Compare commits
2
Commits
v1.0.2
...
a7cc533ed4
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a7cc533ed4 | ||
|
|
40877be160 |
No files matched your search
@@ -20,7 +20,7 @@
|
||||
<img src="https://img.shields.io/badge/rust-stable%20%E2%89%A5%201.87-orange.svg" alt="Rust stable >= 1.87">
|
||||
</a>
|
||||
<a href="https://github.com/thakares/chronoseal-rs/blob/main/docs/REFRACTORING-v0.6.0.md">
|
||||
<img src="https://img.shields.io/badge/version-v1.0.1-green.svg" alt="v0.6.0">
|
||||
<img src="https://img.shields.io/badge/version-v1.0.2-green.svg" alt="v1.0.2">
|
||||
</a>
|
||||
<img src="https://img.shields.io/badge/wasm-rust--compiled-blueviolet.svg" alt="WASM">
|
||||
</p>
|
||||
@@ -68,6 +68,13 @@ ChronoSeal is a cost-raising attestation layer. It is not a CAPTCHA replacement,
|
||||
- Runtime storage abstraction with `sqlite-in-memory`, `sqlite-in-disk`, and `valkey` modes.
|
||||
- CLI-first lifecycle, status, health, metrics, stats, config validation, key generation, and shell completions.
|
||||
- Privacy-oriented design based on ephemeral session state rather than long-term identity tracking.
|
||||
- Security response headers (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-Content-Type-Options).
|
||||
- Fingerprint validation with explicit bounds checking for aspect ratio, device pixel ratio, and hardware concurrency.
|
||||
- DashMap-based concurrent rate limiter internals.
|
||||
- Non-root Docker container execution.
|
||||
- VM stack-depth protection.
|
||||
- WASM and hashing panic-resistance safeguards.
|
||||
- Progressive Web App (PWA) assets including favicon and web manifest support.
|
||||
|
||||
## How It Works
|
||||
|
||||
@@ -280,6 +287,13 @@ bash scripts/build.sh
|
||||
docker compose up -d --build
|
||||
```
|
||||
|
||||
### Container Security
|
||||
|
||||
ChronoSeal containers run as a dedicated non-root user by default.
|
||||
|
||||
This reduces the impact of potential container compromise and follows container security best practices.
|
||||
|
||||
|
||||
## CLI Reference
|
||||
|
||||
Run:
|
||||
@@ -486,6 +500,18 @@ Rejected response:
|
||||
}
|
||||
```
|
||||
|
||||
#### Fingerprint Validation
|
||||
|
||||
ChronoSeal validates browser fingerprint inputs before processing.
|
||||
|
||||
| Field | Accepted Range |
|
||||
|---|---|
|
||||
| aspectRatio | finite positive value |
|
||||
| devicePixelRatio | > 0 |
|
||||
| hardwareConcurrency | 1..=256 |
|
||||
|
||||
Invalid values including NaN, Infinity, negative values, malformed numeric strings, and out-of-range CPU counts are rejected.
|
||||
|
||||
Detailed API semantics are documented in [docs/API.md](docs/API.md).
|
||||
|
||||
## Browser Integration
|
||||
@@ -630,6 +656,9 @@ It helps defend against:
|
||||
- session cloning using only a stolen `session_id`
|
||||
- simple scripted clients that do not run the WASM runtime
|
||||
- basic browser automation with weak interaction simulation
|
||||
- malformed browser fingerprint payloads
|
||||
- invalid numeric fingerprint values
|
||||
- protocol abuse through oversized fingerprint attributes
|
||||
|
||||
It does not claim to stop:
|
||||
|
||||
@@ -680,6 +709,20 @@ Build release artifacts:
|
||||
bash scripts/build.sh
|
||||
```
|
||||
|
||||
### Validation Tests
|
||||
|
||||
```bash
|
||||
cargo test -p chronoseal-server fingerprint
|
||||
cargo test -p chronoseal-server
|
||||
```
|
||||
|
||||
The fingerprint validation suite verifies:
|
||||
|
||||
- aspect ratio bounds
|
||||
- device pixel ratio bounds
|
||||
- hardware concurrency bounds
|
||||
- malformed numeric input handling
|
||||
|
||||
Generate shell completion:
|
||||
|
||||
```bash
|
||||
@@ -750,6 +793,36 @@ Print the effective config:
|
||||
chronoseal config check --format yaml
|
||||
```
|
||||
|
||||
|
||||
## What's New in v1.0.2
|
||||
|
||||
### Security Hardening
|
||||
|
||||
- Added security response headers.
|
||||
- Hardened browser fingerprint validation.
|
||||
- Improved WASM-side error handling.
|
||||
- Improved hashing safety.
|
||||
- Added VM stack-depth protection.
|
||||
|
||||
### Runtime Improvements
|
||||
|
||||
- Refactored rate limiter internals using DashMap.
