v0.10
main
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0
${ noResults }
4 Commits (4377a87f7ff230ffbe7ebcface2a57e1d1352edf)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
4377a87f7f |
The writers as Go: test vectors only through testing/, and the note
Fixes T9, T11 and T12 of the review of the session of 1 and 2 October: - T9: EncryptOptions no longer has testVectors nor areaLen, with which any caller could write format 2, or an area of 512 bytes, which rule 13 forbids and which tells that the capsule has no signature (§55.2). What only a generator of test vectors asks, as Go's TestVectors, is the TestVectors argument of the core of writer.ts, which only the helpers of testing/encrypt.ts pass: encryptVectors and encryptWith write format 2, and encryptFilesWith another area, with which the tests still reproduce byte for byte the fixtures of 512 bytes. encrypt keeps the shape of capsule.Encrypt: without a generator it fails with the text of Go, whatever the caller adds. dependencies.test.ts refuses an import of testing/ from anything but the tests and testing/ itself, check-build.mjs refuses a test or a module of testing/ in the bundle of the pages, and note.ts joins the modules that index.ts must not re-export. - T12: encrypt as a generator refuses a public note and an area with the text of Go, "capsule: format 2 has no security area or public note: ...", after the head and the length, as capsule.Encrypt. The errors of the note carry "capsule: ", and newSealer checks the note, then the profile and the clock, in the order of Go. The tests compare the texts byte for byte, also for two faults at once. - T11: capsuleLength takes the public note and predicts exactly the size of the .dkc with it: eight notes of 1 to 1024 bytes, across the boundaries of the heads of CBOR, with both policies and with other extensions. The 40 texts that capsule.EncryptFiles and extension.CheckNote give at spec-v0.11 on the same notes and options, taken with an oracle, are those of this library; HEAD gave another one in 23 of them. npm run verify passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
c879b104d2 |
Format 3, step 4: format 2 only for test vectors, and /create writes format 3
Spec 62.1 rule 1: a writer writes format 3, and only a generator of test vectors may write format 2. As capsule.Encrypt at spec-v0.10, encrypt now fails without EncryptOptions.testVectors, and with a comment, a declared author or head extensions, which format 2 has no place for, with the texts of the reference, before anything else is checked. The tests of the writer, encryptWith, the interoperability cases and the sample script ask for it. The create page writes format 3 with encryptFiles: the chosen file goes under its name, which is its path in the capsule, with its modification time, both sealed in the head. The plan carries the file as encryptFiles takes it, and its size is exact again with bodyLength. A name that breaks a rule of the paths makes the writing fail with the text of the rule; several files, folders, editable paths, the comment and the author come with step 7. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
3a9d2b11fe |
Phase 3, steps 6 and 7: the create page
/create seals a person's file into a .dkc of format 2 and, when asked, a portable .dkk, in the browser and without network, with the decisions the author confirmed in step 6: time_only by default, the zone of the device with a selector, the warnings of §53 and §50 beyond 365 days, a notice of preliminary protocol, and files named capsula-<opening time, UTC>. - lengths.ts: sealedControlLength moves out of writer.ts, and capsuleLength gives the size of the .dkc before writing it; the property loop checks it on every capsule (500 seeds pass). - datekey.ts: LONG_HORIZON_SECONDS and isLongHorizon. - src/lib/inspector: localtime.ts (local times of a zone as UTC instants, a skipped time refused, a repeated one taken at its later instant), create-input.ts (the form, checked in its order) and creator.ts (the writing, loaded on demand), all at 100 %. - The .dkc goes to an OPFS temporary file, committed only when complete and checked, or to memory up to 64 MiB; the writing can be cancelled. The .dkk stays in memory only; losing it when it is the only credential asks for confirmation. - /inspect also cleans the temporary files of /create, and check-build checks the code loaded on demand of both pages. Checked in the browser on the production build: a capsule made for four minutes later opened afterwards in /inspect with the pasted release and with datekeys decrypt of Go over the network, to the same content. An adversarial review found one major and eight minor issues, all fixed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
8473fdf709 |
Phase 3, steps 3 and 4: the writer of capsule format 2
encrypt(src, opts) writes a .dkc of format 2 and, when asked, a portable .dkk (spec §61, §62, §62.1), in the order and with the texts and codes of capsule.Encrypt: - L known in advance: the size of a Uint8Array or a Blob, or the length declared with a ReadableStream; a source of another length fails with Go's texts; - reforzado padding by default, or bloque256; - 1 to 16 credentials, canonical and not of low order, a dummy in each slot left, whose scalar is wiped once its public key is derived, and a uniform order of the 16; - SEALED_CONTROL_LEN from the formula of §62.1, checked against the real seal; - the self-checks of rule 11, plus OUTER_TIME_AGE under the reader's rules and the header of PAYLOAD_AGE opened by I_PAYLOAD before anything is written. The content is streamed in pieces of 64 KiB, then the zeros of the padding, into memory (up to MAX_MEMORY_DKC) or an output that is closed only once the capsule is complete and checked and aborted on any failure. The core in writer.ts takes its random values from the caller: encrypt.ts passes crypto.getRandomValues, and only testing/encrypt.ts fixes them. Tests: the deterministic sections of the seven format 2 fixtures of Go byte for byte; round trips with open for both policies, 1 to 16 credentials and every padding boundary; the invalid options; streaming and failures of the source and the output; the internal errors with age-encryption replaced by a spy; a property loop (50 seeds per run, 500 by hand). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |