<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mirrors/arti.git/crates/arti-rpcserver/src/connection/auth, branch arti-v1.8.0</title>
<subtitle>mirror of https://gitlab.torproject.org/tpo/core/arti
</subtitle>
<id>http://git.dilluti0n.com/mirrors/arti.git/atom?h=arti-v1.8.0</id>
<link rel='self' href='http://git.dilluti0n.com/mirrors/arti.git/atom?h=arti-v1.8.0'/>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/'/>
<updated>2025-08-07T15:28:36Z</updated>
<entry>
<title>Switch Cargo.toml files to edition 2024.</title>
<updated>2025-08-07T15:28:36Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-08-06T01:19:58Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=77b0de43b8c67cdb81befe0680a3df43b6ad37bc'/>
<id>urn:sha1:77b0de43b8c67cdb81befe0680a3df43b6ad37bc</id>
<content type='text'>
First, run

```
git grep -l "^edition =" |
    xargs perl -i -pe 's/^edition *=.*/edition = "2024"/;'
```

Second, manually verify that all Cargo.toml files have changed,
and nothing else has changed.

Third, run cargo fmt again.
</content>
</entry>
<entry>
<title>squash! Upgrade rand dependency to 0.9.</title>
<updated>2025-03-18T16:09:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-03-18T13:01:31Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=2f8993c22c2b86010e4fd8b5169ef0ab83f8c754'/>
<id>urn:sha1:2f8993c22c2b86010e4fd8b5169ef0ab83f8c754</id>
<content type='text'>
- `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
</content>
</entry>
<entry>
<title>rpcserver: Remove stale TODO about authentication</title>
<updated>2025-01-28T19:50:22Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-28T19:50:22Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=46b7be36420cd151aaf6ea32335cfd578604a9a5'/>
<id>urn:sha1:46b7be36420cd151aaf6ea32335cfd578604a9a5</id>
<content type='text'>
(This TODO dates back to the point before we had sessions.)
</content>
</entry>
<entry>
<title>rpcserver: Improve conversion of authentication error.</title>
<updated>2025-01-28T19:29:15Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-28T19:29:15Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=dc29f9cbfc8e03a6ed1c32d6c079fa8b0d48f623'/>
<id>urn:sha1:dc29f9cbfc8e03a6ed1c32d6c079fa8b0d48f623</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rpc: More documentation on cookie_continue.</title>
<updated>2025-01-15T20:13:39Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-15T20:13:39Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=d6acbeadba6ffcff6fde00fc488abf5a8c652e24'/>
<id>urn:sha1:d6acbeadba6ffcff6fde00fc488abf5a8c652e24</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rpc: Clarify auth-repetition rules.</title>
<updated>2025-01-15T14:18:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-15T14:09:31Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=bdbddedea0a5b8158e57e41ce141bc4424186f89'/>
<id>urn:sha1:bdbddedea0a5b8158e57e41ce141bc4424186f89</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rpc: Document cookie messages a little more.</title>
<updated>2025-01-15T14:18:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-15T14:04:46Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=f2398569b460bf965dbaac5e7546a2125a9f5a14'/>
<id>urn:sha1:f2398569b460bf965dbaac5e7546a2125a9f5a14</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rpc: Refactor Cookie and UnloadedCookie into a single type.</title>
<updated>2025-01-15T14:18:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-15T13:39:23Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=6e0f70d08f437bd593f5e564594dd8a44036c72c'/>
<id>urn:sha1:6e0f70d08f437bd593f5e564594dd8a44036c72c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rpc: consolodate naming of "inherent" auth.</title>
<updated>2025-01-15T14:18:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-09T21:15:51Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=c6445825bc933a248c1b0b11f0baef43f4182de6'/>
<id>urn:sha1:c6445825bc933a248c1b0b11f0baef43f4182de6</id>
<content type='text'>
We don't want to call this "unix path" anywhere, since it
corresponds to _any_ case where the ability to negotiate a
successful connection means that the client is authorized.

We also don't want to call it "none": The authentication
is inherent to the connection, not nonexistent.
</content>
</entry>
<entry>
<title>rpc: Tweak cookie protocol to bind both nonces.</title>
<updated>2025-01-15T14:18:44Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2025-01-09T19:55:50Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=f3fcd71f218595402175c2530a09dabb7ed10f9d'/>
<id>urn:sha1:f3fcd71f218595402175c2530a09dabb7ed10f9d</id>
<content type='text'>
Previously participants in the cookie protocol only bound the peer
nonce in their MACs.  With this change, they bind both nonces.

This change is _probably_ not necessary for security, but it can't
hurt.  It follows a general principle that Adam Langley told me a
long time ago: you won't regret binding more, but you might regret
binding less.
</content>
</entry>
</feed>
