EN

@core / antispam

1.1.0 ▾
verifiedMIT
GitHub

Spam protection for public forms: honeypot, signed timing, Turnstile or hCaptcha and Postgres rate limits

Code9 filesContext~722 tokensscan passed

The exact tree that will be injected, after .genpmignore. Pinned to

src/lib/antispam/crypto.tsread-only · 0328b98
// Utilidades criptográficas con Web Crypto (Node, Workers y navegador).
const enc = new TextEncoder();

const hex = (buf: ArrayBuffer) => [...new Uint8Array(buf)].map((b) => b.toString(16).padStart(2, '0')).join('');

export async function sha256Hex(data: string): Promise<string> {
  return hex(await crypto.subtle.digest('SHA-256', enc.encode(data)));
}

export async function hmacHex(secret: string, data: string): Promise<string> {
  const key = await crypto.subtle.importKey('raw', enc.encode(secret), { name: 'HMAC', hash: 'SHA-256' }, false, ['sign']);
  return hex(await crypto.subtle.sign('HMAC', key, enc.encode(data)));
}

export function safeEqual(a: string, b: string): boolean {
  let d = a.length ^ b.length;
  for (let i = 0; i < Math.max(a.length, b.length); i++) d |= (a.charCodeAt(i) || 0) ^ (b.charCodeAt(i) || 0);
  return d === 0;
}

Report @core/antispam

Sign in with GitHub to report a package.