tracker
All repositories: gitoria
9.4 KB
// hl:crypto — passwords first. JS transpiler twin of plugins/crypto/crypto.zig.//// Parity contract with the native plugin:// hash(password, options) → a PHC string, freshly salted every call// verify(password, stored) → boolean, timing-safe comparison// parsePhc(stored) → the stored string described, or null// kdf() → the algorithm THIS engine hashes with// sha256(data) → 64 lowercase hex characters// randomBytes(n, encoding) → "hex" (default) or "base64"// toBase64(data) → base64 of a String's UTF-8 or of a Bytes (ticket #90)// fromBase64(text) → a Bytes, or null when text is not base64//// The PHC STRING FORMAT, the strictness of the parser, the cost knob and its cap,// and the salt/output lengths are identical on both engines — a `$scrypt$` string// written by either one verifies on the other, byte for byte, because RFC 7914 is// RFC 7914 whether it is reached through Node's crypto or through libcrypto's// EVP_PBE_scrypt.//// THE ONE DIFFERENCE, stated rather than hidden: Node has no argon2 of any kind,// so this engine hashes with scrypt where the native plugin prefers argon2id on a// host whose libcrypto has it. `parsePhc` still reads argon2id strings here — the// format is just a string — but `verify` on one THROWS instead of answering// `false`, because "I cannot compute this algorithm" is not "wrong password".import { createHash, randomBytes as nodeRandomBytes, scryptSync, timingSafeEqual } from 'node:crypto';// Bytes are the runtime's: this file is copied to hl-modules/crypto.js, beside hl-runtime.js.import { hlMakeBytes, hlIsBytes } from '../hl-runtime.js';// The cost knob: base-2 log of the working memory in KiB. Same numbers as the// native plugin — 15 is 32 MiB (scrypt N = 2^15, r = 8, p = 1 is 128·N·r bytes).const COST_DEFAULT = 15;const COST_MIN = 10; // 1 MiBconst COST_MAX = 17; // 128 MiB — see the note in crypto.zig; the two engines// must cap at the same number or a string one of them// wrote would be out of range for the other.const SALT_LEN = 16;const HASH_LEN = 32;// The floor a stored string must clear to be READ at all — see decodePhc().const MIN_SALT_LEN = 8;const MIN_HASH_LEN = 16;const SCRYPT_R = 8;const SCRYPT_P = 1;// Node refuses a derivation whose 128·N·r exceeds maxmem, default 32 MiB — which// the DEFAULT cost sits exactly on. Raised past the cost cap so the cap is the// only thing that limits anything.const SCRYPT_MAXMEM = 2 * 1024 * 1024 * 1024;const B64_CHARS = /^[A-Za-z0-9+/]+$/;function b64(buf) {return buf.toString('base64').replace(/=+$/, '');}// Deliberately strict, to match the Zig decoder, and BOTH halves of that are// load-bearing:// • Node's base64 reader silently skips characters outside the alphabet, so a// string with junk in it would parse rather than be refused;// • it also drops NON-CANONICAL TRAILING BITS. A 32-byte hash is 43 base64// characters, whose last character carries only two significant bits — so// "…L8E" and "…L8F" decode to the SAME 32 bytes and, before this check,// editing the last character of a stored hash did not change what it// verified against. Zig's decoder refuses that outright; re-encoding is how// this engine reaches the same answer.function unb64(text) {if (!B64_CHARS.test(text)) return null;const buf = Buffer.from(text, 'base64');if (buf.length === 0) return null;if (b64(buf) !== text) return null;return buf;}function paramValue(field, key) {for (const pair of field.split(',')) {const eq = pair.indexOf('=');if (eq < 0) continue;if (pair.slice(0, eq) !== key) continue;const raw = pair.slice(eq + 1);if (!/^[0-9]+$/.test(raw)) return null;const n = Number(raw);return Number.isSafeInteger(n) ? n : null;}return null;}/** Strict PHC decode. Any deviation at all is null — that is what makes a* tampered string fail rather than half-parse into something comparable.