You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys/capsule/example_test.go

88 lines
2.9 KiB

package capsule_test
import (
"bytes"
"context"
"encoding/hex"
"errors"
"fmt"
"strings"
"time"
datekeys "github.com/datekeys/datekeys-go"
"github.com/datekeys/datekeys-go/accesskey"
"github.com/datekeys/datekeys-go/capsule"
"github.com/datekeys/datekeys-go/profile"
"github.com/datekeys/datekeys-go/provider"
)
// The published Quicknet signature of round 1000. In real use the release
// comes from drand.New(), which verifies it the same way.
var round1000, _ = hex.DecodeString("b44679b9a59af2ec876b1a6b1ad52ea9b1615fc3982b19576350f93447cb1125e342b73a8dd2bacbe47e4b6b63ed5e39")
func Example() {
reg, err := profile.Default()
if err != nil {
panic(err)
}
p := profile.Quicknet()
// A clock stopped at the Quicknet genesis makes round 1000
// (2023-08-23T15:59:24Z) "the future", so the example runs offline.
genesis := func() time.Time { return time.Unix(p.GenesisTime, 0) }
var dkc bytes.Buffer
res, err := capsule.Encrypt(&dkc, strings.NewReader("hello from the past"), capsule.EncryptOptions{
Profile: p,
UnlockAt: time.Date(2023, 8, 23, 15, 59, 24, 0, time.UTC),
Policy: capsule.TimeAndKey,
NewPortableKey: true,
Now: genesis,
})
if err != nil {
panic(err)
}
var dkk bytes.Buffer
if err := accesskey.Encode(&dkk, res.PortableKey); err != nil {
panic(err)
}
fmt.Println("round", res.DateKey.Round, "unlocks at", res.UnlockAt.Format(time.RFC3339))
// Before the round: no request is made.
key, _ := accesskey.Decode(&dkk)
src := provider.ReleaseSourceFunc(func(_ context.Context, _ *profile.Profile, c provider.Condition) (provider.Release, error) {
return provider.Release{Round: c.Round, Signature: round1000}, nil
})
opts := capsule.OpenOptions{Registry: reg, Source: src, AccessKey: key, Now: genesis}
_, err = capsule.Open(context.Background(), &bytes.Buffer{}, bytes.NewReader(dkc.Bytes()), opts)
fmt.Println("too early:", errors.Is(err, datekeys.ErrReleaseUnavailable))
// After the round: the release is verified locally and the capsule opens.
opts.Now = time.Now
var plain bytes.Buffer
if _, err := capsule.Open(context.Background(), &plain, bytes.NewReader(dkc.Bytes()), opts); err != nil {
panic(err)
}
fmt.Println(plain.String())
// Output:
// round 1000 unlocks at 2023-08-23T15:59:24Z
// too early: true
// hello from the past
}
func ExampleInspect() {
reg, _ := profile.Default()
p := profile.Quicknet()
var dkc bytes.Buffer
_, _ = capsule.Encrypt(&dkc, strings.NewReader("x"), capsule.EncryptOptions{
Profile: p,
UnlockAt: time.Date(2030, 1, 1, 0, 0, 0, 0, time.UTC),
Now: func() time.Time { return time.Date(2026, 9, 25, 0, 0, 0, 0, time.UTC) },
})
in, err := capsule.Inspect(bytes.NewReader(dkc.Bytes()), capsule.InspectOptions{Registry: reg})
if err != nil {
panic(err)
}
fmt.Println(in.Header.Policy, in.Header.DateKey.Round, in.UnlockAt.Format(time.RFC3339), len(in.Checks), "checks passed")
// Output: time_only 66884212 2030-01-01T00:00:00Z 8 checks passed
}

Powered by TurnKey Linux.