New "Generator" nav item, open to every role since it's a pure
client-side utility with no data mutation. Three independent cards:
- Server name: picks from Swedish girl names or Disney characters (or
both), skipping any name already used by an existing server —
checked against the real server list, not just avoiding duplicates
within one session.
- Username: adjective+animal with a configurable separator and an
optional 2-digit suffix.
- Password: length slider, per-charset toggles, an "exclude ambiguous
characters" option (0/O, 1/l/I), and a rough entropy/strength
readout. Uses crypto.getRandomValues with rejection sampling (not
Math.random or a plain modulo), since a biased password generator
is a real security footgun.
Nothing generated here is sent to or stored on the server — it's
computed entirely in the browser and only reaches the backend if the
user pastes it into some other form themselves (e.g. Secrets, adding
a server).
Verified generators.ts directly: collision avoidance always returns
the one remaining unused name when every other option in a themed
list is taken, the full-list-exhausted fallback produces a numbered
name that still doesn't collide, matching is case-insensitive,
per-charset password generation only ever produces characters from
the selected sets, excludeAmbiguous holds across 200 40-character
samples, entropy math matches the expected log2 formula, and a
5000-sample single-character distribution came out uniform (469-521
per digit against an expected 500, no modulo bias) confirming the
rejection-sampling RNG is unbiased.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>