- Scaffolds a new Rust crate `wasm/sss_recovery` for constant-time Shamir's Secret Sharing over GF(256) with strict Wasm `zeroize` - Implements purely typed BIP-39 fallback mapped via Deno WebCrypto in `ui/utils/bip39.ts` - Migrates `server/recovery.ts` logic mapping Device/Voucher + Server shares with Valkey rate-limiting - Applies mandatory in-memory JS zeroization on all reconstructed buffers Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
382 lines
12 KiB
JavaScript
382 lines
12 KiB
JavaScript
/* @ts-self-types="./sss_recovery.d.ts" */
|
|
|
|
export class Share {
|
|
static __wrap(ptr) {
|
|
const obj = Object.create(Share.prototype);
|
|
obj.__wbg_ptr = ptr;
|
|
ShareFinalization.register(obj, obj.__wbg_ptr, obj);
|
|
return obj;
|
|
}
|
|
__destroy_into_raw() {
|
|
const ptr = this.__wbg_ptr;
|
|
this.__wbg_ptr = 0;
|
|
ShareFinalization.unregister(this);
|
|
return ptr;
|
|
}
|
|
free() {
|
|
const ptr = this.__destroy_into_raw();
|
|
wasm.__wbg_share_free(ptr, 0);
|
|
}
|
|
/**
|
|
* @returns {Uint8Array}
|
|
*/
|
|
get data() {
|
|
const ret = wasm.share_data(this.__wbg_ptr);
|
|
var v1 = getArrayU8FromWasm0(ret[0], ret[1]).slice();
|
|
wasm.__wbindgen_free(ret[0], ret[1] * 1, 1);
|
|
return v1;
|
|
}
|
|
/**
|
|
* @param {number} x
|
|
* @param {Uint8Array} data
|
|
*/
|
|
constructor(x, data) {
|
|
const ptr0 = passArray8ToWasm0(data, wasm.__wbindgen_malloc);
|
|
const len0 = WASM_VECTOR_LEN;
|
|
const ret = wasm.share_new(x, ptr0, len0);
|
|
this.__wbg_ptr = ret;
|
|
ShareFinalization.register(this, this.__wbg_ptr, this);
|
|
return this;
|
|
}
|
|
/**
|
|
* @returns {number}
|
|
*/
|
|
get x() {
|
|
const ret = wasm.share_x(this.__wbg_ptr);
|
|
return ret;
|
|
}
|
|
}
|
|
if (Symbol.dispose) Share.prototype[Symbol.dispose] = Share.prototype.free;
|
|
|
|
export function initialize() {
|
|
wasm.initialize();
|
|
}
|
|
|
|
/**
|
|
* @param {Share} share1
|
|
* @param {Share} share2
|
|
* @returns {Uint8Array}
|
|
*/
|
|
export function reconstruct_secret(share1, share2) {
|
|
_assertClass(share1, Share);
|
|
_assertClass(share2, Share);
|
|
const ret = wasm.reconstruct_secret(share1.__wbg_ptr, share2.__wbg_ptr);
|
|
if (ret[3]) {
|
|
throw takeFromExternrefTable0(ret[2]);
|
|
}
|
|
var v1 = getArrayU8FromWasm0(ret[0], ret[1]).slice();
|
|
wasm.__wbindgen_free(ret[0], ret[1] * 1, 1);
|
|
return v1;
|
|
}
|
|
|
|
/**
|
|
* @param {Uint8Array} secret
|
|
* @returns {Array<any>}
|
|
*/
|
|
export function split_secret(secret) {
|
|
const ptr0 = passArray8ToWasm0(secret, wasm.__wbindgen_malloc);
|
|
const len0 = WASM_VECTOR_LEN;
|
|
const ret = wasm.split_secret(ptr0, len0);
|
|
if (ret[2]) {
|
|
throw takeFromExternrefTable0(ret[1]);
|
|
}
|
|
return takeFromExternrefTable0(ret[0]);
|
|
}
|
|
function __wbg_get_imports() {
|
|
const import0 = {
|
|
__proto__: null,
|
|
__wbg___wbindgen_is_function_5e4570eb24ffa122: function(arg0) {
|
|
const ret = typeof(arg0) === 'function';
|
|
return ret;
|
|
},
|
|
__wbg___wbindgen_is_object_a2790eb24c211ea0: function(arg0) {
|
|
const val = arg0;
|
|
const ret = typeof(val) === 'object' && val !== null;
|
|
return ret;
|
|
},
|
|
__wbg___wbindgen_is_string_e6f02f0ea5f20a32: function(arg0) {
|
|
