ludic/ns-crypto.html
2026-09-17 22:10:03 +00:00

28 lines
No EOL
5 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Crypto — Ludic</title>
<meta name="description" content="Secure, test-vector-backed hashing for the handful of security-sensitive things a game actually does: signing a save or leaderboard payload so casual tampering…">
<link rel="stylesheet" href="base.css">
<link rel="stylesheet" href="docs.css">
</head>
<body>
<header class="nav"><div class="wrap nav-in"><a class="brand" href="index.html"><span class="logo">L</span> Ludic</a><button class="nav-toggle" aria-label="Toggle menu" aria-expanded="false">☰</button><nav class="nav-links"><a href="index.html">Home</a><a href="api.html">API Reference</a><a class="nav-cta" href="https://git.workshopsoft.io/workshopsoft/ludic">Source ↗</a></nav></div></header>
<main class="wrap item">
<div class="crumbs"><a href="api.html">API Reference</a> <span>›</span> <span class="here">Crypto</span></div>
<div class="item-head"><span class="kind-badge kind-namespace">namespace</span><h1 id="top">Crypto</h1></div>
<p class="ns-blurb">Secure, test-vector-backed hashing for the handful of security-sensitive things a game actually does: signing a save or leaderboard payload so casual tampering is detectable, and verifying that a network message or token was not forged by someone who does not hold the key. This is the deliberate counterpart to the fast <a href="ns-Hash"><code>Hash</code></a> library — same idea, opposite trade-off. <code>Hash</code> is fast and reversible and must never guard anything; <code>Crypto</code> is <a href="crypto-sha256"><code>SHA-256</code></a> and <a href="crypto-hmac_sha256"><code>HMAC-SHA256</code></a> implemented to the standard, so the algorithms are the ones with published known-answer tests rather than anything home-grown.
Digests are returned as lowercase hex strings, not raw bytes — a <code>str</code> is null-terminated and a raw digest can contain a zero byte, so hex is the form you can print, store, and compare directly.
Alongside hashing, this library exposes the OS cryptographically-secure random generator — <a href="crypto-random_bytes"><code>random_bytes</code></a>, <a href="crypto-random_hex"><code>random_hex</code></a>, and <a href="crypto-random_u32"><code>random_u32</code></a> — for tokens, nonces, and <a href="ns-Uuid"><code>Uuid</code></a> generation, plus <a href="crypto-base64"><code>base64</code></a> for moving bytes through text-only channels. The secure-random helpers are deliberately non-deterministic and must never seed the lockstep simulation RNG (<a href="ns-Random"><code>Random</code></a>).
What this is not: it is not DRM and it is not unbeatable anti-cheat. A client-side game cannot keep a secret from the machine it runs on — a determined owner can always read the key out of the binary. Use it to make *casual* tampering detectable and to authenticate messages between parties who share a key. To verify a MAC always use <a href="crypto-verify_hmac"><code>Crypto.verify_hmac</code></a> (a constant-time check), never <code>==</code>, which leaks how much of a guessed MAC was correct.</p>
<div class="ns-methods"><a class="ns-method" href="crypto-sha256.html"><code class="nm-sig">Crypto.sha256(s) -&gt; string</code><span class="nm-tip">SHA-256 of a string, as 64 hex characters.</span></a><a class="ns-method" href="crypto-hmac_sha256.html"><code class="nm-sig">Crypto.hmac_sha256(key, msg) -&gt; string</code><span class="nm-tip">Sign a message with a shared secret key.</span></a><a class="ns-method" href="crypto-verify_hmac.html"><code class="nm-sig">Crypto.verify_hmac(key, msg, mac) -&gt; bool</code><span class="nm-tip">Constant-time check that a MAC matches.</span></a><a class="ns-method" href="crypto-hex.html"><code class="nm-sig">Crypto.hex(s) -&gt; string</code><span class="nm-tip">Lowercase hex of a string's bytes.</span></a><a class="ns-method" href="crypto-ct_equal.html"><code class="nm-sig">Crypto.ct_equal(a, b) -&gt; bool</code><span class="nm-tip">Constant-time string equality for secrets.</span></a><a class="ns-method" href="crypto-random_bytes.html"><code class="nm-sig">Crypto.random_bytes(n) -&gt; string</code><span class="nm-tip">n bytes from the OS CSPRNG, as a 2n-character hex string.</span></a><a class="ns-method" href="crypto-random_hex.html"><code class="nm-sig">Crypto.random_hex(n) -&gt; string</code><span class="nm-tip">Alias for random_bytes — n secure bytes as a 2n-char hex string.</span></a><a class="ns-method" href="crypto-random_u32.html"><code class="nm-sig">Crypto.random_u32() -&gt; int</code><span class="nm-tip">One CSPRNG-drawn 32-bit integer.</span></a><a class="ns-method" href="crypto-base64.html"><code class="nm-sig">Crypto.base64(s) -&gt; string</code><span class="nm-tip">Standard base64 (RFC 4648) of a string's bytes.</span></a></div>
<a class="back" href="api.html">← All symbols</a>
</main>
<script src="ludic-highlight.js"></script>
<script>Ludic.installCards(); Ludic.flashTarget();</script>
</body></html>