HubCredentials class
The shared secret for one hub session.
The secret is never transmitted — it is the HMAC key at both ends — so this
holds up on plain ws://. TLS still matters for the confidentiality of
session traffic, but not for protecting the credential.
Constructors
- HubCredentials({required String session, required String secret})
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- secret → String
-
The shared secret. Never sent over the wire and never logged.
final
- session → String
-
The session name. Bound into the proof, and checked against every
descriptor a peer publishes, so one hub is one session.
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
Never renders the secret.
override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Static Methods
-
computeProof(
{required String secret, required String nonce, required String session, required int epoch, required String nodeUId}) → String - The proof a client sends and the hub recomputes.
-
generateSecret(
) → String - Generates a secret suitable for handing to participants.
-
newNonce(
) → String - A fresh single-use challenge nonce.
-
secureEquals(
String a, String b) → bool - Length-independent, content-constant-time comparison.