Cockatrice/libcockatrice_utility/libcockatrice/utility
Lukas Brübach 709233d977
[Security] Add challenge-response auth with scrypt verifiers and stop storing plaintext passwords
Challenge-response authentication: the client derives a scrypt verifier
(RFC 7914, EVP_PBE_scrypt, N=32768, r=8, p=1) and authenticates with
HMAC-SHA256(key, nonce), so neither the password nor its hash is
transmitted. The stored format becomes
"$scrypt$<n>$<r>$<p>$<salt>$<verifier>" and Response_PasswordSalt
now carries the cost parameters. Strict servers only accept scrypt
verifiers; legacy accounts are migrated after a successful login.

Fix #344 for challenge-response servers: a saved profile stores the
derived verifier under the password key instead of the plaintext password.
The connect dialog loads it without revealing it, autoconnect passes it
through, the change-password dialog no longer prefills the old password
field with it, and the client only persists the verifier when
"Save password" is checked.

Took 3 minutes

Took 1 minute

Took 10 seconds

Took 7 minutes
2026-09-06 16:16:22 +02:00
..
card_ref.h [DeckList] Move metadata into struct (#6380) 2025-11-30 13:09:09 +01:00
clamped_arithmetic.h Unify counter clamp arithmetic into shared addClamped() helper (#7009) 2026-06-28 16:10:57 -07:00
color.h [Game][Counters] Split counters into AbstractCounter (graphics) and CounterState (logic) (#6917) 2026-05-21 20:16:28 +02:00
counter_limits.h Split trice_limits.h into dedicated headers (#7025) 2026-06-29 14:37:52 -07:00
cryptoutil.cpp [Security] Use a CSPRNG for salts, tokens, and RNG seeding (#7192) 2026-09-04 13:49:18 +02:00
cryptoutil.h [Security] Use a CSPRNG for salts, tokens, and RNG seeding (#7192) 2026-09-04 13:49:18 +02:00
days_years_between.h [Room][UserList] Introduce style delegate (#6981) 2026-06-26 20:52:24 -04:00
dice_limits.h Split trice_limits.h into dedicated headers (#7025) 2026-06-29 14:37:52 -07:00
expression.cpp style: Add braces to all control flow statements (#6887) 2026-05-16 19:19:53 +02:00
expression.h Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
levenshtein.cpp style: Add braces to all control flow statements (#6887) 2026-05-16 19:19:53 +02:00
levenshtein.h Standardize Doxygen documentation (#6885) 2026-05-21 22:58:07 +02:00
macros.h Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
passwordhasher.cpp [Security] Add challenge-response auth with scrypt verifiers and stop storing plaintext passwords 2026-09-06 16:16:22 +02:00
passwordhasher.h [Security] Add challenge-response auth with scrypt verifiers and stop storing plaintext passwords 2026-09-06 16:16:22 +02:00
peglib.h Update peglib to v1.16.0 (#7134) 2026-08-17 22:52:30 +02:00
playmat_params.h [Game] Playmats (#7101) 2026-08-21 10:40:49 +02:00
qt_utils.h Add subtype breakdown counter for card selection (#6923) 2026-06-27 15:53:21 -07:00
server_rate_limiter.cpp [PictureLoader] Schedule exponential backoff on 429 - Too many request handler and call failed on fail (#7053) 2026-08-08 22:55:27 +02:00
server_rate_limiter.h [PictureLoader] Schedule exponential backoff on 429 - Too many request handler and call failed on fail (#7053) 2026-08-08 22:55:27 +02:00
string_limits.h [Server/Client/Protocol] Reporting users + moderation queue functionality (#7091) 2026-08-21 15:00:13 +02:00
warning_categories.cpp [Server/Client/Protocol] Reporting users + moderation queue functionality (#7091) 2026-08-21 15:00:13 +02:00
warning_categories.h [Server/Client/Protocol] Reporting users + moderation queue functionality (#7091) 2026-08-21 15:00:13 +02:00
zone_names.h Refactor zone names (#6686) 2026-03-12 00:34:05 +01:00