v0.4: licensing — server validation, DPAPI cache, Ed25519 signed responses
UX bonus: clicking "Reprendre" on an interrupted download skips the
release-notes confirmation dialog (the user already approved when they
first clicked Installer).
Server side
-----------
- migrations/001_init.sql: licenses, license_machines, rate_limit,
audit_log on InnoDB/utf8mb4. Foreign keys, unique on license_key, slot
uniqueness per (license_id, machine_id).
- api/lib/Db.php: thin PDO singleton (exception mode, prepared, no emul).
- api/lib/Crypto.php: Ed25519 sign/verify via libsodium (sodium_crypto_*),
HMAC-SHA-256 helper for v0.6, canonicalJson() that strips `signature`
before serializing — must match exactly the encoding done client-side
before verify.
- api/routes/ValidateLicense.php: POST /license/validate. Looks up the
key, walks the machine slot logic (insert or update last_seen),
enforces max_machines, returns a payload signed Ed25519 + status of
valid/expired/revoked/machine_limit_exceeded/invalid. Audit logs every
outcome. Rate-limit 10/min/IP via the rate_limit table.
- tools/generate-keypair.php: prints a fresh sodium keypair so the
operator drops the hex into config.php and the public_key_hex into the
launcher resource.
- tools/issue-license.php: PRSRV-XXXX-XXXX-XXXX-XXXX generator (32-char
unambiguous alphabet), inserts the license, prints the key once.
- tools/sign-manifest.php: now also signs the manifest itself with
Ed25519 after computing the per-zip sha256s.
- config.example.php: schema rewritten with sections db / hmac / ed25519
/ jwt / rate-limit. config.php remains gitignored.
Client side
-----------
- Models/License.cs: LicenseValidationRequest + LicenseValidationResponse
with CanDownload(VersionManifest) — entitlement_until vs version's
minLicenseDate. The status valid|expired|revoked|machine_limit_exceeded
flow is preserved end-to-end.
- Core/Licensing/LicenseService.cs:
* machineId = SHA-256 of HKLM/Software/Microsoft/Cryptography/MachineGuid
+ UserName (stable, no PII leak)
* online ValidateAsync calls /license/validate with launcher version
* embedded server-pubkey.txt drives Ed25519 verification of the
response (skipped gracefully if pubkey not yet provisioned)
* SaveCached / GetCached use DPAPI CurrentUser scope on the license
key; the cleartext key never touches disk
* GetCached has a 7-day offline grace window after the last successful
validation, so going offline doesn't lock the user out
- Core/Resources/server-pubkey.txt: EmbeddedResource. Default content is
a comment, which the service treats as "no pubkey configured" and
bypasses verification. Operator pastes the real hex post-deploy and
rebuilds.
- Core/PSLauncher.Core.csproj: Polly, NSec.Cryptography (Ed25519),
System.Security.Cryptography.ProtectedData (DPAPI).
- App/Views/OnboardingDialog.xaml(.cs): first-launch / "🔑 Activer"
modal. Calls LicenseService, displays status messages with red
foreground on errors and green-tinted secondary text otherwise.
- ViewModels/VersionRowViewModel.cs: new LicenseAllowsDownload property.
Install button label switches to "🔒 License insuffisante" when the
user's entitlement_until precedes the version's minLicenseDate;
CanInstall is false in that case so the click is a no-op too.
- ViewModels/MainViewModel.cs: loads the cached license at startup (no
network call), surfaces it as LicenseSummary in the top bar, exposes
ActivateLicenseCommand to (re)open the onboarding dialog. RebuildList
applies the per-version license filter so older installed versions
remain launchable but newer-than-license ones can't be downloaded.
- Views/MainWindow.xaml: top bar gains a "🔑 Activer / changer" button
next to the license summary.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
63
server/tools/issue-license.php
Normal file
63
server/tools/issue-license.php
Normal file
@@ -0,0 +1,63 @@
|
||||
<?php
|
||||
/**
|
||||
* Émet une nouvelle license dans la base. La clé est imprimée en clair sur stdout
|
||||
* (à transmettre au client par canal sécurisé). Aucune trace en clair côté serveur :
|
||||
* la base ne stocke que la clé via UNIQUE pour la lookup constant-time.
|
||||
*
|
||||
* Usage (SSH OVH) :
|
||||
* php tools/issue-license.php "ACME Corp" 2026-12-31 [maxMachines=1]
|
||||
*/
|
||||
declare(strict_types=1);
|
||||
|
||||
require dirname(__DIR__) . '/api/lib/Db.php';
|
||||
$config = require dirname(__DIR__) . '/api/config.php';
|
||||
|
||||
if ($argc < 3) {
|
||||
fwrite(STDERR, "Usage: php tools/issue-license.php \"<owner_name>\" <YYYY-MM-DD entitlement_until> [max_machines=1]\n");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
$owner = $argv[1];
|
||||
$until = $argv[2];
|
||||
$maxMachines = (int)($argv[3] ?? 1);
|
||||
|
||||
if (!preg_match('/^\d{4}-\d{2}-\d{2}$/', $until)) {
|
||||
fwrite(STDERR, "entitlement_until must be YYYY-MM-DD\n"); exit(2);
|
||||
}
|
||||
|
||||
$db = \PSLauncher\Db::get($config);
|
||||
|
||||
// Génère une clé du type PRSRV-XXXX-XXXX-XXXX-XXXX (groupes alphanumériques)
|
||||
function genKey(): string {
|
||||
$alphabet = 'ABCDEFGHJKLMNPQRSTUVWXYZ23456789'; // pas de 0/O/1/I/L
|
||||
$groups = [];
|
||||
for ($g = 0; $g < 4; $g++) {
|
||||
$s = '';
|
||||
for ($i = 0; $i < 4; $i++) $s .= $alphabet[random_int(0, strlen($alphabet) - 1)];
|
||||
$groups[] = $s;
|
||||
}
|
||||
return 'PRSRV-' . implode('-', $groups);
|
||||
}
|
||||
|
||||
// Boucle au cas (très improbable) où collision UNIQUE
|
||||
for ($attempts = 0; $attempts < 5; $attempts++) {
|
||||
$key = genKey();
|
||||
try {
|
||||
$stmt = $db->prepare(
|
||||
'INSERT INTO licenses (license_key, owner_name, issued_at, download_entitlement_until, max_machines)
|
||||
VALUES (?, ?, NOW(), ?, ?)'
|
||||
);
|
||||
$stmt->execute([$key, $owner, $until . ' 23:59:59', $maxMachines]);
|
||||
$id = $db->lastInsertId();
|
||||
echo "==== License émise ====\n";
|
||||
echo "id : {$id}\n";
|
||||
echo "owner : {$owner}\n";
|
||||
echo "until : {$until}\n";
|
||||
echo "key : {$key}\n";
|
||||
exit(0);
|
||||
} catch (\PDOException $e) {
|
||||
if (str_contains($e->getMessage(), 'Duplicate')) continue;
|
||||
throw $e;
|
||||
}
|
||||
}
|
||||
fwrite(STDERR, "Failed to generate unique key after retries\n"); exit(3);
|
||||
Reference in New Issue
Block a user