gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit1ed5457e1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre1ed5457e/plugins/crypto/server.hl

4.5 KB

  1. \* hl:crypto — passwords first. Native realm wrapper (see server.js for the JS twin).
  2. The whole surface is eight calls, and six of them exist to serve the first two.
  3. What this plugin is FOR is that an application never stores a password: it
  4. stores the answer to "could this password have produced that", and the answer
  5. carries its own algorithm and cost so it stays readable when both change.
  6. hash(password, options) the stored value — a PHC string
  7. verify(password, stored) true / false, in constant time
  8. parsePhc(stored) what a stored value says about itself
  9. kdf() which algorithm THIS host hashes with
  10. sha256(data) content hashing (fast on purpose — not for passwords)
  11. randomBytes(n, encoding) n bytes from the kernel CSPRNG
  12. toBase64(data) a String's or a Bytes' bytes as base64 text
  13. fromBase64(text) base64 text back to a Bytes (null if it is not base64)
  14. The realm is SERVER (plugin.json). A password never crosses to the client, so
  15. importing this file is also a declaration about where the importing code runs. *\
  16. \* Hash a password for storage. Returns a self-describing PHC string:
  17. $argon2id$v=19$m=32768,t=2,p=1$<salt>$<hash>
  18. $scrypt$ln=15,r=8,p=1$<salt>$<hash>
  19. Every call salts freshly, so hashing the same password twice gives two
  20. different strings and both verify.
  21. `options` is optional: { cost = 15; kdf = "argon2id" }
  22. cost base-2 log of the working memory in KiB — 15 is 32 MiB, the default.
  23. CAPPED to 10..17 (1 MiB .. 128 MiB); the string records what was
  24. actually used, so asking for 999 and reading the result back is how
  25. you see the cap rather than being told about it.
  26. kdf force an algorithm instead of taking the host's best one. Normally
  27. unnecessary: `hash` picks argon2id when the system libcrypto has it
  28. (OpenSSL >= 3.2) and scrypt otherwise, and `verify` reads both. *\
  29. hash(password, options) {
  30. return __native("crypto.hash", password, options)
  31. }
  32. \* Check a password against a stored PHC string. The comparison is constant-time
  33. and the answer is a plain boolean: a wrong password, a truncated string, a
  34. flipped character and a string that is not PHC at all are all `false`. A
  35. stored string whose ALGORITHM this host cannot compute is a loud error
  36. instead, because answering `false` to that would read as "wrong password". *\
  37. verify(password, stored) {
  38. return __native("crypto.verify", password, stored)
  39. }
  40. \* Read a stored string without the password:
  41. { kdf = "argon2id"; version = 19; params = { m; t; p }; saltLen; hashLen }
  42. { kdf = "scrypt"; version = null; params = { ln; r; p }; saltLen; hashLen }
  43. `null` when the string is not a PHC string this plugin understands — which is
  44. also the cheapest way to spot a store that was never migrated. *\
  45. parsePhc(stored) {
  46. return __native("crypto.parse", stored)
  47. }
  48. \* Which algorithm `hash()` writes with on this host. Reporting only — nothing
  49. needs to branch on it, because every stored string names its own. *\
  50. kdf() {
  51. return __native("crypto.kdf")
  52. }
  53. \* SHA-256 of a string, as 64 lowercase hex characters. Content hashing: fast by
  54. design, and therefore exactly the wrong tool for a password. *\
  55. sha256(data) {
  56. return __native("crypto.sha256", data)
  57. }
  58. \* n random bytes from the kernel CSPRNG, rendered as "hex" (the default) or
  59. "base64". n is 1..1024. Suitable for session ids, one-time tokens and nonces. *\
  60. randomBytes(n, encoding) {
  61. return __native("crypto.random_bytes", n, encoding)
  62. }
  63. \* Base64 (the standard alphabet, padded) of a String's bytes — its UTF-8 — or
  64. of a Bytes, byte for byte:
  65. toBase64('user:pa55') \\ "dXNlcjpwYTU1"
  66. toBase64(req.bytes) \\ any bytes at all, NUL and 0xff included *\
  67. toBase64(
  68. data \\ a String or a Bytes
  69. ) {
  70. if (hlTypeName(data) == 'Bytes') {
  71. return __native("crypto.base64_encode_hex", data.hex())
  72. }
  73. return __native("crypto.base64_encode", data)
  74. }
  75. \* Base64 text back to its bytes, as a Bytes; `.toString()` of it is the text
  76. when the bytes are UTF-8. Padded and unpadded text both decode; anything
  77. that is not base64 in the standard alphabet is null, not an error — a
  78. malformed `Authorization: Basic` header is an answer, not a crash:
  79. let b = fromBase64(req.headers.authorization.slice(6))
  80. if (b != null) { let pair = b.toString() } \\ "user:pa55" *\
  81. fromBase64(String text) {
  82. let raw = __native("crypto.base64_decode", text)
  83. if (raw == null) {
  84. return null
  85. }
  86. return toBytes(raw)
  87. }

Branches

Latest commits

  • 1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre
  • fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
  • d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre
  • f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
  • 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
  • f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
  • f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre
  • 2b7fdd6cmission 056: signed-out header one row on phones ("Log in", nowrap), backfill skips adult titles' posters, gate checksmre
  • 2c53d5efMerge branch 't16-person' (tracker#16 person pages) into main; filmography shows only public titles (054 adult flag), gate race fix (backfill start line)mre
  • c171227emission 054: hide adult/unknown titles from the public lists and the search; in-app adult-flag backfill (TMDB details + poster per title, resumes), gate + real-data proofmre
  • 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
  • 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre
  • 47a3cae6STATUS: mission 053 merge commit idsmre
  • dcc5eecaMerge branch 't14-search'mre
  • 03edc783Merge branch 't15-tvmaze'mre
  • 71b46345tracker#15: numbering check by date or title, placeholder titles in other languages, docs + real-data proofmre
  • 6bb2daf1tracker#13: homepage (tiles, intro, latest movies/shows), /shows, /movies/page/N, /my/movies; lists cached in memorymre
  • b8bd1157tracker#14: README + STATUS (search, real-data numbers, gate, merge notes)mre
  • 65c694a8tracker#14: search — header magnifier, /search/<text> (in-memory word-prefix index over titles + people), Fetch from web (TMDB search/multi, ours left out), Add = import via syncShow; gate +25 checks, real-data scriptmre
  • 34f2c15btracker#15: TVmaze merge in the sync (gaps only: new episodes/seasons, empty titles/air dates; numbering check), fake TVmaze episodes + gatemre