Argon2 derive AES-128/256 keys - #92
Merged
Merged
Conversation
Adds argon2_derive_aes_128_key / argon2_derive_aes_256_key napi functions wrapping CASArgon, deriveAes128Key / deriveAes256Key on Argon2Wrapper, and Rust + Playwright tests. Bumps version to 1.1.001. Closes #76 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance. |
WingZer0o
added a commit
that referenced
this pull request
Sep 26, 2026
All APIs listed in #90 were already exposed by #91 and #92; this fills the remaining test gaps: AES-GCM-SIV X25519 key derivation, tamper and wrong-nonce rejection; Ed25519 key-pair verify failure paths; PBKDF2 salt/iteration/password sensitivity; SLH-DSA wrong-key and tampered signatures; ML-KEM freshness and wrong-key decapsulation; and a public API barrel-export guard. Adds matching Rust tests for SIV X25519 key derivation and Ed25519 key-pair verify failures. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 tasks
WingZer0o
added a commit
that referenced
this pull request
Sep 26, 2026
All APIs listed in #90 were already exposed by #91 and #92; this fills the remaining test gaps: AES-GCM-SIV X25519 key derivation, tamper and wrong-nonce rejection; Ed25519 key-pair verify failure paths; PBKDF2 salt/iteration/password sensitivity; SLH-DSA wrong-key and tampered signatures; ML-KEM freshness and wrong-key decapsulation; and a public API barrel-export guard. Adds matching Rust tests for SIV X25519 key derivation and Ed25519 key-pair verify failures. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #76
Exposes cas-lib 0.2.85's
CASArgon::derive_aes_128_key/derive_aes_256_keythrough the SDK:src/password_hashers/argon2.rs):argon2_derive_aes_128_key/argon2_derive_aes_256_key#[napi]functions, plus inline tests (key lengths, per-call uniqueness, AES-256 encrypt/decrypt round trip).src-ts/password-hashers/argon2-wrapper.ts):Argon2Wrapper.deriveAes128Key/deriveAes256Keywith JSDoc noting the salt is generated internally and discarded, so each call yields a fresh one-time key (usePbkdf2Wrapper.deriveWithSaltfor re-derivable keys).tests/password-hasher.spec.ts): key lengths, uniqueness across calls, and a derived-key AES-256 round trip viaAESWrapper.index.js/index.d.tsregenerated bynpm run build:rust.PasswordHasherFactorylocal now typed asIPasswordHasherBase(the new non-interface methods broke the previous structural assignment).1.1.000→1.1.001for publish.Verified locally:
npm run rust:test(58 passed),npm run build, andnpx playwright test tests/password-hasher.spec.ts tests/symmetric.test.ts(60 passed across all three projects).🤖 Generated with Claude Code
/closes #76