Socket
Socket
Sign inDemoInstall

webcrypto-shim

Package Overview
Dependencies
0
Maintainers
1
Versions
6
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

    webcrypto-shim

Web Cryptography API shim for legacy browsers


Version published
Weekly downloads
491K
increased by4.41%
Maintainers
1
Install size
427 kB
Created
Weekly downloads
 

Readme

Source

webcrypto-shim.js

Web Cryptography API shim for legacy browsers.

Quick start with Bower

Install the package

$ bower install webcrypto-shim

and link scripts into your html code

<script src="bower_components/promiz/promiz.js"></script>
<script src="bower_components/webcrypto-shim/webcrypto-shim.js"></script>

Now you can use webcrypto api through the window.crypto and window.crypto.subtle objects.

Note that IE11 lacks support of Promise-s and requires promiz.js to work properly. You can replace promiz.js with any Promise/A+-compatible implementation.

Supported browsers

The library is targeted to fix these browsers having prefixed and buggy webcrypto api implementations:

  • Internet Explorer 11, Mobile Internet Explorer 11,
  • Safari 8 - 10, iOS Safari 8 - 10.

These browsers have unprefixed and conforming webcrypto api implementations, so no need in shim:

  • Chrome 43+, Chrome for Android 44+,
  • Opera 24+,
  • Firefox 34+,
  • Edge 12+.
  • Safari 11+.

Crossbrowser support of algorithms & operations

  • SHA-256, SHA-384: digest

  • HMAC: sign, verify, generateKey, importKey, exportKey

    • with hash SHA-1, SHA-256, SHA-384
  • AES-CBC: encrypt, decrypt, generateKey, importKey, exportKey, wrapKey, unwrapKey

    • TODO tests
  • AES-KW: generateKey, importKey, exportKey, wrapKey, unwrapKey

    • TODO tests
  • RSASSA-PKCS1-v1_5: sign, verify, generateKey, importKey, exportKey

    • with hash SHA-256, SHA-384
    • and modulusLength at least 2048 bits
  • RSA-OAEP: encrypt, decrypt, generateKey, importKey, exportKey, wrapKey, unwrapKey

    • with hash SHA-1
    • and modulusLength at least 2048 bits
    • FIXME only "jwk" format for wrapped/unwrapped keys

Known limitations

deriveKey, deriveBits are not supported under IE11 and Safari since there is no implementation of any algorithm providing key derivation.

Under IE11 exception is thrown in case of empty input data since IE11 silently discards empty data and leaves returned Promise object never resolved nor rejected.

Other browsers support

See https://vibornoff.github.io/webcrypto-examples/index.html

Sponsored by

BrowserStack — automated & manual crossbrowser testing solution.

Keywords

FAQs

Last updated on 23 Mar 2021

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc