|
|
1aa02a08b9
|
channels: replace Member's six parallel prefix bools (oprefix/owner/admin/op/halfop/voice) with a single u8 bitfield (PFX_*) + inline bool accessors/mutators — same semantics, one byte instead of six, no more risk of the flags drifting out of sync; all call sites go through op()/set_op()-style methods
|
2026-08-19 02:47:04 +00:00 |
|
|
|
a218d65371
|
rpc: authenticate on the header block before buffering the request body — the httpd read up to MAX_REQUEST (256 KiB) and only then checked the Authorization header, so an unauthenticated peer reaching rpc_bind could make each connection consume memory + a worker thread; now POST+auth are validated as soon as headers are complete, before any body is read
|
2026-08-19 01:05:29 +00:00 |
|
|
|
5b33786a46
|
rpc: refuse an all-wildcard x-line via ban.add — the mask went unvalidated, so an authenticated RPC call with "mask":"" or "*@*" installed a K/G/Z-line matching the entire network; require at least one literal host/ip/nick char
|
2026-08-19 01:03:27 +00:00 |
|
|
|
c4456cf002
|
oper: TLS client-cert fingerprint login — oper block gains an optional fp=<sha256>; password=* means cert-only. Named OperBlock struct replaces the (name,pass,level) tuple. (Password login was never broken — verified live.)
|
2026-08-18 22:55:07 +00:00 |
|
|
|
546f6279e7
|
snomasks: make +s a parametric snomask mode with the standard category letters (acdfgjklnoqrtuvwx), route each server notice by category, RPL_SNOMASKIS 008; opers default to all and narrow with +s -c etc.
|
2026-08-15 17:06:14 +00:00 |
|
|
|
35af95fd0f
|
harden: connclass clone-cap at register, ws control-frame limits, uuid recycle-skip, json-escape extjwt/filehost claims, metadata value/key caps, cloak numeric-dotted leak, relaymsg remote-nick, rpc set_oper block validation, isupport 13-token split, multi-hop privmsg routing, connectdelay=0
|
2026-08-15 16:27:11 +00:00 |
|
|
|
e935ee7002
|
harden: fix reachable panics (parse_duration/parse_iso/dechunk char-boundary+overflow), s2s netburst key/limit loss, rpc set_nick/set_vhost/notice injection, webirc rehash reload, panic-state reset, ws line cap, remote nick collision, per-conn state leaks
|
2026-08-15 15:02:36 +00:00 |
|
|
|
3b43abc88a
|
operlevels: oper = <name> <pass> <level>; a lower-level oper can't KILL a higher-level one
|
2026-08-11 18:50:12 +00:00 |
|
|
|
f371ed0a18
|
connclass: cidr/parent/port/limit/globalmax + hashed/trusted-cert passwords, per-class recvq/sendq + fakelag, and rfc1413 ident
|
2026-08-10 18:46:42 +00:00 |
|
|
|
1dd7f77ca8
|
operprefix + ojoin: server oper prefix (!/mode y, above owner) auto-granted to opers + OJOIN command
|
2026-08-10 13:01:07 +00:00 |
|
|
|
19157e0722
|
websocket: native RFC 6455 transport (ws:// + wss://) — handshake, framing, ping/pong keepalive, idle timeout, origin/proxy flags, via_websocket
|
2026-08-09 18:45:12 +00:00 |
|
|
|
06afd1e59d
|
rpc: implement the deferred methods — channel.set_mode, server.connect, log.tail/log.events (in-memory log ring)
|
2026-08-09 16:36:34 +00:00 |
|
|
|
185ff471b1
|
rpc/httpd: accept chunked (Transfer-Encoding) request bodies, not just Content-Length
|
2026-08-09 16:27:04 +00:00 |
|
|
|
89f508aca9
|
rpc: add server/stats/ban/message/whowas/spamfilter providers; fix REHASH to reload raw_config
|
2026-08-09 16:07:53 +00:00 |
|
|
|
ee445396eb
|
rpc: add user + channel providers (list/get + kill/kick/set_topic/set_nick/set_mode/set_vhost/set_oper)
|
2026-08-09 16:00:28 +00:00 |
|
|
|
4b1f096ed8
|
rpc: JSON-RPC-over-HTTP control interface — native httpd + json + dispatch, core provider
|
2026-08-09 15:54:05 +00:00 |
|