# DateKeys App
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Implementación en TypeScript del protocolo DateKeys v0.8.2 y página de prueba en el navegador. Sustituye al prototipo, archivado en `../AppOld` (API Quicknet en Go, CLI tlock y cliente Svelte, commit `4d2b0a1` ).
La implementación de referencia es la librería Go `g.activething.com/go/DateKeys` , en `../datekeys-go` . El plan de trabajo está en [docs/PLAN_codec_cbor_y_pagina_svelte.md ](docs/PLAN_codec_cbor_y_pagina_svelte.md ).
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
## Contenido
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| Parte | Ubicación | Paso del plan | Estado |
|---|---|---|---|
| Codec CBOR del subconjunto, parsers de schema, DateKey, `inspect` | `src/lib/dkc/` | 4 | hecho |
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| Página inspector, sin red | SvelteKit estático: `src/routes/` , `src/lib/inspector/` , `src/lib/components/` | 5 | hecho |
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| Cifrado y descifrado en el navegador | fase 2: [docs/PLAN_fase2_ibe_noble2.md ](docs/PLAN_fase2_ibe_noble2.md ) | 6 | en curso: dependencias y guardas hechas (paso 2 de la fase) |
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Version constants: 0.1.0-dev, implementing spec 0.8.2
- src/lib/dkc/version.ts exports VERSION (0.1.0-dev, which becomes
0.1.0 once phase 2 adds the opening of capsules) and SPEC_VERSION
(0.8.2, the tag spec-v0.8.2 of datekeys-go), from index.ts too.
- package.json and its lockfile move to 0.1.0-dev. version.test.ts ties
VERSION to both and checks it is semantic versioning. It also ties
SPEC_VERSION to the spec field of the shared vectors and fixtures.
testing/vectors.ts now takes SPEC_VERSION from version.ts, so every
vector file is checked against the version the library declares.
- The footer of the page shows both, instead of a fixed 0.8.2.
- README.md gains a "Versiones" section: the three versions (format,
specification, library) and what 0.1.0-dev covers. CHANGELOG.md is
new.
The Go reference gained datekeys.SpecVersion, datekeys.Version() and
`datekeys version` in 5b342d3.
npm run verify is green: 2,406 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
## Versiones
Hay tres números de versión, cada uno con su significado, como en la referencia Go:
| Versión | Dónde | Cambia cuando |
|---|---|---|
| Formato | Dentro de los objetos: la versión de framing de DKC1 y DKK1 y la de schema de la clave 1, hoy todas 1 | Cambia el formato. Un lector rechaza una versión que no conoce (§70) |
| Especificación | `SPEC_VERSION` de `src/lib/dkc/version.ts` , hoy `0.8.2` : la del tag `spec-v0.8.2` de `datekeys-go` | Cambia el texto normativo |
| Librería | `VERSION` de `src/lib/dkc/version.ts` , igual al campo `version` de `package.json` | Cambia la API o el comportamiento. Versionado semántico, sin promesa de estabilidad antes de 1.0.0 |
`version.test.ts` comprueba que `VERSION` coincide con `package.json` y con su lockfile, y que `SPEC_VERSION` es la versión que nombran los vectores y fixtures compartidos; `vectors.test.ts` exige esa versión a cada fichero. El pie de la página muestra las dos.
La versión actual es `0.1.0-dev` . Será `0.1.0` cuando la fase 2 añada la apertura de cápsulas. Cubre:
- la especificación 0.8.2, con versiones de formato 1;
- solo el scheme de Quicknet (`bls-unchained-g1-rfc9380`): un perfil de otro scheme se inspecciona, pero su release no se verifica (decisión 3 del plan de la fase 2);
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- la inspección de los pasos 1 a 8 y la apertura de los pasos 9 a 18 (`open.ts`), desde un `Uint8Array` o un `Blob` y hacia memoria o hacia un stream de salida, como el de un fichero OPFS. El cifrado llega en la fase 3;
Version constants: 0.1.0-dev, implementing spec 0.8.2
- src/lib/dkc/version.ts exports VERSION (0.1.0-dev, which becomes
0.1.0 once phase 2 adds the opening of capsules) and SPEC_VERSION
(0.8.2, the tag spec-v0.8.2 of datekeys-go), from index.ts too.
- package.json and its lockfile move to 0.1.0-dev. version.test.ts ties
VERSION to both and checks it is semantic versioning. It also ties
SPEC_VERSION to the spec field of the shared vectors and fixtures.
testing/vectors.ts now takes SPEC_VERSION from version.ts, so every
vector file is checked against the version the library declares.
- The footer of the page shows both, instead of a fixed 0.8.2.
- README.md gains a "Versiones" section: the three versions (format,
specification, library) and what 0.1.0-dev covers. CHANGELOG.md is
new.
The Go reference gained datekeys.SpecVersion, datekeys.Version() and
`datekeys version` in 5b342d3.
npm run verify is green: 2,406 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- todos los vectores y fixtures compartidos de `datekeys-go` en `9ac9cd9` (`spec-v0.8.2`);
- navegadores con Web Crypto y Node 20 o posterior.
[CHANGELOG.md ](CHANGELOG.md ) recoge los cambios de cada versión.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
## `src/lib/dkc`
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
Lo que hay hoy (pasos 1 a 8) no importa ninguna dependencia. Funciona en navegadores y en Node 20+: solo usa `Uint8Array` , `DataView` , `TextEncoder` /`TextDecoder`, `BigInt` y `crypto.subtle` (SHA-256). La fase 2 añade las dependencias de ejecución de su sección, y noble solo lo importarán `ibe.ts` y `release.ts` .
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
`crypto.subtle` solo existe en contextos seguros: `https` , o `http` en `localhost` . La página del paso 5 servida por `http` desde una IP de la red local (por ejemplo `vite --host` para probar en un móvil) no lo tiene, y `inspect` rechaza entonces con un `Error` que lo dice (`SHA-256 needs Web Crypto (crypto.subtle), …`) en vez de dar un veredicto. El registro por defecto no memoriza ese fallo: la siguiente llamada lo vuelve a intentar.
Follow DateKeys v0.8.2 at f6f2e9f (canonical points, fixed error texts)
testdata is synced from datekeys-go f6f2e9f: mutations.json has 65
cases, the ten new §64 ones at steps 10 and 11 (phase 2, skipped and
counted: 31 run, 34 skipped).
The reference no longer copies library error text into errors, so the
TypeScript uses its fixed texts too: every unreadable age header is
"agewrap: not an age v1 header: malformed, truncated or beyond the
parser limits", with the parser's reason in the error's cause, which the
tests still compare with age's own texts; the profile messages for an
unknown drand scheme and a non-canonical public key follow Go. Against
Go at f6f2e9f, 407,196 differential inputs agree on verdict, code, step,
error text, check details and the full inspect -json output.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| Fichero | Contenido | Equivale en Go (`f6f2e9f`) |
|---|---|---|
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `errors.ts` | `DateKeysError` con el código normativo de §69 (`ERR_*`); mensajes con la forma `contexto: CÓDIGO` de Go | `errors.go` |
| `bytes.ts` | Hex, UTF-8 estricto, `goQuote` (el `%q` de Go, con la tabla de `strconv.IsPrint` de Go 1.26 fijada en el código) y `sha256` (Web Crypto) | `strconv` , `unicode/utf8` |
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `cbor.ts` | El codec propio de la referencia, con las mismas lecturas, las mismas comprobaciones en el mismo orden y los mismos textos de error: `Encoder` con error persistente; `Decoder` , cursor estricto (`map`/`key`/`endMap`, `array` , `uint` /`uint64`, `bstr` , `text` , `done` ); `unmarshal` (decodifica, reencodifica y compara; `onReject` para borrar secretos); `peek` /`checkSchema` (capa 2 de §69.1: tipo y versión antes que nada) y `walk` (lector genérico acotado en profundidad y longitud) | `codec` |
| `schema.ts` | Lo que comparten los decodificadores de PUBLIC_HEADER, CONTROL_CBOR y el cuerpo de la `.dkk` : `key N: ` en los errores, claves obligatorias y arrays de extensiones | `capsule/framing.go` , `accesskey` |
| `extension.ts` | Arrays de extensiones, leídos con su objeto (capa 3 de §69.1). Registros con ubicación opcional (`registeredIn`): una extensión conocida fuera de los objetos y arrays de su registro cuenta allí como desconocida (§54, §72), como `extension.Placement` en Go. Reglas del array: de 1 a 64, en orden estrictamente ascendente de los bytes UTF-8 de `extension_id` (nunca por unidades UTF-16), `extension_version` hasta 2³² − 1, `data` ausente o `bstr` no vacío, ningún id en los dos arrays; registros, críticas y no críticas (capa 4) | `extension` |
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `profile.ts` | Provider Profile: CBOR exacto, `profile_hash` , reglas 1 a 4 de §12.1 en su orden (el límite de `period` de §74 en la capa del esquema; alfabetos, clave pública del grupo del scheme y fórmula de `chain_hash` ), registro pinneado; Quicknet fijado por su CBOR y su hash | `profile` |
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `bls12381.ts` | Pertenencia de claves públicas BLS12-381 comprimidas (G1 y G2) al subgrupo, como `FromCompressed` de kilic | `kyber-bls12381` |
Phase 2, step 7: tlock encryption, checked against Go both ways
- ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the
suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST,
sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR
H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the
canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma
takes a given sigma, for the vectors only; index.ts exports neither.
- tlock.ts adds timeRecipient, the age-encryption Recipient of
OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza
"tlock <round> <chain hash>" with the checks and texts of
NewTimeRecipient: the scheme and the pinned key, then the round range.
age-encryption has no labels, so the writer of phase 3 adds it alone.
Vectors, in src/lib/dkc/testing/tlock-vectors.json from
scripts/tlock-go-vectors.go:
- Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and
1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and
checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock.
encryptOnG2WithSigma reproduces them byte for byte.
- The samples of scripts/tlock-ts-samples.mjs, which Node runs on the
TypeScript sources: IBE bodies and age files that this library made
for rounds 1000 and 1001. Go opened every one: the bodies with
tlock.TimeUnlock and the age files with age.Decrypt and
agewrap.NewTimeIdentity, the identity of step 11. It got the same
file keys and plaintexts, and the samples are frozen with those
verdicts.
tlock.test.ts replays both blocks, the random round trip, the
rejections with their texts, and an age file sealed with timeRecipient
and opened with the step-11 identity of open.ts. Coverage of ibe.ts and
tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan
is recorded as done: the canonicality amendment is in spec-v0.8.2.
npm run verify is green: 2,567 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `ibe.ts` | IBE-CCA de tlock sobre G2 para Quicknet (§63 paso 11): `decryptOnG2` y `encryptOnG2RFC9380` (Qid = H(id) en G1 con el DST de RFC 9380, sigma aleatorio, U = r·G2), con la puerta de codificación canónica de `bls12381.ts` sobre la firma y U; H2 sobre GT serializado en el orden de kilic (nunca `Fp12.toBytes` de noble), H3 y H4; `roundIdentity` ; el cuerpo `U ‖ V ‖ W` de 128 bytes del stanza. Errores `IbeError` con motivo (`length`, `encoding` , `identity` , `proof` ) y texto fijos, sin ningún valor del cálculo; borra sigma y los hashes derivados. Sobre `@noble/curves` 2.4.0; lleva el aviso MIT de `tlock-js` , cuya estructura sigue. Lo usa la apertura (`open.ts`) | `encrypt/ibe` de drand/kyber (`DecryptCCAonG2`), `tlock.BytesToCiphertext` y `TimeUnlock` |
Phase 2, step 5a: open capsules, steps 9 to 18, in memory
src/lib/dkc/open.ts runs steps 9 to 18 of spec §63 on top of the steps
1 to 8 of inspectWith. It follows capsule.Open of the Go reference, with
its checks, codes and texts:
- step 9: the access credentials (the .dkk as an object, then its
capsule_id and capsule_digest), then the release, never before the
round time. Any failure of the source is ERR_RELEASE_UNAVAILABLE
alone, keeping its text and its cause (correction 6);
- step 10: verifyRelease;
- steps 11 to 13: OUTER_TIME_AGE, the structure against access_policy
and INNER_ACCESS_AGE;
- steps 14 to 18: CONTROL_CBOR, header_binding, I_PAYLOAD, PAYLOAD_AGE
and the commit.
The three age files open with the Decrypter of age-encryption and
identities that apply the rules of Go's agewrap: the tlock identity on
ibe.ts, and the access and payload identities on x25519.ts. A failure of
age that no identity reports is ERR_INTEGRITY with the fixed reason of
its phase, header or STREAM, never the text of age-encryption. The
plaintext is decrypted in memory and returned only after step 18.
Streaming to OPFS is step 5b.
src/lib/dkc/x25519.ts opens one age X25519 stanza at a time, in the
order of age's X25519Identity. Step 13 must try every identity on every
stanza (spec §36), and age-encryption's Decrypter stops at the first.
Its primitives are the ones age-encryption uses: X25519 and HKDF from
noble curves and hashes, and ChaCha20-Poly1305 from @noble/ciphers
2.4.0. The author approved declaring that package as a direct
dependency on 2026-09-28; it is the copy already installed and bundled.
The guards now allow ciphers, and x25519.ts in the noble allowlist.
src/lib/dkc/bech32.ts ports age's internal/bech32, with its MIT notice,
to read AGE-SECRET-KEY-1 identities.
Tests:
- vectors.test.ts runs all 65 cases of the mutation corpus through open.
Each gives the code and the step of Go, and no case that fails without
the network requests a release. This includes the 34 cases of steps 9
to 18 that were skipped, so the suite no longer skips any test.
- open.test.ts:
- the five official fixtures open to their plaintext, with each
credential, with the checks and details of the reference;
- the unusable noncritical extensions are reported;
- the source failures and the clock;
- age failures by phase;
- CONTROL_CBOR that does not decode, and a low-order share in
INNER_ACCESS_AGE, through an OUTER_TIME_AGE resealed with the FK_TIME
of the Go vectors;
- the texts of the identities.
- x25519.test.ts checks against age-encryption both ways and against the
Go-written stanzas of the fixtures, and covers every low-order share.
- bech32.test.ts has the vectors of the reference.
x25519.ts and bech32.ts are at 100 % coverage, now thresholds. open.ts
is at 100 % of lines; the one branch left is the one for an error that
is not a DateKeysError.
index.ts does not re-export the opening yet. The page imports index.ts,
and re-exporting would pull noble into /inspect (58.7 to 84.9 KB gzip)
even unused; step 8 will load it on demand. The site does not change.
npm run verify is green: 2,490 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `release.ts` | Verificación local del release (§17, §51, §63 paso 10), en el orden y con los textos de `provider.Verify` :< br > 1. el rango de la ronda (`ERR_DATEKEY_INVALID`);< br > 2. la ronda del release antes que la firma (`ERR_ROUND_MISMATCH`);< br > 3. la longitud de la firma;< br > 4. la clave pinneada (`ERR_UNKNOWN_PROFILE`);< br > 5. la firma: codificación canónica de un punto de G1 que no sea el infinito, y firma BLS válida de la ronda sobre `@noble/curves` 2.4.0, con el DST de RFC 9380 para G1 (`ERR_RELEASE_INVALID`).< br > Nada de noble se copia a los errores. Solo verifica el scheme de Quicknet: un perfil de otro scheme falla con `ERR_UNKNOWN_PROFILE` tras las comprobaciones de ronda, donde la referencia sí lo verificaría (decisión 3 del plan de la fase 2). También define `ReleaseSource` , con su contrato de fuentes de red y de la corrección 6, y `suppliedRelease` , el release que entrega quien llama | `provider` (`Verify`, `ReleaseSource` ) |
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `open.ts` | Los pasos 9 a 18 de §63 sobre los pasos 1 a 8 de `inspectWith` , con los checks, códigos y textos de `capsule.Open` :< br > - las credenciales y el release (paso 9), que cualquier fallo de la fuente convierte en `ERR_RELEASE_UNAVAILABLE` (corrección 6);< br > - la verificación del release (10);< br > - `OUTER_TIME_AGE` (11), la estructura frente a `access_policy` (12) e `INNER_ACCESS_AGE` (13);< br > - `CONTROL_CBOR` (14), `header_binding` (15), `I_PAYLOAD` (16), `PAYLOAD_AGE` (17) y el commit (18).< br > Abre los tres ficheros `age` con el `Decrypter` de `age-encryption` y con identidades propias que aplican las reglas de `agewrap` : la de tiempo, sobre `ibe.ts` ; las de acceso y payload, sobre `x25519.ts` , stanza a stanza. Los fallos de `age` que no informa una identidad son `ERR_INTEGRITY` con el motivo fijo de su fase, cabecera o STREAM, sin copiar el texto de `age-encryption` .< br > La entrada puede ser un `Uint8Array` o un `Blob` , como un `File` . De un `Blob` solo se lee el prefijo de los pasos 1 a 8 (`prefix.ts`), el `capsule_digest` de la `.dkk` se calcula sobre su stream (`digest.ts`) y `PAYLOAD_AGE` se descifra en streaming.< br > El texto en claro va a memoria o a `output` , un `WritableStream` . Se escribe a medida que `age` autentica cada chunk, se cierra solo tras el paso 18 y se aborta ante cualquier fallo, en cualquier paso (§56). Un fallo del stream de salida es `ERR_INTEGRITY` con su texto, como en Go. El `WritableStream` de un fichero OPFS guarda lo escrito en un fichero de intercambio hasta el cierre: comprobado en el navegador, un fallo de STREAM deja intacto el contenido anterior | `capsule.Open` , `agewrap` (`TimeIdentity`, `AccessIdentity` , `PayloadIdentity` ) |
Phase 2, step 7: tlock encryption, checked against Go both ways
- ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the
suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST,
sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR
H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the
canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma
takes a given sigma, for the vectors only; index.ts exports neither.
- tlock.ts adds timeRecipient, the age-encryption Recipient of
OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza
"tlock <round> <chain hash>" with the checks and texts of
NewTimeRecipient: the scheme and the pinned key, then the round range.
age-encryption has no labels, so the writer of phase 3 adds it alone.
Vectors, in src/lib/dkc/testing/tlock-vectors.json from
scripts/tlock-go-vectors.go:
- Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and
1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and
checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock.
encryptOnG2WithSigma reproduces them byte for byte.
- The samples of scripts/tlock-ts-samples.mjs, which Node runs on the
TypeScript sources: IBE bodies and age files that this library made
for rounds 1000 and 1001. Go opened every one: the bodies with
tlock.TimeUnlock and the age files with age.Decrypt and
agewrap.NewTimeIdentity, the identity of step 11. It got the same
file keys and plaintexts, and the samples are frozen with those
verdicts.
tlock.test.ts replays both blocks, the random round trip, the
rejections with their texts, and an age file sealed with timeRecipient
and opened with the step-11 identity of open.ts. Coverage of ibe.ts and
tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan
is recorded as done: the canonicality amendment is in spec-v0.8.2.
npm run verify is green: 2,567 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `tlock.ts` | `timeRecipient` , el `Recipient` de `age-encryption` para `OUTER_TIME_AGE` (§32, §35), como `agewrap.TimeRecipient` : cifra la file key con `ibe.ts` para una ronda de un perfil pinneado y escribe el stanza `tlock <ronda> <chain hash>` de tlock. Comprueba el perfil y luego el rango de la ronda, con los textos de `NewTimeRecipient` . `age-encryption` no tiene etiquetas, así que quien escriba `OUTER_TIME_AGE` (fase 3) lo añade como único recipient | `agewrap.TimeRecipient` |
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `digest.ts` | SHA-256 incremental de un stream, con `@noble/hashes` , para el `capsule_digest` de un `.dkc` que no está en memoria (Web Crypto solo calcula el hash de buffers enteros) | |
Phase 2, step 5a: open capsules, steps 9 to 18, in memory
src/lib/dkc/open.ts runs steps 9 to 18 of spec §63 on top of the steps
1 to 8 of inspectWith. It follows capsule.Open of the Go reference, with
its checks, codes and texts:
- step 9: the access credentials (the .dkk as an object, then its
capsule_id and capsule_digest), then the release, never before the
round time. Any failure of the source is ERR_RELEASE_UNAVAILABLE
alone, keeping its text and its cause (correction 6);
- step 10: verifyRelease;
- steps 11 to 13: OUTER_TIME_AGE, the structure against access_policy
and INNER_ACCESS_AGE;
- steps 14 to 18: CONTROL_CBOR, header_binding, I_PAYLOAD, PAYLOAD_AGE
and the commit.
The three age files open with the Decrypter of age-encryption and
identities that apply the rules of Go's agewrap: the tlock identity on
ibe.ts, and the access and payload identities on x25519.ts. A failure of
age that no identity reports is ERR_INTEGRITY with the fixed reason of
its phase, header or STREAM, never the text of age-encryption. The
plaintext is decrypted in memory and returned only after step 18.
Streaming to OPFS is step 5b.
src/lib/dkc/x25519.ts opens one age X25519 stanza at a time, in the
order of age's X25519Identity. Step 13 must try every identity on every
stanza (spec §36), and age-encryption's Decrypter stops at the first.
Its primitives are the ones age-encryption uses: X25519 and HKDF from
noble curves and hashes, and ChaCha20-Poly1305 from @noble/ciphers
2.4.0. The author approved declaring that package as a direct
dependency on 2026-09-28; it is the copy already installed and bundled.
The guards now allow ciphers, and x25519.ts in the noble allowlist.
src/lib/dkc/bech32.ts ports age's internal/bech32, with its MIT notice,
to read AGE-SECRET-KEY-1 identities.
Tests:
- vectors.test.ts runs all 65 cases of the mutation corpus through open.
Each gives the code and the step of Go, and no case that fails without
the network requests a release. This includes the 34 cases of steps 9
to 18 that were skipped, so the suite no longer skips any test.
- open.test.ts:
- the five official fixtures open to their plaintext, with each
credential, with the checks and details of the reference;
- the unusable noncritical extensions are reported;
- the source failures and the clock;
- age failures by phase;
- CONTROL_CBOR that does not decode, and a low-order share in
INNER_ACCESS_AGE, through an OUTER_TIME_AGE resealed with the FK_TIME
of the Go vectors;
- the texts of the identities.
- x25519.test.ts checks against age-encryption both ways and against the
Go-written stanzas of the fixtures, and covers every low-order share.
- bech32.test.ts has the vectors of the reference.
x25519.ts and bech32.ts are at 100 % coverage, now thresholds. open.ts
is at 100 % of lines; the one branch left is the one for an error that
is not a DateKeysError.
index.ts does not re-export the opening yet. The page imports index.ts,
and re-exporting would pull noble into /inspect (58.7 to 84.9 KB gzip)
even unused; step 8 will load it on demand. The site does not change.
npm run verify is green: 2,490 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `x25519.ts` | El stanza X25519 de `age` , abierto de uno en uno como `X25519Identity.Unwrap` de `age` : argumentos, share, acuerdo de claves, longitud del cuerpo y autenticación, en ese orden, con las primitivas que usa `age-encryption` (X25519 de `@noble/curves` , HKDF-SHA-256 de `@noble/hashes` y ChaCha20-Poly1305 de `@noble/ciphers` ). También lee identidades `AGE-SECRET-KEY-1…` | `filippo.io/age` (`X25519Identity`), `agewrap` |
| `bech32.ts` | Bech32 (BIP 173) tal como `internal/bech32` de `age` , que la referencia copia como `codec/bech32` ; conserva su aviso MIT | `codec/bech32` |
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `datekey.ts` | `dk1_` canónico con las reglas de lectura de §19 (CR, LF y todo carácter fuera del alfabeto fallan el paso 1; números JSON por su valor decimal exacto), ronda desde una fecha con precisión de nanosegundos y cota de 9999-12-31T23:59:59Z (§15), parser RFC 3339 equivalente a `time.Parse(time.RFC3339Nano, …)` | `datekey` |
| `header.ts` , `control.ts` , `accesskey.ts` | PUBLIC_HEADER, CONTROL_CBOR y `.dkk` (cuerpo y trama), decodificar y codificar, con las capas de §69.1 | `capsule` , `accesskey` |
| `framing.ts` | Prelude DKC1 (16 bytes) y DKK1 (12 bytes) en el orden de §23 y §40, longitudes de 1 byte hasta los límites de §57, y troceo de secciones | `capsule/framing.go` |
| `age.ts` | Parser estricto de la cabecera `age` v1 (§28.1) sobre los ficheros binarios, con los textos de error de `age` ; reglas de stanzas; `MAX_AGE_HEADER_LEN` (2 MiB), el límite que usa la página para leer solo el prefijo de un `.dkc` grande | `agewrap` , `filippo.io/age/internal/format` |
| `inspect.ts` | Pasos 1 a 8 de §63 y la vista JSON de `datekeys inspect -json` (`inspectView`, `inspectJSON` ) | `capsule/inspect.go` , `internal/inspectview` |
Phase 2, step 7: tlock encryption, checked against Go both ways
- ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the
suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST,
sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR
H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the
canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma
takes a given sigma, for the vectors only; index.ts exports neither.
- tlock.ts adds timeRecipient, the age-encryption Recipient of
OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza
"tlock <round> <chain hash>" with the checks and texts of
NewTimeRecipient: the scheme and the pinned key, then the round range.
age-encryption has no labels, so the writer of phase 3 adds it alone.
Vectors, in src/lib/dkc/testing/tlock-vectors.json from
scripts/tlock-go-vectors.go:
- Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and
1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and
checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock.
encryptOnG2WithSigma reproduces them byte for byte.
- The samples of scripts/tlock-ts-samples.mjs, which Node runs on the
TypeScript sources: IBE bodies and age files that this library made
for rounds 1000 and 1001. Go opened every one: the bodies with
tlock.TimeUnlock and the age files with age.Decrypt and
agewrap.NewTimeIdentity, the identity of step 11. It got the same
file keys and plaintexts, and the samples are frozen with those
verdicts.
tlock.test.ts replays both blocks, the random round trip, the
rejections with their texts, and an age file sealed with timeRecipient
and opened with the step-11 identity of open.ts. Coverage of ibe.ts and
tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan
is recorded as done: the canonicality amendment is in spec-v0.8.2.
npm run verify is green: 2,567 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `index.ts` | Reexporta todo salvo la fase 2 (`ibe.ts`, `release.ts` , `open.ts` , `tlock.ts` , `x25519.ts` , `bech32.ts` y `digest.ts` ). La página importa `index.ts` , y reexportarlos metería noble en `/inspect` (de 58,7 a 84,9 KB con gzip) aunque no los use, porque noble ejecuta código al cargarse. El paso 8 cargará la apertura bajo demanda | |
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `testing/` | Solo para tests: lectura de `testdata/` y de sus formatos (`vectors.ts`: ediciones, vectores), constructores de CBOR en hex, cirugía de cápsulas | |
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Los tests (`*.test.ts`) están junto a cada fichero.
### Equivalencia con la referencia Go
Follow DateKeys v0.8.2 at f6f2e9f (canonical points, fixed error texts)
testdata is synced from datekeys-go f6f2e9f: mutations.json has 65
cases, the ten new §64 ones at steps 10 and 11 (phase 2, skipped and
counted: 31 run, 34 skipped).
The reference no longer copies library error text into errors, so the
TypeScript uses its fixed texts too: every unreadable age header is
"agewrap: not an age v1 header: malformed, truncated or beyond the
parser limits", with the parser's reason in the error's cause, which the
tests still compare with age's own texts; the profile messages for an
unknown drand scheme and a non-canonical public key follow Go. Against
Go at f6f2e9f, 407,196 differential inputs agree on verdict, code, step,
error text, check details and the full inspect -json output.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
El comportamiento se contrastó con la librería Go en `3820066` (`692cf87` solo cambia la regla de UTF-8 de `dk1_` descrita abajo) mediante un oráculo diferencial fuera del repositorio: 483 527 entradas de tres semillas. Son mutaciones de los cinco `.dkc` oficiales de todas las clases (bits, bytes, truncados, inserciones, borrados, longitudes y campos del prelude, cabeceras reescritas con cambios de CBOR, DateKeys, arrays de extensiones con y sin registro de extensiones, cabeceras `age` de SEALED_CONTROL y de PAYLOAD_AGE, argumentos del stanza tlock, rondas, secciones cambiadas de sitio y combinaciones de varios defectos); CBOR de cada esquema (PUBLIC_HEADER, CONTROL_CBOR, cuerpo y fichero `.dkk` , Provider Profile, arrays de extensiones); `walk` , `peek` y `checkSchema` ; cabeceras `age` , preludes, cadenas `dk1_` , rondas y fechas. En todas coinciden el veredicto, el código y el paso, y también el texto del error, el valor decodificado y la salida entera de `datekeys inspect -json` , byte a byte. Un segundo diferencial con otro generador, de 407 196 entradas, se repitió contra `f6f2e9f` (la enmienda de canonicidad de puntos) con el mismo resultado, textos incluidos.
Como la referencia desde `f6f2e9f` , los errores no copian el texto de una librería: una cabecera `age` que no se puede leer da siempre `agewrap: not an age v1 header: malformed, truncated or beyond the parser limits` (`ERR_INTEGRITY`). El motivo del parser, con las palabras de `age` , queda en `cause` del error, fuera del mensaje, y los tests lo comparan con los textos de `age` para comprobar que se rechaza por la misma razón.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Precedencia de errores (§69.1): primero la trama; después el tipo y la versión de esquema (`checkSchema`); después el perfil CBOR y el CDDL, con los límites de implementación de §74, en una sola decodificación (`unmarshal` con el decodificador del esquema, que ya comprueba tipos, tamaños, rangos, `access_policy` , `extension_version` , el máximo de 64 extensiones y su orden); y solo entonces los campos con código propio, en orden de clave: DateKey, perfil fijado y extensiones críticas en PUBLIC_HEADER; `access_type` y `access_material` en la `.dkk` ; los campos y la autocomprobación de `chain_hash` en el Provider Profile. Entre pasos decide el orden de §63. Un PUBLIC_HEADER que rompe a la vez el CDDL y la DateKey da `ERR_NON_CANONICAL_CBOR` , como en la referencia de `3820066` ; la de `afb44a3` leía `access_policy` y `extension_version` como `uint64` y los acotaba después de la DateKey, y la vía `wideUint` que lo imitaba ya no existe.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Enteros: el decodificador lee cada entero hasta 2⁶⁴ − 1 (un `bigint` por encima de 2⁵³ − 1) y lo compara con el máximo de su campo, con el texto de la referencia (`unsigned integer 9007199254740992 above 9007199254740991`). Ningún campo de un objeto del protocolo admite más de 2⁵³ − 1; `walk` admite cualquier `uint64` , como `codec.Walk` .
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
`peek` lee la capa 2 de §69.1 como `codec.Peek` : una cabecera de mapa de longitud definida que anuncia al menos dos entradas y no más de la mitad de los bytes que la siguen, la clave 0 con un texto de hasta 64 bytes y la clave 1 con un entero de hasta 2⁵³ − 1, todo en su forma más corta. No lee nada más: una versión 2 es `ERR_UNSUPPORTED_VERSION` sea lo que sea lo que venga detrás, y cualquier otra cosa en esas posiciones, `ERR_NON_CANONICAL_CBOR` .
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
UTF-8 inválido en el JSON de un `dk1_` hace fallar el paso 2 de §19 (`ERR_DATEKEY_INVALID`) en las dos implementaciones, también en un miembro que un nombre repetido reemplaza después. Hasta `692cf87` la referencia Go lo sustituía por U+FFFD (`encoding/json`) y en ese caso daba `ERR_DATEKEY_NON_CANONICAL` ; el diferencial de esta implementación lo encontró y la referencia se corrigió para seguir al spec. `datekey.test.ts` y el vector *invalid UTF-8 in a member a repeated name overwrites* de `dk1.json` lo fijan.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
`goQuote` escribe como Go 1.26 (Unicode 15.0.0) los textos entre comillas de los detalles de fallo: usa una tabla de `strconv.IsPrint` generada con Go y no `\p{…}` , porque cada motor JavaScript trae su propia versión de Unicode (V8 en Node 24 ya imprime runas de Unicode 16 que Go escapa, como U+31E4). `bytes.test.ts` fija el SHA-256 del conjunto completo de runas imprimibles. Si el toolchain de la referencia cambia de versión de Unicode, se regenera con `go run scripts/go-isprint-table.go` y se actualizan la tabla y el hash.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Secretos: `access_material` de un `.dkk` e `I_PAYLOAD` de CONTROL_CBOR se borran en todos los caminos, también cuando la decodificación falla a medias o `unmarshal` rechaza el valor, como el `clear` diferido de Go.
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
## Página inspector
Sitio SvelteKit estático (`@sveltejs/adapter-static`, `strict` ): las dos páginas se prerenderizan a HTML y no hay código de servidor.
| Ruta | Contenido |
|---|---|
| `/` | Qué es el inspector y qué garantiza; enlaza con `/inspect` |
| `/inspect` | El inspector |
`/inspect` carga un `.dkc` con el selector de ficheros, soltándolo en cualquier parte de la página o desde la lista de fixtures oficiales, y ejecuta `inspect` (pasos 1 a 8 de §63) sin registro de extensiones, como `datekeys inspect` . Muestra:
- cada paso con su número, su nombre de la CLI, `superado` o el código normativo, y el detalle (los caracteres invisibles o de control se escriben como `\uXXXX` );
- el veredicto, `capsule_id` , la DateKey compacta y decodificada (red y ronda), el perfil fijado, la fecha de apertura en UTC y en la hora local del navegador, `access_policy` , los campos del prelude, los argumentos del stanza `tlock` frente al perfil fijado y el número y tipo de stanzas de OUTER_TIME_AGE y PAYLOAD_AGE;
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- las extensiones de PUBLIC_HEADER según el contrato del plan §8: id (entre comillas y escapado si tiene caracteres no imprimibles), versión, crítica o no, conocida o no, longitud y hex (plegado si pasa de 64 bytes); texto si los bytes son UTF-8 imprimible; vista CBOR con `walk` si son un ítem del perfil de §58, marcada "informativo, no validado por el protocolo"; y el aviso de que son públicas, de que nada las vincula al resto de la cápsula antes del paso 15 y de que ni entonces prueban autoría (§55.1);
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- **Copiar JSON**, que copia exactamente la salida de `datekeys inspect -json` (`cliJSON`: el `json.Encoder` de Go con sangría de dos espacios, `<` , `>` , `&` , U+2028 y U+2029 escapados y salto de línea final). `file` es el nombre del fichero.
No pide ni acepta secretos. Todo el texto leído de la cápsula pasa por interpolación de texto de Svelte (nunca `{@html}` ), y ni las entradas de mapas CBOR ni los identificadores de extensión se usan nunca como claves de objetos o `Map` de JavaScript.
| Fichero | Contenido |
|---|---|
| `src/lib/inspector/report.ts` | `buildReport` : el modelo de la página a partir de `Inspection` , sin DOM ni reloj |
| `src/lib/inspector/format.ts` | Nombres y glosas de pasos, códigos y políticas; texto imprimible y escapado; números y fechas en español; `cliJSON` |
| `src/lib/inspector/diagnostic.ts` | Notación de diagnóstico CBOR (RFC 8949 §8) de `walk` , acotada a 16 384 caracteres |
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `src/lib/dkc/prefix.ts` | Lectura por prefijo, que también usa la apertura: de un `.dkc` grande solo se leen 16 + PUBLIC_HEADER_LEN + SEALED_CONTROL_LEN + 2 MiB + 1 bytes, y solo 16 si los pasos 1 y 2 rechazan el prelude (otro tipo de fichero, un `.dkk` , longitudes fuera de §57), siempre con el mismo resultado que el fichero entero (lo comprueba `prefix.test.ts` ) |
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `src/lib/inspector/fixtures.ts` | Los fixtures oficiales, empaquetados desde `testdata/fixtures` |
| `src/lib/components/` | `InspectionReport` , `StepList` , `ExtensionList` , `DataView` , `Mark` |
| `src/routes/` | Layout, portada e inspector |
### Fixtures
`fixtures.ts` importa con `import.meta.glob` los `.dkc` de `testdata/fixtures` como URL (`?url`) y, de cada registro JSON, solo el campo `description` . `testdata/` sigue siendo la única fuente: Vite copia cada `.dkc` como fichero con hash en `_app/immutable/assets/` y nunca lo incrusta como `data:` (`assetsInlineLimit: 0`), y no se copia nada más. Los `.dkk` , los textos en claro y los demás campos de los registros (`payload_identity`, `control_cbor` …) no llegan al sitio; `check-build.mjs` lo comprueba. En desarrollo, `server.fs.allow` deja que Vite sirva `testdata/fixtures` .
### Sin red: la Content-Security-Policy
`kit.csp` (`svelte.config.js`, modo `hash` ) pone en cada página prerenderizada, como primer elemento que carga algo, un `<meta http-equiv="content-security-policy">` :
```
default-src 'self'; frame-src 'none'; worker-src 'none'; connect-src 'self'; font-src 'self';
img-src 'self'; manifest-src 'self'; object-src 'none'; script-src 'self' 'sha256-…';
style-src 'self'; style-src-attr 'unsafe-hashes' 'sha256-…'; base-uri 'none'; form-action 'none'
```
- `connect-src 'self'` : `fetch` solo llega al propio origen, y solo se usa para los fixtures.
- `script-src` : los módulos del sitio y el hash SHA-256 del único script en línea, el arranque de SvelteKit (los nonces no sirven en HTML prerenderizado).
- `style-src 'self'` : solo hojas de estilo del sitio; sin fuentes web ni CDN, con las fuentes del sistema.
- `style-src-attr` : solo el atributo `style` del anunciador de rutas de SvelteKit, por su hash (`ANNOUNCER_STYLE_HASH`, válido para `@sveltejs/kit` 2.70.3; `app.css` lo oculta también si el navegador bloquea el atributo).
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
`npm run build` ejecuta después `scripts/check-build.mjs` (`postbuild`; también `npm run build:check` ), que falla si una ruta no tiene su HTML prerenderizado; si una página no tiene exactamente esa política, con la etiqueta antes de cualquier elemento que cargue recursos; si un script en línea no está en `script-src` o sobra un hash; si `style-src-attr` no coincide con los atributos `style` del bundle; si hay estilos en línea, manejadores de eventos en atributos, `@import` o URL a otro origen; si algún `.dkc` oficial no está byte a byte; si aparece en el sitio algún secreto de los fixtures (`.dkk`, textos en claro, identidades, `payload_identity` , `access_material` , `control_cbor` ); o si el bundle del cliente contiene `tlock-js` , `drand-client` o helpers de Babel, o una copia anidada de un paquete que no sea la de noble bajo `@noble/post-quantum` . `vite.config.ts` registra los módulos de cada chunk en `.svelte-kit/output/client-modules.json` , fuera del sitio. Al terminar informa del JavaScript que carga cada página, en bytes y con gzip, y de los paquetes npm que lleva el bundle.
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
En un hosting estático basta con servir `build/` . Las directivas que solo funcionan como cabecera HTTP (`frame-ancestors`, `sandbox` , `report-to` ) quedan para el servidor que la aloje. `crypto.subtle` exige contexto seguro: `https` , o `http` en `localhost` .
## Reglas
- Los fixtures y vectores del Go son la verdad. Este proyecto nunca genera fixtures propios: `testdata/` es una copia exacta de un commit de la librería Go.
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- Dependencias de ejecución: solo `age` , `drand` , `tlock` y lo que ellas arrastran; hoy, las de la sección «Dependencias de ejecución». El sitio lleva compilado además el runtime de cliente de Svelte y SvelteKit, el tooling que el plan elige para la página (sección 13).
- Tooling de desarrollo: solo el de la lista siguiente. Cualquier otra dependencia se propone por escrito y no se instala sin aprobación.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
## Comandos
```bash
npm test # vitest, todos los tests
npm run coverage # tests con cobertura v8; falla por debajo de los umbrales
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
npm run typecheck # svelte-kit sync y tsc sobre todo y sobre la librería sin tipos de Node
npm run check # svelte-kit sync y svelte-check (componentes y rutas), falla con avisos
npm run dev # servidor de desarrollo: http://localhost:5173/inspect
npm run build # sitio estático en build/ y, después, scripts/check-build.mjs
npm run preview # sirve build/: http://localhost:4173/inspect
npm run build:check # solo la comprobación del sitio ya construido
npm run verify # check, typecheck, coverage y build (con su comprobación)
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
```
Phase 2, step 7: tlock encryption, checked against Go both ways
- ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the
suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST,
sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR
H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the
canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma
takes a given sigma, for the vectors only; index.ts exports neither.
- tlock.ts adds timeRecipient, the age-encryption Recipient of
OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza
"tlock <round> <chain hash>" with the checks and texts of
NewTimeRecipient: the scheme and the pinned key, then the round range.
age-encryption has no labels, so the writer of phase 3 adds it alone.
Vectors, in src/lib/dkc/testing/tlock-vectors.json from
scripts/tlock-go-vectors.go:
- Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and
1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and
checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock.
encryptOnG2WithSigma reproduces them byte for byte.
- The samples of scripts/tlock-ts-samples.mjs, which Node runs on the
TypeScript sources: IBE bodies and age files that this library made
for rounds 1000 and 1001. Go opened every one: the bodies with
tlock.TimeUnlock and the age files with age.Decrypt and
agewrap.NewTimeIdentity, the identity of step 11. It got the same
file keys and plaintexts, and the samples are frozen with those
verdicts.
tlock.test.ts replays both blocks, the random round trip, the
rejections with their texts, and an age file sealed with timeRecipient
and opened with the step-11 identity of open.ts. Coverage of ibe.ts and
tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan
is recorded as done: the canonicality amendment is in spec-v0.8.2.
npm run verify is green: 2,567 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
Umbrales de cobertura (`vitest.config.ts`): `cbor.ts` , `ibe.ts` , `release.ts` , `tlock.ts` , `x25519.ts` , `bech32.ts` y `digest.ts` al 100 % en líneas, ramas, funciones y sentencias; el conjunto de `src/lib/dkc` al 95/90/95/95, y el de `src/lib/inspector` también.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
`vitest.config.ts` es la configuración de los tests; `vite.config.ts` , la del sitio con el plugin de SvelteKit. Vitest prefiere la primera, así que los tests de `src/lib` corren sin SvelteKit, y `src/lib/inspector` importa la librería por rutas relativas, sin el alias `$lib` . `tsconfig.json` extiende el que genera `svelte-kit sync` (por eso `typecheck` y `check` lo ejecutan antes, y `npm install` también, con `prepare` ).
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
`npm run typecheck` pasa dos veces: `tsconfig.json` (todo, con tipos de Node para los tests) y `tsconfig.lib.json` (solo la librería y sin tipos de Node, para que no se cuele ninguna API que no exista en el navegador).
### Vectores y fixtures
- `testdata/fixtures/*.json` : cada `.dkc` pasa los pasos 1 a 8 con los valores registrados (prelude, PUBLIC_HEADER, DateKey, `capsule_id` , política, `unlock_at` , extensiones con sus bytes exactos, stanzas, `header_binding` , CONTROL_CBOR); cada `.dkk` se decodifica campo a campo y se reencodifica byte a byte. Los fixtures nuevos se recogen solos.
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- `testdata/fixtures/*.inspect.json` : la vista de `inspect` de cada `.dkc` , escrita con `inspectJSON` como la imprime la CLI (`file` incluido), es idéntica byte a byte al fichero, también el texto de cada paso.
- `testdata/vectors/dk1.json` (con los tres vectores de los refinamientos de §19: LF dentro del Base64, CR y LF después, y la versión `1.0000000000000001` ), `quicknet_rounds.json` y `profile_quicknet.json` : se ejecutan todos.
- `testdata/vectors/cbor.json` : cada vector genérico (`accept` y `reject` ) pasa por `walk` con los `max_depth` y `max_len` del fichero; los enteros aceptados comparan su `value` (número o, por encima de 2⁵³ − 1, `bigint` ), y los rechazados «above max_len» o «above max_depth» se aceptan sin ese límite. Cada vector de `schemas` pasa por el decodificador de su esquema (`decodeProfile`, `decodeHeader` , `decodeControl` , `decodeAccessKeyBody` ) con el código exacto, y un objeto aceptado se reescribe a los mismos bytes.
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- `testdata/vectors/tlock_ibe.json` : el vector de H2 del IBE de tlock (§63 paso 11). Hasta que llegue `ibe.ts` (fase 2), el test lo recalcula con `@noble/curves` 2.4.0: los puntos son canónicos para `bls12381.ts` , el pairing serializado en el orden de kilic es el GT del vector y su H2 coincide; el orden propio de noble (`Fp12.toBytes`) da otro hash.
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- `testdata/vectors/mutations.json` : se leen los 65 casos enteros (ediciones sobre un fixture o hex congelado, release, reloj, registro, extensiones, `.dkk` e identidades). Los 65 pasan por `open` con su release, su reloj, su registro, sus extensiones, su `.dkk` y sus identidades, y dan el mismo código en el mismo paso que Go. También pasan como `Blob` con un stream de salida, que termina abortado en los 65. Entre ellos están los 34 de los pasos 9 a 18, con las 10 mutaciones de la enmienda de canonicidad de puntos en los pasos 10 y 11. Ninguno de los que fallan sin red pide un release. Los 31 de los pasos 1 a 8 pasan además por `inspect` , y un test fija los dos recuentos. Las `.dkk` ofrecidas se decodifican.
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- `testdata/vectors/inspect_differential.json` : las 1 825 mutaciones dan el mismo veredicto, código y paso que Go; los `bases` se comprueban por su SHA-256.
Phase 2, step 3: the tlock IBE on noble 2, checked against Go
src/lib/dkc/ibe.ts is DecryptCCAonG2 of drand/kyber encrypt/ibe, the
decryption of tlock.TimeUnlock for Quicknet, on @noble/curves 2.4.0
(plan of phase 2, section 4). It adds nothing that kyber would reject:
- the signature and U pass the canonical-encoding gate of bls12381.ts,
which rejects the point at infinity too;
- H2 hashes GT in the order of kilic, never with noble's Fp12.toBytes;
- H3 and H4 follow kyber, including the rejection sampling of r, and
r = 0 never proves;
- roundIdentity is drand's DigestBeacon;
- the stanza body is exactly U || V || W, 128 bytes, as in tlock.
Errors are IbeError with a fixed reason (length, encoding, identity,
proof) and message: none carries sigma, the message, r or input bytes.
Anything noble throws past the gate is a proof failure. sigma and the
hashes derived from it are wiped on every path. The file keeps the MIT
notice of tlock-js, whose structure it follows. index.ts does not
re-export it yet; the opening of step 5 will use it.
scripts/ibe-go-vectors.go writes src/lib/dkc/testing/ibe-vectors.json
with kyber, tlock and age:
- the GT of e(G1, G2) and of its square, with H2;
- H3, including inputs accepted at the second and third iteration, and
H4;
- round identities;
- for the tlock stanza of every official fixture, the pairing, sigma, r
and the file key. tlock.TimeUnlock unwraps that file key, and age
opens OUTER_TIME_AGE with it;
- messages of 0, 1, 16 and 32 bytes encrypted by EncryptCCAonG2;
- kyber's verdict on eleven edited copies of the time_only stanza.
It restates the unexported H2, H3 and H4 and checks them on every
fixture against tlock and U = r·G2.
ibe.test.ts replays every vector and opens OUTER_TIME_AGE of each
fixture through age-encryption with a custom Identity: the header MAC
and STREAM verify, and a time_only fixture yields its control_cbor. It
also gates all 157 BLS edge encodings as the Go reference decodes them
and checks the fixed error texts. ibe.failure.test.ts mocks a noble
failure. Coverage of ibe.ts is 100 % and is now a threshold. The site
does not change.
npm run verify is green: 2,397 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- `src/lib/dkc/testing/ibe-vectors.json` : los valores de referencia de `ibe.ts` . Los escribe `scripts/ibe-go-vectors.go` con kyber, tlock y `age` , las librerías de la referencia Go, y `ibe.test.ts` los comprueba todos:
- el GT de e(G1, G2) y de su cuadrado, con H2 de 16 y 32 bytes;
- H3 y H4 sobre entradas fijas, entre ellas una H3 aceptada en la segunda iteración y otra en la tercera;
- la identidad de varias rondas;
- para el stanza tlock de cada fixture oficial, el pairing, sigma, r y la file key. La file key es la que devuelve `tlock.TimeUnlock` , y con ella `age` abre el `OUTER_TIME_AGE` . El test lo repite con `age-encryption` : el MAC de la cabecera y STREAM verifican, y el contenido es el `control_cbor` del registro o un `INNER_ACCESS_AGE` ;
- mensajes de 0, 1, 16 y 32 bytes cifrados por `EncryptCCAonG2` de kyber;
- el veredicto de `DecryptCCAonG2` sobre copias editadas del stanza de `time_only` : U con c0 + p, en el infinito o negado, V o W alterados, la firma de otra ronda, negada o en el infinito, y longitudes erróneas.
Phase 2, step 7: tlock encryption, checked against Go both ways
- ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the
suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST,
sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR
H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the
canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma
takes a given sigma, for the vectors only; index.ts exports neither.
- tlock.ts adds timeRecipient, the age-encryption Recipient of
OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza
"tlock <round> <chain hash>" with the checks and texts of
NewTimeRecipient: the scheme and the pinned key, then the round range.
age-encryption has no labels, so the writer of phase 3 adds it alone.
Vectors, in src/lib/dkc/testing/tlock-vectors.json from
scripts/tlock-go-vectors.go:
- Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and
1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and
checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock.
encryptOnG2WithSigma reproduces them byte for byte.
- The samples of scripts/tlock-ts-samples.mjs, which Node runs on the
TypeScript sources: IBE bodies and age files that this library made
for rounds 1000 and 1001. Go opened every one: the bodies with
tlock.TimeUnlock and the age files with age.Decrypt and
agewrap.NewTimeIdentity, the identity of step 11. It got the same
file keys and plaintexts, and the samples are frozen with those
verdicts.
tlock.test.ts replays both blocks, the random round trip, the
rejections with their texts, and an age file sealed with timeRecipient
and opened with the step-11 identity of open.ts. Coverage of ibe.ts and
tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan
is recorded as done: the canonicality amendment is in spec-v0.8.2.
npm run verify is green: 2,567 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
El mismo tratamiento tiene `src/lib/dkc/testing/tlock-vectors.json` , los valores de referencia del cifrado (paso 7 de la fase 2), que escribe `scripts/tlock-go-vectors.go` y comprueba `tlock.test.ts` :
- cifrados con sigma fijo de mensajes de 1, 16 y 32 bytes para las rondas 1000 y 1001. Go reescribe `EncryptCCAonG2` porque kyber toma sigma de `crypto/rand` , y comprueba su reescritura descifrando con `ibe.DecryptCCAonG2` y, en los de 16 bytes, con `tlock.TimeUnlock` . `encryptOnG2WithSigma` los reproduce byte a byte;
- la interoperabilidad de TypeScript a Go. `scripts/tlock-ts-samples.mjs` cifra con esta librería un cuerpo IBE y un fichero `age` escrito con `timeRecipient` , para las rondas 1000 y 1001. Go abre los cuerpos con `tlock.TimeUnlock` y los ficheros con `age.Decrypt` y `agewrap.NewTimeIdentity` , la identidad del paso 11, y obtiene la misma file key y el mismo texto. Esas muestras son aleatorias, así que se congelan con el veredicto de Go.
Para regenerarlo: `node scripts/tlock-ts-samples.mjs > ts-samples.json` , y desde el mismo módulo Go temporal, `go run tlock-go-vectors.go ts-samples.json > tlock-vectors.json` .
En `ibe-vectors.json` , H2, H3 y H4 no son públicas en kyber: el script las reescribe con sus etiquetas y las comprueba en cada fixture contra la file key de tlock y contra U = r·G2. Los cifrados de kyber usan un sigma aleatorio, así que el fichero se genera una vez y se congela. Para regenerarlo, desde un módulo Go temporal que requiera la referencia (`replace g.activething.com/go/DateKeys => ../datekeys-go`, `GOFLAGS=-mod=mod` ): `go run ibe-go-vectors.go ../App/testdata/fixtures > ibe-vectors.json` .
Align with DateKeys v0.8.2 at 3820066
Finishes the interrupted alignment of 3305bbb. The TypeScript now
follows the reference at 3820066 on steps 1 to 8, decoding and profile
validation:
- §69.1 precedence: the schema head is read strictly (a null or simple
version is ERR_NON_CANONICAL_CBOR, version 2 is ERR_UNSUPPORTED_VERSION
whatever follows) and every CDDL rule, including access_policy,
extension_version and the 64-extension cap read from the array head,
is checked before the DateKey; the wideUint path that imitated the
old Go order is gone.
- §19: CR or LF in dk1_ is ERR_DATEKEY_INVALID; §15: a round at exactly
9999-12-31T23:59:59Z is valid; §12.1: period above one day is
rejected on decode and pin; BODY_LEN 0 is ERR_INTEGRITY.
- Inspector texts no longer call header data authenticated at step 15
(§55.1: binding, never authorship or date); the fixture list ignores
the new *.inspect.json goldens.
The harness runs every shared Go vector: dk1.json 30, quicknet_rounds
17, profile 1, cbor.json 103 generic and 135 schema vectors,
mutations.json 31 through inspect with 24 phase-2 cases skipped and
counted, inspect_differential.json 1,825, and the five inspect goldens
byte-identical. A differential of 483,527 inputs against the Go
reference found no disagreement on verdict, code or step.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- Todo se lee con los formatos de `testdata/README.md` (`testing/vectors.ts`): una clave desconocida o que falta, un valor de otro tipo, un código que no es de §69 o una edición fuera de su base hacen fallar el fichero con su motivo; nada se salta en silencio.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
- Todo fichero de `testdata/` tiene que ejecutarlo algún test: un nombre nuevo exportado por Go (otro `vectors/*.json` , un fichero de fixture que ningún JSON nombra) hace fallar `testdata/ holds no file that no test runs` hasta que se le añade su bloque.
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
## Dependencias de ejecución
Phase 2, step 3: the tlock IBE on noble 2, checked against Go
src/lib/dkc/ibe.ts is DecryptCCAonG2 of drand/kyber encrypt/ibe, the
decryption of tlock.TimeUnlock for Quicknet, on @noble/curves 2.4.0
(plan of phase 2, section 4). It adds nothing that kyber would reject:
- the signature and U pass the canonical-encoding gate of bls12381.ts,
which rejects the point at infinity too;
- H2 hashes GT in the order of kilic, never with noble's Fp12.toBytes;
- H3 and H4 follow kyber, including the rejection sampling of r, and
r = 0 never proves;
- roundIdentity is drand's DigestBeacon;
- the stanza body is exactly U || V || W, 128 bytes, as in tlock.
Errors are IbeError with a fixed reason (length, encoding, identity,
proof) and message: none carries sigma, the message, r or input bytes.
Anything noble throws past the gate is a proof failure. sigma and the
hashes derived from it are wiped on every path. The file keeps the MIT
notice of tlock-js, whose structure it follows. index.ts does not
re-export it yet; the opening of step 5 will use it.
scripts/ibe-go-vectors.go writes src/lib/dkc/testing/ibe-vectors.json
with kyber, tlock and age:
- the GT of e(G1, G2) and of its square, with H2;
- H3, including inputs accepted at the second and third iteration, and
H4;
- round identities;
- for the tlock stanza of every official fixture, the pairing, sigma, r
and the file key. tlock.TimeUnlock unwraps that file key, and age
opens OUTER_TIME_AGE with it;
- messages of 0, 1, 16 and 32 bytes encrypted by EncryptCCAonG2;
- kyber's verdict on eleven edited copies of the time_only stanza.
It restates the unexported H2, H3 and H4 and checks them on every
fixture against tlock and U = r·G2.
ibe.test.ts replays every vector and opens OUTER_TIME_AGE of each
fixture through age-encryption with a custom Identity: the header MAC
and STREAM verify, and a time_only fixture yields its control_cbor. It
also gates all 157 BLS edge encodings as the Go reference decodes them
and checks the fixed error texts. ibe.failure.test.ts mocks a noble
failure. Coverage of ibe.ts is 100 % and is now a threshold. The site
does not change.
npm run verify is green: 2,397 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
Aprobadas en el plan de la fase 2 (sección 3 y decisión 5) e instaladas con su versión exacta. `ibe.ts` importa noble desde el paso 3, pero la página todavía no lo usa, así que el sitio no cambia hasta que llegue la apertura.
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| Paquete | Versión | Licencia | Uso |
|---|---|---|---|
| `age-encryption` | 0.3.1 | BSD-3-Clause | las tres envolturas `age` (§28), con `Identity` y `Recipient` propios para el stanza `tlock` |
| `@noble/curves` | 2.4.0 | MIT | BLS12-381 del núcleo IBE y de la verificación de releases; también el oráculo de `bls12381.contrast.test.ts` |
Phase 2, step 5a: open capsules, steps 9 to 18, in memory
src/lib/dkc/open.ts runs steps 9 to 18 of spec §63 on top of the steps
1 to 8 of inspectWith. It follows capsule.Open of the Go reference, with
its checks, codes and texts:
- step 9: the access credentials (the .dkk as an object, then its
capsule_id and capsule_digest), then the release, never before the
round time. Any failure of the source is ERR_RELEASE_UNAVAILABLE
alone, keeping its text and its cause (correction 6);
- step 10: verifyRelease;
- steps 11 to 13: OUTER_TIME_AGE, the structure against access_policy
and INNER_ACCESS_AGE;
- steps 14 to 18: CONTROL_CBOR, header_binding, I_PAYLOAD, PAYLOAD_AGE
and the commit.
The three age files open with the Decrypter of age-encryption and
identities that apply the rules of Go's agewrap: the tlock identity on
ibe.ts, and the access and payload identities on x25519.ts. A failure of
age that no identity reports is ERR_INTEGRITY with the fixed reason of
its phase, header or STREAM, never the text of age-encryption. The
plaintext is decrypted in memory and returned only after step 18.
Streaming to OPFS is step 5b.
src/lib/dkc/x25519.ts opens one age X25519 stanza at a time, in the
order of age's X25519Identity. Step 13 must try every identity on every
stanza (spec §36), and age-encryption's Decrypter stops at the first.
Its primitives are the ones age-encryption uses: X25519 and HKDF from
noble curves and hashes, and ChaCha20-Poly1305 from @noble/ciphers
2.4.0. The author approved declaring that package as a direct
dependency on 2026-09-28; it is the copy already installed and bundled.
The guards now allow ciphers, and x25519.ts in the noble allowlist.
src/lib/dkc/bech32.ts ports age's internal/bech32, with its MIT notice,
to read AGE-SECRET-KEY-1 identities.
Tests:
- vectors.test.ts runs all 65 cases of the mutation corpus through open.
Each gives the code and the step of Go, and no case that fails without
the network requests a release. This includes the 34 cases of steps 9
to 18 that were skipped, so the suite no longer skips any test.
- open.test.ts:
- the five official fixtures open to their plaintext, with each
credential, with the checks and details of the reference;
- the unusable noncritical extensions are reported;
- the source failures and the clock;
- age failures by phase;
- CONTROL_CBOR that does not decode, and a low-order share in
INNER_ACCESS_AGE, through an OUTER_TIME_AGE resealed with the FK_TIME
of the Go vectors;
- the texts of the identities.
- x25519.test.ts checks against age-encryption both ways and against the
Go-written stanzas of the fixtures, and covers every low-order share.
- bech32.test.ts has the vectors of the reference.
x25519.ts and bech32.ts are at 100 % coverage, now thresholds. open.ts
is at 100 % of lines; the one branch left is the one for an error that
is not a DateKeysError.
index.ts does not re-export the opening yet. The page imports index.ts,
and re-exporting would pull noble into /inspect (58.7 to 84.9 KB gzip)
even unused; step 8 will load it on demand. The site does not change.
npm run verify is green: 2,490 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
| `@noble/hashes` | 2.4.0 | MIT | los hashes del IBE y el HKDF de los stanzas X25519; se declara porque se importa directamente |
| `@noble/ciphers` | 2.4.0 | MIT | el ChaCha20-Poly1305 de los stanzas X25519 (`x25519.ts`): la misma copia que usa `age-encryption` , así que no añade nada al bundle. Aprobada el 28-09-2026 para abrir los stanzas de uno en uno, como exige §36 |
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
`age-encryption` arrastra `@noble/ciphers` 2.4.0, `@scure/base` 2.4.0 y `@noble/post-quantum` 0.5.4, todos con licencia MIT. `@noble/post-quantum` fija `@noble/curves` y `@noble/hashes` a `~2.0.0` y trae su propia copia 2.0.1, que usa para el ML-KEM híbrido. La decisión 5 la acepta, sin overrides de npm.
Guardas de `src/lib/dependencies.test.ts` , en cada `npm test` :
Phase 2, step 5a: open capsules, steps 9 to 18, in memory
src/lib/dkc/open.ts runs steps 9 to 18 of spec §63 on top of the steps
1 to 8 of inspectWith. It follows capsule.Open of the Go reference, with
its checks, codes and texts:
- step 9: the access credentials (the .dkk as an object, then its
capsule_id and capsule_digest), then the release, never before the
round time. Any failure of the source is ERR_RELEASE_UNAVAILABLE
alone, keeping its text and its cause (correction 6);
- step 10: verifyRelease;
- steps 11 to 13: OUTER_TIME_AGE, the structure against access_policy
and INNER_ACCESS_AGE;
- steps 14 to 18: CONTROL_CBOR, header_binding, I_PAYLOAD, PAYLOAD_AGE
and the commit.
The three age files open with the Decrypter of age-encryption and
identities that apply the rules of Go's agewrap: the tlock identity on
ibe.ts, and the access and payload identities on x25519.ts. A failure of
age that no identity reports is ERR_INTEGRITY with the fixed reason of
its phase, header or STREAM, never the text of age-encryption. The
plaintext is decrypted in memory and returned only after step 18.
Streaming to OPFS is step 5b.
src/lib/dkc/x25519.ts opens one age X25519 stanza at a time, in the
order of age's X25519Identity. Step 13 must try every identity on every
stanza (spec §36), and age-encryption's Decrypter stops at the first.
Its primitives are the ones age-encryption uses: X25519 and HKDF from
noble curves and hashes, and ChaCha20-Poly1305 from @noble/ciphers
2.4.0. The author approved declaring that package as a direct
dependency on 2026-09-28; it is the copy already installed and bundled.
The guards now allow ciphers, and x25519.ts in the noble allowlist.
src/lib/dkc/bech32.ts ports age's internal/bech32, with its MIT notice,
to read AGE-SECRET-KEY-1 identities.
Tests:
- vectors.test.ts runs all 65 cases of the mutation corpus through open.
Each gives the code and the step of Go, and no case that fails without
the network requests a release. This includes the 34 cases of steps 9
to 18 that were skipped, so the suite no longer skips any test.
- open.test.ts:
- the five official fixtures open to their plaintext, with each
credential, with the checks and details of the reference;
- the unusable noncritical extensions are reported;
- the source failures and the clock;
- age failures by phase;
- CONTROL_CBOR that does not decode, and a low-order share in
INNER_ACCESS_AGE, through an OUTER_TIME_AGE resealed with the FK_TIME
of the Go vectors;
- the texts of the identities.
- x25519.test.ts checks against age-encryption both ways and against the
Go-written stanzas of the fixtures, and covers every low-order share.
- bech32.test.ts has the vectors of the reference.
x25519.ts and bech32.ts are at 100 % coverage, now thresholds. open.ts
is at 100 % of lines; the one branch left is the one for an error that
is not a DateKeysError.
index.ts does not re-export the opening yet. The page imports index.ts,
and re-exporting would pull noble into /inspect (58.7 to 84.9 KB gzip)
even unused; step 8 will load it on demand. The site does not change.
npm run verify is green: 2,490 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- `package.json` declara exactamente estas cuatro dependencias, con versión exacta;
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- `package-lock.json` no contiene `tlock-js` ni `drand-client` , ningún noble 1.x, ni más copias 2.x de `@noble/curves` o `@noble/hashes` que la 2.4.0 de la raíz y la 2.0.1 bajo `@noble/post-quantum` ;
- ningún fichero de `src/` importa `tlock-js` ni `drand-client` ;
Phase 2, step 5b: open from a Blob, streaming to an output
open(dkc, opts) now takes a Uint8Array or a Blob, such as a File.
- Of a Blob it reads only the prefix that steps 1 to 8 need.
inspectedLength and readCapsule move from src/lib/inspector/load.ts to
src/lib/dkc/prefix.ts, and the page imports them from the library.
- The .dkk capsule_digest is computed over the Blob's stream with the
new src/lib/dkc/digest.ts, an incremental SHA-256 on @noble/hashes,
since Web Crypto hashes whole buffers only. digest.ts joins the noble
allowlist of the guards.
- PAYLOAD_AGE is decrypted in streaming.
The plaintext goes to memory, as before, or to opts.output, a
WritableStream. The output is written as age authenticates each chunk,
closed only after step 18, and aborted after any failure at any step,
even before step 17 (spec §56). A failure of the output is ERR_INTEGRITY
with its text, as Go keeps the error of the writer of the plaintext.
Tests:
- the fixtures from Blobs, to memory and to an output;
- a truncated two-chunk payload whose first chunk reached the output
before the abort;
- early failures that never write;
- write and close failures, and an abort that fails;
- a .dkk without capsule_digest;
- the whole mutation corpus again as Blobs into an output, aborted in
every case;
- digest.ts against Web Crypto.
Coverage of digest.ts is 100 % and a threshold.
Checked in the browser (dev server, real OPFS). time_only.dkc, two
STREAM chunks, opened from a Blob into FileSystemFileHandle.createWritable
gives 78,000 bytes with the SHA-256 of its sidecar. The same file
truncated fails at step 17, and the OPFS file keeps its previous
content. The quota check, the temporary file and the download belong to
the page, in step 8.
npm run verify is green: 2,560 tests. The site does not change.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- solo `digest.ts` , `ibe.ts` , `release.ts` , `x25519.ts` y los tests nombran `@noble/` , siempre con subrutas de `@noble/curves` , `@noble/hashes` y `@noble/ciphers` que resuelven a la copia 2.4.0 de la raíz;
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
- cada comprobación se ejecuta también sobre entradas malas, así que una guarda que dejara de detectar algo fallaría.
`check-build.mjs` hace la misma comprobación sobre el bundle del cliente.
Coste medido en el bundle el 28-09-2026, con una compilación de prueba de Vite 8 minificada (gzip de nivel 9):
| Qué se importa | Minificado | gzip |
|---|---|---|
| `Decrypter` de `age-encryption` | 153 645 B | 48 032 B |
| `Decrypter` y `Encrypter` | 183 650 B | 55 915 B |
| `bls12_381` y `sha256` de noble | 92 637 B | 28 090 B |
| Todo lo anterior | 239 454 B | 72 783 B |
`age-encryption` importa de forma estática sus recipients ML-KEM híbridos, P-256 y scrypt. Por eso el `Decrypter` arrastra `@noble/post-quantum` y la copia 2.0.1 de noble, aunque DateKeys no los use: son unos 99 KB de los 212 KB de código antes de minificar. Como referencia, `/inspect` carga hoy unos 157 KB de JavaScript (58,7 KB con gzip). La cifra exacta cambia unos bytes en cada compilación, por la versión que SvelteKit incrusta.
`npm audit --omit=dev` no encuentra vulnerabilidades. El `npm audit` completo encuentra 2 de gravedad baja en el tooling: `cookie` < 0.7.0 ( GHSA-pxg6-pf52-xh8x ), que llega a trav é s de `@sveltejs/kit` 2 . 70 . 3 . Esa es la ú ltima versi ó n y sigue pidiendo `cookie` ^ 0 . 6 . 0 . Solo afecta a la gesti ó n de cookies del servidor de SvelteKit , que un sitio est á tico no usa .
## Tooling de desarrollo
| Paquete | Versión | Estado |
|---|---|---|
| `typescript` | 5.9.3 | en `package.json` ; ya usado en el prototipo |
| `vitest` | 5.0.1 | en `package.json` ; ya usado en el prototipo |
| `@vitest/coverage-v8` | 5.0.1 | en `package.json` ; cobertura del 100 % del codec |
| `@types/node` | 24.13.6 | en `package.json` ; tests que leen `testdata/` desde disco |
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `vite` | 8.3.0 | en `package.json` ; dependencia peer obligatoria de `vitest` 5.0.1 y base del paso 5; la versión del prototipo |
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
| `svelte` | 5.57.1 | en `package.json` ; paso 5 |
| `@sveltejs/kit` | 2.70.3 | en `package.json` ; paso 5 |
| `@sveltejs/vite-plugin-svelte` | 7.3.0 | en `package.json` ; paso 5 |
| `svelte-check` | 4.7.6 | en `package.json` ; paso 5, `npm run check` |
| `@sveltejs/adapter-static` | 3.0.10 | en `package.json` ; paso 5: la página es estática y no necesita servidor |
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
`@noble/curves` 2.4.0 estaba en esta lista como oráculo de `bls12381.contrast.test.ts` y ha pasado a dependencia de ejecución en la fase 2.
TypeScript implementation of DateKeys v0.8.2, steps 1 to 8
Canonical CBOR codec of the spec §58 profile, hand-written schema codecs
(profile, PUBLIC_HEADER, CONTROL_CBOR, .dkk, extensions), DKC1/DKK1
framing, a strict age header parser, dk1_ parsing and nanosecond date to
round resolution, and inspect (spec §63 steps 1 to 8) with the same checks
and view as "datekeys inspect -json". No runtime dependencies.
216 tests, cbor.ts at 100 % coverage, typecheck of the library without
Node types. A differential comparison with the Go reference at afb44a3
found no verdict, code or step disagreement in about 336,000 inputs. The
harness for the future Go vector files runs them when they appear.
vite 8.3.0 is declared explicitly: it is a required peer of vitest 5.0.1
that legacy-peer-deps does not install.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
Todas las versiones se fijan exactas y `package-lock.json` se versiona. `.npmrc` activa `legacy-peer-deps` porque npm 11.5.2 falla al resolver los peers opcionales de `vitest` 5.0.1 (`Cannot read properties of null (reading 'edgesOut')`); con esa opción npm no instala peers, así que el peer obligatorio `vite` está declarado explícitamente.
## testdata
```bash
npm run testdata:sync
```
Copia `testdata/` de `../datekeys-go` en `HEAD` , leyendo los blobs con git para no arrastrar cambios sin commit, y escribe `testdata/SOURCE.json` con el commit completo y el SHA-256 de cada fichero. Para fijar otro commit: `node scripts/sync-testdata.mjs sync --commit <rev>` .
```bash
npm run testdata:check
```
Comprueba que los ficheros coinciden con `SOURCE.json` , sin faltantes ni sobrantes, y vuelve a leerlos del repositorio Go en el commit registrado. Sin la opción `--against` , `node scripts/sync-testdata.mjs check` verifica solo la copia local. Ambos comandos usan solo Node y git.
`.gitattributes` marca `testdata/**` como binario para que git no altere ningún byte.
Copia actual: la de `testdata/SOURCE.json` (rama `v0.8.2` ).
## Licencia
Apache-2.0 ([LICENSE](LICENSE)), como la librería Go de referencia. El código que se derive de terceros conserva su aviso de copyright y licencia en el propio fichero; el primero previsto es el núcleo IBE de la fase 2, derivado de `tlock-js` (Apache-2.0 OR MIT).