
static let blePendingNotificationsCapCount: Int = 128
|
||||
static let bleNotificationRetryDelayMs: Int = 25
|
||||
static let bleNotificationRetryMaxAttempts: Int = 80
|
||||
|
||||
// Nostr
|
||||
static let nostrReadAckInterval: TimeInterval = 0.35 // ~3 per second
|
||||
|
||||
// UI thresholds
|
||||
static let uiLateInsertThreshold: TimeInterval = 15.0
|
||||
// Geohash public chats are more sensitive to ordering; use a tighter threshold
|
||||
static let uiLateInsertThresholdGeo: TimeInterval = 0.0
|
||||
static let uiProcessedNostrEventsCap: Int = 2000
|
||||
static let uiChannelInactivityThresholdSeconds: TimeInterval = 9 * 60
|
||||
|
||||
// UI rate limiters (token buckets)
|
||||
static let uiSenderRateBucketCapacity: Double = 5
|
||||
static let uiSenderRateBucketRefillPerSec: Double = 1.0
|
||||
static let uiContentRateBucketCapacity: Double = 3
|
||||
static let uiContentRateBucketRefillPerSec: Double = 0.5
|
||||
|
||||
// UI sleeps/delays
|
||||
static let uiStartupInitialDelaySeconds: TimeInterval = 1.0
|
||||
static let uiStartupShortSleepNs: UInt64 = 200_000_000
|
||||
static let uiStartupPhaseDurationSeconds: TimeInterval = 2.0
|
||||
static let uiAsyncShortSleepNs: UInt64 = 100_000_000
|
||||
static let uiAsyncMediumSleepNs: UInt64 = 500_000_000
|
||||
static let uiReadReceiptRetryShortSeconds: TimeInterval = 0.1
|
||||
static let uiReadReceiptRetryLongSeconds: TimeInterval = 0.5
|
||||
static let uiBatchDispatchStaggerSeconds: TimeInterval = 0.15
|
||||
static let uiScrollThrottleSeconds: TimeInterval = 0.5
|
||||
static let uiAnimationShortSeconds: TimeInterval = 0.15
|
||||
static let uiAnimationMediumSeconds: TimeInterval = 0.2
|
||||
static let uiAnimationSidebarSeconds: TimeInterval = 0.25
|
||||
static let uiRecentCutoffFiveMinutesSeconds: TimeInterval = 5 * 60
|
||||
static let uiMeshEmptyConfirmationSeconds: TimeInterval = 30.0
|
||||
|
||||
// BLE maintenance & thresholds
|
||||
static let bleMaintenanceInterval: TimeInterval = 5.0
|
||||
static let bleMaintenanceLeewaySeconds: Int = 1
|
||||
static let bleIsolationRelaxThresholdSeconds: TimeInterval = 60
|
||||
static let bleRecentTimeoutWindowSeconds: TimeInterval = 60
|
||||
static let bleRecentTimeoutCountThreshold: Int = 3
|
||||
static let bleRSSIIsolatedBase: Int = -90
|
||||
static let bleRSSIIsolatedRelaxed: Int = -92
|
||||
static let bleRSSIConnectedThreshold: Int = -85
|
||||
static let bleRSSIHighTimeoutThreshold: Int = -80
|
||||
// How long without seeing traffic before we sanity-check the direct link
|
||||
// Lowered to make connected→reachable icon changes react faster when walking out of range
|
||||
static let blePeerInactivityTimeoutSeconds: TimeInterval = 8.0
|
||||
// How long to retain a peer as "reachable" (not directly connected) since lastSeen
|
||||
static let bleReachabilityRetentionVerifiedSeconds: TimeInterval = 21.0 // 21s for verified/favorites
|
||||
static let bleReachabilityRetentionUnverifiedSeconds: TimeInterval = 21.0 // 21s for unknown/unverified
|
||||
static let bleFragmentLifetimeSeconds: TimeInterval = 30.0
|
||||
static let bleIngressRecordLifetimeSeconds: TimeInterval = 3.0
|
||||
static let bleConnectTimeoutBackoffWindowSeconds: TimeInterval = 120.0
|
||||
static let bleRecentPacketWindowSeconds: TimeInterval = 30.0
|
||||
static let bleRecentPacketWindowMaxCount: Int = 100
|
||||
// Keep scanning fully ON when we saw traffic very recently
|
||||
static let bleRecentTrafficForceScanSeconds: TimeInterval = 10.0
|
||||
static let bleThreadSleepWriteShortDelaySeconds: TimeInterval = 0.05
|
||||
static let bleExpectedWritePerFragmentMs: Int = 20
|
||||
static let bleExpectedWriteMaxMs: Int = 5000
|
||||
// Fragment pacing: Conservative spacing to prevent BLE buffer overflow
|
||||
// Aggressive pacing causes packet loss; needs 25-30ms between fragments for reliable delivery
|
||||
static let bleFragmentSpacingMs: Int = 30
|
||||
static let bleFragmentSpacingDirectedMs: Int = 25
|
||||
static let bleAnnounceIntervalSeconds: TimeInterval = 4.0
|
||||
static let bleDutyOnDurationDense: TimeInterval = 3.0
|
||||
static let bleDutyOffDurationDense: TimeInterval = 15.0
|
||||
static let bleConnectedAnnounceBaseSecondsDense: TimeInterval = 30.0
|
||||
static let bleConnectedAnnounceBaseSecondsSparse: TimeInterval = 15.0
|
||||
static let bleConnectedAnnounceJitterDense: TimeInterval = 8.0
|
||||
static let bleConnectedAnnounceJitterSparse: TimeInterval = 4.0
|
||||
|
||||
// Location
|
||||
static let locationDistanceFilterMeters: Double = 1000
|
||||
// Live (channel sheet open) distance threshold for meaningful updates
|
||||
static let locationDistanceFilterLiveMeters: Double = 10.0
|
||||
static let locationLiveRefreshInterval: TimeInterval = 5.0
|
||||
|
||||
// Notifications (geohash)
|
||||
static let uiGeoNotifyCooldownSeconds: TimeInterval = 60.0
|
||||
static let uiGeoNotifySnippetMaxLen: Int = 80
|
||||
|
||||
// Nostr geohash
|
||||
static let nostrGeohashInitialLookbackSeconds: TimeInterval = 3600
|
||||
static let nostrGeohashInitialLimit: Int = 200
|
||||
static let nostrGeoRelayCount: Int = 5
|
||||
static let nostrGeohashSampleLookbackSeconds: TimeInterval = 300
|
||||
static let nostrGeohashSampleLimit: Int = 100
|
||||
static let nostrDMSubscribeLookbackSeconds: TimeInterval = 86400
|
||||
|
||||
// Nostr helpers
|
||||
static let nostrShortKeyDisplayLength: Int = 8
|
||||
static let nostrConvKeyPrefixLength: Int = 16
|
||||
|
||||
// Compression
|
||||
static let compressionThresholdBytes: Int = 100
|
||||
|
||||
// Message deduplication
|
||||
static let messageDedupMaxAgeSeconds: TimeInterval = 300
|
||||
static let messageDedupMaxCount: Int = 1000
|
||||
|
||||
// Verification QR
|
||||
static let verificationQRMaxAgeSeconds: TimeInterval = 5 * 60
|
||||
|
||||
// Nostr relay backoff
|
||||
static let nostrRelayInitialBackoffSeconds: TimeInterval = 1.0
|
||||
static let nostrRelayMaxBackoffSeconds: TimeInterval = 300.0
|
||||
static let nostrRelayBackoffMultiplier: Double = 2.0
|
||||
static let nostrRelayMaxReconnectAttempts: Int = 10
|
||||
static let nostrRelayDefaultFetchLimit: Int = 100
|
||||
|
||||
// Geo relay directory
|
||||
static let geoRelayFetchIntervalSeconds: TimeInterval = 60 * 60 * 24
|
||||
static let geoRelayRefreshCheckIntervalSeconds: TimeInterval = 60 * 60
|
||||
static let geoRelayRetryInitialSeconds: TimeInterval = 60
|
||||
static let geoRelayRetryMaxSeconds: TimeInterval = 60 * 60
|
||||
|
||||
// BLE operational delays
|
||||
static let bleInitialAnnounceDelaySeconds: TimeInterval = 0.6
|
||||
static let bleConnectTimeoutSeconds: TimeInterval = 8.0
|
||||
static let bleRestartScanDelaySeconds: TimeInterval = 0.1
|
||||
static let blePostSubscribeAnnounceDelaySeconds: TimeInterval = 0.05
|
||||
static let blePostAnnounceDelaySeconds: TimeInterval = 0.4
|
||||
static let bleForceAnnounceMinIntervalSeconds: TimeInterval = 0.15
|
||||
|
||||
// BCH-01-004: Rate-limiting for subscription-triggered announces
|
||||
// Prevents rapid enumeration attacks by rate-limiting announce responses
|
||||
static let bleSubscriptionRateLimitMinSeconds: TimeInterval = 2.0 // Minimum interval between announces per central
|
||||
static let bleSubscriptionRateLimitBackoffFactor: Double = 2.0 // Exponential backoff multiplier
|
||||
static let bleSubscriptionRateLimitMaxBackoffSeconds: TimeInterval = 30.0 // Maximum backoff period
|
||||
static let bleSubscriptionRateLimitWindowSeconds: TimeInterval = 60.0 // Window for tracking subscription attempts
|
||||
static let bleSubscriptionRateLimitMaxAttempts: Int = 5 // Max attempts before extended cooldown
|
||||
|
||||
// Store-and-forward for directed packets at relays
|
||||
static let bleDirectedSpoolWindowSeconds: TimeInterval = 15.0
|
||||
|
||||
// Log/UI debounce windows
|
||||
// Shorter debounce so UI reacts faster while still suppressing duplicate callbacks
|
||||
static let bleDisconnectNotifyDebounceSeconds: TimeInterval = 0.9
|
||||
static let bleReconnectLogDebounceSeconds: TimeInterval = 2.0
|
||||
|
||||
// Weak-link cooldown after connection timeouts
|
||||
static let bleWeakLinkCooldownSeconds: TimeInterval = 30.0
|
||||
static let bleWeakLinkRSSICutoff: Int = -90
|
||||
|
||||
// Content hashing / formatting
|
||||
static let contentKeyPrefixLength: Int = 256
|
||||
static let uiLongMessageLengthThreshold: Int = 2000
|
||||
static let uiVeryLongTokenThreshold: Int = 512
|
||||
static let uiLongMessageLineLimit: Int = 30
|
||||
static let uiFingerprintSampleCount: Int = 3
|
||||
|
||||
// UI swipe/gesture thresholds
|
||||
static let uiBackSwipeTranslationLarge: CGFloat = 50
|
||||
static let uiBackSwipeTranslationSmall: CGFloat = 30
|
||||
static let uiBackSwipeVelocityThreshold: CGFloat = 300
|
||||
|
||||
// UI color tuning
|
||||
static let uiColorHueAvoidanceDelta: Double = 0.05
|
||||
static let uiColorHueOffset: Double = 0.12
|
||||
// Peer list palette
|
||||
static let uiPeerPaletteSlots: Int = 36
|
||||
static let uiPeerPaletteRingBrightnessDeltaLight: Double = 0.07
|
||||
static let uiPeerPaletteRingBrightnessDeltaDark: Double = -0.07
|
||||
|
||||
// UI windowing (infinite scroll)
|
||||
static let uiWindowInitialCountPublic: Int = 300
|
||||
static let uiWindowInitialCountPrivate: Int = 300
|
||||
static let uiWindowStepCount: Int = 200
|
||||
|
||||
// Share extension
|
||||
static let uiShareExtensionDismissDelaySeconds: TimeInterval = 2.0
|
||||
static let uiShareAcceptWindowSeconds: TimeInterval = 30.0
|
||||
static let uiMigrationCutoffSeconds: TimeInterval = 24 * 60 * 60
|
||||
|
||||
// Gossip Sync Configuration
|
||||
static let syncSeenCapacity: Int = 1000
|
||||
static let syncGCSMaxBytes: Int = 400
|
||||
static let syncGCSTargetFpr: Double = 0.01
|
||||
static let syncMaxMessageAgeSeconds: TimeInterval = 900
|
||||
static let syncMaintenanceIntervalSeconds: TimeInterval = 30.0
|
||||
static let syncStalePeerCleanupIntervalSeconds: TimeInterval = 60.0
|
||||
static let syncStalePeerTimeoutSeconds: TimeInterval = 60.0
|
||||
static let syncFragmentCapacity: Int = 600
|
||||
static let syncFileTransferCapacity: Int = 200
|
||||
static let syncFragmentIntervalSeconds: TimeInterval = 30.0
|
||||
static let syncFileTransferIntervalSeconds: TimeInterval = 60.0
|
||||
static let syncMessageIntervalSeconds: TimeInterval = 15.0
|
||||
}
|
||||
@@ -0,0 +1,361 @@
|
||||
//
|
||||
// UnifiedPeerService.swift
|
||||
// bitchat
|
||||
//
|
||||
// Unified peer state management combining mesh connectivity and favorites
|
||||
// This is free and unencumbered software released into the public domain.
|
||||
//
|
||||
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
import Nostr
|
||||
import Foundation
|
||||
import Combine
|
||||
import SwiftUI
|
||||
|
||||
/// Single source of truth for peer state, combining mesh connectivity and favorites
|
||||
@MainActor
|
||||
final class UnifiedPeerService: ObservableObject, TransportPeerEventsDelegate {
|
||||
|
||||
// MARK: - Published Properties
|
||||
|
||||
@Published private(set) var peers: [BitchatPeer] = []
|
||||
@Published private(set) var connectedPeerIDs: Set<PeerID> = []
|
||||
@Published private(set) var favorites: [BitchatPeer] = []
|
||||
@Published private(set) var mutualFavorites: [BitchatPeer] = []
|
||||
|
||||
// MARK: - Private Properties
|
||||
|
||||
private var peerIndex: [PeerID: BitchatPeer] = [:]
|
||||
private var fingerprintCache: [PeerID: String] = [:]
|
||||
private let meshService: Transport
|
||||
private let idBridge: NostrIdentityBridge
|
||||
private let identityManager: SecureIdentityStateManagerProtocol
|
||||
weak var messageRouter: MessageRouter?
|
||||
private let favoritesService = FavoritesPersistenceService.shared
|
||||
private var cancellables = Set<AnyCancellable>()
|
||||
|
||||
// MARK: - Initialization
|
||||
|
||||
init(
|
||||
meshService: Transport,
|
||||
idBridge: NostrIdentityBridge,
|
||||
identityManager: SecureIdentityStateManagerProtocol
|
||||
) {
|
||||
self.meshService = meshService
|
||||
self.idBridge = idBridge
|
||||
self.identityManager = identityManager
|
||||
|
||||
// Subscribe to changes from both services
|
||||
setupSubscriptions()
|
||||
|
||||
// Perform initial update
|
||||
Task { @MainActor in
|
||||
updatePeers()
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Setup
|
||||
|
||||
private func setupSubscriptions() {
|
||||
// Subscribe to mesh peer updates via delegate (preferred over publishers)
|
||||
meshService.peerEventsDelegate = self
|
||||
|
||||
// Also listen for favorite change notifications
|
||||
NotificationCenter.default.publisher(for: .favoriteStatusChanged)
|
||||
.receive(on: DispatchQueue.main)
|
||||
.sink { [weak self] _ in
|
||||
self?.updatePeers()
|
||||
}
|
||||
.store(in: &cancellables)
|
||||
}
|
||||
|
||||
// TransportPeerEventsDelegate
|
||||
func didUpdatePeerSnapshots(_ peers: [TransportPeerSnapshot]) {
|
||||
updatePeers()
|
||||
}
|
||||
|
||||
// MARK: - Core Update Logic
|
||||
|
||||
private func updatePeers() {
|
||||
let meshPeers = meshService.currentPeerSnapshots()
|
||||
// If we have no direct links at all, peers should not be marked reachable
|
||||
// "Reachable" means mesh-attached via at least one live link.
