import crypto from "node:crypto";
const PROJECT_ID = "2Q9V222NTI2WJ45N";
const AUTH_SECRET = "c3499ac4ae2f5ca6715e9ee04cfe542aa5070593d6fa6341";
const hmac = (...parts) =>
crypto.createHmac("sha1", AUTH_SECRET).update(parts.join("|"), "utf8").digest("hex");
export async function checkKey(key, hwid) {
const nonce = crypto.randomBytes(16).toString("hex");
const res = await fetch("https://vampauth.com/api/v1/key/check", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
project_id: PROJECT_ID,
key, hwid, nonce,
signature: hmac(nonce, key, hwid),
}),
});
const data = await res.json();
if (!res.ok) throw new Error(`${data.error ?? res.status}: ${data.message ?? ""}`);
const expiresUnix = data.expires_at
? Math.floor(Date.parse(data.expires_at) / 1000)
: 0;
const expected = hmac(data.nonce_echo, data.status, expiresUnix, data.project_id);
const okSig = expected.length === data.signature.length &&
crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(data.signature));
if (data.nonce_echo !== nonce || !okSig) throw new Error("signature verification failed");
return data; // { status, key, hwid_bound, expires_at, created_at, project_id }
}