Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
// Vite configuration of the SvelteKit site. The library tests run with
|
|
|
|
|
// vitest.config.ts, which vitest prefers when both files exist.
|
|
|
|
|
import { sveltekit } from '@sveltejs/kit/vite';
|
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
|
|
|
import { mkdirSync, writeFileSync } from 'node:fs';
|
|
|
|
|
import { join } from 'node:path';
|
|
|
|
|
import { defineConfig, type Plugin } from 'vite';
|
|
|
|
|
|
|
|
|
|
// Records what the client bundle is made of, for scripts/check-build.mjs:
|
|
|
|
|
// each chunk with the chunks it imports and the modules it contains, with
|
|
|
|
|
// their rendered sizes. The record goes to .svelte-kit/output, outside the
|
|
|
|
|
// site.
|
|
|
|
|
function clientModules(): Plugin {
|
|
|
|
|
let root = process.cwd();
|
|
|
|
|
return {
|
|
|
|
|
name: 'datekeys:client-modules',
|
|
|
|
|
apply: 'build',
|
|
|
|
|
configResolved(config) {
|
|
|
|
|
root = config.root;
|
|
|
|
|
},
|
|
|
|
|
generateBundle(_, bundle) {
|
|
|
|
|
if (this.environment.name !== 'client') return;
|
|
|
|
|
const chunks: Record<string, { imports: string[]; dynamicImports: string[]; modules: Record<string, number> }> = {};
|
|
|
|
|
for (const out of Object.values(bundle)) {
|
|
|
|
|
if (out.type !== 'chunk') continue;
|
|
|
|
|
chunks[out.fileName] = {
|
|
|
|
|
imports: out.imports,
|
|
|
|
|
dynamicImports: out.dynamicImports,
|
|
|
|
|
modules: Object.fromEntries(Object.entries(out.modules).map(([id, m]) => [id.replace(/\\/g, '/'), m.renderedLength])),
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
const dir = join(root, '.svelte-kit', 'output');
|
|
|
|
|
mkdirSync(dir, { recursive: true });
|
|
|
|
|
writeFileSync(join(dir, 'client-modules.json'), JSON.stringify({ chunks }, null, 1));
|
|
|
|
|
},
|
|
|
|
|
};
|
|
|
|
|
}
|
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
|
|
|
|
|
export default defineConfig({
|
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and
@noble/hashes 2.4.0 become exact runtime dependencies (plan section 3,
decision 5). The lockfile gains six packages: age-encryption,
@noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and
its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports
them yet, so the site does not change.
- src/lib/dependencies.test.ts guards them. package.json declares exactly
these three, pinned. The lockfile has no tlock-js, drand-client or noble
1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under
@noble/post-quantum. No file of src/ imports tlock-js or drand-client.
Only ibe.ts, release.ts and the tests name @noble/, always subpaths of
@noble/curves or @noble/hashes that resolve to the root 2.4.0 copy.
Every check also runs on bad inputs. It replaces the "only tests import
@noble/curves" test of bls12381.contrast.test.ts.
- vite.config.ts records the modules of each client chunk in
.svelte-kit/output/client-modules.json. check-build.mjs fails if the
bundle holds tlock-js, drand-client or @babel/*, or a nested copy
other than noble under @noble/post-quantum. It also reports the
JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip.
- Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter
is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256
28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM
recipients statically, so post-quantum and its nested noble copy are
about 99 KB of the Decrypter's 212 KB of rendered code.
- npm audit --omit=dev: no vulnerabilities. The full audit finds two low
ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3,
which is the latest version and affects only SvelteKit's server.
npm run verify is green: 2,384 tests.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
|
|
|
plugins: [sveltekit(), clientModules()],
|
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
build: {
|
|
|
|
|
// Never inline an asset as a data: URL. The CSP allows only the page's
|
|
|
|
|
// own origin, so the official fixtures (src/lib/inspector/fixtures.ts)
|
|
|
|
|
// must be separate same-origin files, whatever their size.
|
|
|
|
|
assetsInlineLimit: 0,
|
|
|
|
|
},
|
|
|
|
|
server: {
|
|
|
|
|
fs: {
|
|
|
|
|
// The dev server serves the official fixtures straight from testdata/,
|
|
|
|
|
// the single source of truth; the build copies them as hashed assets.
|
|
|
|
|
allow: ['testdata/fixtures'],
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
});
|