b75d586b863f465265071a4a21633188df491147
Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
ChronoSeal
ChronoSeal is a high-security anti-automation and anti-AI-scraping framework built using Rust, WASM, cryptographic heartbeat ledgers, and behavioral attestation.
Features
- Rust + Axum backend
- WASM runtime verification
- Ed25519 signatures
- Blake3 hash-chain continuity
- Behavioral entropy collection
- Silent anti-bot mitigation
- Adaptive trust scoring
- Stateless HTTP verification
- GPLv3 licensed
Architecture
Browser
├── WASM VM
├── Heartbeat protocol
├── Cryptographic ledger
└── Behavioral attestation
Server
├── Session validation
├── Hash-chain verification
├── Trust scoring
└── Adaptive mitigation
Build
Backend
cargo run -p server --release
WASM
wasm-pack build wasm --target web --release
License
GPLv3
Description
Privacy-first browser attestation framework for anti-bot and anti-AI scraping. Stateless, cryptographic, and Unix-native. Uses Ed25519 heartbeat chains, WASM attestation, and behavioral continuity validation without tracking users, storing IPs, or collecting telemetry.
https://chronoseal.nx9.in/
4.4 MiB
0 Stars
1 Watchers
0 Forks
Languages
Rust
46.4%
HTML
39.7%
JavaScript
6.8%
CSS
6.5%
Shell
0.4%
Other
0.2%