Commit graph

471 commits

Author SHA1 Message Date
19bc4dc544
nickserv: add HELP PUBKEY / HELP SET PUBKEY topic for ECDSA login
All checks were successful
CI / check (push) Successful in 6m33s
2026-08-30 17:33:46 +00:00
cde5575c48
dns: remove redundant duplicate branch in with_port
All checks were successful
CI / check (push) Successful in 6m22s
2026-08-30 12:00:05 +00:00
47014efe92
sasl: add ECDSA-NIST256P-CHALLENGE mechanism + NickServ SET PUBKEY
Some checks failed
CI / check (push) Failing after 3m0s
2026-08-30 04:52:34 +00:00
400f7ac5aa
docs: document P7 anti-abuse config ([security.auth], netsplit_grace, crawl) in config.example + anti-abuse.md
Some checks failed
CI / check (push) Failing after 3m8s
2026-08-27 02:46:51 +00:00
d4148644db
security: P7 — netsplit suppression + auth brute-force + registration flood + channel-crawl + ban-evasion
Some checks failed
CI / check (push) Failing after 4m16s
2026-08-27 02:41:04 +00:00
b15735b4b2
docs: config.example — document the full [security] tree + [mxbl] anti-abuse config + [[oper]].privs
Some checks failed
CI / check (push) Failing after 3m7s
2026-08-27 02:17:40 +00:00
3e0a61c886
docs: consolidate the anti-abuse doc into anti-abuse.md (drop redundant SECURITY.md; SECURITY.md conventionally = vuln-disclosure policy)
Some checks failed
CI / check (push) Failing after 3m40s
2026-08-27 02:03:59 +00:00
782033e7bc
security: P6 — engine-level integration tests (nick-flood/connect-flood+exempt/mass-join) + SECURITY.md operator doc
Some checks failed
CI / check (push) Has been cancelled
2026-08-27 02:03:01 +00:00
4e02e05d2f
security: MX-blacklist registration screening + native async DNS resolver (off the engine lock)
Some checks failed
CI / check (push) Failing after 3m36s
2026-08-27 01:28:27 +00:00
49f7a1992a
security: announce rate-limit + oper/account/voice exemptions + abuse-cascade DEFCON alert
All checks were successful
CI / check (push) Successful in 6m22s
2026-08-27 01:04:26 +00:00
b9d28b275a
security: bad-unicode (zalgo/zero-width) + repeat-spam-wave content detectors
All checks were successful
CI / check (push) Successful in 6m26s
2026-08-27 00:52:03 +00:00
e5b793c38e
security: highlight-spam (mass-ping) content detector on channel messages echo sees
All checks were successful
CI / check (push) Successful in 5m38s
2026-08-27 00:40:43 +00:00
aabb1432e2
security: behavioural detectors (nick-flood, cycle, join-spam-part, mass-join, quit-flood) on native join/part/quit/nick events
All checks were successful
CI / check (push) Successful in 6m21s
2026-08-27 00:25:57 +00:00
ef857f56d4
security: trusted-IP exemption (loopback-exempt by default) + connection pattern DB (glob/regex, ozone-style)
All checks were successful
CI / check (push) Successful in 5m42s
2026-08-27 00:07:21 +00:00
01d0eee843
security: engine-core anti-abuse subsystem + per-IP/range connection-flood detector (report-only default)
All checks were successful
CI / check (push) Successful in 5m46s
2026-08-26 23:33:10 +00:00
44d45e9c68
nickserv: INFO shows services role + GroupServ groups (config∪runtime oper privs, all catalogs)
All checks were successful
CI / check (push) Successful in 5m49s
2026-08-26 22:06:57 +00:00
e303350b2b
nickserv: show account age beside the registration date in INFO (localized human_ago, all catalogs)
All checks were successful
CI / check (push) Successful in 6m0s
2026-08-26 21:27:01 +00:00
bfcefdb83b
nickserv: drop needless borrow on SAREGISTER alert text (clippy needless_borrows_for_generic_args)
Some checks failed
CI / check (push) Failing after 32s
2026-08-26 17:59:23 +00:00
ce8fdb9d5f
chanserv: source channel op/voice/ban changes from the assigned bot when it's online, else ChanServ
Some checks failed
CI / check (push) Failing after 3m0s
2026-08-26 15:40:17 +00:00
0315e4910e
nickserv: SAREGISTER — operators create an account directly (active at once, no confirm/vouch); RegReply::Admin
Some checks failed
CI / check (push) Failing after 3m44s
2026-08-26 13:58:59 +00:00
b9e3e54ee2
panel: security headers (CSP, X-Frame-Options, nosniff, referrer-policy), Secure cookie flag, root-gate /access server-side
All checks were successful
CI / check (push) Successful in 5m45s
2026-08-22 23:40:31 +00:00
54b26d08ef
panel: server pages use the srv-hero hub banner + net-tree topology, detail page too
All checks were successful
CI / check (push) Successful in 5m43s
2026-08-22 21:40:41 +00:00
5fc3e4d71f
panel: satisfy clippy -D warnings (sort_by_key, contains_key, fn reference)
All checks were successful
CI / check (push) Successful in 6m9s
2026-08-22 20:57:42 +00:00
a1f2ae838d panel: percent-encode channel/nick names in links so #channels resolve 2026-08-22 20:35:57 +00:00
ea41fd0c4c panel: port every ircpanel page to askama fed by echo's live view (users/channels/servers/bans/spamfilter/opers/registrations/audit/logs/ip-whois/search) 2026-08-22 19:57:03 +00:00
c0c30d9404 panel: render smoke test covering every page template 2026-08-22 19:20:45 +00:00
056e4b7cbd panel: rewrite to full-Rust askama sourcing live data from echo's own engine 2026-08-22 19:17:37 +00:00
8d7756e69e panel: serve the ircpanel templates over axum with embedded css/js assets and every page routed 2026-08-22 18:16:48 +00:00
406c3b1593
grpc: allow result_large_err on the tonic-generated module so clippy -D warnings passes in CI
All checks were successful
CI / check (push) Successful in 5m44s
2026-08-21 23:51:46 +00:00
5edf969adb
nickserv: CERT ADD note now mentions the automatic reconnect login, not only SASL EXTERNAL
Some checks failed
CI / check (push) Failing after 2m52s
2026-08-21 16:05:50 +00:00
1f0ff95021
cert: log a user in on connect when their TLS fingerprint owns an account (transparent certfp login, no SASL EXTERNAL needed)
Some checks failed
CI / check (push) Failing after 3m1s
2026-08-21 15:58:32 +00:00
debde5198e
signore: store the ircd's per-account SIGNORE list and replay it on login
All checks were successful
CI / check (push) Successful in 6m22s
2026-08-20 15:42:14 +00:00
786368e06b
operserv: bold the SWHOIS line (\x02) so it stands out in /WHOIS
All checks were successful
CI / check (push) Successful in 6m18s
2026-08-20 08:12:03 +00:00
7045ca3b2e
operserv: SWHOIS command — set a persistent extra WHOIS line on an account (event-sourced), pushed to the ircd as a swhois metadata key on set and re-applied on every login; admin to change, operator to view
All checks were successful
CI / check (push) Successful in 7m3s
2026-08-20 00:02:23 +00:00
f1be06d434
chanserv: RENAME command — rename a registered channel over draft/channel-rename S2S, persist the move (ChannelRenamed event), and re-key network tracking
All checks were successful
CI / check (push) Successful in 5m56s
2026-08-17 23:45:07 +00:00
5c2102232b
config: default standard_replies on (echoIRCd re-emits FAIL/WARN/NOTE)
All checks were successful
CI / check (push) Successful in 5m44s
2026-08-17 13:55:20 +00:00
7cb1ab05b7
lock idna to the icu-free adapter (builds on this box's rustc) + gitignore /certs (private TLS keys)
All checks were successful
CI / check (push) Successful in 5m58s
2026-08-16 14:10:26 +00:00
05c6f5e012
engine: re-assert a registered channel's mode-lock when a service bot rejoins it (the uplink sends modeless IJOIN for later member joins, so nothing else re-applies +r after a relink)
All checks were successful
CI / check (push) Successful in 6m34s
2026-08-16 03:20:52 +00:00
1880a7539e
panel: drop unused accessor, use sort_by_key (clippy)
All checks were successful
CI / check (push) Successful in 5m35s
2026-08-01 00:51:59 +00:00
0f9b6619b0
add web admin panel: oper login, dashboard, accounts list
Some checks failed
CI / check (push) Failing after 2m44s
2026-07-31 23:15:39 +00:00
7ed75921eb
account profiles via IRCv3 metadata (avatar/bio/pronouns/timezone/url)
All checks were successful
CI / check (push) Successful in 6m14s
2026-07-31 20:36:09 +00:00
58703db5ae
set +r registered umode on login, clear on logout, re-assert on nick change 2026-07-31 20:35:59 +00:00
8df07f22f9
Complete config.example.toml with all sections
All checks were successful
CI / check (push) Successful in 5m18s
2026-07-21 14:54:26 +00:00
dc046cd6f0
Rewrite the README
All checks were successful
CI / check (push) Successful in 5m28s
2026-07-21 14:21:23 +00:00
45f45a46b9
Warn an oper whose TLS cert fingerprint isn't on their account
All checks were successful
CI / check (push) Successful in 5m31s
2026-07-21 14:13:49 +00:00
cb552c04b0
Support connecting to the uplink over SPKI-pinned TLS
All checks were successful
CI / check (push) Successful in 5m26s
2026-07-21 13:48:50 +00:00
3b76454586
Add a deny-status (d) channel access flag that bars a user from op/voice
All checks were successful
CI / check (push) Successful in 5m21s
2026-07-21 13:36:14 +00:00
acbf557104
Restore the connect cloak or services vhost when a user deopers
All checks were successful
CI / check (push) Successful in 5m26s
2026-07-21 13:17:14 +00:00
ac021ec584
Notify a game opponent when a departing guest's game ends
All checks were successful
CI / check (push) Successful in 5m39s
2026-07-21 10:40:27 +00:00
9e8449b40d
Drop a guest's GamesServ games on disconnect so a recycled uid can't inherit one
All checks were successful
CI / check (push) Successful in 5m39s
2026-07-21 10:23:52 +00:00