** Including the LENGTH FLOOR: a KDF derives as many bytes as it is asked for,* so a stored string whose hash field had been cut down to eight base64* characters derived six bytes and compared six bytes — and six bytes of a* correct derivation match. Truncating the stored value was a way to make a* wrong password verify until this check existed (both engines had it). */function decodePhc(stored) {if (typeof stored !== 'string' || stored.length < 2 || stored[0] !== '$') return null;const parts = stored.slice(1).split('$');if (parts.length > 8) return null;if (parts[0] === 'argon2id') {if (parts.length !== 5) return null;if (!parts[1].startsWith('v=') || !/^[0-9]+$/.test(parts[1].slice(2))) return null;const version = Number(parts[1].slice(2));const m = paramValue(parts[2], 'm');const t = paramValue(parts[2], 't');const p = paramValue(parts[2], 'p');if (m === null || t === null || p === null) return null;const salt = unb64(parts[3]);const hash = unb64(parts[4]);if (!salt || !hash) return null;if (salt.length < MIN_SALT_LEN || hash.length < MIN_HASH_LEN) return null;return { kdf: 'argon2id', version, m, t, p, salt, hash };}if (parts[0] === 'scrypt') {if (parts.length !== 4) return null;const ln = paramValue(parts[1], 'ln');const r = paramValue(parts[1], 'r');const p = paramValue(parts[1], 'p');if (ln === null || r === null || p === null) return null;const salt = unb64(parts[2]);const hash = unb64(parts[3]);if (!salt || !hash) return null;if (salt.length < MIN_SALT_LEN || hash.length < MIN_HASH_LEN) return null;return { kdf: 'scrypt', version: null, ln, r, p, salt, hash };}return null;}function clampCost(value) {if (typeof value !== 'number' || Number.isNaN(value)) return COST_DEFAULT;return Math.trunc(Math.max(COST_MIN, Math.min(COST_MAX, value)));}export function hash(password, options) {if (typeof password !== 'string') throw new Error('hl:crypto hash() expects a string password');const opts = options && typeof options === 'object' ? options : {};const cost = clampCost(opts.cost);const want = typeof opts.kdf === 'string' ? opts.kdf : 'scrypt';if (want === 'argon2id') {throw new Error('hl:crypto hash(): this engine has no argon2id — Node ships no argon2');}if (want !== 'scrypt') {throw new Error('hl:crypto hash(): unknown kdf — expected "argon2id" or "scrypt"');}const salt = nodeRandomBytes(SALT_LEN);const derived = scryptSync(password, salt, HASH_LEN, {N: 2 ** cost, r: SCRYPT_R, p: SCRYPT_P, maxmem: SCRYPT_MAXMEM,});return `$scrypt$ln=${cost},r=${SCRYPT_R},p=${SCRYPT_P}$${b64(salt)}$${b64(derived)}`;}export function verify(password, stored) {if (typeof password !== 'string') return false;const phc = decodePhc(stored);if (phc === null) return false;if (phc.hash.length === 0 || phc.hash.length > 64) return false;if (phc.kdf === 'argon2id') {throw new Error('hl:crypto verify(): stored password is argon2id and this engine has none — Node ships no argon2');}if (phc.ln === 0 || phc.ln > 30 || phc.r === 0 || phc.p === 0) return false;let computed;try {computed = scryptSync(password, phc.salt, phc.hash.length, {N: 2 ** phc.ln, r: phc.r, p: phc.p, maxmem: SCRYPT_MAXMEM,});} catch {// A stored string asking for more memory than this host will give is not a// wrong password, but it is also not something to crash a login over.return false;}return timingSafeEqual(computed, phc.hash);}export function parsePhc(stored) {const phc = decodePhc(stored);if (phc === null) return null;const params = phc.kdf === 'argon2id'? { m: phc.m, t: phc.t, p: phc.p }: { ln: phc.ln, r: phc.r, p: phc.p };return {kdf: phc.kdf,version: phc.version,params,saltLen: phc.salt.length,hashLen: phc.hash.length,};}export function kdf() {return 'scrypt';}export function sha256(data) {if (typeof data !== 'string') throw new Error('hl:crypto sha256() expects a string');return createHash('sha256').update(data, 'utf8').digest('hex');}export function randomBytes(n, encoding) {if (typeof n !== 'number' || !