mirror of
https://github.com/lightninglabs/lightning-terminal.git
synced 2026-08-13 12:33:36 +02:00
terminal: tag and detect super macaroon
Because we're now potentially baking more than just one internal supermacaroon, we can't compare it with that single macaroon anymore. Instead we mark the super macaroons with a specific ID that we can then later use to detect it again.
This commit is contained in:
parent
1ff2411cfe
commit
9444927722
1 changed files with 8 additions and 15 deletions
23
terminal.go
23
terminal.go
|
|
@ -218,11 +218,7 @@ func (g *LightningTerminal) Run() error {
|
|||
),
|
||||
}
|
||||
allOpts = append(allOpts, opts...)
|
||||
mailboxGrpcServer := grpc.NewServer(allOpts...)
|
||||
|
||||
_ = g.RegisterGrpcSubserver(mailboxGrpcServer)
|
||||
|
||||
return mailboxGrpcServer
|
||||
return grpc.NewServer(allOpts...)
|
||||
},
|
||||
)
|
||||
g.sessionRpcServer = &sessionRpcServer{
|
||||
|
|
@ -509,7 +505,10 @@ func (g *LightningTerminal) startSubservers() error {
|
|||
// faraday, loop, and pool, all at the same time.
|
||||
ctx := context.Background()
|
||||
superMacaroon, err := bakeSuperMacaroon(
|
||||
ctx, g.basicClient, 0, getAllPermissions(false), nil,
|
||||
ctx, g.basicClient, session.NewSuperMacaroonRootKeyID(
|
||||
[4]byte{},
|
||||
),
|
||||
getAllPermissions(false), nil,
|
||||
)
|
||||
if err != nil {
|
||||
return err
|
||||
|
|
@ -654,8 +653,7 @@ func (g *LightningTerminal) ValidateMacaroon(ctx context.Context,
|
|||
// which we can just pass straight to lnd for validation. But the user
|
||||
// might still be using a specific macaroon, which should be handled the
|
||||
// same as before.
|
||||
isSuperMacaroon := macHex == g.rpcProxy.superMacaroon
|
||||
if g.cfg.LndMode == ModeIntegrated && isSuperMacaroon {
|
||||
if g.cfg.LndMode == ModeIntegrated && session.IsSuperMacaroon(macHex) {
|
||||
macBytes, err := hex.DecodeString(macHex)
|
||||
if err != nil {
|
||||
return err
|
||||
|
|
@ -1160,23 +1158,18 @@ func bakeSuperMacaroon(ctx context.Context, lnd lnrpc.LightningClient,
|
|||
return "", err
|
||||
}
|
||||
|
||||
macBytes, err := hex.DecodeString(res.Macaroon)
|
||||
mac, err := session.ParseMacaroon(res.Macaroon)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
var mac macaroon.Macaroon
|
||||
if err := mac.UnmarshalBinary(macBytes); err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
for _, caveat := range caveats {
|
||||
if err := mac.AddFirstPartyCaveat(caveat.Id); err != nil {
|
||||
return "", err
|
||||
}
|
||||
}
|
||||
|
||||
macBytes, err = mac.MarshalBinary()
|
||||
macBytes, err := mac.MarshalBinary()
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue