/
opt
/
canhelp
/
node_modules
/
@noble
/
hashes
/
/opt/canhelp/node_modules/@noble/hashes
mkdir
upload
Name
Size
Mode
Actions
src/
-
0755
rm
argon2.d.ts
1498
0644
edit
dl
rm
argon2.d.ts.map
1137
0644
edit
dl
rm
argon2.js
16308
0644
edit
dl
rm
argon2.js.map
21113
0644
edit
dl
rm
blake1.d.ts
3624
0644
edit
dl
rm
blake1.d.ts.map
3743
0644
edit
dl
rm
blake1.js
19433
0644
edit
dl
rm
blake1.js.map
28454
0644
edit
dl
rm
blake2.d.ts
3907
0644
edit
dl
rm
blake2.d.ts.map
4103
0644
edit
dl
rm
blake2.js
16895
0644
edit
dl
rm
blake2.js.map
25543
0644
edit
dl
rm
blake3.d.ts
1837
0644
edit
dl
rm
blake3.d.ts.map
1296
0644
edit
dl
rm
blake3.js
9627
0644
edit
dl
rm
blake3.js.map
10753
0644
edit
dl
rm
eskdf.d.ts
1752
0644
edit
dl
rm
eskdf.d.ts.map
902
0644
edit
dl
rm
eskdf.js
6550
0644
edit
dl
rm
eskdf.js.map
6007
0644
edit
dl
rm
hkdf.d.ts
1996
0644
edit
dl
rm
hkdf.d.ts.map
553
0644
edit
dl
rm
hkdf.js
3538
0644
edit
dl
rm
hkdf.js.map
2147
0644
edit
dl
rm
hmac.d.ts
1090
0644
edit
dl
rm
hmac.d.ts.map
934
0644
edit
dl
rm
hmac.js
2992
0644
edit
dl
rm
hmac.js.map
3067
0644
edit
dl
rm
index.d.ts
46
0644
edit
dl
rm
index.d.ts.map
101
0644
edit
dl
rm
index.js
1162
0644
edit
dl
rm
index.js.map
180
0644
edit
dl
rm
legacy.d.ts
2579
0644
edit
dl
rm
legacy.d.ts.map
1888
0644
edit
dl
rm
legacy.js
9763
0644
edit
dl
rm
legacy.js.map
13498
0644
edit
dl
rm
LICENSE
1109
0644
edit
dl
rm
package.json
2799
0644
edit
dl
rm
pbkdf2.d.ts
1194
0644
edit
dl
rm
pbkdf2.d.ts.map
576
0644
edit
dl
rm
pbkdf2.js
3898
0644
edit
dl
rm
pbkdf2.js.map
4050
0644
edit
dl
rm
README.md
24015
0644
edit
dl
rm
scrypt.d.ts
1337
0644
edit
dl
rm
scrypt.d.ts.map
658
0644
edit
dl
rm
scrypt.js
9720
0644
edit
dl
rm
scrypt.js.map
12136
0644
edit
dl
rm
sha2.d.ts
6512
0644
edit
dl
rm
sha2.d.ts.map
6359
0644
edit
dl
rm
sha2.js
16773
0644
edit
dl
rm
sha2.js.map
20062
0644
edit
dl
rm
sha3-addons.d.ts
6232
0644
edit
dl
rm
sha3-addons.d.ts.map
4419
0644
edit
dl
rm
sha3-addons.js
17028
0644
edit
dl
rm
sha3-addons.js.map
17483
0644
edit
dl
rm
sha3.d.ts
2325
0644
edit
dl
rm
sha3.d.ts.map
1933
0644
edit
dl
rm
sha3.js
9199
0644
edit
dl
rm
sha3.js.map
10690
0644
edit
dl
rm
utils.d.ts
6128
0644
edit
dl
rm
utils.d.ts.map
4117
0644
edit
dl
rm
utils.js
9356
0644
edit
dl
rm
utils.js.map
9127
0644
edit
dl
rm
webcrypto.d.ts
2718
0644
edit
dl
rm
webcrypto.d.ts.map
1099
0644
edit
dl
rm
webcrypto.js
5090
0644
edit
dl
rm
webcrypto.js.map
3969
0644
edit
dl
rm
_blake.d.ts
474
0644
edit
dl
rm
_blake.d.ts.map
553
0644
edit
dl
rm
_blake.js
1661
0644
edit
dl
rm
_blake.js.map
3628
0644
edit
dl
rm
_md.d.ts
1968
0644
edit
dl
rm
_md.d.ts.map
1518
0644
edit
dl
rm
_md.js
5615
0644
edit
dl
rm
_md.js.map
5065
0644
edit
dl
rm
_u64.d.ts
3129
0644
edit
dl
rm
_u64.d.ts.map
4314
0644
edit
dl
rm
_u64.js
3081
0644
edit
dl
rm
_u64.js.map
5045
0644
edit
dl
rm
Edit:
/opt/canhelp/node_modules/@noble/hashes/eskdf.js
(6550B)
/** * Experimental KDF for AES. * @module */ import { hkdf } from "./hkdf.js"; import { pbkdf2 as _pbkdf2 } from "./pbkdf2.js"; import { scrypt as _scrypt } from "./scrypt.js"; import { sha256 } from "./sha2.js"; import { abytes, bytesToHex, clean, createView, hexToBytes, kdfInputToBytes } from "./utils.js"; // A tiny KDF for various applications like AES key-gen. // Uses HKDF in a non-standard way, so it's not "KDF-secure", only "PRF-secure". // Which is good enough: assume sha2-256 retained preimage resistance. const SCRYPT_FACTOR = 2 ** 19; const PBKDF2_FACTOR = 2 ** 17; /** Scrypt KDF */ export function scrypt(password, salt) { return _scrypt(password, salt, { N: SCRYPT_FACTOR, r: 8, p: 1, dkLen: 32 }); } /** PBKDF2-HMAC-SHA256 */ export function pbkdf2(password, salt) { return _pbkdf2(sha256, password, salt, { c: PBKDF2_FACTOR, dkLen: 32 }); } // Combines two 32-byte byte arrays function xor32(a, b) { abytes(a, 32); abytes(b, 32); const arr = new Uint8Array(32); for (let i = 0; i < 32; i++) { arr[i] = a[i] ^ b[i]; } return arr; } function strHasLength(str, min, max) { return typeof str === 'string' && str.length >= min && str.length <= max; } /** * Derives main seed. Takes a lot of time. Prefer `eskdf` method instead. */ export function deriveMainSeed(username, password) { if (!strHasLength(username, 8, 255)) throw new Error('invalid username'); if (!strHasLength(password, 8, 255)) throw new Error('invalid password'); // Declared like this to throw off minifiers which auto-convert .fromCharCode(1) to actual string. // String with non-ascii may be problematic in some envs const codes = { _1: 1, _2: 2 }; const sep = { s: String.fromCharCode(codes._1), p: String.fromCharCode(codes._2) }; const scr = scrypt(password + sep.s, username + sep.s); const pbk = pbkdf2(password + sep.p, username + sep.p); const res = xor32(scr, pbk); clean(scr, pbk); return res; } /** * Converts protocol & accountId pair to HKDF salt & info params. */ function getSaltInfo(protocol, accountId = 0) { // Note that length here also repeats two lines below // We do an additional length check here to reduce the scope of DoS attacks if (!