/opt/canhelp/node_modules/@noble/hashes
NameSizeModeActions
src/-0755rm
argon2.d.ts14980644editdlrm
argon2.d.ts.map11370644editdlrm
argon2.js163080644editdlrm
argon2.js.map211130644editdlrm
blake1.d.ts36240644editdlrm
blake1.d.ts.map37430644editdlrm
blake1.js194330644editdlrm
blake1.js.map284540644editdlrm
blake2.d.ts39070644editdlrm
blake2.d.ts.map41030644editdlrm
blake2.js168950644editdlrm
blake2.js.map255430644editdlrm
blake3.d.ts18370644editdlrm
blake3.d.ts.map12960644editdlrm
blake3.js96270644editdlrm
blake3.js.map107530644editdlrm
eskdf.d.ts17520644editdlrm
eskdf.d.ts.map9020644editdlrm
eskdf.js65500644editdlrm
eskdf.js.map60070644editdlrm
hkdf.d.ts19960644editdlrm
hkdf.d.ts.map5530644editdlrm
hkdf.js35380644editdlrm
hkdf.js.map21470644editdlrm
hmac.d.ts10900644editdlrm
hmac.d.ts.map9340644editdlrm
hmac.js29920644editdlrm
hmac.js.map30670644editdlrm
index.d.ts460644editdlrm
index.d.ts.map1010644editdlrm
index.js11620644editdlrm
index.js.map1800644editdlrm
legacy.d.ts25790644editdlrm
legacy.d.ts.map18880644editdlrm
legacy.js97630644editdlrm
legacy.js.map134980644editdlrm
LICENSE11090644editdlrm
package.json27990644editdlrm
pbkdf2.d.ts11940644editdlrm
pbkdf2.d.ts.map5760644editdlrm
pbkdf2.js38980644editdlrm
pbkdf2.js.map40500644editdlrm
README.md240150644editdlrm
scrypt.d.ts13370644editdlrm
scrypt.d.ts.map6580644editdlrm
scrypt.js97200644editdlrm
scrypt.js.map121360644editdlrm
sha2.d.ts65120644editdlrm
sha2.d.ts.map63590644editdlrm
sha2.js167730644editdlrm
sha2.js.map200620644editdlrm
sha3-addons.d.ts62320644editdlrm
sha3-addons.d.ts.map44190644editdlrm
sha3-addons.js170280644editdlrm
sha3-addons.js.map174830644editdlrm
sha3.d.ts23250644editdlrm
sha3.d.ts.map19330644editdlrm
sha3.js91990644editdlrm
sha3.js.map106900644editdlrm
utils.d.ts61280644editdlrm
utils.d.ts.map41170644editdlrm
utils.js93560644editdlrm
utils.js.map91270644editdlrm
webcrypto.d.ts27180644editdlrm
webcrypto.d.ts.map10990644editdlrm
webcrypto.js50900644editdlrm
webcrypto.js.map39690644editdlrm
_blake.d.ts4740644editdlrm
_blake.d.ts.map5530644editdlrm
_blake.js16610644editdlrm
_blake.js.map36280644editdlrm
_md.d.ts19680644editdlrm
_md.d.ts.map15180644editdlrm
_md.js56150644editdlrm
_md.js.map50650644editdlrm
_u64.d.ts31290644editdlrm
_u64.d.ts.map43140644editdlrm
_u64.js30810644editdlrm
_u64.js.map50450644editdlrm
Edit: /opt/canhelp/node_modules/@noble/hashes/eskdf.js (6550B)
/** * Experimental KDF for AES. * @module */ import { hkdf } from "./hkdf.js"; import { pbkdf2 as _pbkdf2 } from "./pbkdf2.js"; import { scrypt as _scrypt } from "./scrypt.js"; import { sha256 } from "./sha2.js"; import { abytes, bytesToHex, clean, createView, hexToBytes, kdfInputToBytes } from "./utils.js"; // A tiny KDF for various applications like AES key-gen. // Uses HKDF in a non-standard way, so it's not "KDF-secure", only "PRF-secure". // Which is good enough: assume sha2-256 retained preimage resistance. const SCRYPT_FACTOR = 2 ** 19; const PBKDF2_FACTOR = 2 ** 17; /** Scrypt KDF */ export function scrypt(password, salt) { return _scrypt(password, salt, { N: SCRYPT_FACTOR, r: 8, p: 1, dkLen: 32 }); } /** PBKDF2-HMAC-SHA256 */ export function pbkdf2(password, salt) { return _pbkdf2(sha256, password, salt, { c: PBKDF2_FACTOR, dkLen: 32 }); } // Combines two 32-byte byte arrays function xor32(a, b) { abytes(a, 32); abytes(b, 32); const arr = new Uint8Array(32); for (let i = 0; i < 32; i++) { arr[i] = a[i] ^ b[i]; } return arr; } function strHasLength(str, min, max) { return typeof str === 'string' && str.length >= min && str.length <= max; } /** * Derives main seed. Takes a lot of time. Prefer `eskdf` method instead. */ export function deriveMainSeed(username, password) { if (!strHasLength(username, 8, 255)) throw new Error('invalid username'); if (!strHasLength(password, 8, 255)) throw new Error('invalid password'); // Declared like this to throw off minifiers which auto-convert .fromCharCode(1) to actual string. // String with non-ascii may be problematic in some envs const codes = { _1: 1, _2: 2 }; const sep = { s: String.fromCharCode(codes._1), p: String.fromCharCode(codes._2) }; const scr = scrypt(password + sep.s, username + sep.s); const pbk = pbkdf2(password + sep.p, username + sep.p); const res = xor32(scr, pbk); clean(scr, pbk); return res; } /** * Converts protocol & accountId pair to HKDF salt & info params. */ function getSaltInfo(protocol, accountId = 0) { // Note that length here also repeats two lines below // We do an additional length check here to reduce the scope of DoS attacks if (!