Encrypt clipboard text and file bytes at the engine with ChaCha20-Poly1305 (nonce‖ciphertext; clipboard base64'd into the text field) using a key derived from the shared account secret. Sealing happens BEFORE any transport, so LAN, the SSE relay, and RTC all carry only ciphertext — the server is reduced to pure signaling (presence/SDP/ICE), never content. RTC stays doubly protected under DTLS. Receive decrypts in the message + file sinks; undecryptable payloads (wrong key) are dropped. Plaintext passthrough when signed out (account=""). Honest caveat (in crypto.rs): the key is sha256(account) and the account is an email — low entropy, so this stops passive eavesdroppers but not someone who knows the account. The real fix is a high-entropy secret (Sign in with Apple `sub` / passphrase) → same from_secret() API. Verified by examples/e2e_demo.rs: B decrypts A's clipboard over LAN; a relayed send carries ciphertext only (plaintext never on the bus). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
32 lines
933 B
TOML
32 lines
933 B
TOML
[package]
|
|
name = "tethercore"
|
|
version = "0.1.0"
|
|
edition = "2021"
|
|
description = "Shared tether sync engine: codec + SSE client + reconnect, FFI-exported via UniFFI."
|
|
|
|
[lib]
|
|
# lib → examples/tests can link it natively
|
|
# staticlib → iOS .a / desktop agent
|
|
# cdylib → Android .so / bindgen library mode
|
|
crate-type = ["lib", "staticlib", "cdylib"]
|
|
name = "tethercore"
|
|
|
|
[[bin]]
|
|
name = "uniffi-bindgen"
|
|
path = "src/bin/uniffi-bindgen.rs"
|
|
|
|
[dependencies]
|
|
uniffi = { version = "0.28", features = ["cli"] }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream", "json"] }
|
|
tokio = { version = "1", features = ["rt-multi-thread", "time", "sync", "macros", "net", "io-util"] }
|
|
futures-util = "0.3"
|
|
webrtc = "0.17.1"
|
|
mdns-sd = "0.20.0"
|
|
sha2 = "0.11.0"
|
|
bytes = "1.12.0"
|
|
chacha20poly1305 = "0.10.1"
|
|
base64 = "0.22.1"
|
|
getrandom = "0.4.3"
|