Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
183 changes: 167 additions & 16 deletions Cargo.lock

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
[workspace]
members = ["crates/plugin-manager", "crates/agent-controller", "crates/credential-store", "src-tauri"]
members = ["crates/pairing", "crates/plugin-manager", "crates/agent-controller", "crates/credential-store", "src-tauri"]
Comment thread
kalvinnchau marked this conversation as resolved.
default-members = ["crates/plugin-manager"]
resolver = "2"
18 changes: 18 additions & 0 deletions crates/pairing/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
[package]
name = "buzz-pairing"
version = "0.0.0"
edition = "2021"
license = "Apache-2.0"
description = "Buzz NIP-AB device pairing protocol"

[dependencies]
nostr = { version = "0.44", features = ["nip44"] }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "2"
hex = "0.4"
rand = "0.10"
subtle = "2.6"
zeroize = "1.8"
percent-encoding = "2.3"
url = "2"
26 changes: 26 additions & 0 deletions crates/pairing/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Buzz pairing protocol

Ported from [`block/buzz`](https://github.com/block/buzz/tree/ac0ad7c3004683e5db813492846d787404a2b475/crates/buzz-core/src/pairing),
PR [#8085](https://github.com/block/buzz/pull/8085), under the repository's
Apache-2.0 license. The imported protocol and tests preserve the source's
cryptography, event validation, timeout, replay protection, legacy confirmation,
and encrypted `desktop-code-v1` capability. Local changes extract the module as its
own crate, make kind 24134 local, update crate paths in documentation, and format
with this repository's pinned tools.

This crate has no network or Keychain access. Desktop transport and account
export are owned by `src-tauri/src/pairing`. Its tests include the exact source
protocol vectors and code-entry proof regressions. Run `bin/cargo test -p
buzz-pairing` for unit tests and doctests.

The source QR lifetime differs from upstream: `start_source_lifetime()` resets
its two-minute clock after desktop transport setup and immediately before the
visible QR is published. The desktop uses that same deadline for expiry. The
upstream reference starts the clock at session construction and expires the QR
at that original deadline; retaining that behavior here would shorten the
visible-QR contract after slow discovery or subscription. Keep this divergence
when syncing upstream.

The desktop-code port also fails closed when an oversized rejection cannot be
serialized: exhausting the guess budget clears the code and aborts before the
fallible reply construction. A regression covers that boundary.
824 changes: 824 additions & 0 deletions crates/pairing/src/NIP-AB.md

Large diffs are not rendered by default.

Loading
Loading