|
||||
- Improved cleanup task efficiency.
|
||||
- Improved configuration validation.
|
||||
- Improved deployment hardening.
|
||||
|
||||
### Frontend Improvements
|
||||
|
||||
- Added favicon and web manifest assets.
|
||||
- Added CSP defense-in-depth support.
|
||||
- Reduced protocol-state logging in browser consoles.
|
||||
|
||||
### Quality
|
||||
|
||||
- 38/38 server tests passing.
|
||||
- Additional fingerprint validation test coverage.
|
||||
|
||||
|
||||
## Further Reading
|
||||
|
||||
- [Architecture](docs/ARCHITECTURE.md)
|
||||
|
||||
+32
-2
@@ -102,7 +102,7 @@ Important files:
|
||||
| `crypto.rs` | canonical signing payload and Ed25519 signature verification |
|
||||
| `storage.rs` | `DbPool`, SQLite, Valkey compatibility, session persistence, stats |
|
||||
| `trust.rs` | mouse entropy validation |
|
||||
| `fingerprint.rs` | browser signal validation |
|
||||
| `fingerprint.rs` | browser signal validation, bounds enforcement, and fingerprint sanity checks |
|
||||
| `ratelimit.rs` | per-session rate limiting |
|
||||
| `cleanup.rs` | expired session removal |
|
||||
|
||||
@@ -154,7 +154,7 @@ The daemon builds a single Axum application with:
|
||||
Shared runtime state is held in `AppState`:
|
||||
|
||||
- `db_pool`: storage backend handle
|
||||
- `rate_limiter`: process-local rate limiter
|
||||
- `rate_limiter`: process-local DashMap-backed concurrent rate limiter
|
||||
- `config`: runtime configuration snapshot behind an `RwLock`
|
||||
|
||||
Configuration is resolved in this order:
|
||||
@@ -291,6 +291,7 @@ The current validation order is:
|
||||
11. Enforce timestamp drift bounds.
|
||||
12. Validate mouse entropy.
|
||||
13. Validate browser fingerprint fields.
|
||||
13a. Validate fingerprint bounds and numeric sanity constraints.
|
||||
14. Compute the next hash-chain value.
|
||||
15. Generate the next mutation order.
|
||||
16. Generate the next salt.
|
||||
@@ -369,6 +370,14 @@ Current checks include:
|
||||
- timestamp drift bound
|
||||
- basic fingerprint field validation
|
||||
|
||||
Current validation includes:
|
||||
|
||||
- aspect ratio bounds enforcement
|
||||
- device pixel ratio validation
|
||||
- hardware concurrency validation (1..=256)
|
||||
- rejection of NaN and infinite numeric values
|
||||
- rejection of malformed numeric strings
|
||||
|
||||
The checks are intentionally bounded and configurable. They should be treated as one layer in the attestation pipeline, not as the primary security primitive.
|
||||
|
||||
## Storage Architecture
|
||||
@@ -406,6 +415,14 @@ The metrics endpoint reports storage-derived counters including:
|
||||
|
||||
The daemon uses structured tracing and can log to journald through normal systemd operation. Operators should avoid debug logging in production because internal identifiers may appear in logs.
|
||||
|
||||
ChronoSeal applies security response headers including:
|
||||
|
||||
- Content-Security-Policy
|
||||
- X-Frame-Options
|
||||
- X-Content-Type-Options
|
||||
- Referrer-Policy
|
||||
- Permissions-Policy
|
||||
|
||||
## Trust Boundaries
|
||||
|
||||
### Browser Boundary
|
||||
@@ -503,6 +520,7 @@ SQLite disk or Valkey storage
|
||||
Recommended deployment properties:
|
||||
|
||||
- run under systemd with a dedicated service user
|
||||
- container deployments run as a dedicated non-root user by default
|
||||
- bind to localhost behind a reverse proxy unless direct exposure is required
|
||||
- serve over HTTPS
|
||||
- keep debug logs disabled
|
||||
@@ -510,6 +528,18 @@ Recommended deployment properties:
|
||||
- use `sqlite-in-memory` for ephemeral local sessions
|
||||
- use `sqlite-in-disk` or `valkey` when sessions must survive process restarts
|
||||
|
||||
## Security Hardening (v1.0.2)
|
||||
|
||||
Recent hardening improvements include:
|
||||
|
||||
- fingerprint bounds validation
|
||||
- VM stack depth protection
|
||||
- panic-resistant hashing paths
|
||||
- panic-resistant WASM helpers
|
||||
- DashMap-backed concurrent rate limiting
|
||||
- security response headers
|
||||
- non-root container execution
|
||||
|
||||
## Limitations
|
||||
|
||||
ChronoSeal is not:
|
||||
|
||||
Reference in new issue
Block a user