From 0a9434be1bca3ecf7a296e182a1a839eb970d6d1 Mon Sep 17 00:00:00 2001 From: libroot Date: Wed, 6 Aug 2025 16:58:36 +0000 Subject: [PATCH] Initial commit. --- .gitignore | 1 + LICENSE.md | 130 +++++ README.md | 75 +++ client/README.md | 87 ++++ client/nojscap.c | 71 +++ client/nojscap.go | 66 +++ client/nojscap.js | 57 +++ client/nojscap.py | 52 ++ client/nojscap.rs | 65 +++ server/go-http/README.md | 5 + server/go-http/server.go | 175 +++++++ server/python-flask/README.md | 5 + server/python-flask/server.py | 136 +++++ server/ts-express/.gitignore | 1 + server/ts-express/README.md | 6 + server/ts-express/package-lock.json | 758 ++++++++++++++++++++++++++++ server/ts-express/package.json | 16 + server/ts-express/server.ts | 154 ++++++ 18 files changed, 1860 insertions(+) create mode 100644 .gitignore create mode 100644 LICENSE.md create mode 100644 README.md create mode 100644 client/README.md create mode 100644 client/nojscap.c create mode 100644 client/nojscap.go create mode 100644 client/nojscap.js create mode 100644 client/nojscap.py create mode 100644 client/nojscap.rs create mode 100644 server/go-http/README.md create mode 100644 server/go-http/server.go create mode 100644 server/python-flask/README.md create mode 100644 server/python-flask/server.py create mode 100644 server/ts-express/.gitignore create mode 100644 server/ts-express/README.md create mode 100644 server/ts-express/package-lock.json create mode 100644 server/ts-express/package.json create mode 100644 server/ts-express/server.ts diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..ee455fb --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +server/ts-express/node_modules/ diff --git a/LICENSE.md b/LICENSE.md new file mode 100644 index 0000000..1837892 --- /dev/null +++ b/LICENSE.md @@ -0,0 +1,130 @@ +**HIPPOCRATIC LICENSE** + +**Version 3.0, October 2021** + + + +**TERMS AND CONDITIONS** + +TERMS AND CONDITIONS FOR USE, COPY, MODIFICATION, PREPARATION OF DERIVATIVE WORK, REPRODUCTION, AND DISTRIBUTION: + +**[1.](#1) DEFINITIONS:** + +_This section defines certain terms used throughout this license agreement._ + +[1.1.](#1.1) “License” means the terms and conditions, as stated herein, for use, copy, modification, preparation of derivative work, reproduction, and distribution of Software (as defined below). + +[1.2.](#1.2) “Licensor” means the copyright and/or patent owner or entity authorized by the copyright and/or patent owner that is granting the License. + +[1.3.](#1.3) “Licensee” means the individual or entity exercising permissions granted by this License, including the use, copy, modification, preparation of derivative work, reproduction, and distribution of Software (as defined below). + +[1.4.](#1.4) “Software” means any copyrighted work, including but not limited to software code, authored by Licensor and made available under this License. + +[1.5.](#1.5) “Supply Chain” means the sequence of processes involved in the production and/or distribution of a commodity, good, or service offered by the Licensee. + +[1.6.](#1.6) “Supply Chain Impacted Party” or “Supply Chain Impacted Parties” means any person(s) directly impacted by any of Licensee’s Supply Chain, including the practices of all persons or entities within the Supply Chain prior to a good or service reaching the Licensee. + +[1.7.](#1.7) “Duty of Care” is defined by its use in tort law, delict law, and/or similar bodies of law closely related to tort and/or delict law, including without limitation, a requirement to act with the watchfulness, attention, caution, and prudence that a reasonable person in the same or similar circumstances would use towards any Supply Chain Impacted Party. + +[1.8.](#1.8) “Worker” is defined to include any and all permanent, temporary, and agency workers, as well as piece-rate, salaried, hourly paid, legal young (minors), part-time, night, and migrant workers. + +**[2.](#2) INTELLECTUAL PROPERTY GRANTS:** + +_This section identifies intellectual property rights granted to a Licensee_. + +[2.1.](#2.1) _Grant of Copyright License_: Subject to the terms and conditions of this License, Licensor hereby grants to Licensee a worldwide, non-exclusive, no-charge, royalty-free copyright license to use, copy, modify, prepare derivative work, reproduce, or distribute the Software, Licensor authored modified software, or other work derived from the Software. + +[2.2.](#2.2) _Grant of Patent License_: Subject to the terms and conditions of this License, Licensor hereby grants Licensee a worldwide, non-exclusive, no-charge, royalty-free patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer Software. + +**[3.](#3) ETHICAL STANDARDS:** + +_This section lists conditions the Licensee must comply with in order to have rights under this License._ + +The rights granted to the Licensee by this License are expressly made subject to the Licensee’s ongoing compliance with the following conditions: + +* [3.1.](#3.1) The Licensee SHALL NOT, whether directly or indirectly, through agents or assigns: + * [3.1.1.](#3.1.1) Infringe upon any person’s right to life or security of person, engage in extrajudicial killings, or commit murder, without lawful cause (See Article 3, _United Nations Universal Declaration of Human Rights_; Article 6, _International Covenant on Civil and Political Rights_) + * [3.1.2.](#3.1.2) Hold any person in slavery, servitude, or forced labor (See Article 4, _United Nations Universal Declaration of Human Rights_; Article 8, _International Covenant on Civil and Political Rights_); + * [3.1.3.](#3.1.3) Contribute to the institution of slavery, slave trading, forced labor, or unlawful child labor (See Article 4, _United Nations Universal Declaration of Human Rights_; Article 8, _International Covenant on Civil and Political Rights_); + * [3.1.4.](#3.1.4) Torture or subject any person to cruel, inhumane, or degrading treatment or punishment (See Article 5, _United Nations Universal Declaration of Human Rights_; Article 7, _International Covenant on Civil and Political Rights_); + * [3.1.5.](#3.1.5) Discriminate on the basis of sex, gender, sexual orientation, race, ethnicity, nationality, religion, caste, age, medical disability or impairment, and/or any other like circumstances (See Article 7, _United Nations Universal Declaration of Human Rights_; Article 2, _International Covenant on Economic, Social and Cultural Rights_; Article 26, _International Covenant on Civil and Political Rights_); + * [3.1.6.](#3.1.6) Prevent any person from exercising his/her/their right to seek an effective remedy by a competent court or national tribunal (including domestic judicial systems, international courts, arbitration bodies, and other adjudicating bodies) for actions violating the fundamental rights granted to him/her/them by applicable constitutions, applicable laws, or by this License (See Article 8, _United Nations Universal Declaration of Human Rights_; Articles 9 and 14, _International Covenant on Civil and Political Rights_); + * [3.1.7.](#3.1.7) Subject any person to arbitrary arrest, detention, or exile (See Article 9, _United Nations Universal Declaration of Human Rights_; Article 9, _International Covenant on Civil and Political Rights_); + * [3.1.8.](#3.1.8) Subject any person to arbitrary interference with a person’s privacy, family, home, or correspondence without the express written consent of the person (See Article 12, _United Nations Universal Declaration of Human Rights_; Article 17, _International Covenant on Civil and Political Rights_); + * [3.1.9.](#3.1.9) Arbitrarily deprive any person of his/her/their property (See Article 17, _United Nations Universal Declaration of Human Rights_); + * [3.1.10.](#3.1.10) Forcibly remove indigenous peoples from their lands or territories or take any action with the aim or effect of dispossessing indigenous peoples from their lands, territories, or resources, including without limitation the intellectual property or traditional knowledge of indigenous peoples, without the free, prior, and informed consent of indigenous peoples concerned (See Articles 8 and 10, _United Nations Declaration on the Rights of Indigenous Peoples_); + * [3.1.11.](#3.1.11) _Fossil Fuel Divestment_: Be an individual or entity, or a representative, agent, affiliate, successor, attorney, or assign of an individual or entity, on the [FFI Solutions Carbon Underground 200 list](https://www.ffisolutions.com/research-analytics-index-solutions/research-screening/the-carbon-underground-200/?cn-reloaded=1); + * [3.1.12.](#3.1.12) _Ecocide_: Commit ecocide: + * [3.1.12.1.](#3.1.12.1) For the purpose of this section, “ecocide” means unlawful or wanton acts committed with knowledge that there is a substantial likelihood of severe and either widespread or long-term damage to the environment being caused by those acts; + * [3.1.12.2.](#3.1.12.2) For the purpose of further defining ecocide and the terms contained in the previous paragraph: + * [3.1.12.2.1.](#3.1.12.2.1) “Wanton” means with reckless disregard for damage which would be clearly excessive in relation to the social and economic benefits anticipated; + * [3.1.12.2.2.](#3.1.12.2.2) “Severe” means damage which involves very serious adverse changes, disruption, or harm to any element of the environment, including grave impacts on human life or natural, cultural, or economic resources; + * [3.1.12.2.3.](#3.1.12.2.3) “Widespread” means damage which extends beyond a limited geographic area, crosses state boundaries, or is suffered by an entire ecosystem or species or a large number of human beings; + * [3.1.12.2.4.](#3.1.12.2.4) “Long-term” means damage which is irreversible or which cannot be redressed through natural recovery within a reasonable period of time; and + * [3.1.12.2.5.](#3.1.12.2.5) “Environment” means the earth, its biosphere, cryosphere, lithosphere, hydrosphere, and atmosphere, as well as outer space + (See Section II, _Independent Expert Panel for the Legal Definition of Ecocide_, Stop Ecocide Foundation and the Promise Institute for Human Rights at UCLA School of Law, June 2021); + * [3.1.13.](#3.1.13) _Boycott / Divestment / Sanctions_: Be an individual or entity, or a representative, agent, affiliate, successor, attorney, or assign of an individual or entity, identified by the Boycott, Divestment, Sanctions (“BDS”) movement on its website ( and ) as a target for boycott; + * [3.1.14.](#3.1.14) _Mass Surveillance_: Be a government agency or multinational corporation, or a representative, agent, affiliate, successor, attorney, or assign of a government or multinational corporation, which participates in mass surveillance programs; + * [3.1.15.](#3.1.15) _Military Activities_: Be an entity or a representative, agent, affiliate, successor, attorney, or assign of an entity which conducts military activities; + * [3.1.16.](#3.1.16) Interfere with Workers' free exercise of the right to organize and associate (See Article 20, United Nations Universal Declaration of Human Rights; C087 - Freedom of Association and Protection of the Right to Organise Convention, 1948 (No. 87), International Labour Organization; Article 8, International Covenant on Economic, Social and Cultural Rights); and + * [3.1.17.](#3.1.17) Harm the environment in a manner inconsistent with local, state, national, or international law. +* [3.2.](#3.2) The Licensee SHALL: + * [3.2.1.](#3.2.1) _Workers on Board of Directors_: Ensure that if the Licensee has a Board of Directors, 30% of Licensee’s board seats are held by Workers paid no more than 200% of the compensation of the lowest paid Worker of the Licensee; + * [3.2.2.](#3.2.2) Provide equal pay for equal work where the performance of such work requires equal skill, effort, and responsibility, and which are performed under similar working conditions, except where such payment is made pursuant to: + * [3.2.2.1.](#3.2.2.1) A seniority system; + * [3.2.2.2.](#3.2.2.2) A merit system; + * [3.2.2.3.](#3.2.2.3) A system which measures earnings by quantity or quality of production; or + * [3.2.2.4.](#3.2.2.4) A differential based on any other factor other than sex, gender, sexual orientation, race, ethnicity, nationality, religion, caste, age, medical disability or impairment, and/or any other like circumstances (See 29 U.S.C.A. § 206(d)(1); Article 23, _United Nations Universal Declaration of Human Rights_; Article 7, _International Covenant on Economic, Social and Cultural Rights_; Article 26, _International Covenant on Civil and Political Rights_); and + * [3.2.3.](#3.2.3) Allow for reasonable limitation of working hours and periodic holidays with pay (See Article 24, _United Nations Universal Declaration of Human Rights_; Article 7, _International Covenant on Economic, Social and Cultural Rights_). + +**[4.](#4) SUPPLY CHAIN IMPACTED PARTIES:** + +_This section identifies additional individuals or entities that a Licensee could harm as a result of violating the Ethical Standards section, the condition that the Licensee must voluntarily accept a Duty of Care for those individuals or entities, and the right to a private right of action that those individuals or entities possess as a result of violations of the Ethical Standards section._ + +[4.1.](#4.1) In addition to the above Ethical Standards, Licensee voluntarily accepts a Duty of Care for Supply Chain Impacted Parties of this License, including individuals and communities impacted by violations of the Ethical Standards. The Duty of Care is breached when a provision within the Ethical Standards section is violated by a Licensee, one of its successors or assigns, or by an individual or entity that exists within the Supply Chain prior to a good or service reaching the Licensee. + +[4.2.](#4.2) Breaches of the Duty of Care, as stated within this section, shall create a private right of action, allowing any Supply Chain Impacted Party harmed by the Licensee to take legal action against the Licensee in accordance with applicable negligence laws, whether they be in tort law, delict law, and/or similar bodies of law closely related to tort and/or delict law, regardless if Licensee is directly responsible for the harms suffered by a Supply Chain Impacted Party. Nothing in this section shall be interpreted to include acts committed by individuals outside of the scope of his/her/their employment. + +[5.](#5) **NOTICE:** _This section explains when a Licensee must notify others of the License._ + +[5.1.](#5.1) _Distribution of Notice_: Licensee must ensure that everyone who receives a copy of or uses any part of Software from Licensee, with or without changes, also receives the License and the copyright notice included with Software (and if included by the Licensor, patent, trademark, and attribution notice). Licensee must ensure that License is prominently displayed so that any individual or entity seeking to download, copy, use, or otherwise receive any part of Software from Licensee is notified of this License and its terms and conditions. Licensee must cause any modified versions of the Software to carry prominent notices stating that Licensee changed the Software. + +[5.2.](#5.2) _Modified Software_: Licensee is free to create modifications of the Software and distribute only the modified portion created by Licensee, however, any derivative work stemming from the Software or its code must be distributed pursuant to this License, including this Notice provision. + +[5.3.](#5.3) _Recipients as Licensees_: Any individual or entity that uses, copies, modifies, reproduces, distributes, or prepares derivative work based upon the Software, all or part of the Software’s code, or a derivative work developed by using the Software, including a portion of its code, is a Licensee as defined above and is subject to the terms and conditions of this License. + +**[6.](#6) REPRESENTATIONS AND WARRANTIES:** + +[6.1.](#6.1) _Disclaimer of Warranty_: TO THE FULL EXTENT ALLOWED BY LAW, THIS SOFTWARE COMES “AS IS,” WITHOUT ANY WARRANTY, EXPRESS OR IMPLIED, AND LICENSOR SHALL NOT BE LIABLE TO ANY PERSON OR ENTITY FOR ANY DAMAGES OR OTHER LIABILITY ARISING FROM, OUT OF, OR IN CONNECTION WITH THE SOFTWARE OR THIS LICENSE, UNDER ANY LEGAL CLAIM. + +[6.2.](#6.2) _Limitation of Liability_: LICENSEE SHALL HOLD LICENSOR HARMLESS AGAINST ANY AND ALL CLAIMS, DEBTS, DUES, LIABILITIES, LIENS, CAUSES OF ACTION, DEMANDS, OBLIGATIONS, DISPUTES, DAMAGES, LOSSES, EXPENSES, ATTORNEYS' FEES, COSTS, LIABILITIES, AND ALL OTHER CLAIMS OF EVERY KIND AND NATURE WHATSOEVER, WHETHER KNOWN OR UNKNOWN, ANTICIPATED OR UNANTICIPATED, FORESEEN OR UNFORESEEN, ACCRUED OR UNACCRUED, DISCLOSED OR UNDISCLOSED, ARISING OUT OF OR RELATING TO LICENSEE’S USE OF THE SOFTWARE. NOTHING IN THIS SECTION SHOULD BE INTERPRETED TO REQUIRE LICENSEE TO INDEMNIFY LICENSOR, NOR REQUIRE LICENSOR TO INDEMNIFY LICENSEE. + +**[7.](#7) TERMINATION** + +[7.1.](#7.1) _Violations of Ethical Standards or Breaching Duty of Care_: If Licensee violates the Ethical Standards section or Licensee, or any other person or entity within the Supply Chain prior to a good or service reaching the Licensee, breaches its Duty of Care to Supply Chain Impacted Parties, Licensee must remedy the violation or harm caused by Licensee within 30 days of being notified of the violation or harm. If Licensee fails to remedy the violation or harm within 30 days, all rights in the Software granted to Licensee by License will be null and void as between Licensor and Licensee. + +[7.2.](#7.2) _Failure of Notice_: If any person or entity notifies Licensee in writing that Licensee has not complied with the Notice section of this License, Licensee can keep this License by taking all practical steps to comply within 30 days after the notice of noncompliance. If Licensee does not do so, Licensee’s License (and all rights licensed hereunder) will end immediately. + +[7.3.](#7.3) _Judicial Findings_: In the event Licensee is found by a civil, criminal, administrative, or other court of competent jurisdiction, or some other adjudicating body with legal authority, to have committed actions which are in violation of the Ethical Standards or Supply Chain Impacted Party sections of this License, all rights granted to Licensee by this License will terminate immediately. + +[7.4.](#7.4) _Patent Litigation_: If Licensee institutes patent litigation against any entity (including a cross-claim or counterclaim in a suit) alleging that the Software, all or part of the Software’s code, or a derivative work developed using the Software, including a portion of its code, constitutes direct or contributory patent infringement, then any patent license, along with all other rights, granted to Licensee under this License will terminate as of the date such litigation is filed. + +[7.5.](#7.5) _Additional Remedies_: Termination of the License by failing to remedy harms in no way prevents Licensor or Supply Chain Impacted Party from seeking appropriate remedies at law or in equity. + +**[8.](#8) MISCELLANEOUS:** + +[8.1.](#8.1) _Conditions_: Sections 3, 4.1, 5.1, 5.2, 7.1, 7.2, 7.3, and 7.4 are conditions of the rights granted to Licensee in the License. + +[8.2.](#8.2) _Equitable Relief_: Licensor and any Supply Chain Impacted Party shall be entitled to equitable relief, including injunctive relief or specific performance of the terms hereof, in addition to any other remedy to which they are entitled at law or in equity. + +[8.3.](#8.3) _Severability_: If any term or provision of this License is determined to be invalid, illegal, or unenforceable by a court of competent jurisdiction, any such determination of invalidity, illegality, or unenforceability shall not affect any other term or provision of this License or invalidate or render unenforceable such term or provision in any other jurisdiction. If the determination of invalidity, illegality, or unenforceability by a court of competent jurisdiction pertains to the terms or provisions contained in the Ethical Standards section of this License, all rights in the Software granted to Licensee shall be deemed null and void as between Licensor and Licensee. + +[8.4.](#8.4) _Section Titles_: Section titles are solely written for organizational purposes and should not be used to interpret the language within each section. + +[8.5.](#8.5) _Citations_: Citations are solely written to provide context for the source of the provisions in the Ethical Standards. + +[8.6.](#8.6) _Section Summaries_: Some sections have a brief _italicized description_ which is provided for the sole purpose of briefly describing the section and should not be used to interpret the terms of the License. + +[8.7.](#8.7) _Entire License_: This is the entire License between the Licensor and Licensee with respect to the claims released herein and that the consideration stated herein is the only consideration or compensation to be paid or exchanged between them for this License. This License cannot be modified or amended except in a writing signed by Licensor and Licensee. + +[8.8.](#8.8) _Successors and Assigns_: This License shall be binding upon and inure to the benefit of the Licensor’s and Licensee’s respective heirs, successors, and assigns. \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..89a2b5f --- /dev/null +++ b/README.md @@ -0,0 +1,75 @@ +# NOJSCAP + +**NOJSCAP** is a minimal Proof-of-Work system. It includes both: + +- A **NOJSCAP client** that computes valid nonces for challenge strings using SHA-256. +- A **NOJSCAP server** that issue challenges and verify solutions over HTTP. + +This repository is structured as a monorepo containing both the client and server codebases. + +--- + +## Structure + +``` +. +├── client/ # Proof-of-Work nonce generator implementations +└── server/ # Server-side challenge issuers & verifiers +``` + +--- + +## Client + +The client directory includes NOJSCAP client implementations in multiple languages. Each version takes a challenge string and a difficulty level, then searches for a nonce such that the SHA-256 hash of `challenge + nonce` begins with the required number of leading zero bits. + +### Supported Languages + +- **C**: `nojscap.c` +- **Go**: `nojscap.go` +- **Python**: `nojscap.py` +- **JavaScript (Node.js)**: `nojscap.js` +- **Rust**: `nojscap.rs` + +Each implementation is self-contained and demonstrates equivalent functionality. + +--- + +## Server + +The `server` directory contains