Add ChronoSeal product website
No files matched your search
@@ -0,0 +1,403 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>API Reference | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal HTTP API Reference, documenting endpoints, JSON request-response shapes, and WASM exports.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html" class="active">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item active">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Protocol & API</a>
|
||||
<span class="sep">/</span>
|
||||
<span>API Reference</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal API Reference</h1>
|
||||
<p class="doc-subtitle">ChronoSeal exposes a lightweight HTTP API for session handshakes, heartbeat attestation verification, metrics, and statistics.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Endpoint Summary</h2>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Method</th>
|
||||
<th>Path</th>
|
||||
<th>Core Purpose</th>
|
||||
<th>Content Type</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><code>POST</code></td>
|
||||
<td><code>/init</code></td>
|
||||
<td>Create a new attestation session</td>
|
||||
<td><code>application/json</code></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>POST</code></td>
|
||||
<td><code>/hb</code></td>
|
||||
<td>Submit and verify a signed heartbeat</td>
|
||||
<td><code>application/json</code></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>GET</code></td>
|
||||
<td><code>/health</code></td>
|
||||
<td>Check daemon operational health</td>
|
||||
<td><code>application/json</code></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>GET</code></td>
|
||||
<td><code>/stats</code></td>
|
||||
<td>Get runtime database statistics</td>
|
||||
<td><code>application/json</code></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>GET</code></td>
|
||||
<td><code>/metrics</code></td>
|
||||
<td>Prometheus-compatible scraping metrics</td>
|
||||
<td><code>text/plain</code></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>GET</code></td>
|
||||
<td><code>/</code></td>
|
||||
<td>Serve static integration files</td>
|
||||
<td>HTML / JS / WASM</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<h2>Data Encoding Formats</h2>
|
||||
<ul>
|
||||
<li><strong>Keys & Signatures:</strong> Ed25519 public keys represent 64 hex characters (32 bytes). Signatures represent 128 hex characters (64 bytes).</li>
|
||||
<li><strong>Hashes:</strong> Blake3 digests represent 64 hex characters (32 bytes).</li>
|
||||
<li><strong>Salts:</strong> Random seeds represented as 32 hex characters (16 bytes).</li>
|
||||
<li><strong>Timestamps:</strong> Integer epoch milliseconds.</li>
|
||||
<li><strong>Programs:</strong> Base64-encoded strings (representing VM opcodes or mutation steps).</li>
|
||||
</ul>
|
||||
|
||||
<h2><code>POST /init</code></h2>
|
||||
<p>Registers the browser public key and initiates the session tracker.</p>
|
||||
|
||||
<h3>Request Payload</h3>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Request</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"public_key": "24a1b0cd982fecba45...64 hex chars"
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h3>Successful Response (200 OK)</h3>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Response</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"session_id": "8902abc345def678...64 hex chars",
|
||||
"salt": "f51278ba...32 hex chars",
|
||||
"opcodes_b64": "AQAFAwEG...",
|
||||
"initial_hash": "23ab89c0...64 hex chars",
|
||||
"expires_at": 1782390482000,
|
||||
"heartbeat_min_interval_ms": 12000,
|
||||
"heartbeat_max_interval_ms": 25000,
|
||||
"gene_size": 512,
|
||||
"mutation_step": 1,
|
||||
"mutation_order_b64": "YWJjZGVm..."
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h2><code>POST /hb</code></h2>
|
||||
<p>Verifies client compliance for the current step and rolls over session parameters.</p>
|
||||
|
||||
<h3>Request Payload</h3>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Request</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"session_id": "8902abc345def678...64 hex chars",
|
||||
"prev_hash": "23ab89c0...64 hex chars",
|
||||
"timestamp": 1782390494000,
|
||||
"entropy_data": {
|
||||
"events": [
|
||||
{ "x": 124.5, "y": 308.2, "t": 120.4 }
|
||||
]
|
||||
},
|
||||
"stack_state": {
|
||||
"stack": [108429, 3902],
|
||||
"ip": 12
|
||||
},
|
||||
"fingerprint": {
|
||||
"aspectRatio": "1.7777777778",
|
||||
"devicePixelRatio": "2",
|
||||
"hardwareConcurrency": 8
|
||||
},
|
||||
"mutation_step": 1,
|
||||
"gene_commitment": "56ab12cd...64 hex chars",
|
||||
"signature": "ab0921cd56ef...128 hex chars"
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h3>Accepted Response</h3>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Response</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"status": "ok",
|
||||
"next_salt": "78abef90...32 hex chars",
|
||||
"next_mutation_step": 2,
|
||||
"next_mutation_order_b64": "cGFzc3dvcmQ..."
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h3>Rejected Response (Silent Rejection)</h3>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Response</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"status": "ok"
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<div class="doc-alert doc-alert--warn">
|
||||
<div class="doc-alert-icon">⚠️</div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>Important:</strong> Heartbeat rejections return <code>200 OK</code> with <code>status: ok</code> but OMIT next-state fields. Clients must check for the presence of <code>next_salt</code> before advancing local states.
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<h2>Canonical Signing Payload</h2>
|
||||
<p>The Ed25519 signature covers a canonical JSON string. The server orders the keys alphabetically using camelCase notation. Ensure serialization matches this format precisely:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JSON Payload</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>{
|
||||
"entropyData": { "events": [{ "t": 120.4, "x": 124.5, "y": 308.2 }] },
|
||||
"fingerprint": { "aspectRatio": "1.7777777778", "devicePixelRatio": "2", "hardwareConcurrency": 8 },
|
||||
"geneCommitment": "56ab12cd...",
|
||||
"mutationStep": 1,
|
||||
"prevHash": "23ab89c0...",
|
||||
"sessionId": "8902abc3...",
|
||||
"stackState": { "ip": 12, "stack": [108429, 3902] },
|
||||
"timestamp": 1782390494000
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Operational Probes</h2>
|
||||
|
||||
<h3><code>GET /health</code></h3>
|
||||
<div class="code-block">
|
||||
<pre><code>{
|
||||
"status": "healthy"
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h3><code>GET /stats</code></h3>
|
||||
<div class="code-block">
|
||||
<pre><code>{
|
||||
"sessions": 412,
|
||||
"expired_sessions": 3,
|
||||
"max_chain_length": 84
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h3><code>GET /metrics</code></h3>
|
||||
<div class="code-block">
|
||||
<pre><code># HELP chronoseal_sessions Active ChronoSeal sessions
|
||||
# TYPE chronoseal_sessions gauge
|
||||
chronoseal_sessions 412
|
||||
# HELP chronoseal_expired_sessions Expired sessions not yet removed
|
||||
# TYPE chronoseal_expired_sessions gauge
|
||||
chronoseal_expired_sessions 3
|
||||
# HELP chronoseal_max_chain_length Maximum heartbeat chain length
|
||||
# TYPE chronoseal_max_chain_length gauge
|
||||
chronoseal_max_chain_length 84</code></pre>
|
||||
</div>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="protocol.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Protocol Specification</div>
|
||||
</a>
|
||||
<a href="threat-model.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Threat Model</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,300 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Architecture Overview | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal system architecture, state models, components, validation pipelines, and trust boundaries.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html" class="active">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item active">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Core Concepts</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Architecture Overview</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Architecture</h1>
|
||||
<p class="doc-subtitle">ChronoSeal is a Unix-native browser attestation daemon. It validates session continuity by combining cryptographic signatures, hash-chain progression, deterministic VM execution, and a shared Synthetic Gene Mutation Engine.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>System Diagram</h2>
|
||||
<p>The following diagram shows the relationship between browser clients, the daemon process, and the shared protocol library:</p>
|
||||
|
||||
<!-- Inline Architecture Diagram Container -->
|
||||
<div id="diagram-architecture" class="arch-diagram" style="margin-top:24px"></div>
|
||||
|
||||
<h2>Workspace Components</h2>
|
||||
<p>The codebase is structured as a Rust workspace containing three runtime crates and static frontend assets:</p>
|
||||
|
||||
<h3>1. <code>shared/</code> Crate</h3>
|
||||
<p>The <strong>determinism boundary</strong> of ChronoSeal. Any execution logic that must agree precisely between the browser WASM runtime and server verification belongs here. Its responsibilities include:</p>
|
||||
<ul>
|
||||
<li>Wire protocol struct formats for request and response models.</li>
|
||||
<li>Blake3 hash-chain progression functions.</li>
|
||||
<li>Synthetic gene model definitions and commitments.</li>
|
||||
<li>Mutation program bytecode generator, interpreter, and execution tracer.</li>
|
||||
</ul>
|
||||
|
||||
<h3>2. <code>server/</code> Crate</h3>
|
||||
<p>Compiles into the <code>chronoseal</code> daemon binary. It manages the server runtime, HTTP API routes, database backends, and verification logic. Key responsibilities:</p>
|
||||
<ul>
|
||||
<li>CLI command parsing and flag defaults.</li>
|
||||
<li>Axum-based web router and health endpoints.</li>
|
||||
<li>Verification pipeline (signature verification, timestamp drift checks, rate limit validations).</li>
|
||||
<li>Pluggable storage adapters (SQLite memory/disk, Valkey).</li>
|
||||
<li>Background cleanup loop for session purges.</li>
|
||||
</ul>
|
||||
|
||||
<h3>3. <code>wasm/</code> Crate</h3>
|
||||
<p>Compiles into the browser WebAssembly package (using <code>wasm-pack</code>) used by the frontend. Its key functions include:</p>
|
||||
<ul>
|
||||
<li>Secure client-side Ed25519 keypair generation and verification.</li>
|
||||
<li>Message signing for canonical heartbeat payloads.</li>
|
||||
<li>Client-side VM program execution and stack history logging.</li>
|
||||
<li>Previewing, committing, and discarding synthetic gene mutations.</li>
|
||||
</ul>
|
||||
|
||||
<h3>4. <code>frontend/</code> Directory</h3>
|
||||
<p>Contains static JavaScript (<code>heartbeat.js</code>, <code>app.js</code>) and assets served to browsers to orchestrate background attestation calls without blocking UI rendering.</p>
|
||||
|
||||
<h2>Session State Model</h2>
|
||||
<p>The daemon stores a single <code>SessionRecord</code> in the active database per session, structured as follows:</p>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Field</th>
|
||||
<th>Core Description</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><code>session_id</code></td>
|
||||
<td>Random 32-byte session lookup key.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>public_key</code></td>
|
||||
<td>Registered Ed25519 public key. Used to verify all heartbeats.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>salt</code></td>
|
||||
<td>Current server salt required to verify the next heartbeat.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>last_hash</code></td>
|
||||
<td>Current accepted Blake3 hash head. Prevents out-of-order repeats.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>gene</code></td>
|
||||
<td>Committed synthetic gene byte buffer.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>pending_mutation</code></td>
|
||||
<td>The mutation program compiled by the server for the next heartbeat step.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>pending_mutation_step</code></td>
|
||||
<td>Mismatches between this and request steps cause silent rejection.</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<div class="doc-alert doc-alert--warn">
|
||||
<div class="doc-alert-icon">⚠️</div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>State Invariant:</strong> The server-side session state advances ONLY after a heartbeat passes all pipeline validations. Failed heartbeats never alter the stored salt, hash, or gene parameters, preventing desynchronization exploits.
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<h2>Verification Pipeline</h2>
|
||||
<p>Heartbeat verification follows a strict chronological order. If any check fails, execution immediately halts, returning the silent rejection response. The pipeline is:</p>
|
||||
<ol>
|
||||
<li>Load the session record using the submitted <code>session_id</code>.</li>
|
||||
<li>Assert that the session exists and has not expired (<code>now < expires_at</code>).</li>
|
||||
<li>Verify the Ed25519 signature against the reconstructed canonical JSON payload.</li>
|
||||
<li>Assert the request's <code>prev_hash</code> matches the server-stored <code>last_hash</code>.</li>
|
||||
<li>Compare request step with <code>pending_mutation_step</code>.</li>
|
||||
<li>Apply the stored <code>pending_mutation</code> to a cloned gene buffer.</li>
|
||||
<li>Assert the computed gene commitment matches the request's <code>gene_commitment</code>.</li>
|
||||
<li>Assert that the timestamp drift matches liveness bounds (within 30 seconds).</li>
|
||||
<li>Assert that mouse activity entropy is present and speed falls within thresholds.</li>
|
||||
<li>Assert screen aspect ratio, device pixel ratio, and concurrency parameters match bounds.</li>
|
||||
<li>Advance the session's hash head, rotate the salt, compile the next mutation program, and persist.</li>
|
||||
</ol>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="comparison.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">ChronoSeal vs Others</div>
|
||||
</a>
|
||||
<a href="protocol.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Protocol Specification</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
<script src="js/diagrams.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
|
After Width: | Height: | Size: 168 KiB |
@@ -0,0 +1,127 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<svg
|
||||
version="1.1"
|
||||
id="Layer_1"
|
||||
x="0px"
|
||||
y="0px"
|
||||
width="296.99997mm"
|
||||
viewBox="0 0 1122.5196 793.7008"
|
||||
enable-background="new 0 0 1254 1254"
|
||||
xml:space="preserve"
|
||||
height="210mm"
|
||||
sodipodi:docname="chronoseal.svg"
|
||||
inkscape:export-filename="logo1.png"
|
||||
inkscape:export-xdpi="96"
|
||||
inkscape:export-ydpi="96"
|
||||
inkscape:version="1.4.4 (dcaf3e7d9e, 2026-05-05)"
|
||||
xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
|
||||
xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd"
|
||||
xmlns="http://www.w3.org/2000/svg"
|
||||
xmlns:svg="http://www.w3.org/2000/svg"><sodipodi:namedview
|
||||
id="namedview1"
|
||||
pagecolor="#ffffff"
|
||||
bordercolor="#000000"
|
||||
borderopacity="0.25"
|
||||
inkscape:showpageshadow="2"
|
||||
inkscape:pageopacity="0.0"
|
||||
inkscape:pagecheckerboard="0"
|
||||
inkscape:deskcolor="#d1d1d1"
|
||||
inkscape:document-units="mm"
|
||||
inkscape:zoom="1.1654266"
|
||||
inkscape:cx="561.16791"
|
||||
inkscape:cy="396.85039"
|
||||
inkscape:window-width="2048"
|
||||
inkscape:window-height="1205"
|
||||
inkscape:window-x="0"
|
||||
inkscape:window-y="0"
|
||||
inkscape:window-maximized="1"
|
||||
inkscape:current-layer="Layer_1" /><defs
|
||||
id="defs44" />
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<path
|
||||
fill="none"
|
||||
opacity="0"
|
||||
stroke="none"
|
||||
d="m 791.89377,632.01366 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77527,34.39209 -143.33667,69.23047 -215.00567,103.84463 -8.40815,4.06091 -14.32166,9.84101 -14.39978,19.74008 -0.079,10.00498 5.52282,16.22797 14.08978,20.54743 12.3277,6.21567 24.51239,12.71484 37.34228,19.41369 7.51429,3.93381 14.42273,7.5896 21.37854,11.15274 31.68775,16.23208 63.40558,32.40548 95.07782,48.66778 14.943,7.6726 29.74964,15.6123 44.73053,23.2091 8.44464,4.2823 16.79547,9.1534 25.75525,11.9324 18.81989,5.8372 37.10712,3.9335 54.83185,-5.5578 25.51599,-13.6634 51.41541,-26.6141 77.2135,-39.7465 30.82071,-15.6894 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z"
|
||||
id="path2" /><path
|
||||
fill="#4b4d51"
|
||||
opacity="1"
|
||||
stroke="none"
|
||||
d="m 791.89376,550.60089 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77522,34.39209 -143.33662,69.23047 -215.00562,103.84463 -8.4082,4.06091 -14.3217,9.84101 -14.3998,19.74008 -0.079,10.00498 5.5228,16.22797 14.0898,20.54743 12.3277,6.21567 24.5123,12.71484 37.3422,19.41369 7.5143,3.93381 14.4228,7.5896 21.3786,11.15274 31.6877,16.23212 63.4056,32.40552 95.0778,48.66782 14.943,7.67261 29.7496,15.61227 44.73052,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z"
|
||||
id="path45"
|
||||
style="fill:#e1e1e4;fill-opacity:1" /><path
|
||||
fill="#4b4d51"
|
||||
opacity="1"
|
||||
stroke="none"
|
||||
d="m 791.89377,469.18814 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 C 767.4184,378.3558 705.7113,348.37296 643.97308,318.45444 c -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77527,34.39209 -143.33667,69.23047 -215.00567,103.84463 -8.40815,4.06091 -14.32166,9.84101 -14.39978,19.74008 -0.079,10.00498 5.52282,16.22797 14.08978,20.54743 12.3277,6.21567 24.51239,12.71484 37.34228,19.41369 7.51429,3.93381 14.42273,7.5896 21.37854,11.15274 31.68775,16.23212 63.40558,32.40552 95.07782,48.66782 14.943,7.67261 29.74964,15.61227 44.73053,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z"
|
||||
id="path46"
|
||||
style="fill:#b0b2b8;fill-opacity:1" /><path
|
||||
fill="#4b4d51"
|
||||
opacity="1"
|
||||
stroke="none"
|
||||
d="m 791.89377,387.77539 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77527,34.39209 -143.33667,69.23047 -215.00567,103.84463 -8.40815,4.06091 -14.32166,9.84101 -14.39978,19.74008 -0.079,10.00498 5.52282,16.22797 14.08978,20.54743 12.3277,6.21567 24.51239,12.71484 37.34228,19.41369 7.51429,3.93381 14.42273,7.5896 21.37854,11.15274 31.68775,16.23212 63.40558,32.40552 95.07782,48.66782 14.943,7.67261 29.74964,15.61227 44.73053,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z"
|
||||
id="path47"
|
||||
style="fill:#7b7e85;fill-opacity:1" /><text
|
||||
xml:space="preserve"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:160px;font-family:'URW Gothic';-inkscape-font-specification:'URW Gothic, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;writing-mode:lr-tb;direction:ltr;fill:#e1e1e4;fill-opacity:1;stroke-width:39.1"
