Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

@trust/webcrypto

Package Overview
Dependencies
Maintainers
7
Versions
19
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@trust/webcrypto

WebCrypto API for Node.js

  • 0.8.3
  • Source
  • npm
  • Socket score

Version published
Maintainers
7
Created
Source

W3C Web Cryptography API (@trust/webcrypto)

standard-readme compliant Build Status

W3C Web Cryptography API for Node.js

W3C's Web Cryptography API defines a standard interface for performing cryptographic operations in JavaScript, such as key generation, hashing, signing, and encryption. This package implements the API for Node.js, in order to support universal crypto-dependent code required by protocols such as JOSE and OpenID Connect.

Table of Contents

Security

TBD

Background

The purpose of this package is to enable development of universal JavaScript libraries that depend on the availability of cryptographic primitives in order to implement cryptographic protocols. The long term goal of the project is to encourage or provide a native, if not core Web Cryptography module.

Install

@trust/webcrypto requires recent versions of node and npm to run. For key generation operations, it also requires OpenSSL to be installed on the system.

$ npm install @trust/webcrypto --save

Usage

const crypto = require('@trust/webcrypto')

Develop

Install

$ git clone git@github.com:anvilresearch/webcrypto.git
$ cd webcrypto
$ npm install

Test

$ npm test

Supported Algorithms

Algorithm nameencryptdecryptsignverifydigestgenerateKeyderiveKeyderiveBitsimportKeyexportKeywrapKeyunwrapKey
RSASSA-PKCS1-v1_5
RSA-PSS_____
RSA-OAEP
ECDSA
EDDSA
ECDH_____
AES-CTR
AES-CBC
AES-GCM
AES-KW
HMAC
SHA-1
SHA-256
SHA-384
SHA-512
HKDF___
PBKDF2___

Key:

Implemented _ Currently not implemented Partially implemented, only certain paramaters supported.

Partial Support

Only the following paramaters are supported for the corresponding algorithm.

Algorithm nameSupported paramater
ECDSAK-256 (secp256k1), P-256, P-384, P-512
EDDSAed25519
AES-CTRsha-1

API

See W3C Web Cryptography API specification and diafygi's webcrypto-examples.

Contribute

Issues

  • Please file issues :)
  • When writing a bug report, include relevant details such as platform, version, relevant data, and stack traces
  • Ensure to check for existing issues before opening new ones
  • Read the documentation before asking questions
  • It is strongly recommended to open an issue before hacking and submitting a PR
  • We reserve the right to close an issue for excessive bikeshedding

Pull requests

Policy
  • We're not presently accepting unsolicited pull requests
  • Create an issue to discuss proposed features before submitting a pull request
  • Create an issue to propose changes of code style or introduce new tooling
  • Ensure your work is harmonious with the overall direction of the project
  • Ensure your work does not duplicate existing effort
  • Keep the scope compact; avoid PRs with more than one feature or fix
  • Code review with maintainers is required before any merging of pull requests
  • New code must respect the style guide and overall architecture of the project
  • Be prepared to defend your work
Style guide
  • ES6
  • Standard JavaScript
  • jsdocs
Code reviews
  • required before merging PRs
  • reviewers MUST run and test the code under review

Collaborating

Weekly project meeting
  • Thursdays from 1:00 PM to 2:00 Eastern US time at [TBD]
  • Join remotely with Google Hangouts
Pair programming
  • Required for new contributors
  • Work directly with one or more members of the core development team

Code of conduct

Contributors

MIT License

Copyright (c) 2016 Anvil Research, Inc.

Keywords

FAQs

Package last updated on 22 Dec 2017

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc