import { test } from "node:test"; import assert from "node:assert/strict"; import { generateKeyPairSync } from "node:crypto"; import { seal } from "../sealedbox.ts"; // The definitive proof that this seal interoperates with Go's box.OpenAnonymous (the host's Unseal // and mesh-controller's secrets.Seal/Open) is a cross-language test in mesh-controller // (internal/secrets/sealedbox_xcheck_test.go), which opens a fixture this module's seal() produced. // These tests hold the TypeScript side: the output has the crypto_box_seal shape, and it is // randomised so a rotation that changed nothing looks nothing like one that changed everything. /** A node public key as the mesh records it: raw 32-byte X25519, standard base64. */ function aNodePublicKey(): string { const kp = generateKeyPairSync("x25519"); const x = (kp.publicKey.export({ format: "jwk" }) as { x: string }).x; return Buffer.from(x, "base64url").toString("base64"); } test("a seal has the crypto_box_seal shape: ephemeralPub(32) + tag(16) + ciphertext(len)", () => { const pub = aNodePublicKey(); const msg = Buffer.from("rt-a-refresh-token", "utf8"); const blob = Buffer.from(seal(new Uint8Array(msg), pub), "base64"); // 32 (ephemeral public key) + 16 (Poly1305 tag) + message length. assert.equal(blob.length, 32 + 16 + msg.length); }); test("two seals of the same value differ — a fresh ephemeral key each time", () => { const pub = aNodePublicKey(); const msg = new Uint8Array(Buffer.from("rt-a-refresh-token", "utf8")); assert.notEqual(seal(msg, pub), seal(msg, pub)); }); test("a public key that is not 32 bytes is refused before anything is sealed", () => { assert.throws(() => seal(new Uint8Array([1, 2, 3]), Buffer.from("short").toString("base64"))); });