|
||||
x="154.54701"
|
||||
y="550.13623"
|
||||
id="text47"><tspan
|
||||
id="tspan47"
|
||||
x="154.54701"
|
||||
y="550.13623" /><tspan
|
||||
id="tspan48"
|
||||
x="154.54701"
|
||||
y="750.13623"
|
||||
style="font-style:normal;font-variant:normal;font-weight:600;font-stretch:normal;font-size:160px;font-family:'URW Gothic';-inkscape-font-specification:'URW Gothic, Semi-Bold';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal"><tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:600;font-stretch:normal;font-size:160px;font-family:'URW Gothic';-inkscape-font-specification:'URW Gothic, Semi-Bold';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#1f2024;fill-opacity:1"
|
||||
id="tspan49">chrono</tspan>seal</tspan></text><path
|
||||
fill="#4b4d51"
|
||||
opacity="1"
|
||||
stroke="none"
|
||||
d="m 791.89376,306.36264 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77522,34.39209 -143.33662,69.23047 -215.00562,103.84463 -8.4082,4.06091 -14.3217,9.84101 -14.3998,19.74008 -0.079,10.00498 5.5228,16.22797 14.0898,20.54743 12.3277,6.21567 24.5123,12.71484 37.3422,19.41369 7.5143,3.93381 14.4228,7.5896 21.3786,11.15274 31.6877,16.23212 63.4056,32.40552 95.0778,48.66782 14.943,7.67261 29.7496,15.61227 44.73052,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z"
|
||||
id="path1"
|
||||
style="fill:#4a4d53;fill-opacity:1" /></svg>
|
||||
|
After Width: | Height: | Size: 8.1 KiB |
@@ -0,0 +1,356 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>ChronoSeal vs Commercial Anti-Bot Systems | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="Compare ChronoSeal honestly with commercial anti-bot Edge/SaaS platforms like Cloudflare, Akamai, PerimeterX, and reCAPTCHA.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html" class="active">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item active">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Core Concepts</a>
|
||||
<span class="sep">/</span>
|
||||
<span>ChronoSeal vs Others</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal vs Popular Anti-Bot Systems</h1>
|
||||
<p class="doc-subtitle">ChronoSeal is a self-hosted, cryptographic attestation daemon. This document compares it honestly with leading commercial solutions.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Quick Comparison Matrix</h2>
|
||||
|
||||
<div class="comparison-table-wrap" style="margin-bottom: 2rem;">
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Solution</th>
|
||||
<th>Type</th>
|
||||
<th>Core Method</th>
|
||||
<th>Privacy</th>
|
||||
<th>Self-Hosted</th>
|
||||
<th>Strength</th>
|
||||
<th>Behavioral</th>
|
||||
<th>Cost</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><strong>ChronoSeal</strong></td>
|
||||
<td>Self-hosted Daemon</td>
|
||||
<td>Ed25519 + Gene Mutation</td>
|
||||
<td><span class="check"><i class="fas fa-check-circle"></i> Excellent</span></td>
|
||||
<td>Yes</td>
|
||||
<td>Very High</td>
|
||||
<td>Light + Tunable</td>
|
||||
<td><span class="check"><i class="fas fa-check-circle"></i> Free</span></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Cloudflare Bot Mgmt</td>
|
||||
<td>Cloud Edge</td>
|
||||
<td>Challenges + Fingerprint</td>
|
||||
<td>Medium</td>
|
||||
<td>No</td>
|
||||
<td>Medium</td>
|
||||
<td>Strong</td>
|
||||
<td>Freemium</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Akamai Bot Manager</td>
|
||||
<td>Enterprise Edge</td>
|
||||
<td>Fingerprinting + Heuristics</td>
|
||||
<td><span class="times"><i class="fas fa-times-circle"></i> Low</span></td>
|
||||
<td>Hybrid</td>
|
||||
<td>Medium</td>
|
||||
<td>Very Strong</td>
|
||||
<td>Very High</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>HUMAN (PerimeterX)</td>
|
||||
<td>Cloud SaaS</td>
|
||||
<td>Behavioral Biometrics + ML</td>
|
||||
<td><span class="times"><i class="fas fa-times-circle"></i> Low</span></td>
|
||||
<td>No</td>
|
||||
<td>Medium</td>
|
||||
<td>Very Strong</td>
|
||||
<td>Enterprise</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>DataDome</td>
|
||||
<td>Cloud SaaS</td>
|
||||
<td>Real-time ML scoring</td>
|
||||
<td>Medium</td>
|
||||
<td>No</td>
|
||||
<td>Medium</td>
|
||||
<td>Strong</td>
|
||||
<td>Enterprise</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>reCAPTCHA v3</td>
|
||||
<td>Google Service</td>
|
||||
<td>Invisible risk challenges</td>
|
||||
<td><span class="times"><i class="fas fa-times-circle"></i> Poor</span></td>
|
||||
<td>No</td>
|
||||
<td>Low</td>
|
||||
<td>Medium</td>
|
||||
<td>Free → Paid</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Kasada</td>
|
||||
<td>Cloud SaaS</td>
|
||||
<td>Proof-of-Work + Obfuscation</td>
|
||||
<td>Medium</td>
|
||||
<td>No</td>
|
||||
<td>High</td>
|
||||
<td>Strong</td>
|
||||
<td>Enterprise</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<h2>Detailed Analysis</h2>
|
||||
|
||||
<h3>1. ChronoSeal (v1.0.2)</h3>
|
||||
<p><strong>Strengths:</strong></p>
|
||||
<ul>
|
||||
<li>Strongest cryptographic foundation (Ed25519 signatures + Blake3 hash chain + Synthetic Gene Mutation Engine).</li>
|
||||
<li>Fully deterministic server ↔ WASM execution agreement.</li>
|
||||
<li>Completely invisible to users with silent rejection mechanics.</li>
|
||||
<li>Excellent privacy posture — no third-party tracking, profiling, or persistent databases.</li>
|
||||
<li>Tunable mutation complexity parameters (<code>gene_size</code> and <code>mutation_rounds</code>).</li>
|
||||
<li>100% control, auditability, and local operations.</li>
|
||||
</ul>
|
||||
<p><strong>Weaknesses:</strong></p>
|
||||
<ul>
|
||||
<li>Requires self-hosting, configuration management, and server capacity.</li>
|
||||
<li>No global threat intelligence network or shared IP reputation lists.</li>
|
||||
</ul>
|
||||
|
||||
<h3>2. Cloudflare Bot Management</h3>
|
||||
<p><strong>Strengths:</strong></p>
|
||||
<ul>
|
||||
<li>Extremely easy to deploy for domains already routed through Cloudflare.</li>
|
||||
<li>Excellent scale and global threat reputation database.</li>
|
||||
</ul>
|
||||
<p><strong>Weaknesses vs ChronoSeal:</strong></p>
|
||||
<ul>
|
||||
<li>Relies heavily on browser fingerprint heuristics and invasive JS challenges.</li>
|
||||
<li>Sends visitor metadata to Cloudflare (privacy impact).</li>
|
||||
<li>Vendor lock-in and zero visibility into decision algorithms.</li>
|
||||
</ul>
|
||||
|
||||
<h3>3. Enterprise Solutions (Akamai, HUMAN, DataDome, Kasada)</h3>
|
||||
<p><strong>Strengths:</strong></p>
|
||||
<ul>
|
||||
<li>Sophisticated machine learning modeling of biometrics and timing.</li>
|
||||
<li>Professional support, operational SLAs, and security response teams.</li>
|
||||
</ul>
|
||||
<p><strong>Weaknesses vs ChronoSeal:</strong></p>
|
||||
<ul>
|
||||
<li>Extremely expensive enterprise licensing models.</li>
|
||||
<li>Black-box systems with limited logging and transparency.</li>
|
||||
<li>Heavy user data collection, causing privacy and compliance overhead.</li>
|
||||
</ul>
|
||||
|
||||
<h3>4. reCAPTCHA v3</h3>
|
||||
<p><strong>Strengths:</strong></p>
|
||||
<ul>
|
||||
<li>Free tier with wide community adoption.</li>
|
||||
<li>Quick to integrate in basic web forms.</li>
|
||||
</ul>
|
||||
<p><strong>Weaknesses vs ChronoSeal:</strong></p>
|
||||
<ul>
|
||||
<li>Heavy Google user tracking cookies and profiling.</li>
|
||||
<li>Fails to block modern, stateful automated browsers and headless runs.</li>
|
||||
<li>High rate of bypasses by standard captcha-solving farms.</li>
|
||||
</ul>
|
||||
|
||||
<h2>When to Choose ChronoSeal</h2>
|
||||
<p>Choose <strong>ChronoSeal</strong> if you want:</p>
|
||||
<ul>
|
||||
<li>Maximum visitor privacy.</li>
|
||||
<li>Strong, deterministic cryptographic guarantees.</li>
|
||||
<li>Complete control over your server infrastructure and logs.</li>
|
||||
<li>Configurable and tunable verification strength.</li>
|
||||
<li>Zero dependency on third-party SaaS vendors.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Technical Differentiation</h2>
|
||||
<p>ChronoSeal's primary advantage is the <strong>Synthetic Gene Mutation Engine</strong>. Instead of just checking static fingerprint values or browser headers, the server issues dynamic mutation programs that both the server and client WASM execute in sync. This establishes a second stateful channel that is extremely difficult for automation clients to spoof at scale without implementing the complete state model.</p>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="security.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Security Policy</div>
|
||||
</a>
|
||||
<a href="architecture.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Architecture Overview</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,984 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Design System — chronoseal.css
|
||||
Vibrant, premium, glassmorphism theme matching the target site
|
||||
============================================================ */
|
||||
|
||||
/* ---- Custom Properties ---- */
|
||||
:root {
|
||||
--bg-primary: #0a0e27;
|
||||
--bg-secondary: #11162e;
|
||||
--bg-card: rgba(18, 24, 48, 0.7);
|
||||
--bg-card-solid: #121830;
|
||||
--border: rgba(56, 78, 135, 0.3);
|
||||
--border-glow: rgba(0, 255, 255, 0.2);
|
||||
--text-primary: #ffffff;
|
||||
--text-secondary: #a0a8c3;
|
||||
--text-muted: #5a6490;
|
||||
|
||||
--accent-cyan: #00e5ff;
|
||||
--accent-purple: #b84eff;
|
||||
--accent-green: #00ff88;
|
||||
--accent-red: #ff4757;
|
||||
|
||||
--gradient-1: linear-gradient(135deg, #00e5ff 0%, #b84eff 100%);
|
||||
--gradient-2: linear-gradient(135deg, #00ff88 0%, #00e5ff 100%);
|
||||
--shadow-glow: 0 0 30px rgba(0, 229, 255, 0.1);
|
||||
|
||||
--font-sans: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, 'Helvetica Neue', Arial, sans-serif;
|
||||
--font-mono: 'SF Mono', Monaco, 'Cascadia Code', 'Roboto Mono', Consolas, 'Courier New', monospace;
|
||||
|
||||
--max-width: 1400px;
|
||||
--header-h: 75px;
|
||||
--r-sm: 8px;
|
||||
--r-md: 12px;
|
||||
--r-lg: 20px;
|
||||
--ease: cubic-bezier(0.175, 0.885, 0.32, 1.275);
|
||||
--tr: .3s ease;
|
||||
}
|
||||
|
||||
/* ---- Reset ---- */
|
||||
*, *::before, *::after {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
html {
|
||||
scroll-behavior: smooth;
|
||||
-webkit-text-size-adjust: 100%;
|
||||
}
|
||||
|
||||
body {
|
||||
font-family: var(--font-sans);
|
||||
background: var(--bg-primary);
|
||||
color: var(--text-primary);
|
||||
line-height: 1.6;
|
||||
overflow-x: hidden;
|
||||
-webkit-font-smoothing: antialiased;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-secondary);
|
||||
text-decoration: none;
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
a:hover {
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
img, svg {
|
||||
max-width: 100%;
|
||||
display: block;
|
||||
}
|
||||
|
||||
button {
|
||||
cursor: pointer;
|
||||
font-family: inherit;
|
||||
border: none;
|
||||
background: none;
|
||||
}
|
||||
|
||||
code, pre {
|
||||
font-family: var(--font-mono);
|
||||
}
|
||||
|
||||
/* Scrollbar */
|
||||
::-webkit-scrollbar {
|
||||
width: 8px;
|
||||
height: 8px;
|
||||
}
|
||||
::-webkit-scrollbar-track {
|
||||
background: var(--bg-primary);
|
||||
}
|
||||
::-webkit-scrollbar-thumb {
|
||||
background: var(--border);
|
||||
border-radius: 4px;
|
||||
}
|
||||
::-webkit-scrollbar-thumb:hover {
|
||||
background: var(--accent-cyan);
|
||||
}
|
||||
|
||||
/* ---- Layout ---- */
|
||||
.container, .main-content {
|
||||
width: 100%;
|
||||
max-width: var(--max-width);
|
||||
margin: 0 auto;
|
||||
padding: 0 2rem;
|
||||
}
|
||||
|
||||
.main-content {
|
||||
padding-top: var(--header-h);
|
||||
}
|
||||
|
||||
.section {
|
||||
padding: 6rem 0;
|
||||
scroll-margin-top: 100px;
|
||||
}
|
||||
|
||||
.text-center {
|
||||
text-align: center;
|
||||
}
|
||||
|
||||
.arch-diagram {
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
margin: 2rem auto;
|
||||
max-width: 100%;
|
||||
}
|
||||
|
||||
.arch-diagram svg {
|
||||
display: block;
|
||||
margin: 0 auto;
|
||||
max-width: 100%;
|
||||
}
|
||||
|
||||
.section--alt {
|
||||
background: var(--bg-secondary);
|
||||
border-top: 1px solid var(--border);
|
||||
border-bottom: 1px solid var(--border);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
BACKGROUND ANIMATION
|
||||
============================================================ */
|
||||
.bg-animation {
|
||||
position: fixed;
|
||||
top: 0;
|
||||
left: 0;
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
z-index: -1;
|
||||
overflow: hidden;
|
||||
pointer-events: none;
|
||||
}
|
||||
|
||||
.gradient-sphere {
|
||||
position: absolute;
|
||||
border-radius: 50%;
|
||||
filter: blur(80px);
|
||||
opacity: 0.4;
|
||||
animation: float 20s infinite ease-in-out;
|
||||
will-change: transform;
|
||||
}
|
||||
|
||||
.sphere-1 { width: 600px; height: 600px; background: var(--accent-cyan); top: -200px; right: -200px; animation-delay: 0s; }
|
||||
.sphere-2 { width: 500px; height: 500px; background: var(--accent-purple); bottom: -150px; left: -150px; animation-delay: -5s; }
|
||||
.sphere-3 { width: 400px; height: 400px; background: var(--accent-green); top: 40%; left: 30%; animation-delay: -10s; opacity: 0.2; }
|
||||
|
||||
@keyframes float {
|
||||
0%, 100% { transform: translate(0, 0) scale(1); }
|
||||
33% { transform: translate(30px, -30px) scale(1.05); }
|
||||
66% { transform: translate(-20px, 20px) scale(0.95); }
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
NAVBAR / HEADER
|
||||
============================================================ */
|
||||
.navbar {
|
||||
position: fixed;
|
||||
top: 0;
|
||||
left: 0;
|
||||
right: 0;
|
||||
z-index: 1000;
|
||||
background: rgba(10, 14, 39, 0.85);
|
||||
backdrop-filter: blur(12px);
|
||||
-webkit-backdrop-filter: blur(12px);
|
||||
border-bottom: 1px solid transparent;
|
||||
padding: 1.25rem 2rem;
|
||||
transition: all 0.3s ease;
|
||||
}
|
||||
|
||||
.navbar.scrolled {
|
||||
padding: 0.75rem 2rem;
|
||||
background: rgba(10, 14, 39, 0.98);
|
||||
border-bottom: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.nav-container {
|
||||
max-width: var(--max-width);
|
||||
margin: 0 auto;
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.logo {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 0.75rem;
|
||||
font-size: 1.5rem;
|
||||
font-weight: 800;
|
||||
background: var(--gradient-1);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
.logobar {
|
||||
width: 32px;
|
||||
height: 32px;
|
||||
}
|
||||
|
||||
.logo span {
|
||||
color: transparent;
|
||||
background: var(--gradient-1);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
}
|
||||
|
||||
.nav-links {
|
||||
display: flex;
|
||||
gap: 2.5rem;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.nav-links a {
|
||||
color: var(--text-secondary);
|
||||
text-decoration: none;
|
||||
transition: color 0.3s ease;
|
||||
font-weight: 500;
|
||||
font-size: 0.95rem;
|
||||
}
|
||||
|
||||
.nav-links a:hover, .nav-links a.active {
|
||||
color: var(--text-primary);
|
||||
text-shadow: 0 0 10px rgba(0, 229, 255, 0.4);
|
||||
}
|
||||
|
||||
.github-btn {
|
||||
background: var(--bg-card-solid);
|
||||
padding: 0.5rem 1.25rem;
|
||||
border-radius: 8px;
|
||||
border: 1px solid var(--border);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 0.5rem;
|
||||
transition: all 0.3s ease;
|
||||
}
|
||||
|
||||
.github-btn:hover {
|
||||
border-color: var(--accent-cyan);
|
||||
box-shadow: 0 0 15px rgba(0, 229, 255, 0.2);
|
||||
}
|
||||
|
||||
.nav-toggle {
|
||||
display: none;
|
||||
background: none;
|
||||
border: none;
|
||||
color: var(--text-primary);
|
||||
font-size: 1.5rem;
|
||||
cursor: pointer;
|
||||
transition: color 0.3s ease;
|
||||
}
|
||||
|
||||
/* Nav Dropdown */
|
||||
.nav-dropdown {
|
||||
position: relative;
|
||||
}
|
||||
|
||||
.nav-dropdown-menu {
|
||||
position: absolute;
|
||||
top: calc(100% + 15px);
|
||||
left: 50%;
|
||||
transform: translateX(-50%) translateY(8px);
|
||||
min-width: 220px;
|
||||
background: var(--bg-card-solid);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--r-md);
|
||||
padding: 6px;
|
||||
opacity: 0;
|
||||
pointer-events: none;
|
||||
transition: opacity var(--tr), transform var(--tr);
|
||||
box-shadow: 0 16px 48px rgba(0,0,0,.4);
|
||||
backdrop-filter: blur(10px);
|
||||
}
|
||||
|
||||
.nav-dropdown:hover .nav-dropdown-menu {
|
||||
opacity: 1;
|
||||
pointer-events: auto;
|
||||
transform: translateX(-50%) translateY(0);
|
||||
}
|
||||
|
||||
.nav-dropdown-menu a {
|
||||
display: block;
|
||||
padding: 8px 14px;
|
||||
font-size: .88rem;
|
||||
color: var(--text-secondary);
|
||||
border-radius: var(--r-sm);
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
.nav-dropdown-menu a:hover {
|
||||
color: var(--text-primary);
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
HERO SECTION
|
||||
============================================================ */
|
||||
.hero {
|
||||
text-align: center;
|
||||
padding: 6rem 0;
|
||||
}
|
||||
|
||||
.hero-badge {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 0.5rem;
|
||||
padding: 0.5rem 1.25rem;
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
border: 1px solid var(--border-glow);
|
||||
border-radius: 50px;
|
||||
font-size: 0.875rem;
|
||||
color: var(--accent-cyan);
|
||||
margin-bottom: 2rem;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.hero h1 {
|
||||
font-size: clamp(3rem, 5vw, 4.5rem);
|
||||
font-weight: 800;
|
||||
margin-bottom: 1.5rem;
|
||||
background: var(--gradient-1);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
line-height: 1.1;
|
||||
}
|
||||
|
||||
.hero-subtitle {
|
||||
font-size: 1.25rem;
|
||||
color: var(--text-secondary);
|
||||
max-width: 700px;
|
||||
margin: 0 auto 2.5rem;
|
||||
}
|
||||
|
||||
.hero-buttons {
|
||||
display: flex;
|
||||
gap: 1rem;
|
||||
justify-content: center;
|
||||
flex-wrap: wrap;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
BUTTONS
|
||||
============================================================ */
|
||||
.btn {
|
||||
padding: 0.875rem 2rem;
|
||||
border-radius: 12px;
|
||||
font-weight: 600;
|
||||
text-decoration: none;
|
||||
transition: all var(--tr);
|
||||
cursor: pointer;
|
||||
border: none;
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 0.5rem;
|
||||
}
|
||||
|
||||
.btn-primary {
|
||||
background: var(--gradient-1);
|
||||
color: var(--bg-primary);
|
||||
}
|
||||
|
||||
.btn-primary:hover {
|
||||
transform: translateY(-2px);
|
||||
box-shadow: 0 8px 30px rgba(0, 229, 255, 0.4);
|
||||
}
|
||||
|
||||
.btn-secondary {
|
||||
background: rgba(255, 255, 255, 0.05);
|
||||
border: 1px solid var(--border);
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
.btn-secondary:hover {
|
||||
border-color: var(--accent-cyan);
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
}
|
||||
|
||||
.btn-ghost {
|
||||
color: var(--text-secondary);
|
||||
border: 1px solid transparent;
|
||||
}
|
||||
.btn-ghost:hover {
|
||||
color: var(--text-primary);
|
||||
border-color: var(--border);
|
||||
background: rgba(255,255,255,0.05);
|
||||
}
|
||||
.btn-sm {
|
||||
padding: 0.5rem 1rem;
|
||||
font-size: 0.85rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
STATS ROW
|
||||
============================================================ */
|
||||
.stats-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(auto-fit, minmax(200px, 1fr));
|
||||
gap: 2rem;
|
||||
text-align: center;
|
||||
margin-bottom: 6rem;
|
||||
}
|
||||
|
||||
.stat-card {
|
||||
background: var(--bg-card);
|
||||
border-radius: 20px;
|
||||
padding: 2.5rem 2rem;
|
||||
border: 1px solid var(--border);
|
||||
backdrop-filter: blur(10px);
|
||||
-webkit-backdrop-filter: blur(10px);
|
||||
}
|
||||
|
||||
.stat-number {
|
||||
font-size: 3.5rem;
|
||||
font-weight: 800;
|
||||
background: var(--gradient-1);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
line-height: 1;
|
||||
}
|
||||
|
||||
.stat-label {
|
||||
color: var(--text-secondary);
|
||||
margin-top: 1rem;
|
||||
font-weight: 500;
|
||||
font-size: 1.1rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
SECTION HEADER
|
||||
============================================================ */
|
||||
.section-header {
|
||||
text-align: center;
|
||||
margin-bottom: 4rem;
|
||||
}
|
||||
|
||||
.section-label {
|
||||
display: inline-block;
|
||||
font-size: 0.875rem;
|
||||
font-weight: 600;
|
||||
color: var(--accent-cyan);
|
||||
margin-bottom: 1rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: 0.05em;
|
||||
}
|
||||
|
||||
.section-header h2 {
|
||||
font-size: 2.5rem;
|
||||
font-weight: 800;
|
||||
margin-bottom: 1rem;
|
||||
background: var(--gradient-2);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
}
|
||||
|
||||
.section-header p {
|
||||
color: var(--text-secondary);
|
||||
max-width: 600px;
|
||||
margin: 0 auto;
|
||||
font-size: 1.1rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
FEATURES GRID / CARDS
|
||||
============================================================ */
|
||||
.cards-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(auto-fit, minmax(320px, 1fr));
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.card {
|
||||
background: var(--bg-card);
|
||||
backdrop-filter: blur(10px);
|
||||
-webkit-backdrop-filter: blur(10px);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 20px;
|
||||
padding: 2.5rem;
|
||||
transition: all 0.4s var(--ease);
|
||||
}
|
||||
|
||||
.card:hover {
|
||||
transform: translateY(-10px);
|
||||
border-color: var(--accent-cyan);
|
||||
box-shadow: var(--shadow-glow);
|
||||
}
|
||||
|
||||
.card-icon {
|
||||
width: 64px;
|
||||
height: 64px;
|
||||
background: rgba(0, 229, 255, 0.1);
|
||||
border-radius: 16px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
margin-bottom: 1.5rem;
|
||||
border: 1px solid rgba(0, 229, 255, 0.2);
|
||||
}
|
||||
|
||||
.card-icon i {
|
||||
font-size: 1.75rem;
|
||||
color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.card h3 {
|
||||
font-size: 1.5rem;
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
.card p {
|
||||
color: var(--text-secondary);
|
||||
margin-bottom: 1.5rem;
|
||||
line-height: 1.7;
|
||||
}
|
||||
|
||||
.card-tags {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
gap: 0.5rem;
|
||||
}
|
||||
|
||||
.tag {
|
||||
padding: 0.35rem 0.85rem;
|
||||
background: rgba(255, 255, 255, 0.05);
|
||||
border-radius: 20px;
|
||||
font-size: 0.75rem;
|
||||
color: var(--text-primary);
|
||||
font-weight: 500;
|
||||
border: 1px solid var(--border);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
STEPS / HOW IT WORKS
|
||||
============================================================ */
|
||||
.steps {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 1.5rem;
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
.step {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
background: var(--bg-card);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--r-md);
|
||||
padding: 2rem;
|
||||
backdrop-filter: blur(10px);
|
||||
-webkit-backdrop-filter: blur(10px);
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
.step:hover {
|
||||
border-color: var(--accent-cyan);
|
||||
box-shadow: var(--shadow-glow);
|
||||
}
|
||||
|
||||
.step-number {
|
||||
flex-shrink: 0;
|
||||
width: 50px;
|
||||
height: 50px;
|
||||
border-radius: 50%;
|
||||
background: var(--gradient-1);
|
||||
color: var(--bg-primary);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
font-size: 1.25rem;
|
||||
font-weight: 800;
|
||||
}
|
||||
|
||||
.step-content h3 {
|
||||
font-size: 1.25rem;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.step-content p {
|
||||
color: var(--text-secondary);
|
||||
font-size: 0.95rem;
|
||||
line-height: 1.65;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
COMPARISON TABLE
|
||||
============================================================ */
|
||||
.comparison-table-wrap {
|
||||
overflow-x: auto;
|
||||
background: var(--bg-card);
|
||||
border-radius: 20px;
|
||||
border: 1px solid var(--border);
|
||||
padding: 1rem;
|
||||
backdrop-filter: blur(10px);
|
||||
-webkit-backdrop-filter: blur(10px);
|
||||
}
|
||||
|
||||
.comparison-table-wrap table {
|
||||
width: 100%;
|
||||
border-collapse: collapse;
|
||||
min-width: 700px;
|
||||
}
|
||||
|
||||
.comparison-table-wrap th, .comparison-table-wrap td {
|
||||
padding: 1.25rem 1rem;
|
||||
text-align: left;
|
||||
border-bottom: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.comparison-table-wrap th {
|
||||
color: var(--text-primary);
|
||||
font-weight: 600;
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
}
|
||||
|
||||
.comparison-table-wrap tr:last-child td {
|
||||
border-bottom: none;
|
||||
}
|
||||
|
||||
.check {
|
||||
color: var(--accent-green);
|
||||
font-weight: 600;
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 0.4rem;
|
||||
}
|
||||
|
||||
td.check {
|
||||
display: table-cell;
|
||||
}
|
||||
|
||||
td.check i {
|
||||
margin-right: 0.4rem;
|
||||
}
|
||||
|
||||
.times {
|
||||
color: var(--accent-red);
|
||||
opacity: 0.7;
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 0.4rem;
|
||||
}
|
||||
|
||||
td.times {
|
||||
display: table-cell;
|
||||
}
|
||||
|
||||
td.times i {
|
||||
margin-right: 0.4rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
CODE BLOCKS
|
||||
============================================================ */
|
||||
.code-block {
|
||||
background: #080b1a;
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 12px;
|
||||
padding: 1.5rem;
|
||||
overflow-x: auto;
|
||||
font-size: 0.9rem;
|
||||
margin: 1.5rem 0;
|
||||
box-shadow: inset 0 0 10px rgba(0,0,0,0.5);
|
||||
position: relative;
|
||||
}
|
||||
|
||||
.code-block-center {
|
||||
max-width: 700px;
|
||||
margin-left: auto;
|
||||
margin-right: auto;
|
||||
}
|
||||
|
||||
.code-block pre {
|
||||
color: #a0a8c3;
|
||||
line-height: 1.5;
|
||||
font-family: var(--font-mono);
|
||||
}
|
||||
|
||||
.code-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 1rem;
|
||||
border-bottom: 1px solid rgba(255,255,255,0.05);
|
||||
padding-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.code-lang {
|
||||
font-size: 0.75rem;
|
||||
color: var(--accent-cyan);
|
||||
font-weight: 600;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: 0.05em;
|
||||
}
|
||||
|
||||
.code-copy-btn {
|
||||
font-size: 0.75rem;
|
||||
color: var(--text-secondary);
|
||||
border: 1px solid var(--border);
|
||||
padding: 3px 8px;
|
||||
border-radius: 4px;
|
||||
background: rgba(255,255,255,0.03);
|
||||
transition: all var(--tr);
|
||||
}
|
||||
.code-copy-btn:hover {
|
||||
color: var(--text-primary);
|
||||
border-color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
FOOTER
|
||||
============================================================ */
|
||||
.footer {
|
||||
background: var(--bg-secondary);
|
||||
border-top: 1px solid var(--border);
|
||||
padding: 5rem 2rem 2rem;
|
||||
margin-top: 6rem;
|
||||
}
|
||||
|
||||
.footer-content {
|
||||
max-width: var(--max-width);
|
||||
margin: 0 auto;
|
||||
display: grid;
|
||||
grid-template-columns: repeat(auto-fit, minmax(200px, 1fr));
|
||||
gap: 4rem;
|
||||
}
|
||||
|
||||
.footer-section h4 {
|
||||
margin-bottom: 1.5rem;
|
||||
color: var(--text-primary);
|
||||
font-size: 1.1rem;
|
||||
}
|
||||
|
||||
.footer-section p {
|
||||
color: var(--text-secondary);
|
||||
font-size: 0.95rem;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.footer-section a {
|
||||
display: inline-block;
|
||||
color: var(--text-secondary);
|
||||
text-decoration: none;
|
||||
margin-bottom: 0.75rem;
|
||||
transition: all var(--tr);
|
||||
font-size: 0.95rem;
|
||||
}
|
||||
|
||||
.footer-section a:hover {
|
||||
color: var(--accent-cyan);
|
||||
transform: translateX(5px);
|
||||
}
|
||||
|
||||
.footer-bottom {
|
||||
text-align: center;
|
||||
padding-top: 3rem;
|
||||
margin-top: 3rem;
|
||||
border-top: 1px solid var(--border);
|
||||
color: var(--text-muted);
|
||||
font-size: 0.9rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
SEARCH OVERLAY
|
||||
============================================================ */
|
||||
.search-overlay {
|
||||
position: fixed;
|
||||
inset: 0;
|
||||
z-index: 2000;
|
||||
background: rgba(10, 14, 39, 0.85);
|
||||
backdrop-filter: blur(12px);
|
||||
-webkit-backdrop-filter: blur(12px);
|
||||
display: flex;
|
||||
align-items: flex-start;
|
||||
justify-content: center;
|
||||
padding-top: 15vh;
|
||||
opacity: 0;
|
||||
pointer-events: none;
|
||||
transition: opacity var(--tr);
|
||||
}
|
||||
|
||||
.search-overlay.open {
|
||||
opacity: 1;
|
||||
pointer-events: auto;
|
||||
}
|
||||
|
||||
.search-box {
|
||||
width: 100%;
|
||||
max-width: 580px;
|
||||
background: var(--bg-secondary);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--r-lg);
|
||||
overflow: hidden;
|
||||
transform: translateY(16px);
|
||||
transition: transform var(--tr);
|
||||
box-shadow: 0 24px 64px rgba(0,0,0,.5);
|
||||
}
|
||||
|
||||
.search-overlay.open .search-box {
|
||||
transform: translateY(0);
|
||||
}
|
||||
|
||||
.search-input-wrap {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
padding: 16px 20px;
|
||||
gap: 12px;
|
||||
border-bottom: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.search-input-wrap svg {
|
||||
width: 20px;
|
||||
height: 20px;
|
||||
color: var(--text-muted);
|
||||
flex-shrink: 0;
|
||||
}
|
||||
|
||||
.search-input {
|
||||
flex: 1;
|
||||
background: none;
|
||||
border: none;
|
||||
outline: none;
|
||||
font-size: 1rem;
|
||||
color: var(--text-primary);
|
||||
font-family: var(--font-sans);
|
||||
}
|
||||
|
||||
.search-input::placeholder {
|
||||
color: var(--text-muted);
|
||||
}
|
||||
|
||||
.search-kbd {
|
||||
font-size: .7rem;
|
||||
font-weight: 600;
|
||||
color: var(--text-muted);
|
||||
padding: 2px 8px;
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 4px;
|
||||
background: var(--bg-card-solid);
|
||||
}
|
||||
|
||||
.search-results {
|
||||
max-height: 360px;
|
||||
overflow-y: auto;
|
||||
padding: 8px;
|
||||
}
|
||||
|
||||
.search-result {
|
||||
display: block;
|
||||
padding: 10px 16px;
|
||||
border-radius: var(--r-sm);
|
||||
transition: background var(--tr);
|
||||
}
|
||||
|
||||
.search-result:hover, .search-result.selected {
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
}
|
||||
|
||||
.search-result-title {
|
||||
font-size: .9rem;
|
||||
font-weight: 600;
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
.search-result-desc {
|
||||
font-size: .8rem;
|
||||
color: var(--text-secondary);
|
||||
margin-top: 2px;
|
||||
}
|
||||
|
||||
.search-empty {
|
||||
padding: 24px;
|
||||
text-align: center;
|
||||
color: var(--text-secondary);
|
||||
font-size: .9rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
BACK TO TOP
|
||||
============================================================ */
|
||||
.back-to-top {
|
||||
position: fixed;
|
||||
bottom: 24px;
|
||||
right: 24px;
|
||||
width: 44px;
|
||||
height: 44px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
background: var(--bg-card-solid);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 50%;
|
||||
color: var(--text-secondary);
|
||||
font-size: 1.1rem;
|
||||
z-index: 100;
|
||||
opacity: 0;
|
||||
pointer-events: none;
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
.back-to-top.visible {
|
||||
opacity: 1;
|
||||
pointer-events: auto;
|
||||
}
|
||||
|
||||
.back-to-top:hover {
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
color: var(--accent-cyan);
|
||||
border-color: var(--accent-cyan);
|
||||
transform: translateY(-2px);
|
||||
box-shadow: var(--shadow-glow);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
ANIMATION INTERSECT
|
||||
============================================================ */
|
||||
.animate {
|
||||
opacity: 0;
|
||||
transform: translateY(30px);
|
||||
transition: opacity 0.6s ease-out, transform 0.6s ease-out;
|
||||
}
|
||||
.animate.in-view {
|
||||
opacity: 1;
|
||||
transform: translateY(0);
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
RESPONSIVE
|
||||
============================================================ */
|
||||
@media (max-width: 900px) {
|
||||
.nav-links {
|
||||
position: absolute;
|
||||
top: 100%;
|
||||
left: 0;
|
||||
right: 0;
|
||||
background: rgba(10, 14, 39, 0.98);
|
||||
backdrop-filter: blur(15px);
|
||||
flex-direction: column;
|
||||
padding: 2rem 1rem;
|
||||
border-bottom: 1px solid var(--border);
|
||||
gap: 1.5rem;
|
||||
opacity: 0;
|
||||
visibility: hidden;
|
||||
transform: translateY(-10px);
|
||||
transition: all 0.3s cubic-bezier(0.4, 0, 0.2, 1);
|
||||
box-shadow: 0 20px 40px rgba(0,0,0,0.5);
|
||||
}
|
||||
|
||||
.nav-links.active {
|
||||
opacity: 1;
|
||||
visibility: visible;
|
||||
transform: translateY(0);
|
||||
}
|
||||
|
||||
.nav-toggle {
|
||||
display: block;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,440 @@
|
||||
/* ============================================================
|
||||
Documentation Pages — docs.css
|
||||
Layout, sidebar, content rendering for documentation pages
|
||||
============================================================ */
|
||||
|
||||
/* ---- Doc page shell ---- */
|
||||
.doc-page {
|
||||
padding-top: var(--header-h);
|
||||
}
|
||||
|
||||
.doc-layout {
|
||||
display: grid;
|
||||
grid-template-columns: 280px 1fr;
|
||||
gap: 0;
|
||||
min-height: calc(100vh - var(--header-h));
|
||||
max-width: var(--max-width);
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* ---- Sidebar ---- */
|
||||
.doc-sidebar {
|
||||
position: sticky;
|
||||
top: var(--header-h);
|
||||
height: calc(100vh - var(--header-h));
|
||||
overflow-y: auto;
|
||||
padding: 2.5rem 1.5rem;
|
||||
background: rgba(17, 22, 46, 0.5);
|
||||
backdrop-filter: blur(10px);
|
||||
-webkit-backdrop-filter: blur(10px);
|
||||
border-right: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.doc-sidebar-toggle {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.doc-nav-group {
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
.doc-nav-label {
|
||||
font-size: .75rem;
|
||||
font-weight: 700;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: .08em;
|
||||
color: var(--text-muted);
|
||||
margin-bottom: 0.75rem;
|
||||
padding-left: 0.75rem;
|
||||
}
|
||||
|
||||
.doc-nav-item {
|
||||
display: block;
|
||||
padding: 8px 14px;
|
||||
font-size: .9rem;
|
||||
color: var(--text-secondary);
|
||||
border-radius: var(--r-sm);
|
||||
transition: all var(--tr);
|
||||
border-left: 2px solid transparent;
|
||||
margin-bottom: 2px;
|
||||
}
|
||||
|
||||
.doc-nav-item:hover {
|
||||
color: var(--text-primary);
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
}
|
||||
|
||||
.doc-nav-item.active {
|
||||
color: var(--accent-cyan);
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
border-left-color: var(--accent-cyan);
|
||||
text-shadow: 0 0 10px rgba(0, 229, 255, 0.3);
|
||||
}
|
||||
|
||||
/* ---- Content area ---- */
|
||||
.doc-main {
|
||||
padding: 3rem 4rem 6rem;
|
||||
max-width: 960px;
|
||||
}
|
||||
|
||||
/* ---- Breadcrumb ---- */
|
||||
.doc-breadcrumb {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 6px;
|
||||
font-size: .8rem;
|
||||
color: var(--text-muted);
|
||||
margin-bottom: 1.5rem;
|
||||
}
|
||||
|
||||
.doc-breadcrumb a {
|
||||
color: var(--text-muted);
|
||||
}
|
||||
|
||||
.doc-breadcrumb a:hover {
|
||||
color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.doc-breadcrumb .sep {
|
||||
color: var(--text-muted);
|
||||
}
|
||||
|
||||
/* ---- Markdown content rendering ---- */
|
||||
.doc-content h1 {
|
||||
font-size: 2.5rem;
|
||||
font-weight: 800;
|
||||
letter-spacing: -.03em;
|
||||
margin-bottom: 0.5rem;
|
||||
line-height: 1.15;
|
||||
background: var(--gradient-1);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
}
|
||||
|
||||
.doc-content .doc-subtitle {
|
||||
font-size: 1.15rem;
|
||||
color: var(--text-secondary);
|
||||
margin-bottom: 2rem;
|
||||
line-height: 1.65;
|
||||
}
|
||||
|
||||
.doc-content h2 {
|
||||
font-size: 1.75rem;
|
||||
font-weight: 800;
|
||||
letter-spacing: -.02em;
|
||||
margin-top: 3.5rem;
|
||||
margin-bottom: 1.25rem;
|
||||
padding-bottom: 0.5rem;
|
||||
border-bottom: 1px solid var(--border);
|
||||
scroll-margin-top: calc(var(--header-h) + 24px);
|
||||
background: var(--gradient-2);
|
||||
-webkit-background-clip: text;
|
||||
background-clip: text;
|
||||
color: transparent;
|
||||
}
|
||||
|
||||
.doc-content h3 {
|
||||
font-size: 1.35rem;
|
||||
font-weight: 700;
|
||||
margin-top: 2.5rem;
|
||||
margin-bottom: 1rem;
|
||||
scroll-margin-top: calc(var(--header-h) + 24px);
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
.doc-content h4 {
|
||||
font-size: 1.1rem;
|
||||
font-weight: 700;
|
||||
margin-top: 2rem;
|
||||
margin-bottom: 0.75rem;
|
||||
color: var(--text-secondary);
|
||||
scroll-margin-top: calc(var(--header-h) + 24px);
|
||||
}
|
||||
|
||||
.doc-content p {
|
||||
margin-bottom: 1.25rem;
|
||||
color: var(--text-secondary);
|
||||
line-height: 1.8;
|
||||
}
|
||||
|
||||
.doc-content ul, .doc-content ol {
|
||||
margin-bottom: 1.25rem;
|
||||
padding-left: 1.5rem;
|
||||
}
|
||||
|
||||
.doc-content ul {
|
||||
list-style: disc;
|
||||
}
|
||||
|
||||
.doc-content ol {
|
||||
list-style: decimal;
|
||||
}
|
||||
|
||||
.doc-content li {
|
||||
margin-bottom: 0.5rem;
|
||||
color: var(--text-secondary);
|
||||
line-height: 1.7;
|
||||
}
|
||||
|
||||
.doc-content li strong {
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
.doc-content code {
|
||||
padding: 2px 6px;
|
||||
font-size: .88em;
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
border: 1px solid rgba(0, 229, 255, 0.15);
|
||||
border-radius: 4px;
|
||||
color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.doc-content pre {
|
||||
background: #080b1a;
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 12px;
|
||||
padding: 1.5rem;
|
||||
margin: 1.5rem 0 2rem;
|
||||
overflow-x: auto;
|
||||
font-size: .88rem;
|
||||
line-height: 1.6;
|
||||
box-shadow: inset 0 0 10px rgba(0,0,0,0.5);
|
||||
}
|
||||
|
||||
.doc-content pre code {
|
||||
background: none;
|
||||
border: none;
|
||||
padding: 0;
|
||||
color: #a0a8c3;
|
||||
font-size: inherit;
|
||||
}
|
||||
|
||||
.doc-content strong {
|
||||
color: var(--text-primary);
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.doc-content em {
|
||||
color: var(--text-secondary);
|
||||
font-style: italic;
|
||||
}
|
||||
|
||||
.doc-content a {
|
||||
color: var(--accent-cyan);
|
||||
border-bottom: 1px solid transparent;
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
.doc-content a:hover {
|
||||
color: var(--text-primary);
|
||||
border-bottom-color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.doc-content blockquote {
|
||||
margin: 1.5rem 0;
|
||||
padding: 1.25rem 1.5rem;
|
||||
border-left: 4px solid var(--accent-purple);
|
||||
background: var(--bg-card);
|
||||
border-radius: 0 var(--r-md) var(--r-md) 0;
|
||||
color: var(--text-secondary);
|
||||
}
|
||||
|
||||
.doc-content blockquote p {
|
||||
margin-bottom: 0;
|
||||
}
|
||||
|
||||
.doc-content table {
|
||||
width: 100%;
|
||||
margin: 1.5rem 0 2rem;
|
||||
border-collapse: collapse;
|
||||
font-size: .88rem;
|
||||
}
|
||||
|
||||
.doc-content table th {
|
||||
padding: 12px 16px;
|
||||
text-align: left;
|
||||
font-weight: 700;
|
||||
font-size: .78rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: .06em;
|
||||
color: var(--text-primary);
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
border: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.doc-content table td {
|
||||
padding: 12px 16px;
|
||||
border: 1px solid var(--border);
|
||||
color: var(--text-secondary);
|
||||
}
|
||||
|
||||
.doc-content table tr:hover td {
|
||||
background: rgba(255,255,255,0.02);
|
||||
}
|
||||
|
||||
.doc-content hr {
|
||||
border: none;
|
||||
height: 1px;
|
||||
background: var(--border);
|
||||
margin: 3rem 0;
|
||||
}
|
||||
|
||||
/* ---- Alert boxes ---- */
|
||||
.doc-alert {
|
||||
display: flex;
|
||||
gap: 12px;
|
||||
padding: 1rem 1.25rem;
|
||||
margin: 1.5rem 0 2rem;
|
||||
border-radius: var(--r-md);
|
||||
border: 1px solid;
|
||||
}
|
||||
|
||||
.doc-alert-icon {
|
||||
flex-shrink: 0;
|
||||
width: 20px;
|
||||
height: 20px;
|
||||
margin-top: 2px;
|
||||
}
|
||||
|
||||
.doc-alert-body {
|
||||
font-size: .9rem;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.doc-alert-body p {
|
||||
margin-bottom: 4px;
|
||||
color: inherit;
|
||||
}
|
||||
|
||||
.doc-alert-body p:last-child {
|
||||
margin-bottom: 0;
|
||||
}
|
||||
|
||||
.doc-alert--note {
|
||||
background: rgba(0, 229, 255, 0.05);
|
||||
border-color: rgba(0, 229, 255, 0.2);
|
||||
color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.doc-alert--tip {
|
||||
background: rgba(0, 255, 136, 0.05);
|
||||
border-color: rgba(0, 255, 136, 0.2);
|
||||
color: var(--accent-green);
|
||||
}
|
||||
|
||||
.doc-alert--warn {
|
||||
background: rgba(251, 191, 36, 0.05);
|
||||
border-color: rgba(251, 191, 36, 0.2);
|
||||
color: #fbbf24;
|
||||
}
|
||||
|
||||
.doc-alert--danger {
|
||||
background: rgba(255, 71, 87, 0.05);
|
||||
border-color: rgba(255, 71, 87, 0.2);
|
||||
color: var(--accent-red);
|
||||
}
|
||||
|
||||
/* ---- Prev / Next navigation ---- */
|
||||
.doc-pager {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 1.5rem;
|
||||
margin-top: 4rem;
|
||||
padding-top: 2rem;
|
||||
border-top: 1px solid var(--border);
|
||||
}
|
||||
|
||||
.doc-pager-link {
|
||||
padding: 1.5rem;
|
||||
background: var(--bg-card);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--r-md);
|
||||
transition: all var(--tr);
|
||||
}
|
||||
|
||||
.doc-pager-link:hover {
|
||||
border-color: var(--accent-cyan);
|
||||
background: rgba(0, 229, 255, 0.03);
|
||||
box-shadow: var(--shadow-glow);
|
||||
}
|
||||
|
||||
.doc-pager-label {
|
||||
font-size: .75rem;
|
||||
font-weight: 700;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: .08em;
|
||||
color: var(--text-muted);
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.doc-pager-title {
|
||||
font-size: 1rem;
|
||||
font-weight: 600;
|
||||
color: var(--text-primary);
|
||||
}
|
||||
|
||||
.doc-pager-link--next {
|
||||
text-align: right;
|
||||
}
|
||||
|
||||
/* ---- Last updated ---- */
|
||||
.doc-meta {
|
||||
font-size: .8rem;
|
||||
color: var(--text-muted);
|
||||
margin-top: 2.5rem;
|
||||
}
|
||||
|
||||
/* ============================================================
|
||||
RESPONSIVE
|
||||
============================================================ */
|
||||
@media(max-width:900px) {
|
||||
.doc-layout {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
|
||||
.doc-sidebar {
|
||||
position: fixed;
|
||||
top: var(--header-h);
|
||||
left: 0;
|
||||
bottom: 0;
|
||||
width: 280px;
|
||||
z-index: 998;
|
||||
transform: translateX(-100%);
|
||||
transition: transform var(--tr);
|
||||
border-right: 1px solid var(--border);
|
||||
background: var(--bg-secondary);
|
||||
}
|
||||
|
||||
.doc-sidebar.open {
|
||||
transform: translateX(0);
|
||||
}
|
||||
|
||||
.doc-sidebar-toggle {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
padding: 10px 16px;
|
||||
font-size: .85rem;
|
||||
font-weight: 600;
|
||||
color: var(--text-secondary);
|
||||
background: var(--bg-card);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: var(--r-sm);
|
||||
margin-bottom: 16px;
|
||||
width: fit-content;
|
||||
}
|
||||
|
||||
.doc-sidebar-toggle:hover {
|
||||
color: var(--text-primary);
|
||||
border-color: var(--accent-cyan);
|
||||
}
|
||||
|
||||
.doc-main {
|
||||
padding: 2rem 1.5rem 4rem;
|
||||
}
|
||||
|
||||
.doc-pager {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
/* ============================================================
|
||||
Print Stylesheet — print.css
|
||||
Clean print layout for documentation pages
|
||||
============================================================ */
|
||||
|
||||
@media print {
|
||||
*{color:#111!important;background:white!important;box-shadow:none!important;text-shadow:none!important}
|
||||
|
||||
body{font-size:11pt;line-height:1.6}
|
||||
|
||||
.site-header,.site-footer,.nav-toggle,.back-to-top,
|
||||
.search-overlay,.doc-sidebar,.doc-toc,.doc-pager,
|
||||
.doc-sidebar-toggle,.doc-breadcrumb,
|
||||
.hero-bg,.hero-grid,.hero-badge,.hero-actions,
|
||||
.hero-terminal,.cta-section,
|
||||
.btn,.nav-cta{display:none!important}
|
||||
|
||||
.doc-layout,.doc-layout--toc{display:block!important}
|
||||
.doc-main{padding:0!important;max-width:100%!important}
|
||||
.doc-page{padding-top:0!important}
|
||||
|
||||
a{text-decoration:underline}
|
||||
a[href^="http"]::after{content:" (" attr(href) ")";font-size:9pt;color:#666}
|
||||
a[href^="#"]::after{content:""}
|
||||
|
||||
pre,code{font-size:9pt;border:1px solid #ddd;padding:8px;page-break-inside:avoid}
|
||||
table{border-collapse:collapse;width:100%}
|
||||
th,td{border:1px solid #ccc;padding:6px 10px;font-size:9pt}
|
||||
th{background:#eee!important;font-weight:700}
|
||||
|
||||
h1{font-size:20pt;border-bottom:2px solid #111;padding-bottom:6pt;margin-bottom:12pt}
|
||||
h2{font-size:16pt;border-bottom:1px solid #999;padding-bottom:4pt;margin-top:24pt;page-break-after:avoid}
|
||||
h3{font-size:13pt;margin-top:18pt;page-break-after:avoid}
|
||||
|
||||
img{max-width:100%!important}
|
||||
.section{padding:24pt 0!important}
|
||||
|
||||
@page{margin:1.5cm 2cm}
|
||||
}
|
||||
@@ -0,0 +1,334 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Deployment Guide | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal Deployment Guide, detailing compiler requirements, native installation script, environment variables, Nginx configurations, and Docker integration.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html" class="active">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item active">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Lifecycle & Dev</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Deployment Guide</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Deployment Guide</h1>
|
||||
<p class="doc-subtitle">ChronoSeal runs as a native Unix daemon behind TLS, serving WebAssembly assets. This guide covers building, configuring, and service installation options.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>System Requirements</h2>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Requirement</th>
|
||||
<th>Min Version</th>
|
||||
<th>Core Purpose</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>Rust (cargo)</td>
|
||||
<td>1.87 stable</td>
|
||||
<td>Compile server binary and shared libraries</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>wasm-pack</td>
|
||||
<td>0.13</td>
|
||||
<td>Generate the browser WebAssembly module package</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>wasm32 target</td>
|
||||
<td>stable</td>
|
||||
<td>Required target for cargo wasm32 compilation</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>systemd</td>
|
||||
<td>248+</td>
|
||||
<td>Service management and sandbox isolation</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Docker</td>
|
||||
<td>24.x</td>
|
||||
<td>Containerization support</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<h2>Building from Source</h2>
|
||||
<p>Install the Rust WASM build targets and tools:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>rustup target add wasm32-unknown-unknown
|
||||
cargo install wasm-pack</code></pre>
|
||||
</div>
|
||||
|
||||
<p>Build the browser WASM package and compile the server daemon:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code># Build WASM package and copy to frontend assets
|
||||
wasm-pack build wasm --target web --release
|
||||
rm -rf frontend/pkg
|
||||
mv wasm/pkg frontend/pkg
|
||||
|
||||
# Build release server daemon
|
||||
cargo build -p chronoseal-server --bin chronoseal --release</code></pre>
|
||||
</div>
|
||||
<p>The compiled binary is written to <code>target/release/chronoseal</code>.</p>
|
||||
|
||||
<h2>Native Service Installation</h2>
|
||||
<p>The easiest way to deploy ChronoSeal on Linux is using our installer script. This creates a dedicated system user, configures directory paths, copies assets, and sets up systemd sandboxing:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>sudo bash scripts/install.sh</code></pre>
|
||||
</div>
|
||||
<p>Verify installation operational status:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>sudo systemctl status chronoseal
|
||||
chronoseal health
|
||||
sudo journalctl -u chronoseal -f</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Configuration Precedence</h2>
|
||||
<p>ChronoSeal resolves configuration variables in this order:
|
||||
<code>CLI parameters</code> > <code>CHRONOSEAL_* Environment Variables</code> > <code>TOML file</code> > <code>Defaults</code>.
|
||||
</p>
|
||||
<p>The TOML configuration is searched at:
|
||||
<code>$CHRONOSEAL_CONFIG</code>, <code>/etc/chronoseal/config.toml</code>, <code>~/.config/chronoseal/config.toml</code>.
|
||||
</p>
|
||||
|
||||
<h3>Common Environment overrides</h3>
|
||||
<ul>
|
||||
<li><code>CHRONOSEAL_BIND</code>: Binding address (e.g. <code>127.0.0.1:3000</code>).</li>
|
||||
<li><code>CHRONOSEAL_DB_TYPE</code>: <code>sqlite-in-memory</code>, <code>sqlite-in-disk</code>, or <code>valkey</code>.</li>
|
||||
<li><code>CHRONOSEAL_VALKEY_ADDR</code>: Address of Valkey server (defaults to <code>127.0.0.1:6666</code>).</li>
|
||||
<li><code>CHRONOSEAL_FRONTEND_DIR</code>: Directory containing frontend static assets.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Reverse Proxy Configuration (Nginx)</h2>
|
||||
<p>Ensure ChronoSeal runs behind TLS in production. Secure proxy traffic to the local daemon port:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Nginx</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>location / {
|
||||
proxy_pass http://127.0.0.1:3000;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Docker Compose Deployment</h2>
|
||||
<p>Build and run the container service (configured for non-root execution by default):</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>bash scripts/build.sh
|
||||
docker compose up -d --build</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Production Checklist</h2>
|
||||
<ul>
|
||||
<li>Ensure WASM modules in <code>frontend/pkg</code> are rebuilt with the <code>--release</code> flag.</li>
|
||||
<li>Serve all ChronoSeal endpoints exclusively over HTTPS.</li>
|
||||
<li>Restict server bind address to localhost (<code>127.0.0.1</code>) behind a reverse proxy.</li>
|
||||
<li>Run the daemon service under a dedicated unprivileged user account.</li>
|
||||
<li>Disable debug logging (avoid <code>CHRONOSEAL_LOG=debug</code>) in production to protect credentials.</li>
|
||||
<li>Configure Valkey or persistent SQLite for production session storage.</li>
|
||||
</ul>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="operations.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Operations Handbook</div>
|
||||
</a>
|
||||
<a href="testing.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Testing Strategy</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
|
After Width: | Height: | Size: 1.5 KiB |
|
After Width: | Height: | Size: 594 B |
|
After Width: | Height: | Size: 15 KiB |
@@ -0,0 +1 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" version="1.1" id="Layer_1" x="0px" y="0px" width="296.99997mm" viewBox="0 0 1122.5196 793.7008" enable-background="new 0 0 1254 1254" xml:space="preserve" height="210mm" sodipodi:docname="logo1.svg" inkscape:export-filename="logo1.png" inkscape:export-xdpi="96" inkscape:export-ydpi="96" inkscape:version="1.4.4 (dcaf3e7d9e, 2026-05-05)" xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" xmlns:svg="http://www.w3.org/2000/svg"><metadata><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/"><rdf:Description><dc:creator>RealFaviconGenerator</dc:creator><dc:source>https://realfavicongenerator.net</dc:source></rdf:Description></rdf:RDF></metadata><sodipodi:namedview id="namedview1" pagecolor="#ffffff" bordercolor="#000000" borderopacity="0.25" inkscape:showpageshadow="2" inkscape:pageopacity="0.0" inkscape:pagecheckerboard="0" inkscape:deskcolor="#d1d1d1" inkscape:document-units="mm" inkscape:zoom="1.1654266" inkscape:cx="561.16791" inkscape:cy="396.85039" inkscape:window-width="2048" inkscape:window-height="1205" inkscape:window-x="0" inkscape:window-y="0" inkscape:window-maximized="1" inkscape:current-layer="Layer_1"></sodipodi:namedview><defs id="defs44"></defs><path fill="none" opacity="1" stroke="none" d="m 791.89377,632.01366 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77527,34.39209 -143.33667,69.23047 -215.00567,103.84463 -8.40815,4.06091 -14.32166,9.84101 -14.39978,19.74008 -0.079,10.00498 5.52282,16.22797 14.08978,20.54743 12.3277,6.21567 24.51239,12.71484 37.34228,19.41369 7.51429,3.93381 14.42273,7.5896 21.37854,11.15274 31.68775,16.23208 63.40558,32.40548 95.07782,48.66778 14.943,7.6726 29.74964,15.6123 44.73053,23.2091 8.44464,4.2823 16.79547,9.1534 25.75525,11.9324 18.81989,5.8372 37.10712,3.9335 54.83185,-5.5578 25.51599,-13.6634 51.41541,-26.6141 77.2135,-39.7465 30.82071,-15.6894 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z" id="path2"></path><path fill="#4b4d51" opacity="1" stroke="none" d="m 791.89376,550.60089 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 -61.76651,-29.85993 -123.47361,-59.84277 -185.21183,-89.76129 -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77522,34.39209 -143.33662,69.23047 -215.00562,103.84463 -8.4082,4.06091 -14.3217,9.84101 -14.3998,19.74008 -0.079,10.00498 5.5228,16.22797 14.0898,20.54743 12.3277,6.21567 24.5123,12.71484 37.3422,19.41369 7.5143,3.93381 14.4228,7.5896 21.3786,11.15274 31.6877,16.23212 63.4056,32.40552 95.0778,48.66782 14.943,7.67261 29.7496,15.61227 44.73052,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z" id="path45" style="fill:#e1e1e4;fill-opacity:1"></path><path fill="#4b4d51" opacity="1" stroke="none" d="m 791.89377,469.18814 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20.46771 -0.14127,-9.82202 -6.25309,-15.51495 -14.66742,-19.5827 C 767.4184,378.3558 705.7113,348.37296 643.97308,318.45444 c -10.48242,-5.07981 -20.81335,-10.5555 -31.58477,-14.93764 -19.71186,-8.01936 -39.87799,-8.40881 -59.18305,0.84148 -71.77527,34.39209 -143.33667,69.23047 -215.00567,103.84463 -8.40815,4.06091 -14.32166,9.84101 -14.39978,19.74008 -0.079,10.00498 5.52282,16.22797 14.08978,20.54743 12.3277,6.21567 24.51239,12.71484 37.34228,19.41369 7.51429,3.93381 14.42273,7.5896 21.37854,11.15274 31.68775,16.23212 63.40558,32.40552 95.07782,48.66782 14.943,7.67261 29.74964,15.61227 44.73053,23.20911 8.44464,4.28232 16.79547,9.15341 25.75525,11.93237 18.81989,5.83722 37.10712,3.93353 54.83185,-5.55777 25.51599,-13.66336 51.41541,-26.61407 77.2135,-39.74655 30.82071,-15.68933 61.7009,-31.26196 92.58359,-46.82907 1.56006,-0.78641 3.38776,-1.0419 5.09082,-1.54462 z" id="path46" style="fill:#b0b2b8;fill-opacity:1"></path><path fill="#4b4d51" opacity="1" stroke="none" d="m 791.89377,387.77539 c 1.04068,-1.03091 1.90903,-2.38956 3.14896,-3.04166 11.48425,-6.03955 22.98721,-12.04745 34.57742,-17.88034 8.52002,-4.28775 14.37558,-10.49713 14.23218,-20Line truncated
|
||||
|
After Width: | Height: | Size: 8.1 KiB |
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"name": "MyWebSite",
|
||||
"short_name": "MySite",
|
||||
"icons": [
|
||||
{
|
||||
"src": "/web-app-manifest-192x192.png",
|
||||
"sizes": "192x192",
|
||||
"type": "image/png",
|
||||
"purpose": "maskable"
|
||||
},
|
||||
{
|
||||
"src": "/web-app-manifest-512x512.png",
|
||||
"sizes": "512x512",
|
||||
"type": "image/png",
|
||||
"purpose": "maskable"
|
||||
}
|
||||
],
|
||||
"theme_color": "#ffffff",
|
||||
"background_color": "#ffffff",
|
||||
"display": "standalone"
|
||||
}
|
||||
|
After Width: | Height: | Size: 1.6 KiB |
|
After Width: | Height: | Size: 7.0 KiB |
@@ -0,0 +1,424 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>ChronoSeal | Browser Attestation Daemon</title>
|
||||
<meta name="description" content="ChronoSeal is a Unix-native browser attestation daemon combining cryptographic signatures, deterministic state machines, and a synthetic gene mutation engine for session integrity.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Main Content -->
|
||||
<main class="main-content">
|
||||
|
||||
<!-- Hero Section -->
|
||||
<section id="home" class="hero animate">
|
||||
<div class="hero-badge">
|
||||
<i class="fas fa-code-branch"></i> v1.0.2 · Production Hardened
|
||||
</div>
|
||||
<h1>Browser Attestation<br>Reimagined</h1>
|
||||
<p class="hero-subtitle">
|
||||
ChronoSeal is a Unix-native browser attestation daemon combining cryptographic signatures,
|
||||
deterministic state machines, and a synthetic gene mutation engine for unparalleled session integrity.
