You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys-App/src/lib/inspector/release-input.ts

92 lines
4.2 KiB

Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
// The release that the person opening a capsule supplies directly (spec §63
// step 10): pasted from drand's HTTP API, or taken from the record of an
// official fixture. The page never fetches it: it links to the drand URL of
// the round, which the person opens themselves, and verifies what comes back
// at step 10 like any release the caller supplies (plan of phase 2,
// decision 4, confirmed by the author on 28-09-2026).
//
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
// Of what is pasted only the round and the signature are read, with the
// strict reader of drand's JSON of the library (spec v0.16, §47.1), so that
// the page never reads another round than step 10 would: no name twice, names
// exact, the round a number of 1 to 2^53 - 1. drand's answer also carries
// `randomness`, and other drand endpoints carry a public key, a period or a
// chain hash: none of them is read, because the root of trust is the pinned
// profile and never a remote input (spec §11, §13).
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
//
// No noble here: this module is part of the page's initial bundle.
import { fromHex } from '../dkc/index.ts';
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
import { jsonRound, strictJSON } from '../dkc/releaseobject.ts';
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
/** A release as the caller supplies it, before any verification. */
export interface SuppliedRelease {
readonly round: number;
readonly signature: Uint8Array;
}
/** The longest text read as a release: drand's answer is about 230 characters. */
export const MAX_RELEASE_TEXT = 4096;
/** What the person pasted, read as a release, or why it cannot be. */
export type ReleaseInput =
| { readonly ok: true; readonly release: SuppliedRelease; readonly form: 'json' | 'hex' }
| { readonly ok: false; readonly problem: string };
/**
* Reads the text pasted as the release of `round`: drand's JSON answer,
* `{"round": …, "signature": "…"}`, or a signature alone in hexadecimal,
* which is then taken as the release of `round`. Nothing is verified here:
* a round other than `round` or a signature that is not a valid one goes to
* step 10, which reports it with its normative code.
*/
export function parseReleaseText(text: string, round: number): ReleaseInput {
const s = text.trim();
if (s === '') return { ok: false, problem: 'Pega la respuesta de drand o la firma de la ronda.' };
if (s.length > MAX_RELEASE_TEXT) {
return { ok: false, problem: `El texto pegado tiene ${s.length} caracteres; la respuesta de drand tiene unos 230.` };
}
if (s.startsWith('{')) return fromJSON(s);
if (!/^[0-9a-fA-F]+$/.test(s) || s.length % 2 !== 0) {
return {
ok: false,
problem: 'No es la respuesta de drand (un objeto JSON) ni una firma en hexadecimal (un número par de cifras 0-9 y a-f).',
};
}
return { ok: true, release: { round, signature: fromHex(s) }, form: 'hex' };
}
function fromJSON(s: string): ReleaseInput {
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
// JSON text that starts with { and that the strict reader reads is an
// object without a name twice.
const members = strictJSON(new TextEncoder().encode(s));
if (members === undefined) {
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
return { ok: false, problem: 'Empieza por { pero no es JSON válido. Copia la respuesta de drand entera.' };
}
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
const member = (name: string) => members.find((m) => m.name === name);
const r = member('round');
const round = r === undefined ? undefined : jsonRound(r);
if (round === undefined) {
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
return { ok: false, problem: 'El campo round falta o no es un número entero de ronda.' };
}
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
const signature = member('signature');
if (signature?.kind !== '"' || !/^(?:[0-9a-fA-F]{2})+$/.test(signature.str)) {
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
return { ok: false, problem: 'El campo signature falta o no es hexadecimal.' };
}
Specification 0.16 draft: a seal without accuracy, drand's JSON read strictly The draft v0.16 of datekeys-go at 4f78854 (branch v0.16): SPEC_VERSION 0.16, and testdata, wordlists and annex synced from that commit. The annex is §79 of the draft, with the CC BY-ND 4.0 license of the specification in its title and the key of words in 79.7. A seal without accuracy proves nothing before the opening date (§29.7, §29.11, as 7e3b810): a valid seal is S4 only when its token carries accuracy and t plus the accuracy is before round_time; otherwise S5, with the first reason that holds: late, no accuracy under the BTSP policy of ETSI EN 319 421 (0.4.0.2023.1.1), or no accuracy. cms.ts reads hasAccuracy and the policy of the token (tokenIsBTSP); securitycms.ts gives SealReason, Detail.sealReason and SignerLine.reason; S5 has no fixed text any more, and verdictLines writes it and the line of a signer of F6 with the reason, the texts of Go byte for byte (sealReasonText). encryptFiles returns the verdicts of the area it wrote in Encrypted.security, as Result.Security of Go, so that a writer warns of a seal without accuracy (§62.1 rule 19). drand's JSON is read strictly (§47.1, as b570338): parseDrandJSON, as ParseDrandJSON of Go, reads RFC 8259 JSON in valid UTF-8 whose value is an object, with no name repeated in any object, names compared exactly once their escapes are decoded, a lone escaped surrogate malformed, the round a number without sign, fraction or exponent from 1 to 2^53 - 1, and signature and randomness strings, with the error texts of Go. ParsedRelease is now a Release: no round above 2^53 - 1 is read. The page reads the answers of the relays with it (drand.ts), as the client of Go does, and the pasted release with strictJSON and jsonRound (release-input.ts), so that it never reads another round than step 10. Tests: security_cms.json with seal_reason (143 cases), the 38 JSON inputs of release.json, the new cases of signature2_test.go and drandjson_test.go (with the escapes written as escapes), and the new fixtures: format3_time_and_key_words opens with the identity that the words of its words_text give with normalizeWords and wordKey, in the library and in the page, and format3_full_chunk, whose PAYLOAD_AGE ends in a full STREAM chunk, opens. check-build.mjs counts words_text among the secrets of the fixtures. Reference files made again with Go at 4f78854: mutation-texts.json (its spec field only), ibe-vectors.json (the two new fixtures, the rest unchanged) and signing-vectors.json, in an export of 4f78854 with the same frozen samples read again: the capsules are the same, and the tokens of the sealer, without accuracy, now give S5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 hours ago
return { ok: true, release: { round, signature: fromHex(signature.str) }, form: 'json' };
Phase 2, step 8: the open action of /inspect After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
}
/**
* The drand HTTP API URL of the release of `round` on the network of the
* chain hash `chainHash` (lowercase hexadecimal), for the person to open:
* https://api.drand.sh/<chain hash>/public/<round>. The page links to it and
* never fetches it.
*/
export function drandReleaseURL(chainHash: string, round: number): string {
return `https://api.drand.sh/${chainHash}/public/${round}`;
}
/** The JSON text of a release, as drand writes its round and signature. */
export function releaseText(round: number, signatureHex: string): string {
return JSON.stringify({ round, signature: signatureHex });
}

Powered by TurnKey Linux.