Translate remaining Go source and overlay.html comments to English

Identifiers, comments, and log/console messages in auth.go, i18n.go,
counter.go, totals.go, and overlay.html's script/CSS comments — the
files the TLS commit didn't already touch. No functional changes.

locales/*.json and overlay.html's own FALLBACK/data-i18n strings stay
bilingual on purpose: that's end-user text for the overlay/panel, a
different audience than the source code, served by the existing i18n
system rather than this convention.
This commit is contained in:
emmatherock committed 2026-09-17 21:51:33 -03:00
1 parent e9fe10f0f7
commit 5a2c3272e9
7 files changed
+213 -211

No files matched your search

+31 -31
View File
@@ -1,20 +1,19 @@
// auth.go: autenticacion entre el hub y los peers.
// auth.go: authentication between the hub and its peers.
//
// El transporte NO se asume confiable. Puede ser Tailscale, ZeroTier,
// WireGuard, o un puerto abierto directo a internet: eso lo decide quien
// lo usa, no nosotros. Asi que la conexion se defiende sola.
// The transport is NOT assumed trustworthy. It could be Tailscale,
// ZeroTier, WireGuard, or a port opened straight to the internet: that's
// up to whoever runs it, not us. So the connection defends itself.
//
// El token es OBLIGATORIO y lo genera el programa (nadie elige "1234"), y
// nunca viaja por la red: el hub manda un desafio al azar y el peer
// responde con un HMAC del desafio usando el token como clave. Quien
// escuche el trafico no se lleva el token, y no puede repetir una
// respuesta vieja porque el desafio cambia en cada conexion.
// The token is REQUIRED and generated by the program (nobody gets to pick
// "1234"), and it never travels over the network: the hub sends a random
// challenge and the peer replies with an HMAC of it, keyed by the token.
// Anyone listening to the traffic doesn't get the token, and can't replay
// an old response because the challenge changes on every connection.
//
// Lo que esto NO hace: cifrar. Los mensajes (nombre y numero de muertes)
// viajan en claro. Para un contador de muertes en un stream es
// aceptable, pero si te importa, poné la conexion adentro de una VPN o
// un tunel con TLS. Lo que el token garantiza es que nadie pueda
// INYECTAR datos falsos en tu overlay.
// This proves the PEER's identity to the hub. It doesn't encrypt
// anything by itself — that's TLS's job now, one layer up (see
// tlscert.go/pin.go), which in turn proves the HUB's identity to the
// peer via certificate pinning. Neither layer replaces the other.
package main
import (
@@ -33,11 +32,11 @@ import (
const (
tokenBytes = 16 // 128 bits
nonceBytes = 16
// Plazo para autenticarse. Una conexion que se queda callada tras el
// desafio se cierra en vez de ocupar un lugar para siempre.
// Deadline to authenticate. A connection that goes quiet after the
// challenge gets closed instead of holding a slot forever.
authTimeoutSeconds = 10
// Techo de conexiones simultaneas: evita que alguien deje el puerto
// sin recursos abriendo sockets.
// Cap on simultaneous connections: keeps someone from starving the
// port of resources by opening sockets.
maxPeerConns = 8
)
@@ -56,12 +55,13 @@ func randomHex(n int) (string, error) {
return hex.EncodeToString(b), nil
}
// resolveToken decide el token efectivo. Si el config trae uno, manda ese
// (para quien quiera elegirlo a mano o compartir uno ya acordado). Si no,
// se usa el de token.txt, y si tampoco existe se genera uno y se guarda.
// resolveToken decides the effective token. If the config has one, that
// wins (for anyone who wants to pick it by hand or share a pre-agreed
// one). Otherwise it uses the one in token.txt, generating and saving one
// if that doesn't exist either.
//
// Devuelve tambien si lo acaba de generar, para avisarlo fuerte en la
// consola: es lo que hay que pasarle al compañero.
// Also returns whether it was just generated, so it can be announced
// loudly on the console: that's what needs to be handed to your partner.
func resolveToken(cfg config) (token string, generated bool, err error) {
if t := strings.TrimSpace(cfg.Token); t != "" {
return t, false, nil
@@ -74,23 +74,23 @@ func resolveToken(cfg config) (token string, generated bool, err error) {
}
t, gerr := randomHex(tokenBytes)
if gerr != nil {
return "", false, fmt.Errorf("no pude generar un token: %w", gerr)
return "", false, fmt.Errorf("couldn't generate a token: %w", gerr)
}
if werr := os.WriteFile(path, []byte(t), 0600); werr != nil {
return "", false, fmt.Errorf("no pude guardar token.txt: %w", werr)
return "", false, fmt.Errorf("couldn't save token.txt: %w", werr)
}
return t, true, nil
}
// proofFor calcula la respuesta al desafio: HMAC-SHA256(token, nonce).
// proofFor computes the answer to the challenge: HMAC-SHA256(token, nonce).
func proofFor(token, nonce string) string {
m := hmac.New(sha256.New, []byte(token))
m.Write([]byte(nonce))
return hex.EncodeToString(m.Sum(nil))
}
// proofValid compara en tiempo constante. Con == la comparacion corta en
// el primer byte distinto, y eso filtra informacion por tiempos.
// proofValid compares in constant time. With == the comparison short-
// circuits at the first differing byte, which leaks information via timing.
func proofValid(token, nonce, got string) bool {
want := proofFor(token, nonce)
return subtle.ConstantTimeCompare([]byte(want), []byte(got)) == 1
@@ -98,8 +98,8 @@ func proofValid(token, nonce, got string) bool {
func logTokenBanner(token string, generated bool) {
if generated {
log.Printf("generé un token nuevo y lo guardé en token.txt")
log.Printf("generated a new token and saved it to token.txt")
}
log.Printf("token de conexion: %s", token)
log.Printf("tu compañero tiene que poner ESE token en su config.toml; sin el, su conexion se rechaza")
log.Printf("connection token: %s", token)
log.Printf("your partner needs to put THAT exact token in their config.toml; without it, their connection gets rejected")
}