|
||||
</p>
|
||||
<div class="hero-buttons">
|
||||
<a href="deployment.html" class="btn btn-primary">
|
||||
<i class="fas fa-terminal"></i> Get Started
|
||||
</a>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="btn btn-secondary" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> View on GitHub
|
||||
</a>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<!-- Stats Grid -->
|
||||
<div class="stats-grid animate">
|
||||
<div class="stat-card">
|
||||
<div class="stat-number">100</div>
|
||||
<div class="stat-label">Tests Passing</div>
|
||||
</div>
|
||||
<div class="stat-card">
|
||||
<div class="stat-number">3</div>
|
||||
<div class="stat-label">Storage Backends</div>
|
||||
</div>
|
||||
<div class="stat-card">
|
||||
<div class="stat-number">10</div>
|
||||
<div class="stat-label">VM Opcodes</div>
|
||||
</div>
|
||||
<div class="stat-card">
|
||||
<div class="stat-number">30s</div>
|
||||
<div class="stat-label">Max Drift</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Core Features Section -->
|
||||
<section id="features" class="section animate">
|
||||
<div class="section-header">
|
||||
<h2>Core Features</h2>
|
||||
<p>Everything you need for robust, enterprise-grade browser attestation</p>
|
||||
</div>
|
||||
<div class="cards-grid">
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-dna"></i></div>
|
||||
<h3>Synthetic Gene Engine</h3>
|
||||
<p>Deterministic mutation sequence that both server and browser WASM must execute in sync—creating an unprecedented second state channel.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">Mutation Rounds</span>
|
||||
<span class="tag">Gene Size 512-4096</span>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-link"></i></div>
|
||||
<h3>Cryptographic Chain</h3>
|
||||
<p>Ed25519 signatures and a Blake3 hash chain progression with rotating salts ensures replay resistance and continuity verification.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">Ed25519</span>
|
||||
<span class="tag">Blake3</span>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-microchip"></i></div>
|
||||
<h3>Deterministic VM</h3>
|
||||
<p>A lightweight 10-opcode virtual machine executing server-issued programs with exact stack state verification between client and server.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">Stack Verification</span>
|
||||
<span class="tag">Custom Instruction Set</span>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-user-secret"></i></div>
|
||||
<h3>Silent Rejection</h3>
|
||||
<p>Failed heartbeats return identical HTTP 200 responses—providing zero oracle feedback and making automated probing impossible.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">No Oracle</span>
|
||||
<span class="tag">Security First</span>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-database"></i></div>
|
||||
<h3>Pluggable Storage</h3>
|
||||
<p>Use SQLite in-memory for testing, SQLite disk for standalone, or Valkey/Redis for massive distributed cluster deployments.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">SQLite</span>
|
||||
<span class="tag">Valkey/Redis</span>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-server"></i></div>
|
||||
<h3>Production Ready</h3>
|
||||
<p>Built-in Prometheus metrics, liveness/readiness probes, structured logging, systemd integration, and graceful shutdown.</p>
|
||||
<div class="card-tags">
|
||||
<span class="tag">Prometheus</span>
|
||||
<span class="tag">Observability</span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<!-- Architecture Section -->
|
||||
<section id="architecture-sec" class="section animate">
|
||||
<div class="section-header">
|
||||
<h2>System Architecture</h2>
|
||||
<p>A look inside how ChronoSeal protects your sessions in real-time</p>
|
||||
</div>
|
||||
<div class="architecture-container">
|
||||
<!-- Inline diagram container dynamically drawn by diagrams.js -->
|
||||
<div id="diagram-architecture" class="arch-diagram"></div>
|
||||
</div>
|
||||
<div class="text-center" style="margin-top:24px">
|
||||
<a href="architecture.html" class="btn btn-secondary btn-sm">Read Architecture Docs</a>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<!-- Protocol Section -->
|
||||
<section id="protocol-sec" class="section animate">
|
||||
<div class="section-header">
|
||||
<h2>Protocol Flow</h2>
|
||||
<p>Secure handshake and continuous background verification</p>
|
||||
</div>
|
||||
<div class="code-block code-block-center">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Sequence Flow Diagram</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>┌─────────────┐ ┌─────────────┐
|
||||
│ Browser │ │ Server │
|
||||
│ (WASM) │ │ (ChronoSeal)│
|
||||
└──────┬──────┘ └──────┬──────┘
|
||||
│ │
|
||||
│ POST /init { public_key } │
|
||||
│─────────────────────────────────────────────────>│
|
||||
│ │
|
||||
│ 200 { session_id, salt, opcodes, │
|
||||
│ initial_hash, mutation_order } │
|
||||
│<─────────────────────────────────────────────────│
|
||||
│ │
|
||||
│ [Execute VM, Preview Mutation] │
|
||||
│ │
|
||||
│ POST /hb { prev_hash, timestamp, entropy, │
|
||||
│ stack_state, gene_commitment, │
|
||||
│ signature } │
|
||||
│─────────────────────────────────────────────────>│
|
||||
│ │
|
||||
│ [Verify: Signature → Hash → Mutation → Drift] │
|
||||
│ │
|
||||
│ 200 { status: "ok", next_salt, │
|
||||
│ next_mutation_step, next_order } │
|
||||
│<─────────────────────────────────────────────────│
|
||||
│ │
|
||||
│ [Commit Preview, Rotate State] │
|
||||
│ │
|
||||
▼ ▼</code></pre>
|
||||
</div>
|
||||
<div class="text-center" style="margin-top:24px">
|
||||
<a href="protocol.html" class="btn btn-secondary btn-sm">Read Protocol Docs</a>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<!-- Comparison Section -->
|
||||
<section id="comparison-sec" class="section animate">
|
||||
<div class="section-header">
|
||||
<h2>vs Popular Solutions</h2>
|
||||
<p>Why modern privacy-conscious teams choose ChronoSeal</p>
|
||||
</div>
|
||||
<div class="comparison-table-wrap">
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Feature</th>
|
||||
<th>ChronoSeal</th>
|
||||
<th>Cloudflare Turnstile</th>
|
||||
<th>reCAPTCHA v3</th>
|
||||
<th>Enterprise WAFs</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>Self-hosted & Air-gapped</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Yes</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Privacy Focused</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Excellent</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Medium</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Poor</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Low</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Cryptographic Continuity</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Very High</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Medium</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Low</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Medium</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Cost Structure</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Free (FOSS)</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Freemium</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Free → Paid</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> Extremely High</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>WASM Mutation Engine</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Unique</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Silent Rejection Architecture</td>
|
||||
<td class="check"><i class="fas fa-check-circle"></i> Yes</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
<td class="times"><i class="fas fa-times-circle"></i> No</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
<div class="text-center" style="margin-top:24px">
|
||||
<a href="comparison.html" class="btn btn-secondary btn-sm">Detailed Comparison</a>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<!-- Quick Deployment Section -->
|
||||
<section id="deployment-sec" class="section animate">
|
||||
<div class="section-header">
|
||||
<h2>Quick Deployment</h2>
|
||||
<p>Spin up the daemon in under a minute</p>
|
||||
</div>
|
||||
<div class="cards-grid">
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fab fa-docker"></i></div>
|
||||
<h3>Docker</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code>docker run -d -p 3000:3000 \
|
||||
chronoseal/chronoseal:latest</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-cubes"></i></div>
|
||||
<h3>Docker Compose</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code>bash scripts/build.sh
|
||||
docker compose up -d --build</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fab fa-linux"></i></div>
|
||||
<h3>Native (systemd)</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code>curl -sL https://chronoseal.io/install.sh | sudo bash
|
||||
sudo systemctl enable --now chronoseal</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-terminal"></i></div>
|
||||
<h3>From Source</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code>git clone https://github.com/thakares/chronoseal-rs
|
||||
cd chronoseal && cargo run --release</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-network-wired"></i></div>
|
||||
<h3>Nginx Proxy</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code>location / {
|
||||
proxy_pass http://127.0.0.1:3000;
|
||||
proxy_http_version 1.1;
|
||||
}</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
<div class="card">
|
||||
<div class="card-icon"><i class="fas fa-heartbeat"></i></div>
|
||||
<h3>Verification</h3>
|
||||
<div class="code-block" style="margin-top: 1rem; border: none; padding: 1rem; background: rgba(0,0,0,0.3);">
|
||||
<pre><code># Check daemon health status
|
||||
curl http://localhost:3000/health
|
||||
|
||||
# Query daemon CLI metrics
|
||||
chronoseal status --format json</code></pre>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
</main>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
<script src="js/pwa.js"></script>
|
||||
<script src="js/diagrams.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,184 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Website — app.js
|
||||
Core runtime: header scroll, mobile nav, scroll animations,
|
||||
code copy, back-to-top, keyboard shortcuts
|
||||
============================================================ */
|
||||
|
||||
(function () {
|
||||
'use strict';
|
||||
|
||||
/* ---- Header scroll state ---- */
|
||||
var header = document.querySelector('.navbar');
|
||||
if (header) {
|
||||
var onScroll = function () {
|
||||
header.classList.toggle('scrolled', window.scrollY > 20);
|
||||
};
|
||||
window.addEventListener('scroll', onScroll, { passive: true });
|
||||
onScroll();
|
||||
}
|
||||
|
||||
/* ---- Enhanced Mobile nav toggle ---- */
|
||||
var toggle = document.querySelector('.nav-toggle');
|
||||
var navLinks = document.querySelector('.nav-links');
|
||||
if (toggle && navLinks) {
|
||||
var menuIcon = toggle.querySelector('i');
|
||||
toggle.addEventListener('click', function () {
|
||||
var isActive = navLinks.classList.contains('active');
|
||||
if (isActive) {
|
||||
navLinks.classList.remove('active');
|
||||
if (menuIcon) {
|
||||
menuIcon.classList.remove('fa-times');
|
||||
menuIcon.classList.add('fa-bars');
|
||||
}
|
||||
} else {
|
||||
navLinks.classList.add('active');
|
||||
if (menuIcon) {
|
||||
menuIcon.classList.remove('fa-bars');
|
||||
menuIcon.classList.add('fa-times');
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
// Close nav on link click
|
||||
navLinks.querySelectorAll('a').forEach(function (a) {
|
||||
a.addEventListener('click', function () {
|
||||
navLinks.classList.remove('active');
|
||||
if (menuIcon) {
|
||||
menuIcon.classList.remove('fa-times');
|
||||
menuIcon.classList.add('fa-bars');
|
||||
}
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
/* ---- Doc sidebar mobile toggle ---- */
|
||||
var sidebarToggle = document.querySelector('.doc-sidebar-toggle');
|
||||
var sidebar = document.querySelector('.doc-sidebar');
|
||||
if (sidebarToggle && sidebar) {
|
||||
sidebarToggle.addEventListener('click', function () {
|
||||
sidebar.classList.toggle('open');
|
||||
});
|
||||
// Close sidebar on link click (mobile)
|
||||
sidebar.querySelectorAll('.doc-nav-item').forEach(function (a) {
|
||||
a.addEventListener('click', function () {
|
||||
if (window.innerWidth <= 900) sidebar.classList.remove('open');
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
/* ---- Intersection Observer for Scroll Animations ---- */
|
||||
if ('IntersectionObserver' in window) {
|
||||
var observerOptions = { threshold: 0.1, rootMargin: '0px 0px -50px 0px' };
|
||||
var observer = new IntersectionObserver(function (entries) {
|
||||
entries.forEach(function (entry) {
|
||||
if (entry.isIntersecting) {
|
||||
entry.target.classList.add('in-view');
|
||||
observer.unobserve(entry.target);
|
||||
}
|
||||
});
|
||||
}, observerOptions);
|
||||
|
||||
// Observe all animated elements
|
||||
document.querySelectorAll('.animate, .card, .stat-card, .step').forEach(function (el) {
|
||||
if (!el.classList.contains('animate')) {
|
||||
el.classList.add('animate');
|
||||
}
|
||||
observer.observe(el);
|
||||
});
|
||||
}
|
||||
|
||||
/* ---- Code block copy buttons ---- */
|
||||
document.querySelectorAll('.code-copy-btn').forEach(function (btn) {
|
||||
btn.addEventListener('click', function () {
|
||||
var pre = btn.closest('.code-block').querySelector('pre');
|
||||
if (!pre) return;
|
||||
var text = pre.textContent;
|
||||
if (navigator.clipboard) {
|
||||
navigator.clipboard.writeText(text).then(function () {
|
||||
btn.textContent = 'Copied!';
|
||||
setTimeout(function () { btn.textContent = 'Copy'; }, 1500);
|
||||
});
|
||||
} else {
|
||||
// Fallback
|
||||
var ta = document.createElement('textarea');
|
||||
ta.value = text;
|
||||
ta.style.cssText = 'position:fixed;left:-999px';
|
||||
document.body.appendChild(ta);
|
||||
ta.select();
|
||||
document.execCommand('copy');
|
||||
document.body.removeChild(ta);
|
||||
btn.textContent = 'Copied!';
|
||||
setTimeout(function () { btn.textContent = 'Copy'; }, 1500);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
/* ---- Back to top ---- */
|
||||
var btt = document.querySelector('.back-to-top');
|
||||
if (btt) {
|
||||
window.addEventListener('scroll', function () {
|
||||
btt.classList.toggle('visible', window.scrollY > 400);
|
||||
}, { passive: true });
|
||||
btt.addEventListener('click', function (e) {
|
||||
e.preventDefault();
|
||||
window.scrollTo({ top: 0, behavior: 'smooth' });
|
||||
});
|
||||
}
|
||||
|
||||
/* ---- Keyboard shortcut: / or Ctrl+K for search ---- */
|
||||
document.addEventListener('keydown', function (e) {
|
||||
if (e.key === '/' && !isInput(e.target)) {
|
||||
e.preventDefault();
|
||||
if (typeof ChronoSearch !== 'undefined') ChronoSearch.open();
|
||||
}
|
||||
if ((e.ctrlKey || e.metaKey) && e.key === 'k') {
|
||||
e.preventDefault();
|
||||
if (typeof ChronoSearch !== 'undefined') ChronoSearch.open();
|
||||
}
|
||||
if (e.key === 'Escape') {
|
||||
if (typeof ChronoSearch !== 'undefined') ChronoSearch.close();
|
||||
}
|
||||
});
|
||||
|
||||
function isInput(el) {
|
||||
var tag = el.tagName;
|
||||
return tag === 'INPUT' || tag === 'TEXTAREA' || tag === 'SELECT' || el.isContentEditable;
|
||||
}
|
||||
|
||||
/* ---- Nav dropdown (desktop hover + mobile tap) ---- */
|
||||
document.querySelectorAll('.nav-dropdown').forEach(function (dd) {
|
||||
var trigger = dd.querySelector('.nav-link');
|
||||
if (!trigger) return;
|
||||
trigger.addEventListener('click', function (e) {
|
||||
if (window.innerWidth <= 768) {
|
||||
e.preventDefault();
|
||||
dd.classList.toggle('open');
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
/* ---- Active nav link highlight ---- */
|
||||
var currentPage = window.location.pathname.split('/').pop() || 'index.html';
|
||||
document.querySelectorAll('.nav-links a, .doc-nav-item').forEach(function (link) {
|
||||
var href = link.getAttribute('href');
|
||||
if (!href) return;
|
||||
var linkPage = href.split('/').pop().split('#')[0] || 'index.html';
|
||||
if (linkPage === currentPage) {
|
||||
link.classList.add('active');
|
||||
}
|
||||
});
|
||||
|
||||
/* ---- Smooth anchor scroll ---- */
|
||||
document.querySelectorAll('a[href^="#"]').forEach(function (a) {
|
||||
a.addEventListener('click', function (e) {
|
||||
var id = a.getAttribute('href').substring(1);
|
||||
var target = document.getElementById(id);
|
||||
if (target) {
|
||||
e.preventDefault();
|
||||
target.scrollIntoView({ behavior: 'smooth', block: 'start' });
|
||||
history.pushState(null, '', '#' + id);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
})();
|
||||
@@ -0,0 +1,160 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Website — diagrams.js
|
||||
Generates SVG architecture & protocol flow diagrams inline
|
||||
============================================================ */
|
||||
|
||||
var ChronoDiagrams = (function () {
|
||||
'use strict';
|
||||
|
||||
function drawArchitecture(containerId) {
|
||||
var el = document.getElementById(containerId);
|
||||
if (!el) return;
|
||||
|
||||
var svg = '<svg viewBox="0 0 760 420" fill="none" xmlns="http://www.w3.org/2000/svg" style="width:100%;height:auto;max-width:760px">';
|
||||
|
||||
/* Background */
|
||||
svg += '<rect width="760" height="420" rx="12" fill="#131620"/>';
|
||||
|
||||
/* Browser box */
|
||||
svg += '<rect x="40" y="30" width="280" height="170" rx="8" fill="#1e2230" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
svg += '<text x="180" y="55" fill="#b0b2b8" font-size="11" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">BROWSER</text>';
|
||||
|
||||
svg += '<rect x="60" y="70" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="115" y="93" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">WASM Runtime</text>';
|
||||
|
||||
svg += '<rect x="190" y="70" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="245" y="93" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">heartbeat.js</text>';
|
||||
|
||||
svg += '<rect x="60" y="120" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="115" y="143" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Ed25519 Keys</text>';
|
||||
|
||||
svg += '<rect x="190" y="120" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="245" y="143" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Gene Engine</text>';
|
||||
|
||||
svg += '<text x="180" y="185" fill="#6b6f7a" font-size="9" text-anchor="middle" font-family="Inter,sans-serif">Entropy · Signing · VM · Mutation</text>';
|
||||
|
||||
/* Arrow: Browser → Server */
|
||||
svg += '<line x1="320" y1="115" x2="430" y2="115" stroke="#7b7e85" stroke-width="1.5" stroke-dasharray="6 3"/>';
|
||||
svg += '<polygon points="428,110 438,115 428,120" fill="#7b7e85"/>';
|
||||
svg += '<text x="375" y="105" fill="#6b6f7a" font-size="8" text-anchor="middle" font-family="Inter,sans-serif">POST /hb</text>';
|
||||
svg += '<text x="375" y="135" fill="#6b6f7a" font-size="8" text-anchor="middle" font-family="Inter,sans-serif">POST /init</text>';
|
||||
|
||||
/* Server box */
|
||||
svg += '<rect x="440" y="30" width="280" height="170" rx="8" fill="#1e2230" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
svg += '<text x="580" y="55" fill="#b0b2b8" font-size="11" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">SERVER (chronoseal)</text>';
|
||||
|
||||
svg += '<rect x="460" y="70" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="515" y="93" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Axum Router</text>';
|
||||
|
||||
svg += '<rect x="590" y="70" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="645" y="93" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Rate Limiter</text>';
|
||||
|
||||
svg += '<rect x="460" y="120" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="515" y="143" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Verifier</text>';
|
||||
|
||||
svg += '<rect x="590" y="120" width="110" height="36" rx="5" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="645" y="143" fill="#e1e1e4" font-size="10" text-anchor="middle" font-family="Inter,sans-serif">Gene Engine</text>';
|
||||
|
||||
svg += '<text x="580" y="185" fill="#6b6f7a" font-size="9" text-anchor="middle" font-family="Inter,sans-serif">Verify · Advance · Trust · CAS</text>';
|
||||
|
||||
/* Shared box (bottom center) */
|
||||
svg += '<rect x="230" y="240" width="300" height="60" rx="8" fill="#1e2230" stroke="#b0b2b8" stroke-width="1" stroke-dasharray="4 3"/>';
|
||||
svg += '<text x="380" y="266" fill="#b0b2b8" font-size="11" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">shared crate</text>';
|
||||
svg += '<text x="380" y="284" fill="#6b6f7a" font-size="9" text-anchor="middle" font-family="Inter,sans-serif">Protocol · Hashing · Gene · VM · Constants</text>';
|
||||
|
||||
/* Arrows to shared */
|
||||
svg += '<line x1="180" y1="200" x2="310" y2="244" stroke="#7b7e85" stroke-width="1" stroke-dasharray="4 3"/>';
|
||||
svg += '<line x1="580" y1="200" x2="450" y2="244" stroke="#7b7e85" stroke-width="1" stroke-dasharray="4 3"/>';
|
||||
|
||||
/* Storage box */
|
||||
svg += '<rect x="440" y="340" width="280" height="55" rx="8" fill="#1e2230" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
svg += '<text x="580" y="365" fill="#b0b2b8" font-size="11" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">STORAGE</text>';
|
||||
svg += '<text x="580" y="382" fill="#6b6f7a" font-size="9" text-anchor="middle" font-family="Inter,sans-serif">SQLite In-Memory · SQLite Disk · Valkey</text>';
|
||||
|
||||
/* Server → Storage arrow */
|
||||
svg += '<line x1="580" y1="200" x2="580" y2="340" stroke="#7b7e85" stroke-width="1.5" stroke-dasharray="6 3"/>';
|
||||
svg += '<polygon points="575,338 580,348 585,338" fill="#7b7e85"/>';
