As the spec v0.11 draft decides after the review (38.1):
- the salt is "DateKeys llave de palabras v2|chain|round|capsule_id", so
the same words give another key in each capsule and a dictionary
cannot attack together the many capsules of a popular round;
- the words are lowered with the table of Unicode 18.0.0 of pathrule;
- wordkey.Check refuses controls, Default_Ignorable code points and
unassigned ones, and counts toward the six words only the different
ones of three letters or more.
EncryptOptions.Words takes the words: the writer derives their identity
once it has drawn capsule_id, and adds its recipient to the credentials.
The CLI passes them to the writer, and decrypt salts them with the
capsule_id of the capsule. New vector of 38.1.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
returnnil,nil,errors.New("capsule: time_and_key needs at least one recipient or a portable key")
returnnil,nil,errors.New("capsule: time_and_key needs at least one recipient, a portable key or a key of words")
}
ifn>agewrap.AccessSlots{
returnnil,nil,fmt.Errorf("capsule: time_and_key takes at most %d credentials, recipients and portable key together; %d given",agewrap.AccessSlots,n)
returnnil,nil,fmt.Errorf("capsule: time_and_key takes at most %d credentials, recipients, portable key and key of words together; %d given",agewrap.AccessSlots,n)