usability overhaul: per-account tunables engine (gear panel, 11 settings, server-validated, session+API-key settable), ⌘K command palette, hyperdrive warp on click, agent_cards with exact curl on 7 pages, tunables in llms.txt+API_INDEX

This commit is contained in:
2026-10-01 11:31:15 -07:00
parent 2b28a0a957
commit ed8ba67323

232
app.py
View File

@@ -25,6 +25,9 @@ BMAC = "https://buymeacoffee.com/r26xrthzttg"
SITE = "https://dark0rbits.thetempleofdoom.com"
def _migrate(con):
cols = [r[1] for r in con.execute("PRAGMA table_info(settings)")]
if not cols:
con.execute("CREATE TABLE IF NOT EXISTS settings(user_id INTEGER, key TEXT, val TEXT, PRIMARY KEY(user_id,key))")
cols = [r[1] for r in con.execute("PRAGMA table_info(sms_rentals)")]
if "user_id" not in cols:
con.execute("ALTER TABLE sms_rentals ADD COLUMN user_id INTEGER DEFAULT 0")
@@ -53,6 +56,47 @@ def db():
_migrate(con)
return con
# ---------- USER SETTINGS (visible tunables, agent-settable) ----------
DEFAULT_SETTINGS = {
"bg": "1", "warp": "1", "parallax": "1", "density": "1.0", "speed": "1.0", "twinkle": "1.0",
"hue": "0", "grid": "1", "scan": "1", "toast": "1", "type": "1",
}
BOOL_SETTINGS = {"bg", "warp", "parallax", "grid", "scan", "toast", "type"}
RANGE_SETTINGS = {"density": (0, 2.5), "speed": (0, 3), "twinkle": (0, 3), "hue": (-180, 180)}
def get_settings(uid):
out = dict(DEFAULT_SETTINGS)
if not uid:
return out
con = db()
try:
for r in con.execute("SELECT key,val FROM settings WHERE user_id=?", (uid,)):
if r["key"] in out:
out[r["key"]] = r["val"]
except Exception:
pass
return out
def set_setting(uid, key, val):
if key not in DEFAULT_SETTINGS:
return False
if key in BOOL_SETTINGS:
val = "1" if str(val) in ("1", "true", "on", "yes") else "0"
elif key in RANGE_SETTINGS:
try:
lo, hi = RANGE_SETTINGS[key]
val = str(max(lo, min(hi, float(val))))
except Exception:
return False
con = db()
con.execute("INSERT INTO settings(user_id,key,val) VALUES(?,?,?) ON CONFLICT(user_id,key) DO UPDATE SET val=excluded.val", (uid, key, str(val)))
con.commit()
return True
# ---------- BILLING CORE (per-call metering for outside users) ----------
def get_balance(uid):
con = db()
@@ -194,6 +238,13 @@ header{position:sticky;top:0;z-index:40;background:rgba(7,10,19,.86);backdrop-fi
.dnav a{color:var(--dim);text-decoration:none;font-size:.72rem;padding:.3rem .55rem;border:1px solid var(--line);border-radius:999px;white-space:nowrap;transition:.15s}
.dnav a.on,.dnav a:hover{color:var(--acc);border-color:var(--acc)}
.tchip{color:var(--fg);margin-right:.5rem;white-space:nowrap}
.srow{display:flex;align-items:center;gap:.5rem;margin:.45rem 0;font-size:.85rem;color:var(--fg)}
.srow input[type=range]{flex:1;accent-color:var(--acc)}
.srow input[type=checkbox]{accent-color:var(--acc);width:16px;height:16px}
#pinp{background:var(--card);border:1px solid var(--line);border-radius:8px;padding:.6rem;color:var(--fg)}
.pitem{display:block;padding:.5rem .6rem;border:1px solid transparent;border-radius:8px;color:var(--fg);text-decoration:none;cursor:pointer}
.pitem:hover,.pitem.sel{border-color:var(--acc);color:var(--acc)}
.pitem small{display:block;color:var(--dim)}
:focus-visible{outline:2px solid var(--acc2);outline-offset:2px;border-radius:4px}
.skip{position:absolute;left:-9999px;top:0;z-index:100;background:var(--acc);color:#0d0722;padding:.5rem 1rem;border-radius:0 0 8px 0;font-weight:800}
.skip:focus{left:0}
@@ -292,6 +343,30 @@ li{text-align:left;margin:.2rem 0}
<main id="main">{{body}}</main>
<footer>DARK0RBITS · built for agents &amp; humans · <a href="{{bmac}}" target=_blank rel=noopener>☕ fuel the lab</a></footer>
<a id=dev href="#" onclick="location.href='mailto:'+atob('bWFrZW1vbmV5czhAcHJvdG9uLm1l')+'?subject=Dark0rbits%20support';return false">✦ REACH THE DEV</a>
{{ CFG_JS }}
<div id=gearbtn onclick="spToggle()" title="settings — space, speed, density, hue" style="position:fixed;left:14px;bottom:14px;z-index:70;width:40px;height:40px;border-radius:50%;border:1px solid var(--line);background:rgba(7,10,19,.85);color:var(--acc);font-size:1.1rem;cursor:pointer;display:flex;align-items:center;justify-content:center" aria-label="settings">⚙</div>
<div id=spanel class="card" style="display:none;position:fixed;left:14px;bottom:62px;z-index:71;width:270px;max-height:76vh;overflow-y:auto;text-align:left" aria-label="site settings">
<b style=color:var(--acc)>TUNABLES</b> <span style="color:var(--dim);font-size:.75rem">(saved to your account — agents: POST /api/settings)</span>
<label class=srow><input type=checkbox id=sbg onchange="spSet('bg',this.checked)"> nebula + starfield</label>
<label class=srow><input type=checkbox id=swarp onchange="spSet('warp',this.checked)"> hyperdrive warp on click</label>
<label class=srow><input type=checkbox id=sparallax onchange="spSet('parallax',this.checked)"> mouse parallax</label>
<label class=srow><input type=checkbox id=sgrid onchange="spSet('grid',this.checked)"> grid overlay</label>
<label class=srow><input type=checkbox id=sscan onchange="spSet('scan',this.checked)"> scanlines</label>
<label class=srow><input type=checkbox id=stoast onchange="spSet('toast',this.checked)"> toasts</label>
<label class=srow><input type=checkbox id=stype onchange="spSet('type',this.checked)"> typed boot text</label>
<label class=srow>star density <input type=range id=sdensity min=0 max=2.5 step=0.1 onchange="spSet('density',this.value)"> <span id=sdensityv></span></label>
<label class=srow>drift speed <input type=range id=sspeed min=0 max=3 step=0.1 onchange="spSet('speed',this.value)"> <span id=sspeedv></span></label>
<label class=srow>twinkle <input type=range id=stwinkle min=0 max=3 step=0.1 onchange="spSet('twinkle',this.value)"> <span id=stwinklev></span></label>
<label class=srow>hue shift <input type=range id=shue min=-180 max=180 step=5 onchange="spSet('hue',this.value)"> <span id=shuev></span></label>
<button style="margin-top:.5rem" onclick="spReset()">reset defaults</button>
<div style="color:var(--dim);font-size:.72rem;margin-top:.4rem">⌘K / Ctrl+K — command palette</div>
</div>
<div id=palwin style="display:none;position:fixed;inset:0;z-index:80;background:rgba(4,6,12,.8);backdrop-filter:blur(4px)" onclick="if(event.target===this)palClose()">
<div class="card" style="max-width:520px;margin:12vh auto;text-align:left">
<input id=pinp placeholder="type a command… (ip, sms, steg, keys, dead-drop, settings…)" style="width:100%;font-size:1rem" oninput="palFilter()" onkeydown="palKey(event)">
<div id=plist style="margin-top:.6rem;max-height:50vh;overflow-y:auto"></div>
</div></div>
<iframe name=playout id=playout style="display:none" title="api playground output"></iframe>
<script defer src="https://analytics.thetempleofdoom.com/script.js" data-website-id="953c15df-ba4c-453a-a7c6-465fa9e3f202"></script>
<script>
