srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/Cargo.toml
AgeCommit message (Collapse)AuthorFilesLines
2026-03-07Declare hmac, sha2 and subtle at the workspace rootsrdusr1-0/+5
crates/server takes all three with workspace = true for the Stripe webhook signature check, but the root manifest never defined them, so a clean checkout did not resolve. They were already in the tree through argon2; this only names them.
2025-12-15Harden for production: dependencies, headers, admin roles, docssrdusr1-3/+8
Dependencies - The server build carried 37 known advisories, including RUSTSEC-2024-0363 in sqlx 0.7, which is the database layer. sqlx moved to 0.8 with default-features off, which also drops the MySQL and SQLite drivers and with them rsa and RUSTSEC-2023-0071. reqwest moved to 0.12, which brings hyper 1.x and was the sole source of every remaining advisory: h2 0.3, rustls-webpki 0.101, rustls-pemfile 1.0 and idna 0.3. - The server build now reports no known vulnerabilities against OSV. cargo audit itself would not compile, so the check queries OSV with the crate versions cargo tree reports for the server binary. - Cargo.lock is committed. This workspace produces binaries, so the lockfile is what makes a deployed build reproducible and the audit above meaningful. Headers - The application sent no security headers at all. The static server now sends a Content-Security-Policy, nosniff, frame options, a referrer policy and a permissions policy; the API sends a policy of its own, since it serves JSON and should load and frame nothing. - The one inline script in index.html moved to a file so script-src needs no unsafe-inline. WebAssembly needs wasm-unsafe-eval, without which nothing types at all, so that is present and explained. - Five style attributes moved to the CSSOM rather than adding unsafe-inline for styles. A style attribute in markup is refused by the policy; the same property set through element.style is not. Production configuration - With TYPERPUNK_ENV=production the server refuses to start if COOKIE_SECURE is off, if DATABASE_URL is still the development default, or if FRONTEND_ORIGIN is http on a non-local host. These were warnings, and a warning in a log nobody reads is not a safeguard. Administration - Moderators were appointed with psql. There is now an admin role, bootstrapped from TYPERPUNK_ADMIN_USERNAME at startup, and a UI to appoint and remove moderators. An administrator's own role cannot be changed through the API, so a mistake cannot lock everyone out of moderation. Corpus - scripts/export_approved.js writes approved submissions back into data/packs/community-*.json. Approved passages are served from the database and merged at startup, so without this the repository dataset and the live corpus drift apart, and a fresh checkout or the TUI sees only what shipped. Documentation - README rewritten for the repository: what it does, how to run it, the pack format, the server variables, deployment, and what the security posture actually is. Plain English, no em dashes, no emoji. Checked and found already correct: every private endpoint refuses anonymous callers, session cookies are HttpOnly and SameSite=Lax, CORS names a single origin, internal errors are logged rather than returned, and every query is parameterised.
2025-12-07Move the server to PostgreSQL, harden the lyrics proxy, add a hacking modesrdusr1-1/+1
PostgreSQL - sqlx switched from the sqlite feature to postgres; the server now runs on Postgres 18 and the SQLite file is gone. - 95 placeholders renumbered from ? to $N. - REAL widened to DOUBLE PRECISION: Postgres REAL is float4 and will not decode into the f64 the code reads. - flagged and is_bot are real BOOLEANs rather than 0/1 integers, with the decode side reading bool. - The leaderboard's derived table gained the alias Postgres requires, its flag comparisons became boolean predicates, and INSERT OR IGNORE became ON CONFLICT DO NOTHING. - u32 binds cast to i64; Postgres has no unsigned integer types. - Integration tests run against a real database - Postgres has no in-memory mode - each in a throwaway schema, with search_path set per connection because it is session state and the pool opens more than one. - Timestamps stay TEXT for now and LISTEN/NOTIFY is still unused; both are recorded in TODO-postgres.md rather than left implied. Custom text and lyrics, checked rather than assumed - Custom files never reach the server: they are read in the browser through the File API, so there is no upload, no path handling and no remote file inclusion to have. Verified by driving a hostile file - markup in the body and in the filename - all the way onto the typing screen: it renders as literal characters, no nodes are created, nothing executes, and the filename is escaped in the attribution too. - That test found a real regression: picking Custom from the new mode picker selected it without ever starting it, so the mode was unstartable. - /api/lyrics fixes its upstream host, so it cannot be pointed elsewhere, but it was an unbounded relay: now rate limited per IP, with length caps on artist and track and a ceiling on the response body it will read. Hacking mode - 22 single-line drills across recon, web, memory safety, exploit development, crypto, post-exploitation and defence, each syntax highlighted and each explaining what the line actually does. All 19 modes verified to start, render and be typable.