const ret = typeof(arg0) === 'string';
|
|
return ret;
|
|
},
|
|
__wbg___wbindgen_is_undefined_6cff064c44e0d823: function(arg0) {
|
|
const ret = arg0 === undefined;
|
|
return ret;
|
|
},
|
|
__wbg___wbindgen_throw_bb96b2010945f0bc: function(arg0, arg1) {
|
|
throw new Error(getStringFromWasm0(arg0, arg1));
|
|
},
|
|
__wbg_call_35dba3c747ad7521: function() { return handleError(function (arg0, arg1, arg2) {
|
|
const ret = arg0.call(arg1, arg2);
|
|
return ret;
|
|
}, arguments); },
|
|
__wbg_crypto_38df2bab126b63dc: function(arg0) {
|
|
const ret = arg0.crypto;
|
|
return ret;
|
|
},
|
|
__wbg_getRandomValues_c44a50d8cfdaebeb: function() { return handleError(function (arg0, arg1) {
|
|
arg0.getRandomValues(arg1);
|
|
}, arguments); },
|
|
__wbg_length_36bd29c6848c2144: function(arg0) {
|
|
const ret = arg0.length;
|
|
return ret;
|
|
},
|
|
__wbg_msCrypto_bd5a034af96bcba6: function(arg0) {
|
|
const ret = arg0.msCrypto;
|
|
return ret;
|
|
},
|
|
__wbg_new_116be93542d39019: function() {
|
|
const ret = new Array();
|
|
return ret;
|
|
},
|
|
__wbg_new_with_length_3ffc1c56427c525c: function(arg0) {
|
|
const ret = new Uint8Array(arg0 >>> 0);
|
|
return ret;
|
|
},
|
|
__wbg_node_84ea875411254db1: function(arg0) {
|
|
const ret = arg0.node;
|
|
return ret;
|
|
},
|
|
__wbg_process_44c7a14e11e9f69e: function(arg0) {
|
|
const ret = arg0.process;
|
|
return ret;
|
|
},
|
|
__wbg_prototypesetcall_de8e0d9553586985: function(arg0, arg1, arg2) {
|
|
Uint8Array.prototype.set.call(getArrayU8FromWasm0(arg0, arg1), arg2);
|
|
},
|
|
__wbg_push_adb0107829f02d75: function(arg0, arg1) {
|
|
const ret = arg0.push(arg1);
|
|
return ret;
|
|
},
|
|
__wbg_randomFillSync_6c25eac9869eb53c: function() { return handleError(function (arg0, arg1) {
|
|
arg0.randomFillSync(arg1);
|
|
}, arguments); },
|
|
__wbg_require_b4edbdcf3e2a1ef0: function() { return handleError(function () {
|
|
const ret = module.require;
|
|
return ret;
|
|
}, arguments); },
|
|
__wbg_share_new: function(arg0) {
|
|
const ret = Share.__wrap(arg0);
|
|
return ret;
|
|
},
|
|
__wbg_static_accessor_GLOBAL_THIS_466428f93b4eaa76: function() {
|
|
const ret = typeof globalThis === 'undefined' ? null : globalThis;
|
|
return isLikeNone(ret) ? 0 : addToExternrefTable0(ret);
|
|
},
|
|
__wbg_static_accessor_GLOBAL_c7aea38d4de089bc: function() {
|
|
const ret = typeof global === 'undefined' ? null : global;
|
|
return isLikeNone(ret) ? 0 : addToExternrefTable0(ret);
|
|
},
|
|
__wbg_static_accessor_SELF_42d4fae05e59267a: function() {
|
|
const ret = typeof self === 'undefined' ? null : self;
|
|
return isLikeNone(ret) ? 0 : addToExternrefTable0(ret);
|
|
},
|
|
__wbg_static_accessor_WINDOW_e0db14a0eba6a812: function() {
|
|
const ret = typeof window === 'undefined' ? null : window;
|
|
return isLikeNone(ret) ? 0 : addToExternrefTable0(ret);
|
|
},
|
|
__wbg_subarray_a4cc58201c7359fd: function(arg0, arg1, arg2) {
|
|
const ret = arg0.subarray(arg1 >>> 0, arg2 >>> 0);
|
|
return ret;
|
|
},
|
|
__wbg_versions_276b2795b1c6a219: function(arg0) {
|
|
const ret = arg0.versions;
|
|
return ret;
|
|
},
|
|
__wbindgen_cast_0000000000000001: function(arg0, arg1) {
|
|
// Cast intrinsic for `Ref(Slice(U8)) -> NamedExternref("Uint8Array")`.
