commit 14ba1403543c128fe68f1c6390c7a0973f96baaf Author: Paul Hitt Date: Mon Sep 28 14:45:34 2026 -0400 First public release Co-Authored-By: Claude Opus 5.5 diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..f15441a --- /dev/null +++ b/.editorconfig @@ -0,0 +1,12 @@ +root = true + +[*] +charset = utf-8 +end_of_line = lf +insert_final_newline = true +trim_trailing_whitespace = true +indent_style = space +indent_size = 2 + +[*.md] +trim_trailing_whitespace = false diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..5fd8e1d --- /dev/null +++ b/.gitignore @@ -0,0 +1,8 @@ +node_modules/ +dist/ +*.log +.DS_Store +.env* +!.env.example +.npmrc +dist-cjs/ diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml new file mode 100644 index 0000000..e5a37d2 --- /dev/null +++ b/.gitlab-ci.yml @@ -0,0 +1,6 @@ +stages: [test] + +test: + stage: test + image: node:22-alpine + script: [npm ci, npm run build, npm test] diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 0000000..50ca57c --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,17 @@ +# Changelog + +## 0.1.0 - 2026-09-28 + +First public release under MIT. + +- `checkClaims()` and `formatClaims()` check advertised cryptographic claims + against the keys, ciphers and transport settings described. +- `end-to-end-encrypted` and `zero-knowledge` fail when a key is held by the + server, an operator or a third party, whatever the cipher strength. +- `encrypted-at-rest`, `encrypted-in-transit`, `passwords-hashed` and + `forward-secrecy` are each checked against the element that would enforce + them. +- Broken primitives (MD5, SHA-1, DES, 3DES, RC4, ECB) are reported even when + nothing was claimed about them. +- A claim with nothing describing it is reported as not assessed, never as a + pass. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..ec2c11e --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,22 @@ +# Contributing + +Issues and merge requests are welcome at +https://gitlab.com/extant2000/claim-check. + +## Ground rules + +- **A test that cannot fail proves nothing.** If you fix a bug, add a test + that fails without your fix, and check that it does fail before you submit. +- Measure, do not assume. Two modules with the same line count can be + different programs. +- Keep dependencies minimal. Every new dependency needs a reason. +- Explain why in comments, not what. + +## Before you open a merge request + +Run both of these and make sure they pass: + +``` +npm run build +npm test +``` diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..34e49b1 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 Extant 2000 LLC + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md new file mode 100644 index 0000000..c173a63 --- /dev/null +++ b/README.md @@ -0,0 +1,96 @@ +# ClaimCheck + +Checks the cryptographic claims a system makes, such as "end-to-end +encrypted", against the keys, ciphers and transport settings it actually +uses. + +## What it does and why + +A common pattern: a feature is described as encrypted, and it is. AES-256-GCM, +correctly applied, ciphertext at rest. It is still not end-to-end encrypted, +because the server holds the key. Every cryptographic choice is sound, the +claim is false, and no review of the algorithm would catch it. + +That asymmetry is what this library is built around. **Cipher strength is the +easy half and rarely the part that is wrong. The part that goes wrong is key +custody: who can read the plaintext.** A claim of "end-to-end" or +"zero-knowledge" is a claim about custody. An operator holding the key +falsifies it no matter how strong the cipher is. + +In the case above, ClaimCheck fails the end-to-end claim and names who holds +the key. It passes the at-rest claim, because that one is true. Only the +claim that goes beyond its custody fails. + +## What it checks + +| Claim | Checked against | +|---|---| +| `end-to-end-encrypted` | Key custody. Fails if `server`, `operator` or `third-party` holds any key. | +| `zero-knowledge` | The same custody rule. | +| `encrypted-at-rest` | An at-rest cipher exists, and it is not broken and not ECB. | +| `encrypted-in-transit` | A pinned minimum TLS version of 1.2 or higher. | +| `passwords-hashed` | A password KDF (bcrypt, scrypt, argon2, PBKDF2), not a fast hash and not reversible encryption. | +| `forward-secrecy` | Every listed cipher suite uses an ephemeral (ECDHE or DHE) key exchange. | + +Broken primitives (MD5, SHA-1, DES, 3DES, RC4, any ECB mode) are reported +even when nothing was claimed about them. Not advertising a property is no +reason to leave MD5 in a signature path. + +A key held only in an `hsm` does not break a custody claim, because the +operator cannot read it. A `third-party` holder does: "end-to-end with a +vendor in the middle" is the marketing sense of the phrase, not the +technical one. + +## Missing evidence is not a pass + +A claim with nothing in the inventory to support it is reported as NOT +ASSESSED. "No key custody was described" is not evidence that custody is +safe. It only shows that custody was not described. The same applies to a +TLS setup with no pinned minimum version: the result would depend on a +runtime default that can change, so it is not assessed. + +The library is pure. It takes a description of your system and returns +findings, with no filesystem access, network calls or crypto calls. The +output is in the `@extant2000/evidence-record` format, and every conclusion +cites the file or location it rests on. + +## Usage + +```ts +import { checkClaims, formatClaims, type CryptoInventory } from '@extant2000/claim-check' + +const inventory: CryptoInventory = { + claims: ['end-to-end-encrypted', 'encrypted-at-rest', 'passwords-hashed'], + keys: [{ + keyId: 'NOTES_KEY', + heldBy: ['server', 'operator'], // list every party that can obtain it + location: 'config/app.env', + protects: 'note bodies', + }], + ciphers: [ + { algorithm: 'AES', mode: 'GCM', keyBits: 256, purpose: 'at-rest', where: 'src/notes/store.ts', line: 88 }, + { algorithm: 'argon2id', purpose: 'password', where: 'src/auth.ts', line: 30 }, + ], + transport: [{ minTlsVersion: '1.2', where: 'config/tls.yml' }], +} + +const report = checkClaims(inventory) // structured report +console.log(formatClaims(inventory)) // the same report as text +``` + +`heldBy` decides the custody checks, and an optimistic answer defeats the +library. If the operator can read the environment variable that holds the +key, list `operator`. + +For this inventory the end-to-end claim fails at critical severity, citing +`config/app.env`, while the at-rest and password claims pass. + +## Install + +``` +npm install @extant2000/claim-check +``` + +## License + +MIT. See [LICENSE](LICENSE). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..b88987e --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,6 @@ +# Security + +Please report vulnerabilities privately by email to security@extant2000.com. +Do not open a public issue for a security problem. + +We aim to acknowledge every report within 5 business days. diff --git a/package-lock.json b/package-lock.json new file mode 100644 index 0000000..d5cc46e --- /dev/null +++ b/package-lock.json @@ -0,0 +1,1503 @@ +{ + "name": "@extant2000/claim-check", + "version": "0.1.0", + "lockfileVersion": 3, + "requires": true, + "packages": { + "": { + "name": "@extant2000/claim-check", + "version": "0.1.0", + "license": "MIT", + "dependencies": { + "@extant2000/evidence-record": "^0.1.2" + }, + "devDependencies": { + "typescript": "^5.6.0", + "vitest": "^2.1.0" + } + }, + "node_modules/@esbuild/aix-ppc64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.21.5.tgz", + "integrity": "sha512-1SDgH6ZSPTlggy1yI6+Dbkiz8xzpHJEVAlF/AM1tHPLsf5STom9rwtjE4hKAF20FfXXNTFqEYXyJNWh1GiZedQ==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "aix" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-arm": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.21.5.tgz", + "integrity": "sha512-vCPvzSjpPHEi1siZdlvAlsPxXl7WbOVUBBAowWug4rJHb68Ox8KualB+1ocNvT5fjv6wpkX6o/iEpbDrf68zcg==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.21.5.tgz", + "integrity": "sha512-c0uX9VAUBQ7dTDCjq+wdyGLowMdtR/GoC2U5IYk/7D1H1JYC0qseD7+11iMP2mRLN9RcCMRcjC4YMclCzGwS/A==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/android-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.21.5.tgz", + "integrity": "sha512-D7aPRUUNHRBwHxzxRvp856rjUHRFW1SdQATKXH2hqA0kAZb1hKmi02OpYRacl0TxIGz/ZmXWlbZgjwWYaCakTA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/darwin-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.21.5.tgz", + "integrity": "sha512-DwqXqZyuk5AiWWf3UfLiRDJ5EDd49zg6O9wclZ7kUMv2WRFr4HKjXp/5t8JZ11QbQfUS6/cRCKGwYhtNAY88kQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/darwin-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.21.5.tgz", + "integrity": "sha512-se/JjF8NlmKVG4kNIuyWMV/22ZaerB+qaSi5MdrXtd6R08kvs2qCN4C09miupktDitvh8jRFflwGFBQcxZRjbw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/freebsd-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.21.5.tgz", + "integrity": "sha512-5JcRxxRDUJLX8JXp/wcBCy3pENnCgBR9bN6JsY4OmhfUtIHe3ZW0mawA7+RDAcMLrMIZaf03NlQiX9DGyB8h4g==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/freebsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.21.5.tgz", + "integrity": "sha512-J95kNBj1zkbMXtHVH29bBriQygMXqoVQOQYA+ISs0/2l3T9/kj42ow2mpqerRBxDJnmkUDCaQT/dfNXWX/ZZCQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-arm": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.21.5.tgz", + "integrity": "sha512-bPb5AHZtbeNGjCKVZ9UGqGwo8EUu4cLq68E95A53KlxAPRmUyYv2D6F0uUI65XisGOL1hBP5mTronbgo+0bFcA==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.21.5.tgz", + "integrity": "sha512-ibKvmyYzKsBeX8d8I7MH/TMfWDXBF3db4qM6sy+7re0YXya+K1cem3on9XgdT2EQGMu4hQyZhan7TeQ8XkGp4Q==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-ia32": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.21.5.tgz", + "integrity": "sha512-YvjXDqLRqPDl2dvRODYmmhz4rPeVKYvppfGYKSNGdyZkA01046pLWyRKKI3ax8fbJoK5QbxblURkwK/MWY18Tg==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-loong64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.21.5.tgz", + "integrity": "sha512-uHf1BmMG8qEvzdrzAqg2SIG/02+4/DHB6a9Kbya0XDvwDEKCoC8ZRWI5JJvNdUjtciBGFQ5PuBlpEOXQj+JQSg==", + "cpu": [ + "loong64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-mips64el": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.21.5.tgz", + "integrity": "sha512-IajOmO+KJK23bj52dFSNCMsz1QP1DqM6cwLUv3W1QwyxkyIWecfafnI555fvSGqEKwjMXVLokcV5ygHW5b3Jbg==", + "cpu": [ + "mips64el" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-ppc64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.21.5.tgz", + "integrity": "sha512-1hHV/Z4OEfMwpLO8rp7CvlhBDnjsC3CttJXIhBi+5Aj5r+MBvy4egg7wCbe//hSsT+RvDAG7s81tAvpL2XAE4w==", + "cpu": [ + "ppc64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-riscv64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.21.5.tgz", + "integrity": "sha512-2HdXDMd9GMgTGrPWnJzP2ALSokE/0O5HhTUvWIbD3YdjME8JwvSCnNGBnTThKGEB91OZhzrJ4qIIxk/SBmyDDA==", + "cpu": [ + "riscv64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-s390x": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.21.5.tgz", + "integrity": "sha512-zus5sxzqBJD3eXxwvjN1yQkRepANgxE9lgOW2qLnmr8ikMTphkjgXu1HR01K4FJg8h1kEEDAqDcZQtbrRnB41A==", + "cpu": [ + "s390x" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/linux-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.21.5.tgz", + "integrity": "sha512-1rYdTpyv03iycF1+BhzrzQJCdOuAOtaqHTWJZCWvijKD2N5Xu0TtVC8/+1faWqcP9iBCWOmjmhoH94dH82BxPQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/netbsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.21.5.tgz", + "integrity": "sha512-Woi2MXzXjMULccIwMnLciyZH4nCIMpWQAs049KEeMvOcNADVxo0UBIQPfSmxB3CWKedngg7sWZdLvLczpe0tLg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "netbsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/openbsd-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.21.5.tgz", + "integrity": "sha512-HLNNw99xsvx12lFBUwoT8EVCsSvRNDVxNpjZ7bPn947b8gJPzeHWyNVhFsaerc0n3TsbOINvRP2byTZ5LKezow==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/sunos-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.21.5.tgz", + "integrity": "sha512-6+gjmFpfy0BHU5Tpptkuh8+uw3mnrvgs+dSPQXQOv3ekbordwnzTVEb4qnIvQcYXq6gzkyTnoZ9dZG+D4garKg==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "sunos" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-arm64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.21.5.tgz", + "integrity": "sha512-Z0gOTd75VvXqyq7nsl93zwahcTROgqvuAcYDUr+vOv8uHhNSKROyU961kgtCD1e95IqPKSQKH7tBTslnS3tA8A==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-ia32": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.21.5.tgz", + "integrity": "sha512-SWXFF1CL2RVNMaVs+BBClwtfZSvDgtL//G/smwAc5oVK/UPu2Gu9tIaRgFmYFFKrmg3SyAjSrElf0TiJ1v8fYA==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@esbuild/win32-x64": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.21.5.tgz", + "integrity": "sha512-tQd/1efJuzPC6rCFwEvLtci/xNFcTZknmXs98FYDfGE4wP9ClFV98nyKrzJKVPMhdDnjzLhdUyMX4PsQAPjwIw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": ">=12" + } + }, + "node_modules/@extant2000/evidence-record": { + "version": "0.1.2" + }, + "node_modules/@jridgewell/sourcemap-codec": { + "version": "1.6.0", + "resolved": "https://registry.npmjs.org/@jridgewell/sourcemap-codec/-/sourcemap-codec-1.6.0.tgz", + "integrity": "sha512-T7jf+5zgsZHwNJ4lvQ7/aezbyk0nNX+zJVWpmHA7VYsEx7a7qr5Rg5IbtJFqkgze5Y2sruq1RUY8Q837Od7iFw==", + "dev": true, + "license": "MIT" + }, + "node_modules/@napi-rs/lzma-linux-x64-gnu": { + "version": "1.5.1", + "resolved": "https://registry.npmjs.org/@napi-rs/lzma-linux-x64-gnu/-/lzma-linux-x64-gnu-1.5.1.tgz", + "integrity": "sha512-oTXEIha4SsuXdTA4Iyskj0kpdx2yVXdhd75c2v3xGrHFfVMsbhTPZU/nMPL4sWKo4pBHm3aucLaqGlF696dTyQ==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^22.20 || ^24.12 || >=25" + } + }, + "node_modules/@rollup/rollup-android-arm-eabi": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-android-arm-eabi/-/rollup-android-arm-eabi-4.63.5.tgz", + "integrity": "sha512-J25QJU+B78T4FhhBsNpLJyVWOi31mwtpcMwywHmOKH65Q9IWGA81gPj+dnwlhU8wktVriYE+tFAaQgrnJRzAZg==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ] + }, + "node_modules/@rollup/rollup-android-arm64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-android-arm64/-/rollup-android-arm64-4.63.5.tgz", + "integrity": "sha512-LDopB3zuZM5Ux9TT2luNEBJW/tYbGU2g1d+VpKk6I+gSKDb+/7sYE6M225gRQt4RbMX6MSwMsVR/phdjVUgRLg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ] + }, + "node_modules/@rollup/rollup-darwin-arm64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-darwin-arm64/-/rollup-darwin-arm64-4.63.5.tgz", + "integrity": "sha512-wlJEERGfeuHeBavCL2qVnNacOK43NDoZM4sjkeRPymd04OAE9T1zBqDJgmZ+CIsPTYKwdzpUC8vmOw84dwY4Tg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ] + }, + "node_modules/@rollup/rollup-darwin-x64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-darwin-x64/-/rollup-darwin-x64-4.63.5.tgz", + "integrity": "sha512-4nJJGg5jbo2wwPP4JP+LfEBA3bvP8rU9CLuhp7jWvq9sxEyhjQFTFdrqi+/dHEin/pd8jpT0vcehIpnZtmEdcQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ] + }, + "node_modules/@rollup/rollup-freebsd-arm64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-freebsd-arm64/-/rollup-freebsd-arm64-4.63.5.tgz", + "integrity": "sha512-DrZbyCDF1hneuO6jRbvZ2D7+PIBM6yIwYnJpg2vIk58T+wuFpiaGZrfUr59lDWw45bg+IrpTGLPiNi/Fk4w3Cg==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ] + }, + "node_modules/@rollup/rollup-freebsd-x64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-freebsd-x64/-/rollup-freebsd-x64-4.63.5.tgz", + "integrity": "sha512-gqfUVMJMB3mehqywxp6hTBFfgtMQykZY19+cfiaYP0toIJLb/1DZRJHVkQQGP13W4TAwfZDWeg1qBcheTRioXQ==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ] + }, + "node_modules/@rollup/rollup-linux-arm-gnueabihf": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm-gnueabihf/-/rollup-linux-arm-gnueabihf-4.63.5.tgz", + "integrity": "sha512-CFmhpvAwzSaWMlN3VN7UtmoTihlZNzoP0juQib5TQRnYUyDV8dXeWOp29sobWAT6gXl/hQgAClLlEiYozQG3OQ==", + "cpu": [ + "arm" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm-musleabihf": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm-musleabihf/-/rollup-linux-arm-musleabihf-4.63.5.tgz", + "integrity": "sha512-Uc9H8eXCOayV6JLTH5bXKMId6qbhNHa818/BgYjm4jrlq3vZquC9cqyvHBw17xy5Mnj5f+I3gFK5JcEf3hSqrw==", + "cpu": [ + "arm" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm64-gnu/-/rollup-linux-arm64-gnu-4.63.5.tgz", + "integrity": "sha512-VcPr/szv/1BFw112Kt//fxulXt/JPqzzidU84iW68L2DdjnOO8QFUv2zTSYBEPHD6movBD4z+bbr5y60GYM7Jw==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-arm64-musl": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-arm64-musl/-/rollup-linux-arm64-musl-4.63.5.tgz", + "integrity": "sha512-BnxtJ5/91BrIHYIkGrmjz/lbMhqEHt1dPFqIxIFR+jPn0xVc/oUSCtIT089zfp5ufwGDlYz2UC+Fe1SRBpYFbQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-loong64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-loong64-gnu/-/rollup-linux-loong64-gnu-4.63.5.tgz", + "integrity": "sha512-LrYcHZwF+fAMNKHYTOQ5osWM4AZF7YF6D+XtsjDyEvljtt11twc+zHVXBLNEjxVSUnKYsOhvVz4Z213eW02COQ==", + "cpu": [ + "loong64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-loong64-musl": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-loong64-musl/-/rollup-linux-loong64-musl-4.63.5.tgz", + "integrity": "sha512-nj7QKQePAAUpCpJHtg0pR0W/b92A9NO17JS3BAQmHDn/yhmkir2p8llrKY9TOhleKIaSzy1JhxS3T9FVld6coA==", + "cpu": [ + "loong64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-ppc64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-ppc64-gnu/-/rollup-linux-ppc64-gnu-4.63.5.tgz", + "integrity": "sha512-5ylkX6dWMeBKge9nTU+Rxfb+ZfaCIJ9lRqIFaK0eAMcWp7OJbYnLveLgXmm0VrvuLKb8qIK+mHyH0qu88RM+iA==", + "cpu": [ + "ppc64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-ppc64-musl": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-ppc64-musl/-/rollup-linux-ppc64-musl-4.63.5.tgz", + "integrity": "sha512-oHK4ZHYFDKjZviK34I+NwgfbGxgI7ztrNxj2hPTSSNFgeq1a/lEd7dHV2fdGAuTH4Iym3RHJg+vAbWaWG4B7Zg==", + "cpu": [ + "ppc64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-riscv64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-riscv64-gnu/-/rollup-linux-riscv64-gnu-4.63.5.tgz", + "integrity": "sha512-UcetmHZ6XOXuUByiKZyQmb55ZPr0LABr3Ec/HB9wKZn6CEAFWZkE+hsJErJ9hbPBC7nI0dKuELx7CoV6IM7TMg==", + "cpu": [ + "riscv64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-riscv64-musl": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-riscv64-musl/-/rollup-linux-riscv64-musl-4.63.5.tgz", + "integrity": "sha512-C5CmDPQBtvjVo8cgQsBs+w6WB0JLkiixhgi6hVLV11hERWdn/p0XcPU2OUcZzac9BPOFq7SbaHFa8r3SWEysCQ==", + "cpu": [ + "riscv64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-s390x-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-s390x-gnu/-/rollup-linux-s390x-gnu-4.63.5.tgz", + "integrity": "sha512-lHVQHJFKsuuxLMi3MQO9XVL8Tje3JR82CzB+QDKC5NWBcsIWuwsn9uIM5e3lBhI+fF1/s63qnyYqsg65+8rV/w==", + "cpu": [ + "s390x" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-x64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-x64-gnu/-/rollup-linux-x64-gnu-4.63.5.tgz", + "integrity": "sha512-3W9bTFcQNJn71cSJVM9RKIiZOy8DO/XLDii8Uv/Pm6WKqDRj7JV3ZfuXIEfyuy5LXpIzAbB/1M4Ukp9GKNa7nA==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-linux-x64-musl": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-linux-x64-musl/-/rollup-linux-x64-musl-4.63.5.tgz", + "integrity": "sha512-VDC7rRJlee/scpki96GZ27Omf6yU87s1YXwVTpjE5841faVlDYYT565rgfmoR1U0sqL7z5ivQSDjcsF6VRXyBA==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ] + }, + "node_modules/@rollup/rollup-openbsd-x64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-openbsd-x64/-/rollup-openbsd-x64-4.63.5.tgz", + "integrity": "sha512-z86Ok2p4pTdv5xqCKZsTooO7yBEiaJR/HzU3Wx8RmWsPoLppnMKROhJusQob8B3IE1ghC343kUW9rC2r+Wf3ig==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openbsd" + ] + }, + "node_modules/@rollup/rollup-openharmony-arm64": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-openharmony-arm64/-/rollup-openharmony-arm64-4.63.5.tgz", + "integrity": "sha512-IzQmj+xXwQFGhMAMKMQVXkMwMZN3TqkJgAE0nSsqvVwWWciP4AIPMmWRqOQ2GfX7TUDZr+xqGFcBS36CRPGw0g==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ] + }, + "node_modules/@rollup/rollup-win32-arm64-msvc": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-arm64-msvc/-/rollup-win32-arm64-msvc-4.63.5.tgz", + "integrity": "sha512-F6qpTaPc9bwBH85kjy0/BLmLSW1uv7AoOXCoRIkg2arlgCYlWYcAbiMkvZuAcaWk9TpCRG//okznLAqLGshkMw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-ia32-msvc": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-ia32-msvc/-/rollup-win32-ia32-msvc-4.63.5.tgz", + "integrity": "sha512-igoDsTFhhwECBeGbUuLeIk7t8Y1apa+cs6mDWpx2EZ0ch7oEQgzHbFUXN9euoHekCAQzXdXApAGkV6jznS7tWw==", + "cpu": [ + "ia32" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-x64-gnu": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-x64-gnu/-/rollup-win32-x64-gnu-4.63.5.tgz", + "integrity": "sha512-U3teMeMbXFmaM5D+OTJpsOXd+wV/qftIeYF9kBKL4v73641qyJmoXFtA28DQLsnmlyayEsTe72xpLHrArq6vHw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@rollup/rollup-win32-x64-msvc": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/@rollup/rollup-win32-x64-msvc/-/rollup-win32-x64-msvc-4.63.5.tgz", + "integrity": "sha512-ypfC34F3RKXvCXBglGqGMsUSMKlgwd1HX9AOAlx9RoZZ6GaI42YHVeKpzg3JG+wpBUJYTG+NNZhqbDWL8tBZkw==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ] + }, + "node_modules/@types/estree": { + "version": "1.0.9", + "resolved": "https://registry.npmjs.org/@types/estree/-/estree-1.0.9.tgz", + "integrity": "sha512-GhdPgy1el4/ImP05X05Uw4cw2/M93BCUmnEvWZNStlCzEKME4Fkk+YpoA5OiHNQmoS7Cafb8Xa3Pya8m1Qrzeg==", + "dev": true, + "license": "MIT" + }, + "node_modules/@vitest/expect": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/expect/-/expect-2.1.9.tgz", + "integrity": "sha512-UJCIkTBenHeKT1TTlKMJWy1laZewsRIzYighyYiJKZreqtdxSos/S1t+ktRMQWu2CKqaarrkeszJx1cgC5tGZw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/spy": "2.1.9", + "@vitest/utils": "2.1.9", + "chai": "^5.1.2", + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/mocker": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-2.1.9.tgz", + "integrity": "sha512-tVL6uJgoUdi6icpxmdrn5YNo3g3Dxv+IHJBr0GXHaEdTcw3F+cPKnsXFhli6nO+f/6SDKPHEK1UN+k+TQv0Ehg==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/spy": "2.1.9", + "estree-walker": "^3.0.3", + "magic-string": "^0.30.12" + }, + "funding": { + "url": "https://opencollective.com/vitest" + }, + "peerDependencies": { + "msw": "^2.4.9", + "vite": "^5.0.0" + }, + "peerDependenciesMeta": { + "msw": { + "optional": true + }, + "vite": { + "optional": true + } + } + }, + "node_modules/@vitest/pretty-format": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/pretty-format/-/pretty-format-2.1.9.tgz", + "integrity": "sha512-KhRIdGV2U9HOUzxfiHmY8IFHTdqtOhIzCpd8WRdJiE7D/HUcZVD0EgQCVjm+Q9gkUXWgBvMmTtZgIG48wq7sOQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/runner": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/runner/-/runner-2.1.9.tgz", + "integrity": "sha512-ZXSSqTFIrzduD63btIfEyOmNcBmQvgOVsPNPe0jYtESiXkhd8u2erDLnMxmGrDCwHCCHE7hxwRDCT3pt0esT4g==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/utils": "2.1.9", + "pathe": "^1.1.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/snapshot": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/snapshot/-/snapshot-2.1.9.tgz", + "integrity": "sha512-oBO82rEjsxLNJincVhLhaxxZdEtV0EFHMK5Kmx5sJ6H9L183dHECjiefOAdnqpIgT5eZwT04PoggUnW88vOBNQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/pretty-format": "2.1.9", + "magic-string": "^0.30.12", + "pathe": "^1.1.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/spy": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/spy/-/spy-2.1.9.tgz", + "integrity": "sha512-E1B35FwzXXTs9FHNK6bDszs7mtydNi5MIfUWpceJ8Xbfb1gBMscAnwLbEu+B44ed6W3XjL9/ehLPHR1fkf1KLQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "tinyspy": "^3.0.2" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/@vitest/utils": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/@vitest/utils/-/utils-2.1.9.tgz", + "integrity": "sha512-v0psaMSkNJ3A2NMrUEHFRzJtDPFn+/VWZ5WxImB21T9fjucJRmS7xCS3ppEnARb9y11OAzaD+P2Ps+b+BGX5iQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/pretty-format": "2.1.9", + "loupe": "^3.1.2", + "tinyrainbow": "^1.2.