summaryrefslogtreecommitdiff
path: root/crates/tor-rpc-connect/src/auth
Commit message (Collapse)AuthorAgeFilesLines
* rpc-connect: Abort on misformed cookie file, and explain why.Nick Mathewson2025-01-271-6/+3
|
* rpc-connect: Use file_access() API, and permit symlinks.Nick Mathewson2025-01-271-7/+11
|
* rpc: Expose Cookie::load unconditionally.Nick Mathewson2025-01-151-2/+0
|
* rpc: Use symbolic constants for nonce/mac lengths.Nick Mathewson2025-01-151-7/+14
|
* rpc: Tests for cookie nonce/mac encoding/decoding.Nick Mathewson2025-01-151-2/+46
| | | | Also fix a bug in decoding, where we accepted too-short strings.
* rpc: Tweak cookie protocol to bind both nonces.Nick Mathewson2025-01-151-2/+8
| | | | | | | | | | Previously participants in the cookie protocol only bound the peer nonce in their MACs. With this change, they bind both nonces. This change is _probably_ not necessary for security, but it can't hurt. It follows a general principle that Adam Langley told me a long time ago: you won't regret binding more, but you might regret binding less.
* arti-rpcserver: Server side of cookie auth.Nick Mathewson2025-01-151-2/+25
|
* tor-rpc-connect: Cryptographic support for cookie auth.Nick Mathewson2025-01-151-2/+208
| | | | Conforms to rpc-cookie-sketch.md.
* tor-rpc-connect: defer loading auth cookies on the client side.Nick Mathewson2025-01-151-1/+22
| | | | | We want to load cookies only after we've connected and gotten a banner.
* tor-rpc-connect: move cookie auth support to its own module.Nick Mathewson2025-01-151-0/+167