fix: correct 7 bugs found in security audit
Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
1 parent
3f779a5295
commit
b75d586b86
10 files changed
+103
-43
No files matched your search
+3
-3
@@ -1,5 +1,5 @@
|
||||
[package]
|
||||
name = "antibot-wasm"
|
||||
name = "chronoseal-wasm"
|
||||
version = "0.2.0"
|
||||
edition = "2021"
|
||||
|
||||
@@ -12,9 +12,9 @@ wasm-bindgen = "0.2"
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
serde_json = "1"
|
||||
ed25519-dalek = { version = "2", features = ["rand_core"] }
|
||||
rand = "0.8" # <-- add this
|
||||
rand = "0.8"
|
||||
blake3 = "1"
|
||||
getrandom = { version = "0.2", features = ["js"] }
|
||||
hex = "0.4"
|
||||
base64 = "0.22"
|
||||
serde-wasm-bindgen = "0.6"
|
||||
serde-wasm-bindgen = "0.6"
|
||||
Reference in new issue
Block a user