HmacQuicTokenHandler
A secure QuicTokenHandler that generates and validates QUIC retry tokens using HMAC-SHA256. Tokens bind the client's address and port to a timestamp and are cryptographically signed to prevent forgery. Expired tokens are rejected to mitigate replay attacks.
Assign an instance to NettyHttp3Configuration.quicTokenHandler to enable QUIC address validation via stateless Retry. Note that this adds one round trip to every connection handshake; see NettyHttp3Configuration.quicTokenHandler for the trade-offs.
Token format:
[timestamp (8 bytes)] [HMAC-SHA256 (32 bytes)] [dcid (variable)]The HMAC is computed over:
[timestamp (8 bytes)] [address bytes] [port (4 bytes)] [dcid bytes]The destination connection id is appended after the HMAC so that the QUIC implementation can extract it at the offset returned by validateToken.
Parameters
a function for providing the secret key used in HMAC signing and validation. If not provided, a random 256-bit key is generated. Provide a shared key when tokens must validate across multiple server instances.
maximum age of a valid token.