|
||||
let hasAnyConnected = meshPeers.contains { $0.isConnected }
|
||||
let favorites = favoritesService.favorites
|
||||
|
||||
var enrichedPeers: [BitchatPeer] = []
|
||||
var connected: Set<PeerID> = []
|
||||
var addedPeerIDs: Set<PeerID> = []
|
||||
|
||||
// Phase 1: Add all mesh peers (connected and reachable)
|
||||
for peerInfo in meshPeers {
|
||||
let peerID = peerInfo.peerID
|
||||
guard peerID != meshService.myPeerID else { continue } // Never add self
|
||||
|
||||
let peer = buildPeerFromMesh(
|
||||
peerInfo: peerInfo,
|
||||
favorites: favorites,
|
||||
meshAttached: hasAnyConnected
|
||||
)
|
||||
|
||||
enrichedPeers.append(peer)
|
||||
if peer.isConnected { connected.insert(peerID) }
|
||||
addedPeerIDs.insert(peerID)
|
||||
|
||||
// Update fingerprint cache
|
||||
if let publicKey = peerInfo.noisePublicKey {
|
||||
fingerprintCache[peerID] = publicKey.sha256Fingerprint()
|
||||
}
|
||||
}
|
||||
|
||||
// Phase 2: Add offline favorites that we actively favorite
|
||||
for (favoriteKey, favorite) in favorites where favorite.isFavorite {
|
||||
let peerID = PeerID(hexData: favoriteKey)
|
||||
|
||||
// Skip if already added (connected peer)
|
||||
if addedPeerIDs.contains(peerID) { continue }
|
||||
|
||||
// Skip if connected under different ID but same nickname
|
||||
let isConnectedByNickname = enrichedPeers.contains {
|
||||
$0.nickname == favorite.peerNickname && $0.isConnected
|
||||
}
|
||||
if isConnectedByNickname { continue }
|
||||
|
||||
let peer = buildPeerFromFavorite(favorite: favorite, peerID: peerID)
|
||||
enrichedPeers.append(peer)
|
||||
addedPeerIDs.insert(peerID)
|
||||
|
||||
// Update fingerprint cache
|
||||
fingerprintCache[peerID] = favoriteKey.sha256Fingerprint()
|
||||
}
|
||||
|
||||
// Phase 3: Sort peers
|
||||
enrichedPeers.sort { lhs, rhs in
|
||||
// Connectivity rank: connected > reachable > others
|
||||
func rank(_ p: BitchatPeer) -> Int { p.isConnected ? 2 : (p.isReachable ? 1 : 0) }
|
||||
let lr = rank(lhs), rr = rank(rhs)
|
||||
if lr != rr { return lr > rr }
|
||||
// Then favorites inside same rank
|
||||
if lhs.isFavorite != rhs.isFavorite { return lhs.isFavorite }
|
||||
// Finally alphabetical
|
||||
return lhs.displayName < rhs.displayName
|
||||
}
|
||||
|
||||
// Phase 4: Build subsets and indices
|
||||
var favoritesList: [BitchatPeer] = []
|
||||
var mutualsList: [BitchatPeer] = []
|
||||
var newIndex: [PeerID: BitchatPeer] = [:]
|
||||
|
||||
for peer in enrichedPeers {
|
||||
newIndex[peer.peerID] = peer
|
||||
|
||||
if peer.isFavorite {
|
||||
favoritesList.append(peer)
|
||||
}
|
||||
if peer.isMutualFavorite {
|
||||
mutualsList.append(peer)
|
||||
}
|
||||
}
|
||||
|
||||
// Phase 5: Filter out offline non-mutual peers and update published properties
|
||||
let filtered = enrichedPeers.filter { p in
|
||||
p.isConnected || p.isReachable || p.isMutualFavorite
|
||||
}
|
||||
self.peers = filtered
|
||||
self.connectedPeerIDs = connected
|
||||
self.favorites = favoritesList
|
||||
self.mutualFavorites = mutualsList
|
||||
self.peerIndex = newIndex
|
||||
|
||||
// Log summary (commented out to reduce noise)
|
||||
// let connectedCount = connected.count
|
||||
// let offlineCount = enrichedPeers.count - connectedCount
|
||||
// Peer update: \(enrichedPeers.count) total (\(connectedCount) connected, \(offlineCount) offline)
|
||||
}
|
||||
|
||||
// MARK: - Peer Building Helpers
|
||||
|
||||
private func buildPeerFromMesh(
|
||||
peerInfo: TransportPeerSnapshot,
|
||||
favorites: [Data: FavoritesPersistenceService.FavoriteRelationship],
|
||||
meshAttached: Bool
|
||||
) -> BitchatPeer {
|
||||
// Determine reachability based on lastSeen and identity trust
|
||||
let now = Date()
|
||||
let fingerprint = peerInfo.noisePublicKey?.sha256Fingerprint()
|
||||
let isVerified = fingerprint.map { identityManager.isVerified(fingerprint: $0) } ?? false
|
||||
let isFav = peerInfo.noisePublicKey.flatMap { favorites[$0]?.isFavorite } ?? false
|
||||
let retention: TimeInterval = (isVerified || isFav) ? TransportConfig.bleReachabilityRetentionVerifiedSeconds : TransportConfig.bleReachabilityRetentionUnverifiedSeconds
|
||||
// A peer is reachable if we recently saw them AND we are attached to the mesh
|
||||
let withinRetention = now.timeIntervalSince(peerInfo.lastSeen) <= retention
|
||||
let isReachable = peerInfo.isConnected ? true : (withinRetention && meshAttached)
|
||||
|
||||
var peer = BitchatPeer(
|
||||
peerID: peerInfo.peerID,
|
||||
noisePublicKey: peerInfo.noisePublicKey ?? Data(),
|
||||
nickname: peerInfo.nickname,
|
||||
lastSeen: peerInfo.lastSeen,
|
||||
isConnected: peerInfo.isConnected,
|
||||
isReachable: isReachable
|
||||
)
|
||||
|
||||
// Check for favorite status
|
||||
if let noiseKey = peerInfo.noisePublicKey,
|
||||
let favoriteStatus = favorites[noiseKey] {
|
||||
peer.favoriteStatus = favoriteStatus
|
||||
peer.nostrPublicKey = favoriteStatus.peerNostrPublicKey
|
||||
}
|
||||
|
||||
return peer
|
||||
}
|
||||
|
||||
private func buildPeerFromFavorite(
|
||||
favorite: FavoritesPersistenceService.FavoriteRelationship,
|
||||
peerID: PeerID
|
||||
) -> BitchatPeer {
|
||||
var peer = BitchatPeer(
|
||||
peerID: peerID,
|
||||
noisePublicKey: favorite.peerNoisePublicKey,
|
||||
nickname: favorite.peerNickname,
|
||||
lastSeen: favorite.lastUpdated,
|
||||
isConnected: false,
|
||||
isReachable: false
|
||||
)
|
||||
|
||||
peer.favoriteStatus = favorite
|
||||
peer.nostrPublicKey = favorite.peerNostrPublicKey
|
||||
|
||||
return peer
|
||||
}
|
||||
|
||||
// MARK: - Public Methods
|
||||
|
||||
/// Get peer by ID
|
||||
func getPeer(by peerID: PeerID) -> BitchatPeer? {
|
||||
return peerIndex[peerID]
|
||||
}
|
||||
|
||||
/// Get peer ID for nickname
|
||||
func getPeerID(for nickname: String) -> PeerID? {
|
||||
for peer in peers {
|
||||
if peer.displayName == nickname || peer.nickname == nickname {
|
||||
return peer.peerID
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
/// Check if peer is blocked
|
||||
func isBlocked(_ peerID: PeerID) -> Bool {
|
||||
// Get fingerprint
|
||||
guard let fingerprint = getFingerprint(for: peerID) else { return false }
|
||||
|
||||
// Check SecureIdentityStateManager for block status
|
||||
if let identity = identityManager.getSocialIdentity(for: fingerprint) {
|
||||
return identity.isBlocked
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
/// Toggle favorite status
|
||||
func toggleFavorite(_ peerID: PeerID) {
|
||||
guard let peer = getPeer(by: peerID) else {
|
||||
SecureLogger.warning("⚠️ Cannot toggle favorite - peer not found: \(peerID)", category: .session)
|
||||
return
|
||||
}
|
||||
|
||||
let wasFavorite = peer.isFavorite
|
||||
|
||||
// Get the actual nickname for logging and saving
|
||||
var actualNickname = peer.nickname
|
||||
|
||||
// Debug logging to understand the issue
|
||||
SecureLogger.debug("🔍 Toggle favorite - peer.nickname: '\(peer.nickname)', peer.displayName: '\(peer.displayName)', peerID: \(peerID)", category: .session)
|
||||
|
||||
if actualNickname.isEmpty {
|
||||
// Try to get from mesh service's current peer list
|
||||
if let meshPeerNickname = meshService.peerNickname(peerID: peerID) {
|
||||
actualNickname = meshPeerNickname
|
||||
SecureLogger.debug("🔍 Got nickname from mesh service: '\(actualNickname)'", category: .session)
|
||||
}
|
||||
}
|
||||
|
||||
// Use displayName as fallback (which shows ID prefix if nickname is empty)
|
||||
let finalNickname = actualNickname.isEmpty ? peer.displayName : actualNickname
|
||||
|
||||
if wasFavorite {
|
||||
// Remove favorite
|
||||
favoritesService.removeFavorite(peerNoisePublicKey: peer.noisePublicKey)
|
||||
} else {
|
||||
// Get or derive peer's Nostr public key if not already known
|
||||
var peerNostrKey = peer.nostrPublicKey
|
||||
if peerNostrKey == nil {
|
||||
// Try to get from NostrIdentityBridge association
|
||||
peerNostrKey = idBridge.getNostrPublicKey(for: peer.noisePublicKey)
|
||||
}
|
||||
|
||||
// Add favorite
|
||||
favoritesService.addFavorite(
|
||||
peerNoisePublicKey: peer.noisePublicKey,
|
||||
peerNostrPublicKey: peerNostrKey,
|
||||
peerNickname: finalNickname
|
||||
)
|
||||
}
|
||||
|
||||
// Log the final nickname being saved
|
||||
SecureLogger.debug("⭐️ Toggled favorite for '\(finalNickname)' (peerID: \(peerID), was: \(wasFavorite), now: \(!wasFavorite))", category: .session)
|
||||
|
||||
// Send favorite notification to the peer via router (mesh or Nostr)
|
||||
if let router = messageRouter {
|
||||
router.sendFavoriteNotification(to: peerID, isFavorite: !wasFavorite)
|
||||
} else {
|
||||
// Fallback to mesh-only if router not yet wired
|
||||
meshService.sendFavoriteNotification(to: peerID, isFavorite: !wasFavorite)
|
||||
}
|
||||
|
||||
// Force update of peers to reflect the change
|
||||
updatePeers()
|
||||
|
||||
// Force UI update by notifying SwiftUI directly
|
||||
DispatchQueue.main.async { [weak self] in
|
||||
self?.objectWillChange.send()
|
||||
}
|
||||
}
|
||||
|
||||
func getFingerprint(for peerID: PeerID) -> String? {
|
||||
// Check cache first
|
||||
if let cached = fingerprintCache[peerID] {
|
||||
return cached
|
||||
}
|
||||
|
||||
// Try to get from mesh service
|
||||
if let fingerprint = meshService.getFingerprint(for: peerID) {
|
||||
fingerprintCache[peerID] = fingerprint
|
||||
return fingerprint
|
||||
}
|
||||
|
||||
// Try to get from peer's public key
|
||||
if let peer = getPeer(by: peerID) {
|
||||
let fingerprint = peer.noisePublicKey.sha256Fingerprint()
|
||||
fingerprintCache[peerID] = fingerprint
|
||||
return fingerprint
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// MARK: - Compatibility Methods (for easy migration)
|
||||
|
||||
var allPeers: [BitchatPeer] { peers }
|
||||
var connectedPeers: Set<PeerID> { connectedPeerIDs }
|
||||
var favoritePeers: Set<String> {
|
||||
Set(favorites.compactMap { getFingerprint(for: $0.peerID) })
|
||||
}
|
||||
var blockedUsers: Set<String> {
|
||||
Set(peers.compactMap { peer in
|
||||
isBlocked(peer.peerID) ? getFingerprint(for: peer.peerID) : nil
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,184 @@
|
||||
import Foundation
|
||||
|
||||
/// QR verification scaffolding: schema, signing, and basic challenge/response helpers.
