Skip to content

files: a file row's name and media type travel in cleartext in the signed envelope #698

Description

@emooreatx

files::publish (edge v32.1.0, src/files.rs ~L340) builds the file:v1 row envelope with filename (FIELD_FILENAME), the room target (cohort_target_field = the room's content id; for a self file, the owner's identity key id), and the BlobPointer, which carries media_type. All of it is in cleartext. The BYTES are sealed (tier InvisibleEncrypted for a self file), and the pointer's content_sha256 is the at-rest hash, so the content stays private. The file's DESCRIPTION does not.

Why it matters now: CIRISServer's selffiles ladder, run 36278132685, measured another person's peered node holding the owner's self file rows, with names readable (contract (signed).pdf, archive.zip, screenshot.png, …). How they got there is CIRISPersist#919: the #530 consent sweep widened them to federation. That is fixed in persist v50. But even after that, the name is readable by anything that stores the row legitimately: a relay, a holder, and any node that ever receives the row through a future widening defect. Existence metadata then fails OPEN, not closed.

Ask: seal filename (and optionally media_type) under the room's content key, beside the bytes or as a small sealed metadata field in the pointer. files::open / FileRef would return them after the room DEK opens. A room member sees no difference; anyone else sees a row with a pointer and no name. If a cleartext hint is needed for routing or policy, name the field and why.

Server side: CIRISServer's drive reads FileRef.filename and needs no change beyond adopting the sealed form.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions