gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit7565a8637565a863tracker: LOG timemre7565a863/plugins/crypto/server.hl

4.5 KB

  1. \* hl:crypto — passwords first. Native realm wrapper (see server.js for the JS twin).
  2. The whole surface is eight calls, and six of them exist to serve the first two.
  3. What this plugin is FOR is that an application never stores a password: it
  4. stores the answer to "could this password have produced that", and the answer
  5. carries its own algorithm and cost so it stays readable when both change.
  6. hash(password, options) the stored value — a PHC string
  7. verify(password, stored) true / false, in constant time
  8. parsePhc(stored) what a stored value says about itself
  9. kdf() which algorithm THIS host hashes with
  10. sha256(data) content hashing (fast on purpose — not for passwords)
  11. randomBytes(n, encoding) n bytes from the kernel CSPRNG
  12. toBase64(data) a String's or a Bytes' bytes as base64 text
  13. fromBase64(text) base64 text back to a Bytes (null if it is not base64)
  14. The realm is SERVER (plugin.json). A password never crosses to the client, so
  15. importing this file is also a declaration about where the importing code runs. *\
  16. \* Hash a password for storage. Returns a self-describing PHC string:
  17. $argon2id$v=19$m=32768,t=2,p=1$<salt>$<hash>
  18. $scrypt$ln=15,r=8,p=1$<salt>$<hash>
  19. Every call salts freshly, so hashing the same password twice gives two
  20. different strings and both verify.
  21. `options` is optional: { cost = 15; kdf = "argon2id" }
  22. cost base-2 log of the working memory in KiB — 15 is 32 MiB, the default.
  23. CAPPED to 10..17 (1 MiB .. 128 MiB); the string records what was
  24. actually used, so asking for 999 and reading the result back is how
  25. you see the cap rather than being told about it.
  26. kdf force an algorithm instead of taking the host's best one. Normally
  27. unnecessary: `hash` picks argon2id when the system libcrypto has it
  28. (OpenSSL >= 3.2) and scrypt otherwise, and `verify` reads both. *\
  29. hash(password, options) {
  30. return __native("crypto.hash", password, options)
  31. }
  32. \* Check a password against a stored PHC string. The comparison is constant-time
  33. and the answer is a plain boolean: a wrong password, a truncated string, a
  34. flipped character and a string that is not PHC at all are all `false`. A
  35. stored string whose ALGORITHM this host cannot compute is a loud error
  36. instead, because answering `false` to that would read as "wrong password". *\
  37. verify(password, stored) {
  38. return __native("crypto.verify", password, stored)
  39. }
  40. \* Read a stored string without the password:
  41. { kdf = "argon2id"; version = 19; params = { m; t; p }; saltLen; hashLen }
  42. { kdf = "scrypt"; version = null; params = { ln; r; p }; saltLen; hashLen }
  43. `null` when the string is not a PHC string this plugin understands — which is
  44. also the cheapest way to spot a store that was never migrated. *\
  45. parsePhc(stored) {
  46. return __native("crypto.parse", stored)
  47. }
  48. \* Which algorithm `hash()` writes with on this host. Reporting only — nothing
  49. needs to branch on it, because every stored string names its own. *\
  50. kdf() {
  51. return __native("crypto.kdf")
  52. }
  53. \* SHA-256 of a string, as 64 lowercase hex characters. Content hashing: fast by
  54. design, and therefore exactly the wrong tool for a password. *\
  55. sha256(data) {
  56. return __native("crypto.sha256", data)
  57. }
  58. \* n random bytes from the kernel CSPRNG, rendered as "hex" (the default) or
  59. "base64". n is 1..1024. Suitable for session ids, one-time tokens and nonces. *\
  60. randomBytes(n, encoding) {
  61. return __native("crypto.random_bytes", n, encoding)
  62. }
  63. \* Base64 (the standard alphabet, padded) of a String's bytes — its UTF-8 — or
  64. of a Bytes, byte for byte:
  65. toBase64('user:pa55') \\ "dXNlcjpwYTU1"
  66. toBase64(req.bytes) \\ any bytes at all, NUL and 0xff included *\
  67. toBase64(
  68. data \\ a String or a Bytes
  69. ) {
  70. if (hlTypeName(data) == 'Bytes') {
  71. return __native("crypto.base64_encode_hex", data.hex())
  72. }
  73. return __native("crypto.base64_encode", data)
  74. }
  75. \* Base64 text back to its bytes, as a Bytes; `.toString()` of it is the text
  76. when the bytes are UTF-8. Padded and unpadded text both decode; anything
  77. that is not base64 in the standard alphabet is null, not an error — a
  78. malformed `Authorization: Basic` header is an answer, not a crash:
  79. let b = fromBase64(req.headers.authorization.slice(6))
  80. if (b != null) { let pair = b.toString() } \\ "user:pa55" *\
  81. fromBase64(String text) {
  82. let raw = __native("crypto.base64_decode", text)
  83. if (raw == null) {
  84. return null
  85. }
  86. return toBytes(raw)
  87. }

