Skip to content

feat(blockchain): owner-only nas-credentials action - #250

Merged
ehsan6sha merged 1 commit into
mainfrom
feat/nas-credentials-action
Oct 4, 2026
Merged

ehsan6sha merged 1 commit into
mainfrom
feat/nas-credentials-action

Conversation

@ehsan6sha

Copy link
Copy Markdown
Member

Summary

Adds an owner-only libp2p action nas-credentials that returns the blox's Samba NAS credentials (written by fula-ota's nas-credentials.sh to /internal/nas/credentials.json) so fxblox-web-app can show them to the owner.

  • Owner only: added to the actionAuth case in authorized(); delegated peers are excluded. No change to request signing or verification.
  • The request carries blox_peer_id, which must equal this blox's kubo peer ID, so an owner-signed request cannot be replayed to another blox.
  • 4 KiB read cap, Cache-Control: no-store, never logs the password. Statuses: 200 ok, 404 not_provisioned, 400 bad_request / blox_peer_mismatch, 503 unavailable, 500 malformed / error.
  • Client method NasCredentials for app/SDK callers.

Testing

  • go vet ./blockchain/ clean; go test ./blockchain/ -run NasCredentials passes: authorization matrix, every handler branch, and an end-to-end run through serveProxy (owner-signed 200; unsigned, delegated and stranger 401). linux/arm64 build passes.
  • On the RK3588 test blox with this build: the binary contains the action; unsigned and stranger-signed requests are rejected with 401 (the log shows the rejection at authorization for nas-credentials); the password never appears in the logs. The owner-signed success path needs the app owner's key, so it is covered by the unit tests.
  • Pre-existing failures on main are unchanged (TestBlockchainHealthCheck, TestRealContractIntegration, TestPoolDiscoveryWithMockServer).

Companion change: functionland/fula-ota (Samba LAN NAS + credentials file). fula-ota's release CI builds go-fula from this repo's main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01E9tV7663sXt1NFiCzM47wy

Returns the device's Samba NAS credentials (written by fula-ota's
nas-credentials.sh to /internal/nas/credentials.json) to the blox owner over
the existing signed libp2p channel, so the fxblox-web app can show them.

- Owner only: added to the actionAuth case in authorized(); delegated peers in
  authorizedPeers are excluded. No change to request signing or verification.
- The request carries blox_peer_id, which must equal this blox's kubo peer ID,
  so an owner-signed request cannot be replayed to another blox.
- 4 KiB read cap, Cache-Control: no-store, never logs the password. Statuses:
  200 ok, 404 not_provisioned, 400 bad_request / blox_peer_mismatch,
  503 unavailable, 500 malformed / error.
- Tests: authorization matrix, every handler branch, and an end-to-end run
  through serveProxy (owner-signed 200; unsigned, delegated and stranger 401).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E9tV7663sXt1NFiCzM47wy
@ehsan6sha
ehsan6sha merged commit 3a128a6 into main Oct 4, 2026
3 of 9 checks passed
@ehsan6sha
ehsan6sha deleted the feat/nas-credentials-action branch October 4, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant