From 2024bb526a3d130c93cad0a1abf2bbb43e466466 Mon Sep 17 00:00:00 2001 From: VasilevNStas Date: Sun, 28 Jun 2026 19:43:36 +0300 Subject: [PATCH] =?UTF-8?q?docs(auth):=20fix=20client=5Fid=20origin=20?= =?UTF-8?q?=E2=80=94=20client=20generates=20it,=20not=20Hub?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- auth.proto | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/auth.proto b/auth.proto index c5b1ba5..cd466bf 100644 --- a/auth.proto +++ b/auth.proto @@ -9,14 +9,10 @@ package proto; // against its current (and previous) pre-shared key and uses the // recovered identity to set up the tunnel session. message Auth { - // Stable client identifier. MUST be exactly nine bytes. The HMAC - // (field 3) covers (client_id || timestamp); any other length - // passes the wire and the HMAC verifies cleanly against the same - // non-nine-byte input on both sides, silently breaking the - // identity contract. Both sender and receiver MUST validate the - // length before computing or checking the HMAC. Not a UUID — the - // client generates it once per installation using a CSPRNG and - // persists it across launches. + // Stable client identifier, exactly nine raw UTF-8 bytes; signed + // by the HMAC together with timestamp. Not a UUID — the client + // generates it once per installation using a cryptographically + // secure RNG and persists it across launches. bytes client_id = 1; // Minutes since the project epoch (2024-01-01 UTC), used as a