example implementations in multiple languages of NOJSCAP servers that issue PoW challenges and validate solutions. + +### Available Servers + +* **Python + Flask** + + +```sh +cd server/python-html +python3 server.py +``` + +* **TypeScript + Express** + + +```sh +cd server/ts-express +npm install +npx tsx start +``` + +* **Go + net/http** + + +```sh +cd server/go-http +go run server.go +``` + +Each server implementation listens for challenge requests and verifies submitted nonces against the configured difficulty level. + +--- + +## License + +TODO diff --git a/client/README.md b/client/README.md new file mode 100644 index 0000000..908d4e2 --- /dev/null +++ b/client/README.md @@ -0,0 +1,87 @@ +# NOJSCAP client + +The client directory includes NOJSCAP client implementations in multiple languages. Each version takes a challenge string and a difficulty level, then searches for a nonce such that the SHA-256 hash of `challenge + nonce` begins with the required number of leading zero bits. + +## Implementations + +- **C**: `nojscap.c` +- **Go**: `nojscap.go` +- **Python**: `nojscap.py` +- **JavaScript (Node.js)**: `nojscap.js` +- **Rust**: `nojscap.rs` + +Each implementation provides similar usage and functionality. + +--- + +## C Version + +### Compilation + +You need: + +- GCC or any C compiler +- OpenSSL development libraries (`libssl-dev` on Debian-based systems) + +```sh +gcc -O2 -o nojscap nojscap.c -lssl -lcrypto +``` + +### Usage + +```sh +./nojscap +``` + +- `challenge_string`: Any input string used as the challenge. +- `difficulty_bits`: Integer between 1 and 256. Higher values are more computationally expensive. + +### Example + +```sh +./nojscap libroot12 26 +Attempts: 0 +Attempts: 1048576 +Attempts: 2097152 +Attempts: 3145728 +Attempts: 4194304 +Attempts: 5242880 +Attempts: 6291456 +Found nonce: 6368109 +Hash: 0000000e724d990815e84e8a53f3f2410875046fe62a050de830d706b853ebe2 +``` + +--- + +## Python + +```sh +python3 nojscap.py +``` + +May require the `hashlib` module if using older Python verisons (standard in Python 3). + +## Go + +```sh +go run nojscap.go +``` + +Requires Go 1.13+. + +## JavaScript (Node.js) + +```sh +node nojscap.js +``` + +Uses the built-in `crypto` module. + +## Rust + +```sh +rustc nojscap.rs -o nojscap_rs +./nojscap_rs +``` + +Requires Rust and `sha2` crate if using the `Cargo` version. diff --git a/client/nojscap.c b/client/nojscap.c new file mode 100644 index 0000000..369234b --- /dev/null +++ b/client/nojscap.c @@ -0,0 +1,71 @@ +#include +#include +#include +#include + +int check_difficulty(const unsigned char *hash, int difficulty_bits) { + int bits = difficulty_bits; + int i = 0; + while (bits > 0) { + unsigned char byte = hash[i]; + if (bits >= 8) { + if (byte != 0) return 0; + bits -= 8; + } else { + unsigned char mask = 0xFF << (8 - bits); + if ((byte & mask) != 0) return 0; + bits = 0; + } + i++; + } + return 1; +} + +int main(int argc, char *argv[]) { + if (argc != 3) { + fprintf(stderr, "Usage: %s \n", argv[0]); + return 1; + } + + const char *challenge = argv[1]; + int difficulty_bits = atoi(argv[2]); + if (difficulty_bits <= 0 || difficulty_bits > 256) { + fprintf(stderr, "Difficulty bits must be between 1 and 256\n"); + return 1; + } + + unsigned char hash[SHA256_DIGEST_LENGTH]; + unsigned long long counter = 0; + + size_t challenge_len = strlen(challenge); + char *input = malloc(challenge_len + 32); + + if (!input) { + fprintf(stderr, "Memory allocation failed\n"); + return 1; + } + + while (1) { + sprintf(input, "%s%llu", challenge, counter); + SHA256((unsigned char *)input, strlen(input), hash); + + if (check_difficulty(hash, difficulty_bits)) { + printf("===================\n"); + printf("Found nonce: %llu\n", counter); + printf("===================\n"); + printf("Hash: "); + for (int i = 0; i < SHA256_DIGEST_LENGTH; i++) + printf("%02x", hash[i]); + printf("\n"); + break; + } + + if ((counter & 0xFFFFF) == 0) { + printf("Attempts: %llu\n", counter); + } + counter++; + } + + free(input); + return 0; +} diff --git a/client/nojscap.go b/client/nojscap.go new file mode 100644 index 0000000..55a4348 --- /dev/null +++ b/client/nojscap.go @@ -0,0 +1,66 @@ +package main + +import ( + "crypto/sha256" + "encoding/hex" + "fmt" + "os" + "strconv" +) + +func checkDifficulty(hash []byte, difficultyBits int) bool { + bits := difficultyBits + i := 0 + for bits > 0 { + b := hash[i] + if bits >= 8 { + if b != 0 { + return false + } + bits -= 8 + } else { + mask := byte(0xFF << (8 - bits)) + if (b & mask) != 0 { + return false + } + bits = 0 + } + i++ + } + return true +} + +func main() { + if len(os.Args) != 3 { + fmt.Fprintf(os.Stderr, "Usage: %s \n", os.Args[0]) + os.Exit(1) + } + + challenge := os.Args[1] + difficultyBits, err := strconv.Atoi(os.Args[2]) + if err != nil || difficultyBits <= 0 || difficultyBits > 256 { + fmt.Fprintln(os.Stderr, "Difficulty bits must be between 1 and 256") + os.Exit(1) + } + + var counter uint64 = 0 + + for { + input := fmt.Sprintf("%s%d", challenge, counter) + hash := sha256.Sum256([]byte(input)) + + if checkDifficulty(hash[:], difficultyBits) { + fmt.Printf("===================\n") + fmt.Printf("Found nonce: %d\n", counter) + fmt.Printf("===================\n") + fmt.Printf("Hash: %s\n", hex.EncodeToString(hash[:])) + break + } + + if counter&0xFFFFF == 0 { + fmt.Printf("Attempts: %d\n", counter) + } + + counter++ + } +} diff --git a/client/nojscap.js b/client/nojscap.js new file mode 100644 index 0000000..de97524 --- /dev/null +++ b/client/nojscap.js @@ -0,0 +1,57 @@ +const crypto = require('crypto'); + +function checkDifficulty(hashBuffer, difficultyBits) { + let bits = difficultyBits; + let i = 0; + while (bits > 0) { + const byte = hashBuffer[i]; + if (bits >= 8) { + if (byte !== 0) return false; + bits -= 8; + } else { + const mask = 0xFF << (8 - bits); + if ((byte & mask) !== 0) return false; + bits = 0; + } + i++; + } + return true; +} + +function main() { + if (process.argv.length !== 4) { + console.error(`Usage: node ${process.argv[1]} `); + process.exit(1); + } + + const challenge = process.argv[2]; + const difficultyBits = parseInt(process.argv[3], 10); + + if (isNaN(difficultyBits) || difficultyBits <= 0 || difficultyBits > 256) { + console.error('Difficulty bits must be a number between 1 and 256'); + process.exit(1); + } + + let counter = 0; + + while (true) { + const input = challenge + counter; + const hash = crypto.createHash('sha256').update(input).digest(); + + if (checkDifficulty(hash, difficultyBits)) { + console.log('==================='); + console.log(`Found nonce: ${counter}`); + console.log('==================='); + console.log(`Hash: ${hash.toString('hex')}`); + break; + } + + if ((counter & 0xFFFFF) === 0) { + console.log(`Attempts: ${counter}`); + } + + counter++; + } +} + +main(); diff --git a/client/nojscap.py b/client/nojscap.py new file mode 100644 index 0000000..2dbb80c --- /dev/null +++ b/client/nojscap.py @@ -0,0 +1,52 @@ +import hashlib +import sys + +def check_difficulty(hash_bytes: bytes, difficulty_bits: int) -> bool: + bits = difficulty_bits + i = 0 + while bits > 0: + byte = hash_bytes[i] + if bits >= 8: + if byte != 0: + return False + bits -= 8 + else: + mask = 0xFF << (8 - bits) & 0xFF + if (byte & mask) != 0: + return False + bits = 0 + i += 1 + return True + +def main(): + if len(sys.argv) != 3: + print(f"Usage: {sys.argv[0]} ") + sys.exit(1) + + challenge = sys.argv[1] + try: + difficulty_bits = int(sys.argv[2]) + except ValueError: + print("Difficulty must be a number") + sys.exit(1) + + if difficulty_bits <= 0 or difficulty_bits > 256: + print("Difficulty bits must be between 1 and 256") + sys.exit(1) + + counter = 0 + while True: + input_str = f"{challenge}{counter}" + hash_bytes = hashlib.sha256(input_str.encode()).digest() + if check_difficulty(hash_bytes, difficulty_bits): + print("====================") + print(f"Found nonce: {counter}") + print("====================") + print(f"Hash: {hash_bytes.hex()}") + break + if counter & 0xFFFFF == 0: + print(f"Attempts: {counter}") + counter += 1 + +if __name__ == "__main__": + main() diff --git a/client/nojscap.rs b/client/nojscap.rs new file mode 100644 index 0000000..6175b0f --- /dev/null +++ b/client/nojscap.rs @@ -0,0 +1,65 @@ +use sha2::{Digest, Sha256}; +use std::env; +use std::process; + +fn check_difficulty(hash: &[u8], difficulty_bits: u32) -> bool { + let mut bits = difficulty_bits; + let mut i = 0; + + while bits > 0 { + let byte = hash[i]; + if bits >= 8 { + if byte != 0 { + return false; + } + bits -= 8; + } else { + let mask = 0xFF << (8 - bits); + if (byte & mask) != 0 { + return false; + } + bits = 0; + } + i += 1; + } + true +} + +fn main() { + let args: Vec = env::args().collect(); + + if args.len() != 3 { + eprintln!("Usage: {} ", args[0]); + process::exit(1); + } + + let challenge = &args[1]; + let difficulty_bits: u32 = match args[2].parse() { + Ok(num) if num > 0 && num <= 256 => num, + _ => { + eprintln!("Difficulty bits must be between 1 and 256"); + process::exit(1); + } + }; + + let mut counter: u64 = 0; + + loop { + let input = format!("{}{}", challenge, counter); + let hash = Sha256::digest(input.as_bytes()); + + if check_difficulty(&hash, difficulty_bits) { + println!("==================="); + println!("Found nonce: {}", counter); + println!("==================="); + println!("Hash: {:x}", hash); + break; + } + + if counter & 0xFFFFF == 0 { + println!("Attempts: {}", counter); + } + + counter += 1; + } +} diff --git a/server/go-http/README.md b/server/go-http/README.md new file mode 100644 index 0000000..5001fea --- /dev/null +++ b/server/go-http/README.md @@ -0,0 +1,5 @@ +NOJSCAP Go server example with net/http + html/template. + +# Running + +go run server.go diff --git a/server/go-http/server.go b/server/go-http/server.go new file mode 100644 index 0000000..ea39af5 --- /dev/null +++ b/server/go-http/server.go @@ -0,0 +1,175 @@ +package main + +import ( + "crypto/rand" + "crypto/sha256" + "encoding/hex" + "fmt" + "html/template" + "log" + "net/http" + "strconv" + "sync" + "time" +) + +const ( + port = 3000 + difficulty = 20 +) + +var ( + challengeStore = make(map[string]time.Time) + storeMutex sync.Mutex +) + +func generateChallenge() string { + b := make([]byte, 12) + _, err := rand.Read(b) + if err != nil { + panic(err) + } + return hex.EncodeToString(b) +} + +func checkDifficulty(hash []byte, bits int) bool { + i := 0 + for bits > 0 { + b := hash[i] + if bits >= 8 { + if b != 0 { + return false + } + bits -= 8 + } else { + mask := byte(0xFF << (8 - bits)) + if b&mask != 0 { + return false + } + bits = 0 + } + i++ + } + return true +} + +func indexHandler(w http.ResponseWriter, r *http.Request) { + challenge := generateChallenge() + + storeMutex.Lock() + challengeStore[challenge] = time.Now() + storeMutex.Unlock() + + tmpl.Execute(w, map[string]string{ + "Challenge": challenge, + "Difficulty": strconv.Itoa(difficulty), + }) +} + +func postHandler(w http.ResponseWriter, r *http.Request) { + challenge := r.FormValue("challenge") + nonce := r.FormValue("nonce") + + storeMutex.Lock() + _, ok := challengeStore[challenge] + if ok { + delete(challengeStore, challenge) + } + storeMutex.Unlock() + + if !ok { + fmt.Fprint(w, "

