The manager module's seal now runs over the audited tweetnacl-sealedbox-js (mesh-catalog anthropic-manager) rather than a hand-transcribed NaCl. Regenerate the fixture's sealed value from that new seal() over the same node key pair and plaintext, so the fixture is the new library's output. crypto_box_seal is randomised, so the blob differs; the wire format does not. TestModuleSealedBoxOpensInGo still opens it under box.OpenAnonymous and recovers the plaintext, proving TS(tweetnacl-sealedbox-js) to Go interop. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
8 lines
634 B
JSON
8 lines
634 B
JSON
{
|
|
"_comment": "Produced by mesh-catalog anthropic-manager sealedbox.ts (crypto_box_seal). Proves that value the module seals to a node's public key opens under Go box.OpenAnonymous — the host's Unseal and mesh-control secrets.Seal/Open. Regenerate with the module's compiled seal().",
|
|
"managerPublicKey": "rJZ9OSnuCcU5MNi8iV0EK8c5nYN+Cx5A+q+miIIIoUc=",
|
|
"managerPrivateKey": "wGHx9hpbO1pyvLiw8oGwi31LBce3HscDiGhXpNU+wl4=",
|
|
"plaintext": "rt-a-refresh-token-only-the-manager-may-read",
|
|
"sealed": "/fI4OGzdLLQnhwv1IagCiS8DNhsjiaPdJTaLjZYBayxHa5xLZ5T74+00yxKHToAoMGimQ0pCrz5ykQPp6YPsSFUSO8Oujz48f1tl/xRyRtkbulVBBC6ylS0KAAM="
|
|
}
|