2025-12-06Fix content packs, seed the leaderboard, and add the missing site furnituresrdusr1-1/+1
Naming - "Typing Test" removed from the browser tab, the crate description and the READMEs. The scope outgrew it: solo practice, live races, code drills and adaptive weak-key training. Content - Movies was prose *about* film, not film quotes - the same mistake the programming pack had. Replaced with 28 attributed lines. New anime pack, 28 lines across 24 series. - This follows the model TypeRacer states outright ("type quotes from popular music, songs, anime, comic books and more"): short excerpts attributed to the work they came from. The scalable half of their approach is user submission with moderation, which is a feature this does not have yet. Leaderboard - An empty board tells a new player nobody is here. Bots now race the eight fixed-length leaderboard modes, seeded with a fortnight of backdated results on first run and one new result every 90 seconds after. - They are ordinary users carrying is_bot, returned by the same query and labelled "bot" in the UI. Seeding a board is reasonable; passing synthetic scores off as human results is not, so the flag travels with the row. - Seeding is checked per mode. A single result from the live ticker used to satisfy an "any bot results" guard and leave every other mode empty forever. Stats - The per-key accuracy data Practice mode is built on was computed, used to generate text, and never shown. The screen now ranks your weakest keys with the error rate and pause length behind each one. - Added recent form against your lifetime average, best accuracy, and tests this week. Multiplayer standings - Now place, racer, WPM, accuracy and time, with column labels - the columns TypeRacer and 10FastFingers both show. Site furniture - Share (Web Share where available, clipboard otherwise - no third-party button, no tracking script), a GitHub link, and a real privacy page written from what the code actually stores rather than from a template. Button hierarchy - Everything was an outlined box of roughly equal weight, so a screen's one real action, a settings toggle and a filter chip looked alike. Three tiers now: primary (filled, one per screen), default (outlined), quiet (toggles and filters, bordered only when hovered or active).
2025-09-11Add multiplayer bots, typing languages, and rework the UI layoutsrdusr1-17/+60
Multiplayer - Quick match: POST /api/multiplayer/quickmatch returns whichever room is still filling, or opens one. Players never see a room code; joining by code stays for racing specific people. - Bots fill quick-match rooms after a short wait so a new game is never an empty lobby. They only ever join quick-match rooms, never a room opened by code. One or two per room, drawn from separate ~40 and ~80 WPM tiers so two bots are never near each other's pace, and they stall to correct mistakes rather than typing a clean straight line. - Live player count via GET /api/multiplayer/online, shown on the Multiplayer control and under the main menu's Multiplayer button. - Per-racer colours: you are the theme accent, opponents take distinct hues that stay the same from lobby to race. - The countdown no longer holds the room lock for its full three seconds, which is what reset clients mid-countdown. Typing languages - 16 languages for the generated-word modes, each with its own high-frequency vocabulary rather than a translation of the English list. - Picker in the top-right rail; non-English uses its own list at every difficulty tier instead of falling back to English words. Fix UTF-8 accuracy in the game core - update_game_state mixed byte and character counts: total_characters_typed accumulated byte-length deltas while total_correct_characters compared a char index against that byte count. Equal on ASCII, so it went unnoticed; a correctly typed Spanish passage scored 6%. The old byte slicing would also have panicked if an index landed inside a multi-byte character. Rewritten char-based, with regression tests. Programming mode - Replaced prose about programming with real code: 26 syntax-highlighted snippets across JavaScript, Python, Rust, C/Go/Java and shell. Single-line by necessity, since the typing input is a single-line field. Layout and readability - One icon rail arrangement on every screen: Settings/Store under the wordmark, Language/Theme/Friends/Account top-right, Stats/Leaderboard/ Multiplayer bottom-right. - Main menu: mode picker moved out of the Single Player button, which it was notching a divider through and pushing the label off-centre. - Escape returns to the menu, closing any open popover first, and confirms before abandoning a live race. - Split --text-color and --sub-color per theme; they shared one value that measured 3.65:1 against the background, below the 4.5:1 body-text floor. - Semantic colours used in exactly one place each: gold for a personal best, amber for the race countdown and the mobile-result badge. - Passage now sits in the same place on the typing and end screens, and its column is a whole number of characters wide so wrapping cannot leave a permanent gap on the right. - End screen: keystrokes and a correct/wrong/extra/missed split, attribution carried over from the typing screen, and a graph with a separate error axis, axis titles including seconds, and smoothed lines.
2024-10-26Restart project with clean slatesrdusr1-7/+11
2024-03-05Add dependenciessrdusr1-0/+9
2024-02-14Initial commit of empty filessrdusr1-0/+8