Swap the in-memory-only chat store for durable sqlite persistence with real
per-transaction timestamps, encrypted at rest under a key derived from the
wallet's own seed (no passphrase, works on encrypted and unencrypted wallets).
- ChatDatabase (src/chat/chat_database.{h,cpp}): sqlite store mirroring
data::TransactionHistoryCache. unlockWithSecret(seed) derives a 32-byte AEAD
storage key and a wallet-partition tag via domain-separated keyed BLAKE2b
(generichash) contexts. Every record — bodies, peer z-addrs, threading,
timestamps — is crypto_aead_xchacha20poly1305_ietf-encrypted with a random
nonce and the wallet tag as associated data; even the dedup key is a keyed
hash of txid+position, so nothing about your conversations is in cleartext on
disk. Rows are partitioned per-wallet; a different seed sees nothing. Messages
are decrypted once at ingest then re-encrypted under the storage key, so
load() needs only the storage key, not the chat identity.
- ChatService: ingest() now stamps each message with its own transaction time
(txid->time map + fallback) and writes new (store-deduped) messages through to
the database; loadFromDatabase() rehydrates the in-memory read model on unlock.
- App: unlock the chat DB with the same seed in provisionChatIdentityFromSecret
and load prior history; lock the DB + clear the decrypted in-memory store on
relock and on lite-controller rebuild.
Adversarial review (4 confirmed findings, all fixed): don't provision if the
wallet locks mid-fetch (re-check isLocked at completion); wipe the serialized
plaintext temporary in append(); trim the seed into a separate fully-wiped
buffer (no residue past a shrunk size()); scrub the mnemonic copy in the RPC
json result.
Tests: ChatDatabase round-trip (persist/reload, field + order fidelity), dedup,
per-wallet isolation, lock inertness, and ChatService write-through + reload
without an identity. Gated by DRAGONX_ENABLE_CHAT (default OFF). Verified:
Linux + Windows(mingw) build with chat ON, ctest 100%, hygiene clean; caches
restored to the OFF default.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
39 lines
1.2 KiB
C++
39 lines
1.2 KiB
C++
#pragma once
|
|
|
|
// DragonX Wallet - HushChat in-memory message store: the fast read model / dedup view. Durable
|
|
// persistence lives in ChatDatabase; ChatService rehydrates this store from it on unlock.
|
|
|
|
#include "chat_message.h"
|
|
|
|
#include <string>
|
|
#include <unordered_set>
|
|
#include <vector>
|
|
|
|
namespace dragonx::chat {
|
|
|
|
// Threads messages by conversation_id (cid) and deduplicates by (txid, payload_position) so
|
|
// re-scanning the chain never double-inserts. Not thread-safe — drive from the main thread.
|
|
class ChatStore {
|
|
public:
|
|
// Returns true if newly inserted, false if a duplicate was ignored.
|
|
bool append(const ChatMessage& message);
|
|
|
|
// Messages in a conversation, in insertion order.
|
|
std::vector<ChatMessage> conversation(const std::string& conversationId) const;
|
|
|
|
// Distinct conversation ids, in first-seen order.
|
|
std::vector<std::string> conversationIds() const;
|
|
|
|
std::size_t size() const { return messages_.size(); }
|
|
bool empty() const { return messages_.empty(); }
|
|
void clear();
|
|
|
|
private:
|
|
static std::string dedupKey(const ChatMessage& message);
|
|
|
|
std::vector<ChatMessage> messages_;
|
|
std::unordered_set<std::string> seen_;
|
|
};
|
|
|
|
} // namespace dragonx::chat
|