Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 0 additions & 56 deletions docs/RFCs/pnet.md

This file was deleted.

124 changes: 124 additions & 0 deletions docs/RFCs/private-network.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
- Feature Name: private-network
- Start Date: 2022-02-01
- RFC PR: https://github.com/functionland/docs/pull/67
- Functionland Issue: https://github.com/functionland/docs/issues/63

## Background
We are using IPFS as our file system. But IPFS is built to use for public data, and it does not support ACL,
So we need to find a way to keep users safe until our security layer becomes mature. And also ipfs-cluster [docs](https://cluster.ipfs.io/documentation/guides/security/#ports-overview) recommended to have a secret.

###Current Network
Our current network topology is too simple, its only base on webrtc-start and peer discovery is disabled.
#### Server
Node with roll of server is a js-libp2p node with our protocol's and server side implementations (use js-ipfs as fs) that listen on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts).

#### Client
Node with the roll of [client](https://github.com/functionland/fula/tree/main/libraries/fula-client) (phone,webapp) are listening on [webrtc-start](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/config.ts) and when user provide the string peer id (`B58String`) of the box with [connect](https://docs.fx.land/api/client-instance#connect-to-box) API, the api create multiAddress based on webrtc signaling server add it to libp2p peer store and keep the connection alive with the box.
also have to mention inbound connections are blocked.


## Problem Statement
We need to protect users and their data from harms and risks of public networks and also cover the [multi box scenario](https://github.com/functionland/docs/issues/58).
The public network risks are:
- Anyone on the internet can connect to the box.
- Anyone on the internet that is connected to the box can use bitswap to get data from the box.
- Peer routing and Content discovery can leak what you are doing to the public.
- deficiency in our encryption algorithm or key management can leak all user data to the public.
- clusters running without a secret may discover and connect to the main IPFS network, which is mostly useless for the cluster peers (and for the IPFS network).

## Motivation
Isolating users from public networks can help us reduce the scope of work while maintaining the usefulness of our product, and testing our security layer without putting users in harm's way.

## Proposal
We can use built-in libp2p components to create a private network with encrypted communication.
The components are:
- Libp2p built-in private network. It uses a [private shared key](https://github.com/libp2p/js-libp2p/tree/master/src/pnet#private-shared-keys) for creating an isolated network with encrypted communication.
- [spec](https://github.com/libp2p/specs/blob/master/pnet/Private-Networks-PSK-V1.md)
- [js-doc](https://github.com/libp2p/js-libp2p/tree/master/src/pnet)
- Libp2p bootstrap for bootstrapping the network of boxes:
- [js-doc](https://github.com/libp2p/js-libp2p-bootstrap)

In this way when a node comes online, Libp2p uses the key and the list of other node's to join the network.

## Scope of work
### Box
For box setup users provide an environment variable `FULA_NET_SECRET` which they should remember. and provide a list of node as `config.json`

### FULA-Client
user calls `createClient` they should also provide the secret they used for setting up the boxes. and when he calls `connect` it should pass the list of string peerId's

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also need to talk about how the network is joined together. So far this reads as a simple key generation RFC.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will try to add current network topology to background and also how network join in the proposal


## Implementation
The box and client already support private-key but need to add test and fixes namings.
### Box
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should change the name `PKEY` to `FULA_NET_SECRET`

We need to add [`js-libp2p-bootstrap`](https://github.com/libp2p/js-libp2p-bootstrap) and
In the [Config](https://github.com/functionland/fula/blob/main/apps/box/src/config.ts) we should add to support to load `config.json` in this format:

```json
{
"nodes": [
"/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN",
"/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa"
]
}
```
Which will be used for creating `js-libp2p-bootstrap` [config](https://github.com/libp2p/js-libp2p-bootstrap).


### FULA-client
In [fula-client](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/index.ts) We have to change pkey to fulaSecret so:
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, pKey = undefined): Promise<Fula>
```
to
```ts
createClient(config?: Partial<Libp2pOptions & constructorOptions>, fulaSecret = undefined): Promise<Fula>
```
and change connect interface to get a list of peerId`s from:
```
connect: (peerId: string) => Connection
```
to
```
connect: (peerId: [string]) => Connection
```

We need to change [`Connection`](https://github.com/functionland/fula/blob/main/libraries/fula-client/src/connection.ts) in the way that:
- Connection `Status`
- If we connect to at least one box we are `Online`.
- When we are not connected to any box and try to connect we are at `Connecting`.
- When connection fails to all the serverPeerIds we Are `Offline`.
- Connection should have a list of `serverPeerId`.
- Connect to all the `serverPeerId` and keep the connection alive.



## Case Study
For dogfooding of new changes we can use a copy of [react-gallery](https://github.com/functionland/fula/tree/main/examples/react-gallery) and change
the [`BoxConfig`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/components/BoxConfig.jsx)
to get list of comma seperated peerIds and [`App`](https://github.com/functionland/fula/blob/main/examples/react-gallery/src/App.js) should change to pass the list of peerId's to fula-client.

Note: if example repo would be outside mono-repo we can just use branch for describing every functionality.


## Alternative approaches
### VPN
Using VPN for creating the private network.

Disadvantage:
- It adds another point of failure to the system.
- It is also not that decentralized.

## Risks
### Work prioritization
### Anything that impacts the value of RFC
### What could impact delivery of this RFC?
## Dependencies
## Impact




2 changes: 1 addition & 1 deletion sidebars.js
Original file line numberDiff line numberDiff line change
Expand Up@@ -65,7 +65,7 @@ const sidebars = {
id:'RFCs/rfc-process'
},
items:[
'RFCs/pnet',
'RFCs/private-network',
'RFCs/replication'
]
}
Expand Down