Skip to content

feat: improve security - #106

Open
jackssrt wants to merge 3 commits into
ynoproject:masterfrom
jackssrt:feat-improve-security
Open

jackssrt wants to merge 3 commits into
ynoproject:masterfrom
jackssrt:feat-improve-security

Conversation

@jackssrt

Copy link
Copy Markdown
Contributor

this pr makes cheating by injecting packets on the room websocket a little bit harder.

  • feat(room): enforce new counter is old counter + 1
  • feat(room): disconnect probably cheating clients
    • makes it more annoying (complicated) to cheat
    • will disconnect the client if this happens:
      • legit packet counter=1
      • bad packet counter=2
      • legit packet counter=2
    • or this:
      • legit packet counter=1
      • bad packet counter=1
    • the previous behavior only logged the discrepancy, check your logs to make sure there are no false positives
    • if the counter is not reset on the client you essentially get soft locked from connecting to a room again, until you refresh the page
  • fix(room): allow 0 as the first packet counter
    • fixes a bug where the first packet would be ignored (and now gets you disconnected) since fix: initialize msg_count in YNOConnection ynoengine#89 initialized the counter to 0 properly.
    • kind of hacky but nitran says its okay /shrug
    • if it works this would be good to merge regardless of the other stuff, sorry for introducing the bug in the first place :c

Caution

untested, if you couldn't tell

Tip

feel free to cherry pick this pr and partially merge it.

if they provide a bad counter or bad signature
Signed-off-by: Colourless <205353678+AcrylonitrileButadieneStyrene@users.noreply.github.com>
@Desdaemon

Copy link
Copy Markdown
Contributor

ynoproject/ynoengine#89 is pushed to prod

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants