Port pluggable cryptography and re-wire current cryptography as default
@gkc ci sta già lavorando.
Dal 1/9/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Is your feature request related to a problem? Please describe.
The current cyrptography is hard coded in SelfKeyCommands, SharedKeyCommands, PublicKeyCommands and both of AtClientImpl's notification handlers. An application cannot supply a different scheme.
NOTE: Metadata.AppMetadata — the field that would carry the cryptography scheme / provider — already exists on trunk but nothing in the repo reads or writes it.
Describe the solution you'd like
A new interface CryptographyProvider which defines 2 methods encrypt/decrypt. This is mirrors CryptoProvider in Dart.
The existing cryptography is moved into an implementation LegacyCryptographyProvider. This mirrors LegacyCryptoProvider in Dart.
RuntimeCryptographyProvider is a implementation with a map of registered implementations keyed by provider ids. It's encrypt/decrypt implementation will delegate to a registered implementation based on the key Metadata.AppMetadata. Where this is not set it will default.
AtClientImpl and the static command method it invokes to execute at server commands will be modified to invoke a CryptographyProvider.
AtClients builder will be modified to pass a RuntimeCryptographyProvider, with LegacyCryptoProvider as the default, to the AtClientImpl it constructs.
Dart mapping
| Dart | Java |
|---|---|
CryptoProvider (crypto.dart) |
CryptographyProvider (api) |
CryptoProvider.id |
dropped — the id is the registry key, not provider behaviour |
CryptoContext {atClient, atKeysIo} (crypto.dart) |
dropped — (AtCommandExecutor, AtCommandExecutorContext) |
CryptoConfig {defaultProviderId, providers, lookup} (crypto.dart) |
dropped — RuntimeCryptographyProvider's builder |
CryptoConfig.lookup(id) linear scan over a List |
Map<CryptographyProviderId, CryptographyProvider> |
legacyCryptoProviderId = 'legacy' (crypto.dart) |
CryptographyProviderId.LEGACY — same wire literal |
CryptoRuntime (crypto_runtime.dart) |
RuntimeCryptographyProvider (impl.crypto) |
encryptForPut / encryptForNotification |
CryptographyProvider.encrypt |
decryptForGet / decryptForNotification / decryptForSyncConflict |
CryptographyProvider.decrypt |
LegacyCryptoProvider (legacy/legacy_crypto_provider.dart) |
LegacyCryptographyProvider (impl.crypto) |
LegacyEncryption.build / LegacyDecryption.build runtime key sniffing |
private methods per Keys.AtKey subtype |
SelfKeyEncryption / SelfKeyDecryption |
encryptSelfKey / decryptSelfKey |
SharedKeyEncryption / SharedByMeDecryption / SharedWithMeDecryption |
encryptSharedKey / decryptSharedKey |
AbstractAtKeyEncryption (shared-key management) |
the shared-key helpers inside LegacyCryptographyProvider |
AppMetadata.providerId (String, at_commons) |
Metadata.AppMetadata.providerId typed as CryptographyProviderId |
Describe alternatives you've considered
like for like mapping
Additional context
No response
- Lingua principale
- Java
- Stelle
- 2
- Fork
- 19
- Merge medio
- 23h 2m
- PR unite (30g)
- 8
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di atsign-foundation/at_java
-
Port Dart's typed atKeys key material to at_java, with Dart-interoperable JSONForse già presa @gkc l’ha presa 27 giorni fa. Apertaenhancement
atsign-foundation/at_java#425 · 1 assegnatario ·
-
Generate a SBOM and SLSA attestations during the release workflowForse di nuovo libera @cpswan l’ha presa 182 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#383 · 3 commenti · 2 assegnatari ·
-
Enhance Activate utility such that it has feature parity with dart activate_cliForse di nuovo libera @akafredperry l’ha presa 244 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#338 · 1 assegnatario ·
-
Should Activate utility be migrated to an AtActivationClient interface and implementation in the api package?Forse di nuovo libera @akafredperry l’ha presa 244 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#334 · 1 assegnatario ·
-
Introduce a protocol package and migrate all code that builds at protocol commands and interprets at protocol responses and notificationsForse di nuovo libera @akafredperry l’ha presa 244 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#335 · 2 commenti · 1 assegnatario ·
Tutte le issue di atsign-foundation/at_java
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
component/zeebe kind/bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
UniversalMediaServer/UniversalMediaServer#6356 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
refinedmods/refinedstorage2#1414 · 1 commento ·
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
yegor256/rultor-image#76 · 1 commento ·