Commit Graph

24 Commits

Author SHA1 Message Date
Cathy J. Fitzpatrick
78356e64c3 Specify character encoding for getassertion output 2013-02-09 02:40:42 -07:00
Cathy J. Fitzpatrick
d3c4bc26fe Remove two more unused actions 2013-02-08 19:24:13 -07:00
Cathy J. Fitzpatrick
3d810fa926 Remove more obsolete code from action.php 2013-02-08 18:37:40 -07:00
Cathy J. Fitzpatrick
500999151d Remove obsolete upkeep action from action.php 2013-02-08 18:15:21 -07:00
Cathy J. Fitzpatrick
86a81f9614 Display friendly error message when trying to register 'guest*' 2013-02-08 17:02:31 -07:00
Cathy J. Fitzpatrick
4076152c85 Add support for omitting userid for getassertion 2013-02-08 05:15:49 -07:00
Cathy J. Fitzpatrick
d2783cf610 No need to sanitise $challenge in getassertion
I now sanitise the challenge in getAssertion() instead.
2013-02-08 03:44:00 -07:00
Cathy J. Fitzpatrick
01522f0a15 Fix bug in testing for presence of challengekeyid 2013-02-08 01:07:52 -07:00
Cathy J. Fitzpatrick
f0fde921ec Changes to action.php for challenge-response authentication 2013-02-07 23:22:13 -07:00
Cathy J. Fitzpatrick
f7adbee232 More changes to cached index.php logging
- record lag time in the log
- use an <img> tag rather than an AJAX request to reduce false
  positives caused by slow internet
2013-02-07 13:54:24 -07:00
Cathy J. Fitzpatrick
7a50b31b6b More changes to cached index.php logging
- check timestamp in index.php rather than sim.js to reduce the chance
  of false positives caused by the user's internet connection being
  slow or the user's clock being slightly wrong

- require timestamp logging to be a POST request
2013-02-06 22:36:32 -07:00
Cathy J. Fitzpatrick
3e86a976dd Changes to cached index.php logging
- use human-readable times
- log user agent
2013-02-06 19:00:34 -07:00
Cathy J. Fitzpatrick
22138d3e25 Log cases where user has cached index.php
In addition, if the user has a cached index.php, we no longer make a
special request to action.php?act=upkeep.
2013-02-06 18:40:33 -07:00
Cathy J. Fitzpatrick
417d95c392 Server tokens are now optional for ladder updates
As of this commit, if a registered server does not provide us with
a server token, authentication for `ladderupdate` is based purely on
the IP address of the server. This technically also applies to
the `prepreplay` action, but only the main server can use that at
this time, so that does not actually change anything.
2013-02-06 16:34:43 -07:00
Cathy J. Fitzpatrick
83fe1d5b72 Don't return valid JavaScript from action.php
This avoids an attack where a malicious webpage contains

  <script id="data" type="application/json"
    src="http://play.pokemonshowdown.com/~~showdown/action.php?act=upkeep"/>

The webpage could then read the value of the `data` element using
standard DOM methods in order to steal the user's login assertion
and login as the user on the `showdown` server.
2013-02-04 20:42:38 -07:00
Cathy J. Fitzpatrick
2acc89748a Each server now gets its own session
This commit implements the following:

- each server now has a separate session with a 'sid' cookie
  scoped to /~~server:port

- 'sid' cookies are now HTTP-only and not accessible in JavaScript

- the showdown_token cookie is removed

Together, these changes fix various XSS attacks.
2013-02-02 19:37:57 -07:00
Cathy J. Fitzpatrick
5ae66a78aa Changes for Railgun 2013-01-31 22:33:00 -07:00
Cathy J. Fitzpatrick
1208dee10f Verify that source IP is valid for server requests
Currently, server authentication for updating the ladder and for
uploading replays is done by comparing the hash of the token provided
by the server to the hash on record. This commit adds a second layer
of authentication by also verifying that the request actually
originates from the Pokemon Showdown server in question.

For now, I have also maintained the server token check as a form of
two-factor authentication.
2013-01-31 11:31:35 -07:00
Cathy J. Fitzpatrick
b8daba264f Fix theoretical IE6 XSS 2013-01-31 01:38:21 -07:00
Cathy J. Fitzpatrick
5a26bc4fdb Fix XSS in getassertion 2013-01-30 22:49:51 -07:00
Cathy J. Fitzpatrick
9e28dc7e7d Include hostname in assertion to avoid vulnerability 2013-01-30 06:25:32 -07:00
Cathy J. Fitzpatrick
5c2160d875 Remove glickotest and laddertest features 2013-01-30 04:16:48 -07:00
Cathy J. Fitzpatrick
b630ff5c49 Remove sekrit2q53mkuser feature 2013-01-30 04:11:14 -07:00
Guangcong Luo
b16c1527da Populate with current state of client 2013-01-23 16:39:14 -08:00