mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-26 17:25:22 +00:00
Closes the last cleartext private-content path over BLE: private DM images/voice were sent as plaintext signed fileTransfer packets, TTL-relayed across the mesh, so every relay saw the full bytes. Now the complete BitchatFilePacket is encrypted as a single Noise AEAD message (inner type 0x20, matching Android) and the opaque ciphertext is fragmented. Adds an authenticated in-session capability proof (0x21 TLV: capabilities + Ed25519 key), TOFU-style downgrade pinning, a per-send consent dialog for the signed-cleartext fallback to legacy peers, and a cancellation/admission registry so cancel/delete cannot race a deferred cleartext send. Android wire constants (0x20 / 0x21 / capability bit 8) confirmed shipping. The 256-fragment preflight cap applies only to the directed fileTransfer migration fallback; encrypted media to capable peers uses the full receiver ceiling. Rebased over #1428/#1349: identity reads go through BLELocalIdentityStateStore; the session-bound authenticated signing-key check and the announce-path TOFU pin are kept as complementary checks. Full local suite green (1744+197 tests).
42 lines
1.1 KiB
Swift
42 lines
1.1 KiB
Swift
//
|
|
// NoisePayload.swift
|
|
// bitchat
|
|
//
|
|
// This is free and unencumbered software released into the public domain.
|
|
// For more information, see <https://unlicense.org>
|
|
//
|
|
|
|
import Foundation
|
|
|
|
/// Helper to create typed Noise payloads
|
|
struct NoisePayload {
|
|
let type: NoisePayloadType
|
|
let data: Data
|
|
|
|
/// Encode payload with type prefix
|
|
func encode() -> Data {
|
|
var encoded = Data()
|
|
encoded.append(type.rawValue)
|
|
encoded.append(data)
|
|
return encoded
|
|
}
|
|
|
|
/// Decode payload from data
|
|
static func decode(_ data: Data) -> NoisePayload? {
|
|
// Ensure we have at least 1 byte for the type
|
|
guard !data.isEmpty else {
|
|
return nil
|
|
}
|
|
|
|
// Safely get the first byte
|
|
let firstByte = data[data.startIndex]
|
|
guard let type = NoisePayloadType.decoded(rawValue: firstByte) else {
|
|
return nil
|
|
}
|
|
|
|
// Create a proper Data copy (not a subsequence) for thread safety
|
|
let payloadData = data.count > 1 ? Data(data.dropFirst()) : Data()
|
|
return NoisePayload(type: type, data: payloadData)
|
|
}
|
|
}
|