You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR adds public key infrastructure for end-to-end encryption. The changes add two nullable columns to the devices table: public_key (text) and key_version (int), exposed through device registration and update endpoints.
Major changes:
E2E key storage — devices can now register an RSA public key with version tracking for key rotation
Phone number expansion — recipient phone number storage increased from 128 to 512 characters
Documentation — new CHANGELOG.md documents the public key feature and updated .env.example with clarified config descriptions
Diagram
sequenceDiagram
participant Client as Android App
participant Handler as Mobile Handler
participant Service as Device Service
participant Repo as Repository
participant DB as MySQL
Note over Client,DB: Device Registration with E2E Key
Client->>Handler: "POST /mobile/v1/device<br/>{publicKey, keyVersion, ...}"
Handler->>Handler: Validate (go-playground/validator)
Handler->>Service: RegisterDevice(publicKey, keyVersion)
Service->>Repo: Insert(device)
Repo->>DB: "INSERT INTO devices<br/>(public_key, key_version, ...)"
DB-->>Repo: OK
Repo-->>Service: Device
Service-->>Handler: Device
Handler-->>Client: "201 {id, token}"
Note over Client,DB: Key Rotation via Update
Client->>Handler: "PATCH /mobile/v1/device<br/>{publicKey, keyVersion}"
Handler->>Handler: Validate new key pair
Handler->>Service: Update(publicKey, keyVersion)
Service->>Repo: Update(device)
Repo->>DB: "UPDATE devices<br/>SET public_key=?, key_version=?"
DB-->>Repo: OK
Repo-->>Service: OK
Service-->>Handler: OK
Handler-->>Client: 204 No Content
E2E consistency not validated on device registrationinternal/sms-gateway/modules/devices/service.go:42▶
The ErrInconsistentE2E guard exists in Update, but Insert has no equivalent check. RegisterDevice calls devicesSvc.Insert directly, so a registration request that supplies publicKey without keyVersion (or vice versa) bypasses the pairing validation entirely and persists the inconsistent state to the DB - exactly the case Update is designed to prevent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is safe to merge with minimal risk
Summary
This PR adds public key infrastructure for end-to-end encryption. The changes add two nullable columns to the devices table:
public_key(text) andkey_version(int), exposed through device registration and update endpoints.Major changes:
Diagram
sequenceDiagram participant Client as Android App participant Handler as Mobile Handler participant Service as Device Service participant Repo as Repository participant DB as MySQL Note over Client,DB: Device Registration with E2E Key Client->>Handler: "POST /mobile/v1/device<br/>{publicKey, keyVersion, ...}" Handler->>Handler: Validate (go-playground/validator) Handler->>Service: RegisterDevice(publicKey, keyVersion) Service->>Repo: Insert(device) Repo->>DB: "INSERT INTO devices<br/>(public_key, key_version, ...)" DB-->>Repo: OK Repo-->>Service: Device Service-->>Handler: Device Handler-->>Client: "201 {id, token}" Note over Client,DB: Key Rotation via Update Client->>Handler: "PATCH /mobile/v1/device<br/>{publicKey, keyVersion}" Handler->>Handler: Validate new key pair Handler->>Service: Update(publicKey, keyVersion) Service->>Repo: Update(device) Repo->>DB: "UPDATE devices<br/>SET public_key=?, key_version=?" DB-->>Repo: OK Repo-->>Service: OK Service-->>Handler: OK Handler-->>Client: 204 No ContentReviews (39) · Last reviewed commit: "[docs] create changelog, update dotenv e..." · Reviewed by Greptile