feat(backend): self-managed TLS identity for the native app's encrypted LAN link
services/tls_identity.py creates an EC P-256 key + self-signed cert (10y,
SAN localhost/127.0.0.1/HOST_IP) under <data dir>/tls at startup, and
re-issues the cert with the SAME key when < 2 years remain. A cert that
doesn't belong to the key is replaced. Nothing to renew by hand; a backup of
the data directory keeps the identity. Runs in lifespan before the app is
healthy, so the proxy (which waits for healthy) always finds the files.
/api/system/identity and /api/system/status now include
tls: {port: TLS_PORT (default 8443), spki_sha256} - the base64 SHA-256 of the
public key that phones pin. Adds cryptography==46.0.4.
Tests: create / restart (no change) / renewal 8 years later keeps the key
and pin / foreign cert replaced; pin equals openssl's SPKI sha256.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -771,6 +771,9 @@ async def lifespan(app: FastAPI):
|
||||
ws_init_loop(loop)
|
||||
Base.metadata.create_all(bind=engine)
|
||||
_run_migrations()
|
||||
# Before the app reports healthy: the proxy's :8443 needs these files to start
|
||||
from services.tls_identity import ensure_tls_identity
|
||||
ensure_tls_identity()
|
||||
start_print_retry_thread()
|
||||
pruned = prune_old_events(hours=24)
|
||||
if pruned:
|
||||
|
||||
Reference in New Issue
Block a user