feat: Implement end-to-end encryption for channels

- Added EncryptionSalt and WrappedRoomKey properties to Channel model.
- Introduced RoomCrypto class for client-side encryption and decryption.
- Updated ChannelService to handle encrypted channels, including creation and rekeying.
- Modified ChannelsController to expose crypto metadata and rekey functionality.
- Enhanced IrcCommandHandler to block joining encrypted channels over IRC.
- Updated database schema with migration for new encryption fields.
- Refactored file validation and image processing services to accommodate encrypted channels.
- Added unit tests for RoomCrypto functionality and updated existing tests for channel services.
This commit is contained in:
HueByte
2026-07-16 03:50:23 +02:00
parent ea8e583ee5
commit e05b420ce9
36 changed files with 1400 additions and 67 deletions
@@ -390,6 +390,16 @@ public sealed class IrcCommandHandler
continue;
}
// End-to-end encrypted channels can't be read over IRC (the gateway would
// have to hold the room key server-side, defeating the privacy guarantee).
var crypto = await _channelService.GetChannelCryptoAsync(channelName);
if (crypto?.IsEncrypted == true)
{
await _conn.SendNumericAsync(ServerName, IrcNumericReply.ERR_BADCHANNELKEY,
$"#{channelName} :Cannot join channel — end-to-end encrypted, use the EchoHub client");
continue;
}
var (history, error, passwordRequired) = await _chatService.JoinChannelAsync(
_conn.ConnectionId, _conn.UserId!.Value, _conn.Nickname!, channelName, key);