Skip to main content

Module supporter

Module supporter 

Source

Modulesยง

manual

Structsยง

LsActivateResponse ๐Ÿ”’
LsInstance ๐Ÿ”’
LsValidateResponse ๐Ÿ”’
SupporterRecord
SupporterStatus

Enumsยง

SupporterSource

Constantsยง

FILE_NAME ๐Ÿ”’
FUTURE_CLOCK_SKEW_TOLERANCE ๐Ÿ”’
How far into the future a timestamp may sit before we treat it as tampering rather than clock skew. 1 hour swallows reasonable NTP drift.
LS_API_BASE ๐Ÿ”’
MAX_FILE_BYTES ๐Ÿ”’
Maximum on-disk size for supporter.json. The legitimate record is well under 1 KiB; capping the read at 16 KiB defends against pathological inputs (10 GiB JSON file with one nested object) without constraining future record growth.
OFFLINE_GRACE ๐Ÿ”’
RECORD_HMAC_KEY ๐Ÿ”’
Tag-binding HMAC key for supporter.json. The threat model here is โ€œraise the bar above text-editor tamperingโ€ โ€” a determined user with the binary can extract this constant, so this is not a security boundary against a sophisticated adversary. It is, however, sufficient to detect casual JSON edits (โ€œflip is_supporter to trueโ€) and prevents replay of records between machines (each install pins the HMAC against a per-record activated_at + instance_id).
VALIDATE_INTERVAL ๐Ÿ”’

Functionsยง

activate_remote
activate_remote_at ๐Ÿ”’
HTTP-layer split for activate_remote: takes an explicit base URL so tests can point it at mockito::Server without bringing up Lemon Squeezy. The production caller hard-codes LS_API_BASE.
activate_with
Pure activation helper: sniffs the keyโ€™s source, runs the matching verification path (offline Ed25519 for ENT1-โ€ฆ, Lemon Squeezy API for everything else), and persists the resulting record to disk.
activate_with_base ๐Ÿ”’
Override manual_verifier to bypass the embedded production public key (e.g. tests that mint a token with a freshly generated keypair). Production always passes None.
canonical_bytes ๐Ÿ”’
Canonical byte encoding of the recordโ€™s verifiable fields. Field ordering and length-prefixing are fixed so the same record always serialises identically โ€” JSONโ€™s object-key order is not stable enough for HMAC input.
compute_signature ๐Ÿ”’
delete
file_path
is_supporter_now
Single-call answer to โ€œis this install a supporter right now?โ€. Reads the on-disk record and applies the offline grace window so callers donโ€™t have to thread now/grace logic of their own. Used by gated IPC paths (e.g. custom_css) to authorise per-call.
is_within_grace
load
Read the supporter record from disk. Returns None if the file is missing, malformed, larger than MAX_FILE_BYTES, or carries a signature that doesnโ€™t verify under the current HMAC key. Records with an empty signature (written by app versions before HMAC binding shipped) parse but record_is_active will require the next online validation to re-sign before granting supporter status.
mask_key
needs_remote_revalidation
Whether the daily background loop should hit the storefront for this record. Manual (community) licences carry their proof on the token itself, so the network round-trip is skipped.
needs_revalidation
record_is_active ๐Ÿ”’
save
signature_matches ๐Ÿ”’
temporal_sanity ๐Ÿ”’
Reject records whose timestamps are impossible โ€” e.g. activated_at later than last_validated_at, or either timestamp far enough into the future to suggest the user wound their clock forward to extend the offline grace window. NTP drift is accommodated by FUTURE_CLOCK_SKEW_TOLERANCE.
validate_remote
validate_remote_at ๐Ÿ”’
HTTP-layer split for validate_remote. See activate_remote_at.