HmacQuicTokenHandler

class HmacQuicTokenHandler(keyGen: () -> SecretKey = ::generateDefaultKey, tokenLifetime: Duration = TOKEN_LIFETIME_MS.milliseconds) : QuicTokenHandler(source)

A secure QuicTokenHandler that generates and validates QUIC retry tokens using HMAC-SHA256. Tokens bind the client's address and port to a timestamp and are cryptographically signed to prevent forgery. Expired tokens are rejected to mitigate replay attacks.

Assign an instance to NettyHttp3Configuration.quicTokenHandler to enable QUIC address validation via stateless Retry. Note that this adds one round trip to every connection handshake; see NettyHttp3Configuration.quicTokenHandler for the trade-offs.

Token format:

[timestamp (8 bytes)] [HMAC-SHA256 (32 bytes)] [dcid (variable)]

The HMAC is computed over:

[timestamp (8 bytes)] [address bytes] [port (4 bytes)] [dcid bytes]

The destination connection id is appended after the HMAC so that the QUIC implementation can extract it at the offset returned by validateToken.

Report a problem

Parameters

keyGen

a function for providing the secret key used in HMAC signing and validation. If not provided, a random 256-bit key is generated. Provide a shared key when tokens must validate across multiple server instances.

tokenLifetime

maximum age of a valid token.

Constructors

Link copied to clipboard
constructor(keyGen: () -> SecretKey = ::generateDefaultKey, tokenLifetime: Duration = TOKEN_LIFETIME_MS.milliseconds)

Functions

Link copied to clipboard
open override fun maxTokenLength(): Int
Link copied to clipboard
open override fun validateToken(token: ByteBuf, address: InetSocketAddress): Int
Link copied to clipboard
open override fun writeToken(out: ByteBuf, dcid: ByteBuf, address: InetSocketAddress): Boolean