Branches

Latest commits

  • 7565a863tracker: LOG timemre
  • b10f00c8tracker#39: double episodes — migrated episodes whose TMDB id TMDB replaced are adopted by their number in the sync (old id -> migratedTmdbId); merge.hl step 3 merges each season's doubles at start (keeper: most watches > synced > first; watches moved/parked; tombstones into mergedEpisodes, nothing deleted); tools/count-duplicate-episodes.hl; gate fixture + paths-m039; live copy 850 -> 0 in 64 s; gates 373/0, 32/0, 52/0mre
  • 8751adb8tracker: report 032mre
  • 9bce1f65tracker mission 032: STATUS gate files + the hour-boundary flakemre
  • 718bfb89tracker#37 (mission 032): /people = everyone, last updated first (updatedAt stamped by the person fill; view built at boot, touched people first at once), photo + name tiles (person colour) with the /movies pagination, /people/<letter> removed; photo = our file, tmdbProfile, a cast/crew entry's profile (in-memory map at boot), else the new 'no photo' placeholder; new cast/crew/created_by people keep tmdbProfile; search people rows with the photo; /settings = the heading only; util.hl sortDesc starts from sorted runs (same result, 105k: 1.6 s -> 0.15 s); gates 369/0, 32/0, 52/0, check-theme 0; README/STATUS/LOGmre
  • 96ba683adeploy.sh: a gate without a 'passed,' line (check-theme) no longer ends the scriptmre
  • eb3b9205tracker: report 031mre
  • 9b5d2e89tracker mission 031: README (What it does, Test: four gates + the #32 checks, Files: theme/, new pages), STATUS (real copy, A/B load, how to repeat, open points), LOGmre
  • 39950e4ctracker#32 (mission 031): the WorldAPI theme (theme/ vendored verbatim from layouts.worldapi.org 85b5654; styles.hl inherits it: accent green-dark, type colours 1-6; own base/header rules, row lines, genre-pill and inverted-button frames removed, the season foldable keeps its line; check-theme 21 -> 0, 4th deploy gate; main actions class primary) and the #32 header (theme AppHeader/MainMenu/UserMenu/Sidebar/ContentFirst: desktop brand, search, Series|Shows|Movies|Genres|People, user icon with Unwatched..Settings, Logout; signed out the ident selector, phone the iD icon dropdown; phone menu in the sidebar overlay; marked entry by :has); /find -> /search/<q>, /genres, /people(/<letter>), /settings; main { ContentFirst { slot } } works around the hl:web one-line slot bug; gates 365/0, 32/0, 52/0, check-theme 0mre
  • a386dc92tracker: reports 029 + 030mre
  • 71e0fd7dtracker missions 029 + 030: README (What it does, Files, gate count), STATUS (real-copy numbers, how to repeat, open points), LOGmre
  • d36ea6eatracker#34 + #35 (mission 030): Follow directly under the poster, as wide as the poster (show.hl, styles.hl); the status pill next to a series' title — TVmaze's status (new tvmazeStatus, stored by the sync's TVmaze merge) else TMDB's, TVmaze Ended + TMDB Canceled = Canceled, inverted (filled, dark text, no border), green running / yellow pending / red canceled / muted ended (shows.hl statusOf); the daily delta asks TVmaze's status of an unfollowed series TVmaze's change list names (dailysync.hl syncRunStep, sync.hl syncTvmazeStatus); the status backfill after the details repair (backfill.hl, jobs.hl statusTick; resumable, 550 ms per TVmaze request); gates 354/0, 32/0, 52/0mre
