HubCredentials class

The shared secret for one hub session.

The secret is never transmitted — it is the HMAC key at both ends — so this holds up on plain ws://. TLS still matters for the confidentiality of session traffic, but not for protecting the credential.

Constructors

HubCredentials({required String session, required String secret})

Properties

hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
secret → String
The shared secret. Never sent over the wire and never logged.
final
session → String
The session name. Bound into the proof, and checked against every descriptor a peer publishes, so one hub is one session.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
Never renders the secret.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

computeProof({required String secret, required String nonce, required String session, required int epoch, required String nodeUId}) → String
The proof a client sends and the hub recomputes.
generateSecret() → String
Generates a secret suitable for handing to participants.
newNonce() → String
A fresh single-use challenge nonce.
secureEquals(String a, String b) → bool
Length-independent, content-constant-time comparison.