The parts of the agent module that hold whichever way the console is registered: X25519 + HKDF + AES-GCM from Node's own library so the bundle carries no dependency; the predecessor's lineage rule (rotation only if newer, a re-issue adopted, a switch regardless) with its incidents as tests; an atomic 0600 write that strips any refresh token and keeps keys it does not know; the account read from the agent's own state file. Manifest and renderer follow.
32 lines
1.1 KiB
TypeScript
32 lines
1.1 KiB
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { generateKeyPair, open, seal } from "../dist/seal.js";
|
|
|
|
test("a box opens with its recipient's key and yields the value", () => {
|
|
const k = generateKeyPair();
|
|
assert.equal(open(seal("at-secret", k.publicKey), k.privateKey), "at-secret");
|
|
});
|
|
|
|
test("a box sealed for one node does not open with another node's key", () => {
|
|
const a = generateKeyPair();
|
|
const b = generateKeyPair();
|
|
assert.throws(() => open(seal("at-secret", a.publicKey), b.privateKey));
|
|
});
|
|
|
|
test("a tampered box is refused, not opened to garbage", () => {
|
|
const k = generateKeyPair();
|
|
const box = seal("at-secret", k.publicKey);
|
|
const ct = Buffer.from(box.ct, "base64");
|
|
ct[0] ^= 0xff;
|
|
assert.throws(() => open({ ...box, ct: ct.toString("base64") }, k.privateKey));
|
|
});
|
|
|
|
test("two boxes of one value share nothing a reader could compare", () => {
|
|
const k = generateKeyPair();
|
|
const x = seal("at-secret", k.publicKey);
|
|
const y = seal("at-secret", k.publicKey);
|
|
assert.notEqual(x.ct, y.ct);
|
|
assert.notEqual(x.eph, y.eph);
|
|
assert.ok(!JSON.stringify(x).includes("at-secret"));
|
|
});
|