Files
n_signer/firmware/teensy41/signer/src/dispatch.h
T

97 lines
3.5 KiB
C

/* dispatch.h — verb dispatch for the Teensy 4.1 n_signer firmware.
*
* Phase 6 of plans/teensy41_signer_implementation.md.
*
* Ported from firmware/cyd_esp32_2432s028/main/main.c handle_request() (line
* 1297+). This is the bulk of the signer logic: parse a JSON-RPC request,
* optionally verify the auth envelope, dispatch by verb, call ui_approve() for
* signing verbs, build the structured JSON result, and return the response.
*
* The verb set and wire protocol are defined in api.md and
* plans/algorithm_based_api.md, and match the CYD and host n_signer so the
* same clients work against all three.
*
* Signer state (seed, privkey, pubkey, npub) is owned by signer.ino (Phase 7)
* and declared here as `extern` so dispatch.cpp can read them. signer.ino
* defines and populates them after the startup menu.
*/
#ifndef FIRMWARE_TEENSY41_SIGNER_DISPATCH_H
#define FIRMWARE_TEENSY41_SIGNER_DISPATCH_H
#include <stddef.h>
#include <stdint.h>
#ifdef __cplusplus
extern "C" {
#endif
/* ---- Firmware identity (signer.ino may override via -D) ---- */
#ifndef FIRMWARE_VERSION
#define FIRMWARE_VERSION "0.1.0"
#endif
#ifndef GIT_HASH
#define GIT_HASH "dev"
#endif
#define DISPATCH_IMPLEMENTATION "teensy41"
/* ---- Auth envelope policy ----
* If non-zero, every request must carry a valid kind-27235 auth envelope
* signed by an authorized caller. If zero, the caller is treated as "anon".
* Configurable at build time via -DAUTH_REQUIRED=0/1. */
#ifndef AUTH_REQUIRED
#define AUTH_REQUIRED 0
#endif
/* ---- Signer state (defined by signer.ino in Phase 7) ----
* These are populated after the startup menu applies the mnemonic:
* s_seed : 64-byte BIP-39 seed (mnemonic_to_seed output)
* s_privkey : 32-byte secp256k1 NIP-06 privkey at index 0
* s_pubkey : 32-byte secp256k1 x-only pubkey (Nostr pubkey)
* s_npub : NUL-terminated bech32 npub string ("npub1...")
* s_pubkey_hex : NUL-terminated 64-hex of s_pubkey
*
* s_seed_len is the number of valid bytes in s_seed (64 for BIP-39). */
extern uint8_t g_seed[64];
extern size_t g_seed_len;
extern uint8_t g_privkey[32];
extern uint8_t g_pubkey[32];
extern char g_npub[128];
extern char g_pubkey_hex[65];
/* Whether the signer has a loaded mnemonic / derived keys (set by signer.ino
* after apply_mnemonic). When 0, every verb except get_info returns an error. */
extern int g_signer_ready;
/* The role table (populated by signer.ino after the role wizard). Used by the
* nostr_* verbs to resolve role + role_path selectors. Defined in dispatch.cpp
* as a DMAMEM global. */
struct role_table_t;
extern struct role_table_t g_roles;
/* ---- Entry point ----
* Process one parsed JSON-RPC request and write the JSON-RPC response into
* `out_buf`.
*
* request_json : NUL-terminated raw JSON-RPC request string.
* out_buf : caller-provided response buffer.
* out_buf_len : size of out_buf in bytes.
*
* Returns the number of bytes written to out_buf (excluding the NUL), or -1
* if the response did not fit (caller should treat as an internal error).
*
* This function performs auth-envelope verification (if AUTH_REQUIRED),
* dispatches the verb, calls ui_approve() for signing verbs, and formats the
* structured JSON result. It does NOT do transport I/O — the caller frames
* the response. */
int dispatch_handle_request(const char *request_json,
char *out_buf, size_t out_buf_len);
/* Initialize dispatch state (nonce cache, etc). Call once at boot. */
void dispatch_init(void);
#ifdef __cplusplus
}
#endif
#endif /* FIRMWARE_TEENSY41_SIGNER_DISPATCH_H */