|
||||
final class VerificationService {
|
||||
static let shared = VerificationService()
|
||||
|
||||
// Injected Noise service from the running transport (do NOT create new BLEService)
|
||||
private var noise: NoiseEncryptionService?
|
||||
func configure(with noise: NoiseEncryptionService) { self.noise = noise }
|
||||
|
||||
/// Encapsulates the data encoded into a verification QR
|
||||
struct VerificationQR: Codable {
|
||||
let v: Int
|
||||
let noiseKeyHex: String
|
||||
let signKeyHex: String
|
||||
let npub: String?
|
||||
let nickname: String
|
||||
let ts: Int64
|
||||
let nonceB64: String
|
||||
var sigHex: String
|
||||
|
||||
static let context = "bitchat-verify-v1"
|
||||
|
||||
/// Canonical bytes used for signature (deterministic ordering)
|
||||
func canonicalBytes() -> Data {
|
||||
var out = Data()
|
||||
func appendField(_ s: String) {
|
||||
let d = s.data(using: .utf8) ?? Data()
|
||||
out.append(UInt8(min(d.count, 255)))
|
||||
out.append(d.prefix(255))
|
||||
}
|
||||
appendField(Self.context)
|
||||
appendField(String(v))
|
||||
appendField(noiseKeyHex.lowercased())
|
||||
appendField(signKeyHex.lowercased())
|
||||
appendField(npub ?? "")
|
||||
appendField(nickname)
|
||||
appendField(String(ts))
|
||||
appendField(nonceB64)
|
||||
return out
|
||||
}
|
||||
|
||||
func toURLString() -> String {
|
||||
var comps = URLComponents()
|
||||
comps.scheme = "bitchat"
|
||||
comps.host = "verify"
|
||||
comps.queryItems = [
|
||||
URLQueryItem(name: "v", value: String(v)),
|
||||
URLQueryItem(name: "noise", value: noiseKeyHex),
|
||||
URLQueryItem(name: "sign", value: signKeyHex),
|
||||
URLQueryItem(name: "nick", value: nickname),
|
||||
URLQueryItem(name: "ts", value: String(ts)),
|
||||
URLQueryItem(name: "nonce", value: nonceB64),
|
||||
URLQueryItem(name: "sig", value: sigHex)
|
||||
] + (npub != nil ? [URLQueryItem(name: "npub", value: npub)] : [])
|
||||
return comps.string ?? ""
|
||||
}
|
||||
|
||||
static func fromURL(_ url: URL) -> VerificationQR? {
|
||||
guard url.scheme == "bitchat", url.host == "verify",
|
||||
let items = URLComponents(url: url, resolvingAgainstBaseURL: false)?.queryItems else { return nil }
|
||||
func val(_ name: String) -> String? { items.first(where: { $0.name == name })?.value }
|
||||
guard let vStr = val("v"), let v = Int(vStr),
|
||||
let noise = val("noise"), let sign = val("sign"),
|
||||
let nick = val("nick"), let tsStr = val("ts"), let ts = Int64(tsStr),
|
||||
let nonce = val("nonce"), let sig = val("sig") else { return nil }
|
||||
return VerificationQR(v: v, noiseKeyHex: noise, signKeyHex: sign, npub: val("npub"), nickname: nick, ts: ts, nonceB64: nonce, sigHex: sig)
|
||||
}
|
||||
}
|
||||
|
||||
// MARK: - Public API
|
||||
|
||||
/// Build a signed QR string for the current identity
|
||||
func buildMyQRString(nickname: String, npub: String?) -> String? {
|
||||
// Simple short-lived cache to speed up sheet opening
|
||||
struct Cache { static var last: (nick: String, npub: String?, builtAt: Date, value: String)? }
|
||||
if let c = Cache.last, c.nick == nickname, c.npub == npub, Date().timeIntervalSince(c.builtAt) < 60 {
|
||||
return c.value
|
||||
}
|
||||
guard let noise = noise else { return nil }
|
||||
let noiseKey = noise.getStaticPublicKeyData().hexEncodedString()
|
||||
let signKey = noise.getSigningPublicKeyData().hexEncodedString()
|
||||
let ts = Int64(Date().timeIntervalSince1970)
|
||||
var nonce = Data(count: 16)
|
||||
_ = nonce.withUnsafeMutableBytes { SecRandomCopyBytes(kSecRandomDefault, 16, $0.baseAddress!) }
|
||||
let nonceB64 = nonce.base64EncodedString().replacingOccurrences(of: "+", with: "-").replacingOccurrences(of: "/", with: "_").replacingOccurrences(of: "=", with: "")
|
||||
let payload = VerificationQR(v: 1, noiseKeyHex: noiseKey, signKeyHex: signKey, npub: npub, nickname: nickname, ts: ts, nonceB64: nonceB64, sigHex: "")
|
||||
let msg = payload.canonicalBytes()
|
||||
guard let sig = noise.signData(msg) else { return nil }
|
||||
let signed = VerificationQR(v: payload.v,
|
||||
noiseKeyHex: payload.noiseKeyHex,
|
||||
signKeyHex: payload.signKeyHex,
|
||||
npub: payload.npub,
|
||||
nickname: payload.nickname,
|
||||
ts: payload.ts,
|
||||
nonceB64: payload.nonceB64,
|
||||
sigHex: sig.hexEncodedString())
|
||||
let out = signed.toURLString()
|
||||
Cache.last = (nickname, npub, Date(), out)
|
||||
return out
|
||||
}
|
||||
|
||||
/// Verify a scanned QR and return the parsed payload if valid (signature + freshness checks)
|
||||
func verifyScannedQR(_ urlString: String, maxAge: TimeInterval = TransportConfig.verificationQRMaxAgeSeconds) -> VerificationQR? {
|
||||
guard let url = URL(string: urlString), let qr = VerificationQR.fromURL(url) else { return nil }
|
||||
// Freshness
|
||||
let now = Date().timeIntervalSince1970
|
||||
if now - Double(qr.ts) > maxAge { return nil }
|
||||
// Verify signature using embedded ed25519 signKey
|
||||
guard let sig = Data(hexString: qr.sigHex), let signKey = Data(hexString: qr.signKeyHex) else { return nil }
|
||||
guard let noise = noise else { return nil }
|
||||
let ok = noise.verifySignature(sig, for: qr.canonicalBytes(), publicKey: signKey)
|
||||
return ok ? qr : nil
|
||||
}
|
||||
|
||||
// MARK: - Noise payloads (scaffold only)
|
||||
|
||||
func buildVerifyChallenge(noiseKeyHex: String, nonceA: Data) -> Data {
|
||||
// TLV: [0x01 len noiseKeyHex ascii] [0x02 len nonceA]
|
||||
var tlv = Data()
|
||||
let n0: [UInt8] = [0x01, UInt8(min(noiseKeyHex.count, 255))]
|
||||
tlv.append(contentsOf: n0)
|
||||
tlv.append(noiseKeyHex.data(using: .utf8)!.prefix(255))
|
||||
tlv.append(0x02)
|
||||
tlv.append(UInt8(min(nonceA.count, 255)))
|
||||
tlv.append(nonceA.prefix(255))
|
||||
return NoisePayload(type: .verifyChallenge, data: tlv).encode()
|
||||
}
|
||||
|
||||
func buildVerifyResponse(noiseKeyHex: String, nonceA: Data) -> Data? {
|
||||
// Sign context: verify-response | noiseKeyHex | nonceA
|
||||
var msg = Data("bitchat-verify-resp-v1".utf8)
|
||||
let nk = noiseKeyHex.data(using: .utf8) ?? Data()
|
||||
msg.append(UInt8(min(nk.count, 255))); msg.append(nk.prefix(255))
|
||||
msg.append(nonceA)
|
||||
guard let noise = noise, let sig = noise.signData(msg) else { return nil }
|
||||
var tlv = Data()
|
||||
tlv.append(0x01); tlv.append(UInt8(min(nk.count, 255))); tlv.append(nk.prefix(255))
|
||||
tlv.append(0x02); tlv.append(UInt8(min(nonceA.count, 255))); tlv.append(nonceA.prefix(255))
|
||||
tlv.append(0x03); tlv.append(UInt8(min(sig.count, 255))); tlv.append(sig.prefix(255))
|
||||
