NEC-93: Presence envelope: end-to-end encrypted, tagged by surface #144
No reviewers
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda!144
Loading…
Reference in a new issue
No description provided.
Delete branch "worktree-nec-93-presence-envelope-end-to-end-encrypted-ta"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Task: NEC-93 — https://projectron.nerchure.com/tasks/93
Seals presence (Yjs awareness) end to end. Each non-null state is now an AES-GCM envelope {e,k} under the folder content key, with AAD binding domain label, docName, clientID and clock. Plaintext is padded to 512-byte multiples, removals stay plain, and a client refuses any state that is not sealed. The server needs no code change, because it never read a state's contents. Also adds presence format v1 in packages/shared (surface-tagged pointer, viewport and selection) and the optional additionalData on shared encrypt/decrypt. Docs: crypto.md section 12 (CRYPTO-110..115); security-model.md now lists presence as metadata only, and says it is not authenticated as live. Review changes the approved plan in one place: the padding moved from 256 to 512 bytes, because 256 was measured to leak editor focus (y-codemirror nulls the cursor on blur: about 310 bytes focused, 140 not). Mutation-checked: AAD, plaintext refusal, epoch guard, send ordering and padding each fail their test when broken. Unchaining the receive side fails nothing, because y-protocols' clock check already rejects stale states, and CRYPTO-114 says so rather than claiming otherwise. Found and not fixed here, because it predates this change: close-time retraction leaves remote clocks unchanged, so the QueryAwareness reply after a reconnect is rejected, and peers reappear only on their next renewal (up to ~18 s). multiplexed-provider.ts's onclose comment claims otherwise. Held for human review by risk.mjs (e2ee-constrained, crypto sources, security model), as intended.
Spec:
docs/changes/NEC-93-presence-envelope/spec.mdChangelog
Presence (collaborators' names, colours and cursor positions) is now end-to-end encrypted, so the server can no longer see who is where in a note.
The local state now carries v: 1 and null pointer/viewport/selection. The server needed no change; a new test drives coalescing, QueryAwareness vouching and close retraction with envelopes and checks the bytes relayed are the sender's. The multi-vault presence e2e now also asserts the server's own Awareness holds only {e, k}. crypto.md gains section 12 (CRYPTO-110..115). security-model.md states that presence contents are sealed and its rate is not. Task: NEC-93 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018AVesyLGq78y4Zgn9oE8Awe6e0ddc1579f9ed905709f9ed90570fc272844acfc272844ac541382b010