From 2840ddfc58a314f649f9740ac10d533544b301d2 Mon Sep 17 00:00:00 2001 From: Sunil Thakares Date: Sat, 9 May 2026 18:11:15 +0530 Subject: [PATCH] docs: comprehensive ARCHITECTURE, DEPLOYMENT, API, and THREAT_MODEL MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ARCHITECTURE.md - Full component map with ASCII diagram - Complete session lifecycle (init + heartbeat + failure path) - Cryptographic protocol spec (hash chain formula, canonical JSON) - Stack machine instruction set table with stack effects - Behavioral validation thresholds - SQLite schema, threat model summary, module reference DEPLOYMENT.md - Build instructions (WASM + server + convenience script) - native binary, systemd (with hardened sandbox notes), Docker - nginx, Nginx Proxy Manager, and HAProxy reverse proxy configs - Integration options (sidecar vs proxy-only) - Full configuration table with all constants - Observability (RUST_LOG levels), health check, security checklist API.md - Full /init and /hb request/response schemas with field tables - Canonical signing payload specification - Complete validation rules table (all 13 rejection conditions) - Hash chain byte-level specification - WASM exported function reference THREAT_MODEL.md - Four attacker profiles (script kiddie → sophisticated adversary) - Eight attack vectors with mitigations (replay, forgery, hijack, DoS…) - Explicit out-of-scope limitations - Operational security notes (CORS, TLS, log level, SQLite) --- docs/ARCHITECTURE.md | 34 +++++++++++++++++----------------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/docs/ARCHITECTURE.md b/docs/ARCHITECTURE.md index 0b03ad2..d4e3a90 100644 --- a/docs/ARCHITECTURE.md +++ b/docs/ARCHITECTURE.md @@ -47,22 +47,22 @@ synchronisation burden alone makes scaled operation expensive. ┌─────────────────────────────────────────────────────────┐ │ Browser │ │ │ -│ ┌─────────────┐ ┌──────────────┐ ┌─────────────┐ │ -│ │ entropy.js │ │ heartbeat.js │ │ transport.js│ │ -│ │ │ │ │ │ │ │ -│ │ mousemove │──►│ orchestrates │──►│ fetch POST │ │ -│ │ event ring │ │ init + HB │ │ /init /hb │ │ -│ └─────────────┘ └──────┬───────┘ └─────────────┘ │ +│ ┌─────────────┐ ┌──────────────┐ ┌─────────────┐ │ +│ │ entropy.js │ │ heartbeat.js │ │ transport.js│ │ +│ │ │ │ │ │ │ │ +│ │ mousemove │──►│ orchestrates │──►│ fetch POST │ │ +│ │ event ring │ │ init + HB │ │ /init /hb │ │ +│ └─────────────┘ └──────┬───────┘ └─────────────┘ │ │ │ │ │ ┌──────▼───────────────────────┐ │ -│ │ WASM Module (antibot_wasm) │ │ -│ │ │ │ -│ │ crypto.rs vm.rs │ │ -│ │ ├ generate_keypair() │ │ -│ │ ├ sign_message() │ │ -│ │ ├ compute_next_hash() │ │ -│ │ └ run_program() │ │ -│ └───────────────────────────────┘ │ +│ │ WASM Module (antibot_wasm) │ │ +│ │ │ │ +│ │ crypto.rs vm.rs │ │ +│ │ ├ generate_keypair() │ │ +│ │ ├ sign_message() │ │ +│ │ ├ compute_next_hash() │ │ +│ │ └ run_program() │ │ +│ └──────────────────────────────┘ │ └─────────────────────────────────────────────────────────┘ │ HTTPS ┌─────────────────────────▼───────────────────────────────┐ @@ -71,7 +71,7 @@ synchronisation burden alone makes scaled operation expensive. │ routes/init.rs routes/heartbeat.rs │ │ │ │ │ │ └──────────┬───────────────┘ │ -│ ▼ │ +│ ▼ │ │ session.rs │ │ ├ create_session() │ │ └ verify_heartbeat() │ @@ -111,7 +111,7 @@ Client Server │ │ opcodes = generate_random_program(8..=16) │ │ INSERT INTO sessions … │ │ - │◄── { session_id, salt, opcodes_b64, │ + │◄── { session_id, salt, opcodes_b64, │ │ initial_hash, expires_at } ───────┤ │ │ │ prevHash = initial_hash │ @@ -138,7 +138,7 @@ Client Server │ sig = sign_message( │ │ JSON.stringify(signable, keys.sort))│ │ │ - ├─── { session_id, prev_hash, timestamp,│ + ├─── { session_id, prev_hash, timestamp, │ │ entropy_data, stack_state, │ │ fingerprint, signature } ────────►│ │ │ 1. Rate limit check