One name per thing, per the HQ glossary: the module/container/image/binary/repo becomes mesh-controller, the seat the-controller, and the store+broker pair the foundation (embedded base bundles, default template and example lock renamed with their go:embed directives). No behaviour change — a pure vocabulary rename. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
37 lines
1.7 KiB
TypeScript
37 lines
1.7 KiB
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { generateKeyPairSync } from "node:crypto";
|
|
|
|
import { seal } from "../sealedbox.ts";
|
|
|
|
// The definitive proof that this seal interoperates with Go's box.OpenAnonymous (the host's Unseal
|
|
// and mesh-controller's secrets.Seal/Open) is a cross-language test in mesh-controller
|
|
// (internal/secrets/sealedbox_xcheck_test.go), which opens a fixture this module's seal() produced.
|
|
// These tests hold the TypeScript side: the output has the crypto_box_seal shape, and it is
|
|
// randomised so a rotation that changed nothing looks nothing like one that changed everything.
|
|
|
|
/** A node public key as the mesh records it: raw 32-byte X25519, standard base64. */
|
|
function aNodePublicKey(): string {
|
|
const kp = generateKeyPairSync("x25519");
|
|
const x = (kp.publicKey.export({ format: "jwk" }) as { x: string }).x;
|
|
return Buffer.from(x, "base64url").toString("base64");
|
|
}
|
|
|
|
test("a seal has the crypto_box_seal shape: ephemeralPub(32) + tag(16) + ciphertext(len)", () => {
|
|
const pub = aNodePublicKey();
|
|
const msg = Buffer.from("rt-a-refresh-token", "utf8");
|
|
const blob = Buffer.from(seal(new Uint8Array(msg), pub), "base64");
|
|
// 32 (ephemeral public key) + 16 (Poly1305 tag) + message length.
|
|
assert.equal(blob.length, 32 + 16 + msg.length);
|
|
});
|
|
|
|
test("two seals of the same value differ — a fresh ephemeral key each time", () => {
|
|
const pub = aNodePublicKey();
|
|
const msg = new Uint8Array(Buffer.from("rt-a-refresh-token", "utf8"));
|
|
assert.notEqual(seal(msg, pub), seal(msg, pub));
|
|
});
|
|
|
|
test("a public key that is not 32 bytes is refused before anything is sealed", () => {
|
|
assert.throws(() => seal(new Uint8Array([1, 2, 3]), Buffer.from("short").toString("base64")));
|
|
});
|