As of this commit, if a registered server does not provide us with
a server token, authentication for `ladderupdate` is based purely on
the IP address of the server. This technically also applies to
the `prepreplay` action, but only the main server can use that at
this time, so that does not actually change anything.
This commit adds support for 'config data' that begins with a ']'
character so that output from the upkeep page can be copied directly
without having to manually remove the ']' prefix.
This avoids an attack where a malicious webpage contains
<script id="data" type="application/json"
src="http://play.pokemonshowdown.com/~~showdown/action.php?act=upkeep"/>
The webpage could then read the value of the `data` element using
standard DOM methods in order to steal the user's login assertion
and login as the user on the `showdown` server.
Improve timestamps so they can be configured separatedly for
PMs and lobby chat.
Cathy J. Fitzpatrick <cathy@cathyjf.com> revised this commit to
fix a number of bugs.
This commit implements the following:
- each server now has a separate session with a 'sid' cookie
scoped to /~~server:port
- 'sid' cookies are now HTTP-only and not accessible in JavaScript
- the showdown_token cookie is removed
Together, these changes fix various XSS attacks.
Firefox renders the height of a <textarea> based on the `rows`
attribute, which was not previously specified, causing the <textarea>
in the teambuilder to be very short. This commit specifies a
(somewhat arbitrary) `rows` attribute so that the <textarea> has
some more height.
Added highlighting words:
Users may now use the new highlight commands:
-Use /highlight add, word to add a highlighting word.
You might add several words separated with commands.
-In a likewise fashion, /highlight delete, word deletes words.
-Using /highlight delete with no words will delete all.
-/highlight show or list will show all current highlight words.
-By default no word is added to highlights.
-Words are escaped
Currently, server authentication for updating the ladder and for
uploading replays is done by comparing the hash of the token provided
by the server to the hash on record. This commit adds a second layer
of authentication by also verifying that the request actually
originates from the Pokemon Showdown server in question.
For now, I have also maintained the server token check as a form of
two-factor authentication.
- battle logs no longer have timestamps
- getTimestamp is moved to a property of the Lobby function
- the prefs global variable is replaced by a prefs API
In order to preserve the previous status quo for now, this
commit turns timestamps off by default. They can be turned on
using /timestamps minutes or /timestamps seconds.