Skip to content

Add the authenticated Iroh trust broker and relay minter - #7840

Closed
azooz2003-bit wants to merge 44 commits into
mainfrom
feat-iroh-trust-broker-0709
Closed

azooz2003-bit wants to merge 44 commits into
mainfrom
feat-iroh-trust-broker-0709

Conversation

@azooz2003-bit

@azooz2003-bit azooz2003-bit commented Jul 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • add challenge-signed Iroh endpoint registration, same-account discovery, exact endpoint pair grants, offline endpoint attestations, relay-token brokerage, revocation, and retention
  • add account-deletion fencing, transactional quotas, replay protection, globally unique active EndpointIDs, bounded cleanup, and indexed cascade paths
  • isolate the Iroh Services project secret in a Rust relay minter authenticated by rotating HMAC keys
  • document the offline pairing contract and production secret boundaries

Security properties

  • path hints never authorize peers and pair grants bind both device IDs, EndpointIDs, generations, ALPN, scope, and expiry
  • registration challenges are one-use and endpoint-signed
  • authorization, revocation, deletion, grant issuance, relay reservations, and retention are transactionally linearized
  • the TypeScript web service never receives the Iroh Services project secret

Verification

  • bun test tests/iroh-model-crypto.test.ts tests/iroh-trust-broker.test.ts tests/iroh-route-handler.test.ts tests/client-config-env.test.ts: 72 passed
  • bun run db:test: migrations applied twice and 141 database behavior tests passed
  • bun run typecheck: passed
  • cargo fmt --check: passed
  • cargo clippy --all-targets --locked -- -D warnings: passed
  • cargo test --locked: 10 passed
  • ./scripts/reload.sh --tag irhbk1: tagged macOS build passed

Deployment is intentionally separate. The planning credential must be rotated before production, then migrations, minter secrets, and web secrets can be applied in order.


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

High Risk
New auth, pairing, grant signing, and relay minting paths with many secrets and DB invariants; misconfiguration or broker/minter bugs could affect device trust and relay access.

Overview
Introduces personal-account Iroh end-to-end: a TypeScript trust broker on the web app, an isolated Rust relay-token minter, schema/migrations, and a v1 offline same-account pairing spec.

The broker adds authenticated routes under /api/devices/iroh (discovery, challenge/register, pair grants, endpoint attestations, relay-token brokerage, revocation) plus cron-gated /api/internal/iroh/retention. It persists bindings, challenges, grant/relay issuance audit rows, and account security state; account deletion now cascades those tables. Route publication for devices is tightened so server-stored Iroh presence keeps only approved relay hints (legacy non-Iroh routes unchanged). Env gains required broker secrets (LAN discovery, account subject, Ed25519 grant signing/verification, rate-limit id) and optional minter URL/HMAC; the Iroh Services API key is explicitly not on the web project.

services/iroh-relay-minter is a new Vercel Rust function: POST /api/relay-token with HMAC-SHA256 over method/path/timestamp/body hash, 30s clock skew, optional previous HMAC during rotation, and mints 24h relay:use RCANs via iroh-services. CI (.github/workflows/iroh-relay-minter.yml) runs fmt/clippy/test/release build. Migrations add indexes, path-hint expiry, relay reservation expired status, and a one-time wipe of legacy server-held Iroh path hints / device Iroh routes before relay-only publication.

Reviewed by Cursor Bugbot for commit ac4decb. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Adds an authenticated Iroh trust broker and an optional Rust relay‑token minter for same‑account offline pairing and managed relay access using our 7 self‑hosted relay.cmux.dev relays. Enforces server and presence route privacy by storing/publishing only EndpointID + an approved relay URL; the legacy hosted minter is no longer required.

  • New Features

    • API routes: challenge, register, discover, revoke, endpoint_attestation, pair_grant, relay_token.
    • Trust model: challenge‑signed registration; pair grants bind device IDs, EndpointIDs, identity generation, ALPN, scope, expiry; replay protection; linearized auth/revocation/deletion; serialized LAN discovery; globally unique active EndpointIDs.
    • Route privacy: registry and presence strip direct/private Iroh hints and keep only EndpointID + an allow‑listed managed relay URL; legacy non‑Iroh routes pass through unchanged.
    • Relay access: 24h relay:use RCAN via an isolated Rust minter (services/iroh-relay-minter) with bounded HMAC rotation, dev‑only insecure loopback opt‑in, and CI at .github/workflows/iroh-relay-minter.yml; broker/worker enforce the 7 self‑hosted relay.cmux.dev URLs.
    • Ops/hardening: quotas and cron cleanup at /api/internal/iroh/retention (abandoned reservations auto‑expire as expired); canonical errors; @vercel/firewall rate‑limit integration with in‑flight caps, timeout recovery, and public‑host fallback; accepts JSON media type parameters; stricter env parsing and DB indexes; deferred reservation constraint validation.
  • Migration

    • Apply DB migrations and clear legacy server‑held Iroh path hints; hosts will republish EndpointID + managed relay URL on the next heartbeat.
    • Optional: deploy the Rust minter as a separate Vercel project and set IROH_SERVICES_API_SECRET, CMUX_IROH_MINT_HMAC_SECRET_B64 (and optional CMUX_IROH_MINT_HMAC_PREVIOUS_SECRET_B64 during rotation).
    • Configure web env for the broker: CMUX_IROH_LAN_DISCOVERY_SECRET_B64, CMUX_IROH_ACCOUNT_SUBJECT_SECRET_B64, CMUX_IROH_GRANT_SIGNING_KEY_P8, CMUX_IROH_GRANT_SIGNING_KID, CMUX_IROH_GRANT_VERIFICATION_KEYS_JSON, and (only if minting via the hosted service) CMUX_IROH_MINT_URL, CMUX_IROH_MINT_HMAC_SECRET_B64, plus CMUX_IROH_RATE_LIMIT_ID.
    • Optional for local dev: set CMUX_IROH_DEV_ALLOW_INSECURE_LOOPBACK_MINTER=1 and run the loopback minter (examples/loopback.rs, port CMUX_IROH_MINT_DEV_PORT); keep HTTPS in all deployments.

Written for commit ac4decb. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added Iroh trust-broker API endpoints for discovery, challenges, registration, pair grants, endpoint attestations, revocation, and relay-token minting.
    • Introduced a relay-token minter with strict validation and support for bounded HMAC secret rotation.
    • Added cron-protected Iroh state retention to prune expired/revoked data.
    • Added database-backed tracking for Iroh security state, bindings, challenges, and relay/pair grant issuance auditing (including schema/index hardening).
  • Documentation
    • Added the Iroh offline same-account pairing v1 specification and relay-token minter guide.
  • Bug Fixes
    • Improved account-deletion cleanup to also remove related Iroh records.
  • Tests
    • Added extensive crypto, routing, quota/concurrency, and retention integration test coverage.

@vercel

vercel Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jul 13, 2026 8:15am
cmux-staging Building Building Preview, Comment Jul 13, 2026 8:15am

@socket-security

socket-security Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​iroh@​1.0.01310093100100
Addedcargo/​iroh-services@​1.0.08210093100100
Addedcargo/​hmac@​0.12.110010093100100
Addedcargo/​rcan@​0.4.010010093100100
Addedcargo/​vercel_runtime@​2.0.09810093100100
Addedcargo/​zeroize@​1.9.010010093100100

View full report

@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds a complete Iroh trust broker with cryptographic pairing and attestation flows, PostgreSQL persistence and retention, authenticated Next.js routes, isolated Rust relay-token minting, deployment configuration, protocol documentation, and extensive tests.