Invalid challenge.

Try again") + return + } + + hash := sha256.Sum256([]byte(challenge + nonce)) + if checkDifficulty(hash[:], difficulty) { + fmt.Fprint(w, "

Success! Valid nonce.

Try again") + } else { + fmt.Fprint(w, "

Invalid nonce.

Try again") + } +} + +var tmpl = template.Must(template.New("page").Parse(` + + + + NOJSCAP demo + + + + + +

NOJSCAP demo

+

https://git.libroot.org/libroot/NOJSCAP/

+

If you don't already have the NOJSCAP client:

+ $ git clone https://git.libroot.org/libroot/NOJSCAP/$ cd NOJSCAP/client/ +

$ python3 pow_client.py {{.Challenge}} {{.Difficulty}}

+

Go:

+

$ go run pow_client.go {{.Challenge}} {{.Difficulty}}

+

Node.js:

+

$ node pow_client.js {{.Challenge}} {{.Difficulty}}

+

Rust:

+

$ rustc pow_client.rs -o pow_client_rs$ pow_client_rs {{.Challenge}} {{.Difficulty}}

+

C:

+

$ gcc -O2 -o pow_client pow_client.c -lssl -lcrypto$ ./pow_client {{.Challenge}} {{.Difficulty}}

+
+ + + +
+ + +`)) + +func main() { + http.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) { + if r.Method == http.MethodPost { + postHandler(w, r) + } else { + indexHandler(w, r) + } + }) + fmt.Printf("Running on http://localhost:%d\n", port) + log.Fatal(http.ListenAndServe(fmt.Sprintf(":%d", port), nil)) +} + diff --git a/server/python-flask/README.md b/server/python-flask/README.md new file mode 100644 index 0000000..bd8ca1b --- /dev/null +++ b/server/python-flask/README.md @@ -0,0 +1,5 @@ +NOJSCAP Python server example with Flask. + +# Running + +python3 server.py diff --git a/server/python-flask/server.py b/server/python-flask/server.py new file mode 100644 index 0000000..3b5c4b9 --- /dev/null +++ b/server/python-flask/server.py @@ -0,0 +1,136 @@ +from flask import Flask, request +import hashlib, os, time + +app = Flask(__name__) +DIFFICULTY = 20 +challenge_store = {} + +def generate_challenge(): + return os.urandom(12).hex() + +def check_difficulty(hash_bytes, bits): + i = 0 + while bits > 0: + byte = hash_bytes[i] + if bits >= 8: + if byte != 0: return False + bits -= 8 + else: + if byte & (0xFF << (8 - bits)) != 0: return False + bits = 0 + i += 1 + return True + +@app.route('/', methods=['GET']) +def index(): + challenge = generate_challenge() + challenge_store[challenge] = time.time() + return f''' + + + + NOJSCAP demo + + + + + +

NOJSCAP demo

+

https://git.libroot.org/libroot/NOJSCAP/


+

If you don't already have the NOJSCAP client:

+ $ git clone https://git.libroot.org/libroot/NOJSCAP/ +$ cd NOJSCAP/client/ +


+

+ $ python3 pow_client.py {challenge} {DIFFICULTY} +

+

+ Go: +

+

+ $ go run pow_client.go {challenge} {DIFFICULTY} +

+

+ Node.js: +

+

+ $ node pow_client.js {challenge} {DIFFICULTY} +

+

+ Rust: +

+

+$ rustc pow_client.rs -o pow_client_rs +$ pow_client_rs {challenge} {DIFFICULTY} + + Requires Rust and sha2 crate if using the Cargo version. +

+

+ C: +

+

+$ gcc -O2 -o pow_client pow_client.c -lssl -lcrypto +$ ./pow_client {challenge} {DIFFICULTY} + + Required: GCC or any C compiler. OpenSSL development libraries (libssl-dev on Debian-based systems) +

+
+ + + +
+ + + ''' + +@app.route('/', methods=['POST']) +def submit(): + challenge = request.form.get("challenge") + nonce = request.form.get("nonce") + if challenge not in challenge_store: return "Invalid challenge" + challenge_store.pop(challenge) + combined = (challenge + nonce).encode() + h = hashlib.sha256(combined).digest() + return "

Success! Valid nonce.

Try again" if check_difficulty(h, DIFFICULTY) else "

Invalid nonce.

Try again" + +app.run(port=3000) + diff --git a/server/ts-express/.gitignore b/server/ts-express/.gitignore new file mode 100644 index 0000000..c2658d7 --- /dev/null +++ b/server/ts-express/.gitignore @@ -0,0 +1 @@ +node_modules/ diff --git a/server/ts-express/README.md b/server/ts-express/README.md new file mode 100644 index 0000000..0d83b66 --- /dev/null +++ b/server/ts-express/README.md @@ -0,0 +1,6 @@ +NOJSCAP TypeScript server example with Express. + +# Running + +npm install +npx tsx server.ts diff --git a/server/ts-express/package-lock.json b/server/ts-express/package-lock.json new file mode 100644 index 0000000..07c3d28 --- /dev/null +++ b/server/ts-express/package-lock.json @@ -0,0 +1,758 @@ +{ + "name": "NOJSCAP server", + "version": "1.0.0", + "lockfileVersion": 3, + "requires": true, + "packages": { + "": { + "name": "NOJSCAP server", + "version": "1.0.0", + "license": "ISC", + "dependencies": { + "express": "^5.1.0" + } + }, + "node_modules/accepts": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/accepts/-/accepts-2.0.0.tgz", + "integrity": "sha512-5cvg6CtKwfgdmVqY1WIiXKc3Q1bkRqGLi+2W/6ao+6Y7gu/RCwRuAhGEzh5B4KlszSuTLgZYuqFqo5bImjNKng==", + "dependencies": { + "mime-types": "^3.0.0", + "negotiator": "^1.0.0" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/body-parser": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.2.0.tgz", + "integrity": "sha512-02qvAaxv8tp7fBa/mw1ga98OGm+eCbqzJOKoRt70sLmfEEi+jyBYVTDGfCL/k06/4EMk/z01gCe7HoCH/f2LTg==", + "dependencies": { + "bytes": "^3.1.2", + "content-type": "^1.0.5", + "debug": "^4.4.0", + "http-errors": "^2.0.0", + "iconv-lite": "^0.6.3", + "on-finished": "^2.4.1", + "qs": "^6.14.0", + "raw-body": "^3.0.0", + "type-is": "^2.0.0" + }, + "engines": { + "node": ">=18" + } + }, + "node_modules/bytes": { + "version": "3.1.2", + "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz", + "integrity": "sha512-/Nf7TyzTx6S3yRJObOAV7956r8cr2+Oj8AC5dt8wSP3BQAoeX58NoHyCU8P8zGkNXStjTSi6fzO6F0pBdcYbEg==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/call-bind-apply-helpers": { + "version": "1.0.2", + "resolved": "https://registry.npmjs.org/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz", + "integrity": "sha512-Sp1ablJ0ivDkSzjcaJdxEunN5/XvksFJ2sMBFfq6x0ryhQV/2b/KwFe21cMpmHtPOSij8K99/wSfoEuTObmuMQ==", + "dependencies": { + "es-errors": "^1.3.0", + "function-bind": "^1.1.2" + }, + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/call-bound": { + "version": "1.0.4", + "resolved": "https://registry.npmjs.org/call-bound/-/call-bound-1.0.4.tgz", + "integrity": "sha512-+ys997U96po4Kx/ABpBCqhA9EuxJaQWDQg7295H4hBphv3IZg0boBKuwYpt4YXp6MZ5AmZQnU/tyMTlRpaSejg==", + "dependencies": { + "call-bind-apply-helpers": "^1.0.2", + "get-intrinsic": "^1.3.0" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/content-disposition": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-1.0.0.tgz", + "integrity": "sha512-Au9nRL8VNUut/XSzbQA38+M78dzP4D+eqg3gfJHMIHHYa3bg067xj1KxMUWj+VULbiZMowKngFFbKczUrNJ1mg==", + "dependencies": { + "safe-buffer": "5.2.1" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/content-type": { + "version": "1.0.5", + "resolved": "https://registry.npmjs.org/content-type/-/content-type-1.0.5.tgz", + "integrity": "sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/cookie": { + "version": "0.7.2", + "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.7.2.tgz", + "integrity": "sha512-yki5XnKuf750l50uGTllt6kKILY4nQ1eNIQatoXEByZ5dWgnKqbnqmTrBE5B4N7lrMJKQ2ytWMiTO2o0v6Ew/w==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/cookie-signature": { + "version": "1.2.2", + "resolved": "https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.2.2.tgz", + "integrity": "sha512-D76uU73ulSXrD1UXF4KE2TMxVVwhsnCgfAyTg9k8P6KGZjlXKrOLe4dJQKI3Bxi5wjesZoFXJWElNWBjPZMbhg==", + "engines": { + "node": ">=6.6.0" + } + }, + "node_modules/debug": { + "version": "4.4.1", + "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.1.tgz", + "integrity": "sha512-KcKCqiftBJcZr++7ykoDIEwSa3XWowTfNPo92BYxjXiyYEVrUQh2aLyhxBCwww+heortUFxEJYcRzosstTEBYQ==", + "dependencies": { + "ms": "^2.1.3" + }, + "engines": { + "node": ">=6.0" + }, + "peerDependenciesMeta": { + "supports-color": { + "optional": true + } + } + }, + "node_modules/depd": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/depd/-/depd-2.0.0.tgz", + "integrity": "sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/dunder-proto": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/dunder-proto/-/dunder-proto-1.0.1.tgz", + "integrity": "sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==", + "dependencies": { + "call-bind-apply-helpers": "^1.0.1", + "es-errors": "^1.3.0", + "gopd": "^1.2.0" + }, + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/ee-first": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz", + "integrity": "sha512-WMwm9LhRUo+WUaRN+vRuETqG89IgZphVSNkdFgeb6sS/E4OrDIN7t48CAewSHXc6C8lefD8KKfr5vY61brQlow==" + }, + "node_modules/encodeurl": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/encodeurl/-/encodeurl-2.0.0.tgz", + "integrity": "sha512-Q0n9HRi4m6JuGIV1eFlmvJB7ZEVxu93IrMyiMsGC0lrMJMWzRgx6WGquyfQgZVb31vhGgXnfmPNNXmxnOkRBrg==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/es-define-property": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/es-define-property/-/es-define-property-1.0.1.tgz", + "integrity": "sha512-e3nRfgfUZ4rNGL232gUgX06QNyyez04KdjFrF+LTRoOXmrOgFKDg4BCdsjW8EnT69eqdYGmRpJwiPVYNrCaW3g==", + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/es-errors": { + "version": "1.3.0", + "resolved": "https://registry.npmjs.org/es-errors/-/es-errors-1.3.0.tgz", + "integrity": "sha512-Zf5H2Kxt2xjTvbJvP2ZWLEICxA6j+hAmMzIlypy4xcBg1vKVnx89Wy0GbS+kf5cwCVFFzdCFh2XSCFNULS6csw==", + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/es-object-atoms": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/es-object-atoms/-/es-object-atoms-1.1.1.tgz", + "integrity": "sha512-FGgH2h8zKNim9ljj7dankFPcICIK9Cp5bm+c2gQSYePhpaG5+esrLODihIorn+Pe6FGJzWhXQotPv73jTaldXA==", + "dependencies": { + "es-errors": "^1.3.0" + }, + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/escape-html": { + "version": "1.0.3", + "resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz", + "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==" + }, + "node_modules/etag": { + "version": "1.8.1", + "resolved": "https://registry.npmjs.org/etag/-/etag-1.8.1.tgz", + "integrity": "sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/express": { + "version": "5.1.0", + "resolved": "https://registry.npmjs.org/express/-/express-5.1.0.tgz", + "integrity": "sha512-DT9ck5YIRU+8GYzzU5kT3eHGA5iL+1Zd0EutOmTE9Dtk+Tvuzd23VBU+ec7HPNSTxXYO55gPV/hq4pSBJDjFpA==", + "dependencies": { + "accepts": "^2.0.0", + "body-parser": "^2.2.0", + "content-disposition": "^1.0.0", + "content-type": "^1.0.5", + "cookie": "^0.7.1", + "cookie-signature": "^1.2.1", + "debug": "^4.4.0", + "encodeurl": "^2.0.0", + "escape-html": "^1.0.3", + "etag": "^1.8.1", + "finalhandler": "^2.1.0", + "fresh": "^2.0.0", + "http-errors": "^2.0.0", + "merge-descriptors": "^2.0.0", + "mime-types": "^3.0.0", + "on-finished": "^2.4.1", + "once": "^1.4.0", + "parseurl": "^1.3.3", + "proxy-addr": "^2.0.7", + "qs": "^6.14.0", + "range-parser": "^1.2.1", + "router": "^2.2.0", + "send": "^1.1.0", + "serve-static": "^2.2.0", + "statuses": "^2.0.1", + "type-is": "^2.0.1", + "vary": "^1.1.2" + }, + "engines": { + "node": ">= 18" + }, + "funding": { + "type": "opencollective", + "url": "https://opencollective.com/express" + } + }, + "node_modules/finalhandler": { + "version": "2.1.0", + "resolved": "https://registry.npmjs.org/finalhandler/-/finalhandler-2.1.0.tgz", + "integrity": "sha512-/t88Ty3d5JWQbWYgaOGCCYfXRwV1+be02WqYYlL6h0lEiUAMPM8o8qKGO01YIkOHzka2up08wvgYD0mDiI+q3Q==", + "dependencies": { + "debug": "^4.4.0", + "encodeurl": "^2.0.0", + "escape-html": "^1.0.3", + "on-finished": "^2.4.1", + "parseurl": "^1.3.3", + "statuses": "^2.0.1" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/forwarded": { + "version": "0.2.0", + "resolved": "https://registry.npmjs.org/forwarded/-/forwarded-0.2.0.tgz", + "integrity": "sha512-buRG0fpBtRHSTCOASe6hD258tEubFoRLb4ZNA6NxMVHNw2gOcwHo9wyablzMzOA5z9xA9L1KNjk/Nt6MT9aYow==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/fresh": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/fresh/-/fresh-2.0.0.tgz", + "integrity": "sha512-Rx/WycZ60HOaqLKAi6cHRKKI7zxWbJ31MhntmtwMoaTeF7XFH9hhBp8vITaMidfljRQ6eYWCKkaTK+ykVJHP2A==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/function-bind": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/function-bind/-/function-bind-1.1.2.tgz", + "integrity": "sha512-7XHNxH7qX9xG5mIwxkhumTox/MIRNcOgDrxWsMt2pAr23WHp6MrRlN7FBSFpCpr+oVO0F744iUgR82nJMfG2SA==", + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/get-intrinsic": { + "version": "1.3.0", + "resolved": "https://registry.npmjs.org/get-intrinsic/-/get-intrinsic-1.3.0.tgz", + "integrity": "sha512-9fSjSaos/fRIVIp+xSJlE6lfwhES7LNtKaCBIamHsjr2na1BiABJPo0mOjjz8GJDURarmCPGqaiVg5mfjb98CQ==", + "dependencies": { + "call-bind-apply-helpers": "^1.0.2", + "es-define-property": "^1.0.1", + "es-errors": "^1.3.0", + "es-object-atoms": "^1.1.1", + "function-bind": "^1.1.2", + "get-proto": "^1.0.1", + "gopd": "^1.2.0", + "has-symbols": "^1.1.0", + "hasown": "^2.0.2", + "math-intrinsics": "^1.1.0" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/get-proto": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/get-proto/-/get-proto-1.0.1.tgz", + "integrity": "sha512-sTSfBjoXBp89JvIKIefqw7U2CCebsc74kiY6awiGogKtoSGbgjYE/G/+l9sF3MWFPNc9IcoOC4ODfKHfxFmp0g==", + "dependencies": { + "dunder-proto": "^1.0.1", + "es-object-atoms": "^1.0.0" + }, + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/gopd": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/gopd/-/gopd-1.2.0.tgz", + "integrity": "sha512-ZUKRh6/kUFoAiTAtTYPZJ3hw9wNxx+BIBOijnlG9PnrJsCcSjs1wyyD6vJpaYtgnzDrKYRSqf3OO6Rfa93xsRg==", + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/has-symbols": { + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/has-symbols/-/has-symbols-1.1.0.tgz", + "integrity": "sha512-1cDNdwJ2Jaohmb3sg4OmKaMBwuC48sYni5HUw2DvsC8LjGTLK9h+eb1X6RyuOHe4hT0ULCW68iomhjUoKUqlPQ==", + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/hasown": { + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.2.tgz", + "integrity": "sha512-0hJU9SCPvmMzIBdZFqNPXWa6dqh7WdH0cII9y+CyS8rG3nL48Bclra9HmKhVVUHyPWNH5Y7xDwAB7bfgSjkUMQ==", + "dependencies": { + "function-bind": "^1.1.2" + }, + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/http-errors": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.0.tgz", + "integrity": "sha512-FtwrG/euBzaEjYeRqOgly7G0qviiXoJWnvEH2Z1plBdXgbyjv34pHTSb9zoeHMyDy33+DWy5Wt9Wo+TURtOYSQ==", + "dependencies": { + "depd": "2.0.0", + "inherits": "2.0.4", + "setprototypeof": "1.2.0", + "statuses": "2.0.1", + "toidentifier": "1.0.1" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/http-errors/node_modules/statuses": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/statuses/-/statuses-2.0.1.tgz", + "integrity": "sha512-RwNA9Z/7PrK06rYLIzFMlaF+l73iwpzsqRIFgbMLbTcLD6cOao82TaWefPXQvB2fOC4AjuYSEndS7N/mTCbkdQ==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/iconv-lite": { + "version": "0.6.3", + "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.6.3.tgz", + "integrity": "sha512-4fCk79wshMdzMp2rH06qWrJE4iolqLhCUH+OiuIgU++RB0+94NlDL81atO7GX55uUKueo0txHNtvEyI6D7WdMw==", + "dependencies": { + "safer-buffer": ">= 2.1.2 < 3.0.0" + }, + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/inherits": { + "version": "2.0.4", + "resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz", + "integrity": "sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==" + }, + "node_modules/ipaddr.js": { + "version": "1.9.1", + "resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-1.9.1.tgz", + "integrity": "sha512-0KI/607xoxSToH7GjN1FfSbLoU0+btTicjsQSWQlh/hZykN8KpmMf7uYwPW3R+akZ6R/w18ZlXSHBYXiYUPO3g==", + "engines": { + "node": ">= 0.10" + } + }, + "node_modules/is-promise": { + "version": "4.0.0", + "resolved": "https://registry.npmjs.org/is-promise/-/is-promise-4.0.0.tgz", + "integrity": "sha512-hvpoI6korhJMnej285dSg6nu1+e6uxs7zG3BYAm5byqDsgJNWwxzM6z6iZiAgQR4TJ30JmBTOwqZUw3WlyH3AQ==" + }, + "node_modules/math-intrinsics": { + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/math-intrinsics/-/math-intrinsics-1.1.0.tgz", + "integrity": "sha512-/IXtbwEk5HTPyEwyKX6hGkYXxM9nbj64B+ilVJnC/R6B0pH5G4V3b0pVbL7DBj4tkhBAppbQUlf6F6Xl9LHu1g==", + "engines": { + "node": ">= 0.4" + } + }, + "node_modules/media-typer": { + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/media-typer/-/media-typer-1.1.0.tgz", + "integrity": "sha512-aisnrDP4GNe06UcKFnV5bfMNPBUw4jsLGaWwWfnH3v02GnBuXX2MCVn5RbrWo0j3pczUilYblq7fQ7Nw2t5XKw==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/merge-descriptors": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/merge-descriptors/-/merge-descriptors-2.0.0.tgz", + "integrity": "sha512-Snk314V5ayFLhp3fkUREub6WtjBfPdCPY1Ln8/8munuLuiYhsABgBVWsozAG+MWMbVEvcdcpbi9R7ww22l9Q3g==", + "engines": { + "node": ">=18" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, + "node_modules/mime-db": { + "version": "1.54.0", + "resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.54.0.tgz", + "integrity": "sha512-aU5EJuIN2WDemCcAp2vFBfp/m4EAhWJnUNSSw0ixs7/kXbd6Pg64EmwJkNdFhB8aWt1sH2CTXrLxo/iAGV3oPQ==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/mime-types": { + "version": "3.0.1", + "resolved": "https://registry.npmjs.org/mime-types/-/mime-types-3.0.1.tgz", + "integrity": "sha512-xRc4oEhT6eaBpU1XF7AjpOFD+xQmXNB5OVKwp4tqCuBpHLS/ZbBDrc07mYTDqVMg6PfxUjjNp85O6Cd2Z/5HWA==", + "dependencies": { + "mime-db": "^1.54.0" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==" + }, + "node_modules/negotiator": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/negotiator/-/negotiator-1.0.0.tgz", + "integrity": "sha512-8Ofs/AUQh8MaEcrlq5xOX0CQ9ypTF5dl78mjlMNfOK08fzpgTHQRQPBxcPlEtIw0yRpws+Zo/3r+5WRby7u3Gg==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/object-inspect": { + "version": "1.13.4", + "resolved": "https://registry.npmjs.org/object-inspect/-/object-inspect-1.13.4.tgz", + "integrity": "sha512-W67iLl4J2EXEGTbfeHCffrjDfitvLANg0UlX3wFUUSTx92KXRFegMHUVgSqE+wvhAbi4WqjGg9czysTV2Epbew==", + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/on-finished": { + "version": "2.4.1", + "resolved": "https://registry.npmjs.org/on-finished/-/on-finished-2.4.1.tgz", + "integrity": "sha512-oVlzkg3ENAhCk2zdv7IJwd/QUD4z2RxRwpkcGY8psCVcCYZNq4wYnVWALHM+brtuJjePWiYF/ClmuDr8Ch5+kg==", + "dependencies": { + "ee-first": "1.1.1" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/once": { + "version": "1.4.0", + "resolved": "https://registry.npmjs.org/once/-/once-1.4.0.tgz", + "integrity": "sha512-lNaJgI+2Q5URQBkccEKHTQOPaXdUxnZZElQTZY0MFUAuaEqe1E+Nyvgdz/aIyNi6Z9MzO5dv1H8n58/GELp3+w==", + "dependencies": { + "wrappy": "1" + } + }, + "node_modules/parseurl": { + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/parseurl/-/parseurl-1.3.3.tgz", + "integrity": "sha512-CiyeOxFT/JZyN5m0z9PfXw4SCBJ6Sygz1Dpl0wqjlhDEGGBP1GnsUVEL0p63hoG1fcj3fHynXi9NYO4nWOL+qQ==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/path-to-regexp": { + "version": "8.2.0", + "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-8.2.0.tgz", + "integrity": "sha512-TdrF7fW9Rphjq4RjrW0Kp2AW0Ahwu9sRGTkS6bvDi0SCwZlEZYmcfDbEsTz8RVk0EHIS/Vd1bv3JhG+1xZuAyQ==", + "engines": { + "node": ">=16" + } + }, + "node_modules/proxy-addr": { + "version": "2.0.7", + "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz", + "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==", + "dependencies": { + "forwarded": "0.2.0", + "ipaddr.js": "1.9.1" + }, + "engines": { + "node": ">= 0.10" + } + }, + "node_modules/qs": { + "version": "6.14.0", + "resolved": "https://registry.npmjs.org/qs/-/qs-6.14.0.tgz", + "integrity": "sha512-YWWTjgABSKcvs/nWBi9PycY/JiPJqOD4JA6o9Sej2AtvSGarXxKC3OQSk4pAarbdQlKAh5D4FCQkJNkW+GAn3w==", + "dependencies": { + "side-channel": "^1.1.0" + }, + "engines": { + "node": ">=0.6" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/range-parser": { + "version": "1.2.1", + "resolved": "https://registry.npmjs.org/range-parser/-/range-parser-1.2.1.tgz", + "integrity": "sha512-Hrgsx+orqoygnmhFbKaHE6c296J+HTAQXoxEF6gNupROmmGJRoyzfG3ccAveqCBrwr/2yxQ5BVd/GTl5agOwSg==", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/raw-body": { + "version": "3.0.0", + "resolved": "https://registry.npmjs.org/raw-body/-/raw-body-3.0.0.tgz", + "integrity": "sha512-RmkhL8CAyCRPXCE28MMH0z2PNWQBNk2Q09ZdxM9IOOXwxwZbN+qbWaatPkdkWIKL2ZVDImrN/pK5HTRz2PcS4g==", + "dependencies": { + "bytes": "3.1.2", + "http-errors": "2.0.0", + "iconv-lite": "0.6.3", + "unpipe": "1.0.0" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/router": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/router/-/router-2.2.0.tgz", + "integrity": "sha512-nLTrUKm2UyiL7rlhapu/Zl45FwNgkZGaCpZbIHajDYgwlJCOzLSk+cIPAnsEqV955GjILJnKbdQC1nVPz+gAYQ==", + "dependencies": { + "debug": "^4.4.0", + "depd": "^2.0.0", + "is-promise": "^4.0.0", + "parseurl": "^1.3.3", + "path-to-regexp": "^8.0.0" + }, + "engines": { + "node": ">= 18" + } + }, + "node_modules/safe-buffer": { + "version": "5.2.1", + "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.2.1.tgz", + "integrity": "sha512-rp3So07KcdmmKbGvgaNxQSJr7bGVSVk5S9Eq1F+ppbRo70+YeaDxkw5Dd8NPN+GD6bjnYm2VuPuCXmpuYvmCXQ==", + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/feross" + }, + { + "type": "patreon", + "url": "https://www.patreon.com/feross" + }, + { + "type": "consulting", + "url": "https://feross.org/support" + } + ] + }, + "node_modules/safer-buffer": { + "version": "2.1.2", + "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz", + "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==" + }, + "node_modules/send": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/send/-/send-1.2.0.tgz", + "integrity": "sha512-uaW0WwXKpL9blXE2o0bRhoL2EGXIrZxQ2ZQ4mgcfoBxdFmQold+qWsD2jLrfZ0trjKL6vOw0j//eAwcALFjKSw==", + "dependencies": { + "debug": "^4.3.5", + "encodeurl": "^2.0.0", + "escape-html": "^1.0.3", + "etag": "^1.8.1", + "fresh": "^2.0.0", + "http-errors": "^2.0.0", + "mime-types": "^3.0.1", + "ms": "^2.1.3", + "on-finished": "^2.4.1", + "range-parser": "^1.2.1", + "statuses": "^2.0.1" + }, + "engines": { + "node": ">= 18" + } + }, + "node_modules/serve-static": { + "version": "2.2.0", + "resolved": "https://registry.npmjs.org/serve-static/-/serve-static-2.2.0.tgz", + "integrity": "sha512-61g9pCh0Vnh7IutZjtLGGpTA355+OPn2TyDv/6ivP2h/AdAVX9azsoxmg2/M6nZeQZNYBEwIcsne1mJd9oQItQ==", + "dependencies": { + "encodeurl": "^2.0.0", + "escape-html": "^1.0.3", + "parseurl": "^1.3.3", + "send": "^1.2.0" + }, + "engines": { + "node": ">= 18" + } + }, + "node_modules/setprototypeof": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.2.0.tgz", + "integrity": "sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==" + }, + "node_modules/side-channel": { + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/side-channel/-/side-channel-1.1.0.tgz", + "integrity": "sha512-ZX99e6tRweoUXqR+VBrslhda51Nh5MTQwou5tnUDgbtyM0dBgmhEDtWGP/xbKn6hqfPRHujUNwz5fy/wbbhnpw==", + "dependencies": { + "es-errors": "^1.3.0", + "object-inspect": "^1.13.3", + "side-channel-list": "^1.0.0", + "side-channel-map": "^1.0.1", + "side-channel-weakmap": "^1.0.2" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/side-channel-list": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/side-channel-list/-/side-channel-list-1.0.0.tgz", + "integrity": "sha512-FCLHtRD/gnpCiCHEiJLOwdmFP+wzCmDEkc9y7NsYxeF4u7Btsn1ZuwgwJGxImImHicJArLP4R0yX4c2KCrMrTA==", + "dependencies": { + "es-errors": "^1.3.0", + "object-inspect": "^1.13.3" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/side-channel-map": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/side-channel-map/-/side-channel-map-1.0.1.tgz", + "integrity": "sha512-VCjCNfgMsby3tTdo02nbjtM/ewra6jPHmpThenkTYh8pG9ucZ/1P8So4u4FGBek/BjpOVsDCMoLA/iuBKIFXRA==", + "dependencies": { + "call-bound": "^1.0.2", + "es-errors": "^1.3.0", + "get-intrinsic": "^1.2.5", + "object-inspect": "^1.13.3" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/side-channel-weakmap": { + "version": "1.0.2", + "resolved": "https://registry.npmjs.org/side-channel-weakmap/-/side-channel-weakmap-1.0.2.tgz", + "integrity": "sha512-WPS/HvHQTYnHisLo9McqBHOJk2FkHO/tlpvldyrnem4aeQp4hai3gythswg6p01oSoTl58rcpiFAjF2br2Ak2A==", + "dependencies": { + "call-bound": "^1.0.2", + "es-errors": "^1.3.0", + "get-intrinsic": "^1.2.5", + "object-inspect": "^1.13.3", + "side-channel-map": "^1.0.1" + }, + "engines": { + "node": ">= 0.4" + }, + "funding": { + "url": "https://github.com/sponsors/ljharb" + } + }, + "node_modules/statuses": { + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/statuses/-/statuses-2.0.2.tgz", + "integrity": "sha512-DvEy55V3DB7uknRo+4iOGT5fP1slR8wQohVdknigZPMpMstaKJQWhwiYBACJE3Ul2pTnATihhBYnRhZQHGBiRw==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/toidentifier": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.1.tgz", + "integrity": "sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==", + "engines": { + "node": ">=0.6" + } + }, + "node_modules/type-is": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/type-is/-/type-is-2.0.1.tgz", + "integrity": "sha512-OZs6gsjF4vMp32qrCbiVSkrFmXtG/AZhY3t0iAMrMBiAZyV9oALtXO8hsrHbMXF9x6L3grlFuwW2oAz7cav+Gw==", + "dependencies": { + "content-type": "^1.0.5", + "media-typer": "^1.1.0", + "mime-types": "^3.0.0" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/unpipe": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/unpipe/-/unpipe-1.0.0.tgz", + "integrity": "sha512-pjy2bYhSsufwWlKwPc+l3cN7+wuJlK6uz0YdJEOlQDbl6jo/YlPi4mb8agUkVC8BF7V8NuzeyPNqRksA3hztKQ==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/vary": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/vary/-/vary-1.1.2.tgz", + "integrity": "sha512-BNGbWLfd0eUPabhkXUVm0j8uuvREyTh5ovRa/dyow/BqAbZJyC+5fU+IzQOzmAKzYqYRAISoRhdQr3eIZ/PXqg==", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/wrappy": { + "version": "1.0.2", + "resolved": "https://registry.npmjs.org/wrappy/-/wrappy-1.0.2.tgz", + "integrity": "sha512-l4Sp/DRseor9wL6EvV2+TuQn63dMkPjZ/sp9XkghTEbV9KlPS1xUsZ3u7/IQO4wxtcFB4bgpQPRcR3QCvezPcQ==" + } + } +} diff --git a/server/ts-express/package.json b/server/ts-express/package.json new file mode 100644 index 0000000..509bca4 --- /dev/null +++ b/server/ts-express/package.json @@ -0,0 +1,16 @@ +{ + "name": "NOJSCAP server", + "type": "module", + "version": "1.0.0", + "description": "", + "main": "server.ts", + "scripts": { + "start": "npx tsx server.ts" + }, + "keywords": [], + "author": "", + "license": "ISC", + "dependencies": { + "express": "^5.1.0" + } +} diff --git a/server/ts-express/server.ts b/server/ts-express/server.ts new file mode 100644 index 0000000..edff301 --- /dev/null +++ b/server/ts-express/server.ts @@ -0,0 +1,154 @@ +import express, { Request, Response } from 'express'; +import crypto from 'crypto'; + +const app = express(); +app.use(express.urlencoded({ extended: false })); + +const DIFFICULTY = 20; +const challengeStore = new Map(); + +function generateChallenge(): string { + return crypto.randomBytes(12).toString('hex'); +} + +function hashSha256(input: string): Buffer { + return crypto.createHash('sha256').update(input).digest(); +} + +function checkDifficulty(hash: Buffer, bits: number): boolean { + let remaining = bits, i = 0; + while (remaining > 0 && i < hash.length) { + const byte = hash[i]; + if (remaining >= 8) { + if (byte !== 0) return false; + remaining -= 8; + } else { + const mask = 0xFF << (8 - remaining); + if ((byte & mask) !== 0) return false; + break; + } + i++; + } + return true; +} + +app.get('/', (_req: Request, res: Response) => { + const challenge = generateChallenge(); + challengeStore.set(challenge, Date.now()); + res.send(` + + + + POWOW POC + + + + + +

NOJSCAP demo

+

https://git.libroot.org/libroot/NOJSCAP/


+

If you don't already have the NOJSCAP client:

+ $ git clone https://git.libroot.org/libroot/NOJSCAP/ +$ cd NOJSCAP/client/ +


+

+ Python: +

+

+ +

+

+ Go: +

+

+ +

+

+ Node.js: +

+

+ +

+

+ Rust: +

+

+

Show compilation commands$ rustc pow_client.rs -o pow_client_rs + Requires Rust and sha2 crate if using the Cargo version.
+ +

+

+ C: +

+

+

Show compilation commands$ gcc -O2 -o pow_client pow_client.c -lssl -lcrypto + Required: GCC or any C compiler. OpenSSL development libraries (libssl-dev on Debian-based systems)
+ + + +

+
+ + + +
+ + + `); +}); + +app.post('/', (req: Request, res: Response) => { + const { challenge, nonce } = req.body as { challenge?: string; nonce?: string }; + if (!challenge || !nonce || !challengeStore.has(challenge)) { + return res.send('Invalid input.'); + } + + challengeStore.delete(challenge); + const hash = hashSha256(challenge + nonce); + if (checkDifficulty(hash, DIFFICULTY)) { + res.send('

Success! Valid nonce.

Try again'); + } else { + res.send('

Invalid nonce.

Try again'); + } +}); + +app.listen(3000, () => console.log('Server running at http://localhost:3000'));