From 81ebd267c89011ca65cd5cfe382e10fabd9017ac Mon Sep 17 00:00:00 2001 From: Yigit Sever Date: Mon, 19 Apr 2021 18:21:06 +0300 Subject: Moving site to separate repo --- site/config.toml | 28 --- site/content/JWT.md | 41 ---- site/content/_index.md | 98 --------- site/content/block_docs.md | 43 ---- site/content/misc_docs.md | 17 -- site/content/register_docs.md | 54 ----- site/content/transaction_docs.md | 52 ----- site/public/404.html | 3 - site/public/android-chrome-192x192.png | Bin 26249 -> 0 bytes site/public/android-chrome-512x512.png | Bin 80376 -> 0 bytes site/public/apple-touch-icon.png | Bin 24023 -> 0 bytes site/public/block-docs/index.html | 190 ----------------- site/public/elasticlunr.min.js | 10 - site/public/favicon-16x16.png | Bin 878 -> 0 bytes site/public/favicon-32x32.png | Bin 2463 -> 0 bytes site/public/favicon.ico | Bin 15406 -> 0 bytes site/public/gradecoin.png | Bin 197656 -> 0 bytes site/public/gradecoin.pub | 9 - site/public/index.html | 362 -------------------------------- site/public/juice.css | 1 - site/public/jwt/index.html | 182 ---------------- site/public/misc-docs/index.html | 155 -------------- site/public/normalize.css | 349 ------------------------------ site/public/register-docs/index.html | 198 ----------------- site/public/robots.txt | 3 - site/public/search_index.en.js | 1 - site/public/site.css | 57 ----- site/public/sitemap.xml | 21 -- site/public/transaction-docs/index.html | 196 ----------------- site/static/android-chrome-192x192.png | Bin 26249 -> 0 bytes site/static/android-chrome-512x512.png | Bin 80376 -> 0 bytes site/static/apple-touch-icon.png | Bin 24023 -> 0 bytes site/static/favicon-16x16.png | Bin 878 -> 0 bytes site/static/favicon-32x32.png | Bin 2463 -> 0 bytes site/static/favicon.ico | Bin 15406 -> 0 bytes site/static/gradecoin.png | Bin 197656 -> 0 bytes site/static/gradecoin.pub | 9 - site/static/site.css | 57 ----- site/templates/_variables.html | 15 -- site/templates/index.html | 68 ------ site/templates/shortcodes/exp.html | 1 - site/templates/shortcodes/tidbit.html | 5 - site/themes/juice | 1 - 43 files changed, 2226 deletions(-) delete mode 100644 site/config.toml delete mode 100644 site/content/JWT.md delete mode 100644 site/content/_index.md delete mode 100644 site/content/block_docs.md delete mode 100644 site/content/misc_docs.md delete mode 100644 site/content/register_docs.md delete mode 100644 site/content/transaction_docs.md delete mode 100644 site/public/404.html delete mode 100644 site/public/android-chrome-192x192.png delete mode 100644 site/public/android-chrome-512x512.png delete mode 100644 site/public/apple-touch-icon.png delete mode 100644 site/public/block-docs/index.html delete mode 100644 site/public/elasticlunr.min.js delete mode 100644 site/public/favicon-16x16.png delete mode 100644 site/public/favicon-32x32.png delete mode 100644 site/public/favicon.ico delete mode 100644 site/public/gradecoin.png delete mode 100644 site/public/gradecoin.pub delete mode 100644 site/public/index.html delete mode 100644 site/public/juice.css delete mode 100644 site/public/jwt/index.html delete mode 100644 site/public/misc-docs/index.html delete mode 100644 site/public/normalize.css delete mode 100644 site/public/register-docs/index.html delete mode 100644 site/public/robots.txt delete mode 100644 site/public/search_index.en.js delete mode 100644 site/public/site.css delete mode 100644 site/public/sitemap.xml delete mode 100644 site/public/transaction-docs/index.html delete mode 100644 site/static/android-chrome-192x192.png delete mode 100644 site/static/android-chrome-512x512.png delete mode 100644 site/static/apple-touch-icon.png delete mode 100644 site/static/favicon-16x16.png delete mode 100644 site/static/favicon-32x32.png delete mode 100644 site/static/favicon.ico delete mode 100644 site/static/gradecoin.png delete mode 100644 site/static/gradecoin.pub delete mode 100644 site/static/site.css delete mode 100644 site/templates/_variables.html delete mode 100644 site/templates/index.html delete mode 100644 site/templates/shortcodes/exp.html delete mode 100644 site/templates/shortcodes/tidbit.html delete mode 160000 site/themes/juice (limited to 'site') diff --git a/site/config.toml b/site/config.toml deleted file mode 100644 index 070b762..0000000 --- a/site/config.toml +++ /dev/null @@ -1,28 +0,0 @@ -# The URL the site will be built for -base_url = "https://gradecoin.xyz" - -theme = "juice" - -title = "Gradecoin" -description = "Mine Your Grades" - -# Whether to automatically compile all Sass files in the sass directory -compile_sass = true - -# Whether to build a search index to be used later on by a JavaScript library -build_search_index = true - -[markdown] -# Whether to do syntax highlighting -# Theme can be customised by setting the `highlight_theme` variable to a theme supported by Zola -highlight_code = true -highlight_theme = "subway-moscow" - -[extra] -# Put all your custom variables here -juice_logo_name = "Gradecoin" -juice_logo_path = "gradecoin.png" -juice_extra_menu = [ - { title = "why?", link = "https://github.com/zhuowei/nft_ptr#why"} -] - diff --git a/site/content/JWT.md b/site/content/JWT.md deleted file mode 100644 index 46da1a2..0000000 --- a/site/content/JWT.md +++ /dev/null @@ -1,41 +0,0 @@ -+++ -title = "JWT" -description = "JSON Web Token Documentation" -weight = 4 -+++ - -> JSON Web Tokens are representations of claims, or authorization proofs that fit into the `Header` of HTTP requests. - -# How? - -JWTs are used as the [MAC](https://en.wikipedia.org/wiki/Message_authentication_code) of operations that require authorization: -- block proposal -- transaction proposal. - -They are send alongside the JSON request body in the `Header`; - -```html -Authorization: Bearer aaaaaa.bbbbbb.ccccc -``` - -Gradecoin uses 3 fields for the JWTs; - -```json -{ -"tha": "Hash of the payload, check invididual references", -"iat": "Issued At, Unix Time", -"exp": "Expiration Time, epoch" -} -``` - -- `tha` is explained in [blocks](@/block_docs.md) and [transactions](@/transaction_docs.md) documentations. -- `iat` when the JWT was created in [Unix Time](https://en.wikipedia.org/wiki/Unix_time) format -- `exp` when the JWT will expire & be rejected in [Unix Time](https://en.wikipedia.org/wiki/Unix_time) - -# Algorithm -We are using [RS256](https://www.rfc-editor.org/rfc/rfc7518.html#section-3.1), `RSASSA-PKCS1-v1_5 using SHA-256`. The JWTs you encode with your private RSA key will be decoded using the public key you have authenticated with. You can see how the process works [here](https://jwt.io/). - -# References -- [RFC, the ultimate reference](https://tools.ietf.org/html/rfc7519) -- [JWT Debugger](https://jwt.io/) - diff --git a/site/content/_index.md b/site/content/_index.md deleted file mode 100644 index d0be673..0000000 --- a/site/content/_index.md +++ /dev/null @@ -1,98 +0,0 @@ -+++ -title = "Gradecoin" -sort_by = "weight" -+++ - -# Welcome to Gradecoin! - -Blockchains are incredibly simple yet can appear very complicated, we will see how they work and practice programming _production_ cryptography code. - -This server is the sandbox for the PA1, it's currently running the Gradecoin application. Gradecoin is the faux currency we will use to simulate a blockchain network. At the end of the simulation, the amount of Gradecoin you hold will be your PA1 grade. - -**A quick summary**: authenticate yourself to the system using public key encryption. -Craft [Transaction](@/transaction_docs.md) proposals and tag them using [JWTs](@/JWT.md). -When there are enough transactions then you can propose [Blocks](@/block_docs.md) in the same way. -Blocks need to be _mined_ beforehand using Proof-of-work, or brute force. - -Gradecoin offers 3 endpoints at [/register](/register), [/block](/block) and [/transaction](/transaction). You can only send GET requests to /block and /transaction without authorization. -The server is programmed in [RESTful](https://www.service-architecture.com/articles/web-services/representational_state_transfer_rest.html) architecture, there are no `DELETE`, `PUT` or `UPDATE` operations, though. - -Gradecoin uses a Proof-of-work block accepting mechanism. It uses single round [Blake2s](https://www.blake2.net/) hashing which produces 256-bit (64 hexadecimal characters) output. The [target](https://wiki.bitcoinsv.io/index.php/Target) hash is _24 bits_ or _6 hexadecimal characters_ of 0. During testing, I could mine a block on average around 4-6 minutes. - -> We're expecting you to use existing tools and implementations. Standards are hard. [Don't roll your own crypto](https://www.reddit.com/r/crypto/comments/2coqsy/dont_roll_your_own/). Feel free to ask questions. Collaborate. - -You might ask, - -> But if nobody has any Gradecoin then how do we have transactions? - -There is a bank! Their public key is `31415926535897932384626433832795028841971693993751058209749445923` and they have some amount of Gradecoin preloaded. It's also the only account that you can send transactions requests _to_ yourself. - -# Coinbase -The first transactions of a block is called the `coinbase`. They are the **author** of the block proposal and if the block is accepted then they get compensated for their efforts with some Gradecoin. - -# Public Key Signatures -Gradecoin uses 2048 bit RSA keypairs. - -# Services -## /register -- Create your own 2048 bit RSA `keypair` -- Download `Gradecoin`'s Public Key from [Moodle](https://odtuclass.metu.edu.tr/my/) -- Encrypt your [JSON](https://www.json.org/json-en.html) wrapped `Public Key`, `Student ID` and one time `passwd` using Gradecoin's Public Key -- Your public key is now in our database and can be used to sign your JWT's during requests -- For more information, check the [register](@/register_docs.md) page - -## /transaction -- You can offer a [Transaction](@/transaction_docs.md) with a POST request - - The request should have `Authorization` - - The request header should be signed by the Public Key of the `by` field in the transaction -- Fetch the list of `Transaction`s with a GET request -- For more information, check our [transaction](@/transaction_docs.md) page - -## /block -- Offer a [Block](@/block_docs.md) with a POST request - - The request should have `Authorization` - - The `transaction_list` of the block should be a subset of pending transactions, available on [/transaction](/transaction) -- Fetch the last accepted `Block` with a GET request -- For more information, check our [block](@/block_docs.md) page - - `Authorization`: The request header should have Bearer JWT.Token signed with Student Public Key - -## /user -- Meant to be used in the browser, you can see the current list of users and their balance here - -# Questions -## This all sound complicated! -- I've drawn inspiration from [actual Bitcoin transactions](https://explorer.bitcoin.com/btc) and [warp](https://github.com/seanmonstar/warp/blob/master/examples/todos.rs). The simplicity of the system is how little interfaces it has. -- Don't know where to start? Gradecoin uses RESTful API; simple `curl` commands or even your browser will work! [This website can help as well](https://curl.trillworks.com/). -- [JWT Debugger](https://jwt.io) and the corresponding [RFC](https://tools.ietf.org/html/rfc7519). -- Remember that you are absolutely encouraged to grab off-the-shelf implementations for every cryptography primitive you will use. You can start by finding a code snippet to generate a RSA keypair? -- Check out [misc](@/misc_docs.md) for everything else you might be curious about. - -## How do you actually earn Gradecoin? -- Register yourself to at [/register](@/register_docs.md) -- Create transactions at [/transaction](@/transaction_docs.md) -- Create blocks to commit transactions at [/block](@/block_docs.md) -- See how everyone is doing and find people to trade with at [/user](/user) - -## I found a bug! -Thank you! Please [let me know](mailto:yigit@ceng.metu.edu.tr) so we can solve it. - -## I hacked the server! -That wasn't supposed to happen :( I did not place any intentional vulnerabilities to the system so if you cracked something, it was not intended. Please don't abuse it and let me know so I can patch it. - -## Submission? -At the end of the _simulation_, your Gradecoin balance will be your grade. I will also expect a unique client programmed in either; -- c -- c++ -- perl -- rust -- python -- random assortment of bash scripts - -If your favourite programming language is missing please let me know 🤷? - -## Can my friends play? -Sadly, no. Student's who are enrolled to the class will receive one-time-passwords for authentication. - -## How and or Why? -- [Built](https://xkcd.com/2314/), [with](https://lofi.cafe/) [Rust](https://xkcd.com/2418/) diff --git a/site/content/block_docs.md b/site/content/block_docs.md deleted file mode 100644 index 92880b6..0000000 --- a/site/content/block_docs.md +++ /dev/null @@ -1,43 +0,0 @@ -+++ -title = "Blocks" -description = "Block Documentation" -weight = 10 -+++ - -A block that was proposed to commit Transactions in `transaction_list` to the -ledger with a nonce that made `hash` valid; 6 zeroes at the left hand side of the -hash (24 bytes). - -We are _mining_ using [blake2s](https://www.blake2.net/) algorithm, which produces 256 bit hashes. Hash/second is roughly {{ exp(num="20x10", exponent="3") }} on my machine, a new block can be mined in around 4-6 minutes. - -# Requests - -## GET -A HTTP `GET` request to [/block](/block) endpoint will return the latest mined block. - -## POST - -A HTTP `POST` request with Authorization using JWT will allow you to propose your own blocks. - -# Fields -``` -transaction_list: [array of Fingerprints] -nonce: unsigned 32-bit integer -timestamp: ISO 8601 T