v0.10
main
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0
${ noResults }
10 Commits (a670d9768f2808dab17fd233abd188507659ed3b)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
9e5e3ba081 |
The writer signs and seals: the hooks of capsule.EncryptFiles of Go
encryptFiles gains authorKey (alg 1, an AuthorSigner such as AuthorKey), cmsSigner (alg 2, a CMS signature with certificates), sealer (seal_type 2, an RFC 3161 token) and largeArea, as EncryptOptions of Go at spec-v0.12: the same checks in the same order with the same texts, the signature and the seal made with the final control and head and before anything is written, and the security area evaluated by the reader of this library in the context of the capsule before it is written, as Go's security does. The hooks may be asynchronous. The area grows to 64 KiB only when what was signed does not fit and largeArea allows it, and the larger capsule counts in the limit of memory. security.ts encodes the area with its signature and seal, and securitycms.ts encodes SIGNERS. scripts/signing-go-vectors_test.go, run as a test in an export of datekeys-go at spec-v0.12, writes testing/signing-vectors.json: with the draws of crypto/rand of Go and the signatures and tokens of its hooks, encryptFiles writes the eight signed and sealed capsules of Go byte for byte, asks the hooks over the same messages, and fails with the text of Go in the other 15 recipes; and Go opens the five capsules that scripts/signing-ts-samples.mjs writes with this library, its own random values and certificates, with the same verdicts and lines. check-build.mjs fails when a page loads the author keys with the page, or when /inspect can load them at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
2 days ago |
|
|
e2c51bca3a |
The sealing and the envelope of the locator, and its documentation
ageio.ts reads and writes age files as filippo.io/age v1.3.2, with its texts and its order of random draws, which Go's locator copies; it uses only the noble modules that x25519.ts already uses. envelope.ts is Open, Info.OpenLocator, OpenEnvelope, Seal and NewEnvelope of package locator at spec-v0.12, with an injectable random source read in the order of Go. - locator-seal.json (scripts/locator-seal-go-vectors.go): with the same seed, seal and newEnvelope write the bytes of Go; - locator-interop.json (scripts/locator-ts-samples.mjs and locator-go-verdicts.go): Go opens what this library writes, up to a .dkc of 16 MiB and one byte; - vectors.test.ts runs all of testdata/vectors/locator.json with the texts of Go, instead of its spec field only. Shared files: dependencies.test.ts lets ageio.ts import noble and keeps the four locator modules out of index.ts; check-build.mjs fails when a page loads the locator with its first load; vitest.config.ts holds them at 100 % coverage; ibe.ts updates the comment of encryptOnG2WithSigma; README and CHANGELOG describe the port. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
2 days ago |
|
|
4377a87f7f |
The writers as Go: test vectors only through testing/, and the note
Fixes T9, T11 and T12 of the review of the session of 1 and 2 October: - T9: EncryptOptions no longer has testVectors nor areaLen, with which any caller could write format 2, or an area of 512 bytes, which rule 13 forbids and which tells that the capsule has no signature (§55.2). What only a generator of test vectors asks, as Go's TestVectors, is the TestVectors argument of the core of writer.ts, which only the helpers of testing/encrypt.ts pass: encryptVectors and encryptWith write format 2, and encryptFilesWith another area, with which the tests still reproduce byte for byte the fixtures of 512 bytes. encrypt keeps the shape of capsule.Encrypt: without a generator it fails with the text of Go, whatever the caller adds. dependencies.test.ts refuses an import of testing/ from anything but the tests and testing/ itself, check-build.mjs refuses a test or a module of testing/ in the bundle of the pages, and note.ts joins the modules that index.ts must not re-export. - T12: encrypt as a generator refuses a public note and an area with the text of Go, "capsule: format 2 has no security area or public note: ...", after the head and the length, as capsule.Encrypt. The errors of the note carry "capsule: ", and newSealer checks the note, then the profile and the clock, in the order of Go. The tests compare the texts byte for byte, also for two faults at once. - T11: capsuleLength takes the public note and predicts exactly the size of the .dkc with it: eight notes of 1 to 1024 bytes, across the boundaries of the heads of CBOR, with both policies and with other extensions. The 40 texts that capsule.EncryptFiles and extension.CheckNote give at spec-v0.11 on the same notes and options, taken with an oracle, are those of this library; HEAD gave another one in 23 of them. npm run verify passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
2ec7102f1b |
/inspect asks drand for the release when the person asks
The author found copying the release of the round tedious. A button, "Pedir la firma a drand", fetches it from the three public relays of the CLI of the reference, as its client does: raced, 6 s, at most 8 KiB an answer, no redirects, and the randomness checked against the signature; step 10 still verifies the signature with the pinned key, so a relay cannot make the page accept a false one. It is the only connection the page makes to another site, and only on that click: the CSP allows those three origins in connect-src, check-build.mjs requires exactly them, and the footer says so. Pasting by hand still works. Checked in Chromium: api2.drand.sh gave the release of round 32668196 and the capsule opened. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
651178a740 |
Format 3, step 6: /inspect opens format 3
The page opens capsules of format 3. The files go to the temporary file through a ZipSink, a lone file of one segment as it is and a ZIP otherwise, or to memory; the page shows the verdicts first, then the declared author and the comment as unchecked text of the creator, and then each path as text in a bdi, with its size, its mtime and the warnings of the CLI of the reference, compared by their key of R7. - files.ts: pathWarnings, fileFacts, and the names and order of the downloads: the file itself when it is the only one, with the ZIP of its folder second (decision 8), or the ZIP and each file. - opener.ts: OpenedFiles, and noRoom when the ZIP does not fit. - zipsink.ts: NoRoom, thrown by begin before writing anything. - check-build.mjs: the tables of pathrule-tables.ts never come with the first load of a page, and do come with the code on demand of /inspect and /create. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
b176ad2f17 |
Format 3, step 3: read capsule format 3 of spec v0.10
Syncs testdata with datekeys-go at the tag spec-v0.10 (cc35d2c) and moves the reader to the DateKeys Protocol Specification v0.10. The three capsule formats are read. - framing: FORMAT_3, and isPadded for formats 2 and 3. control: schema version 3, with the keys 6 and 7 of version 2. SPEC_VERSION is 0.10. - open: OpenOptions.sink receives the files of a format 3 capsule (sink.ts: Sink with begin, create, commit and abort, as capsule.Sink, and MemorySink). Without one, open rejects with a TypeError right after step 2, before any request, as ErrSinkRequired. Opened gains head, verdicts, areaLen and unusableHeadExtensions. - open3.ts: step 17 of format 3 in its substeps 17.2 to 17.8, as openBody of the reference: a failure of age or a plaintext whose length is not P prevails, the first failing substep decides, and the codes other than ERR_INTEGRITY are reported only after reading PAYLOAD_AGE to its end. Reads grow with the bytes received, never with the lengths BODY declares. A failure of the sink is ERR_INTEGRITY with its text, and the sink is aborted once after begin. - The page: opener.ts opens the fixtures of format 3 into a MemorySink; the open panel says that it does not deliver their files yet, and the glosses of the steps name format 3. check-build.mjs refuses to ship the heads, salts, comments and paths of the format 3 fixtures. Tests: the 21 fixtures, format 3 laid out byte by byte from its record and opened into a sink with its files and verdicts; the 209 cases of the corpus from memory and from a Blob, with the code, the step and, new, the exact text of capsule.Open, frozen by scripts/mutation-go-texts.go in testing/mutation-texts.json, which replays the corpus as internal/testkit does (its extension validator texts included); the 5110 differential cases over 14 bases; paths, path_fold, head_schema and security vectors; the control of schema version 3 in cbor.json; and step 17 on crafted plaintexts sealed again to I_PAYLOAD, whose texts capsule.Open gives on the same plaintexts. ibe-vectors.json gains the nine format 3 fixtures from scripts/ibe-go-vectors.go; the twelve before are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
3a9d2b11fe |
Phase 3, steps 6 and 7: the create page
/create seals a person's file into a .dkc of format 2 and, when asked, a portable .dkk, in the browser and without network, with the decisions the author confirmed in step 6: time_only by default, the zone of the device with a selector, the warnings of §53 and §50 beyond 365 days, a notice of preliminary protocol, and files named capsula-<opening time, UTC>. - lengths.ts: sealedControlLength moves out of writer.ts, and capsuleLength gives the size of the .dkc before writing it; the property loop checks it on every capsule (500 seeds pass). - datekey.ts: LONG_HORIZON_SECONDS and isLongHorizon. - src/lib/inspector: localtime.ts (local times of a zone as UTC instants, a skipped time refused, a repeated one taken at its later instant), create-input.ts (the form, checked in its order) and creator.ts (the writing, loaded on demand), all at 100 %. - The .dkc goes to an OPFS temporary file, committed only when complete and checked, or to memory up to 64 MiB; the writing can be cancelled. The .dkk stays in memory only; losing it when it is the only credential asks for confirmation. - /inspect also cleans the temporary files of /create, and check-build checks the code loaded on demand of both pages. Checked in the browser on the production build: a capsule made for four minutes later opened afterwards in /inspect with the pasted release and with datekeys decrypt of Go over the network, to the same content. An adversarial review found one major and eight minor issues, all fixed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
48d6704b4b |
Phase 2, step 8: the open action of /inspect
After steps 1 to 8, a valid capsule whose date has passed on the device clock can be opened in the page: steps 9 to 18 of spec section 63 with open, loaded on demand with a dynamic import (opener.ts), so noble and age-encryption stay out of the first load of every page. - The release is supplied directly by the person (spec 63, step 10): drand's JSON answer or the bare signature, pasted after opening the drand URL the page links to, or the release in the record of an official fixture. The page never fetches it and reads only its round and signature (spec 11, 13). The CSP is unchanged. - time_and_key credentials: a .dkk (readAccessKey reads at most 12 bytes + 16 MiB + 1) or age identities, one per line. - The plaintext of the person's own file goes to a temporary OPFS file (tempfile.ts), committed only after step 18 (spec 56), offered for download and deleted on request, with another capsule, on pagehide and, if left over, on the next visit. One directory and one Web Lock per tab keep other tabs' clean-up away from files in use. Without OPFS, or when the browser refuses it, capsules up to 64 MiB open in memory. An opening in progress stops when another capsule is loaded. - opening.ts builds the page model of steps 9 to 18 as the reference records them; fixtures show their plaintext and compare its SHA-256 with their record. - licenses.txt: the notices of tlock-js (ibe.ts) and age (bech32.ts), the license of every package in the client bundle, Vite's and rolldown's runtime code, and the site's own license. check-build now fails if a notice is missing, or if a page loads noble, @scure/base or age-encryption with its first load. - The home page no longer says that the page never asks for keys. Checked in the browser on the production build: the time_only, time_and_key_portable (with its .dkk) and time_and_key_recipients (with a pasted identity) fixtures open with the SHA-256 of their records; a tampered signature fails at step 10 and a tampered STREAM chunk at step 17, with no download and no file left; an own file opens to OPFS, downloads without a CSP violation and is deleted with its lock; a left over directory goes on the next visit; no request leaves the origin. An adversarial review (four dimensions, each finding checked by a refuter) confirmed 15 findings, all fixed here. 2611 tests; coverage 100 % of the new modules, now a threshold. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
74e1215ee1 |
Phase 2, step 2: runtime dependencies and their guards
- age-encryption 0.3.1, @noble/curves 2.4.0 (moved from dev) and @noble/hashes 2.4.0 become exact runtime dependencies (plan section 3, decision 5). The lockfile gains six packages: age-encryption, @noble/ciphers 2.4.0, @scure/base 2.4.0, @noble/post-quantum 0.5.4 and its own @noble/curves and @noble/hashes 2.0.1. No file of src/ imports them yet, so the site does not change. - src/lib/dependencies.test.ts guards them. package.json declares exactly these three, pinned. The lockfile has no tlock-js, drand-client or noble 1.x, and no noble 2.x copy other than 2.4.0 at the root and 2.0.1 under @noble/post-quantum. No file of src/ imports tlock-js or drand-client. Only ibe.ts, release.ts and the tests name @noble/, always subpaths of @noble/curves or @noble/hashes that resolve to the root 2.4.0 copy. Every check also runs on bad inputs. It replaces the "only tests import @noble/curves" test of bls12381.contrast.test.ts. - vite.config.ts records the modules of each client chunk in .svelte-kit/output/client-modules.json. check-build.mjs fails if the bundle holds tlock-js, drand-client or @babel/*, or a nested copy other than noble under @noble/post-quantum. It also reports the JavaScript each page loads: /inspect today loads 157 KB, 58.7 KB gzip. - Measured with a probe build (Vite 8, minified, gzip 9): the Decrypter is 48 KB gzip, with the Encrypter 56 KB, noble BLS12-381 plus SHA-256 28 KB, and all of them 73 KB. age-encryption imports its hybrid ML-KEM recipients statically, so post-quantum and its nested noble copy are about 99 KB of the Decrypter's 212 KB of rendered code. - npm audit --omit=dev: no vulnerabilities. The full audit finds two low ones in the tooling: cookie < 0.7.0 through @sveltejs/kit 2.70.3, which is the latest version and affects only SvelteKit's server. npm run verify is green: 2,384 tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
2 weeks ago |
|
|
5f8c8c8031 |
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and /inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file picker, dropped anywhere on the page, or taken from the official fixtures bundled at build time. It shows every step, the decoded header, the unlock date in UTC and local time, and each extension's id, version, criticality, length and hex, with a text view and an informative CBOR diagnostic view, all escaped and labelled as unauthenticated before step 15. Copiar JSON copies the exact "datekeys inspect -json" view. No network: a hash-mode Content-Security-Policy with connect-src 'self' is the first element of every page, and scripts/check-build.mjs verifies it, the fixtures and the absence of external URLs after every build. Large files are read only up to what steps 1 to 8 need. Reviewed for design and accessibility (WCAG AA contrast, keyboard, focus, live status, 360 px), security and correctness; 262 tests pass, svelte-check has no warnings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
2 weeks ago |