Skip to content

Add test coverage for cas-lib 0.2.85 APIs (#90) - #94

Merged
WingZer0o merged 1 commit into
mainfrom
#90-cas-lib-0.2.85
Sep 26, 2026
Merged

WingZer0o merged 1 commit into
mainfrom
#90-cas-lib-0.2.85

Conversation

@WingZer0o

Copy link
Copy Markdown
Member

Summary

Audit of issue #90 found that every API it lists (AES-GCM-SIV, ML-KEM-1024, SLH-DSA, PBKDF2, Argon2 AES key derivation, AES-GCM key_from_vec, Ed25519 verify-with-key-pair) is already exposed through the FFI and TS layers via #91 and #92, and nothing else public in cas-lib 0.2.85 is unexposed. This PR fills the remaining test gaps.

TS tests (Playwright)

  • AES-GCM-SIV: X25519 shared-secret key derivation (128/256) agrees on both sides and round-trips; KeyFromBytes keys round-trip; key/nonce/tag sizes; tampered ciphertext and wrong nonce throw
  • Ed25519: verifyWithKeyPairBytes rejects a different key pair and a tampered signature, agrees with public-key verify, throws on wrong-length inputs
  • PBKDF2: iteration count and password change the key; derive generates a fresh salt per call; derived key works as an AES-256-GCM key
  • SLH-DSA: wrong verification key / tampered signature fail; wrong-length signature throws
  • ML-KEM-1024: fresh encapsulation per call; wrong secret key yields a different shared secret; shared secret keys AES-256-GCM
  • New public-api.spec.ts: guards barrel exports of the new wrappers/methods

Rust tests

  • AES-GCM-SIV key from X25519 shared secret, end to end
  • Ed25519 key-pair verify: tampered message returns false, bad lengths error

Reviewer notes

Test plan

  • cargo test --release — 61 passed
  • npx playwright test on the 6 affected spec files — 114 passed (all 3 projects)

Closes #90

🤖 Generated with Claude Code

All APIs listed in #90 were already exposed by #91 and #92; this fills
the remaining test gaps: AES-GCM-SIV X25519 key derivation, tamper and
wrong-nonce rejection; Ed25519 key-pair verify failure paths; PBKDF2
salt/iteration/password sensitivity; SLH-DSA wrong-key and tampered
signatures; ML-KEM freshness and wrong-key decapsulation; and a public
API barrel-export guard. Adds matching Rust tests for SIV X25519 key
derivation and Ed25519 key-pair verify failures.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@WingZer0o
WingZer0o merged commit a7d5545 into main Sep 26, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Expose remaining cas-lib 0.2.85 APIs through the FFI layer

1 participant