如何检查ECC密钥和公钥是否通过Js文件传递?

时间:2016-03-23 03:57:21

标签: javascript node.js security messaging pubnub

我在查找问题所在的位置时遇到问题。我正在使用PubNub进行实时消息传递,示例项目使用ECC(椭圆曲线加密)加密消息传递。

除发送消息外,文件中的所有内容都有效(动画,频道存在等)。我每次点击发送都会收到此消息:

这是我的chat-app.js文件:

(function() {

  if (typeof(user) === 'undefined') {
    return;
  } 

  var output = document.getElementById('output'), 
      input = document.getElementById('input'), 
      picture = document.getElementById('picture'),
      presence = document.getElementById('presence'),
      action = document.getElementById('action'),
      send = document.getElementById('send');

  var channel = 'fun';

  var keysCache = {};

  var pubnub = PUBNUB.init({
      subscribe_key: 'sub-c-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx',
      publish_key: 'pub-c-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx',
      uuid: user.name,
      auth_key: user.gtoken,
      ssl: true
  });


  function displayOutput(message) {
    if(!message) return;
    if(typeof(message.text) === 'undefined') return;

    var html = '';

    if ('userid' in message && message.userid in keysCache) {

      var signature = message.signature;

      delete message.signature;

      var result = ecc.verify(keysCache[message.userid].publicKey, signature, JSON.stringify(message));

      if(result) {
        html = '<p><img src="'+ keysCache[message.userid].picture +'" class="avatar"><strong>' +  keysCache[message.userid].name + '</strong><br><span>' + message.text + '</span></p>';
      } else {
        html = '<p><img src="images/troll.png" class="avatar"><strong></strong><br><em>A troll tried to spoof '+ keysCache[message.userid].name +' (but failed).</em></p>';
      } 

      output.innerHTML = html + output.innerHTML;

    } else {
      var xhr = new XMLHttpRequest();
      xhr.open('GET', '/user/' + message.userid, true);
      xhr.onreadystatechange = function() {
        if (xhr.readyState === 4) {
          var res = JSON.parse(xhr.responseText);

          keysCache[message.userid] = {
            'publicKey': res.publicKey,
            'name': res.name,
            'artist': res.artist,
            'picture': res.picture,
            'id': res.id
          }
          displayOutput(message);
        }
      };
      xhr.send(null); 
    }
  }

  function getHistory() {
    pubnub.history({
      channel: channel,
      count: 30,
      callback: function(messages) {
        messages[0].forEach(function(m){ 
          displayOutput(m);
        });
      }
    });
  }

  pubnub.subscribe({
    channel: channel,
    restore: true,
    connect: getHistory,
    disconnect: function(res){
      console.log('disconnect called');
    },
    reconnect: function(res){
      console.log('reconnecting to pubnub');
    },
    callback: function(m) {
      displayOutput(m);
    },
    presence: function(m){
      if(m.occupancy === 1) {
        presence.textContent = m.occupancy + ' person online';
      } else {
        presence.textContent = m.occupancy + ' people online';
      }
      if((m.action === 'join') || (m.action === 'timeout') || (m.action === 'leave')){
        var status = (m.action === 'join') ? 'joined' : 'left';
        action.textContent = m.uuid + ' ' + status +' room';
        action.classList.add(m.action);
        action.classList.add('poof');
        action.addEventListener('animationend', function(){action.className='';}, false);
      }
    }
  });

  function post() {
    var safeText = input.value.replace(/\&/g, '&amp;').replace( /</g,  '&lt;').replace(/>/g,  '&gt;');
    var message = { text: safeText, userid: user.id };

    var signature = ecc.sign(user.eccKey, JSON.stringify(message));
    message['signature'] = signature;

    pubnub.publish({
      channel: channel,
      message: message
    });

    input.value = '';
  }

  input.addEventListener('keyup', function(e) {
    if(input.value === '') return;
    (e.keyCode || e.charCode) === 13 && post();
  }, false);

  send.addEventListener('click', function(e) {
    if(input.value === '') return;
    post();
  }, false);


})();

此错误来自我的ecc.js文件

Uncaught TypeError: Cannot read property 'r' of undefined 

但是,我假设错误发生在chat-app.js文件中,因为我没有触及ecc.js文件。我从项目中得到了它 - https://github.com/pubnub/auth-chat-demo

有关ECC的更多信息,请访问:https://github.com/jpillora/eccjs

1 个答案:

答案 0 :(得分:0)

根据你的描述,看起来这一行给你的错误是:

var signature = ecc.sign(user.eccKey, JSON.stringify(message));

所以我猜你没有正确传递user.eccKey?

您是否拥有oAuth(或任何登录身份验证)的所有用户数据?或者用户注册时是否正确生成了eccKey?

此外,请尝试包含ecc.js的非缩小版本,以便您可以更轻松地跟踪错误的来源。 https://raw.githubusercontent.com/jpillora/eccjs/gh-pages/dist/0.3/ecc.js