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/assertion-error": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/assertion-error/-/assertion-error-2.0.1.tgz", + "integrity": "sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=12" + } + }, + "node_modules/cac": { + "version": "6.7.14", + "resolved": "https://registry.npmjs.org/cac/-/cac-6.7.14.tgz", + "integrity": "sha512-b6Ilus+c3RrdDk+JhLKUAQfzzgLEPy6wcXqS7f/xe1EETvsDP6GORG7SFuOs6cID5YkqchW/LXZbX5bc8j7ZcQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=8" + } + }, + "node_modules/chai": { + "version": "5.3.3", + "resolved": "https://registry.npmjs.org/chai/-/chai-5.3.3.tgz", + "integrity": "sha512-4zNhdJD/iOjSH0A05ea+Ke6MU5mmpQcbQsSOkgdaUMJ9zTlDTD/GYlwohmIE2u0gaxHYiVHEn1Fw9mZ/ktJWgw==", + "dev": true, + "license": "MIT", + "dependencies": { + "assertion-error": "^2.0.1", + "check-error": "^2.1.1", + "deep-eql": "^5.0.1", + "loupe": "^3.1.0", + "pathval": "^2.0.0" + }, + "engines": { + "node": ">=18" + } + }, + "node_modules/check-error": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/check-error/-/check-error-2.1.3.tgz", + "integrity": "sha512-PAJdDJusoxnwm1VwW07VWwUN1sl7smmC3OKggvndJFadxxDRyFJBX/ggnu/KE4kQAB7a3Dp8f/YXC1FlUprWmA==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 16" + } + }, + "node_modules/debug": { + "version": "4.4.3", + "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz", + "integrity": "sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==", + "dev": true, + "license": "MIT", + "dependencies": { + "ms": "^2.1.3" + }, + "engines": { + "node": ">=6.0" + }, + "peerDependenciesMeta": { + "supports-color": { + "optional": true + } + } + }, + "node_modules/deep-eql": { + "version": "5.0.2", + "resolved": "https://registry.npmjs.org/deep-eql/-/deep-eql-5.0.2.tgz", + "integrity": "sha512-h5k/5U50IJJFpzfL6nO9jaaumfjO/f2NjK/oYB2Djzm4p9L+3T9qWpZqZ2hAbLPuuYq9wrU08WQyBTL5GbPk5Q==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=6" + } + }, + "node_modules/es-module-lexer": { + "version": "1.7.0", + "resolved": "https://registry.npmjs.org/es-module-lexer/-/es-module-lexer-1.7.0.tgz", + "integrity": "sha512-jEQoCwk8hyb2AZziIOLhDqpm5+2ww5uIE6lkO/6jcOCusfk6LhMHpXXfBLXTZ7Ydyt0j4VoUQv6uGNYbdW+kBA==", + "dev": true, + "license": "MIT" + }, + "node_modules/esbuild": { + "version": "0.21.5", + "resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.21.5.tgz", + "integrity": "sha512-mg3OPMV4hXywwpoDxu3Qda5xCKQi+vCTZq8S9J/EpkhB2HzKXq4SNFZE3+NK93JYxc8VMSep+lOUSC/RVKaBqw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "bin": { + "esbuild": "bin/esbuild" + }, + "engines": { + "node": ">=12" + }, + "optionalDependencies": { + "@esbuild/aix-ppc64": "0.21.5", + "@esbuild/android-arm": "0.21.5", + "@esbuild/android-arm64": "0.21.5", + "@esbuild/android-x64": "0.21.5", + "@esbuild/darwin-arm64": "0.21.5", + "@esbuild/darwin-x64": "0.21.5", + "@esbuild/freebsd-arm64": "0.21.5", + "@esbuild/freebsd-x64": "0.21.5", + "@esbuild/linux-arm": "0.21.5", + "@esbuild/linux-arm64": "0.21.5", + "@esbuild/linux-ia32": "0.21.5", + "@esbuild/linux-loong64": "0.21.5", + "@esbuild/linux-mips64el": "0.21.5", + "@esbuild/linux-ppc64": "0.21.5", + "@esbuild/linux-riscv64": "0.21.5", + "@esbuild/linux-s390x": "0.21.5", + "@esbuild/linux-x64": "0.21.5", + "@esbuild/netbsd-x64": "0.21.5", + "@esbuild/openbsd-x64": "0.21.5", + "@esbuild/sunos-x64": "0.21.5", + "@esbuild/win32-arm64": "0.21.5", + "@esbuild/win32-ia32": "0.21.5", + "@esbuild/win32-x64": "0.21.5" + } + }, + "node_modules/estree-walker": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/estree-walker/-/estree-walker-3.0.3.tgz", + "integrity": "sha512-7RUKfXgSMMkzt6ZuXmqapOurLGPPfgj6l9uRZ7lRGolvk0y2yocc35LdcxKC5PQZdn2DMqioAQ2NoWcrTKmm6g==", + "dev": true, + "license": "MIT", + "dependencies": { + "@types/estree": "^1.0.0" + } + }, + "node_modules/expect-type": { + "version": "1.4.0", + "resolved": "https://registry.npmjs.org/expect-type/-/expect-type-1.4.0.tgz", + "integrity": "sha512-KfYbmpRm0VbLjEvVa9yGwCi9GI34xvi7A/HXYWQO65CSD2u3MczUJSuwXKFIxlGsgBQizV9q5J9NHj4VG0n+pA==", + "dev": true, + "license": "Apache-2.0", + "engines": { + "node": ">=12.0.0" + } + }, + "node_modules/fsevents": { + "version": "2.3.3", + "resolved": "https://registry.npmjs.org/fsevents/-/fsevents-2.3.3.tgz", + "integrity": "sha512-5xoDfX+fL7faATnagmWPpbFtwh/R77WmMMqqHGS65C3vvB0YHrgF+B1YmZ3441tMj5n63k0212XNoJwzlhffQw==", + "dev": true, + "hasInstallScript": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^8.16.0 || ^10.6.0 || >=11.0.0" + } + }, + "node_modules/loupe": { + "version": "3.2.1", + "resolved": "https://registry.npmjs.org/loupe/-/loupe-3.2.1.tgz", + "integrity": "sha512-CdzqowRJCeLU72bHvWqwRBBlLcMEtIvGrlvef74kMnV2AolS9Y8xUv1I0U/MNAWMhBlKIoyuEgoJ0t/bbwHbLQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/magic-string": { + "version": "0.30.21", + "resolved": "https://registry.npmjs.org/magic-string/-/magic-string-0.30.21.tgz", + "integrity": "sha512-vd2F4YUyEXKGcLHoq+TEyCjxueSeHnFxyyjNp80yg0XV4vUhnDer/lvvlqM/arB5bXQN5K2/3oinyCRyx8T2CQ==", + "dev": true, + "license": "MIT", + "dependencies": { + "@jridgewell/sourcemap-codec": "^1.5.5" + } + }, + "node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", + "dev": true, + "license": "MIT" + }, + "node_modules/nanoid": { + "version": "3.3.19", + "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.19.tgz", + "integrity": "sha512-Y2tUNy4ouw6tq5oDSKeQYGOyhkUBhNOcGV/02KC+6kd9eDGqdZd++mjMiIDilrBYvjEnCYvVtsuHCuP+okSfug==", + "dev": true, + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "bin": { + "nanoid": "bin/nanoid.cjs" + }, + "engines": { + "node": "^10 || ^12 || ^13.7 || ^14 || >=15.0.1" + } + }, + "node_modules/pathe": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/pathe/-/pathe-1.1.2.tgz", + "integrity": "sha512-whLdWMYL2TwI08hn8/ZqAbrVemu0LNaNNJZX73O6qaIdCTfXutsLhMkjdENX0qhsQ9uIimo4/aQOmXkoon2nDQ==", + "dev": true, + "license": "MIT" + }, + "node_modules/pathval": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/pathval/-/pathval-2.0.1.tgz", + "integrity": "sha512-//nshmD55c46FuFw26xV/xFAaB5HF9Xdap7HJBBnrKdAd6/GxDBaNA1870O79+9ueg61cZLSVc+OaFlfmObYVQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">= 14.16" + } + }, + "node_modules/picocolors": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/picocolors/-/picocolors-1.1.1.tgz", + "integrity": "sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==", + "dev": true, + "license": "ISC" + }, + "node_modules/postcss": { + "version": "8.5.28", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.28.tgz", + "integrity": "sha512-RRuzqDtt5Y9h3quz5hWhK+TPnsmVs6WwSU6LkJMeY4HstUEDuYTG8UJSdawMRzmzAtV+KEoG8N3Qg2qLy5vM/A==", + "dev": true, + "funding": [ + { + "type": "opencollective", + "url": "https://opencollective.com/postcss/" + }, + { + "type": "tidelift", + "url": "https://tidelift.com/funding/github/npm/postcss" + }, + { + "type": "github", + "url": "https://github.com/sponsors/ai" + } + ], + "license": "MIT", + "dependencies": { + "nanoid": "^3.3.18", + "picocolors": "^1.1.1", + "source-map-js": "^1.2.1" + }, + "engines": { + "node": "^10 || ^12 || >=14" + } + }, + "node_modules/rollup": { + "version": "4.63.5", + "resolved": "https://registry.npmjs.org/rollup/-/rollup-4.63.5.tgz", + "integrity": "sha512-KRWwmNLlPw5M7HcdYfm15oBv9n9LPtjzpzCIxS/phwqvPyxHSoKX6Y2YU3pxSPfy0CLquVgsx/j/hBi6OvH1Nw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@types/estree": "1.0.9" + }, + "bin": { + "rollup": "dist/bin/rollup" + }, + "engines": { + "node": ">=18.0.0", + "npm": ">=8.0.0" + }, + "optionalDependencies": { + "@napi-rs/lzma-linux-x64-gnu": "1.5.1", + "@rollup/rollup-android-arm-eabi": "4.63.5", + "@rollup/rollup-android-arm64": "4.63.5", + "@rollup/rollup-darwin-arm64": "4.63.5", + "@rollup/rollup-darwin-x64": "4.63.5", + "@rollup/rollup-freebsd-arm64": "4.63.5", + "@rollup/rollup-freebsd-x64": "4.63.5", + "@rollup/rollup-linux-arm-gnueabihf": "4.63.5", + "@rollup/rollup-linux-arm-musleabihf": "4.63.5", + "@rollup/rollup-linux-arm64-gnu": "4.63.5", + "@rollup/rollup-linux-arm64-musl": "4.63.5", + "@rollup/rollup-linux-loong64-gnu": "4.63.5", + "@rollup/rollup-linux-loong64-musl": "4.63.5", + "@rollup/rollup-linux-ppc64-gnu": "4.63.5", + "@rollup/rollup-linux-ppc64-musl": "4.63.5", + "@rollup/rollup-linux-riscv64-gnu": "4.63.5", + "@rollup/rollup-linux-riscv64-musl": "4.63.5", + "@rollup/rollup-linux-s390x-gnu": "4.63.5", + "@rollup/rollup-linux-x64-gnu": "4.63.5", + "@rollup/rollup-linux-x64-musl": "4.63.5", + "@rollup/rollup-openbsd-x64": "4.63.5", + "@rollup/rollup-openharmony-arm64": "4.63.5", + "@rollup/rollup-win32-arm64-msvc": "4.63.5", + "@rollup/rollup-win32-ia32-msvc": "4.63.5", + "@rollup/rollup-win32-x64-gnu": "4.63.5", + "@rollup/rollup-win32-x64-msvc": "4.63.5", + "fsevents": "~2.3.2" + } + }, + "node_modules/siginfo": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/siginfo/-/siginfo-2.0.0.tgz", + "integrity": "sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==", + "dev": true, + "license": "ISC" + }, + "node_modules/source-map-js": { + "version": "1.2.1", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", + "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "dev": true, + "license": "BSD-3-Clause", + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/stackback": { + "version": "0.0.2", + "resolved": "https://registry.npmjs.org/stackback/-/stackback-0.0.2.tgz", + "integrity": "sha512-1XMJE5fQo1jGH6Y/7ebnwPOBEkIEnT4QF32d5R1+VXdXveM0IBMJt8zfaxX1P3QhVwrYe+576+jkANtSS2mBbw==", + "dev": true, + "license": "MIT" + }, + "node_modules/std-env": { + "version": "3.10.0", + "resolved": "https://registry.npmjs.org/std-env/-/std-env-3.10.0.tgz", + "integrity": "sha512-5GS12FdOZNliM5mAOxFRg7Ir0pWz8MdpYm6AY6VPkGpbA7ZzmbzNcBJQ0GPvvyWgcY7QAhCgf9Uy89I03faLkg==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinybench": { + "version": "2.9.0", + "resolved": "https://registry.npmjs.org/tinybench/-/tinybench-2.9.0.tgz", + "integrity": "sha512-0+DUvqWMValLmha6lr4kD8iAMK1HzV0/aKnCtWb9v9641TnP/MFb7Pc2bxoxQjTXAErryXVgUOfv2YqNllqGeg==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinyexec": { + "version": "0.3.2", + "resolved": "https://registry.npmjs.org/tinyexec/-/tinyexec-0.3.2.tgz", + "integrity": "sha512-KQQR9yN7R5+OSwaK0XQoj22pwHoTlgYqmUscPYoknOoWCWfj/5/ABTMRi69FrKU5ffPVh5QcFikpWJI/P1ocHA==", + "dev": true, + "license": "MIT" + }, + "node_modules/tinypool": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/tinypool/-/tinypool-1.1.1.tgz", + "integrity": "sha512-Zba82s87IFq9A9XmjiX5uZA/ARWDrB03OHlq+Vw1fSdt0I+4/Kutwy8BP4Y/y/aORMo61FQ0vIb5j44vSo5Pkg==", + "dev": true, + "license": "MIT", + "engines": { + "node": "^18.0.0 || >=20.0.0" + } + }, + "node_modules/tinyrainbow": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/tinyrainbow/-/tinyrainbow-1.2.0.tgz", + "integrity": "sha512-weEDEq7Z5eTHPDh4xjX789+fHfF+P8boiFB+0vbWzpbnbsEr/GRaohi/uMKxg8RZMXnl1ItAi/IUHWMsjDV7kQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/tinyspy": { + "version": "3.0.2", + "resolved": "https://registry.npmjs.org/tinyspy/-/tinyspy-3.0.2.tgz", + "integrity": "sha512-n1cw8k1k0x4pgA2+9XrOkFydTerNcJ1zWCO5Nn9scWHTD+5tp8dghT2x1uduQePZTZgd3Tupf+x9BxJjeJi77Q==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, + "node_modules/typescript": { + "version": "5.9.3", + "resolved": "https://registry.npmjs.org/typescript/-/typescript-5.9.3.tgz", + "integrity": "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==", + "dev": true, + "license": "Apache-2.0", + "bin": { + "tsc": "bin/tsc", + "tsserver": "bin/tsserver" + }, + "engines": { + "node": ">=14.17" + } + }, + "node_modules/vite": { + "version": "5.4.21", + "resolved": "https://registry.npmjs.org/vite/-/vite-5.4.21.tgz", + "integrity": "sha512-o5a9xKjbtuhY6Bi5S3+HvbRERmouabWbyUcpXXUA1u+GNUKoROi9byOJ8M0nHbHYHkYICiMlqxkg1KkYmm25Sw==", + "dev": true, + "license": "MIT", + "dependencies": { + "esbuild": "^0.21.3", + "postcss": "^8.4.43", + "rollup": "^4.20.0" + }, + "bin": { + "vite": "bin/vite.js" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://github.com/vitejs/vite?sponsor=1" + }, + "optionalDependencies": { + "fsevents": "~2.3.3" + }, + "peerDependencies": { + "@types/node": "^18.0.0 || >=20.0.0", + "less": "*", + "lightningcss": "^1.21.0", + "sass": "*", + "sass-embedded": "*", + "stylus": "*", + "sugarss": "*", + "terser": "^5.4.0" + }, + "peerDependenciesMeta": { + "@types/node": { + "optional": true + }, + "less": { + "optional": true + }, + "lightningcss": { + "optional": true + }, + "sass": { + "optional": true + }, + "sass-embedded": { + "optional": true + }, + "stylus": { + "optional": true + }, + "sugarss": { + "optional": true + }, + "terser": { + "optional": true + } + } + }, + "node_modules/vite-node": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/vite-node/-/vite-node-2.1.9.tgz", + "integrity": "sha512-AM9aQ/IPrW/6ENLQg3AGY4K1N2TGZdR5e4gu/MmmR2xR3Ll1+dib+nook92g4TV3PXVyeyxdWwtaCAiUL0hMxA==", + "dev": true, + "license": "MIT", + "dependencies": { + "cac": "^6.7.14", + "debug": "^4.3.7", + "es-module-lexer": "^1.5.4", + "pathe": "^1.1.2", + "vite": "^5.0.0" + }, + "bin": { + "vite-node": "vite-node.mjs" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + } + }, + "node_modules/vitest": { + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/vitest/-/vitest-2.1.9.tgz", + "integrity": "sha512-MSmPM9REYqDGBI8439mA4mWhV5sKmDlBKWIYbA3lRb2PTHACE0mgKwA8yQ2xq9vxDTuk4iPrECBAEW2aoFXY0Q==", + "dev": true, + "license": "MIT", + "dependencies": { + "@vitest/expect": "2.1.9", + "@vitest/mocker": "2.1.9", + "@vitest/pretty-format": "^2.1.9", + "@vitest/runner": "2.1.9", + "@vitest/snapshot": "2.1.9", + "@vitest/spy": "2.1.9", + "@vitest/utils": "2.1.9", + "chai": "^5.1.2", + "debug": "^4.3.7", + "expect-type": "^1.1.0", + "magic-string": "^0.30.12", + "pathe": "^1.1.2", + "std-env": "^3.8.0", + "tinybench": "^2.9.0", + "tinyexec": "^0.3.1", + "tinypool": "^1.0.1", + "tinyrainbow": "^1.2.0", + "vite": "^5.0.0", + "vite-node": "2.1.9", + "why-is-node-running": "^2.3.0" + }, + "bin": { + "vitest": "vitest.mjs" + }, + "engines": { + "node": "^18.0.0 || >=20.0.0" + }, + "funding": { + "url": "https://opencollective.com/vitest" + }, + "peerDependencies": { + "@edge-runtime/vm": "*", + "@types/node": "^18.0.0 || >=20.0.0", + "@vitest/browser": "2.1.9", + "@vitest/ui": "2.1.9", + "happy-dom": "*", + "jsdom": "*" + }, + "peerDependenciesMeta": { + "@edge-runtime/vm": { + "optional": true + }, + "@types/node": { + "optional": true + }, + "@vitest/browser": { + "optional": true + }, + "@vitest/ui": { + "optional": true + }, + "happy-dom": { + "optional": true + }, + "jsdom": { + "optional": true + } + } + }, + "node_modules/why-is-node-running": { + "version": "2.3.0", + "resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-2.3.0.tgz", + "integrity": "sha512-hUrmaWBdVDcxvYqnyh09zunKzROWjbZTiNy8dBEjkS7ehEDQibXJ7XvlmtbwuTclUiIyN+CyXQD4Vmko8fNm8w==", + "dev": true, + "license": "MIT", + "dependencies": { + "siginfo": "^2.0.0", + "stackback": "0.0.2" + }, + "bin": { + "why-is-node-running": "cli.js" + }, + "engines": { + "node": ">=8" + } + } + } +} diff --git a/package.json b/package.json new file mode 100644 index 0000000..ea32853 --- /dev/null +++ b/package.json @@ -0,0 +1,46 @@ +{ + "name": "@extant2000/claim-check", + "version": "0.1.0", + "private": false, + "description": "Checks advertised cryptographic claims, such as end-to-end encryption, against key custody, ciphers and TLS settings.", + "license": "MIT", + "type": "module", + "main": "./dist-cjs/index.js", + "files": [ + "dist", + "dist-cjs", + "src", + "README.md", + "LICENSE" + ], + "repository": { + "type": "git", + "url": "https://gitlab.com/extant2000/claim-check.git" + }, + "dependencies": { + "@extant2000/evidence-record": "^0.1.2" + }, + "module": "./dist/index.js", + "types": "./dist/index.d.ts", + "exports": { + ".": { + "types": "./dist/index.d.ts", + "import": "./dist/index.js", + "require": "./dist-cjs/index.js" + } + }, + "scripts": { + "build": "tsc && tsc -p tsconfig.cjs.json && node -e \"require('fs').writeFileSync('dist-cjs/package.json', JSON.stringify({type:'commonjs'}))\"", + "test": "vitest run", + "prepublishOnly": "npm run build" + }, + "devDependencies": { + "typescript": "^5.6.0", + "vitest": "^2.1.0" + }, + "author": "Extant 2000 LLC", + "homepage": "https://gitlab.com/extant2000/claim-check", + "bugs": { + "url": "https://gitlab.com/extant2000/claim-check/-/issues" + } +} diff --git a/src/index.ts b/src/index.ts new file mode 100644 index 0000000..dc9fa33 --- /dev/null +++ b/src/index.ts @@ -0,0 +1,430 @@ +/** + * ClaimCheck — verify the cryptography a system actually enforces, against + * the cryptography it advertises. + * + * The typical case: a feature is described as encrypted, and it is (AES, + * properly applied, ciphertext at rest). It is NOT end-to-end encrypted, + * because the server holds the key. Every individual cryptographic choice + * is sound; the CLAIM is still false, and no amount of checking the + * algorithm would catch it. + * + * That is the asymmetry this library is built around. Cipher strength is the + * easy half and rarely the one that is wrong. The half that goes wrong is + * KEY CUSTODY: who can read the plaintext. A claim of "end-to-end" or + * "zero-knowledge" is a claim about custody, and it is falsified by an + * operator with the key regardless of how strong the cipher is. + * + * Boundary with `@extant2000/policy-enforced`: that library asks whether a + * written policy holds in code, by pattern. This one asks whether a + * cryptographic claim survives its own key custody. Keep the split + * deliberate — they merge by accident otherwise. + * + * Pure: takes a described inventory, returns findings. No filesystem, no + * network, no crypto calls, so it is safe to run anywhere and its output is + * reproducible evidence rather than a reading taken at a moment. + */ + +import { + type CapabilityReport, + type Determination, + type Finding, + type FormatOptions, + type Severity, + evidence, + formatReport as renderReport, +} from '@extant2000/evidence-record' + +/** Claims a system can make about its cryptography. */ +export type CryptoClaim = + /** Only the endpoints can read the plaintext. A custody claim. */ + | 'end-to-end-encrypted' + /** The operator cannot read the plaintext. A custody claim. */ + | 'zero-knowledge' + /** Stored bytes are ciphertext. Says nothing about who holds the key. */ + | 'encrypted-at-rest' + /** Bytes on the wire are ciphertext. */ + | 'encrypted-in-transit' + /** Credentials are irreversible, not merely encrypted. */ + | 'passwords-hashed' + /** Session keys do not compromise past traffic. */ + | 'forward-secrecy' + +/** Who can obtain the key material. */ +export type KeyHolder = 'client' | 'server' | 'operator' | 'hsm' | 'third-party' + +export interface KeyCustody { + keyId: string + /** + * Every party that can obtain this key. Be honest here — the point of the + * library is defeated by an optimistic answer, and "the operator can read + * the env var" counts. + */ + heldBy: KeyHolder[] + /** Where the key lives, cited in findings: an env var, a file, a KMS arn. */ + location: string + /** What the key protects. */ + protects: string +} + +export type CipherPurpose = 'transit' | 'at-rest' | 'password' | 'token' | 'signature' + +export interface CipherUse { + algorithm: string + /** Block mode, when it applies: `GCM`, `CBC`, `ECB`. */ + mode?: string + keyBits?: number + purpose: CipherPurpose + /** Source location, cited in findings. */ + where: string + line?: number +} + +export interface TransportConfig { + minTlsVersion?: string + /** Named suites, when the caller enumerates them. */ + cipherSuites?: string[] + where: string +} + +export interface CryptoInventory { + claims: CryptoClaim[] + keys?: KeyCustody[] + ciphers?: CipherUse[] + transport?: TransportConfig[] +} + +/** + * Parties whose possession of a key falsifies a custody claim. + * + * `hsm` is absent deliberately: a key that never leaves an HSM is not + * readable by the operator, which is the property the claim is about. A + * `third-party` IS disqualifying — "end-to-end" with a vendor in the middle + * is the marketing sense of the phrase, not the technical one. + */ +const CUSTODY_DISQUALIFIERS: KeyHolder[] = ['server', 'operator', 'third-party'] + +/** Algorithms that are broken, or were fine once and are not any more. */ +const BROKEN: Record = { + md5: 'collision-broken since 2004', + sha1: 'collision-broken (SHAttered, 2017)', + des: '56-bit key, brute-forceable', + '3des': 'Sweet32 birthday attack on 64-bit blocks', + rc4: 'biased keystream, prohibited by RFC 7465', +} + +/** Fast hashes: correct for integrity, catastrophic for passwords. */ +const FAST_HASHES = ['md5', 'sha1', 'sha256', 'sha512', 'sha3'] + +/** Password KDFs. Anything else storing a password is a finding. */ +const PASSWORD_KDFS = ['bcrypt', 'scrypt', 'argon2', 'argon2i', 'argon2d', 'argon2id', 'pbkdf2'] + +const norm = (s: string) => s.toLowerCase().replace(/[-_\s]/g, '') + +function cipherEvidence(c: CipherUse) { + return evidence.file(c.where, c.line, `${c.algorithm}${c.mode ? `-${c.mode}` : ''}`, `used for ${c.purpose}`) +} + +/** + * Check a claim of exclusive custody — "end-to-end", "zero-knowledge". + * + * This is the check that matters. It ignores the cipher entirely: a claim + * that the operator cannot read the plaintext is falsified by the operator + * holding the key, and AES-256-GCM does not change that. + */ +function custodyFinding(claim: CryptoClaim, inv: CryptoInventory): Finding { + const keys = inv.keys ?? [] + + if (keys.length === 0) { + return { + id: claim, + summary: `"${claim}" is claimed, but no key custody was described`, + determination: 'not-assessed', + severity: 'high', + detail: 'A custody claim can only be checked against custody. Describe who holds each key — an undescribed key is not a safe one.', + evidence: [], + } + } + + const compromising = keys.filter(k => k.heldBy.some(h => CUSTODY_DISQUALIFIERS.includes(h))) + + if (compromising.length === 0) { + return { + id: claim, + summary: `"${claim}" holds — no key is reachable by the server, an operator, or a third party`, + determination: 'pass', + severity: 'info', + evidence: keys.map(k => + evidence.file(k.location, undefined, k.heldBy.join(', '), `key "${k.keyId}" protects ${k.protects}`)), + } + } + + return { + id: claim, + summary: `"${claim}" is FALSE — ${compromising.length} key(s) are held by a party the claim excludes`, + determination: 'fail', + severity: 'critical', + detail: 'The data may be encrypted correctly and the claim still be untrue. Whoever holds the key can read the plaintext, so this is encryption at rest, not end-to-end. Say the former.', + evidence: compromising.map(k => + evidence.file( + k.location, + undefined, + k.heldBy.join(', '), + `key "${k.keyId}" protects ${k.protects} and is held by ${k.heldBy.filter(h => CUSTODY_DISQUALIFIERS.includes(h)).join(', ')}`, + )), + } +} + +function ciphersFor(inv: CryptoInventory, purpose: CipherPurpose): CipherUse[] { + return (inv.ciphers ?? []).filter(c => c.purpose === purpose) +} + +/** A claim that something is ciphertext, checked against a cipher doing it. */ +function cipherClaimFinding( + claim: CryptoClaim, + purpose: CipherPurpose, + inv: CryptoInventory, +): Finding { + const uses = ciphersFor(inv, purpose) + + if (uses.length === 0) { + return { + id: claim, + summary: `"${claim}" is claimed, but no ${purpose} cipher was found`, + determination: 'not-assessed', + severity: 'high', + detail: 'Nothing in the described inventory performs this encryption. That is not proof it is absent — it is proof it was not shown.', + evidence: [], + } + } + + const bad = uses.filter(u => BROKEN[norm(u.algorithm)] || norm(u.mode ?? '') === 'ecb') + if (bad.length > 0) { + return { + id: claim, + summary: `"${claim}" is enforced with a broken primitive`, + determination: 'fail', + severity: 'critical', + detail: bad.map(u => + norm(u.mode ?? '') === 'ecb' + ? `${u.algorithm}-ECB leaks plaintext structure — identical blocks encrypt identically` + : `${u.algorithm}: ${BROKEN[norm(u.algorithm)]}`).join('; '), + evidence: bad.map(cipherEvidence), + } + } + + return { + id: claim, + summary: `"${claim}" holds — ${uses.length} ${purpose} cipher(s), none broken`, + determination: 'pass', + severity: 'info', + evidence: uses.map(cipherEvidence), + } +} + +/** + * Password storage. + * + * A fast hash is the right tool for integrity and the wrong one for a + * password: SHA-256 is fast by design, which is precisely the property an + * attacker holding the hash file wants. "Encrypted" is also wrong — + * encryption is reversible and password storage must not be. + */ +function passwordFinding(inv: CryptoInventory): Finding { + const uses = ciphersFor(inv, 'password') + + if (uses.length === 0) { + return { + id: 'passwords-hashed', + summary: '"passwords-hashed" is claimed, but no password hashing was found', + determination: 'not-assessed', + severity: 'high', + evidence: [], + } + } + + const weak = uses.filter(u => !PASSWORD_KDFS.includes(norm(u.algorithm))) + if (weak.length > 0) { + return { + id: 'passwords-hashed', + summary: `"passwords-hashed" is FALSE for ${weak.length} of ${uses.length} store(s)`, + determination: 'fail', + severity: 'critical', + detail: weak.map(u => FAST_HASHES.includes(norm(u.algorithm)) + ? `${u.algorithm} is a fast hash — correct for integrity, catastrophic for passwords. Use bcrypt, scrypt or argon2id.` + : `${u.algorithm} is not a password KDF. If it is reversible, this is not hashing at all.`).join('; '), + evidence: weak.map(cipherEvidence), + } + } + + return { + id: 'passwords-hashed', + summary: `"passwords-hashed" holds — ${uses.length} store(s), all using a password KDF`, + determination: 'pass', + severity: 'info', + evidence: uses.map(cipherEvidence), + } +} + +const TLS_ORDER = ['1.0', '1.1', '1.2', '1.3'] + +function transitFinding(inv: CryptoInventory): Finding { + const configs = inv.transport ?? [] + + if (configs.length === 0) { + return { + id: 'encrypted-in-transit', + summary: '"encrypted-in-transit" is claimed, but no transport configuration was described', + determination: 'not-assessed', + severity: 'high', + evidence: [], + } + } + + const weak = configs.filter(c => { + const i = TLS_ORDER.indexOf(c.minTlsVersion ?? '') + return i >= 0 && i < TLS_ORDER.indexOf('1.2') + }) + + if (weak.length > 0) { + return { + id: 'encrypted-in-transit', + summary: '"encrypted-in-transit" is enforced with a deprecated TLS floor', + determination: 'fail', + severity: 'high', + detail: 'TLS 1.0 and 1.1 are deprecated (RFC 8996). A floor below 1.2 means a downgrade is available to anyone who can influence the handshake.', + evidence: weak.map(c => evidence.file(c.where, undefined, `minTlsVersion ${c.minTlsVersion}`)), + } + } + + const unspecified = configs.filter(c => !c.minTlsVersion) + if (unspecified.length === configs.length) { + return { + id: 'encrypted-in-transit', + summary: '"encrypted-in-transit" is claimed, but no minimum TLS version is pinned', + determination: 'not-assessed', + severity: 'medium', + detail: 'Without a floor the answer depends on the runtime default, which is not a property of this system and can change under it.', + evidence: configs.map(c => evidence.file(c.where, undefined, 'no minTlsVersion set')), + } + } + + return { + id: 'encrypted-in-transit', + summary: `"encrypted-in-transit" holds — TLS floor at ${configs.map(c => c.minTlsVersion).filter(Boolean).join(', ')}`, + determination: 'pass', + severity: 'info', + evidence: configs.map(c => evidence.file(c.where, undefined, `minTlsVersion ${c.minTlsVersion ?? 'unset'}`)), + } +} + +function forwardSecrecyFinding(inv: CryptoInventory): Finding { + const suites = (inv.transport ?? []).flatMap(c => (c.cipherSuites ?? []).map(s => ({ suite: s, where: c.where }))) + + if (suites.length === 0) { + return { + id: 'forward-secrecy', + summary: '"forward-secrecy" is claimed, but no cipher suites were enumerated', + determination: 'not-assessed', + severity: 'medium', + detail: 'Forward secrecy is a property of the key exchange, so it can only be read off the negotiated suites.', + evidence: [], + } + } + + // Ephemeral key exchange is the whole property: a static-RSA suite means + // one leaked server key retroactively decrypts every captured session. + const nonPfs = suites.filter(s => !/ECDHE|DHE/i.test(s.suite)) + if (nonPfs.length > 0) { + return { + id: 'forward-secrecy', + summary: `"forward-secrecy" is FALSE — ${nonPfs.length} suite(s) use a non-ephemeral key exchange`, + determination: 'fail', + severity: 'high', + detail: 'Without an ephemeral exchange, one leaked server key retroactively decrypts every session that was ever captured.', + evidence: nonPfs.map(s => evidence.file(s.where, undefined, s.suite, 'no ECDHE/DHE key exchange')), + } + } + + return { + id: 'forward-secrecy', + summary: `"forward-secrecy" holds — all ${suites.length} suite(s) use an ephemeral exchange`, + determination: 'pass', + severity: 'info', + evidence: suites.map(s => evidence.file(s.where, undefined, s.suite)), + } +} + +function findingFor(claim: CryptoClaim, inv: CryptoInventory): Finding { + switch (claim) { + case 'end-to-end-encrypted': + case 'zero-knowledge': + return custodyFinding(claim, inv) + case 'encrypted-at-rest': + return cipherClaimFinding(claim, 'at-rest', inv) + case 'encrypted-in-transit': + return transitFinding(inv) + case 'passwords-hashed': + return passwordFinding(inv) + case 'forward-secrecy': + return forwardSecrecyFinding(inv) + } +} + +/** + * Findings about the inventory itself, independent of any claim. + * + * A broken primitive is worth reporting even when nothing was claimed about + * it — the absence of a marketing sentence is not a reason to leave MD5 in + * a signature path. + */ +function unclaimedFindings(inv: CryptoInventory): Finding[] { + const claimed = new Set(inv.claims) + const covered = new Set() + if (claimed.has('encrypted-at-rest')) covered.add('at-rest') + if (claimed.has('passwords-hashed')) covered.add('password') + + return (inv.ciphers ?? []) + .filter(c => !covered.has(c.purpose)) + .filter(c => BROKEN[norm(c.algorithm)] || norm(c.mode ?? '') === 'ecb') + .map((c, i) => ({ + id: `unclaimed-${i}`, + summary: `${c.algorithm}${c.mode ? `-${c.mode}` : ''} used for ${c.purpose}`, + determination: 'fail' as Determination, + severity: (c.purpose === 'signature' ? 'critical' : 'high') as Severity, + detail: BROKEN[norm(c.algorithm)] ?? 'ECB mode leaks plaintext structure', + evidence: [cipherEvidence(c)], + })) +} + +/** Check every claim against the inventory that is supposed to support it. */ +export function checkClaims(inv: CryptoInventory): CapabilityReport { + const claims = inv.claims ?? [] + const described = (inv.keys?.length ?? 0) + (inv.ciphers?.length ?? 0) + (inv.transport?.length ?? 