harden: connclass clone-cap at register, ws control-frame limits, uuid recycle-skip, json-escape extjwt/filehost claims, metadata value/key caps, cloak numeric-dotted leak, relaymsg remote-nick, rpc set_oper block validation, isupport 13-token split, multi-hop privmsg routing, connectdelay=0

This commit is contained in:
Jean Chevronnet 2026-08-15 16:27:11 +00:00
parent e935ee7002
commit 35af95fd0f
11 changed files with 129 additions and 27 deletions

View file

@ -99,7 +99,13 @@ pub fn cloak_host(key: &str, host: &str) -> String {
format!("{alpha}.{beta}.{gamma}{IP_SUFFIX}")
} else {
let parts: Vec<&str> = host.split('.').filter(|p| !p.is_empty()).collect();
if parts.len() >= 3 {
// reveal the registered domain suffix only for a real hostname (its TLD has a
// letter); a numeric dotted string that slipped past the IP parsers is fully
// cloaked so no octets leak in cleartext
let real_host = parts
.last()
.is_some_and(|t| t.bytes().any(|b| b.is_ascii_alphabetic()));
if parts.len() >= 3 && real_host {
let suffix = parts[parts.len() - 2..].join(".");
format!("{}.{suffix}", label(key, host, 8))
} else {