|
||||
|
||||
/* CLI box */
|
||||
svg += '<rect x="40" y="340" width="170" height="55" rx="8" fill="#1e2230" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
svg += '<text x="125" y="365" fill="#b0b2b8" font-size="11" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">CLI</text>';
|
||||
svg += '<text x="125" y="382" fill="#6b6f7a" font-size="9" text-anchor="middle" font-family="Inter,sans-serif">status · health · metrics · stats</text>';
|
||||
|
||||
svg += '</svg>';
|
||||
el.innerHTML = svg;
|
||||
}
|
||||
|
||||
function drawProtocolFlow(containerId) {
|
||||
var el = document.getElementById(containerId);
|
||||
if (!el) return;
|
||||
|
||||
var svg = '<svg viewBox="0 0 600 520" fill="none" xmlns="http://www.w3.org/2000/svg" style="width:100%;height:auto;max-width:600px">';
|
||||
svg += '<rect width="600" height="520" rx="12" fill="#131620"/>';
|
||||
|
||||
/* Columns */
|
||||
svg += '<text x="150" y="30" fill="#b0b2b8" font-size="12" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">Browser</text>';
|
||||
svg += '<text x="450" y="30" fill="#b0b2b8" font-size="12" font-weight="700" text-anchor="middle" font-family="Inter,sans-serif">Server</text>';
|
||||
|
||||
/* Lifelines */
|
||||
svg += '<line x1="150" y1="44" x2="150" y2="500" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
svg += '<line x1="450" y1="44" x2="450" y2="500" stroke="#2a2f40" stroke-width="1.5"/>';
|
||||
|
||||
var y = 70;
|
||||
var arrows = [
|
||||
{ from: 150, to: 450, label: 'Generate Ed25519 keypair', note: '', dir: 'self' },
|
||||
{ from: 150, to: 450, label: 'POST /init { public_key }', note: '', dir: 'right' },
|
||||
{ from: 450, to: 150, label: '{ session_id, salt, opcodes, gene_size, mutation_order }', note: '', dir: 'left' },
|
||||
{ from: 150, to: 450, label: 'Execute VM program', note: '', dir: 'self' },
|
||||
{ from: 150, to: 450, label: 'Collect entropy + sign payload', note: '', dir: 'self' },
|
||||
{ from: 150, to: 450, label: 'Preview gene commitment', note: '', dir: 'self' },
|
||||
{ from: 150, to: 450, label: 'POST /hb { session_id, hash, signature, gene_commitment, … }', note: '', dir: 'right' },
|
||||
{ from: 450, to: 150, label: 'Verify chain + signature + gene + trust', note: '', dir: 'selfr' },
|
||||
{ from: 450, to: 150, label: '{ next_salt, next_mutation_step, next_mutation_order }', note: 'accepted', dir: 'left' },
|
||||
{ from: 450, to: 150, label: '{ status: "ok" }', note: 'rejected (silent)', dir: 'left' },
|
||||
];
|
||||
|
||||
for (var i = 0; i < arrows.length; i++) {
|
||||
var a = arrows[i];
|
||||
if (a.dir === 'right') {
|
||||
svg += '<line x1="155" y1="' + y + '" x2="445" y2="' + y + '" stroke="#7b7e85" stroke-width="1.2"/>';
|
||||
svg += '<polygon points="443,' + (y - 4) + ' 450,' + y + ' 443,' + (y + 4) + '" fill="#7b7e85"/>';
|
||||
svg += '<text x="300" y="' + (y - 8) + '" fill="#e1e1e4" font-size="8.5" text-anchor="middle" font-family="Inter,sans-serif">' + a.label + '</text>';
|
||||
} else if (a.dir === 'left') {
|
||||
svg += '<line x1="445" y1="' + y + '" x2="155" y2="' + y + '" stroke="#7b7e85" stroke-width="1.2"/>';
|
||||
svg += '<polygon points="157,' + (y - 4) + ' 150,' + y + ' 157,' + (y + 4) + '" fill="#7b7e85"/>';
|
||||
svg += '<text x="300" y="' + (y - 8) + '" fill="#e1e1e4" font-size="8.5" text-anchor="middle" font-family="Inter,sans-serif">' + a.label + '</text>';
|
||||
if (a.note) {
|
||||
svg += '<text x="300" y="' + (y + 14) + '" fill="#6b6f7a" font-size="8" text-anchor="middle" font-style="italic" font-family="Inter,sans-serif">' + a.note + '</text>';
|
||||
y += 8;
|
||||
}
|
||||
} else if (a.dir === 'self') {
|
||||
svg += '<rect x="60" y="' + (y - 12) + '" width="180" height="22" rx="4" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="150" y="' + (y + 3) + '" fill="#9a9da6" font-size="8.5" text-anchor="middle" font-family="Inter,sans-serif">' + a.label + '</text>';
|
||||
} else if (a.dir === 'selfr') {
|
||||
svg += '<rect x="360" y="' + (y - 12) + '" width="180" height="22" rx="4" fill="#252a3a" stroke="#2a2f40"/>';
|
||||
svg += '<text x="450" y="' + (y + 3) + '" fill="#9a9da6" font-size="8.5" text-anchor="middle" font-family="Inter,sans-serif">' + a.label + '</text>';
|
||||
}
|
||||
y += 44;
|
||||
}
|
||||
|
||||
svg += '</svg>';
|
||||
el.innerHTML = svg;
|
||||
}
|
||||
|
||||
/* ---- Auto-init ---- */
|
||||
function init() {
|
||||
drawArchitecture('diagram-architecture');
|
||||
drawProtocolFlow('diagram-protocol');
|
||||
}
|
||||
|
||||
if (document.readyState === 'loading') {
|
||||
document.addEventListener('DOMContentLoaded', init);
|
||||
} else {
|
||||
init();
|
||||
}
|
||||
|
||||
return {
|
||||
drawArchitecture: drawArchitecture,
|
||||
drawProtocolFlow: drawProtocolFlow
|
||||
};
|
||||
})();
|
||||
@@ -0,0 +1,41 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Website — pwa.js
|
||||
Progressive Web App: service worker registration + install
|
||||
============================================================ */
|
||||
|
||||
(function () {
|
||||
'use strict';
|
||||
|
||||
if ('serviceWorker' in navigator) {
|
||||
window.addEventListener('load', function () {
|
||||
navigator.serviceWorker.register('/sw.js').then(function (reg) {
|
||||
/* Update found — silent refresh */
|
||||
reg.addEventListener('updatefound', function () {
|
||||
var worker = reg.installing;
|
||||
if (!worker) return;
|
||||
worker.addEventListener('statechange', function () {
|
||||
if (worker.state === 'activated' && navigator.serviceWorker.controller) {
|
||||
/* New version available — user can refresh */
|
||||
}
|
||||
});
|
||||
});
|
||||
}).catch(function () {
|
||||
/* SW registration failed — app still works */
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
/* ---- Installable PWA banner (A2HS) ---- */
|
||||
var deferredPrompt = null;
|
||||
|
||||
window.addEventListener('beforeinstallprompt', function (e) {
|
||||
e.preventDefault();
|
||||
deferredPrompt = e;
|
||||
/* Could show a custom install banner here */
|
||||
});
|
||||
|
||||
window.addEventListener('appinstalled', function () {
|
||||
deferredPrompt = null;
|
||||
});
|
||||
|
||||
})();
|
||||
@@ -0,0 +1,144 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Website — search.js
|
||||
Client-side full-text search across all pages
|
||||
============================================================ */
|
||||
|
||||
var ChronoSearch = (function () {
|
||||
'use strict';
|
||||
|
||||
/* ---- Search index ---- */
|
||||
var pages = [
|
||||
{ title: 'Home', url: 'index.html', desc: 'ChronoSeal overview, features, and quick start', keywords: 'home overview features quick start install' },
|
||||
{ title: 'Architecture', url: 'architecture.html', desc: 'System architecture, crate layout, and data flow', keywords: 'architecture crates workspace wasm shared server' },
|
||||
{ title: 'Protocol', url: 'protocol.html', desc: 'Heartbeat protocol, hash chain, and mutation engine', keywords: 'protocol heartbeat hash chain blake3 ed25519 mutation gene' },
|
||||
{ title: 'API Reference', url: 'api.html', desc: 'HTTP endpoints: /init, /hb, /health, /metrics, /stats', keywords: 'api http post init heartbeat health metrics stats json' },
|
||||
{ title: 'Deployment', url: 'deployment.html', desc: 'Installation, systemd, Docker, nginx reverse proxy', keywords: 'deploy install systemd docker nginx proxy production' },
|
||||
{ title: 'Threat Model', url: 'threat-model.html', desc: 'Security threat model and defense boundaries', keywords: 'threat model security attack replay automation defense' },
|
||||
{ title: 'Performance', url: 'performance.html', desc: 'Performance tuning, benchmarks, and optimization', keywords: 'performance tuning benchmark latency throughput' },
|
||||
{ title: 'Philosophy', url: 'philosophy.html', desc: 'Design philosophy and engineering priorities', keywords: 'philosophy design unix privacy operator control' },
|
||||
{ title: 'Privacy Policy', url: 'privacy.html', desc: 'Data handling, storage, and privacy commitments', keywords: 'privacy policy data collection storage session' },
|
||||
{ title: 'Security', url: 'security.html', desc: 'Security assumptions, hardening, and response headers', keywords: 'security assumptions headers hardening csp' },
|
||||
{ title: 'Operations', url: 'operations.html', desc: 'Monitoring, health checks, metrics, and logging', keywords: 'operations health status metrics stats logging monitor' },
|
||||
{ title: 'Testing', url: 'testing.html', desc: 'Test suite, fuzzing, and validation coverage', keywords: 'testing tests cargo fuzz validation fingerprint' },
|
||||
{ title: 'Comparison', url: 'comparison.html', desc: 'ChronoSeal vs commercial anti-bot solutions', keywords: 'comparison cloudflare akamai recaptcha datadome kasada' },
|
||||
];
|
||||
|
||||
var overlay = null;
|
||||
var input = null;
|
||||
var results = null;
|
||||
|
||||
function init() {
|
||||
overlay = document.querySelector('.search-overlay');
|
||||
input = document.querySelector('.search-input');
|
||||
results = document.querySelector('.search-results');
|
||||
if (!overlay || !input || !results) return;
|
||||
|
||||
input.addEventListener('input', debounce(onInput, 150));
|
||||
overlay.addEventListener('click', function (e) {
|
||||
if (e.target === overlay) close();
|
||||
});
|
||||
|
||||
// Keyboard nav inside results
|
||||
input.addEventListener('keydown', function (e) {
|
||||
if (e.key === 'ArrowDown' || e.key === 'ArrowUp') {
|
||||
e.preventDefault();
|
||||
navigateResults(e.key === 'ArrowDown' ? 1 : -1);
|
||||
}
|
||||
if (e.key === 'Enter') {
|
||||
var sel = results.querySelector('.search-result.selected');
|
||||
if (sel) { window.location.href = sel.getAttribute('href'); close(); }
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function open() {
|
||||
if (!overlay) init();
|
||||
if (!overlay) return;
|
||||
overlay.classList.add('open');
|
||||
input.value = '';
|
||||
results.innerHTML = renderHints();
|
||||
setTimeout(function () { input.focus(); }, 100);
|
||||
}
|
||||
|
||||
function close() {
|
||||
if (overlay) overlay.classList.remove('open');
|
||||
}
|
||||
|
||||
function onInput() {
|
||||
var q = input.value.trim().toLowerCase();
|
||||
if (!q) { results.innerHTML = renderHints(); return; }
|
||||
|
||||
var matches = [];
|
||||
for (var i = 0; i < pages.length; i++) {
|
||||
var p = pages[i];
|
||||
var hay = (p.title + ' ' + p.desc + ' ' + p.keywords).toLowerCase();
|
||||
if (hay.indexOf(q) !== -1) {
|
||||
matches.push(p);
|
||||
}
|
||||
}
|
||||
|
||||
if (matches.length === 0) {
|
||||
results.innerHTML = '<div class="search-empty">No results for “' + escHtml(q) + '”</div>';
|
||||
return;
|
||||
}
|
||||
|
||||
var html = '';
|
||||
for (var j = 0; j < matches.length; j++) {
|
||||
var m = matches[j];
|
||||
html += '<a class="search-result' + (j === 0 ? ' selected' : '') + '" href="' + m.url + '">';
|
||||
html += '<div class="search-result-title">' + highlightMatch(m.title, q) + '</div>';
|
||||
html += '<div class="search-result-desc">' + highlightMatch(m.desc, q) + '</div>';
|
||||
html += '</a>';
|
||||
}
|
||||
results.innerHTML = html;
|
||||
}
|
||||
|
||||
function navigateResults(dir) {
|
||||
var items = results.querySelectorAll('.search-result');
|
||||
if (!items.length) return;
|
||||
var idx = -1;
|
||||
for (var i = 0; i < items.length; i++) {
|
||||
if (items[i].classList.contains('selected')) { idx = i; break; }
|
||||
}
|
||||
if (idx >= 0) items[idx].classList.remove('selected');
|
||||
idx = Math.max(0, Math.min(items.length - 1, idx + dir));
|
||||
items[idx].classList.add('selected');
|
||||
items[idx].scrollIntoView({ block: 'nearest' });
|
||||
}
|
||||
|
||||
function renderHints() {
|
||||
return '<div class="search-empty">Type to search documentation…<br><span style="font-size:.78rem;color:var(--text-muted)">↑↓ Navigate · ↵ Open · Esc Close</span></div>';
|
||||
}
|
||||
|
||||
function highlightMatch(text, q) {
|
||||
var idx = text.toLowerCase().indexOf(q);
|
||||
if (idx === -1) return escHtml(text);
|
||||
return escHtml(text.substring(0, idx)) +
|
||||
'<mark style="background:rgba(176,178,184,.2);color:var(--text-primary);border-radius:2px;padding:0 2px">' +
|
||||
escHtml(text.substring(idx, idx + q.length)) + '</mark>' +
|
||||
escHtml(text.substring(idx + q.length));
|
||||
}
|
||||
|
||||
function escHtml(s) {
|
||||
var div = document.createElement('div');
|
||||
div.appendChild(document.createTextNode(s));
|
||||
return div.innerHTML;
|
||||
}
|
||||
|
||||
function debounce(fn, ms) {
|
||||
var t;
|
||||
return function () {
|
||||
clearTimeout(t);
|
||||
t = setTimeout(fn, ms);
|
||||
};
|
||||
}
|
||||
|
||||
/* ---- Auto-init ---- */
|
||||
if (document.readyState === 'loading') {
|
||||
document.addEventListener('DOMContentLoaded', init);
|
||||
} else {
|
||||
init();
|
||||
}
|
||||
|
||||
return { open: open, close: close };
|
||||
})();
|
||||
@@ -0,0 +1,304 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Operations Handbook | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal Operations Handbook, detailing deployment, monitoring, scaling, failure diagnosis, and debugging options.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html" class="active">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item active">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Lifecycle & Dev</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Operations Handbook</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>Operations & Diagnostics Handbook</h1>
|
||||
<p class="doc-subtitle">This guide details how to monitor, scale, maintain, and debug the ChronoSeal daemon (<code>chronoseal</code>) in production environments.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Systemd Service Configuration</h2>
|
||||
<p>On single-node Linux systems, run the daemon under systemd. The standard service unit file is configured at <code>/etc/systemd/system/chronoseal.service</code>:</p>
|
||||
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">systemd Unit File</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>[Unit]
|
||||
Description=ChronoSeal Attestation Daemon
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=chronoseal
|
||||
Group=chronoseal
|
||||
WorkingDirectory=/var/lib/chronoseal
|
||||
ExecStart=/usr/local/bin/chronoseal run --config /etc/chronoseal.toml
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
LimitNOFILE=65536
|
||||
|
||||
# Hardening
|
||||
ProtectSystem=full
|
||||
ProtectHome=true
|
||||
NoNewPrivileges=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target</code></pre>
|
||||
</div>
|
||||
|
||||
<p>Reload and enable the service:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>sudo systemctl daemon-reload
|
||||
sudo systemctl enable --now chronoseal</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Reverse Proxy & TLS Termination</h2>
|
||||
<p>Do not expose the raw ChronoSeal port directly to the internet. Always terminate TLS using Nginx, HAProxy, or a cloud load balancer. A sample Nginx setup is shown below:</p>
|
||||
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Nginx config</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>server {
|
||||
listen 443 ssl http2;
|
||||
server_name attestation.example.com;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_ciphers HIGH:!aNULL:!MD5;
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3000;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
}</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Storage & Horizontal Scaling</h2>
|
||||
|
||||
<h3>Single Node (SQLite)</h3>
|
||||
<p>Set <code>db_type = "sqlite-in-disk"</code> and configure a writeable path in <code>db_path</code>. Optimistic Compare-And-Swap (CAS) locking prevents concurrency errors, but high transaction loads may face write lock queuing.</p>
|
||||
|
||||
<h3>Multi-Node Scaling (Valkey / Redis)</h3>
|
||||
<p>For high availability, run multiple stateless <code>chronoseal</code> instances behind a load balancer and set <code>db_type = "valkey"</code>. Connect all nodes to the same shared Valkey/Redis instance using <code>CHRONOSEAL_VALKEY_ADDR</code>. This keeps sessions consistent across all server nodes.</p>
|
||||
|
||||
<h2>Monitoring & Observability</h2>
|
||||
<p>Configure Prometheus to scrape operational metrics from `/metrics`:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Prometheus config</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>scrape_configs:
|
||||
- job_name: 'chronoseal'
|
||||
static_configs:
|
||||
- targets: ['localhost:3000']</code></pre>
|
||||
</div>
|
||||
<p>Set alerts for these key metrics:</p>
|
||||
<ul>
|
||||
<li><code>chronoseal_sessions</code>: Spike suggests rate limit thresholds should be reviewed or a scraper campaign is initiating.</li>
|
||||
<li><code>chronoseal_max_chain_length</code>: Tracks session duration. Low values suggest clients are failing attestation.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Failure Diagnostic Guide</h2>
|
||||
<p>Because ChronoSeal returns a silent success response <code>{"status":"ok"}</code> on heartbeat rejections, check the following variables when debugging client integration issues:</p>
|
||||
|
||||
<h3>A. Clock Drift (<code>TimestampDrift</code>)</h3>
|
||||
<p><strong>Cause:</strong> Client machine clock differs from the server clock by more than 30 seconds (<code>max_timestamp_drift_ms</code>). Sync both clocks using NTP.</p>
|
||||
|
||||
<h3>B. Out-of-Sequence Replays (<code>ChainBroken</code>)</h3>
|
||||
<p><strong>Cause:</strong> Client submitted a <code>prev_hash</code> that does not match the server's <code>last_hash</code>. This occurs when network packet drops cause retries from outdated states, or if an attacker attempts replay. The client must restart liveness via <code>/init</code>.</p>
|
||||
|
||||
<h3>C. Signature Mismatch (<code>Signature</code>)</h3>
|
||||
<p><strong>Cause:</strong> The Ed25519 signature over the canonical JSON payload is invalid. Verify that the client orders JSON keys alphabetically (<code>entropyData</code>, <code>fingerprint</code>, <code>geneCommitment</code>, <code>mutationStep</code>, <code>prevHash</code>, <code>sessionId</code>, <code>stackState</code>, <code>timestamp</code>) and serializes types correctly.</p>
|
||||
|
||||
<h3>D. VM State Mismatch (<code>VmStackMismatch</code>)</h3>
|
||||
<p><strong>Cause:</strong> Client's VM <code>stack_state</code> differs from server re-execution results. Ensure the browser VM implementation wraps 32-bit math correctly matching <code>shared/src/vm.rs</code>.</p>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="performance.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Performance Tuning</div>
|
||||
</a>
|
||||
<a href="deployment.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Deployment Guide</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,300 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Performance Tuning Guide | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal Performance Tuning Guide, detailing mutation parameters, recommended setups, diagnostic metrics, and optimization profiles.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html" class="active">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item active">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Operations & Security</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Performance Tuning</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>Performance Tuning Guide</h1>
|
||||
<p class="doc-subtitle">ChronoSeal uses a deterministic Synthetic Gene Mutation Engine. This guide explains how to tune the mutation parameters to balance security, server throughput, and client mobile CPU limits.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Primary Tuning Parameters</h2>
|
||||
<p>Two configuration constants in the ChronoSeal daemon dictate the complexity of synthetic mutation progression:</p>
|
||||
<ul>
|
||||
<li><strong><code>gene_size</code>:</strong> The size of the synthetic gene byte buffer (configured from 1 to 4096 bytes). Larger values increase state vector complexity.</li>
|
||||
<li><strong><code>mutation_rounds</code>:</strong> The number of mutation iterations executed per heartbeat (configured from 1 to 10 rounds). Higher counts increase server and browser CPU operations.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Recommended Profiles</h2>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Profile</th>
|
||||
<th><code>gene_size</code></th>
|
||||
<th><code>mutation_rounds</code></th>
|
||||
<th>Security Strength</th>
|
||||
<th>Recommended Environment</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>Default</td>
|
||||
<td>512</td>
|
||||
<td>4</td>
|
||||
<td>Moderate</td>
|
||||
<td>Development and local testing</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><strong>Recommended</strong></td>
|
||||
<td><strong>2048</strong></td>
|
||||
<td><strong>4</strong></td>
|
||||
<td><strong>Strong</strong></td>
|
||||
<td><strong>Most production deployments</strong></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>High Security</td>
|
||||
<td>4096</td>
|
||||
<td>8</td>
|
||||
<td>Very Strong</td>
|
||||
<td>Sensitive financial or auth APIs</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Max Practical</td>
|
||||
<td>4096</td>
|
||||
<td>10</td>
|
||||
<td>Extremely Strong</td>
|
||||
<td>High-value targets under active abuse</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<div class="doc-alert doc-alert--note">
|
||||
<div class="doc-alert-icon">ℹ️</div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>v1.0.2 Protocol Limits:</strong> The validator enforces maximum bounds of <code>gene_size = 4096</code> and <code>mutation_rounds = 10</code>. Values exceeding these ranges are rejected during configuration verification.