0) + + if (claims.length === 0 && described === 0) { + return { + capability: 'ClaimCheck', + scope: 'nothing described', + examined: 0, + findings: [], + notes: ['No claims and no cryptography were described, so nothing was checked.'], + } + } + + return { + capability: 'ClaimCheck', + scope: `${claims.length} claim(s) against ${described} described element(s)`, + // Claims are the unit of assessment. A system that describes plenty of + // cryptography and claims nothing has still had every claim it makes + // checked — vacuously — and the count says so. + examined: claims.length, + findings: [...claims.map(c => findingFor(c, inv)), ...unclaimedFindings(inv)], + } +} + +/** Render a claim check for a terminal, CI log or evidence package. */ +export function formatClaims(inv: CryptoInventory, opts: FormatOptions = {}): string { + return renderReport(checkClaims(inv), opts) +} + +export { CUSTODY_DISQUALIFIERS, PASSWORD_KDFS, BROKEN } diff --git a/test/claim-check.test.ts b/test/claim-check.test.ts new file mode 100644 index 0000000..5356bda --- /dev/null +++ b/test/claim-check.test.ts @@ -0,0 +1,206 @@ +import { describe, expect, it } from 'vitest' +import { overall, validateReport } from '@extant2000/evidence-record' +import { checkClaims, formatClaims, type CryptoInventory } from '../src/index.js' + +/** + * The shape this library is built around: a notes feature that really is + * encrypted with a sound cipher, and is NOT end-to-end, because the server + * holds the key. + */ +const notes: CryptoInventory = { + claims: ['end-to-end-encrypted', 'encrypted-at-rest'], + keys: [{ + keyId: 'NOTES_KEY', + heldBy: ['server', 'operator'], + location: 'config/app.env', + protects: 'note bodies', + }], + ciphers: [{ + algorithm: 'AES', + mode: 'GCM', + keyBits: 256, + purpose: 'at-rest', + where: 'src/notes/store.ts', + line: 88, + }], +} + +describe('custody is the check that matters', () => { + it('sound cipher, false claim', () => { + // Every cryptographic choice here is correct. The claim is still untrue, + // and no amount of checking the algorithm would have caught it. + const r = checkClaims(notes) + const e2e = r.findings.find(f => f.id === 'end-to-end-encrypted')! + const atRest = r.findings.find(f => f.id === 'encrypted-at-rest')! + + expect(e2e.determination).toBe('fail') + expect(atRest.determination).toBe('pass') // the encryption really is fine + expect(overall(r)).toBe('fail') + }) + + it('names who holds the key, not just that the claim failed', () => { + const text = formatClaims(notes, { evidence: 'full' }) + expect(text).toContain('config/app.env') + expect(text).toContain('server, operator') + expect(text).toContain('this is encryption at rest, not end-to-end') + }) + + it('ignores cipher strength entirely for a custody claim', () => { + // AES-256-GCM does not make an operator-held key end-to-end. + const stronger: CryptoInventory = { + ...notes, + ciphers: [{ ...notes.ciphers![0]!, keyBits: 512 }], + } + expect(checkClaims(stronger).findings[0]!.determination).toBe('fail') + }) + + it('passes a custody claim when only the client holds the key', () => { + const r = checkClaims({ + claims: ['end-to-end-encrypted'], + keys: [{ keyId: 'k', heldBy: ['client'], location: 'browser/keystore.ts', protects: 'messages' }], + }) + expect(overall(r)).toBe('pass') + }) + + it('treats an HSM-held key as compatible with the claim', () => { + // A key that never leaves an HSM is not readable by the operator, which + // is the property the claim is about. + const r = checkClaims({ + claims: ['zero-knowledge'], + keys: [{ keyId: 'k', heldBy: ['hsm'], location: 'kms://arn', protects: 'records' }], + }) + expect(overall(r)).toBe('pass') + }) + + it('treats a third party as disqualifying', () => { + // "End-to-end with a vendor in the middle" is the marketing sense of the + // phrase, not the technical one. + const r = checkClaims({ + claims: ['end-to-end-encrypted'], + keys: [{ keyId: 'k', heldBy: ['client', 'third-party'], location: 'vendor.md', protects: 'x' }], + }) + expect(overall(r)).toBe('fail') + }) + + it('reports an undescribed custody as not-assessed, never a pass', () => { + const r = checkClaims({ claims: ['end-to-end-encrypted'] }) + expect(r.findings[0]!.determination).toBe('not-assessed') + expect(overall(r)).toBe('not-assessed') + expect(formatClaims({ claims: ['end-to-end-encrypted'] })).not.toContain('✓') + }) +}) + +describe('primitives', () => { + const at = (algorithm: string, mode?: string): CryptoInventory => ({ + claims: ['encrypted-at-rest'], + ciphers: [{ algorithm, mode, purpose: 'at-rest', where: 'lib/crypto.ts', line: 4 }], + }) + + it('fails a broken algorithm', () => { + expect(checkClaims(at('3DES')).findings[0]!.determination).toBe('fail') + expect(checkClaims(at('RC4')).findings[0]!.detail).toContain('RFC 7465') + }) + + it('fails ECB regardless of the cipher', () => { + const f = checkClaims(at('AES', 'ECB')).findings[0]! + expect(f.determination).toBe('fail') + expect(f.detail).toContain('identical blocks encrypt identically') + }) + + it('accepts AES-GCM', () => { + expect(checkClaims(at('AES', 'GCM')).findings[0]!.determination).toBe('pass') + }) + + it('reports a broken primitive even when nothing was claimed about it', () => { + // The absence of a marketing sentence is not a reason to leave MD5 in a + // signature path. + const r = checkClaims({ + claims: [], + ciphers: [{ algorithm: 'MD5', purpose: 'signature', where: 'lib/sign.ts', line: 12 }], + }) + expect(r.findings).toHaveLength(1) + expect(r.findings[0]!.severity).toBe('critical') + expect(r.findings[0]!.detail).toContain('collision-broken') + }) +}) + +describe('passwords', () => { + const pw = (algorithm: string): CryptoInventory => ({ + claims: ['passwords-hashed'], + ciphers: [{ algorithm, purpose: 'password', where: 'server/api/auth.ts', line: 30 }], + }) + + it('fails a fast hash — right for integrity, wrong for a password', () => { + const f = checkClaims(pw('SHA-256')).findings[0]! + expect(f.determination).toBe('fail') + expect(f.detail).toContain('catastrophic for passwords') + }) + + it('fails a reversible cipher, which is not hashing at all', () => { + expect(checkClaims(pw('AES')).findings[0]!.determination).toBe('fail') + }) + + it('accepts a real KDF', () => { + for (const kdf of ['bcrypt', 'argon2id', 'scrypt', 'PBKDF2']) { + expect(checkClaims(pw(kdf)).findings[0]!.determination).toBe('pass') + } + }) +}) + +describe('transport', () => { + it('fails a TLS floor below 1.2', () => { + const f = checkClaims({ + claims: ['encrypted-in-transit'], + transport: [{ minTlsVersion: '1.0', where: 'config/tls.yml' }], + }).findings[0]! + expect(f.determination).toBe('fail') + expect(f.detail).toContain('RFC 8996') + }) + + it('accepts a 1.2 floor and a 1.3 floor', () => { + for (const v of ['1.2', '1.3']) { + expect(checkClaims({ + claims: ['encrypted-in-transit'], + transport: [{ minTlsVersion: v, where: 'config/tls.yml' }], + }).findings[0]!.determination).toBe('pass') + } + }) + + it('reports an unpinned floor as not-assessed, not a pass', () => { + // Without a floor the answer is the runtime default, which is not a + // property of this system and can change under it. + const f = checkClaims({ + claims: ['encrypted-in-transit'], + transport: [{ where: 'config/tls.yml' }], + }).findings[0]! + expect(f.determination).toBe('not-assessed') + }) + + it('fails forward secrecy on a non-ephemeral suite', () => { + const f = checkClaims({ + claims: ['forward-secrecy'], + transport: [{ where: 'config/tls.yml', cipherSuites: ['TLS_RSA_WITH_AES_128_CBC_SHA'] }], + }).findings[0]! + expect(f.determination).toBe('fail') + expect(f.detail).toContain('retroactively decrypts') + }) + + it('accepts ephemeral suites', () => { + expect(checkClaims({ + claims: ['forward-secrecy'], + transport: [{ where: 't.yml', cipherSuites: ['TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256'] }], + }).findings[0]!.determination).toBe('pass') + }) +}) + +describe('conformance with the evidence-record standard', () => { + it('every conclusion carries a citation', () => { + expect(validateReport(checkClaims(notes))).toEqual([]) + }) + + it('an empty inventory is not-assessed, never clean', () => { + const r = checkClaims({ claims: [] }) + expect(overall(r)).toBe('not-assessed') + expect(formatClaims({ claims: [] })).not.toContain('✓') + }) +}) diff --git a/tsconfig.cjs.json b/tsconfig.cjs.json new file mode 100644 index 0000000..0d99093 --- /dev/null +++ b/tsconfig.cjs.json @@ -0,0 +1,9 @@ +{ + "extends": "./tsconfig.json", + "compilerOptions": { + "module": "CommonJS", + "moduleResolution": "Node", + "outDir": "dist-cjs", + "declaration": false + } +} diff --git a/tsconfig.json b/tsconfig.json new file mode 100644 index 0000000..9f56c30 --- /dev/null +++ b/tsconfig.json @@ -0,0 +1,8 @@ +{ + "compilerOptions": { + "target": "ES2022", "module": "ES2022", "moduleResolution": "bundler", + "declaration": true, "outDir": "dist", "rootDir": "src", + "strict": true, "skipLibCheck": true + }, + "include": ["src/**/*.ts"] +}