return NoisePayload(type: .verifyResponse, data: tlv).encode()
|
||||
}
|
||||
|
||||
func parseVerifyChallenge(_ data: Data) -> (noiseKeyHex: String, nonceA: Data)? {
|
||||
var idx = 0
|
||||
func take(_ n: Int) -> Data? {
|
||||
guard idx + n <= data.count else { return nil }
|
||||
let d = data[idx..<(idx+n)]
|
||||
idx += n
|
||||
return Data(d)
|
||||
}
|
||||
// Expect type already stripped; we receive only TLV here
|
||||
// TLV 0x01 noiseKeyHex
|
||||
guard let t1 = take(1), t1[0] == 0x01, let l1 = take(1), let s1 = take(Int(l1[0])),
|
||||
let noiseStr = String(data: s1, encoding: .utf8) else { return nil }
|
||||
// TLV 0x02 nonceA
|
||||
guard let t2 = take(1), t2[0] == 0x02, let l2 = take(1), let nA = take(Int(l2[0])) else { return nil }
|
||||
return (noiseStr, nA)
|
||||
}
|
||||
|
||||
func parseVerifyResponse(_ data: Data) -> (noiseKeyHex: String, nonceA: Data, signature: Data)? {
|
||||
var idx = 0
|
||||
func take(_ n: Int) -> Data? {
|
||||
guard idx + n <= data.count else { return nil }
|
||||
let d = data[idx..<(idx+n)]
|
||||
idx += n
|
||||
return Data(d)
|
||||
}
|
||||
guard let t1 = take(1), t1[0] == 0x01, let l1 = take(1), let s1 = take(Int(l1[0])),
|
||||
let noiseStr = String(data: s1, encoding: .utf8) else { return nil }
|
||||
guard let t2 = take(1), t2[0] == 0x02, let l2 = take(1), let nA = take(Int(l2[0])) else { return nil }
|
||||
guard let t3 = take(1), t3[0] == 0x03, let l3 = take(1), let sig = take(Int(l3[0])) else { return nil }
|
||||
return (noiseStr, nA, sig)
|
||||
}
|
||||
|
||||
func verifyResponseSignature(noiseKeyHex: String, nonceA: Data, signature: Data, signerPublicKeyHex: String) -> Bool {
|
||||
var msg = Data("bitchat-verify-resp-v1".utf8)
|
||||
let nk = noiseKeyHex.data(using: .utf8) ?? Data()
|
||||
msg.append(UInt8(min(nk.count, 255))); msg.append(nk.prefix(255))
|
||||
msg.append(nonceA)
|
||||
guard let noise = noise, let pub = Data(hexString: signerPublicKeyHex) else { return false }
|
||||
return noise.verifySignature(signature, for: msg, publicKey: pub)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,237 @@
|
||||
import Foundation
|
||||
import CryptoKit
|
||||
|
||||
// Golomb-Coded Set (GCS) filter utilities for sync.
|
||||
// Hashing:
|
||||
// - Packet ID is 16 bytes (see PacketIdUtil). For GCS mapping, use h64 = first 8 bytes of SHA-256 over the 16-byte ID.
|
||||
// - Map to [1, M) by computing (h64 % M) and remapping 0 -> 1 to avoid zero-length deltas.
|
||||
// Encoding (v1):
|
||||
// - Sort mapped values ascending; encode deltas (first is v0, then vi - v{i-1}) as positive integers x >= 1.
|
||||
// - Golomb-Rice with parameter P: q = (x - 1) >> P encoded as unary (q ones then a zero), then write P-bit remainder r = (x - 1) & ((1<<P)-1).
|
||||
// - Bitstream is MSB-first within each byte.
|
||||
enum GCSFilter {
|
||||
struct Params { let p: Int; let m: UInt32; let data: Data }
|
||||
|
||||
// Derive P from FPR (~ 1 / 2^P)
|
||||
static func deriveP(targetFpr: Double) -> Int {
|
||||
let f = max(0.000001, min(0.25, targetFpr))
|
||||
// ceil(log2(1/f))
|
||||
let p = Int(ceil(log2(1.0 / f)))
|
||||
return max(1, p)
|
||||
}
|
||||
|
||||
// Estimate max elements that fit in size bytes: bits per element ~= P + 2 (approx)
|
||||
static func estimateMaxElements(sizeBytes: Int, p: Int) -> Int {
|
||||
let bits = max(8, sizeBytes * 8)
|
||||
let per = max(3, p + 2)
|
||||
return max(1, bits / per)
|
||||
}
|
||||
|
||||
static func buildFilter(ids: [Data], maxBytes: Int, targetFpr: Double) -> Params {
|
||||
let p = deriveP(targetFpr: targetFpr)
|
||||
guard !ids.isEmpty else {
|
||||
return Params(p: p, m: 1, data: Data())
|
||||
}
|
||||
|
||||
let cap = estimateMaxElements(sizeBytes: maxBytes, p: p)
|
||||
let selected = Array(ids.prefix(cap))
|
||||
let range = max(1, hashRange(count: selected.count, p: p))
|
||||
let modulo = UInt64(range)
|
||||
|
||||
var mapped = selected
|
||||
.map { h64($0) }
|
||||
.map { mapHash($0, modulo: modulo) }
|
||||
.sorted()
|
||||
mapped = normalizeMappedValues(mapped, modulo: modulo)
|
||||
|
||||
if mapped.isEmpty {
|
||||
return Params(p: p, m: range, data: Data())
|
||||
}
|
||||
|
||||
var encoded = encode(sorted: mapped, p: p)
|
||||
var trimmedCount = mapped.count
|
||||
|
||||
while encoded.count > maxBytes && trimmedCount > 0 {
|
||||
if trimmedCount == 1 {
|
||||
mapped.removeAll()
|
||||
encoded = Data()
|
||||
break
|
||||
}
|
||||
trimmedCount = max(1, (trimmedCount * 9) / 10)
|
||||
mapped = Array(mapped.prefix(trimmedCount))
|
||||
encoded = encode(sorted: mapped, p: p)
|
||||
}
|
||||
|
||||
return Params(p: p, m: range, data: encoded)
|
||||
}
|
||||
|
||||
static func decodeToSortedSet(p: Int, m: UInt32, data: Data) -> [UInt64] {
|
||||
var values: [UInt64] = []
|
||||
let reader = BitReader(data)
|
||||
var acc: UInt64 = 0
|
||||
while true {
|
||||
guard let q = reader.readUnary() else { break }
|
||||
guard let r = reader.readBits(count: p) else { break }
|
||||
let x = (UInt64(q) << UInt64(p)) + UInt64(r) + 1
|
||||
acc &+= x
|
||||
if acc >= UInt64(m) { break }
|
||||
values.append(acc)
|
||||
}
|
||||
return values
|
||||
}
|
||||
|
||||
static func contains(sortedValues: [UInt64], candidate: UInt64) -> Bool {
|
||||
var lo = 0
|
||||
var hi = sortedValues.count - 1
|
||||
while lo <= hi {
|
||||
let mid = (lo + hi) >> 1
|
||||
let v = sortedValues[mid]
|
||||
if v == candidate { return true }
|
||||
if v < candidate { lo = mid + 1 } else { hi = mid - 1 }
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
static func bucket(for id: Data, modulus m: UInt32) -> UInt64 {
|
||||
let modulo = UInt64(max(1, m))
|
||||
guard modulo > 1 else { return 0 }
|
||||
return mapHash(h64(id), modulo: modulo)
|
||||
}
|
||||
|
||||
private static func h64(_ id16: Data) -> UInt64 {
|
||||
var hasher = SHA256()
|
||||
hasher.update(data: id16)
|
||||
let d = hasher.finalize()
|
||||
let db = Data(d)
|
||||
var x: UInt64 = 0
|
||||
let take = min(8, db.count)
|
||||
for i in 0..<take { x = (x << 8) | UInt64(db[i]) }
|
||||
return x & 0x7fff_ffff_ffff_ffff
|
||||
}
|
||||
|
||||
private static func hashRange(count: Int, p: Int) -> UInt32 {
|
||||
guard count > 0 else { return 1 }
|
||||
if p >= 64 { return UInt32.max }
|
||||
let multiplier = UInt64(1) << UInt64(p)
|
||||
let (product, overflow) = UInt64(count).multipliedReportingOverflow(by: multiplier)
|
||||
if overflow { return UInt32.max }
|
||||
if product == 0 { return 1 }
|
||||
return product > UInt64(UInt32.max) ? UInt32.max : UInt32(product)
|
||||
}
|
||||
