mirror of
https://github.com/ipfs/kubo.git
synced 2025-09-09 19:32:24 +08:00
cache public keys and use better method for fetching
This commit is contained in:
@ -8,6 +8,7 @@ import (
|
||||
"github.com/ipfs/go-ipfs/Godeps/_workspace/src/golang.org/x/net/context"
|
||||
pb "github.com/ipfs/go-ipfs/namesys/internal/pb"
|
||||
ci "github.com/ipfs/go-ipfs/p2p/crypto"
|
||||
peer "github.com/ipfs/go-ipfs/p2p/peer"
|
||||
routing "github.com/ipfs/go-ipfs/routing"
|
||||
u "github.com/ipfs/go-ipfs/util"
|
||||
)
|
||||
@ -65,24 +66,38 @@ func (r *routingResolver) Resolve(ctx context.Context, name string) (u.Key, erro
|
||||
|
||||
// name should be a public key retrievable from ipfs
|
||||
// /ipfs/<name>
|
||||
key := u.Key("/pk/" + string(hash))
|
||||
pkval, err := r.routing.GetValue(ctx, key)
|
||||
if err != nil {
|
||||
log.Warning("RoutingResolve PubKey Get failed.")
|
||||
return "", err
|
||||
var pubkey ci.PubKey
|
||||
if dht, ok := r.routing.(routing.PubKeyFetcher); ok {
|
||||
// If we have a DHT as our routing system, use optimized fetcher
|
||||
pk, err := dht.GetPublicKey(ctx, peer.ID(hash))
|
||||
if err != nil {
|
||||
log.Warning("RoutingResolve PubKey Get failed.")
|
||||
return "", err
|
||||
}
|
||||
pubkey = pk
|
||||
} else {
|
||||
key := u.Key("/pk/" + string(hash))
|
||||
pkval, err := r.routing.GetValue(ctx, key)
|
||||
if err != nil {
|
||||
log.Warning("RoutingResolve PubKey Get failed.")
|
||||
return "", err
|
||||
}
|
||||
|
||||
// get PublicKey from node.Data
|
||||
pk, err := ci.UnmarshalPublicKey(pkval)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
pubkey = pk
|
||||
}
|
||||
|
||||
// get PublicKey from node.Data
|
||||
pk, err := ci.UnmarshalPublicKey(pkval)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
hsh, _ := pk.Hash()
|
||||
hsh, _ := pubkey.Hash()
|
||||
log.Debugf("pk hash = %s", u.Key(hsh))
|
||||
|
||||
// check sig with pk
|
||||
if ok, err := pk.Verify(ipnsEntryDataForSig(entry), entry.GetSignature()); err != nil || !ok {
|
||||
return "", fmt.Errorf("Invalid value. Not signed by PrivateKey corresponding to %v", pk)
|
||||
if ok, err := pubkey.Verify(ipnsEntryDataForSig(entry), entry.GetSignature()); err != nil || !ok {
|
||||
return "", fmt.Errorf("Invalid value. Not signed by PrivateKey corresponding to %v", pubkey)
|
||||
}
|
||||
|
||||
// ok sig checks out. this is a valid name.
|
||||
|
Reference in New Issue
Block a user