tracker
All repositories: gitoria
9.4 KB
// hl:crypto — passwords first. JS transpiler twin of plugins/crypto/crypto.zig.//// Parity contract with the native plugin:// hash(password, options) → a PHC string, freshly salted every call// verify(password, stored) → boolean, timing-safe comparison// parsePhc(stored) → the stored string described, or null// kdf() → the algorithm THIS engine hashes with// sha256(data) → 64 lowercase hex characters// randomBytes(n, encoding) → "hex" (default) or "base64"// toBase64(data) → base64 of a String's UTF-8 or of a Bytes (ticket #90)// fromBase64(text) → a Bytes, or null when text is not base64//// The PHC STRING FORMAT, the strictness of the parser, the cost knob and its cap,// and the salt/output lengths are identical on both engines — a `$scrypt$` string// written by either one verifies on the other, byte for byte, because RFC 7914 is// RFC 7914 whether it is reached through Node's crypto or through libcrypto's// EVP_PBE_scrypt.//// THE ONE DIFFERENCE, stated rather than hidden: Node has no argon2 of any kind,// so this engine hashes with scrypt where the native plugin prefers argon2id on a// host whose libcrypto has it. `parsePhc` still reads argon2id strings here — the// format is just a string — but `verify` on one THROWS instead of answering// `false`, because "I cannot compute this algorithm" is not "wrong password".import { createHash, randomBytes as nodeRandomBytes, scryptSync, timingSafeEqual } from 'node:crypto';// Bytes are the runtime's: this file is copied to hl-modules/crypto.js, beside hl-runtime.js.import { hlMakeBytes, hlIsBytes } from '../hl-runtime.js';// The cost knob: base-2 log of the working memory in KiB. Same numbers as the// native plugin — 15 is 32 MiB (scrypt N = 2^15, r = 8, p = 1 is 128·N·r bytes).const COST_DEFAULT = 15;const COST_MIN = 10; // 1 MiBconst COST_MAX = 17; // 128 MiB — see the note in crypto.zig; the two engines// must cap at the same number or a string one of them// wrote would be out of range for the other.const SALT_LEN = 16;const HASH_LEN = 32;// The floor a stored string must clear to be READ at all — see decodePhc().const MIN_SALT_LEN = 8;const MIN_HASH_LEN = 16;const SCRYPT_R = 8;const SCRYPT_P = 1;// Node refuses a derivation whose 128·N·r exceeds maxmem, default 32 MiB — which// the DEFAULT cost sits exactly on. Raised past the cost cap so the cap is the// only thing that limits anything.const SCRYPT_MAXMEM = 2 * 1024 * 1024 * 1024;const B64_CHARS = /^[A-Za-z0-9+/]+$/;function b64(buf) {return buf.toString('base64').replace(/=+$/, '');}// Deliberately strict, to match the Zig decoder, and BOTH halves of that are// load-bearing:// • Node's base64 reader silently skips characters outside the alphabet, so a// string with junk in it would parse rather than be refused;// • it also drops NON-CANONICAL TRAILING BITS. A 32-byte hash is 43 base64// characters, whose last character carries only two significant bits — so// "…L8E" and "…L8F" decode to the SAME 32 bytes and, before this check,// editing the last character of a stored hash did not change what it// verified against. Zig's decoder refuses that outright; re-encoding is how// this engine reaches the same answer.function unb64(text) {if (!B64_CHARS.test(text)) return null;const buf = Buffer.from(text, 'base64');if (buf.length === 0) return null;if (b64(buf) !== text) return null;return buf;}function paramValue(field, key) {for (const pair of field.split(',')) {const eq = pair.indexOf('=');if (eq < 0) continue;if (pair.slice(0, eq) !== key) continue;const raw = pair.slice(eq + 1);if (!/^[0-9]+$/.test(raw)) return null;const n = Number(raw);return Number.isSafeInteger(n) ? n : null;}return null;}/** Strict PHC decode. Any deviation at all is null — that is what makes a* tampered string fail rather than half-parse into something comparable.