R-105 (decision 169): retire the never-built slim DR record fields (no writer, no reader); 05 §9/§11, 06 §3.5 corrected
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -87,9 +87,9 @@ func (h *Handler) handleClearRecoveryMode(w http.ResponseWriter, r *http.Request
|
||||
type reEnrollResponse struct {
|
||||
HostID string `json:"host_id"`
|
||||
APIKeyRotated bool `json:"api_key_rotated"`
|
||||
Directive json.RawMessage `json:"directive"` // non-secret DR directive
|
||||
KEscrowB64 string `json:"k_escrow_b64"` // opaque PBS-key escrow blob
|
||||
IdentityEscrowB64 string `json:"identity_escrow_b64"` // opaque identity escrow blob
|
||||
Directive json.RawMessage `json:"directive"` // always {} — the directive is retired (R-105, decision 169); kept for the wire shape
|
||||
KEscrowB64 string `json:"k_escrow_b64"` // opaque PBS-key escrow blob
|
||||
IdentityEscrowB64 string `json:"identity_escrow_b64"` // opaque identity escrow blob
|
||||
}
|
||||
|
||||
// handleReEnroll is the re-enroll handshake (slice 10D.2). Gated ONLY on RECOVERY MODE (the lost box
|
||||
@@ -136,9 +136,6 @@ func (h *Handler) handleReEnroll(w http.ResponseWriter, r *http.Request, hostID
|
||||
if bundle, err := h.store.GetHostDRBundle(hostID); err == nil && bundle != nil {
|
||||
resp.KEscrowB64 = base64.StdEncoding.EncodeToString(bundle.KEscrowBlob)
|
||||
resp.IdentityEscrowB64 = base64.StdEncoding.EncodeToString(bundle.IdentityBlob)
|
||||
if bundle.DirectiveJSON != "" {
|
||||
resp.Directive = json.RawMessage(bundle.DirectiveJSON)
|
||||
}
|
||||
}
|
||||
h.logger.Printf("[INFO] DR: host %s RE-ENROLLED (hub credential rotated; old key revoked; directive served)", hostID)
|
||||
// The new key is returned so the box can use it; the operator sees the rotation in the response.
|
||||
@@ -175,9 +172,6 @@ func (h *Handler) handleGetRestoreDirective(w http.ResponseWriter, r *http.Reque
|
||||
if bundle, err := h.store.GetHostDRBundle(hostID); err == nil && bundle != nil {
|
||||
resp.KEscrowB64 = base64.StdEncoding.EncodeToString(bundle.KEscrowBlob)
|
||||
resp.IdentityEscrowB64 = base64.StdEncoding.EncodeToString(bundle.IdentityBlob)
|
||||
if bundle.DirectiveJSON != "" {
|
||||
resp.Directive = json.RawMessage(bundle.DirectiveJSON)
|
||||
}
|
||||
}
|
||||
writeJSON(w, http.StatusOK, resp)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user