computeProof static method

String computeProof({
  1. required String secret,
  2. required String nonce,
  3. required String session,
  4. required int epoch,
  5. required String nodeUId,
})

The proof a client sends and the hub recomputes.

The nonce makes it single-use, session and epoch bind it to this session generation — so ending a session invalidates every outstanding proof — and nodeUId binds it to the identity the peer then publishes descriptors under, which is what stops one authenticated peer claiming another's endpoints.

Implementation

static String computeProof({
  required String secret,
  required String nonce,
  required String session,
  required int epoch,
  required String nodeUId,
}) => base64.encode(
  Hmac(
    sha256,
    utf8.encode(secret),
  ).convert(utf8.encode('$nonce|$session|$epoch|$nodeUId')).bytes,
);