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<h2>Monitoring Performance</h2>
|
||||
|
||||
<h3>1. Server-Side Observability</h3>
|
||||
<p>Check the effective parameters and database write latencies using the daemon CLI:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>chronoseal config check --format yaml
|
||||
chronoseal stats --format json</code></pre>
|
||||
</div>
|
||||
<p>Avoid running the daemon with <code>CHRONOSEAL_LOG=debug</code> in production, as debug logging session buffers degrades server throughput.</p>
|
||||
|
||||
<h3>2. Client-Side Time Measurement</h3>
|
||||
<p>Measure WASM execution time inside your browser console to verify mobile compatibility:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">JavaScript</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>console.time("gene-mutation");
|
||||
const commitment = preview_gene_commitment(
|
||||
order_b64,
|
||||
session_id,
|
||||
mutation_step,
|
||||
rounds
|
||||
);
|
||||
console.timeEnd("gene-mutation");</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Tuning Progression Strategy</h2>
|
||||
<p>When upgrading mutation strength in production, we recommend a step-by-step approach to monitor mobile battery impact:</p>
|
||||
<ol>
|
||||
<li>Start at our standard baseline: <code>gene_size = 2048</code>, <code>mutation_rounds = 4</code>.</li>
|
||||
<li>Deploy and monitor the heartbeat verification success metrics. Look for increases in client timeouts.</li>
|
||||
<li>Increase state size first (e.g. to <code>4096</code>) before raising the number of execution rounds.</li>
|
||||
<li>Perform testing on older Android/iOS mobile devices. Desktops are highly forgiving of high WASM execution loads; low-end mobile CPUs are not.</li>
|
||||
</ol>
|
||||
|
||||
<h2>Storage Backend Impact</h2>
|
||||
<p>The choice of storage backend has a significant impact on transaction throughput:</p>
|
||||
<ul>
|
||||
<li><strong><code>sqlite-in-memory</code>:</strong> Highest performance, zero write latency. Ideal for ephemeral deployments.</li>
|
||||
<li><strong><code>sqlite-in-disk</code>:</strong> Bounded by disk write capacity and database file locks.</li>
|
||||
<li><strong><code>valkey</code>:</strong> Scales horizontally across multiple stateless daemon instances connecting to a shared Redis/Valkey cluster.</li>
|
||||
</ul>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="threat-model.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Threat Model</div>
|
||||
</a>
|
||||
<a href="operations.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Operations Handbook</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,247 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Design Philosophy | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal design philosophy, engineering priorities, non-goals, and cost-raising anti-automation security biases.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html" class="active">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item active">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Core Concepts</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Design Philosophy</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Design Philosophy</h1>
|
||||
<p class="doc-subtitle">ChronoSeal is designed for operators who want a local, inspectable, Unix-native browser attestation layer rather than a hosted anti-bot black box.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Core Position</h2>
|
||||
<p>ChronoSeal is infrastructure software. It should feel closer to <code>nginx</code>, <code>redis-server</code>, or a small system daemon than to a third-party analytics platform.</p>
|
||||
<p>Our core design priorities include:</p>
|
||||
<ul>
|
||||
<li><strong>CLI-first operation:</strong> Simple commands for service validation and control.</li>
|
||||
<li><strong>Explicit configuration:</strong> Plain text parameters, clear priorities, and no hidden magic.</li>
|
||||
<li><strong>Deterministic protocol:</strong> Verifiable, cryptographic state progressions shared between browser WASM and server Rust.</li>
|
||||
<li><strong>Small runtime surface:</strong> Low footprint, lightweight execution boundaries.</li>
|
||||
<li><strong>Privacy-preserving:</strong> Short-lived sessions with zero long-term profiling or persistent databases.</li>
|
||||
<li><strong>Observable:</strong> Native health probes, JSON statistics, and Prometheus metrics.</li>
|
||||
<li><strong>Telemetry-free:</strong> Absolutely no hidden dashboards, tracking tags, or phone-home systems.</li>
|
||||
</ul>
|
||||
|
||||
<h2>What ChronoSeal Optimizes For</h2>
|
||||
|
||||
<h3>1. Operator Control</h3>
|
||||
<p>Operators should be able to build, run, inspect, configure, monitor, and stop the service with ordinary Unix tools. This is why ChronoSeal provides first-class integrations and commands like <code>chronoseal run</code>, <code>status</code>, <code>health</code>, and native systemd configurations.</p>
|
||||
|
||||
<h3>2. Determinism</h3>
|
||||
<p>The core protocol depends on strict mathematical agreement between server Rust and browser WASM. To guarantee this, all deterministic execution logic is kept in the <code>shared/</code> crate, including hash chains, synthetic gene models, and VM instructions. This eliminates client/server runtime drift.</p>
|
||||
|
||||
<h3>3. Cost Escalation</h3>
|
||||
<p>ChronoSeal does not claim impossible security. We recognize that any client code can eventually be decompiled or emulated. Instead, we focus on cost escalation—making automation expensive by forcing clients to maintain authentic signatures, stack execution history, mutation steps, and interaction signals. The objective is to make cheap automation brittle and expensive automation highly complex to maintain.</p>
|
||||
|
||||
<blockquote>
|
||||
<p><strong>Silent Rejection Semantics:</strong> Heartbeat rejection is intentionally ambiguous. Invalid requests receive the same basic response structure as accepted heartbeats but omit the necessary next-state tokens. This prevents the API from acting as an oracle to guide attackers.</p>
|
||||
</blockquote>
|
||||
|
||||
<h3>4. Privacy by Default</h3>
|
||||
<p>ChronoSeal is not a tracking or analytics engine. It avoids long-term identifiers, cross-site identity graphs, behavioral profiling, and fingerprint history. The database retains only the minimal, ephemeral session state required to validate continuous liveness.</p>
|
||||
|
||||
<h2>Non-Goals</h2>
|
||||
<p>ChronoSeal is explicitly <strong>not</strong>:</p>
|
||||
<ul>
|
||||
<li>A CAPTCHA replacement with interactive puzzles.</li>
|
||||
<li>A fraud scoring system utilizing machine learning risk weights.</li>
|
||||
<li>An authentication provider or OAuth server.</li>
|
||||
<li>A hosted SaaS product under vendor control.</li>
|
||||
<li>A complete defense against fully resourced, human-operated browser farms.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Engineering Biases</h2>
|
||||
<p>When the project faces design trade-offs, we adhere to the following biases:</p>
|
||||
<ul>
|
||||
<li>Prefer <strong>explicit configuration</strong> over implicit magic.</li>
|
||||
<li>Prefer <strong>server-side recomputation</strong> over trusting browser claims.</li>
|
||||
<li>Prefer <strong>bounded execution limits</strong> over unbounded heuristics.</li>
|
||||
<li>Prefer <strong>clear CLI output</strong> over hidden cloud dashboards.</li>
|
||||
<li>Prefer <strong>local self-hosting</strong> over mandatory third-party API dependencies.</li>
|
||||
<li>Prefer <strong>data minimization</strong> over policies and promises alone.</li>
|
||||
</ul>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="index.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Home Page</div>
|
||||
</a>
|
||||
<a href="architecture.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Architecture Overview</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,288 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Privacy Policy | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal privacy policy, ephemeral data parameters, storage options, and client-side key-generation boundaries.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html" class="active">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item active">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Operations & Security</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Privacy Policy</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Privacy Policy</h1>
|
||||
<p class="doc-subtitle">ChronoSeal is a privacy-oriented browser attestation system. It is designed to validate short-lived session continuity without creating persistent user profiles.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<p>This document describes what ChronoSeal itself collects and stores. Applications that integrate ChronoSeal may collect additional data under their own policies.</p>
|
||||
|
||||
<h2>Data ChronoSeal Processes</h2>
|
||||
<p>ChronoSeal processes only the minimum protocol parameters needed to validate a live browser session. We collect no personal data, identifiers, or tracking tokens.</p>
|
||||
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Data Parameter</th>
|
||||
<th>Core Purpose</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><code>session_id</code></td>
|
||||
<td>Opaque session lookup key. Generated randomly, unrelated to user identity.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Public Key</td>
|
||||
<td>Required to verify signed heartbeats for the specific session.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>salt</code></td>
|
||||
<td>Rotated material used for secure hash-chain progression.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>initial_hash</code> / <code>prev_hash</code></td>
|
||||
<td>Provides replay-resistant cryptographic continuity.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Timestamp</td>
|
||||
<td>Enforces drift bounds and liveness thresholds.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Mouse Event Samples</td>
|
||||
<td>Lightweight validation of input activity plausibility.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>VM Stack State</td>
|
||||
<td>Verifies correct execution of the randomized math program.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Fingerprint Fields</td>
|
||||
<td>Sanity validation (Screen aspect ratio, device pixel ratio, concurrency CPU count).</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Gene Commitment</td>
|
||||
<td>Verifies client execution of server-issued synthetic gene mutations.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Expiration Time</td>
|
||||
<td>Manages session lifecycle and garbage-collection checks.</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<h2>Data ChronoSeal Does Not Collect</h2>
|
||||
<p>ChronoSeal is built on the principle of data minimization. It does <strong>not</strong> collect, process, or build databases of:</p>
|
||||
<ul>
|
||||
<li>Personal information (names, emails, logins, accounts).</li>
|
||||
<li>Browser history or page navigation tracks.</li>
|
||||
<li>IP address history or device fingerprints across multiple sessions.</li>
|
||||
<li>Location history or geological coordinate lookups.</li>
|
||||
<li>Cross-site tracking identifiers or cookie graphs.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Session Lifetime & Expiration</h2>
|
||||
<p>Sessions are short-lived. By default, they expire after <strong>30 minutes</strong> (configurable via <code>expiration_minutes</code>). Expired sessions are continuously purged from memory and storage by background cleanup workers. If the daemon runs in-memory, all session history is immediately lost when the process exits.</p>
|
||||
|
||||
<h2>Storage Modes & Persistence</h2>
|
||||
<p>Storage is fully configured by the operator and supports the following modes:</p>
|
||||
<ul>
|
||||
<li><strong>sqlite-in-memory:</strong> Default mode. Process memory only, completely ephemeral.</li>
|
||||
<li><strong>sqlite-in-disk:</strong> Persisted to local SQLite file for recovery across restarts.</li>
|
||||
<li><strong>valkey:</strong> Distributed storage, persisted according to Valkey deployment settings.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Client-Side Cryptographic Key Custody</h2>
|
||||
<p>The browser WASM runtime generates an Ed25519 keypair locally when the session starts.</p>
|
||||
<ul>
|
||||
<li>The <strong>public key</strong> is transmitted to the server during the <code>/init</code> handshake.</li>
|
||||
<li>The <strong>private key</strong> is retained in browser WASM memory and is <strong>never transmitted</strong> over the network.</li>
|
||||
<li>Heartbeat payloads are signed locally in the browser before submission.</li>
|
||||
</ul>
|
||||
<p>This provides strong session continuity without creating long-term tracking identifiers.</p>
|
||||
|
||||
<div class="doc-alert doc-alert--note">
|
||||
<div class="doc-alert-icon"><i class="fas fa-info-circle"></i></div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>Silent Rejection:</strong> To minimize feedback for attackers, ChronoSeal returns identical success responses <code>{"status":"ok"}</code> for accepted and rejected heartbeat requests, omitting next-state fields on rejection.
|
||||
</div>
|
||||
</div>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="philosophy.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Design Philosophy</div>
|
||||
</a>
|
||||
<a href="security.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Security Policy</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,261 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Protocol Specification | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal cryptographic wire protocol specifications, state transition mechanics, VM instruction opcodes, and stability guidelines.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html" class="active">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item active">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Protocol & API</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Protocol Specification</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Protocol Specification</h1>
|
||||
<p class="doc-subtitle">This document defines the formal wire protocol, state transitions, cryptographic primitives, and execution invariants of the ChronoSeal attestation system.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Sequence Flow</h2>
|
||||
<p>ChronoSeal operates as a stateful, sequential challenge-response sequence over HTTP/REST between the client browser (WASM/JS) and the native server daemon:</p>
|
||||
|
||||
<!-- Inline Protocol Flow Container -->
|
||||
<div id="diagram-protocol" class="arch-diagram" style="margin-top:24px"></div>
|
||||
|
||||
<h2>Cryptographic Transitions</h2>
|
||||
|
||||
<h3>1. Handshake Phase (<code>/init</code>)</h3>
|
||||
<p>The client registers a 32-byte Ed25519 verifying key represented as a hex string. The server then performs the following steps:</p>
|
||||
<ol>
|
||||
<li>Generates a 32-byte session ID (<code>session_id</code>) and a 16-byte initial salt (<code>S_0</code>).</li>
|
||||
<li>Computes the initial hash chain head:<br>
|
||||
<code>H_0 = Blake3(session_id || public_key || S_0)</code>
|
||||
</li>
|
||||
<li>Generates a randomized VM program (between 8 and 16 bytes of opcodes).</li>
|
||||
<li>Creates the initial mutation order program <code>M_1</code>.</li>
|
||||
<li>Persists the initial session record.</li>
|
||||
</ol>
|
||||
|
||||
<h3>2. Heartbeat Progression (<code>/hb</code>)</h3>
|
||||
<p>For each heartbeat step <code>n >= 1</code>, the client submits:
|
||||
<code>prev_hash</code> (H_n-1), <code>timestamp</code>, <code>entropy_data</code>, <code>stack_state</code> (VM stack + instruction pointer), <code>gene_commitment</code>, and the <code>signature</code>.
|
||||
</p>
|
||||
<p>The server receives the request and executes these validations:</p>
|
||||
<ol>
|
||||
<li>Loads the session record from storage, enforcing an optimistic concurrency lock (CAS) to confirm that the database <code>last_hash</code> matches the request <code>prev_hash</code>.</li>
|
||||
<li>Validates the Ed25519 signature against the canonical alphabetical serialization.</li>
|
||||
<li>Re-executes the session's VM opcodes and asserts the client's VM <code>stack_state</code> matches the output.</li>
|
||||
<li>Applies the mutation order <code>M_n</code> to the stored gene buffer, computes the expected commitment:<br>
|
||||
<code>C_n = Blake3(CandidateGene || session_id || n)</code><br>
|
||||
Asserts the client's <code>gene_commitment</code> matches.
|
||||
</li>
|
||||
<li>Validates clock alignment: <code>|timestamp_server - timestamp_client| <= max_drift</code>.</li>
|
||||
<li>Advances the cryptographic hash chain head:<br>
|
||||
<code>H_n = Blake3(H_n-1 || timestamp || Blake3(entropy_data) || Blake3(S_n) || S_n-1)</code>
|
||||
</li>
|
||||
<li>Rotates the salt to <code>S_n</code> and compiles the next mutation program <code>M_n+1</code>.</li>
|
||||
</ol>
|
||||
|
||||
<h2>VM Instruction Specification</h2>
|
||||
<p>The browser VM executes opcodes sequentially on a 32-bit unsigned integer stack. The supported instruction set consists of:</p>
|
||||
<ul>
|
||||
<li><code>0x00</code>: Pushes the next 4 bytes in the opcode stream onto the stack as a <code>u32</code> (little-endian).</li>
|
||||
<li><code>0x01</code>: Wrapping Add (<code>a.wrapping_add(b)</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x02</code>: Wrapping Sub (<code>a.wrapping_sub(b)</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x03</code>: Wrapping Mul (<code>a.wrapping_mul(b)</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x04</code>: Bitwise XOR (<code>a ^ b</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x05</code>: Bitwise AND (<code>a & b</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x06</code>: Bitwise OR (<code>a | b</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x07</code>: Rotate Left (<code>a.rotate_left(b % 32)</code>). Requires at least 2 stack elements.</li>
|
||||
<li><code>0x08</code>: Unary Bitwise NOT (<code>!a</code>). Requires at least 1 stack element.</li>
|
||||
<li><code>0x09</code>: Hash Stack. Hashes all stack elements using BLAKE3 and reduces it to a single <code>u32</code> value, clearing the stack and pushing the result.</li>
|
||||
<li><em>Any other opcode:</em> Terminates VM execution immediately.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Protocol Stability Policy</h2>
|
||||
<p>The public surface of ChronoSeal is frozen at version 1.0. This includes:</p>
|
||||
<ul>
|
||||
<li><strong>Wire API:</strong> The JSON schemas and routes of <code>POST /init</code> and <code>POST /hb</code>.</li>
|
||||
<li><strong>State Transition:</strong> Hash chain folding, VM opcodes, and gene mutation mechanics.</li>
|
||||
<li><strong>CLI & Config:</strong> Daemon commands and TOML configuration keys.</li>
|
||||
</ul>
|
||||
<p>Internal details are subject to change without notice. Integrations must not depend on database schemas, Valkey key structures, or internal Rust SDK APIs.</p>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="architecture.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Architecture Overview</div>
|
||||
</a>
|
||||
<a href="api.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">API Reference</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
<script src="js/diagrams.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,6 @@
|
||||
# www.robotstxt.org/
|
||||
|
||||
User-agent: *
|
||||
Allow: /
|
||||
|
||||
Sitemap: https://chronoseal.dev/sitemap.xml
|
||||
@@ -0,0 +1,237 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Security Policy | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal security policy, reporting vulnerabilities, response workflow, and security boundaries.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html" class="active">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item active">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Operations & Security</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Security Policy</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>Security Policy</h1>
|
||||
<p class="doc-subtitle">This document outlines responsible disclosure practices, project security scopes, and hardening details for ChronoSeal.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Reporting Vulnerabilities</h2>
|
||||
<p>Please do not disclose security vulnerabilities publicly before coordinate disclosure. If you identify a potential security issue in ChronoSeal, contact the maintainers privately.</p>
|
||||
<p>When reporting, please include the following details to assist our review:</p>
|
||||
<ul>
|
||||
<li>Detailed description of the issue and potential impact.</li>
|
||||
<li>Step-by-step reproduction guide or proof-of-concept (PoC) script.</li>
|
||||
<li>Affected versions of the daemon, WASM package, or shared components.</li>
|
||||
<li>Any proposed mitigations or code patches.</li>
|
||||
</ul>
|
||||
|
||||
<div class="doc-alert doc-alert--warn">
|
||||
<div class="doc-alert-icon"><i class="fas fa-exclamation-triangle"></i></div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>Do not file public GitHub issues for security vulnerabilities.</strong> Email or message the project maintainers directly via security contacts defined in the project repository.
