Encryption and the site's users
What your plugin sends through WordPlus Cloud is sealed on the way: the realtime servers carry it without being able to read it or change it. You don't write any encryption code. The site holds the keys, gives each user the ones they may have, and the browser part opens everything before your listener sees it.
What is sealed
| What | Sealed with | Who can open it |
|---|---|---|
| Events your server publishes to a private or presence channel | the channel's key | whoever the channel's owner lets in |
| Client events between browsers on those channels | the channel's key | the same |
A presence member's info | the channel's key | the same |
What a call's and a room's people see of each other (info) | the day's key | everyone the site knows |
| The site's users in the directory (name, avatar, profile link) | the day's key | everyone the site knows |
Public channels are not sealed. Anyone may subscribe to them, so nothing secret belongs there anyway.
The realtime servers see user ids, which key a value needs, and the sealed values. They never hold a key.
How it works
- One master key on the site. The package makes it the first time it's needed and keeps it in the option
wordplus_realtime_master_key. It never leaves WordPress: not to WordPlus Cloud, not to a browser. - Every other key is derived from it, so every plugin on the site, whichever copy of the package it carries, has the same keys. What one plugin seals, another plugin's code opens.
- The browser gets only the keys its user may have:
- a signed-in user's page carries their own key and the day's keys;
- a channel's key comes with the channel's token, from your channel's callback;
- anything else, the page asks the site for (
POST /wp-json/wordplus/v1/realtime/keys), and the site checks again.
- Keys never come from the realtime servers. A key a server handed out could open what the browser seals next, so the browser takes keys from the site only.
- XChaCha20-Poly1305: a value changed on the way doesn't open. PHP seals with sodium, which every WordPress site has (WordPress carries a copy for a PHP without the extension).
Who gets which key
| Key | Label | Given to |
|---|---|---|
| The day's | d:{day} | everyone the site knows: a signed-in user, or a visitor a plugin names (wordplus_realtime_visitor_id) |
| A user's own | u:{id}:{generation} | that user |
| A channel's | ch:{channel}:{generation} | whoever the channel's callback lets in |
| A plugin's own kind | {kind}:{…} | whoever that plugin's callback says |
A user the site cut off gets none (the filter wordplus_realtime_user_has_keys).