feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h): - vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads - VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password - VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_ until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519) - vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only - VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate - vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores it atomically so the audio RT path reads without a lock C++ implementation: - SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id, password_protected, and max_users (were permanently zeroed) - TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS - TofuStore split into peek (read-only) + pin (write) so first-connect only persists after user approval; tofu_store_path in vc_config for per-user pin file location - TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows) - windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests - New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green) Windows client (clients/windows/ — .NET 10 WinForms): - VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks, Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer - VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity- Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode, per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar) - PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation) - PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams - Accessibility: explicit AccessibleName/Description on every control, & mnemonics, Activity log ListBox as durable screen-reader record, AutomationNotification for curated live announcements Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
29
clients/windows/VoiceCat.App/Models/PasswordProtector.cs
Normal file
29
clients/windows/VoiceCat.App/Models/PasswordProtector.cs
Normal file
@@ -0,0 +1,29 @@
|
||||
using System.Security.Cryptography;
|
||||
using System.Text;
|
||||
|
||||
namespace VoiceCat.App.Models;
|
||||
|
||||
/// <summary>
|
||||
/// DPAPI (CurrentUser scope) wrapper for the opt-in "remember my password on this computer"
|
||||
/// feature (SavedServer.ProtectedPasswordBase64). DPAPI keys are derived from the user's
|
||||
/// Windows credentials and are not portable/exportable — a stolen servers.json file alone,
|
||||
/// copied to another machine or read by another OS user, is not decryptable. This is the same
|
||||
/// primitive Windows Credential Manager and many first-party Windows apps use for exactly this
|
||||
/// "remember a secret only on this machine, only for this user" case.
|
||||
/// </summary>
|
||||
public static class PasswordProtector
|
||||
{
|
||||
public static string Protect(string plaintext)
|
||||
{
|
||||
byte[] data = Encoding.UTF8.GetBytes(plaintext);
|
||||
byte[] protectedData = ProtectedData.Protect(data, optionalEntropy: null, DataProtectionScope.CurrentUser);
|
||||
return Convert.ToBase64String(protectedData);
|
||||
}
|
||||
|
||||
public static string Unprotect(string protectedBase64)
|
||||
{
|
||||
byte[] protectedData = Convert.FromBase64String(protectedBase64);
|
||||
byte[] data = ProtectedData.Unprotect(protectedData, optionalEntropy: null, DataProtectionScope.CurrentUser);
|
||||
return Encoding.UTF8.GetString(data);
|
||||
}
|
||||
}
|
||||
26
clients/windows/VoiceCat.App/Models/SavedServer.cs
Normal file
26
clients/windows/VoiceCat.App/Models/SavedServer.cs
Normal file
@@ -0,0 +1,26 @@
|
||||
namespace VoiceCat.App.Models;
|
||||
|
||||
public enum AuthMode
|
||||
{
|
||||
Guest,
|
||||
Password,
|
||||
}
|
||||
|
||||
/// <summary>One entry in the saved-server list (%AppData%\VoiceCat\servers.json).</summary>
|
||||
public sealed class SavedServer
|
||||
{
|
||||
public string DisplayName { get; set; } = "";
|
||||
public string Host { get; set; } = "";
|
||||
public ushort Port { get; set; } = 8384;
|
||||
public string LastNickname { get; set; } = "";
|
||||
public AuthMode AuthMode { get; set; } = AuthMode.Guest;
|
||||
public string? SavedUsername { get; set; }
|
||||
|
||||
/// <summary>DPAPI-protected (CurrentUser scope), base64 — only set when the user opts in
|
||||
/// via the "Remember my password on this computer" checkbox. Never plaintext, never the
|
||||
/// default. See PasswordProtector.</summary>
|
||||
public string? ProtectedPasswordBase64 { get; set; }
|
||||
|
||||
public override string ToString() =>
|
||||
string.IsNullOrWhiteSpace(DisplayName) ? $"{Host}:{Port}" : $"{DisplayName} ({Host}:{Port})";
|
||||
}
|
||||
42
clients/windows/VoiceCat.App/Models/ServerListStore.cs
Normal file
42
clients/windows/VoiceCat.App/Models/ServerListStore.cs
Normal file
@@ -0,0 +1,42 @@
|
||||
using System.Text.Json;
|
||||
|
||||
namespace VoiceCat.App.Models;
|
||||
|
||||
/// <summary>
|
||||
/// Simple Load()/Save() over %AppData%\VoiceCat\servers.json. Tolerant of a missing/corrupt
|
||||
/// file — that yields an empty list rather than throwing and blocking app startup.
|
||||
/// </summary>
|
||||
public static class ServerListStore
|
||||
{
|
||||
private static readonly JsonSerializerOptions JsonOptions = new() { WriteIndented = true };
|
||||
|
||||
private static string AppDataDir => Path.Combine(
|
||||
Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "VoiceCat");
|
||||
|
||||
private static string ServersFilePath => Path.Combine(AppDataDir, "servers.json");
|
||||
|
||||
/// <summary>Passed to VoiceCatClient's tofuStorePath — the C++ core owns the actual pin
|
||||
/// file format/logic (TofuStore), this just picks where it lives.</summary>
|
||||
public static string TofuStorePath => Path.Combine(AppDataDir, "tofu_pins.txt");
|
||||
|
||||
public static List<SavedServer> Load()
|
||||
{
|
||||
try
|
||||
{
|
||||
if (!File.Exists(ServersFilePath)) return new List<SavedServer>();
|
||||
string json = File.ReadAllText(ServersFilePath);
|
||||
return JsonSerializer.Deserialize<List<SavedServer>>(json) ?? new List<SavedServer>();
|
||||
}
|
||||
catch
|
||||
{
|
||||
return new List<SavedServer>();
|
||||
}
|
||||
}
|
||||
|
||||
public static void Save(List<SavedServer> servers)
|
||||
{
|
||||
Directory.CreateDirectory(AppDataDir);
|
||||
string json = JsonSerializer.Serialize(servers, JsonOptions);
|
||||
File.WriteAllText(ServersFilePath, json);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user