** Including the LENGTH FLOOR: a KDF derives as many bytes as it is asked for,* so a stored string whose hash field had been cut down to eight base64* characters derived six bytes and compared six bytes — and six bytes of a* correct derivation match. Truncating the stored value was a way to make a* wrong password verify until this check existed (both engines had it). */function decodePhc(stored) {if (typeof stored !== 'string' || stored.length < 2 || stored[0] !== '$') return null;const parts = stored.slice(1).split('$');if (parts.length > 8) return null;if (parts[0] === 'argon2id') {if (parts.length !== 5) return null;if (!parts[1].startsWith('v=') || !/^[0-9]+$/.test(parts[1].slice(2))) return null;const version = Number(parts[1].slice(2));const m = paramValue(parts[2], 'm');const t = paramValue(parts[2], 't');const p = paramValue(parts[2], 'p');if (m === null || t === null || p === null) return null;const salt = unb64(parts[3]);const hash = unb64(parts[4]);if (!salt || !hash) return null;if (salt.length < MIN_SALT_LEN || hash.length < MIN_HASH_LEN) return null;return { kdf: 'argon2id', version, m, t, p, salt, hash };}if (parts[0] === 'scrypt') {if (parts.length !== 4) return null;const ln = paramValue(parts[1], 'ln');const r = paramValue(parts[1], 'r');const p = paramValue(parts[1], 'p');if (ln === null || r === null || p === null) return null;const salt = unb64(parts[2]);const hash = unb64(parts[3]);if (!salt || !hash) return null;if (salt.length < MIN_SALT_LEN || hash.length < MIN_HASH_LEN) return null;return { kdf: 'scrypt', version: null, ln, r, p, salt, hash };}return null;}function clampCost(value) {if (typeof value !== 'number' || Number.isNaN(value)) return COST_DEFAULT;return Math.trunc(Math.max(COST_MIN, Math.min(COST_MAX, value)));}export function hash(password, options) {if (typeof password !== 'string') throw new Error('hl:crypto hash() expects a string password');const opts = options && typeof options === 'object' ? options : {};const cost = clampCost(opts.cost);const want = typeof opts.kdf === 'string' ? opts.kdf : 'scrypt';if (want === 'argon2id') {throw new Error('hl:crypto hash(): this engine has no argon2id — Node ships no argon2');}if (want !== 'scrypt') {throw new Error('hl:crypto hash(): unknown kdf — expected "argon2id" or "scrypt"');}const salt = nodeRandomBytes(SALT_LEN);const derived = scryptSync(password, salt, HASH_LEN, {N: 2 ** cost, r: SCRYPT_R, p: SCRYPT_P, maxmem: SCRYPT_MAXMEM,});return `$scrypt$ln=${cost},r=${SCRYPT_R},p=${SCRYPT_P}$${b64(salt)}$${b64(derived)}`;}export function verify(password, stored) {if (typeof password !== 'string') return false;const phc = decodePhc(stored);if (phc === null) return false;if (phc.hash.length === 0 || phc.hash.length > 64) return false;if (phc.kdf === 'argon2id') {throw new Error('hl:crypto verify(): stored password is argon2id and this engine has none — Node ships no argon2');}if (phc.ln === 0 || phc.ln > 30 || phc.r === 0 || phc.p === 0) return false;let computed;try {computed = scryptSync(password, phc.salt, phc.hash.length, {N: 2 ** phc.ln, r: phc.r, p: phc.p, maxmem: SCRYPT_MAXMEM,});} catch {// A stored string asking for more memory than this host will give is not a// wrong password, but it is also not something to crash a login over.return false;}return timingSafeEqual(computed, phc.hash);}export function parsePhc(stored) {const phc = decodePhc(stored);if (phc === null) return null;const params = phc.kdf === 'argon2id'? { m: phc.m, t: phc.t, p: phc.p }: { ln: phc.ln, r: phc.r, p: phc.p };return {kdf: phc.kdf,version: phc.version,params,saltLen: phc.salt.length,hashLen: phc.hash.length,};}export function kdf() {return 'scrypt';}export function sha256(data) {if (typeof data !