(n >= 1) || n > 1024) {throw new Error('hl:crypto randomBytes(): count must be between 1 and 1024');}const buf = nodeRandomBytes(Math.trunc(n));const enc = typeof encoding === 'string' ? encoding : 'hex';if (enc === 'hex') return buf.toString('hex');if (enc === 'base64') return buf.toString('base64');throw new Error('hl:crypto randomBytes(): encoding must be "hex" or "base64"');}// Base64, standard alphabet (ticket #90) — the rules are crypto.zig's: encoding// pads; decoding takes padded or unpadded text and answers null for anything an// encoder would not have written. Node's own decoder skips what it does not// understand, so the text is checked first and the result re-encoded after.export function toBase64(data) {if (hlIsBytes(data)) return Buffer.from(data._d).toString('base64');if (typeof data !== 'string') throw new Error('hl:crypto toBase64() expects a String or a Bytes');return Buffer.from(data, 'utf8').toString('base64');}export function fromBase64(text) {if (typeof text !== 'string') throw new Error('hl:crypto fromBase64() expects a String');let core = text;if (core.length % 4 === 0) core = core.replace(/={1,2}$/, '');if (core.length % 4 === 1 || !/^[A-Za-z0-9+/]*$/.test(core)) return null;const buf = Buffer.from(core, 'base64');if (buf.toString('base64').replace(/=+$/, '') !== core) return null;return hlMakeBytes(new Uint8Array(buf));}
Branches
- mainmain branch
Latest commits
- 7565a863tracker: LOG timemre
- b10f00c8tracker#39: double episodes — migrated episodes whose TMDB id TMDB replaced are adopted by their number in the sync (old id -> migratedTmdbId); merge.hl step 3 merges each season's doubles at start (keeper: most watches > synced > first; watches moved/parked; tombstones into mergedEpisodes, nothing deleted); tools/count-duplicate-episodes.hl; gate fixture + paths-m039; live copy 850 -> 0 in 64 s; gates 373/0, 32/0, 52/0mre
- 8751adb8tracker: report 032mre
- 9bce1f65tracker mission 032: STATUS gate files + the hour-boundary flakemre
- 718bfb89tracker#37 (mission 032): /people = everyone, last updated first (updatedAt stamped by the person fill; view built at boot, touched people first at once), photo + name tiles (person colour) with the /movies pagination, /people/<letter> removed; photo = our file, tmdbProfile, a cast/crew entry's profile (in-memory map at boot), else the new 'no photo' placeholder; new cast/crew/created_by people keep tmdbProfile; search people rows with the photo; /settings = the heading only; util.hl sortDesc starts from sorted runs (same result, 105k: 1.6 s -> 0.15 s); gates 369/0, 32/0, 52/0, check-theme 0; README/STATUS/LOGmre
- 96ba683adeploy.sh: a gate without a 'passed,' line (check-theme) no longer ends the scriptmre
- eb3b9205tracker: report 031mre
- 9b5d2e89tracker mission 031: README (What it does, Test: four gates + the #32 checks, Files: theme/, new pages), STATUS (real copy, A/B load, how to repeat, open points), LOGmre
- 39950e4ctracker#32 (mission 031): the WorldAPI theme (theme/ vendored verbatim from layouts.worldapi.org 85b5654; styles.hl inherits it: accent green-dark, type colours 1-6; own base/header rules, row lines, genre-pill and inverted-button frames removed, the season foldable keeps its line; check-theme 21 -> 0, 4th deploy gate; main actions class primary) and the #32 header (theme AppHeader/MainMenu/UserMenu/Sidebar/ContentFirst: desktop brand, search, Series|Shows|Movies|Genres|People, user icon with Unwatched..Settings, Logout; signed out the ident selector, phone the iD icon dropdown; phone menu in the sidebar overlay; marked entry by :has); /find -> /search/<q>, /genres, /people(/<letter>), /settings; main { ContentFirst { slot } } works around the hl:web one-line slot bug; gates 365/0, 32/0, 52/0, check-theme 0mre
- a386dc92tracker: reports 029 + 030mre
- 71e0fd7dtracker missions 029 + 030: README (What it does, Files, gate count), STATUS (real-copy numbers, how to repeat, open points), LOGmre
- d36ea6eatracker#34 + #35 (mission 030): Follow directly under the poster, as wide as the poster (show.hl, styles.hl); the status pill next to a series' title — TVmaze's status (new tvmazeStatus, stored by the sync's TVmaze merge) else TMDB's, TVmaze Ended + TMDB Canceled = Canceled, inverted (filled, dark text, no border), green running / yellow pending / red canceled / muted ended (shows.hl statusOf); the daily delta asks TVmaze's status of an unfollowed series TVmaze's change list names (dailysync.hl syncRunStep, sync.hl syncTvmazeStatus); the status backfill after the details repair (backfill.hl, jobs.hl statusTick; resumable, 550 ms per TVmaze request); gates 354/0, 32/0, 52/0mre
- 7d7d4487tracker#33 (mission 029): reduced titles — every title TMDB's details never went through this app (no detailsAt, no tmdbSync) is incomplete (shows.hl isIncomplete; the old tracker's migrated rows passed #26's test: 5,697 non-adult on the live copy, 691 series without seasons); the repair job does the visibly reduced first (shows.hl missingParts), the page completes one on open; a title TMDB has no poster for (The Remaining) shows the placeholder; tools/count-incomplete.hl; gate fixtures stand for synced titles (tmdbSync), tests/seed-reduced.hl + #33 checks; gates 347/0, 32/0, 52/0mre
- 661c2592tracker: report 028mre
- 27c916fatracker mission 028: README ("Code order", the new file map), STATUS (counts before/after, tests, how to repeat, open), LOGmre
- d924f398tracker mission 028: comments name the new files (sync.hl, dailysync.hl, backfill.hl, credits.hl, jobs.hl, images.hl …); tools/ref-params.py + tools/lambda-audit.py also scan lib/ (they globbed the root only), lambda-audit counts a plain `x = p` alias like `let x = p`mre
- 2e89b968tracker mission 028 (code order) 5/5 let: `let` only where a variable is reassigned — 667 never-reassigned lets became plain declarations (project.hl, lib/, components/, tools/, tests/); kept: 264 in loop bodies (a plain declaration there is 'Cannot reassign' on the 2nd pass), 234 reassigned, 27 whose name is also a member/outer/free name (a plain write would rebind it); tools/let-audit.py decides and fixes (README 'Code order'); tests/realdata-m028.{sh,mjs} = the page-output diff on a real copy; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
- 54796ff2tracker mission 028 (code order) 4/5 thin faces + last copies: the show page's check/follow faces call lib/watches.hl toggleWatched / toggleSeasonWatched (seasonAllWatched moved there) and lib/follows.hl toggleFollowed; both logins (header selector face, /login/callback) share lib/users.hl userOfCode; todayStr/listOf copies in components and the export readers copied into tools/migrate.hl + tools/old-short-ids.hl now once (lib/util.hl, lib/export.hl); gates 342/0, 32/0, 52/0; old-short-ids output byte-identical, migrate output identicalmre
- 06b078e3tracker mission 028 (code order) 3/5 project.hl is the map: config, routes, wiring and a feature → file index (914 → 258 lines); the background jobs (daily sync run, backfills, details repair, credits job, merge, short ids, collection seed) moved unchanged into lib/jobs.hl (a class: their state is reassigned every step, a static cannot be; one instance made after the server), the login callback into lib/users.hl, poster/photo serving into lib/images.hl, the /shows/<slug> rule into lib/shows.hl showsMovedPath; route handlers are thin wrappers; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
- 94716fd2tracker mission 028 (code order) 2/5 util + topics: lib/util.hl holds envOr, storageDir, postersDir, profilesDir, newId, hexDigits, todayStr, dateOr, textOr, hasId, listOr, firstOf, sortDesc once (were copied into up to 5 files); tmdbsync.hl split into tmdb.hl (TMDB/TVmaze requests), sync.hl (one title's sync), sync-helpers.hl, backfill.hl; details.hl split into details.hl, credits.hl, credits-helpers.hl (isIncomplete to shows.hl); search-helpers.hl (words, query, ranking, slugs); collections.hl (the TMDB collection seed, out of franchises.hl); deltasync.hl renamed dailysync.hl; no behaviour change: gates 342/0, 32/0, 52/0, real-copy pages identicalmre