(strHasLength(protocol, 3, 15) && /^[a-z0-9]{3,15}$/.test(protocol))) { throw new Error('invalid protocol'); } // Allow string account ids for some protocols const allowsStr = /^password\d{0,3}|ssh|tor|file$/.test(protocol); let salt; // Extract salt. Default is undefined. if (typeof accountId === 'string') { if (!allowsStr) throw new Error('accountId must be a number'); if (!strHasLength(accountId, 1, 255)) throw new Error('accountId must be string of length 1..255'); salt = kdfInputToBytes(accountId); } else if (Number.isSafeInteger(accountId)) { if (accountId < 0 || accountId > Math.pow(2, 32) - 1) throw new Error('invalid accountId'); // Convert to Big Endian Uint32 salt = new Uint8Array(4); createView(salt).setUint32(0, accountId, false); } else { throw new Error('accountId must be a number' + (allowsStr ? ' or string' : '')); } const info = kdfInputToBytes(protocol); return { salt, info }; } function countBytes(num) { if (typeof num !== 'bigint' || num <= BigInt(128)) throw new Error('invalid number'); return Math.ceil(num.toString(2).length / 8); } /** * Parses keyLength and modulus options to extract length of result key. * If modulus is used, adds 64 bits to it as per FIPS 186 B.4.1 to combat modulo bias. */ function getKeyLength(options) { if (!options || typeof options !== 'object') return 32; const hasLen = 'keyLength' in options; const hasMod = 'modulus' in options; if (hasLen && hasMod) throw new Error('cannot combine keyLength and modulus options'); if (!hasLen && !hasMod) throw new Error('must have either keyLength or modulus option'); // FIPS 186 B.4.1 requires at least 64 more bits const l = hasMod ? countBytes(options.modulus) + 8 : options.keyLength; if (!(typeof l === 'number' && l >= 16 && l <= 8192)) throw new Error('invalid keyLength'); return l; } /** * Converts key to bigint and divides it by modulus. Big Endian. * Implements FIPS 186 B.4.1, which removes 0 and modulo bias from output. */ function modReduceKey(key, modulus) { const _1 = BigInt(1); const num = BigInt('0x' + bytesToHex(key)); // check for ui8a, then bytesToNumber() const res = (num % (modulus - _1)) + _1; // Remove 0 from output if (res < _1) throw new Error('expected positive number'); // Guard against bad values const len = key.length - 8; // FIPS requires 64 more bits = 8 bytes const hex = res.toString(16).padStart(len * 2, '0'); // numberToHex() const bytes = hexToBytes(hex); if (bytes.length !== len) throw new Error('invalid length of result key'); return bytes; } /** * ESKDF * @param username - username, email, or identifier, min: 8 characters, should have enough entropy * @param password - password, min: 8 characters, should have enough entropy * @example * const kdf = await eskdf('example-university', 'beginning-new-example'); * const key = kdf.deriveChildKey('aes', 0); * console.log(kdf.fingerprint); * kdf.expire(); */ export async function eskdf(username, password) { // We are using closure + object instead of class because // we want to make `seed` non-accessible for any external function. let seed = deriveMainSeed(username, password); function deriveCK(protocol, accountId = 0, options) { abytes(seed, 32); const { salt, info } = getSaltInfo(protocol, accountId); // validate protocol & accountId const keyLength = getKeyLength(options); // validate options const key = hkdf(sha256, seed, salt, info, keyLength); // Modulus has already been validated return options && 'modulus' in options ? modReduceKey(key, options.modulus) : key; } function expire() { if (seed) seed.fill(1); seed = undefined; } // prettier-ignore const fingerprint = Array.from(deriveCK('fingerprint', 0)) .slice(0, 6) .map((char) => char.toString(16).padStart(2, '0').toUpperCase()) .join(':'); return Object.freeze({ deriveChildKey: deriveCK, expire, fingerprint }); } //# sourceMappingURL=eskdf.js.map
Save
cmd:
run