You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys-App/package.json

45 lines
1.5 KiB

{
"name": "datekeys-ts",
"version": "0.2.0",
"private": true,
"description": "DateKeys in TypeScript: canonical CBOR codec, DKC1/DKK1 parsers, capsule inspector library and its static inspector page; later, browser encryption and decryption.",
"license": "Apache-2.0",
"type": "module",
"engines": {
"node": ">=20"
},
"scripts": {
"dev": "vite dev",
"build": "vite build",
"postbuild": "node scripts/check-build.mjs",
"preview": "vite preview",
"prepare": "svelte-kit sync || echo \"\"",
"check": "svelte-kit sync && svelte-check --tsconfig ./tsconfig.json --fail-on-warnings",
"test": "vitest run",
"coverage": "vitest run --coverage",
"typecheck": "svelte-kit sync && tsc --noEmit && tsc --noEmit -p tsconfig.lib.json",
"build:check": "node scripts/check-build.mjs",
"verify": "npm run check && npm run typecheck && npm run coverage && npm run build",
"testdata:sync": "node scripts/sync-testdata.mjs sync",
"testdata:check": "node scripts/sync-testdata.mjs check --against ../datekeys-go"
},
"devDependencies": {
"@sveltejs/adapter-static": "3.0.10",
"@sveltejs/kit": "2.70.3",
"@sveltejs/vite-plugin-svelte": "7.3.0",
"@types/node": "24.13.6",
"@vitest/coverage-v8": "5.0.1",
"svelte": "5.57.1",
"svelte-check": "4.7.6",
"typescript": "5.9.3",
"vite": "8.3.0",
"vitest": "5.0.1"
Phase 2, step 2: runtime dependencies and their guards - age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and @noble/hashes 2.4.0 become exact runtime dependencies (plan section 3, decision 5). The lockfile gains six packages: age-encryption, @noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports them yet, so the site does not change. - src/lib/dependencies.test.ts guards them. package.json declares exactly these three, pinned. The lockfile has no tlock-js, drand-client or noble 1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under @noble/post-quantum. No file of src/ imports tlock-js or drand-client. Only ibe.ts, release.ts and the tests name @noble/, always subpaths of @noble/curves or @noble/hashes that resolve to the root 2.4.0 copy. Every check also runs on bad inputs. It replaces the "only tests import @noble/curves" test of bls12381.contrast.test.ts. - vite.config.ts records the modules of each client chunk in .svelte-kit/output/client-modules.json. check-build.mjs fails if the bundle holds tlock-js, drand-client or @babel/*, or a nested copy other than noble under @noble/post-quantum. It also reports the JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip. - Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256 28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM recipients statically, so post-quantum and its nested noble copy are about 99 KB of the Decrypter's 212 KB of rendered code. - npm audit --omit=dev: no vulnerabilities. The full audit finds two low ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3, which is the latest version and affects only SvelteKit's server. npm run verify is green: 2,384 tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
},
"dependencies": {
Phase 2, step 5a: open capsules, steps 9 to 18, in memory src/lib/dkc/open.ts runs steps 9 to 18 of spec §63 on top of the steps 1 to 8 of inspectWith. It follows capsule.Open of the Go reference, with its checks, codes and texts: - step 9: the access credentials (the .dkk as an object, then its capsule_id and capsule_digest), then the release, never before the round time. Any failure of the source is ERR_RELEASE_UNAVAILABLE alone, keeping its text and its cause (correction 6); - step 10: verifyRelease; - steps 11 to 13: OUTER_TIME_AGE, the structure against access_policy and INNER_ACCESS_AGE; - steps 14 to 18: CONTROL_CBOR, header_binding, I_PAYLOAD, PAYLOAD_AGE and the commit. The three age files open with the Decrypter of age-encryption and identities that apply the rules of Go's agewrap: the tlock identity on ibe.ts, and the access and payload identities on x25519.ts. A failure of age that no identity reports is ERR_INTEGRITY with the fixed reason of its phase, header or STREAM, never the text of age-encryption. The plaintext is decrypted in memory and returned only after step 18. Streaming to OPFS is step 5b. src/lib/dkc/x25519.ts opens one age X25519 stanza at a time, in the order of age's X25519Identity. Step 13 must try every identity on every stanza (spec §36), and age-encryption's Decrypter stops at the first. Its primitives are the ones age-encryption uses: X25519 and HKDF from noble curves and hashes, and ChaCha20-Poly1305 from @noble/ciphers 2.4.0. The author approved declaring that package as a direct dependency on 2026-09-28; it is the copy already installed and bundled. The guards now allow ciphers, and x25519.ts in the noble allowlist. src/lib/dkc/bech32.ts ports age's internal/bech32, with its MIT notice, to read AGE-SECRET-KEY-1 identities. Tests: - vectors.test.ts runs all 65 cases of the mutation corpus through open. Each gives the code and the step of Go, and no case that fails without the network requests a release. This includes the 34 cases of steps 9 to 18 that were skipped, so the suite no longer skips any test. - open.test.ts: - the five official fixtures open to their plaintext, with each credential, with the checks and details of the reference; - the unusable noncritical extensions are reported; - the source failures and the clock; - age failures by phase; - CONTROL_CBOR that does not decode, and a low-order share in INNER_ACCESS_AGE, through an OUTER_TIME_AGE resealed with the FK_TIME of the Go vectors; - the texts of the identities. - x25519.test.ts checks against age-encryption both ways and against the Go-written stanzas of the fixtures, and covers every low-order share. - bech32.test.ts has the vectors of the reference. x25519.ts and bech32.ts are at 100 % coverage, now thresholds. open.ts is at 100 % of lines; the one branch left is the one for an error that is not a DateKeysError. index.ts does not re-export the opening yet. The page imports index.ts, and re-exporting would pull noble into /inspect (58.7 to 84.9 KB gzip) even unused; step 8 will load it on demand. The site does not change. npm run verify is green: 2,490 tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
"@noble/ciphers": "2.4.0",
Phase 2, step 2: runtime dependencies and their guards - age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and @noble/hashes 2.4.0 become exact runtime dependencies (plan section 3, decision 5). The lockfile gains six packages: age-encryption, @noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports them yet, so the site does not change. - src/lib/dependencies.test.ts guards them. package.json declares exactly these three, pinned. The lockfile has no tlock-js, drand-client or noble 1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under @noble/post-quantum. No file of src/ imports tlock-js or drand-client. Only ibe.ts, release.ts and the tests name @noble/, always subpaths of @noble/curves or @noble/hashes that resolve to the root 2.4.0 copy. Every check also runs on bad inputs. It replaces the "only tests import @noble/curves" test of bls12381.contrast.test.ts. - vite.config.ts records the modules of each client chunk in .svelte-kit/output/client-modules.json. check-build.mjs fails if the bundle holds tlock-js, drand-client or @babel/*, or a nested copy other than noble under @noble/post-quantum. It also reports the JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip. - Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256 28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM recipients statically, so post-quantum and its nested noble copy are about 99 KB of the Decrypter's 212 KB of rendered code. - npm audit --omit=dev: no vulnerabilities. The full audit finds two low ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3, which is the latest version and affects only SvelteKit's server. npm run verify is green: 2,384 tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
"@noble/curves": "2.4.0",
"@noble/hashes": "2.4.0",
"age-encryption": "0.3.1"
}
}

Powered by TurnKey Linux.