From fda55a6ff04998d8ac9b8c312f6d2f3b462359a9 Mon Sep 17 00:00:00 2001 From: Nulled <63370961+Nul-led@users.noreply.github.com> Date: Sat, 26 Sep 2026 08:58:59 +0200 Subject: [PATCH 1/4] chore: Enhance Privacy --- client/config.js | 2 ++ client/loader.js | 55 +++++++++++++++++++++++++++++++++++++++++++++++- 2 files changed, 56 insertions(+), 1 deletion(-) diff --git a/client/config.js b/client/config.js index ec7bc023..2980a697 100644 --- a/client/config.js +++ b/client/config.js @@ -17,6 +17,8 @@ */ const BUILD = "6f59094d60f98fafc14371671d3ff31ef4d75d9e"; +// Update this SHA-512 pin whenever BUILD changes. +const BUILD_INTEGRITY = "sha512-wMsIkGuT5cbZoZqnzqJIRXmTOE1Tn4KP/XdiF40XobfJ6XVrgaiQNduF5USHoaut5p+X6a5rswWq8O4Ia9qXRw=="; const CDN = "https://static.diep.io/"; const API_URL = `${window.location.href}api/`; diff --git a/client/loader.js b/client/loader.js index f6f000e0..68865e27 100644 --- a/client/loader.js +++ b/client/loader.js @@ -337,7 +337,60 @@ Module.todo.push([() => { Module.status = "FETCH"; // fetch necessary info and build return [ - fetch(`${CDN}build_${BUILD}.wasm.wasm`).then(res => res.arrayBuffer()), + (async () => { + const url = `${CDN}build_${BUILD}.wasm.wasm`; + let cache; + try { + cache = await caches.open("diepcustom-wasm-v1"); + const hit = await cache.match(url); + if (hit) { + const buffer = await hit.arrayBuffer(); + const hash = await crypto.subtle.digest("SHA-512", buffer); + if (`sha512-${btoa(String.fromCharCode(...new Uint8Array(hash)))}` === BUILD_INTEGRITY) return buffer; + await cache.delete(url); + } + } catch (_) { /* Cache Storage may be unavailable. */ } + + // A sandboxed frame sends Origin: null instead of the site's origin. + const buffer = await new Promise((resolve, reject) => { + const frame = document.createElement("iframe"); + frame.hidden = true; + frame.setAttribute("sandbox", "allow-scripts"); + const finish = data => { + clearTimeout(timer); + window.removeEventListener("message", onMessage); + frame.remove(); + if (data instanceof ArrayBuffer) resolve(data); + else reject(new Error(data?.error || "WASM fetch failed")); + }; + const onMessage = event => { + if (event.source === frame.contentWindow && event.origin === "null") finish(event.data); + }; + const timer = setTimeout(() => finish({ error: "WASM fetch timed out" }), 60000); + window.addEventListener("message", onMessage); + frame.srcdoc = `