feat: public guest discovery endpoints + privacy fix (v0.3.0) #17
2 changed files with 18 additions and 3 deletions
fix: strip checkin_instructions from public room dicts (privacy leak)
The AUTH_NONE RPC room endpoints (chatelet_room_list/_get) stripped wallet but NOT checkin_instructions — which was added in #5 after this code, so the operator's private access details (address, gate code) were leaking to any guest. Centralize a public_room_dict(room) helper (strips wallet + checkin_instructions) and route both doors through it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019VUQCfdqiLSsFS2jcGnaFD
commit
4d6dba5487
12
models.py
12
models.py
|
|
@ -17,6 +17,7 @@ Design notes carried into the field definitions:
|
|||
arbiter of "is this range open" — Nostr events are requests, not locks.
|
||||
"""
|
||||
|
||||
import json
|
||||
from datetime import datetime, timezone
|
||||
from enum import Enum
|
||||
|
||||
|
|
@ -194,6 +195,17 @@ class Block(BaseModel):
|
|||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def public_room_dict(room: Room) -> dict:
|
||||
"""A Room as public JSON for guests — strips operator-private fields: the
|
||||
wallet id, and the check-in instructions (address/gate code, delivered only
|
||||
in the encrypted post-payment DM). Shared by the HTTP and Nostr-RPC guest
|
||||
doors so neither can leak them."""
|
||||
d = json.loads(room.json())
|
||||
d.pop("wallet", None)
|
||||
d.pop("checkin_instructions", None)
|
||||
return d
|
||||
|
||||
|
||||
class AvailabilityQuery(BaseModel):
|
||||
room_id: str
|
||||
check_in: str # YYYY-MM-DD inclusive
|
||||
|
|
|
|||
|
|
@ -196,6 +196,9 @@ def _to_dict(obj) -> dict:
|
|||
|
||||
|
||||
def _public_room(room) -> dict:
|
||||
d = _to_dict(room)
|
||||
d.pop("wallet", None) # wallet id is operator-internal, not for guests
|
||||
return d
|
||||
# Shared with the HTTP door; strips wallet id AND checkin_instructions
|
||||
# (the latter was leaking to guests before — added after this file's
|
||||
# original public dict).
|
||||
from .models import public_room_dict
|
||||
|
||||
return public_room_dict(room)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue