# Aztris ME Node Integration

Contract: `aztris-me-node/1`

A Node is a registered Property with silent attestation enabled. Create it in **ME Utility → Add property → Node**, then download its integration ZIP. The generated `AME.php` already contains that Node's Property ID, secret, and expected ME account.

If `AME.php` is missing, stop and download the package again. Do not reconstruct or edit the generated credentials.

## Protect one endpoint

Put `AME.php` beside the endpoint:

```php
<?php
$ame = require __DIR__ . '/AME.php';
if ($ame !== true) { http_response_code(403); exit; }
```

The first successful browser visit may briefly pass through Aztris ME. ME sees its own login cookie and establishes Node-local continuity. Later visits stay on the Provider in the browser; the Provider validates that continuity with ME server-to-server.

Flow:

```text
User → Provider: request
Provider → ME: begin user attestation
User → ME → Provider: one-time bootstrap
Provider → ME: consume proof
ME → Provider: Node continuity token

Later:
User → Provider: provider cookie
Provider → ME: revalidate
ME → Provider: active / inactive
Provider → User: local decision
```

Aztris ME answers identity. The Provider owns authorization.

## Node-to-Node trust

Load `AME.php` in library mode:

```php
<?php
$AME_NODE = ['mode' => 'library'];
require __DIR__ . '/AME.php';
```

Target B creates a challenge. Source A obtains a short-lived proof for B. B verifies it with ME:

```text
B → A: challenge
A → ME: attest me for B + challenge
ME → A: temporary proof
A → B: proof
B → ME: verify A + challenge
ME → B: yes / no
```

Source:

```php
$challenge = 'challenge-from-target';
$proof = ame_node_attest_property('TARGET_PROPERTY_ID', $challenge);
$attestation = $proof['attestation'];
```

Target:

```php
$valid = ame_node_verify_property(
    $attestation,
    'EXPECTED_SOURCE_PROPERTY_ID',
    $challenge
);
```

Proofs are short-lived, target-bound, challenge-bound, and one-use. After trust is established, the Nodes communicate directly. ME does not carry the payload.

## Security invariants

- Keep the generated Property secret server-side.
- Do not expose it in HTML, JavaScript, browser storage, URLs, logs, or client-visible errors.
- Do not copy the ME browser cookie. Node continuity uses a Provider-scoped cookie after bootstrap.
- Fail closed when ME cannot validate identity.
- A valid identity assertion does not grant arbitrary local permission; the Provider decides what that identity may do.
- Only Properties explicitly registered with **Node** may call Node attestation endpoints.