(strHasLength(protocol, 3, 15) && /^[a-z0-9]{3,15}$/.test(protocol))) { throw new Error('invalid protocol'); } // Allow string account ids for some protocols const allowsStr = /^password\d{0,3}|ssh|tor|file$/.test(protocol); let salt; // Extract salt. Default is undefined. if (typeof accountId === 'string') { if (!allowsStr) throw new Error('accountId must be a number'); if (!strHasLength(accountId, 1, 255)) throw new Error('accountId must be string of length 1..255'); salt = kdfInputToBytes(accountId); } else if (Number.isSafeInteger(accountId)) { if (accountId < 0 || accountId > Math.pow(2, 32) - 1) throw new Error('invalid accountId'); // Convert to Big Endian Uint32 salt = new Uint8Array(4); createView(salt).setUint32(0, accountId, false); } else { throw new Error('accountId must be a number' + (allowsStr ? ' or string' : '')); } const info = kdfInputToBytes(protocol); return { salt, info }; } function countBytes(num) { if (typeof num !== 'bigint' || num <= BigInt(128)) throw new Error('invalid number'); return Math.ceil(num.toString(2).length / 8); } /** * Parses keyLength and modulus options to extract length of result key. * If modulus is used, adds 64 bits to it as per FIPS 186 B.4.1 to combat modulo bias. */ function getKeyLength(options) { if (!options || typeof options !== 'object') return 32; const hasLen = 'keyLength' in options; const hasMod = 'modulus' in options; if (hasLen && hasMod) throw new Error('cannot combine keyLength and modulus options'); if (!hasLen && !hasMod) throw new Error('must have either keyLength or modulus option'); // FIPS 186 B.4.1 requires at least 64 more bits const l = hasMod ? countBytes(options.modulus) + 8 : options.keyLength; if (!(typeof l === 'number' && l >= 16 && l <= 8192)) throw new Error('invalid keyLength'); return l; } /** * Converts key to bigint and divides it by modulus. Big Endian. * Implements FIPS 186 B.4.1, which removes 0 and modulo bias from output. */ function modReduceKey(key, modulus) { const _1 = BigInt(1); const num = BigInt('0x' + bytesToHex(key)); // check for ui8a, then bytesToNumber() const res = (num % (modulus - _1)) + _1; // Remove 0 from output if (res < _1) throw new Error('expected positive number'); // Guard against bad values const len = key.length - 8; // FIPS requires 64 more bits = 8 bytes const hex = res.toString(16).padStart(len * 2, '0'); // numberToHex() const bytes = hexToBytes(hex); if (bytes.length !== len) throw new Error('invalid length of result key'); return bytes; } /** * ESKDF * @param username - username, email, or identifier, min: 8 characters, should have enough entropy * @param password - password, min: 8 characters, should have enough entropy * @example * const kdf = await eskdf('example-university', 'beginning-new-example'); * const key = kdf.deriveChildKey('aes', 0); * console.log(kdf.fingerprint); * kdf.expire(); */ export async function eskdf(username, password) { // We are using closure + object instead of class because // we want to make `seed` non-accessible for any external function. let seed = deriveMainSeed(username, password); function deriveCK(protocol, accountId = 0, options) { abytes(seed, 32); const { salt, info } = getSaltInfo(protocol, accountId); // validate protocol & accountId const keyLength = getKeyLength(options); // validate options const key = hkdf(sha256, seed, salt, info, keyLength); // Modulus has already been validated return options && 'modulus' in options ? modReduceKey(key, options.modulus) : key; } function expire() { if (seed) seed.fill(1); seed = undefined; } // prettier-ignore const fingerprint = Array.from(deriveCK('fingerprint', 0)) .slice(0, 6) .map((char) => char.toString(16).padStart(2, '0').toUpperCase()) .join(':'); return Object.freeze({ deriveChildKey: deriveCK, expire, fingerprint }); } //# sourceMappingURL=eskdf.js.map