Full codebase review by 4 independent agents (security, architecture,
code quality, correctness) identified ~80 findings. This commit fixes 40
of them across all workspace crates.
Critical fixes:
- Federation service: validate origin against mTLS cert CN/SAN (C1)
- WS bridge: add DM channel auth, size limits, rate limiting (C2)
- hpke_seal: panic on error instead of silent empty ciphertext (C3)
- hpke_setup_sender_and_export: error on parse fail, no PQ downgrade (C7)
Security fixes:
- Zeroize: seed_bytes() returns Zeroizing<[u8;32]>, private_to_bytes()
returns Zeroizing<Vec<u8>>, ClientAuth.access_token, SessionState.password,
conversation hex_key all wrapped in Zeroizing
- Keystore: 0o600 file permissions on Unix
- MeshIdentity: 0o600 file permissions on Unix
- Timing floors: resolveIdentity + WS bridge resolve_user get 5ms floor
- Mobile: TLS verification gated behind insecure-dev feature flag
- Proto: from_bytes default limit tightened from 64 MiB to 8 MiB
Correctness fixes:
- fetch_wait: register waiter before fetch to close TOCTOU window
- MeshEnvelope: exclude hop_count from signature (forwarding no longer
invalidates sender signature)
- BroadcastChannel: encrypt returns Result instead of panicking
- transcript: rename verify_transcript_chain → validate_transcript_structure
- group.rs: extract shared process_incoming() for receive_message variants
- auth_ops: remove spurious RegistrationRequest deserialization
- MeshStore.seen: bounded to 100K with FIFO eviction
Quality fixes:
- FFI error classification: typed downcast instead of string matching
- Plugin HookVTable: SAFETY documentation for unsafe Send+Sync
- clippy::unwrap_used: warn → deny workspace-wide
- Various .unwrap_or("") → proper error returns
Review report: docs/REVIEW-2026-03-04.md
152 tests passing (72 core + 35 server + 14 E2E + 1 doctest + 30 P2P)
96 lines
2.8 KiB
TOML
96 lines
2.8 KiB
TOML
[package]
|
|
name = "quicproquo-client"
|
|
version = "0.1.0"
|
|
edition = "2021"
|
|
description = "CLI client for quicproquo."
|
|
license = "MIT"
|
|
|
|
[[bin]]
|
|
name = "qpq"
|
|
path = "src/main.rs"
|
|
|
|
[dependencies]
|
|
quicproquo-core = { path = "../quicproquo-core" }
|
|
quicproquo-proto = { path = "../quicproquo-proto" }
|
|
quicproquo-kt = { path = "../quicproquo-kt" }
|
|
openmls_rust_crypto = { workspace = true }
|
|
|
|
# Serialisation + RPC
|
|
capnp = { workspace = true }
|
|
capnp-rpc = { workspace = true }
|
|
|
|
# Async
|
|
tokio = { workspace = true }
|
|
tokio-util = { workspace = true }
|
|
futures = { workspace = true }
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
bincode = { workspace = true }
|
|
|
|
# Crypto — OPAQUE PAKE
|
|
opaque-ke = { workspace = true }
|
|
rand = { workspace = true }
|
|
|
|
# Error handling
|
|
anyhow = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
|
|
# Crypto — for fingerprint verification in fetch-key subcommand
|
|
sha2 = { workspace = true }
|
|
argon2 = { workspace = true }
|
|
chacha20poly1305 = { workspace = true }
|
|
ciborium = { workspace = true }
|
|
zeroize = { workspace = true }
|
|
quinn = { workspace = true }
|
|
quinn-proto = { workspace = true }
|
|
rustls = { workspace = true }
|
|
|
|
# Logging
|
|
tracing = { workspace = true }
|
|
tracing-subscriber = { workspace = true }
|
|
|
|
# CLI
|
|
clap = { workspace = true }
|
|
|
|
# Local message/conversation storage
|
|
rusqlite = { workspace = true }
|
|
|
|
# Hex encoding/decoding
|
|
hex = { workspace = true }
|
|
|
|
# Secure password prompting (no echo)
|
|
rpassword = "5"
|
|
|
|
# mDNS discovery for mesh mode (Freifunk). Only compiled with --features mesh.
|
|
mdns-sd = { version = "0.12", optional = true }
|
|
|
|
# Optional P2P transport for direct node-to-node messaging.
|
|
quicproquo-p2p = { path = "../quicproquo-p2p", optional = true }
|
|
|
|
# Optional TUI dependencies (Ratatui full-screen interface).
|
|
ratatui = { version = "0.29", optional = true, default-features = false, features = ["crossterm"] }
|
|
crossterm = { version = "0.28", optional = true }
|
|
|
|
# YAML playbook parsing (only compiled with --features playbook).
|
|
serde_yaml = { version = "0.9", optional = true }
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[features]
|
|
# Enable mesh-mode features: mDNS local peer discovery + P2P transport.
|
|
# Build: cargo build -p quicproquo-client --features mesh
|
|
mesh = ["dep:mdns-sd", "dep:quicproquo-p2p"]
|
|
# Enable full-screen Ratatui TUI: cargo build -p quicproquo-client --features tui
|
|
tui = ["dep:ratatui", "dep:crossterm"]
|
|
# Enable playbook (scripted command execution): YAML parser + serde derives.
|
|
# Build: cargo build -p quicproquo-client --features playbook
|
|
playbook = ["dep:serde_yaml"]
|
|
|
|
[dev-dependencies]
|
|
dashmap = { workspace = true }
|
|
assert_cmd = "2"
|
|
tempfile = "3"
|
|
portpicker = "0.1"
|
|
rand = "0.8"
|