This commit implements the following:
- each server now has a separate session with a 'sid' cookie
scoped to /~~server:port
- 'sid' cookies are now HTTP-only and not accessible in JavaScript
- the showdown_token cookie is removed
Together, these changes fix various XSS attacks.
Firefox renders the height of a <textarea> based on the `rows`
attribute, which was not previously specified, causing the <textarea>
in the teambuilder to be very short. This commit specifies a
(somewhat arbitrary) `rows` attribute so that the <textarea> has
some more height.
Added highlighting words:
Users may now use the new highlight commands:
-Use /highlight add, word to add a highlighting word.
You might add several words separated with commands.
-In a likewise fashion, /highlight delete, word deletes words.
-Using /highlight delete with no words will delete all.
-/highlight show or list will show all current highlight words.
-By default no word is added to highlights.
-Words are escaped
Currently, server authentication for updating the ladder and for
uploading replays is done by comparing the hash of the token provided
by the server to the hash on record. This commit adds a second layer
of authentication by also verifying that the request actually
originates from the Pokemon Showdown server in question.
For now, I have also maintained the server token check as a form of
two-factor authentication.
- battle logs no longer have timestamps
- getTimestamp is moved to a property of the Lobby function
- the prefs global variable is replaced by a prefs API
In order to preserve the previous status quo for now, this
commit turns timestamps off by default. They can be turned on
using /timestamps minutes or /timestamps seconds.
The past log sent from the server when joining a room does not
contain information about when the messages were sent, so we
do not show a timestamp for those messages.
This commit implements timestamp functionality in the lobby chat,
in private messages, and in battle chats. Timestamps are controlled
by a /timestamps command, which has three legal invocations:
/timestamps off
turns off timestamps
/timestamps minutes
show timestamps of the form [hh:mm]
/timestamps seconds
show timestamps of the form [hh:mm:ss]
For now, the default setting is /timestamps minutes. If this proves
unpopular, it can be changed. The timestamp preference is stored in
localStorage and does not have to be set every time.
Teams are stored in localStorage. Most browsers appear to clear
localStorage as part of clearing cookies. Very often, users
inadvertently delete their teams when they clear their cookies.
This message will not prevent all instances of this, but it
will at least decrease the chance of it happening.
I would have followed the pattern of specifying a hash, but my
shade of pink is not within the colour space spanned by the
normal algorithm (the proof of that claim is left as an exercise
to the reader), so it was necessary to hardcode the colour.
After the introduction of the tab complete feature, the tab
key can no longer be used to navigate away from the chatbox.
This commit adds a shift+tab function to navigate away from
the chatbox, rather than tab completing a name.