|
||||
private static func mapHash(_ hash: UInt64, modulo: UInt64) -> UInt64 {
|
||||
guard modulo > 1 else { return 0 }
|
||||
let value = hash % modulo
|
||||
if value == 0 { return 1 }
|
||||
return value
|
||||
}
|
||||
|
||||
private static func normalizeMappedValues(_ values: [UInt64], modulo: UInt64) -> [UInt64] {
|
||||
guard modulo > 1 else { return [] }
|
||||
guard !values.isEmpty else { return [] }
|
||||
var result: [UInt64] = []
|
||||
result.reserveCapacity(values.count)
|
||||
var last: UInt64 = 0
|
||||
for value in values {
|
||||
let normalized = min(value, modulo - 1)
|
||||
if normalized > last {
|
||||
result.append(normalized)
|
||||
last = normalized
|
||||
}
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
private static func encode(sorted: [UInt64], p: Int) -> Data {
|
||||
let writer = BitWriter()
|
||||
var prev: UInt64 = 0
|
||||
let mask: UInt64 = (p >= 64) ? ~0 : ((1 << UInt64(p)) - 1)
|
||||
for v in sorted {
|
||||
let delta = v &- prev
|
||||
prev = v
|
||||
let x = delta
|
||||
let q = (x &- 1) >> UInt64(p)
|
||||
let r = (x &- 1) & mask
|
||||
// unary q ones then zero
|
||||
if q > 0 { writer.writeOnes(count: Int(q)) }
|
||||
writer.writeBit(0)
|
||||
writer.writeBits(value: r, count: p)
|
||||
}
|
||||
return writer.toData()
|
||||
}
|
||||
|
||||
// MARK: - Bit helpers (MSB-first)
|
||||
private final class BitWriter {
|
||||
private var buf = Data()
|
||||
private var cur: UInt8 = 0
|
||||
private var nbits: Int = 0
|
||||
func writeBit(_ bit: Int) { // 0 or 1
|
||||
cur = UInt8((Int(cur) << 1) | (bit & 1))
|
||||
nbits += 1
|
||||
if nbits == 8 {
|
||||
buf.append(cur)
|
||||
cur = 0; nbits = 0
|
||||
}
|
||||
}
|
||||
func writeOnes(count: Int) {
|
||||
guard count > 0 else { return }
|
||||
for _ in 0..<count { writeBit(1) }
|
||||
}
|
||||
func writeBits(value: UInt64, count: Int) {
|
||||
guard count > 0 else { return }
|
||||
for i in stride(from: count - 1, through: 0, by: -1) {
|
||||
let bit = Int((value >> UInt64(i)) & 1)
|
||||
writeBit(bit)
|
||||
}
|
||||
}
|
||||
func toData() -> Data {
|
||||
if nbits > 0 {
|
||||
let rem = UInt8(Int(cur) << (8 - nbits))
|
||||
buf.append(rem)
|
||||
cur = 0; nbits = 0
|
||||
}
|
||||
return buf
|
||||
}
|
||||
}
|
||||
|
||||
private final class BitReader {
|
||||
private let data: Data
|
||||
private var idx: Int = 0
|
||||
private var cur: UInt8 = 0
|
||||
private var left: Int = 0
|
||||
init(_ data: Data) {
|
||||
self.data = data
|
||||
if !data.isEmpty {
|
||||
cur = data[0]
|
||||
left = 8
|
||||
}
|
||||
}
|
||||
func readBit() -> Int? {
|
||||
if idx >= data.count { return nil }
|
||||
let bit = (Int(cur) >> 7) & 1
|
||||
cur = UInt8((Int(cur) << 1) & 0xFF)
|
||||
left -= 1
|
||||
if left == 0 {
|
||||
idx += 1
|
||||
if idx < data.count { cur = data[idx]; left = 8 }
|
||||
}
|
||||
return bit
|
||||
}
|
||||
func readUnary() -> Int? {
|
||||
var q = 0
|
||||
while true {
|
||||
guard let b = readBit() else { return nil }
|
||||
if b == 1 { q += 1 } else { break }
|
||||
}
|
||||
return q
|
||||
}
|
||||
func readBits(count: Int) -> UInt64? {
|
||||
var v: UInt64 = 0
|
||||
for _ in 0..<count {
|
||||
guard let b = readBit() else { return nil }
|
||||
v = (v << 1) | UInt64(b)
|
||||
}
|
||||
return v
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,462 @@
|
||||
import Foundation
|
||||
import BitLogger
|
||||
import BitFoundation
|
||||
|
||||
// Gossip-based sync manager using on-demand GCS filters
|
||||
final class GossipSyncManager {
|
||||
protocol Delegate: AnyObject {
|
||||
func sendPacket(_ packet: BitchatPacket)
|
||||
func sendPacket(to peerID: PeerID, packet: BitchatPacket)
|
||||
func signPacketForBroadcast(_ packet: BitchatPacket) -> BitchatPacket
|
||||
func getConnectedPeers() -> [PeerID]
|
||||
}
|
||||
|
||||
private struct PacketStore {
|
||||
private(set) var packets: [String: BitchatPacket] = [:]
|
||||
private(set) var order: [String] = []
|
||||
|
||||
mutating func insert(idHex: String, packet: BitchatPacket, capacity: Int) {
|
||||
guard capacity > 0 else { return }
|
||||
if packets[idHex] != nil {
|
||||
packets[idHex] = packet
|
||||
return
|
||||
}
|
||||
packets[idHex] = packet
|
||||
order.append(idHex)
|
||||
while order.count > capacity {
|
||||
let victim = order.removeFirst()
|
||||
packets.removeValue(forKey: victim)
|
||||
}
|
||||
}
|
||||
|
||||
func allPackets(isFresh: (BitchatPacket) -> Bool) -> [BitchatPacket] {
|
||||
order.compactMap { key in
|
||||
guard let packet = packets[key], isFresh(packet) else { return nil }
|
||||
return packet
|
||||
}
|
||||
}
|
||||
|
||||
mutating func remove(where shouldRemove: (BitchatPacket) -> Bool) {
|
||||
var nextOrder: [String] = []
|
||||
for key in order {
|
||||
guard let packet = packets[key] else { continue }
|
||||
if shouldRemove(packet) {
|
||||
packets.removeValue(forKey: key)
|
||||
} else {
|
||||
nextOrder.append(key)
|
||||
}
|
||||
}
|
||||
order = nextOrder
|
||||
}
|
||||
|
||||
mutating func removeExpired(isFresh: (BitchatPacket) -> Bool) {
|
||||
remove { !isFresh($0) }
|
||||
}
|
||||
}
|
||||
|
||||
private struct SyncSchedule {
|
||||
let types: SyncTypeFlags
|
||||
let interval: TimeInterval
|
||||
var lastSent: Date
|
||||
}
|
||||
|
||||
struct Config {
|
||||
var seenCapacity: Int = 1000 // max packets per sync (cap across types)
|
||||
var gcsMaxBytes: Int = 400 // filter size budget (128..1024)
|
||||
var gcsTargetFpr: Double = 0.01 // 1%
|
||||
var maxMessageAgeSeconds: TimeInterval = 900 // 15 min - discard older messages
|
||||
var maintenanceIntervalSeconds: TimeInterval = 30.0
|
||||
var stalePeerCleanupIntervalSeconds: TimeInterval = 60.0
|
||||
var stalePeerTimeoutSeconds: TimeInterval = 60.0
|
||||
var fragmentCapacity: Int = 600
|
||||
var fileTransferCapacity: Int = 200
|
||||
var fragmentSyncIntervalSeconds: TimeInterval = 30.0
|
||||
var fileTransferSyncIntervalSeconds: TimeInterval = 60.0
|
||||
var messageSyncIntervalSeconds: TimeInterval = 15.0
|
||||
}
|
||||
|
||||
private let myPeerID: PeerID
|
||||
private let config: Config
|
||||
private let requestSyncManager: RequestSyncManager
|
||||
weak var delegate: Delegate?
|
||||
|
||||
// Storage: broadcast packets by type, and latest announce per sender
|
||||
private var messages = PacketStore()
|
||||
private var fragments = PacketStore()
|
||||
private var fileTransfers = PacketStore()
|
||||
private var latestAnnouncementByPeer: [PeerID: (id: String, packet: BitchatPacket)] = [:]
|
||||
|
||||
// Timer
|
||||
private var periodicTimer: DispatchSourceTimer?
|
||||
private let queue = DispatchQueue(label: "mesh.sync", qos: .utility)
|
||||
private var lastStalePeerCleanup: Date = .distantPast
|
||||
private var syncSchedules: [SyncSchedule] = []
|
||||
|
||||
init(myPeerID: PeerID, config: Config = Config(), requestSyncManager: RequestSyncManager) {
|
||||
self.myPeerID = myPeerID
|
||||
self.config = config
|
||||
self.requestSyncManager = requestSyncManager
|
||||
var schedules: [SyncSchedule] = []
|
||||
if config.seenCapacity > 0 && config.messageSyncIntervalSeconds > 0 {
|
||||
schedules.append(SyncSchedule(types: .publicMessages, interval: config.messageSyncIntervalSeconds, lastSent: .distantPast))
|
||||
}
|
||||
if config.fragmentCapacity > 0 && config.fragmentSyncIntervalSeconds > 0 {
|
||||
schedules.append(SyncSchedule(types: .fragment, interval: config.fragmentSyncIntervalSeconds, lastSent: .distantPast))
|
||||
}
|
||||
if config.fileTransferCapacity > 0 && config.fileTransferSyncIntervalSeconds > 0 {
|
||||
schedules.append(SyncSchedule(types: .fileTransfer, interval: config.fileTransferSyncIntervalSeconds, lastSent: .distantPast))
|
||||
}
|
||||
syncSchedules = schedules
|
||||
}
|
||||
|
||||
func start() {
|
||||
stop()
|
||||
let timer = DispatchSource.makeTimerSource(queue: queue)
|
||||
let interval = max(0.1, config.maintenanceIntervalSeconds)
|
||||
timer.schedule(deadline: .now() + interval, repeating: interval, leeway: .seconds(1))
|
||||
timer.setEventHandler { [weak self] in
|
||||
self?.performPeriodicMaintenance()
|
||||
}
|
||||
timer.resume()
|
||||
periodicTimer = timer
|
||||
}
|
||||
|
||||
func stop() {
|
||||
periodicTimer?.cancel(); periodicTimer = nil
|
||||
}
|
||||
|
||||
func scheduleInitialSyncToPeer(_ peerID: PeerID, delaySeconds: TimeInterval = 5.0) {
|
||||
queue.asyncAfter(deadline: .now() + delaySeconds) { [weak self] in
|
||||
guard let self = self else { return }
|
||||
self.sendRequestSync(to: peerID, types: .publicMessages)
|
||||
if self.config.fragmentCapacity > 0 && self.config.fragmentSyncIntervalSeconds > 0 {
|
||||
self.queue.asyncAfter(deadline: .now() + 0.5) { [weak self] in
|
||||
self?.sendRequestSync(to: peerID, types: .fragment)
|
||||
}
|
||||
}
|
||||
if self.config.fileTransferCapacity > 0 && self.config.fileTransferSyncIntervalSeconds > 0 {
|
||||
self.queue.asyncAfter(deadline: .now() + 1.0) { [weak self] in
|
||||
self?.sendRequestSync(to: peerID, types: .fileTransfer)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func onPublicPacketSeen(_ packet: BitchatPacket) {
|
||||
queue.async { [weak self] in
|
||||
self?._onPublicPacketSeen(packet)
|
||||
}
|
||||
}
|
||||
|
||||
// Helper to check if a packet is within the age threshold
|
||||
private func isPacketFresh(_ packet: BitchatPacket) -> Bool {
|
||||
let nowMs = UInt64(Date().timeIntervalSince1970 * 1000)
|
||||
let ageThresholdMs = UInt64(config.maxMessageAgeSeconds * 1000)
|
||||
|
||||
// If current time is less than threshold, accept all (handle clock issues gracefully)
|
||||
guard nowMs >= ageThresholdMs else { return true }
|
||||
|
||||
let cutoffMs = nowMs - ageThresholdMs
|
||||
return packet.timestamp >= cutoffMs
|
||||
}
|
||||
|
||||
private func isAnnouncementFresh(_ packet: BitchatPacket) -> Bool {
|
||||
guard config.stalePeerTimeoutSeconds > 0 else { return true }
|
||||
let nowMs = UInt64(Date().timeIntervalSince1970 * 1000)
|
||||
let timeoutMs = UInt64(config.stalePeerTimeoutSeconds * 1000)
|
||||
guard nowMs >= timeoutMs else { return true }
|
||||
let cutoffMs = nowMs - timeoutMs
|
||||
return packet.timestamp >= cutoffMs
|
||||
}
|
||||
|
||||
private func _onPublicPacketSeen(_ packet: BitchatPacket) {
|
||||
guard let messageType = MessageType(rawValue: packet.type) else { return }
|
||||
let isBroadcastRecipient: Bool = {
|
||||
guard let r = packet.recipientID else { return true }
|
||||
return r.count == 8 && r.allSatisfy { $0 == 0xFF }
|
||||
}()
|
||||
|
||||
switch messageType {
|
||||
case .announce:
|
||||
guard isPacketFresh(packet) else { return }
|
||||
guard isAnnouncementFresh(packet) else {
|
||||
let sender = PeerID(hexData: packet.senderID)
|
||||
removeState(for: sender)
|
||||
return
|
||||
}
|
||||
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
|
||||
let sender = PeerID(hexData: packet.senderID)
|
||||
latestAnnouncementByPeer[sender] = (id: idHex, packet: packet)
|
||||
case .message:
|
||||
guard isBroadcastRecipient else { return }
|
||||
guard isPacketFresh(packet) else { return }
|
||||
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
|
||||
messages.insert(idHex: idHex, packet: packet, capacity: max(1, config.seenCapacity))
|
||||
case .fragment:
|
||||
guard isBroadcastRecipient else { return }
|
||||
guard isPacketFresh(packet) else { return }
|
||||
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
|
||||
fragments.insert(idHex: idHex, packet: packet, capacity: max(1, config.fragmentCapacity))
|
||||
case .fileTransfer:
|
||||
guard isBroadcastRecipient else { return }
|
||||
guard isPacketFresh(packet) else { return }
|
||||
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
|
||||
fileTransfers.insert(idHex: idHex, packet: packet, capacity: max(1, config.fileTransferCapacity))
|
||||
default:
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
private func sendPeriodicSync(for types: SyncTypeFlags) {
|
||||
// Unicast sync to connected peers to allow RSR attribution
|
||||
if let connectedPeers = delegate?.getConnectedPeers(), !connectedPeers.isEmpty {
|
||||
SecureLogger.debug("Sending periodic sync to \(connectedPeers.count) connected peers", category: .sync)
|
||||
for peerID in connectedPeers {
|
||||
sendRequestSync(to: peerID, types: types)
|
||||
}
|
||||
} else {
|
||||
// Fallback to broadcast (discovery phase)
|
||||
sendRequestSync(for: types)
|
||||
}
|
||||
}
|
||||
|
||||
private func sendRequestSync(for types: SyncTypeFlags) {
|
||||
let payload = buildGcsPayload(for: types)
|
||||
let pkt = BitchatPacket(
|
||||
type: MessageType.requestSync.rawValue,
|
||||
senderID: Data(hexString: myPeerID.id) ?? Data(),
|
||||
recipientID: nil, // broadcast
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 0 // local-only
|
||||
)
|
||||
let signed = delegate?.signPacketForBroadcast(pkt) ?? pkt
|
||||
delegate?.sendPacket(signed)
|
||||
}
|
||||
|
||||
private func sendRequestSync(to peerID: PeerID, types: SyncTypeFlags) {
|
||||
// Register the request for RSR validation
|
||||
requestSyncManager.registerRequest(to: peerID)
|
||||
|
||||
let payload = buildGcsPayload(for: types)
|
||||
var recipient = Data()
|
||||
var temp = peerID.id
|
||||
while temp.count >= 2 && recipient.count < 8 {
|
||||
let hexByte = String(temp.prefix(2))
|
||||
if let b = UInt8(hexByte, radix: 16) { recipient.append(b) }
|
||||
temp = String(temp.dropFirst(2))
|
||||
}
|
||||
let pkt = BitchatPacket(
|
||||
type: MessageType.requestSync.rawValue,
|
||||
senderID: Data(hexString: myPeerID.id) ?? Data(),
|
||||
recipientID: recipient,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 0 // local-only
|
||||
)
|
||||
let signed = delegate?.signPacketForBroadcast(pkt) ?? pkt
|
||||
delegate?.sendPacket(to: peerID, packet: signed)
|
||||
}
|
||||
|
||||
func handleRequestSync(from peerID: PeerID, request: RequestSyncPacket) {
|
||||
queue.async { [weak self] in
|
||||
self?._handleRequestSync(from: peerID, request: request)
|
||||
}
|
||||
}
|
||||
|
||||
private func _handleRequestSync(from peerID: PeerID, request: RequestSyncPacket) {
|
||||
let requestedTypes = (request.types ?? .publicMessages)
|
||||
// Decode GCS into sorted set and prepare membership checker
|
||||
let sorted = GCSFilter.decodeToSortedSet(p: request.p, m: request.m, data: request.data)
|
||||
func mightContain(_ id: Data) -> Bool {
|
||||
let bucket = GCSFilter.bucket(for: id, modulus: request.m)
|
||||
return GCSFilter.contains(sortedValues: sorted, candidate: bucket)
|
||||
}
|
||||
|
||||
if requestedTypes.contains(.announce) {
|
||||
for (_, pair) in latestAnnouncementByPeer {
|
||||
let (idHex, pkt) = pair
|
||||
guard isPacketFresh(pkt) else { continue }
|
||||
let idBytes = Data(hexString: idHex) ?? Data()
|
||||
if !mightContain(idBytes) {
|
||||
var toSend = pkt
|
||||
toSend.ttl = 0
|
||||
toSend.isRSR = true // Mark as solicited response
|
||||
delegate?.sendPacket(to: peerID, packet: toSend)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if requestedTypes.contains(.message) {
|
||||
let toSendMsgs = messages.allPackets(isFresh: isPacketFresh)
|
||||
for pkt in toSendMsgs {
|
||||
let idBytes = PacketIdUtil.computeId(pkt)
|
||||
if !mightContain(idBytes) {
|
||||
var toSend = pkt
|
||||
toSend.ttl = 0
|
||||
toSend.isRSR = true // Mark as solicited response
|
||||
delegate?.sendPacket(to: peerID, packet: toSend)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if requestedTypes.contains(.fragment) {
|
||||
let frags = fragments.allPackets(isFresh: isPacketFresh)
|
||||
for pkt in frags {
|
||||
let idBytes = PacketIdUtil.computeId(pkt)
|
||||
if !mightContain(idBytes) {
|
||||
var toSend = pkt
|
||||
toSend.ttl = 0
|
||||
toSend.isRSR = true // Mark as solicited response
|
||||
delegate?.sendPacket(to: peerID, packet: toSend)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if requestedTypes.contains(.fileTransfer) {
|
||||
let files = fileTransfers.allPackets(isFresh: isPacketFresh)
|
||||
for pkt in files {
|
||||
let idBytes = PacketIdUtil.computeId(pkt)
|
||||
if !mightContain(idBytes) {
|
||||
var toSend = pkt
|
||||
toSend.ttl = 0
|
||||
toSend.isRSR = true // Mark as solicited response
|
||||
delegate?.sendPacket(to: peerID, packet: toSend)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Build REQUEST_SYNC payload using current candidates and GCS params
|
||||
private func buildGcsPayload(for types: SyncTypeFlags) -> Data {
|
||||
var candidates: [BitchatPacket] = []
|
||||
if types.contains(.announce) {
|
||||
for (_, pair) in latestAnnouncementByPeer where isPacketFresh(pair.packet) {
|
||||
candidates.append(pair.packet)
|
||||
}
|
||||
}
|
||||
if types.contains(.message) {
|
||||
candidates.append(contentsOf: messages.allPackets(isFresh: isPacketFresh))
|
||||
}
|
||||
if types.contains(.fragment) {
|
||||
candidates.append(contentsOf: fragments.allPackets(isFresh: isPacketFresh))
|
||||
}
|
||||
if types.contains(.fileTransfer) {
|
||||
candidates.append(contentsOf: fileTransfers.allPackets(isFresh: isPacketFresh))
|
||||
}
|
||||
if candidates.isEmpty {
|
||||
let p = GCSFilter.deriveP(targetFpr: config.gcsTargetFpr)
|
||||
let req = RequestSyncPacket(p: p, m: 1, data: Data(), types: types)
|
||||
return req.encode()
|
||||
}
|
||||
|
||||
// Sort by timestamp desc
|
||||
candidates.sort { $0.timestamp > $1.timestamp }
|
||||
|
||||
let p = GCSFilter.deriveP(targetFpr: config.gcsTargetFpr)
|
||||
let nMax = GCSFilter.estimateMaxElements(sizeBytes: config.gcsMaxBytes, p: p)
|
||||
let cap: Int
|
||||
if types == .fragment {
|
||||
cap = max(1, config.fragmentCapacity)
|
||||
} else if types == .fileTransfer {
|
||||
cap = max(1, config.fileTransferCapacity)
|
||||
} else {
|
||||
cap = max(1, config.seenCapacity)
|
||||
}
|
||||
let takeN = min(candidates.count, min(nMax, cap))
|
||||
if takeN <= 0 {
|
||||
let req = RequestSyncPacket(p: p, m: 1, data: Data(), types: types)
|
||||
return req.encode()
|
||||
}
|
||||
let ids: [Data] = candidates.prefix(takeN).map { PacketIdUtil.computeId($0) }
|
||||
let params = GCSFilter.buildFilter(ids: ids, maxBytes: config.gcsMaxBytes, targetFpr: config.gcsTargetFpr)
|
||||
let req = RequestSyncPacket(p: params.p, m: params.m, data: params.data, types: types)
|
||||
return req.encode()
|
||||
}
|
||||
|
||||
// Periodic cleanup of expired messages and announcements
|
||||
private func cleanupExpiredMessages() {
|
||||
// Remove expired announcements
|
||||
latestAnnouncementByPeer = latestAnnouncementByPeer.filter { _, pair in
|
||||
isPacketFresh(pair.packet)
|
||||
}
|
||||
|
||||
messages.removeExpired(isFresh: isPacketFresh)
|
||||
fragments.removeExpired(isFresh: isPacketFresh)
|
||||
fileTransfers.removeExpired(isFresh: isPacketFresh)
|
||||
}
|
||||
|
||||
private func performPeriodicMaintenance(now: Date = Date()) {
|
||||
cleanupExpiredMessages()
|
||||
cleanupStaleAnnouncementsIfNeeded(now: now)
|
||||
requestSyncManager.cleanup() // Cleanup expired sync requests
|
||||
|
||||
for index in syncSchedules.indices {
|
||||
guard syncSchedules[index].interval > 0 else { continue }
|
||||
if syncSchedules[index].lastSent == .distantPast || now.timeIntervalSince(syncSchedules[index].lastSent) >= syncSchedules[index].interval {
|
||||
syncSchedules[index].lastSent = now
|
||||
sendPeriodicSync(for: syncSchedules[index].types)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private func cleanupStaleAnnouncementsIfNeeded(now: Date) {
|
||||
guard now.timeIntervalSince(lastStalePeerCleanup) >= config.stalePeerCleanupIntervalSeconds else {
|
||||
return
|
||||
}
|
||||
lastStalePeerCleanup = now
|
||||
cleanupStaleAnnouncements(now: now)
|
||||
}
|
||||
|
||||
private func cleanupStaleAnnouncements(now: Date) {
|
||||
let timeoutMs = UInt64(config.stalePeerTimeoutSeconds * 1000)
|
||||
let nowMs = UInt64(now.timeIntervalSince1970 * 1000)
|
||||
guard nowMs >= timeoutMs else { return }
|
||||
let cutoff = nowMs - timeoutMs
|
||||
let stalePeerIDs = latestAnnouncementByPeer.compactMap { peerID, pair in
|
||||
pair.packet.timestamp < cutoff ? peerID : nil
|
||||
}
|
||||
guard !stalePeerIDs.isEmpty else { return }
|
||||
for peerKey in stalePeerIDs {
|
||||
removeState(for: peerKey)
|
||||
}
|
||||
}
|
||||
|
||||
// Explicit removal hook for LEAVE/stale peer
|
||||
func removeAnnouncementForPeer(_ peerID: PeerID) {
|
||||
queue.async { [weak self] in
|
||||
self?.removeState(for: peerID)
|
||||
}
|
||||
}
|
||||
|
||||
private func removeState(for peerID: PeerID) {
|
||||
_ = latestAnnouncementByPeer.removeValue(forKey: peerID)
|
||||
messages.remove { PeerID(hexData: $0.senderID) == peerID }
|
||||
fragments.remove { PeerID(hexData: $0.senderID) == peerID }
|
||||
fileTransfers.remove { PeerID(hexData: $0.senderID) == peerID }
|
||||
}
|
||||
}
|
||||
|
||||
#if DEBUG
|
||||
extension GossipSyncManager {
|
||||
func _performMaintenanceSynchronously(now: Date = Date()) {
|
||||
queue.sync {
|
||||
performPeriodicMaintenance(now: now)
|
||||
}
|
||||
}
|
||||
|
||||
func _hasAnnouncement(for peerID: PeerID) -> Bool {
|
||||
queue.sync {
|
||||
latestAnnouncementByPeer[peerID] != nil
|
||||
}
|
||||
}
|
||||
|
||||
func _messageCount(for peerID: PeerID) -> Int {
|
||||
queue.sync {
|
||||
messages.allPackets { _ in true }.filter { PeerID(hexData: $0.senderID) == peerID }.count
|
||||
}
|
||||
}
|
||||
}
|
||||
#endif
|
||||