Commit Graph
23 Commits
Author SHA1 Message Date
thakares 2ac0afa691 Update copyright name in LICENSE-MIT file 2026-05-12 20:32:39 +05:30
thakares cbe12bcd49 Delete logo.png 2026-05-12 20:14:21 +05:30
thakares f21146e2f2 Add ChronoSeal logo to README 2026-05-12 20:05:59 +05:30
thakares 7972123887 Add ChronoSeal logo to README 2026-05-12 20:04:17 +05:30
thakares 630c451688 Refine ChronoSeal logo assets 2026-05-12 19:34:31 +05:30
thakares 8559e023be Refine ChronoSeal logo assets 2026-05-12 19:33:40 +05:30
thakares 75cb978fba Add ChronoSeal logo assets 2026-05-12 18:42:52 +05:30
thakares 8d318d5da4 Add Contributor Covenant Code of Conduct
Added Contributor Covenant Code of Conduct to promote a harassment-free community.
2026-05-10 14:16:19 +05:30
thakares d567655645 Update LICENSE 2026-05-09 18:35:56 +05:30
thakares 4fb4022188 fix: correct license link and remove residual LICENSE.md 2026-05-09 18:23:11 +05:30
thakares 256f12023e docs: add WASM_BUILD.md explaining pkg generation and frontend loading
Covers:
- What antibot_wasm.js is and why it is not in the repo
- How wasm-pack compiles wasm/src/ and what wasm/pkg/ contains
- Step-by-step build (rustup target, wasm-pack install, build, mv to frontend/pkg)
- How heartbeat.js loads and initialises the module via await init()
- MIME type requirements for serving .wasm files
- .gitignore rationale for wasm/pkg/ and frontend/pkg/
- Troubleshooting (missing target, wasm-opt, 404, empty string returns)
2026-05-09 18:17:53 +05:30
thakares 2840ddfc58 docs: comprehensive ARCHITECTURE, DEPLOYMENT, API, and THREAT_MODEL
ARCHITECTURE.md
- Full component map with ASCII diagram
- Complete session lifecycle (init + heartbeat + failure path)
- Cryptographic protocol spec (hash chain formula, canonical JSON)
- Stack machine instruction set table with stack effects
- Behavioral validation thresholds
- SQLite schema, threat model summary, module reference

DEPLOYMENT.md
- Build instructions (WASM + server + convenience script)
- native binary, systemd (with hardened sandbox notes), Docker
- nginx, Nginx Proxy Manager, and HAProxy reverse proxy configs
- Integration options (sidecar vs proxy-only)
- Full configuration table with all constants
- Observability (RUST_LOG levels), health check, security checklist

API.md
- Full /init and /hb request/response schemas with field tables
- Canonical signing payload specification
- Complete validation rules table (all 13 rejection conditions)
- Hash chain byte-level specification
- WASM exported function reference

THREAT_MODEL.md
- Four attacker profiles (script kiddie → sophisticated adversary)
- Eight attack vectors with mitigations (replay, forgery, hijack, DoS…)
- Explicit out-of-scope limitations
- Operational security notes (CORS, TLS, log level, SQLite)
2026-05-09 18:11:15 +05:30
thakares 4b27a342d1 docs: comprehensive ARCHITECTURE, DEPLOYMENT, API, and THREAT_MODEL
ARCHITECTURE.md
- Full component map with ASCII diagram
- Complete session lifecycle (init + heartbeat + failure path)
- Cryptographic protocol spec (hash chain formula, canonical JSON)
- Stack machine instruction set table with stack effects
- Behavioral validation thresholds
- SQLite schema, threat model summary, module reference

DEPLOYMENT.md
- Build instructions (WASM + server + convenience script)
- native binary, systemd (with hardened sandbox notes), Docker
- nginx, Nginx Proxy Manager, and HAProxy reverse proxy configs
- Integration options (sidecar vs proxy-only)
- Full configuration table with all constants
- Observability (RUST_LOG levels), health check, security checklist

API.md
- Full /init and /hb request/response schemas with field tables
- Canonical signing payload specification
- Complete validation rules table (all 13 rejection conditions)
- Hash chain byte-level specification
- WASM exported function reference

THREAT_MODEL.md
- Four attacker profiles (script kiddie → sophisticated adversary)
- Eight attack vectors with mitigations (replay, forgery, hijack, DoS…)
- Explicit out-of-scope limitations
- Operational security notes (CORS, TLS, log level, SQLite)
2026-05-09 18:04:13 +05:30
thakares 851d3b4876 Further refine architecture documentation 2026-05-08 15:24:49 +05:30
thakares ac57752ec2 Improve README presentation and project overview 2026-05-08 15:19:33 +05:30
thakares ebfbbf9901 Refine architecture docs and add project logo 2026-05-08 15:14:27 +05:30
thakares b866471825 fix: rename LICENSE.md to LICENSE so GitHub detects MIT correctly
GitHub license auto-detection requires a file named LICENSE containing
the full license text. LICENSE-MIT and LICENSE-APACHE remain for
dual-license reference.
2026-05-08 15:07:11 +05:30
thakares f95b3c0d4a license: switch from GPL-3.0 to MIT OR Apache-2.0 dual license
Companies integrating security tooling into proprietary stacks are
blocked by GPL copyleft. MIT/Apache-2.0 dual licensing matches the
convention used by the Rust ecosystem (tokio, axum, serde, etc.) and
removes all adoption friction for commercial users.

- Add LICENSE-MIT
- Add LICENSE-APACHE
- Update LICENSE.md to dual-license declaration
- Add [workspace.package] license field to Cargo.toml
2026-05-08 15:02:02 +05:30
thakares 7df32cd599 docs: rewrite README to reflect refactored codebase
Rust / build (push) Canceled after 0s
v0.2.0
2026-05-08 14:32:36 +05:30
thakares 68b181dad2 chore: update Cargo.lock and server/Cargo.toml after compilation 2026-05-08 14:28:36 +05:30
thakares b75d586b86 fix: correct 7 bugs found in security audit
Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
2026-05-08 14:27:41 +05:30
thakares 3f779a5295 Update LICENSE.md 2026-05-07 22:08:50 +05:30
thakares a66debdece Initial ChronoSeal release 2026-05-07 21:57:47 +05:30