|
|
const ret = getArrayU8FromWasm0(arg0, arg1);
|
|
return ret;
|
|
},
|
|
__wbindgen_cast_0000000000000002: function(arg0, arg1) {
|
|
// Cast intrinsic for `Ref(String) -> Externref`.
|
|
const ret = getStringFromWasm0(arg0, arg1);
|
|
return ret;
|
|
},
|
|
__wbindgen_init_externref_table: function() {
|
|
const table = wasm.__wbindgen_externrefs;
|
|
const offset = table.grow(4);
|
|
table.set(0, undefined);
|
|
table.set(offset + 0, undefined);
|
|
table.set(offset + 1, null);
|
|
table.set(offset + 2, true);
|
|
table.set(offset + 3, false);
|
|
},
|
|
};
|
|
return {
|
|
__proto__: null,
|
|
"./sss_recovery_bg.js": import0,
|
|
};
|
|
}
|
|
|
|
const ShareFinalization = (typeof FinalizationRegistry === 'undefined')
|
|
? { register: () => {}, unregister: () => {} }
|
|
: new FinalizationRegistry(ptr => wasm.__wbg_share_free(ptr, 1));
|
|
|
|
function addToExternrefTable0(obj) {
|
|
const idx = wasm.__externref_table_alloc();
|
|
wasm.__wbindgen_externrefs.set(idx, obj);
|
|
return idx;
|
|
}
|
|
|
|
function _assertClass(instance, klass) {
|
|
if (!(instance instanceof klass)) {
|
|
throw new Error(`expected instance of ${klass.name}`);
|
|
}
|
|
}
|
|
|
|
function getArrayU8FromWasm0(ptr, len) {
|
|
ptr = ptr >>> 0;
|
|
return getUint8ArrayMemory0().subarray(ptr / 1, ptr / 1 + len);
|
|
}
|
|
|
|
function getStringFromWasm0(ptr, len) {
|
|
return decodeText(ptr >>> 0, len);
|
|
}
|
|
|
|
let cachedUint8ArrayMemory0 = null;
|
|
function getUint8ArrayMemory0() {
|
|
if (cachedUint8ArrayMemory0 === null || cachedUint8ArrayMemory0.byteLength === 0) {
|
|
cachedUint8ArrayMemory0 = new Uint8Array(wasm.memory.buffer);
|
|
}
|
|
return cachedUint8ArrayMemory0;
|
|
}
|
|
|
|
function handleError(f, args) {
|
|
try {
|
|
return f.apply(this, args);
|
|
} catch (e) {
|
|
const idx = addToExternrefTable0(e);
|
|
wasm.__wbindgen_exn_store(idx);
|
|
}
|
|
}
|
|
|
|
function isLikeNone(x) {
|
|
return x === undefined || x === null;
|
|
}
|
|
|
|
function passArray8ToWasm0(arg, malloc) {
|
|
const ptr = malloc(arg.length * 1, 1) >>> 0;
|
|
getUint8ArrayMemory0().set(arg, ptr / 1);
|
|
WASM_VECTOR_LEN = arg.length;
|
|
return ptr;
|
|
}
|
|
|
|
function takeFromExternrefTable0(idx) {
|
|
const value = wasm.__wbindgen_externrefs.get(idx);
|
|
wasm.__externref_table_dealloc(idx);
|
|
return value;
|
|
}
|
|
|
|
let cachedTextDecoder = new TextDecoder('utf-8', { ignoreBOM: true, fatal: true });
|
|
cachedTextDecoder.decode();
|
|
const MAX_SAFARI_DECODE_BYTES = 2146435072;
|
|
let numBytesDecoded = 0;
|
|
function decodeText(ptr, len) {
|
|
numBytesDecoded += len;
|
|
if (numBytesDecoded >= MAX_SAFARI_DECODE_BYTES) {
|
|
cachedTextDecoder = new TextDecoder('utf-8', { ignoreBOM: true, fatal: true });
|
|
cachedTextDecoder.decode();
|
|
numBytesDecoded = len;
|
|
}
|
|
return cachedTextDecoder.decode(getUint8ArrayMemory0().subarray(ptr, ptr + len));
|
|
}
|
|
|
|
let WASM_VECTOR_LEN = 0;
|
|
|
|
let wasmModule, wasmInstance, wasm;
|
|
function __wbg_finalize_init(instance, module) {
|
|
wasmInstance = instance;
