mirror of
https://github.com/chaos-zhu/easynode.git
synced 2026-10-07 17:27:53 +08:00
test: add mobile crypto envelope
This commit is contained in:
@@ -0,0 +1,44 @@
|
||||
const crypto = require('crypto')
|
||||
|
||||
function assertTempKey(key) {
|
||||
if (!Buffer.isBuffer(key) || key.length !== 32) {
|
||||
throw new Error('temporary key must be 32 bytes')
|
||||
}
|
||||
}
|
||||
|
||||
function encryptJsonForMobile(payload, key) {
|
||||
assertTempKey(key)
|
||||
const iv = crypto.randomBytes(12)
|
||||
const cipher = crypto.createCipheriv('aes-256-gcm', key, iv)
|
||||
const plaintext = Buffer.from(JSON.stringify(payload), 'utf8')
|
||||
const ciphertext = Buffer.concat([cipher.update(plaintext), cipher.final()])
|
||||
const tag = cipher.getAuthTag()
|
||||
|
||||
return {
|
||||
alg: 'AES-256-GCM',
|
||||
iv: iv.toString('base64'),
|
||||
tag: tag.toString('base64'),
|
||||
ciphertext: ciphertext.toString('base64')
|
||||
}
|
||||
}
|
||||
|
||||
function decryptMobileJsonForTest(envelope, key) {
|
||||
assertTempKey(key)
|
||||
const decipher = crypto.createDecipheriv(
|
||||
'aes-256-gcm',
|
||||
key,
|
||||
Buffer.from(envelope.iv, 'base64')
|
||||
)
|
||||
decipher.setAuthTag(Buffer.from(envelope.tag, 'base64'))
|
||||
const plaintext = Buffer.concat([
|
||||
decipher.update(Buffer.from(envelope.ciphertext, 'base64')),
|
||||
decipher.final()
|
||||
])
|
||||
return JSON.parse(plaintext.toString('utf8'))
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
assertTempKey,
|
||||
encryptJsonForMobile,
|
||||
decryptMobileJsonForTest
|
||||
}
|
||||
+2
-1
@@ -11,7 +11,8 @@
|
||||
"lint:fix": "eslint . --ext .js,.jsx,.cjs,.mjs --fix",
|
||||
"test": "node test/test-rest-api-auth.js && node test/test-ws-comprehensive.js",
|
||||
"test:api": "node test/test-rest-api-auth.js",
|
||||
"test:ws": "node test/test-ws-comprehensive.js"
|
||||
"test:ws": "node test/test-ws-comprehensive.js",
|
||||
"test:mobile": "node test/test-mobile-crypto.js && node test/test-mobile-ssh-payload.js"
|
||||
},
|
||||
"keywords": [],
|
||||
"author": "",
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
const assert = require('assert')
|
||||
const { encryptJsonForMobile, decryptMobileJsonForTest, assertTempKey } = require('../app/utils/mobile-crypto')
|
||||
|
||||
function testRejectsShortKey() {
|
||||
assert.throws(() => assertTempKey(Buffer.alloc(16)), /temporary key must be 32 bytes/)
|
||||
}
|
||||
|
||||
function testEncryptsAndDecryptsJson() {
|
||||
const key = Buffer.from('0123456789abcdef0123456789abcdef')
|
||||
const payload = { host: '127.0.0.1', password: 'secret' }
|
||||
const envelope = encryptJsonForMobile(payload, key)
|
||||
|
||||
assert.strictEqual(envelope.alg, 'AES-256-GCM')
|
||||
assert.ok(envelope.iv)
|
||||
assert.ok(envelope.tag)
|
||||
assert.ok(envelope.ciphertext)
|
||||
assert.ok(!JSON.stringify(envelope).includes('secret'))
|
||||
|
||||
const decoded = decryptMobileJsonForTest(envelope, key)
|
||||
assert.deepStrictEqual(decoded, payload)
|
||||
}
|
||||
|
||||
testRejectsShortKey()
|
||||
testEncryptsAndDecryptsJson()
|
||||
console.log('test-mobile-crypto passed')
|
||||
Reference in New Issue
Block a user