Skip to main content

Module server

Module server 

Source
Expand description

An in-memory reference prekey server (requires the server feature)

A PrekeyServer holds every user’s identity key and signed prekeys, and hands each one-time prekey out only once. When a user’s one-time prekeys run out, it hands out their last-resort prekey instead.

It is meant for prototypes, tests and as an executable description of the server’s rules. A production server must also:

  • Persist prekeys in a database, and remove each one-time prekey in the same transaction that hands it out, so it can never be given out twice.
  • Authenticate accounts. The first publish for a user decides their identity key; after that only the holder of that key can add prekeys, because every prekey must carry their signature. Who may claim a user name in the first place is up to your account system.
  • Rate-limit fetches. Otherwise an attacker can drain a user’s one-time prekeys, which pushes everyone onto the last-resort prekey and its weaker forward secrecy.
  • Deliver the session setup (ciphertext, prekey id, base nonce, sender identity) and the messages themselves. That transport is not part of this crate.

Structs§

PrekeyBundle
What an initiator needs to start a session with a user
PrekeyServer
In-memory store of users’ prekeys, keyed by any user id type K