== 'string') throw new Error('hl:crypto sha256() expects a string');return createHash('sha256').update(data, 'utf8').digest('hex');}export function randomBytes(n, encoding) {if (typeof n !== 'number' || !(n >= 1) || n > 1024) {throw new Error('hl:crypto randomBytes(): count must be between 1 and 1024');}const buf = nodeRandomBytes(Math.trunc(n));const enc = typeof encoding === 'string' ? encoding : 'hex';if (enc === 'hex') return buf.toString('hex');if (enc === 'base64') return buf.toString('base64');throw new Error('hl:crypto randomBytes(): encoding must be "hex" or "base64"');}// Base64, standard alphabet (ticket #90) — the rules are crypto.zig's: encoding// pads; decoding takes padded or unpadded text and answers null for anything an// encoder would not have written. Node's own decoder skips what it does not// understand, so the text is checked first and the result re-encoded after.export function toBase64(data) {if (hlIsBytes(data)) return Buffer.from(data._d).toString('base64');if (typeof data !== 'string') throw new Error('hl:crypto toBase64() expects a String or a Bytes');return Buffer.from(data, 'utf8').toString('base64');}export function fromBase64(text) {if (typeof text !== 'string') throw new Error('hl:crypto fromBase64() expects a String');let core = text;if (core.length % 4 === 0) core = core.replace(/={1,2}$/, '');if (core.length % 4 === 1 || !/^[A-Za-z0-9+/]*$/.test(core)) return null;const buf = Buffer.from(core, 'base64');if (buf.toString('base64').replace(/=+$/, '') !== core) return null;return hlMakeBytes(new Uint8Array(buf));}
Branches
- mainmain branch
Latest commits
- 1cda451dtracker: Hybriel master 190aa11d (#127 both shapes, GC correctness fc838894) — conductor adopts despite /my/series 2.4x after jobs (memory 8.0 → 1.7 GB boot); see reports/071mre
- c1fa2f2etracker (mission 071): Hybriel master 190aa11d measured on the real copy vs the live binary 8590df63 — NOT adopted (after the first-start jobs /my/series 2.4x slower, /series 1.6x, RSS swings 7.4-12.2 GB; fresh it is flat at 1.7-2.2 GB and /my/unwatched faster), vendor stays 8efba065, candidate kept in .scratch/w071/vendor-190aa11d; tests/kinds.mjs: collection seed off (its TMDB request broke check 1 in 1 of 4 runs); tests/realdata-071.sh + realdata-071-bench.mjs + tools/realdata-071-table.py; README + STATUS (numbers, how to repeat); gates 325/0, 32/0, 50/0mre
- 8081350atracker docs (mission 070): README (summary, Config HL_GC_BYTES — kept at Hybriel's default, the 256 MiB setting is taken out of docker-compose.yml again: the jobs grew to 12+ GB with it too, see STATUS), Test (three gates), Deploy (first start ~50 min: kinds then seed, restart once after collections done, memory numbers), Vendored Hybriel 8efba065 + #48 audit, Files; STATUS mission 070 entry (merges, migrated counts, lambda audit, gates, RSS old vs new, how to repeat, open points); docs/kinds.md + docs/franchises.md job order; tests/realdata-070-*.sh, tools/count-migrated.hl, tools/ref-params.py, tools/lambda-audit.pymre
- 1ad19c8ctracker: re-vendor Hybriel master 8efba065 (#126 GC by bytes, #48 lambda parameters copy) (mission 070): bin/hybriel sha256 50361e95…, plugins core crypto data fetch fs http http1 mpackdb proc smtp time web; lambda audit: 13 lambdas change a passed record/list (11 through a local alias), no caller relies on it — unchanged; 319 read-only lambda parameters get & (no copy per call: /my/schedule 2.35 → 0.46 s, /my/unwatched 13.7 → 5.7 s on the real copy); /my/unwatched one merge sort instead of n² inserts; docker-compose HL_GC_BYTES=268435456; deploy.sh runs kinds.mjs + franchises.mjs too (default ports 8700–8710); tests/realdata-070.mjs; gates browser 325/0, kinds 32/0, franchises 50/0mre
- 46b21389tracker (mission 070, conductor): the sync never destroys migrated data — the one-time summary step MOVES a copied summary to migratedSummary (marker summaries-moved.txt) instead of clearing it; a migrated record's first title/genres/homepage/tagline TMDB replaces → migratedTitle/migratedGenres/migratedHomepage/migratedTagline, a migrated season's/episode's title/summary → migratedTitle/migratedSummary (set once); tests/peek-shows.hl prints them; gate 325/0mre
- 749019b0Merge t19 (tracker#19 franchises + timelines) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs/faketmdb.mjs, both sides kept; franchise/timeline pages get #20's typed heading (Franchise | …, Timeline | …), their title links via titlePath (/movies|/series|/shows); the collection seed waits for repair, kinds and credits too; franchises.mjs URLs + 2 new checks; gates browser 323/0, kinds 32/0, franchises 50/0mre
- daf49feaMerge t20 (tracker#20 typed headings + #21 series/shows split) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/search.hl/components/search.hl/browser.mjs/faketmdb.mjs, both sides kept; clock order backfill → repair → kinds → credits; withDetailsFields stores tmdbType + kind; gates: browser.mjs URLs → /series|/movies, typed h1 selectors; kinds.mjs repair/credits off, fixture name = seed name; browser 323/0, kinds 32/0mre
- 20e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre
- f83571c3tracker#18 (mission 067): daily sync by change lists — TMDB /tv|movie/changes (since the stored day, paged) + TVmaze /updates/shows → only our changed titles (followed: full step, unfollowed: light step — changed seasons, no TVmaze), full walk on first run / gap > 14 days / failed list; show record refreshed (title, tmdbSummary, tagline, status, genres …; renamed titles re-indexed); summary = the creator's own text (page: summary > tmdbSummary > tvmazeSummary), one-time clear of copied summaries (9,647 on the live copy); gate 261, tests/realdata-018*.mjs, README + STATUSmre
- 1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre
- f2b00674Merge t26 (tracker#26 + #28) into main (mission 062): short ids for every new person (castPersonId, guest route), guest stars stored on the title and created as people only when opened (/person/tmdb/<id>?show=<id> → 302), lean watch/follow clicks (showRow a small object, cast/crew from the slug, watches cached per user, face rows only after a season toggle); gate 311, tests/realdata-062.mjs, README + STATUSmre
- 0553b51ftracker#19 (mission 066): franchises and timelines — tables, /franchises, /franchises/<slug>, /timelines/<slug> (Timeline | Release sort, series by last episode), the Prequel | Timeline | Sequel widget with the franchise above, the creator's editor, TMDB collection seed in the app (resumes, paced); gate tests/franchises.mjs 48/0 + browser.mjs 266/0, tests/realdata-066.mjs, docs/franchises.md, README + STATUSmre
- fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
- 10bb3f93tracker#28 (mission 061): full cast (all seasons, main cast by episodes, guest stars) + crew (created by, directed by, written by, screenplay, story, music) — stored by the details completion, the daily sync, the search import (one details request) and a background credits job (resumes, RSS limit); show page collapsed after 20 with client-side Show all; showBySlug via a slug map; gate 249, tests/realdata-028.mjs, README + STATUSmre
- d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre
- 25a50bc4tracker#26 (mission 059): titles from a filmography are completed — on open (skeleton, step-wise face showComplete, no reload) and by the in-app details repair (resumes, TMDB-paced, series in parts); cast from TMDB credits; gate 231, tests/realdata-026.mjs, README + STATUSmre
- f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
- 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
- f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
- f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre