2026-06-13 01:12:55 -07:00
|
|
|
import Foundation
|
|
|
|
|
import Security
|
|
|
|
|
import NucleicProtocol
|
2026-07-03 23:59:29 -07:00
|
|
|
#if canImport(UIKit)
|
|
|
|
|
import UIKit
|
|
|
|
|
#endif
|
2026-06-13 01:12:55 -07:00
|
|
|
|
|
|
|
|
/// What the phone pins about its Mac at pairing (SYNC §4.2): the host's static key (for IK
|
2026-07-03 03:50:45 -07:00
|
|
|
/// reconnect), a display name, and the transport + connection hint from the QR — LAN
|
|
|
|
|
/// host:port or the Mac's tailnet IP. The pairing secret is *not* stored — it's one-time.
|
|
|
|
|
/// Non-secret, so UserDefaults is fine; the device private key goes to Keychain. The new
|
|
|
|
|
/// optional fields decode as nil from a pre-transport record (= LAN).
|
2026-06-13 01:12:55 -07:00
|
|
|
struct PairedHost: Codable, Equatable {
|
|
|
|
|
var deviceID: String
|
|
|
|
|
var hostName: String
|
|
|
|
|
var hostStaticKey: Data
|
|
|
|
|
var fingerprint: String
|
|
|
|
|
var lanHost: String?
|
|
|
|
|
var lanPort: UInt16?
|
2026-07-03 03:50:45 -07:00
|
|
|
/// `SyncTransportHint` raw value; nil = LAN (records saved before transports existed).
|
|
|
|
|
var transport: String?
|
|
|
|
|
var tailnetHost: String?
|
|
|
|
|
var tailnetPort: UInt16?
|
|
|
|
|
|
|
|
|
|
var transportHint: SyncTransportHint { transport.flatMap(SyncTransportHint.init(rawValue:)) ?? .lan }
|
2026-06-13 01:12:55 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// Loads/persists this device's long-term `DeviceIdentity` (Keychain) and the pinned host
|
|
|
|
|
/// (UserDefaults). The identity is generated once on first launch and reused thereafter.
|
|
|
|
|
enum IdentityStore {
|
2026-06-26 16:52:14 -07:00
|
|
|
private static let keychainAccount = "xyz.blakeslee.nucleic.remote.identity"
|
2026-06-13 01:12:55 -07:00
|
|
|
private static let pairedHostKey = "nucleic.pairedHost"
|
|
|
|
|
private static let deviceIDKey = "nucleic.deviceID"
|
|
|
|
|
|
|
|
|
|
static func loadOrCreateIdentity() -> DeviceIdentity {
|
|
|
|
|
if let data = keychainRead(), let identity = try? DeviceIdentity(importingRaw: data) {
|
|
|
|
|
return identity
|
|
|
|
|
}
|
|
|
|
|
let identity = DeviceIdentity()
|
|
|
|
|
keychainWrite(identity.exportRaw())
|
|
|
|
|
return identity
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// Stable per-install device id (re-used across reconnects so the host can match the pin).
|
|
|
|
|
static func deviceID() -> String {
|
|
|
|
|
let defaults = UserDefaults.standard
|
|
|
|
|
if let existing = defaults.string(forKey: deviceIDKey) { return existing }
|
2026-07-03 23:59:29 -07:00
|
|
|
let id = deviceIDPrefix + UUID().uuidString.prefix(8).lowercased()
|
2026-06-13 01:12:55 -07:00
|
|
|
defaults.set(id, forKey: deviceIDKey)
|
|
|
|
|
return id
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-03 23:59:29 -07:00
|
|
|
/// Idiom-tagged prefix so the host lists a paired device with the right kind/icon
|
|
|
|
|
/// (`ipad-…` vs `iphone-…`). Only stamps *freshly generated* ids — an existing install
|
|
|
|
|
/// keeps whatever id it already persisted, so upgrading a phone never changes its identity.
|
|
|
|
|
private static var deviceIDPrefix: String {
|
|
|
|
|
#if canImport(UIKit)
|
|
|
|
|
return UIDevice.current.userInterfaceIdiom == .pad ? "ipad-" : "iphone-"
|
|
|
|
|
#else
|
|
|
|
|
return "iphone-"
|
|
|
|
|
#endif
|
|
|
|
|
}
|
|
|
|
|
|
2026-06-13 01:12:55 -07:00
|
|
|
static func loadPairedHost() -> PairedHost? {
|
|
|
|
|
guard let data = UserDefaults.standard.data(forKey: pairedHostKey) else { return nil }
|
|
|
|
|
return try? JSONDecoder().decode(PairedHost.self, from: data)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
static func savePairedHost(_ host: PairedHost) {
|
|
|
|
|
if let data = try? JSONEncoder().encode(host) {
|
|
|
|
|
UserDefaults.standard.set(data, forKey: pairedHostKey)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
static func clearPairedHost() {
|
|
|
|
|
UserDefaults.standard.removeObject(forKey: pairedHostKey)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// MARK: - Keychain
|
|
|
|
|
|
|
|
|
|
private static func keychainRead() -> Data? {
|
|
|
|
|
let query: [String: Any] = [
|
|
|
|
|
kSecClass as String: kSecClassGenericPassword,
|
|
|
|
|
kSecAttrAccount as String: keychainAccount,
|
|
|
|
|
kSecReturnData as String: true,
|
|
|
|
|
kSecMatchLimit as String: kSecMatchLimitOne,
|
|
|
|
|
]
|
|
|
|
|
var item: CFTypeRef?
|
|
|
|
|
guard SecItemCopyMatching(query as CFDictionary, &item) == errSecSuccess else { return nil }
|
|
|
|
|
return item as? Data
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private static func keychainWrite(_ data: Data) {
|
|
|
|
|
let delete: [String: Any] = [
|
|
|
|
|
kSecClass as String: kSecClassGenericPassword,
|
|
|
|
|
kSecAttrAccount as String: keychainAccount,
|
|
|
|
|
]
|
|
|
|
|
SecItemDelete(delete as CFDictionary)
|
|
|
|
|
let add: [String: Any] = [
|
|
|
|
|
kSecClass as String: kSecClassGenericPassword,
|
|
|
|
|
kSecAttrAccount as String: keychainAccount,
|
|
|
|
|
kSecValueData as String: data,
|
|
|
|
|
kSecAttrAccessible as String: kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly,
|
|
|
|
|
]
|
|
|
|
|
SecItemAdd(add as CFDictionary, nil)
|
|
|
|
|
}
|
|
|
|
|
}
|