diff --git a/documentation/audits/visitors-2026-10-01/C/C0-license.txt b/documentation/audits/visitors-2026-10-01/C/C0-license.txt new file mode 100644 index 00000000..3cba1b3d --- /dev/null +++ b/documentation/audits/visitors-2026-10-01/C/C0-license.txt @@ -0,0 +1,75 @@ +# SparkyFitness LICENSE at main, fetched 2026-10-01T20:14:42Z from raw.githubusercontent.com/CodeWithCJ/SparkyFitness/main/LICENSE (GitHub API spdx: NOASSERTION) +Copyright (c) 2025–present codewithcj + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to use, +copy, modify, and distribute the Software for **non-commercial purposes only**, +subject to the following conditions: + +1. Non-Commercial Use Only + The Software may not be used, directly or indirectly, in any product, service, + or project primarily intended for or resulting in commercial advantage or + monetary compensation, without prior written permission from the author. + Non-commercial use includes personal, educational, or nonprofit activities, + provided they do not generate revenue. + +2. Modifications & Derivative Works + You may modify the Software or create derivative works for non-commercial + purposes. Derivative works are any modified versions of the Software or new + works that incorporate substantial portions of it. All derivative works + must also be licensed under these same non-commercial terms unless + explicitly approved in writing by the author. + +3. Distribution + You may distribute the Software or derivative works for non-commercial + purposes, provided that all copies include this copyright notice and + license in their entirety. + +4. Attribution + This copyright notice and license must be included in all copies or + substantial portions of the Software. + +5. No Warranty + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT. IN NO EVENT SHALL + THE AUTHOR BE LIABLE FOR ANY CLAIM, DAMAGES, OR OTHER LIABILITY ARISING FROM + THE USE OF THE SOFTWARE. + +6. Contributor Assignment + By submitting any code, documentation, or other contributions (the + "Contribution") to this project, you hereby assign **all** right, title, + and interest in the Contribution to the original author (codewithcj). You + waive any claim of ownership or compensation for your Contribution, and + acknowledge that contributions do not grant the contributor any rights to + use the Software commercially. + +7. Termination + This license terminates automatically if you breach any of its terms, + including using the Software for commercial purposes without permission. + Upon termination, you must cease all use and distribution of the Software + and destroy all copies in your possession. + +--- + +For commercial use, licensing, or partnership inquiries, please contact the author: +https://github.com/codewithcj + +> **Note:** “codewithcj” refers to the GitHub handle of the original author. + +# git log of LICENSE (newest first) +2025-07-12T17:41:35Z 475a7ec08d WIP Meal & Meal Plan Features +2025-06-21T20:59:58Z eb491dfe42 License update +# LICENSE at the pinned tag v0.17.3: +Copyright (c) 2025–present codewithcj + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to use, +copy, modify, and distribute the Software for **non-commercial purposes only**, +subject to the following conditions: + +1. Non-Commercial Use Only + The Software may not be used, directly or indirectly, in any product, service, + or project primarily intended for or resulting in commercial advantage or + monetary compensation, without prior written permission from the author. + Non-commercial use includes personal, educational, or nonprofit activities, diff --git a/documentation/audits/visitors-2026-10-01/C/box/sparky-box.txt b/documentation/audits/visitors-2026-10-01/C/box/sparky-box.txt index cac05030..fefb340f 100644 --- a/documentation/audits/visitors-2026-10-01/C/box/sparky-box.txt +++ b/documentation/audits/visitors-2026-10-01/C/box/sparky-box.txt @@ -1 +1,36 @@ ##### SparkyFitness on 9202 — controller gitea.dooplex.hu/admin/felhom-controller:0.286.1 | catalog ca144ea b | 2026-10-01T20:05:23Z +deploy -> True (66 s to `deployed`) +4.3 every container healthy 69 s after the press; restarts: sparkyfitness=0 sparkyfitness-server=0 sparkyfitness-db=0 | state: running +3.3 before the setup, a stranger (LAN) on / , /api/auth/sign-up/email: 302 401 + sparkyfitness: sign-up http=200 + sparkyfitness: check-in http=200 + sparkyfitness: seeded user drill3760ab with a weight of 62.03 on 2026-09-01 +3.1 the household's first account through the gate -> ok +3.5 a stranger's 77 sign-up tries (1/s) from the press until the household's account: codes {'404': 56, '401': 21}; any 200: False +the household presses 'Done, I set it up' -> 200 +3.4 lock record: setup_gate: | state: open | since: "2026-10-01T20:05:26Z" | hosts: | - sparky.enkisfelhom.hu | opened_at: "2026-10-01T20:06:47Z" | opened_by: household | native_lock: applied | after_setup: | app env SPARKY_FITNESS_DISABLE_SIGNUP = true +3.4 a stranger signs up at /api/auth/sign-up/email (LAN) -> 403 +3.4 a stranger signs up at /API/Auth/Sign-Up/email (LAN) -> 403 +3.4 a stranger signs up at //api//auth/sign-up/email (LAN) -> 403 +3.4 the same straight at the server (behind the block — the app's own switch): 000 +3.9 browser-shaped sign-in (Origin, JSON) right / wrong: 200 401 +3.6 waiting 20 s (better-auth's own window) +3.6 stranger 198.51.100.66, 8 wrong sign-ins for the household's e-mail, a new forged leftmost each: ['401', '401', '401', '429', '429', '401', '401', '401'] +3.6 the household from 203.0.113.10, right password, from the stranger's last try on (s, code): [(3, '429'), (10, '429'), (16, '200')] +1.5 processes: sparkyfitness-server: node ./node_modules/.bin/../tsx/dist/cli.mjs index.ts +sparkyfitness: nginx: master process nginx -g daemon off; +1.8 an unknown page -> 200 | an unknown API -> 401 +0.4 outbound hosts named in the server's first-start log: ['dotenvx.com', 'sparky.enkisfelhom.hu'] +4.4 sparkyfitness-server STOPPED — states (s, state): [(5, 'running'), (10, 'degraded')]; the front door / -> 200 ; /api/health -> 000 + running again 20 s after docker start +2.7 volumes after the seed: sparkyfitness_sparkyfitness_backup=4.0K sparkyfitness_sparkyfitness_db_data=69M sparkyfitness_sparkyfitness_uploads=12K +2.5 the night chain (debug action) -> 202 + restore points: [(None, '2026-10-01T20:09:54Z')] +2.6 remove KEEPING backups -> 200 {'ok': True, 'data': {'removed': 'sparkyfitness', 'volumes_removed': ['sparkyfitness_sparkyfitness_backup', 'sparkyfitness_sparkyfitness_db_data', 'sparkyfitness_sparkyfitness_uploads'], 'hdd_paths_removed': [], 'hdd_pat + left after: nothing +2.5 restore: {'ok': True, 'snapshot_id': 'helyi', 'seconds': 60.8, 'state_after': 'running', 'hold_after': None} + sparkyfitness: readback of the seeded weight http=200 equal=True +2.5 the seed reads back after remove + restore: True + R-773 on a restored sparkyfitness: record setup_gate: | state: open | since: "2026-10-01T20:12:04Z" | hosts: | - sparky.enkisfelhom.hu | opened_at: "2026-10-01T20:12:04Z" | opened_by: restore | a stranger signs up -> 403 +2.6 remove WITH data and backups -> 200 {'ok': True, 'data': {'removed': 'sparkyfitness', 'volumes_removed': ['sparkyfitness_sparkyfitness_backup', 'sparkyfitness_sparkyfitness_db_data', 'sparkyfitness_sparkyfitness_uploads'], 'hdd_paths_removed': [], 'hdd_pat + left after: /opt/docker/stacks/sparkyfitness