computeProof static method
The proof a client sends and the hub recomputes.
The nonce makes it single-use, session and epoch bind it to this
session generation — so ending a session invalidates every outstanding
proof — and nodeUId binds it to the identity the peer then publishes
descriptors under, which is what stops one authenticated peer claiming
another's endpoints.
Implementation
static String computeProof({
required String secret,
required String nonce,
required String session,
required int epoch,
required String nodeUId,
}) => base64.encode(
Hmac(
sha256,
utf8.encode(secret),
).convert(utf8.encode('$nonce|$session|$epoch|$nodeUId')).bytes,
);