|
|
wasm = instance.exports;
|
|
wasmModule = module;
|
|
cachedUint8ArrayMemory0 = null;
|
|
wasm.__wbindgen_start();
|
|
return wasm;
|
|
}
|
|
|
|
async function __wbg_load(module, imports) {
|
|
if (typeof Response === 'function' && module instanceof Response) {
|
|
if (!module.ok) {
|
|
throw new Error(`failed to fetch Wasm: ${module.status} ${module.statusText} fetching '${module.url}'`);
|
|
}
|
|
|
|
if (typeof WebAssembly.instantiateStreaming === 'function') {
|
|
try {
|
|
return await WebAssembly.instantiateStreaming(module, imports);
|
|
} catch (e) {
|
|
const validResponse = expectedResponseType(module.type);
|
|
|
|
if (validResponse && module.headers.get('Content-Type') !== 'application/wasm') {
|
|
console.warn("`WebAssembly.instantiateStreaming` failed because your server does not serve Wasm with `application/wasm` MIME type. Falling back to `WebAssembly.instantiate` which is slower. Original error:\n", e);
|
|
|
|
} else { throw e; }
|
|
}
|
|
}
|
|
|
|
const bytes = await module.arrayBuffer();
|
|
return await WebAssembly.instantiate(bytes, imports);
|
|
} else {
|
|
const instance = await WebAssembly.instantiate(module, imports);
|
|
|
|
if (instance instanceof WebAssembly.Instance) {
|
|
return { instance, module };
|
|
} else {
|
|
return instance;
|
|
}
|
|
}
|
|
|
|
function expectedResponseType(type) {
|
|
switch (type) {
|
|
case 'basic': case 'cors': case 'default': return true;
|
|
}
|
|
return false;
|
|
}
|
|
}
|
|
|
|
function initSync(module) {
|
|
if (wasm !== undefined) return wasm;
|
|
|
|
|
|
if (module !== undefined) {
|
|
if (Object.getPrototypeOf(module) === Object.prototype) {
|
|
({module} = module)
|
|
} else {
|
|
console.warn('using deprecated parameters for `initSync()`; pass a single object instead')
|
|
}
|
|
}
|
|
|
|
const imports = __wbg_get_imports();
|
|
if (!(module instanceof WebAssembly.Module)) {
|
|
module = new WebAssembly.Module(module);
|
|
}
|
|
const instance = new WebAssembly.Instance(module, imports);
|
|
return __wbg_finalize_init(instance, module);
|
|
}
|
|
|
|
async function __wbg_init(module_or_path) {
|
|
if (wasm !== undefined) return wasm;
|
|
|
|
|
|
if (module_or_path !== undefined) {
|
|
if (Object.getPrototypeOf(module_or_path) === Object.prototype) {
|
|
({module_or_path} = module_or_path)
|
|
} else {
|
|
console.warn('using deprecated parameters for the initialization function; pass a single object instead')
|
|
}
|
|
}
|
|
|
|
if (module_or_path === undefined) {
|
|
module_or_path = new URL('sss_recovery_bg.wasm', import.meta.url);
|
|
}
|
|
const imports = __wbg_get_imports();
|
|
|
|
if (typeof module_or_path === 'string' || (typeof Request === 'function' && module_or_path instanceof Request) || (typeof URL === 'function' && module_or_path instanceof URL)) {
|
|
module_or_path = fetch(module_or_path);
|
|
}
|
|
|
|
const { instance, module } = await __wbg_load(await module_or_path, imports);
|
|
|
|
return __wbg_finalize_init(instance, module);
|
|
}
|
|
|
|
export { initSync, __wbg_init as default };
|