  • 7d7d4487tracker#33 (mission 029): reduced titles — every title TMDB's details never went through this app (no detailsAt, no tmdbSync) is incomplete (shows.hl isIncomplete; the old tracker's migrated rows passed #26's test: 5,697 non-adult on the live copy, 691 series without seasons); the repair job does the visibly reduced first (shows.hl missingParts), the page completes one on open; a title TMDB has no poster for (The Remaining) shows the placeholder; tools/count-incomplete.hl; gate fixtures stand for synced titles (tmdbSync), tests/seed-reduced.hl + #33 checks; gates 347/0, 32/0, 52/0mre
  • 661c2592tracker: report 028mre
  • 27c916fatracker mission 028: README ("Code order", the new file map), STATUS (counts before/after, tests, how to repeat, open), LOGmre
  • d924f398tracker mission 028: comments name the new files (sync.hl, dailysync.hl, backfill.hl, credits.hl, jobs.hl, images.hl …); tools/ref-params.py + tools/lambda-audit.py also scan lib/ (they globbed the root only), lambda-audit counts a plain `x = p` alias like `let x = p`mre
  • 2e89b968tracker mission 028 (code order) 5/5 let: `let` only where a variable is reassigned — 667 never-reassigned lets became plain declarations (project.hl, lib/, components/, tools/, tests/); kept: 264 in loop bodies (a plain declaration there is 'Cannot reassign' on the 2nd pass), 234 reassigned, 27 whose name is also a member/outer/free name (a plain write would rebind it); tools/let-audit.py decides and fixes (README 'Code order'); tests/realdata-m028.{sh,mjs} = the page-output diff on a real copy; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
  • 54796ff2tracker mission 028 (code order) 4/5 thin faces + last copies: the show page's check/follow faces call lib/watches.hl toggleWatched / toggleSeasonWatched (seasonAllWatched moved there) and lib/follows.hl toggleFollowed; both logins (header selector face, /login/callback) share lib/users.hl userOfCode; todayStr/listOf copies in components and the export readers copied into tools/migrate.hl + tools/old-short-ids.hl now once (lib/util.hl, lib/export.hl); gates 342/0, 32/0, 52/0; old-short-ids output byte-identical, migrate output identicalmre
  • 06b078e3tracker mission 028 (code order) 3/5 project.hl is the map: config, routes, wiring and a feature → file index (914 → 258 lines); the background jobs (daily sync run, backfills, details repair, credits job, merge, short ids, collection seed) moved unchanged into lib/jobs.hl (a class: their state is reassigned every step, a static cannot be; one instance made after the server), the login callback into lib/users.hl, poster/photo serving into lib/images.hl, the /shows/<slug> rule into lib/shows.hl showsMovedPath; route handlers are thin wrappers; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
  • 94716fd2tracker mission 028 (code order) 2/5 util + topics: lib/util.hl holds envOr, storageDir, postersDir, profilesDir, newId, hexDigits, todayStr, dateOr, textOr, hasId, listOr, firstOf, sortDesc once (were copied into up to 5 files); tmdbsync.hl split into tmdb.hl (TMDB/TVmaze requests), sync.hl (one title's sync), sync-helpers.hl, backfill.hl; details.hl split into details.hl, credits.hl, credits-helpers.hl (isIncomplete to shows.hl); search-helpers.hl (words, query, ranking, slugs); collections.hl (the TMDB collection seed, out of franchises.hl); deltasync.hl renamed dailysync.hl; no behaviour change: gates 342/0, 32/0, 52/0, real-copy pages identicalmre