Changes

Iroh trust broker

Layer / File(s) Summary
Protocol validation and cryptography
docs/iroh-offline-pairing-v1.md, web/services/iroh/{config,crypto,errors,model,relayMinter}.ts, web/app/env.ts, web/.env.example
Defines request and path-hint validation, Ed25519 token contracts, offline pairing consumption, key rotation, relay-minter communication, typed errors, and environment configuration.
Trust-broker persistence and retention
web/db/schema.ts, web/db/migrations/*, web/services/iroh/repository.ts, web/app/api/account/route.ts
Adds Iroh tables, constraints, indexes, transactional repository operations, quota ledgers, account-deletion cleanup, and bounded retention processing.
Broker orchestration and HTTP routes
web/services/iroh/{trustBroker,routeHandler}.ts, web/app/api/devices/iroh/*, web/app/api/internal/iroh/retention/route.ts, web/vercel.json
Implements challenge, registration, discovery, revocation, pair-grant, attestation, relay-token, and retention endpoints with authentication, rate limiting, bounded bodies, and typed error responses.
Contract and integration validation
web/tests/*, tests/fixtures/iroh/*
Tests model and cryptographic contracts, key rotation, offline pairing, broker behavior, route boundaries, quotas, retention authentication, production environment requirements, database concurrency, and relay-minter compatibility.
Isolated relay-token minter
services/iroh-relay-minter/*, .github/workflows/iroh-relay-minter.yml
Adds the Rust HTTP minter with HMAC authentication, bounded request/response handling, RCAN token generation, rotation support, deployment metadata, documentation, fixtures, and CI checks.

Estimated code review effort: 5 (Critical) | ~120 minutes

Possibly related PRs

  • manaflow-ai/cmux#7386: Updates the same Vercel non-preview environment validation helper used by this trust-broker configuration.
  • manaflow-ai/cmux#7645: Also updates account-deletion database cleanup, including staged deletion of Iroh-related records.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant IrohRoute
  participant IrohTrustBroker
  participant IrohRepository
  participant IrohRelayMinter

  Client->>IrohRoute: Authenticated Iroh request
  IrohRoute->>IrohTrustBroker: Dispatch operation
  IrohTrustBroker->>IrohRepository: Validate or update binding state
  IrohRepository-->>IrohTrustBroker: Binding, challenge, or issuance result
  IrohTrustBroker->>IrohRelayMinter: Mint relay token when required
  IrohRelayMinter-->>IrohTrustBroker: Token and expiry
  IrohTrustBroker-->>IrohRoute: Broker response
  IrohRoute-->>Client: JSON response
Loading

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux Swiftpm Lockfiles ❌ Error PR modifies cmux.xcodeproj/project.pbxproj but omits root Xcode Package.resolved diff, violating swiftpm-package-resolved.md rule. Include cmux.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved diff in PR to document Xcode SwiftPM lockfile changes.
Docstring Coverage ⚠️ Warning Docstring coverage is 6.63% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (23 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed PR contains no Swift code changes; check applies only to production Swift modifications. All changes are in Rust, TypeScript, SQL, and configuration files.
Cmux Swift Blocking Runtime ✅ Passed No Swift files were modified in this PR. All changes are in TypeScript (web/services/iroh, web/app/api), Rust (services/iroh-relay-minter), SQL migrations, documentation, and configuration. The che...
Cmux Browser Automation Off-Main ✅ Passed Diff only touches Iroh trust-broker files; no browser.*/WebKit socket-automation files changed or routed off-main.
Cmux Expensive Synchronous Load ✅ Passed No Swift files are modified in this PR. All changes are in TypeScript, Rust, SQL, YAML, Markdown, JSON, and TOML files related to the Iroh trust broker and relay minter backend services.
Cmux Cache Substitution Correctness ✅ Passed No cache substitution issues found. All Iroh snapshots use fresh database reads within transactions with advisory locks, never persisted/cached, and HTTP responses include cache-control: no-store h...
Cmux No Hacky Sleeps ✅ Passed No added fixed sleeps/timers/polling found in changed runtime code; only bounded retention batching and promise-based test synchronization, which is allowed.
Cmux Algorithmic Complexity ✅ Passed All production code uses explicitly bounded collections: path hints (≤16), relay hints (≤2), verification keys (≤2), quotas (60 hourly pair grants, 100 daily relays per user), and batch sizes (500)...
Cmux Swift Concurrency ✅ Passed No Swift code files were modified in this PR. All 42 changes are TypeScript, Rust, SQL, JSON, Markdown, TOML, or config files. The check is not applicable.
Cmux Swift @Concurrent ✅ Passed PR contains no Swift file changes; custom check for Swift @concurrent annotations is not applicable.
Cmux Swift File And Package Boundaries ✅ Passed PR contains no Swift file changes; check is not applicable. All 42 changes are TypeScript, Rust, SQL, JSON, Markdown, and configuration files.
Cmux Swift Logging ✅ Passed PR contains no Swift code changes; all modifications are TypeScript/Rust/SQL/documentation. Swift logging check is not applicable.
Cmux User-Facing Error Privacy ✅ Passed All user-facing error messages follow the privacy rules: no vendor/provider names, env vars, database details, constraint names, or raw upstream messages are exposed. Generic codes like "iroh_servi...
Cmux Full Internationalization ✅ Passed PR introduces Iroh trust broker and relay minter. Error codes are machine-readable protocol tokens (per rule exceptions), READMEs/docs are operational developer docs, and no user-facing UI strings...
Cmux Swiftui State Layout ✅ Passed This PR contains no SwiftUI or Swift file changes. All modifications are in Rust, TypeScript, SQL, YAML, and documentation files. The custom check is not applicable to this PR.
Cmux Architecture Rethink ✅ Passed No Swift files were changed in the diff, so the Swift architectural rethink rule is not applicable.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains no Swift code. The check for Swift auxiliary window close shortcuts does not apply—all changes are TypeScript, Rust, SQL, and documentation.
Cmux Source Artifacts ✅ Passed All 41 changed paths are intentional source artifacts: hand-written TypeScript/Rust source, tests, docs, configs, migrations, and fixtures with no build output, logs, caches, or scratch directories.
Cmux No Test Or Debug Seam In Production Source ✅ Passed This PR contains no Swift files. The custom check applies only to Swift files under production Sources/ paths, which are not modified in this PR.
Cmux No Ambient Global State ✅ Passed No Swift files were changed in the diff, so the no-ambient-global-state rule isn’t implicated.
Title check ✅ Passed The title clearly names the main addition: an authenticated Iroh trust broker plus the relay minter.
Description check ✅ Passed The description includes the key summary and testing details and is mostly aligned with the template.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-iroh-trust-broker-0709

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds an authenticated Iroh trust broker and relay-token minter. The main changes are:

  • New Iroh device registration, discovery, revocation, attestations, pair grants, and relay-token routes.
  • New database schema, migrations, quotas, cleanup, and account-deletion fencing for Iroh state.
  • New isolated Rust relay minter authenticated by HMAC and backed by Iroh Services secrets.
  • Route privacy handling for web and presence workers.
  • Documentation and tests for offline same-account pairing and relay minting.

Confidence Score: 5/5

This looks safe to merge.

  • The previously broken JSON content-type case is now handled.
  • The minter still rejects duplicate, malformed, and non-JSON content-type headers.
  • No blocking issues were found in the changed follow-up code.

Important Files Changed

Filename Overview
services/iroh-relay-minter/src/lib.rs Updates the minter request validation to accept JSON content types with normal parameters while preserving rejection for duplicate, malformed, and non-JSON headers.
web/services/iroh/relayMinter.ts Adds the web-side relay-token brokerage request path that signs JSON requests to the isolated minter.

Reviews (17): Last reviewed commit: "fix(iroh): use public host for firewall ..." | Re-trigger Greptile

Comment thread services/iroh-relay-minter/src/lib.rs
Comment thread web/services/iroh/repository.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/iroh-offline-pairing-v1.md`:
- Around line 86-95: Add the pending privacy review for pseudonymous attestation
correlation to the “Release gate” checklist, alongside the existing Swift-client
requirements, explicitly requiring resolution before release.

In `@web/services/iroh/crypto.ts`:
- Around line 134-150: Update verifyEndpointRegistrationSignature to decode
input.signature with decodeCanonicalBase64url, matching verifyPairGrant,
verifyEndpointAttestation, and offline-pair proof verification; enforce the
canonical base64url format and exact 64-byte length before passing the result to
node:crypto verify.

In `@web/services/iroh/errors.ts`:
- Around line 53-63: Replace the description-based symbol lookup in
irohExpectedError with the exported FiberFailureCauseId from effect/Runtime,
confirming it is available in effect@3.21.2. Import and access
error[FiberFailureCauseId] directly, then pass the cause to errorFromCause when
present, removing the Object.getOwnPropertySymbols search.

In `@web/services/iroh/relayMinter.ts`:
- Around line 44-101: The catch handler in the relay minting Effect incorrectly
converts IrohInvalidInputError from endpointId into minter_unavailable. Update
the catch logic in the Effect.tryPromise block to explicitly preserve and return
IrohInvalidInputError, or move endpointId validation before tryPromise, ensuring
invalid endpoint IDs surface as invalid_endpoint_id.

In `@web/services/iroh/trustBroker.ts`:
- Around line 276-281: Extract the existing grantSigningKid presence and
/^[A-Za-z0-9._-]{1,64}$/ format check from issuePairGrant into a shared
validation helper, preserving the IrohConfigurationError behavior. Use this
helper in both issuePairGrant and issueEndpointAttestation before passing the
value to signing or verification-key logic, including the
signEndpointAttestation path.

In `@web/tests/iroh-db-behavior.test.ts`:
- Around line 483-496: Remove the FinalizeEndpointAttestation type declaration,
defensive cast, runtime type assertion, and early return in the “fails
attestation finalization when revocation commits during signing” test; use the
already-typed repository.finalizeEndpointAttestation method directly, matching
the earlier test in this file.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5046591a-d285-4950-9f74-d67c1e8944a4

📥 Commits

Reviewing files that changed from the base of the PR and between 6c3ffc5 and 2e411df.

⛔ Files ignored due to path filters (1)
  • services/iroh-relay-minter/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (41)
  • .github/workflows/iroh-relay-minter.yml
  • docs/iroh-offline-pairing-v1.md
  • services/iroh-relay-minter/.env.example
  • services/iroh-relay-minter/.gitignore
  • services/iroh-relay-minter/Cargo.toml
  • services/iroh-relay-minter/README.md
  • services/iroh-relay-minter/api/relay-token.rs
  • services/iroh-relay-minter/rust-toolchain.toml
  • services/iroh-relay-minter/src/lib.rs
  • services/iroh-relay-minter/vercel.json
  • tests/fixtures/iroh/path-hint-v1.json
  • tests/fixtures/iroh/relay-minter-request-v1.json
  • web/.env.example
  • web/app/api/account/route.ts
  • web/app/api/devices/iroh/challenge/route.ts
  • web/app/api/devices/iroh/endpoint-attestations/route.ts
  • web/app/api/devices/iroh/pair-grants/route.ts
  • web/app/api/devices/iroh/register/route.ts
  • web/app/api/devices/iroh/relay-token/route.ts
  • web/app/api/devices/iroh/route.ts
  • web/app/api/internal/iroh/retention/route.ts
  • web/app/env.ts
  • web/db/migrations/20260709000000_iroh_trust_broker/migration.sql
  • web/db/migrations/20260710000000_iroh_trust_broker_hardening/migration.sql
  • web/db/migrations/20260710010000_iroh_trust_broker_review_hardening/migration.sql
  • web/db/schema.ts
  • web/services/iroh/README.md
  • web/services/iroh/config.ts
  • web/services/iroh/crypto.ts
  • web/services/iroh/errors.ts
  • web/services/iroh/model.ts
  • web/services/iroh/relayMinter.ts
  • web/services/iroh/repository.ts
  • web/services/iroh/routeHandler.ts
  • web/services/iroh/trustBroker.ts
  • web/tests/client-config-env.test.ts
  • web/tests/iroh-db-behavior.test.ts
  • web/tests/iroh-model-crypto.test.ts
  • web/tests/iroh-route-handler.test.ts
  • web/tests/iroh-trust-broker.test.ts
  • web/vercel.json

Comment thread docs/iroh-offline-pairing-v1.md
Comment thread web/services/iroh/crypto.ts
Comment thread web/services/iroh/errors.ts
Comment thread web/services/iroh/relayMinter.ts
Comment thread web/services/iroh/trustBroker.ts Outdated
Comment thread web/tests/iroh-db-behavior.test.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/.env.example`:
- Around line 47-63: Reorder the CMUX_IROH entries in the environment template
alphabetically by variable name to satisfy dotenv-linter, including placing
ACCOUNT_SUBJECT_SECRET_B64 after LAN_DISCOVERY_SECRET_B64 and MINT_URL before
MINT_HMAC_SECRET_B64; preserve all comments and values.

In
`@web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql`:
- Around line 4-6: Update the constraint definition in the migration to add the
CHECK constraint with NOT VALID, then add a subsequent VALIDATE CONSTRAINT
statement for iroh_relay_token_issuances_status_check so existing rows are
checked separately from constraint creation.

In `@web/services/iroh/config.ts`:
- Line 38: Update the configuration construction in the relevant config module
so deploymentEnvironment is sourced from the validated env object, matching the
other fields, rather than reading process.env directly. Add VERCEL_ENV and
NODE_ENV to the validated exports in the env module if needed, then use those
values with the existing fallback semantics while preserving the
deviceLimitOverrideAllowed behavior.

In `@web/services/iroh/model.ts`:
- Around line 271-276: Remove the redundant `kind === "relay_url" && source !==
"native"` check and its `IrohInvalidInputError` throw after `managedRelayUrl`;
rely on `managedRelayUrl` to reject non-native relay hints while preserving the
existing `hintValue` behavior.

In `@web/services/iroh/routeHandler.ts`:
- Around line 70-89: Wrap the broker Effect executed in the try block of the
route handler with an application-level Effect.timeout using the service’s
appropriate request deadline, covering both the injected broker and
runtime-provided broker paths. Handle timeout failures through the existing
irohExpectedError/JSON error flow so requests return a clean response instead of
waiting for the platform timeout.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 59ddf908-811e-44a6-8d88-9379dbe827a4

📥 Commits

Reviewing files that changed from the base of the PR and between 6c3ffc5 and be7801a.

⛔ Files ignored due to path filters (1)
  • services/iroh-relay-minter/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (42)
  • .github/workflows/iroh-relay-minter.yml
  • docs/iroh-offline-pairing-v1.md
  • services/iroh-relay-minter/.env.example
  • services/iroh-relay-minter/.gitignore
  • services/iroh-relay-minter/Cargo.toml
  • services/iroh-relay-minter/README.md
  • services/iroh-relay-minter/api/relay-token.rs
  • services/iroh-relay-minter/rust-toolchain.toml
  • services/iroh-relay-minter/src/lib.rs
  • services/iroh-relay-minter/vercel.json
  • tests/fixtures/iroh/path-hint-v1.json
  • tests/fixtures/iroh/relay-minter-request-v1.json
  • web/.env.example
  • web/app/api/account/route.ts
  • web/app/api/devices/iroh/challenge/route.ts
  • web/app/api/devices/iroh/endpoint-attestations/route.ts
  • web/app/api/devices/iroh/pair-grants/route.ts
  • web/app/api/devices/iroh/register/route.ts
  • web/app/api/devices/iroh/relay-token/route.ts
  • web/app/api/devices/iroh/route.ts
  • web/app/api/internal/iroh/retention/route.ts
  • web/app/env.ts
  • web/db/migrations/20260709000000_iroh_trust_broker/migration.sql
  • web/db/migrations/20260710000000_iroh_trust_broker_hardening/migration.sql
  • web/db/migrations/20260710010000_iroh_trust_broker_review_hardening/migration.sql
  • web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql
  • web/db/schema.ts
  • web/services/iroh/README.md
  • web/services/iroh/config.ts
  • web/services/iroh/crypto.ts
  • web/services/iroh/errors.ts
  • web/services/iroh/model.ts
  • web/services/iroh/relayMinter.ts
  • web/services/iroh/repository.ts
  • web/services/iroh/routeHandler.ts
  • web/services/iroh/trustBroker.ts
  • web/tests/client-config-env.test.ts
  • web/tests/iroh-db-behavior.test.ts
  • web/tests/iroh-model-crypto.test.ts
  • web/tests/iroh-route-handler.test.ts
  • web/tests/iroh-trust-broker.test.ts
  • web/vercel.json

