release: WRNexusJS 0.5.0

This commit is contained in:
2026-07-29 12:51:10 +05:30
parent 76c768099d
commit 6afe32f63f
456 changed files with 40879 additions and 8850 deletions
+21
View File
@@ -0,0 +1,21 @@
import { expect, test } from "bun:test";
import { createKeyring, generateKey, seal } from "@wrnexus/encryption";
import { createAuthSecretProtector } from "../src/protector.ts";
test("secret protector binds encrypted values to their auth purpose", async () => {
const keyring = createKeyring([{ id: "primary", secret: await generateKey(), active: true }]);
const protector = createAuthSecretProtector(keyring);
const protectedValue = await protector.protect("secret-value", "totp");
expect(await protector.reveal(protectedValue, "totp")).toBe("secret-value");
await expect(protector.reveal(protectedValue, "oauth-access")).rejects.toThrow(
"WRN-AUTH-SECRET-PURPOSE",
);
});
test("secret protector can read legacy unbound ciphertext", async () => {
const keyring = createKeyring([{ id: "primary", secret: await generateKey(), active: true }]);
const protector = createAuthSecretProtector(keyring);
const legacy = await seal("legacy-secret", keyring);
expect(await protector.reveal(legacy, "oauth-refresh")).toBe("legacy-secret");
});