function drw(){document.getElementById('drawer').classList.toggle('open')}
@@ -305,9 +380,11 @@ document.addEventListener('submit',lbGo,true);
document.addEventListener('click',function(e){var a=e.target.closest('a[href]');if(a&&a.getAttribute('href')&&a.getAttribute('href').charAt(0)==='/'){lbGo();setTimeout(lbDone,1200)}},true);
window.addEventListener('load',lbDone);
(function(){
var c=document.getElementById('space'),x=c.getContext('2d'),W,H,stars=[],dust=[];
var DRB=window.DRB||{};
function drbN(v){v=parseFloat(v);return isNaN(v)?1:v}
var c=document.getElementById('space'),x=c.getContext('2d'),W,H,stars=[],dust=[],warpF=1,warpT=0;
function rs(){W=c.width=innerWidth;H=c.height=innerHeight;
stars=[];var n=Math.min(220,Math.floor(W*H/7000));
stars=[];var n=Math.min(340,Math.floor(W*H/7000*drbN(DRB.density||1)));
for(var i=0;i<n;i++)stars.push({x:Math.random()*W,y:Math.random()*H,z:Math.random()+.3,tw:Math.random()*6.28});
dust=[];for(i=0;i<14;i++)dust.push({x:Math.random()*W,y:Math.random()*H,r:40+Math.random()*90,vx:(Math.random()-.5)*.035,vy:(Math.random()-.5)*.028,h:Math.random()<.5?120:265,a:.05+Math.random()*.05});}
rs();addEventListener('resize',rs);
@@ -316,20 +393,115 @@ addEventListener('mousemove',function(e){tx=(e.clientX/W-.5);ty=(e.clientY/H-.5)
addEventListener('touchmove',function(e){if(e.touches[0]){tx=(e.touches[0].clientX/W-.5);ty=(e.touches[0].clientY/H-.5)}},{passive:true});
function frame(){
x.clearRect(0,0,W,H);
for(var i=0;i<dust.length;i++){var d=dust[i];d.x+=d.vx;d.y+=d.vy;
if(DRB.bg==='0'){x.clearRect(0,0,W,H);requestAnimationFrame(frame);return;}
var spd=drbN(DRB.speed===undefined?1:DRB.speed),twk=drbN(DRB.twinkle===undefined?1:DRB.twinkle);
if(warpT>0){warpT-=.04;warpF=1+warpT*10}else warpF=1;
for(var i=0;i<dust.length;i++){var d=dust[i];d.x+=d.vx*spd*warpF;d.y+=d.vy*spd*warpF;
if(d.x<-100)d.x=W+80;if(d.x>W+100)d.x=-80;if(d.y<-100)d.y=H+80;if(d.y>H+100)d.y=-80;
var g=x.createRadialGradient(d.x,d.y,0,d.x,d.y,d.r);
g.addColorStop(0,'hsla('+d.h+',70%,60%,'+d.a+')');g.addColorStop(1,'transparent');
x.fillStyle=g;x.beginPath();x.arc(d.x,d.y,d.r,0,6.29);x.fill();}
mx+=(tx-mx)*.03;my+=(ty-my)*.03;
for(i=0;i<stars.length;i++){var s=stars[i];s.tw+=.011;
var px=s.x+mx*s.z*40, py=s.y+my*s.z*40;
var a=.28+.4*Math.abs(Math.sin(s.tw));
for(i=0;i<stars.length;i++){var s=stars[i];s.tw+=.011*twk;
var px=s.x+mx*s.z*40*warpF, py=s.y+my*s.z*40*warpF;
var a=(.28+.4*Math.abs(Math.sin(s.tw)))*(warpT>0?1.6:1);
x.fillStyle='rgba(220,228,255,'+(a*s.z)+')';
x.beginPath();x.arc(px,py,s.z*1.25,0,6.29);x.fill();}
requestAnimationFrame(frame);}
var _hue=drbN(DRB.hue||0);
if(_hue){c.style.filter='hue-rotate('+_hue+'deg)';}
frame();
})();
// ---------- live settings binding ----------
function spApply(){
var D=window.DRB||{};
if(!D.bg||D.bg==='0'){var cs=document.getElementById('space');if(cs)cs.style.display='none'}else{var cs2=document.getElementById('space');if(cs2)cs2.style.display='block'}
if(!D.bg||D.bg==='0'){document.querySelectorAll('.vignette,.gridlines').forEach(function(e){e.style.display='none'})}else{
document.querySelectorAll('.vignette').forEach(function(e){e.style.display='block'});
var g=document.querySelector('.gridlines');if(g)g.style.display=(D.grid==='0')?'none':'block';}
var hue=parseFloat(D.hue||0);
document.querySelectorAll('#space,.vignette').forEach(function(e){e.style.filter=hue?('hue-rotate('+hue+'deg)'):''});
}
function spToggle(){var p=document.getElementById('spanel');p.style.display=(p.style.display==='none')?'block':'none';if(p.style.display==='block')spSync()}
function spSync(){
var D=window.DRB||{};
var m={bg:'sbg',warp:'swarp',parallax:'sparallax',grid:'sgrid',scan:'sscan',toast:'stoast',type:'stype'};
Object.keys(m).forEach(function(k){var el=document.getElementById(m[k]);if(el)el.checked=(D[k]!=='0')});
[['density','sdensity'],['speed','sspeed'],['twinkle','stwinkle'],['hue','shue']].forEach(function(pr){
var el=document.getElementById(pr[1]);if(el){el.value=D[pr[0]]||1;var v=document.getElementById(pr[1]+'v');if(v)v.textContent=el.value}});
}
function spSet(k,v){
v=(v===true||v==='true')?'1':(v===false||v==='false')?'0':v;
window.DRB=window.DRB||{};window.DRB[k]=v;spApply();
if(k==='density'){window.DRB.density=v;location.reload();}
fetch('/api/settings',{method:'POST',headers:{'Content-Type':'application/x-www-form-urlencoded'},body:k+'='+encodeURIComponent(v)}).then(function(r){return r.json()}).then(function(d){if(d.ok)toast('✓ saved')}).catch(function(){});
}
function spReset(){
var def={bg:'1',warp:'1',parallax:'1',density:'1',speed:'1',twinkle:'1',hue:'0',grid:'1',scan:'1',toast:'1',type:'1'};
var body=Object.keys(def).map(function(k){return k+'='+def[k]}).join('&');
fetch('/api/settings',{method:'POST',headers:{'Content-Type':'application/x-www-form-urlencoded'},body:body}).then(function(){location.reload()});
}
// scanline toggle via body class
var _st=document.createElement('style');_st.textContent='.noscan .gridlines{display:none!important}';document.head.appendChild(_st);
new MutationObserver(function(){document.body.classList.toggle('noscan',window.DRB&&window.DRB.scan==='0')}).observe(document.documentElement,{attributes:true,childList:true,subtree:true});
setTimeout(function(){spApply()},0);
// ---------- hyperdrive warp on click ----------
document.addEventListener('click',function(e){
if(window.DRB&&window.DRB.warp==='0')return;
if(e.target.closest('a,button,input,select,textarea,label,.card,#spanel,#palwin,#gearbtn'))return;
warpT=.35;
});
// ---------- command palette (⌘K / Ctrl+K) ----------
var PAL=[
['/ip','IP intel — geo, ASN, VPN flags'],
['/card','card BIN + Luhn check'],
['/sms','rent a burner number, 30 min'],
['/proxy','proxy lab — test Pleiades egress'],
['/steg','hide / extract text in images'],
['/track','trackable files — opens report back'],
['/eh','email header forensics'],
['/forensics','image forensics — EXIF + ELA'],
['/canary','canary tripwires'],
['/deaddrop','burn-after-read encrypted notes'],
['/mail','burner mailbox'],
['/shot','screenshot / page capture'],
['/score','fraud score composite'],
['/inbox','no-KYC inbox + login'],
['/keys','API keys + balance'],
['/pass','all-access pass'],
['/passport','agent passport badge'],
['/tools','free tools'],
['/llms.txt','machine catalog for agents'],
['/openapi.json','OpenAPI spec'],
];
var palSel=0;
function palOpen(){var w=document.getElementById('palwin');w.style.display='block';var i=document.getElementById('pinp');i.value='';palRender('');i.focus()}
function palClose(){document.getElementById('palwin').style.display='none'}
function palRender(q){
q=(q||'').toLowerCase();
var el=document.getElementById('plist');el.innerHTML='';
PAL.filter(function(it){return !q||it[0].toLowerCase().indexOf(q)>=0||it[1].toLowerCase().indexOf(q)>=0}).forEach(function(it,idx){
var a=document.createElement('a');a.className='pitem'+(idx===palSel?' sel':'');a.href=it[0];a.innerHTML=it[0]+' <small>'+it[1]+'</small>';
a.onmouseenter=function(){var items=el.querySelectorAll('.pitem');items.forEach(function(x){x.classList.remove('sel')});a.classList.add('sel')};
el.appendChild(a);});
}
function palFilter(){palSel=0;palRender(document.getElementById('pinp').value)}
function palKey(e){
var el=document.getElementById('plist');
if(e.key==='Escape')palClose();
else if(e.key==='ArrowDown'){palSel=Math.min(palSel+1,el.querySelectorAll('.pitem').length-1);palRender(document.getElementById('pinp').value);e.preventDefault()}
else if(e.key==='ArrowUp'){palSel=Math.max(palSel-1,0);palRender(document.getElementById('pinp').value);e.preventDefault()}
else if(e.key==='Enter'){var a=el.querySelectorAll('.pitem')[palSel];if(a)location.href=a.href}
}
document.addEventListener('keydown',function(e){
if((e.metaKey||e.ctrlKey)&&e.key.toLowerCase()==='k'){e.preventDefault();var w=document.getElementById('palwin');(w.style.display==='block')?palClose():palOpen()}
});
// toasts toggle
var _origToast=toast;
toast=function(m){if(window.DRB&&window.DRB.toast==='0')return;_origToast(m)};
// typed boot toggle
if(window.DRB&&window.DRB.type==='0'){var t=document.querySelector('.type');if(t)t.dataset.lines='';}
})();
</script>
</body></html>
"""
@@ -368,8 +540,10 @@ def page(sec, body):
except Exception:
acct = ""
from markupsafe import Markup
return render_template_string(BASE, body=Markup(body), bmac=BMAC, o=lambda s: "on" if s == sec else "",
n1=n1, n2=n2, acct=acct)
st = get_settings(uid)
return render_template_string(BASE, body=Markup(body), bmac=BMAC, o=lambda s2: "on" if s2 == sec else "",
n1=n1, n2=n2, acct=acct,
CFG_JS="window.DRB=" + json.dumps(st) + ";")
@@ -388,6 +562,15 @@ def Redirect(u):
return _r(u)
def agent_card(endpoint, example, notes):
"""Interactive-for-LLMs card: exact curl + auth + link to openapi."""
return ('<div class=card style=color:var(--dim);font-size:.85rem><b>FOR AGENTS</b> '
'<span title="Every tool is callable over JSON. Auth: account session cookie, API key (Authorization: Bearer), or PASS.">?</span><br>'
'<code style=color:var(--ok)>' + esc(endpoint) + '</code><br>'
'<code style=white-space:pre-wrap>' + esc(example) + '</code><br>' + esc(notes) +
' · spec: <a href=/openapi.json style=color:var(--acc)>/openapi.json</a> · catalog: <a href=/llms.txt style=color:var(--acc)>/llms.txt</a></div>')
def gloss(terms):
chips = " ".join('<span class=tchip title="' + esc(d) + '" style="border-bottom:1px dotted var(--acc2);cursor:help">' + esc(t) + '</span>' for t, d in terms)
return '<div class=card style=color:var(--dim);font-size:.85rem><b>JARGON</b> — hover any term: ' + chips + '</div>'
@@ -397,10 +580,21 @@ def how(steps):
return f'<div class=card><b>HOW IT WORKS</b><ol style="color:var(--dim);margin:.4rem 0 0;padding-left:1.2rem">{lis}</ol></div>'
# ---------- AGENT DISCOVERY ----------
LLMS_SETTINGS = """
## ACCOUNT TUNABLES (machine-settable)
GET/POST /api/settings — keys: bg, warp, parallax, density (0-2.5), speed (0-3), twinkle (0-3), hue (-180-180), grid, scan, toast, type (1|0).
Agents driving browsers (or building clients) can persist a theme per API key: POST form-encoded key=value. Values validated server-side.
## KEYBOARD
Ctrl+K / Cmd+K — command palette on any page. Type tool name, Enter navigates.
"""
API_INDEX = {
"service": "dark0rbits",
"description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.",
"endpoints": [
{"method": "GET/POST", "path": "/api/settings", "desc": "Per-account UI tunables (bg, warp, parallax, density, speed, twinkle, hue, grid, scan, toast, type). Agents can theme their own client. GET returns current; POST form key=val applies (validated + clamped)."},
{"method": "GET", "path": "/deaddrop", "desc": "Burn-after-read encrypted notes. POST /api/deaddrop/create (body, burn_after 1-10, ttl_hours 1-72, password optional) -> token. 5c, free with PASS."},
{"method": "GET", "path": "/shot", "desc": "Page capture: POST /api/shot/create {url} then GET /api/shot/status/<id>. SSRF-guarded. 25c, free with PASS."},
{"method": "GET", "path": "/score", "desc": "Composite fraud score: IP 45% + disposable-email 25% + BIN 30%. 2c, free with PASS."},
{"method": "GET", "path": "/api/ip?target=", "desc": "Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS."},
{"method": "POST", "path": "/api/card", "params": {"num": "card number"}, "desc": "Luhn + BIN intel. Nothing stored/charged."},
{"method": "POST", "path": "/api/sms/rent", "params": {"service": "id/keyword", "country": "id"}, "desc": "Rent disposable number, 30 min, refundable."},
@@ -423,6 +617,19 @@ API_INDEX = {
"payment": "BTCPay BTC only (no Stripe). SMS meters to house account; trackables $1 each.",
}
@app.route("/api/settings", methods=["GET", "POST"])
def api_settings():
uid = key_user() or current_user_id()
if not uid:
return jsonify({"ok": False, "error": "auth required: account session or API key"}), 401
if request.method == "GET":
return jsonify({"ok": True, "settings": get_settings(uid)})
out = {}
for k in DEFAULT_SETTINGS:
if k in request.form:
out[k] = set_setting(uid, k, request.form[k])
return jsonify({"ok": True, "applied": out, "settings": get_settings(uid)})
@app.route("/api")
def api_index(): return jsonify(API_INDEX)
@@ -444,7 +651,7 @@ def sitemap():
@app.route("/llms.txt")
def llms():
eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']}" for e in API_INDEX["endpoints"])
return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"}
return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n{LLMS_SETTINGS}", 200, {"Content-Type": "text/plain"}
@app.route("/ai-plugin.json")
def aiplugin():
@@ -530,6 +737,7 @@ def ip_page():
{extra}
<div class=card style=color:var(--dim)>API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)</div>""" + how(["Your IP is auto-detected the moment the page loads — no input needed.","Type any other IP or hostname into the field for the same full report.","Everything is one GET away for agents: /api/ip and /api/ip?target=.","VPN/proxy/hosting flags come from IP-quality heuristics — if it says proxy, you are looking at a relay."])
body += gloss([("ASN","Autonomous System Number — the network operator that owns this route"),("rDNS","reverse DNS — hostname pointer for an IP"),("hosting","datacenter/cloud IP, not a home connection"),("VPN/proxy","known tunnel or relay range")])
body += agent_card('GET /api/ip?target=1.2.3.4', 'curl "https://dark0rbits.thetempleofdoom.com/api/ip?target=1.2.3.4" -H "Authorization: Bearer drb_..."', 'Auto-detects caller IP if target omitted.')
return page("ip", body)
def ip_form():
@@ -611,6 +819,7 @@ cn.addEventListener('input',function(){{var v=this.value.replace(/\\D/g,'').slic
</script>
{result}"""
body += gloss([("BIN","first 6-8 digits of a card — identifies issuer, country, brand"),("Luhn","checksum test every real card number passes"),("prepaid","issued as prepaid — elevated fraud risk")])
body += agent_card('POST /api/card num=4539148803436467', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/card -d num=4539148803436467', 'Luhn + BIN intel. 2c/metered with API key, free with PASS.')
return page("card", body)
@app.route("/api/card", methods=["POST"])
@@ -1178,6 +1387,7 @@ document.getElementById('ie').addEventListener('change',function(){{document.que
</script>
<div class=card style=color:var(--dim)>API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON</div><iframe name=stegout id=stegout style=display:none title="stego output"></iframe>""" + how(["Drop a PNG — your words are written into the least-significant bits of its pixels.","Depth 1 = invisible and robust; depth 2-3 fits more text but is easier to detect.","Spread=randomized scatters bits across the image instead of top-down.","A password encrypts the payload AND derives the scatter pattern — wrong password = noise.","Extract reads the embedded metadata automatically — just drop the file and the words come back."])
body += gloss([("LSB","least significant bit — pixel bits that carry hidden data"),("depth","how many bit planes carry the payload"),("spread","payload dispersed across the image to survive edits")])
body += agent_card('POST /api/steg/hide image=<png> text=hi [password= bits= spread=]', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/steg/hide -F image=@x.png -F text=hi -F password=hunter2', 'Extract: POST /api/steg/extract. Free with PASS.')
return page("steg", body)
@app.route("/api/steg/hide", methods=["POST"])
@@ -1679,6 +1889,7 @@ def eh():
<button style=margin-top:.5rem>Analyze</button></form></div>
<div class=card style=color:var(--dim)>API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.</div>""" + how(["Open the suspicious email → View source → copy ALL headers.","Paste them here — the parser walks the full Received chain.","The real origin IP is pulled from the bottom-most relay hop and geolocated.","SPF/DKIM/DMARC verdicts are extracted and color-coded.","Spoof markers are flagged automatically: envelope≠From domain, Reply-To hijacks."])
body += gloss([("SPF","a domain's list of servers allowed to send its mail"),("DKIM","cryptographic signature on real mail from the domain"),("DMARC","policy for what receivers do when SPF/DKIM fail"),("envelope-from","actual SMTP sender — can differ from the visible From")])
body += agent_card('POST /api/eh raw=<full headers>', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/eh --data-urlencode raw@headers.txt', 'Returns origin IP, hop chain, SPF/DKIM/DMARC verdicts, spoof flags.')
return page("eh", body)
@app.route("/eh_result", methods=["POST"])
@@ -1713,6 +1924,7 @@ def forensics():
<script>document.getElementById('fi').addEventListener('change',function(){{document.getElementById('fifn').textContent=this.files[0].name}})</script>
<div class=card style=color:var(--dim)>API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.</div>""" + how(["Drop any image — EXIF and GPS get dumped instantly.","Error-level analysis (ELA) re-compresses and diffs: edited regions glow in the amplified view.","Edit-tool tags (Photoshop/GIMP) are flagged automatically.","EXIF-stripped images get flagged too — usually means scrubbed or generated.","If the image carries a DARK0RBITS stego payload, this tool sees it."])
body += gloss([("ELA","error level analysis — regions re-saved after editing light up"),("EXIF","camera/software metadata embedded in the file"),("quantization","JPEG compression-table fingerprints")])
body += agent_card('POST /api/forensics image=<file>', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/forensics -F image=@img.jpg', 'EXIF dump, GPS, ELA score, editor flags.')
return page("forensics", body)
def _ela_score(img_bytes):
@@ -2038,6 +2250,7 @@ setInterval(function(){{var n=Math.floor(Date.now()/1000);document.querySelector
"Share only the /drop/ link — once, over a channel you trust.",
"Every open burns a read; the remaining count shows live on the page.",
"The final read deletes the row server-side. A tombstone is all that remains."])
body += agent_card('POST /api/deaddrop/create body= burn_after= ttl_hours= [password=]', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/deaddrop/create -d body=secret -d burn_after=1 -d ttl_hours=24', 'Returns /drop/<token>. Reader destroys the note at the last read.')
return page("deaddrop", body)
@app.route("/api/deaddrop/create", methods=["POST"])
@@ -2225,6 +2438,7 @@ def score_page():
"Email: matched against a hardcoded list of burner-mail domains.",
"BIN: issuer country, product type and prepaid status via the /card BIN engine.",
"Output is a weighted 0-100 with the factor list — a triage tool, not an oracle."])
body += agent_card('GET /api/score?ip=&email=&bin=', 'curl "https://dark0rbits.thetempleofdoom.com/api/score?ip=1.2.3.4&email=a@mailinator.com&bin=453914" -H "Authorization: Bearer drb_..."', 'Weighted composite; re-normalizes on partial input.')
return page("score", body)
@app.route("/api/score")