The manager reseals a rotated refresh token to the node key with crypto_box_seal. That seal was a full inline transcription of TweetNaCl's XSalsa20-Poly1305 and blakejs' BLAKE2b (dependency-free, ~440 lines). Replace the internals with the audited tweetnacl-sealedbox-js library — the same crypto_box_seal, on the same tweetnacl and blakejs the mesh used to validate the seal during Phase C. The exported API is unchanged: seal(value, recipientPublicB64) -> base64. The wire format is unchanged too — ephemeralPub(32) followed by the box, nonce = blake2b(ephemeralPub + recipientPub, 24) — so the host's Go box.OpenAnonymous still opens it. The mesh-control cross-check fixture is regenerated from this seal(). The library and tweetnacl are added to the module's package.json dependencies so the runtime image bundles them (blakejs arrives transitively). A local ambient .d.ts types the untyped CJS bundle; it is imported as a default import because Node's ESM loader cannot see a UMD bundle's named exports. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
14 lines
680 B
TypeScript
14 lines
680 B
TypeScript
// Ambient types for `tweetnacl-sealedbox-js` (crypto_box_seal), which ships without its own.
|
|
// The library is a small UMD bundle over `tweetnacl` and `blakejs`; only `seal` is used here.
|
|
declare module "tweetnacl-sealedbox-js" {
|
|
/** crypto_box_seal: returns ephemeralPub(32) ‖ box, sealed to `recipientPublicKey`. */
|
|
export function seal(message: Uint8Array, recipientPublicKey: Uint8Array): Uint8Array;
|
|
/** crypto_box_seal_open: returns the plaintext, or null if it does not open. */
|
|
export function open(
|
|
sealed: Uint8Array,
|
|
recipientPublicKey: Uint8Array,
|
|
recipientSecretKey: Uint8Array,
|
|
): Uint8Array | null;
|
|
export const overheadLength: number;
|
|
}
|