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<h2>Project Scope</h2>
|
||||
<p>ChronoSeal operates as a cost-raising security layer, specifically:</p>
|
||||
<ul>
|
||||
<li><strong>Anti-scraper middleware:</strong> Restricts low-resource, simple command-line scripts and scrapers.</li>
|
||||
<li><strong>Behavioral attestation layer:</strong> Asserts basic input sanity signals.</li>
|
||||
<li><strong>Cryptographic continuity verifier:</strong> Guarantees that heartbeats progress chronologically along a server-controlled path.</li>
|
||||
</ul>
|
||||
<p>We actively harden the following boundaries and welcome reports regarding:</p>
|
||||
<ul>
|
||||
<li>Bypassing the hash-chain sequence without having session secrets.</li>
|
||||
<li>Replaying previously accepted heartbeat requests.</li>
|
||||
<li>Causing server panics, database memory leaks, or execution exhaustion.</li>
|
||||
<li>Bypassing stateful synthetic gene mutations.</li>
|
||||
<li>Security response header bypasses or CSP evasion.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Hardened Security Features (v1.0.2)</h2>
|
||||
<p>The latest version includes the following security hardening implementations:</p>
|
||||
<ul>
|
||||
<li><strong>Sanitized Fingerprints:</strong> Strict validation of aspect ratio, DPR, and CPU concurrency limits to reject malformed inputs.</li>
|
||||
<li><strong>Stack-Depth Protection:</strong> Bounded stack limits (capped at 512) to prevent VM buffer overflows.</li>
|
||||
<li><strong>DashMap Rate Limiter:</strong> Hardened concurrent rate limiting to mitigate denial-of-service attempts.</li>
|
||||
<li><strong>Response Headers:</strong> Automatic inject of Content-Security-Policy (CSP), X-Frame-Options, and Referrer-Policy headers to secure browser pages.</li>
|
||||
</ul>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="privacy.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Privacy Policy</div>
|
||||
</a>
|
||||
<a href="comparison.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">ChronoSeal vs Others</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"name": "ChronoSeal",
|
||||
"short_name": "ChronoSeal",
|
||||
"description": "Unix-native cryptographic attestation daemon for browser session continuity",
|
||||
"start_url": "/index.html",
|
||||
"display": "standalone",
|
||||
"background_color": "#0d0f14",
|
||||
"theme_color": "#0a0c10",
|
||||
"orientation": "portrait-primary",
|
||||
"categories": ["developer", "security", "utilities"],
|
||||
"icons": [
|
||||
{
|
||||
"src": "/assets/logo.png",
|
||||
"sizes": "512x512",
|
||||
"type": "image/png",
|
||||
"purpose": "any maskable"
|
||||
},
|
||||
{
|
||||
"src": "/assets/logo.svg",
|
||||
"sizes": "any",
|
||||
"type": "image/svg+xml",
|
||||
"purpose": "any maskable"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,81 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/index.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>1.0</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/architecture.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.8</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/protocol.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.8</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/api.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.8</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/deployment.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.8</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/threat-model.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.8</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/performance.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/philosophy.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/privacy.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.6</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/security.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/operations.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/testing.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
<url>
|
||||
<loc>https://chronoseal.dev/comparison.html</loc>
|
||||
<lastmod>2026-06-05</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>0.7</priority>
|
||||
</url>
|
||||
</urlset>
|
||||
@@ -0,0 +1,99 @@
|
||||
/* ============================================================
|
||||
ChronoSeal Website — Service Worker (sw.js)
|
||||
Enables PWA offline capabilities and asset caching
|
||||
============================================================ */
|
||||
|
||||
var CACHE_NAME = 'chronoseal-cache-v1';
|
||||
var ASSETS = [
|
||||
'/',
|
||||
'/index.html',
|
||||
'/architecture.html',
|
||||
'/protocol.html',
|
||||
'/api.html',
|
||||
'/deployment.html',
|
||||
'/threat-model.html',
|
||||
'/performance.html',
|
||||
'/philosophy.html',
|
||||
'/privacy.html',
|
||||
'/security.html',
|
||||
'/operations.html',
|
||||
'/testing.html',
|
||||
'/comparison.html',
|
||||
'/css/chronoseal.css',
|
||||
'/css/docs.css',
|
||||
'/css/print.css',
|
||||
'/js/app.js',
|
||||
'/js/search.js',
|
||||
'/js/diagrams.js',
|
||||
'/js/pwa.js',
|
||||
'/assets/logo.svg',
|
||||
'/assets/logo.png',
|
||||
'/site.webmanifest',
|
||||
'/robots.txt'
|
||||
];
|
||||
|
||||
/* Install Event — Pre-cache critical assets */
|
||||
self.addEventListener('install', function (e) {
|
||||
e.waitUntil(
|
||||
caches.open(CACHE_NAME).then(function (cache) {
|
||||
return cache.addAll(ASSETS);
|
||||
}).then(function () {
|
||||
return self.skipWaiting();
|
||||
})
|
||||
);
|
||||
});
|
||||
|
||||
/* Activate Event — Clean up old caches */
|
||||
self.addEventListener('activate', function (e) {
|
||||
e.waitUntil(
|
||||
caches.keys().then(function (keys) {
|
||||
return Promise.all(
|
||||
keys.map(function (key) {
|
||||
if (key !== CACHE_NAME) {
|
||||
return caches.delete(key);
|
||||
}
|
||||
})
|
||||
);
|
||||
}).then(function () {
|
||||
return self.clients.claim();
|
||||
})
|
||||
);
|
||||
});
|
||||
|
||||
/* Fetch Event — Cache-first with Network Fallback */
|
||||
self.addEventListener('fetch', function (e) {
|
||||
// Only handle GET requests and local requests
|
||||
if (e.request.method !== 'GET') return;
|
||||
|
||||
var url = new URL(e.request.url);
|
||||
if (url.origin !== self.location.origin) return;
|
||||
|
||||
e.respondWith(
|
||||
caches.match(e.request).then(function (cachedResponse) {
|
||||
if (cachedResponse) {
|
||||
// Fetch fresh in background to update cache (stale-while-revalidate)
|
||||
fetch(e.request).then(function (networkResponse) {
|
||||
if (networkResponse.status === 200) {
|
||||
caches.open(CACHE_NAME).then(function (cache) {
|
||||
cache.put(e.request, networkResponse);
|
||||
});
|
||||
}
|
||||
}).catch(function() {
|
||||
/* Ignore background fetch errors (e.g. offline) */
|
||||
});
|
||||
return cachedResponse;
|
||||
}
|
||||
|
||||
return fetch(e.request).then(function (networkResponse) {
|
||||
if (!networkResponse || networkResponse.status !== 200 || networkResponse.type !== 'basic') {
|
||||
return networkResponse;
|
||||
}
|
||||
var responseToCache = networkResponse.clone();
|
||||
caches.open(CACHE_NAME).then(function (cache) {
|
||||
cache.put(e.request, responseToCache);
|
||||
});
|
||||
return networkResponse;
|
||||
});
|
||||
})
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,288 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Testing Strategy | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal testing strategy, detailing test categories, execution instructions, mock simulations, and release verification processes.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html" class="active">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item active">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Lifecycle & Dev</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Testing Strategy</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Testing Strategy</h1>
|
||||
<p class="doc-subtitle">ChronoSeal maintains a security-focused test suite designed to validate cryptographic correctness, client/server deterministic parity, and sandbox limits.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<p>As of <strong>v1.0.2</strong>, the project contains <strong>100 passing tests</strong> across the workspaces:</p>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Workspace Crate</th>
|
||||
<th>Test Count</th>
|
||||
<th>Validation Scope</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><code>chronoseal-server</code></td>
|
||||
<td>38</td>
|
||||
<td>API handlers, rate limiters, storage persistence, and fingerprint constraints</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>chronoseal-wasm</code></td>
|
||||
<td>24</td>
|
||||
<td>Key generation, signing, VM instruction runners, and state transitions</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>shared</code> (unit tests)</td>
|
||||
<td>36</td>
|
||||
<td>Blake3 folding, gene mutation opcodes, and program serializations</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><code>shared</code> (property tests)</td>
|
||||
<td>2</td>
|
||||
<td>Proptest input fuzzing to confirm panic-resistance invariants</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td style="font-weight: bold;">Total</td>
|
||||
<td style="font-weight: bold;">100</td>
|
||||
<td style="font-weight: bold;">Comprehensive Attestation Coverage</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<h2>Core Test Categories</h2>
|
||||
|
||||
<h3>1. Browser Fingerprint Hardening (v1.0.2)</h3>
|
||||
<p>Enforces strict limits on metadata values to protect the attestation pipeline from adversarial inputs. Tests assert limits like CPU count (<code>1..=256</code>), device pixel ratio, aspect ratio bounds, and the rejection of malformed or non-finite values (<code>NaN</code> and <code>Infinity</code>).</p>
|
||||
|
||||
<h3>2. Session Lifecycle & Replay Resistance</h3>
|
||||
<p>Verifies session establishing, expiration rules, and invalid key boundaries. Critical checks assert that repeating a successful heartbeat or tampering with the synthetic gene commitment leads to immediate rejection.</p>
|
||||
|
||||
<h3>3. Mathematical VM Engine Parity</h3>
|
||||
<p>Evaluates VM opcode parsing, stack underflow boundaries, and wrapping arithmetic calculations (XOR, AND, Rotate, Add, Sub, Mul). Tests run the VM state engine across both WebAssembly and server Rust environments to confirm absolute mathematical consensus.</p>
|
||||
|
||||
<h3>4. Synthetic Gene Mutation Parity</h3>
|
||||
<p>Validates state vector updates across seeded RNG sequences, table-driven inputs, and random program arrays to assert that the client and server gene buffers never drift.</p>
|
||||
|
||||
<h3>5. Property-Based Fuzzing</h3>
|
||||
<p>Leverages <code>proptest</code> to exercise the VM execution and gene serialization paths under billions of random input vectors, guaranteeing that the daemon never panics on malformed network payloads.</p>
|
||||
|
||||
<h2>Running the Test Suite</h2>
|
||||
<p>Run the entire workspace suite:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code>cargo test --workspace</code></pre>
|
||||
</div>
|
||||
|
||||
<p>Run crate-specific test sets:</p>
|
||||
<div class="code-block">
|
||||
<div class="code-header">
|
||||
<span class="code-lang">Shell</span>
|
||||
<button class="code-copy-btn">Copy</button>
|
||||
</div>
|
||||
<pre><code># Test server components only
|
||||
cargo test -p chronoseal-server
|
||||
|
||||
# Test fingerprint hardening suite only
|
||||
cargo test -p chronoseal-server fingerprint
|
||||
|
||||
# Test WASM modules only
|
||||
cargo test -p chronoseal-wasm
|
||||
|
||||
# Test shared libraries and property tests
|
||||
cargo test -p shared</code></pre>
|
||||
</div>
|
||||
|
||||
<h2>Release-Blocking Security Invariants</h2>
|
||||
<p>The following unit tests guard critical security boundaries. Any failure in these tests blocks release compilation:</p>
|
||||
<ul>
|
||||
<li><code>test_replay_attack_is_rejected</code>: Protects against session hijack.</li>
|
||||
<li><code>test_mutation_commitment_tamper_is_rejected</code>: Ensures gene commitment authenticity.</li>
|
||||
<li><code>test_vm_execute_never_panics</code>: Ensures VM robustness against invalid opcodes.</li>
|
||||
<li><code>rejects_invalid_aspect_ratios</code> / <code>rejects_invalid_hardware_concurrency</code>: Protects against fingerprint parser exploits.</li>
|
||||
</ul>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="deployment.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">Deployment Guide</div>
|
||||
</a>
|
||||
<a href="index.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Home Page</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,258 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
|
||||
<title>Threat Model & Security Assumptions | ChronoSeal Documentation</title>
|
||||
<meta name="description" content="ChronoSeal threat model, classification parameters, attacker categories, mitigations, and security boundaries.">
|
||||
<link rel="stylesheet" href="css/chronoseal.css">
|
||||
<link rel="stylesheet" href="css/docs.css">
|
||||
<link rel="stylesheet" href="css/print.css" media="print">
|
||||
<link rel="manifest" href="site.webmanifest">
|
||||
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
|
||||
|
||||
<!-- Font Awesome for Icons -->
|
||||
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
|
||||
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
|
||||
crossorigin="anonymous"
|
||||
referrerpolicy="no-referrer" />
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<!-- Floating Background Spheres -->
|
||||
<div class="bg-animation">
|
||||
<div class="gradient-sphere sphere-1"></div>
|
||||
<div class="gradient-sphere sphere-2"></div>
|
||||
<div class="gradient-sphere sphere-3"></div>
|
||||
</div>
|
||||
|
||||
<!-- Header / Navbar -->
|
||||
<nav class="navbar" id="navbar">
|
||||
<div class="nav-container">
|
||||
<a href="index.html" class="logo">
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
|
||||
<span>ChronoSeal</span>
|
||||
</a>
|
||||
<div class="nav-links" id="navLinks">
|
||||
<a href="philosophy.html">Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
<div class="nav-dropdown">
|
||||
<a href="#" class="nav-link">More <small>▼</small></a>
|
||||
<div class="nav-dropdown-menu">
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="deployment.html">Deployment Guide</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
<a href="testing.html">Testing Strategy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="threat-model.html" class="active">Threat Model</a>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
</div>
|
||||
</div>
|
||||
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
</button>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
|
||||
<i class="fab fa-github"></i> GitHub
|
||||
</a>
|
||||
</div>
|
||||
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
|
||||
<i class="fas fa-bars"></i>
|
||||
</button>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<!-- Doc Page Shell -->
|
||||
<div class="doc-page">
|
||||
<div class="doc-layout">
|
||||
|
||||
<!-- Sidebar -->
|
||||
<aside class="doc-sidebar">
|
||||
<button class="doc-sidebar-toggle">
|
||||
<i class="fas fa-bars"></i> Sidebar Menu
|
||||
</button>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Core Concepts</div>
|
||||
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
|
||||
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
|
||||
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Protocol & API</div>
|
||||
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
|
||||
<a href="api.html" class="doc-nav-item">API Reference</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Operations & Security</div>
|
||||
<a href="threat-model.html" class="doc-nav-item active">Threat Model</a>
|
||||
<a href="security.html" class="doc-nav-item">Security Policy</a>
|
||||
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
|
||||
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
|
||||
</div>
|
||||
<div class="doc-nav-group">
|
||||
<div class="doc-nav-label">Lifecycle & Dev</div>
|
||||
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
|
||||
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
|
||||
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
|
||||
</div>
|
||||
</aside>
|
||||
|
||||
<!-- Main Content Area -->
|
||||
<main class="doc-main">
|
||||
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
|
||||
<a href="index.html">Home</a>
|
||||
<span class="sep">/</span>
|
||||
<a href="#">Operations & Security</a>
|
||||
<span class="sep">/</span>
|
||||
<span>Threat Model</span>
|
||||
</nav>
|
||||
|
||||
<article class="doc-content">
|
||||
<h1>ChronoSeal Threat Model & Security Assumptions</h1>
|
||||
<p class="doc-subtitle">ChronoSeal is a cost-raising session attestation layer. It makes API scraping and session replay attacks expensive by requiring continuous, stateful execution.</p>
|
||||
|
||||
<hr>
|
||||
|
||||
<h2>Security Objectives</h2>
|
||||
<p>The system aims to achieve the following cryptographic and protocol protections:</p>
|
||||
<ul>
|
||||
<li>Reject replayed or out-of-order heartbeat payloads.</li>
|
||||
<li>Reject heartbeats that do not maintain the exact server-issued synthetic gene mutation sequence.</li>
|
||||
<li>Bind heartbeats to a browser-local Ed25519 session key.</li>
|
||||
<li>Ensure basic HTTP clients (without JS/WASM engines) cannot pass validation.</li>
|
||||
<li>Avoid detailed verification feedback via a silent failure model.</li>
|
||||
<li>Ensure user privacy by avoiding long-term profiling or cross-site tracking.</li>
|
||||
</ul>
|
||||
|
||||
<h2>Attacker Cost Model & Classification</h2>
|
||||
<p>We classify potential adversaries into four distinct capability tiers:</p>
|
||||
|
||||
<h3>Tier 1: Commodity HTTP Clients</h3>
|
||||
<p><strong>Examples:</strong> <code>curl</code> requests, Python <code>requests</code>, Go scrapers, or scripts without browser execution capabilities.</p>
|
||||
<p><strong>Status:</strong> <span class="check"><i class="fas fa-check-circle"></i> Fully Protected</span>. These clients cannot generate Ed25519 signatures, interpret the VM math challenges, or maintain the BLAKE3 hash-chain. They are rejected at the first check.</p>
|
||||
|
||||
<h3>Tier 2: Basic Headless Browsers</h3>
|
||||
<p><strong>Examples:</strong> Out-of-the-box Puppeteer, Playwright, or Selenium setups.</p>
|
||||
<p><strong>Status:</strong> <span class="times" style="color:var(--warning)"><i class="fas fa-exclamation-circle"></i> Partially Protected</span>. These engines can run JS and load the WASM runtime. However, the attacker must simulate plausible interaction paths, maintain state, and solve VM challenges. This imposes substantial CPU and memory overhead on the automation runner, rendering large-scale automated scraping expensive.</p>
|
||||
|
||||
<h3>Tier 3: Stealth Automation</h3>
|
||||
<p><strong>Examples:</strong> Patched browser binaries, custom Node.js scripts using mock variables, or WASM emulator state runners.</p>
|
||||
<p><strong>Status:</strong> <span class="times" style="color:var(--warning)"><i class="fas fa-exclamation-circle"></i> Partially Protected</span>. Attackers must implement the complete state progression model. The server-controlled Synthetic Gene Mutation Engine forces emulator scripts to execute matching dynamic programs. Silent rejection hides which validation failed, complicating debugging.</p>
|
||||
|
||||
<h3>Tier 4: Distributed Browser Farms</h3>
|
||||
<p><strong>Examples:</strong> Clusters of real browsers, custom input hardware simulators, or human-operated CAPTCHA solvers.</p>
|
||||
<p><strong>Status:</strong> <span class="times"><i class="fas fa-times-circle"></i> Unprotected</span>. ChronoSeal raises execution costs but cannot guarantee complete protection against real user machines. Additional application-level access gating is required.</p>
|
||||
|
||||
<h2>Attack Vectors & Mitigations</h2>
|
||||
|
||||
<h3>1. Replay Attacks</h3>
|
||||
<p><strong>Attack:</strong> Intercepting a successful client heartbeat and sending it again to keep a session alive.</p>
|
||||
<p><strong>Mitigation:</strong> The server checks if the request's <code>prev_hash</code> matches the stored <code>last_hash</code>. Since accepted heartbeats rotate the salt and advance the hash, a repeated payload is immediately discarded as stale. Step counts and timestamp drift bounds also block historical replays.</p>
|
||||
|
||||
<h3>2. Signature Forgery</h3>
|
||||
<p><strong>Attack:</strong> Generating heartbeats without possessing the session's private key.</p>
|
||||
<p><strong>Mitigation:</strong> All heartbeats are signed using the Ed25519 key generated locally in the WASM engine. The server validates the signature against the registered public key before processing.</p>
|
||||
|
||||
<h3>3. Mutation Spoofing</h3>
|
||||
<p><strong>Attack:</strong> Submitting fake gene commitments or bypassing mutation rounds.</p>
|
||||
<p><strong>Mitigation:</strong> The server keeps the authoring program of the pending mutation. It applies the program to a clone of the session's committed gene state and asserts that the client's submitted commitment matches, failing silently on divergence.</p>
|
||||
|
||||
<h3>4. Feedback Oracle Probing</h3>
|
||||
<p><strong>Attack:</strong> Eliciting detailed error reasons (e.g. "invalid signature", "limiter triggered") to reverse-engineer verification thresholds.</p>
|
||||
<p><strong>Mitigation:</strong> Heartbeat endpoints always return <code>200 OK</code> with a standard <code>status: ok</code> JSON shape on failure. Accepted responses are distinguished only by containing next-state keys (<code>next_salt</code>, etc.).</p>
|
||||
|
||||
<h2>Key Security Invariants</h2>
|
||||
<p>The system guarantees the following invariants to preserve attestation integrity:</p>
|
||||
<ul>
|
||||
<li><strong>Single Sequence:</strong> A session can have exactly one expected step at any time. Bifurcation is impossible.</li>
|
||||
<li><strong>VM Parity:</strong> Stack results must exactly match server re-execution of the VM opcodes.</li>
|
||||
<li><strong>Locking:</strong> Session changes use Compare-And-Swap (CAS) optimistic locking to prevent race conditions.</li>
|
||||
</ul>
|
||||
|
||||
<div class="doc-alert doc-alert--warn">
|
||||
<div class="doc-alert-icon">⚠️</div>
|
||||
<div class="doc-alert-body">
|
||||
<strong>v1.0.2 Hardening:</strong> We enforce strict CPU concurrency limits (1 to 256), DPR boundaries, aspect ratio validations, and an entropy event cap (max 500 events) to prevent server resource exhaustion attacks.
|
||||
</div>
|
||||
</div>
|
||||
</article>
|
||||
|
||||
<!-- Pager -->
|
||||
<nav class="doc-pager" aria-label="Doc navigation Pager">
|
||||
<a href="api.html" class="doc-pager-link">
|
||||
<div class="doc-pager-label">Previous</div>
|
||||
<div class="doc-pager-title">API Reference</div>
|
||||
</a>
|
||||
<a href="performance.html" class="doc-pager-link doc-pager-link--next">
|
||||
<div class="doc-pager-label">Next</div>
|
||||
<div class="doc-pager-title">Performance Tuning</div>
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="doc-meta">
|
||||
Last Updated: June 2026 (v1.0.2)
|
||||
</div>
|
||||
</main>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Footer -->
|
||||
<footer class="footer">
|
||||
<div class="footer-content">
|
||||
<div class="footer-section">
|
||||
<h4>
|
||||
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
|
||||
</h4>
|
||||
<p>Next-generation browser attestation daemon built for the modern web.</p>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Resources</h4>
|
||||
<a href="philosophy.html">Design Philosophy</a>
|
||||
<a href="architecture.html">Architecture</a>
|
||||
<a href="protocol.html">Protocol</a>
|
||||
<a href="api.html">API Reference</a>
|
||||
<a href="comparison.html">Comparison</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Community</h4>
|
||||
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
|
||||
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
|
||||
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
|
||||
</div>
|
||||
<div class="footer-section">
|
||||
<h4>Legal & Security</h4>
|
||||
<a href="security.html">Security Policy</a>
|
||||
<a href="privacy.html">Privacy Policy</a>
|
||||
<a href="performance.html">Performance Tuning</a>
|
||||
<a href="operations.html">Operations Guide</a>
|
||||
</div>
|
||||
</div>
|
||||
<div class="footer-bottom">
|
||||
<p>© 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<!-- Search Overlay -->
|
||||
<div class="search-overlay">
|
||||
<div class="search-box">
|
||||
<div class="search-input-wrap">
|
||||
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
|
||||
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
|
||||
<span class="search-kbd">/</span>
|
||||
</div>
|
||||
<div class="search-results"></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Back to top -->
|
||||
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
|
||||
|
||||
<!-- JS Scripts -->
|
||||
<script src="js/search.js"></script>
|
||||
<script src="js/app.js"></script>
|
||||
</body>
|
||||
</html>
|
||||