Comment thread web/.env.example
Comment thread web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql Outdated
Comment thread web/services/iroh/config.ts
Comment thread web/services/iroh/model.ts Outdated
Comment thread web/services/iroh/routeHandler.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql (1)

1-9: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Split the constraint add and validation into separate migrations

ALTER TABLE ... ADD CONSTRAINT ... NOT VALID still takes an ACCESS EXCLUSIVE lock, and Drizzle runs each Postgres migration file in a transaction, so VALIDATE CONSTRAINT here still keeps readers blocked until commit. Split the add and validate steps into separate migration files if this is meant to be a zero-downtime pattern for populated tables.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql`
around lines 1 - 9, Split the constraint change currently represented by the
iroh relay reservation expiry migration into two sequential migration files: one
that drops and re-adds the status check constraint as NOT VALID, and a later one
that runs VALIDATE CONSTRAINT. Ensure the migration ordering guarantees
validation occurs only after the add migration has committed.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In
`@web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql`:
- Around line 1-9: Split the constraint change currently represented by the iroh
relay reservation expiry migration into two sequential migration files: one that
drops and re-adds the status check constraint as NOT VALID, and a later one that
runs VALIDATE CONSTRAINT. Ensure the migration ordering guarantees validation
occurs only after the add migration has committed.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: ceba8ceb-7797-49d9-b2ef-79cf1e2ec6a9

📥 Commits

Reviewing files that changed from the base of the PR and between c9661e4 and f1a0f59.

📒 Files selected for processing (9)
  • docs/iroh-offline-pairing-v1.md
  • web/db/migrations/20260710113000_iroh_relay_reservation_expiry/migration.sql
  • web/services/iroh/crypto.ts
  • web/services/iroh/errors.ts
  • web/services/iroh/model.ts
  • web/services/iroh/relayMinter.ts
  • web/services/iroh/trustBroker.ts
  • web/tests/iroh-db-behavior.test.ts
  • web/tests/iroh-model-crypto.test.ts
💤 Files with no reviewable changes (1)
  • web/services/iroh/model.ts

Comment thread workers/presence/src/validate.ts
Comment thread web/services/iroh/trustBroker.ts
…v URLs

Replaces the 4 hosted iroh.link relays with our self-hosted fleet in both
allowlists (web MANAGED_RELAY_URLS + presence worker APPROVED_IROH_RELAY_URLS,
kept in lockstep) and the tests that referenced hosted URLs. The self-hosted
relays run iroh-relay 1.0.2 behind per-region MIG+L4-LB (zero-downtime
upgrades), gated by the cmux EdDSA JWT that /api/relay/token (merged, #7879)
mints.
iroh broker: use the 7 self-hosted relay.cmux.dev relays
Comment thread services/iroh-relay-minter/src/lib.rs
@azooz2003-bit
azooz2003-bit force-pushed the feat-iroh-trust-broker-0709 branch from e6f1aee to 695de0c Compare July 13, 2026 05:47

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit ac4decb. Configure here.

return hostname === "localhost" ||
hostname === "127.0.0.1" ||
hostname === "[::1]";
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IPv6 loopback host check broken

Low Severity

isCanonicalLoopbackHost compares against `[::1]`, but WHATWG URL.hostname returns IPv6 addresses without brackets (::1). An opted-in local HTTP minter URL using IPv6 loopback is therefore rejected even though tests and the policy treat that form as allowed; localhost and 127.0.0.1 still work.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit ac4decb. Configure here.

@azooz2003-bit

Copy link
Copy Markdown
Collaborator Author

Superseded by #8484, which includes the authenticated Iroh trust broker and relay minter plus the later security, relay-policy, direct-port, settings, compatibility, and end-to-end integration work. PR 8484 merged in 288f1e1 and its production database migration completed successfully.

This branch was successfully deployed

1 active deployment
Preview – cmux — ac4decb8 Deployed Jul 13, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants