altcha_lib 1.0.0
altcha_lib: ^1.0.0 copied to clipboard
Server-side Dart library for the ALTCHA Proof-of-Work v2 challenge system. Create, solve, and verify challenges using PBKDF2, SHA, Scrypt, or Argon2id.
1.0.0 #
- Fix challenge signatures for
datawith unsorted keys ornullvalues:createChallengeandverifySolutionnow both sign altcha-lib's canonical JSON (keys sorted recursively, nulls kept). Before this fix, such challenges never verified, in Dart or in JS. ChallengeParameters.toSortedJson()now sorts nested map keys too.verifySolutionnow returnsinvalidSolutioninstead of throwing whensolution.derivedKeyis not valid even-length hex on the key-signature path.verifySolutionnow compares an even-lengthkeyPrefixas bytes, likesolveChallengeand altcha-lib, so uppercase hex prefixes verify.verifySolutionexpiry now matches altcha-lib:expiresAtis compared against the current time in fractional seconds (no up-to-1 s grace), andexpiresAt: 0means no expiry.- Empty-string secrets are now treated as unset, as in altcha-lib:
createChallengewithhmacSignatureSecret: ''returns an unsigned challenge,hmacKeySignatureSecret: ''adds nokeySignatureand makesverifySolutionre-derive the key, andverifySolutionwithhmacSignatureSecret: ''returnsinvalidSignature(previously any challenge HMAC'd under the empty key verified). Likewise,verifyServerSignaturewithhmacSecret: ''returnsinvalidSignature, andsignChallengewithhmacSignatureSecret: ''throwsArgumentError. solveChallengeandsolveChallengeIsolatesnow treattimeout: Duration.zeroas no timeout, as in altcha-lib (previously it returnednullimmediately).solveChallengeIsolatesalso no longer truncates sub-millisecond timeouts to zero.- Unknown challenge parameters are now preserved, as in altcha-lib:
ChallengeParameters.extraholds keys not modelled as fields,fromJsonfills it andtoJsonemits it, so they are signed and verified (keys inextrathat name a modelled field are ignored).createChallengemerges every key returned byderiveKey(likeObject.assign), not just a fixed subset. - Breaking:
ChallengeParameters.expiresAtis nownum?(wasint?), andcreateChallenge(expiresAt:)accepts anynum, so fractionalexpiresAtvalues from altcha-lib parse and verify instead of throwing. canonicalJsonnow formats numbers likeJSON.stringify: integral doubles have no.0(1.0→1) and-0.0is0, so challenges whosedataholds such doubles verify across implementations.canonicalJsonnow orders keys exactly as altcha-lib'sJSON.stringify(sortKeys(...)): integer-like keys ("0"…"4294967294") come first in numeric order, then the remaining keys sorted, and a__proto__key is dropped. Previously, challenges whosedatahad integer-like keys (e.g.{'9': …, '10': …}) failed signature verification across implementations.verifyServerSignatureno longer throws whenverificationDatahas a non-integerexpire(e.g.1.5,abc, empty); such input was client-controlled and crashed the call even for forged payloads.expireis now evaluated like altcha-lib:0or empty means no expiry, fractional values are compared as numbers.
0.4.0 #
- Fix web compatibility issues
0.2.0 #
- The PBKDF2 algorithm now uses
cryptofor improved performance - Added
adaptiveDeriveKeywith automatic algorithm detection
0.1.1 #
- Upgraded
pointycastleto^4.0.0. - Removed
argon2dependency; Argon2id now uses pointycastle's built-in implementation. - Upgraded
lintsto^6.1.0.
0.1.0 #
- Initial release.
createChallenge— create signed PoW v2 challenges with optional deterministic mode.solveChallenge— brute-force solve a challenge on the current isolate.solveChallengeIsolates— parallel solver using multiple Dart isolates.verifySolution— verify a client-submitted solution.verifyServerSignature— verify an ALTCHA Sentinel server signature payload.verifyFieldsHash— verify a hash of submitted form fields.- Algorithm support: PBKDF2/SHA-256, PBKDF2/SHA-384, PBKDF2/SHA-512, SHA-256, SHA-384, SHA-512, Scrypt, Argon2id.