Currently, server authentication for updating the ladder and for uploading replays is done by comparing the hash of the token provided by the server to the hash on record. This commit adds a second layer of authentication by also verifying that the request actually originates from the Pokemon Showdown server in question. For now, I have also maintained the server token check as a form of two-factor authentication.
Pokemon Showdown Client
This is a repository for some of the client code for Pokemon Showdown.
This is what runs play.pokemonshowdown.com.
WARNING: You probably want the Pokemon Showdown server.
Testing
You can make and test client changes simply by opening testclient.html.
It will ask for config data. Config data for the main server can be copied from:
http://play.pokemonshowdown.com/action.php?act=upkeep&servertoken=sim.smogon.com
This will allow you to test changes to the client without setting up your own login server.
Certain things will fail:
Registering, changing name, the ladder tab, and the /ladder command
Everything else can be tested, though.
Setup
This repository is not "batteries included". It does NOT include everything necessary to run a full Pokemon Showdown client.
In particular, it doesn't include a login/authentication server, nor does it
include the database abstraction library used by the ladder library (although
it's similar enough to mysqli that you can use that with minimal changes).
It also doesn't include several resource files (namely, the /audio/ and
/sprites/ directories) for size reasons.
In other words, this repository is incomplete and NOT intended for people who wish to serve their own Pokemon Showdown client (you can, but it'll require you to rewrite some things). Rather, it's intended for people who wish to contribute and submit pull requests to Pokemon Showdown's client.
License
Pokemon Showdown's client is distributed under the terms of the AGPLv3.
WARNING: This is NOT the same license as Pokemon Showdown's server.