#7 add SCRAM-SHA-512 and document TLS 1.3 support
- Implement SCRAM-SHA-512 (RFC 5802 with SHA-512) as a Luma-side SaslMechanism and register it ahead of Martin's SHA-256/SHA-1/PLAIN, so modern servers preferring SHA-512 authenticate with it. - Verify the math against Python-computed reference vectors (salted password, client proof, server signature) in SCRAMSHA512Tests and guard the mechanism registration in Scripts/verify.sh. - Confirm the TLS stack negotiates TLS 1.3 (negotiatedSSL + ALPN via SecureTransport, handshake verified against a TLS 1.3-only server) and document the TLS/SCRAM posture in SECURITY.md.
This commit is contained in:
@@ -84,6 +84,8 @@ required=(
|
||||
Tests/SASLprepTests.swift
|
||||
Tests/SaslFailureMessageTests.swift
|
||||
Tests/MediaPreviewProcessorVideoTests.swift
|
||||
Tests/SCRAMSHA512Tests.swift
|
||||
Sources/Shared/XMPP/LumaScramSha512Mechanism.swift
|
||||
Sources/Shared/XMPP/SASLprep.swift
|
||||
Sources/Shared/XMPP/LumaSaslFailureModule.swift
|
||||
Sources/Shared/XMPP/SaslFailureMessage.swift
|
||||
@@ -321,6 +323,14 @@ grep -q 'passwordVisible' Sources/Shared/UI/LoginView.swift || {
|
||||
echo "The login screen must let the user verify the typed password"
|
||||
exit 1
|
||||
}
|
||||
grep -q 'SCRAM-SHA-512' Sources/Shared/XMPP/LumaScramSha512Mechanism.swift || {
|
||||
echo "The SCRAM-SHA-512 mechanism must be available"
|
||||
exit 1
|
||||
}
|
||||
grep -q 'addMechanism(LumaScramSha512Mechanism' Sources/Shared/XMPP/XMPPService.swift || {
|
||||
echo "SCRAM-SHA-512 must be registered ahead of Martin's mechanisms"
|
||||
exit 1
|
||||
}
|
||||
grep -q 'func deleteGroupChat' Sources/Shared/Models/AppModel.swift || {
|
||||
echo "Group chats must support local deletion"
|
||||
exit 1
|
||||
|
||||
Reference in New Issue
Block a user