Translate remaining Go source and overlay.html comments to English
Identifiers, comments, and log/console messages in auth.go, i18n.go, counter.go, totals.go, and overlay.html's script/CSS comments — the files the TLS commit didn't already touch. No functional changes. locales/*.json and overlay.html's own FALLBACK/data-i18n strings stay bilingual on purpose: that's end-user text for the overlay/panel, a different audience than the source code, served by the existing i18n system rather than this convention.
This commit is contained in:
1 parent
e9fe10f0f7
commit
5a2c3272e9
7 files changed
+213
-211
No files matched your search
@@ -1,20 +1,19 @@
|
||||
// auth.go: autenticacion entre el hub y los peers.
|
||||
// auth.go: authentication between the hub and its peers.
|
||||
//
|
||||
// El transporte NO se asume confiable. Puede ser Tailscale, ZeroTier,
|
||||
// WireGuard, o un puerto abierto directo a internet: eso lo decide quien
|
||||
// lo usa, no nosotros. Asi que la conexion se defiende sola.
|
||||
// The transport is NOT assumed trustworthy. It could be Tailscale,
|
||||
// ZeroTier, WireGuard, or a port opened straight to the internet: that's
|
||||
// up to whoever runs it, not us. So the connection defends itself.
|
||||
//
|
||||
// El token es OBLIGATORIO y lo genera el programa (nadie elige "1234"), y
|
||||
// nunca viaja por la red: el hub manda un desafio al azar y el peer
|
||||
// responde con un HMAC del desafio usando el token como clave. Quien
|
||||
// escuche el trafico no se lleva el token, y no puede repetir una
|
||||
// respuesta vieja porque el desafio cambia en cada conexion.
|
||||
// The token is REQUIRED and generated by the program (nobody gets to pick
|
||||
// "1234"), and it never travels over the network: the hub sends a random
|
||||
// challenge and the peer replies with an HMAC of it, keyed by the token.
|
||||
// Anyone listening to the traffic doesn't get the token, and can't replay
|
||||
// an old response because the challenge changes on every connection.
|
||||
//
|
||||
// Lo que esto NO hace: cifrar. Los mensajes (nombre y numero de muertes)
|
||||
// viajan en claro. Para un contador de muertes en un stream es
|
||||
// aceptable, pero si te importa, poné la conexion adentro de una VPN o
|
||||
// un tunel con TLS. Lo que el token garantiza es que nadie pueda
|
||||
// INYECTAR datos falsos en tu overlay.
|
||||
// This proves the PEER's identity to the hub. It doesn't encrypt
|
||||
// anything by itself — that's TLS's job now, one layer up (see
|
||||
// tlscert.go/pin.go), which in turn proves the HUB's identity to the
|
||||
// peer via certificate pinning. Neither layer replaces the other.
|
||||
package main
|
||||
|
||||
import (
|
||||
@@ -33,11 +32,11 @@ import (
|
||||
const (
|
||||
tokenBytes = 16 // 128 bits
|
||||
nonceBytes = 16
|
||||
// Plazo para autenticarse. Una conexion que se queda callada tras el
|
||||
// desafio se cierra en vez de ocupar un lugar para siempre.
|
||||
// Deadline to authenticate. A connection that goes quiet after the
|
||||
// challenge gets closed instead of holding a slot forever.
|
||||
authTimeoutSeconds = 10
|
||||
// Techo de conexiones simultaneas: evita que alguien deje el puerto
|
||||
// sin recursos abriendo sockets.
|
||||
// Cap on simultaneous connections: keeps someone from starving the
|
||||
// port of resources by opening sockets.
|
||||
maxPeerConns = 8
|
||||
)
|
||||
|
||||
@@ -56,12 +55,13 @@ func randomHex(n int) (string, error) {
|
||||
return hex.EncodeToString(b), nil
|
||||
}
|
||||
|
||||
// resolveToken decide el token efectivo. Si el config trae uno, manda ese
|
||||
// (para quien quiera elegirlo a mano o compartir uno ya acordado). Si no,
|
||||
// se usa el de token.txt, y si tampoco existe se genera uno y se guarda.
|
||||
// resolveToken decides the effective token. If the config has one, that
|
||||
// wins (for anyone who wants to pick it by hand or share a pre-agreed
|
||||
// one). Otherwise it uses the one in token.txt, generating and saving one
|
||||
// if that doesn't exist either.
|
||||
//
|
||||
// Devuelve tambien si lo acaba de generar, para avisarlo fuerte en la
|
||||
// consola: es lo que hay que pasarle al compañero.
|
||||
// Also returns whether it was just generated, so it can be announced
|
||||
// loudly on the console: that's what needs to be handed to your partner.
|
||||
func resolveToken(cfg config) (token string, generated bool, err error) {
|
||||
if t := strings.TrimSpace(cfg.Token); t != "" {
|
||||
return t, false, nil
|
||||
@@ -74,23 +74,23 @@ func resolveToken(cfg config) (token string, generated bool, err error) {
|
||||
}
|
||||
t, gerr := randomHex(tokenBytes)
|
||||
if gerr != nil {
|
||||
return "", false, fmt.Errorf("no pude generar un token: %w", gerr)
|
||||
return "", false, fmt.Errorf("couldn't generate a token: %w", gerr)
|
||||
}
|
||||
if werr := os.WriteFile(path, []byte(t), 0600); werr != nil {
|
||||
return "", false, fmt.Errorf("no pude guardar token.txt: %w", werr)
|
||||
return "", false, fmt.Errorf("couldn't save token.txt: %w", werr)
|
||||
}
|
||||
return t, true, nil
|
||||
}
|
||||
|
||||
// proofFor calcula la respuesta al desafio: HMAC-SHA256(token, nonce).
|
||||
// proofFor computes the answer to the challenge: HMAC-SHA256(token, nonce).
|
||||
func proofFor(token, nonce string) string {
|
||||
m := hmac.New(sha256.New, []byte(token))
|
||||
m.Write([]byte(nonce))
|
||||
return hex.EncodeToString(m.Sum(nil))
|
||||
}
|
||||
|
||||
// proofValid compara en tiempo constante. Con == la comparacion corta en
|
||||
// el primer byte distinto, y eso filtra informacion por tiempos.
|
||||
// proofValid compares in constant time. With == the comparison short-
|
||||
// circuits at the first differing byte, which leaks information via timing.
|
||||
func proofValid(token, nonce, got string) bool {
|
||||
want := proofFor(token, nonce)
|
||||
return subtle.ConstantTimeCompare([]byte(want), []byte(got)) == 1
|
||||
@@ -98,8 +98,8 @@ func proofValid(token, nonce, got string) bool {
|
||||
|
||||
func logTokenBanner(token string, generated bool) {
|
||||
if generated {
|
||||
log.Printf("generé un token nuevo y lo guardé en token.txt")
|
||||
log.Printf("generated a new token and saved it to token.txt")
|
||||
}
|
||||
log.Printf("token de conexion: %s", token)
|
||||
log.Printf("tu compañero tiene que poner ESE token en su config.toml; sin el, su conexion se rechaza")
|
||||
log.Printf("connection token: %s", token)
|
||||
log.Printf("your partner needs to put THAT exact token in their config.toml; without it, their connection gets rejected")
|
||||
}
|
||||
Reference in new issue
Block a user