{"_id":"@calaespi/crypto","_rev":"3-1d3b752e7584598521d64151a4aacb44","name":"@calaespi/crypto","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@calaespi/crypto","version":"0.1.0","keywords":["encryption","aes-256-gcm","password-manager","zero-knowledge","client-side","pbkdf2","password-generator","password-strength","webcrypto","lockdownkeys"],"author":{"name":"Calatayud Digital Solutions"},"license":"AGPL-3.0-or-later","_id":"@calaespi/crypto@0.1.0","maintainers":[{"name":"calaespi","email":"info@calatayud-digital-solutions.es"}],"homepage":"https://lockdownkeys.com","bugs":{"url":"https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto/issues"},"dist":{"shasum":"3e1ea3d1eb33f60b538ec295a1ccfd587b5a9881","tarball":"https://registry.npmjs.org/@calaespi/crypto/-/crypto-0.1.0.tgz","fileCount":23,"integrity":"sha512-v/bOFtix6dhHbj5uykZik3ZfhUJSX41e3IfCyRN/0/xJcerez64XZe7FicRQRdLXh6sOjD4Jyf0CbwUWUs5smQ==","signatures":[{"sig":"MEQCIFwZwp9I5qOJgslWzccrx++U5JtxKnRNZMzzsomXiekTAiAYi0hzaTqVshAjYgKpy03yfBpGVCEOWkIR6CrJk4dWmg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68507},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./strength":"./dist/strength.js","./generator":"./dist/generator.js","./encryption":"./dist/encryption.js"},"gitHead":"3ee06809da95f48f7ead2434396ea2a44adf87ab","scripts":{"lint":"eslint src test","test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"calaespi","email":"info@calatayud-digital-solutions.es"},"repository":{"url":"git+https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto.git","type":"git"},"_npmVersion":"10.9.4","description":"Client-side AES-256-GCM encryption, password generator and strength checker — the cryptographic core of Lock Down Keys.","directories":{},"_nodeVersion":"22.21.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","vitest":"^2.0.0","@eslint/js":"^10.0.1","typescript":"^5.5.0","@types/node":"^20.0.0","typescript-eslint":"^8.59.2"},"_npmOperationalInternal":{"tmp":"tmp/crypto_0.1.0_1777923761084_0.23361300080685865","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@calaespi/crypto","version":"0.1.1","description":"Client-side AES-256-GCM encryption, password generator and strength checker — the cryptographic core of Lock Down Keys.","type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./encryption":"./dist/encryption.js","./generator":"./dist/generator.js","./strength":"./dist/strength.js"},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest","lint":"eslint src test"},"keywords":["encryption","aes-256-gcm","password-manager","zero-knowledge","client-side","pbkdf2","password-generator","password-strength","webcrypto","lockdownkeys"],"author":{"name":"Calatayud Digital Solutions"},"license":"AGPL-3.0-or-later","repository":{"type":"git","url":"git+https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto.git"},"homepage":"https://lockdownkeys.com","bugs":{"url":"https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto/issues"},"devDependencies":{"@eslint/js":"^10.0.1","@types/node":"^20.0.0","eslint":"^10.3.0","typescript":"^5.5.0","typescript-eslint":"^8.59.2","vitest":"^2.0.0"},"engines":{"node":">=18"},"publishConfig":{"access":"public"},"gitHead":"c63dbeed4a95794fba1db5a16c0a59edb0e6a7db","_id":"@calaespi/crypto@0.1.1","_nodeVersion":"22.14.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-amoUaPinp1Vomr5CbJRgZSBd4bQfyymFaMVd11w0QoUB5I1uc4owf+aqxtsDtdDy/d6h8opZtlufL1RWsrpAKw==","shasum":"7b814e40ec3be372effe5dc7a362b942a38050f8","tarball":"https://registry.npmjs.org/@calaespi/crypto/-/crypto-0.1.1.tgz","fileCount":28,"unpackedSize":70666,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@calaespi%2fcrypto@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDEZ2x8lom1nGIgT5zQ655mG07YXB6wBV7SgZ7+MHEaSQIgJd8vrTaXUOGaMbYU4nhJu5GiA+lqw6XWTD9lZj7D5Pg="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6f918f5b-3aff-4b22-ba61-977777fb4769"}},"directories":{},"maintainers":[{"name":"calatayud-digital-solutions","email":"info@calatayud-digital-solutions.es"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/crypto_0.1.1_1777964925786_0.3775798028931443"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-04T19:42:41.006Z","modified":"2026-05-05T07:08:46.283Z","0.1.0":"2026-05-04T19:42:41.257Z","0.1.1":"2026-05-05T07:08:45.947Z"},"bugs":{"url":"https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto/issues"},"author":{"name":"Calatayud Digital Solutions"},"license":"AGPL-3.0-or-later","homepage":"https://lockdownkeys.com","keywords":["encryption","aes-256-gcm","password-manager","zero-knowledge","client-side","pbkdf2","password-generator","password-strength","webcrypto","lockdownkeys"],"repository":{"type":"git","url":"git+https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto.git"},"description":"Client-side AES-256-GCM encryption, password generator and strength checker — the cryptographic core of Lock Down Keys.","maintainers":[{"name":"calatayud-digital-solutions","email":"info@calatayud-digital-solutions.es"}],"readme":"# @calaespi/crypto\n\n> Client-side **AES-256-GCM** encryption, cryptographically-secure **password generator** and **strength checker** — the open-source cryptographic core of [Lock Down Keys](https://lockdownkeys.com).\n\n[![License: AGPL v3](https://img.shields.io/badge/License-AGPL_v3-blue.svg)](https://www.gnu.org/licenses/agpl-3.0)\n[![npm](https://img.shields.io/npm/v/@calaespi/crypto.svg)](https://www.npmjs.com/package/@calaespi/crypto)\n\n---\n\n## Why open source?\n\nLock Down Keys is a zero-knowledge password manager. **Trust requires verification**: anyone should be able to read, audit and reproduce the cryptography that protects user data. This package contains the exact primitives running in production:\n\n- 🔐 **AES-256-GCM** authenticated encryption with random 12-byte IV\n- 🔑 **PBKDF2-SHA-256**, 250 000 iterations, 16-byte salt — derived per record\n- 🎲 **`crypto.getRandomValues`** rejection-sampled to avoid modulo bias\n- 📐 **Shannon-entropy** strength estimator with common-pattern penalties\n\nThe server **never** sees plaintext, the master password, or the derived key.\n\n## Install\n\n```bash\nnpm install @calaespi/crypto\n```\n\nWorks in modern browsers, Node 18+, Deno, Bun, React Native (with WebCrypto polyfill).\n\n## Usage\n\n```ts\nimport { encrypt, decrypt, generatePassword, estimateStrength } from \"@calaespi/crypto\";\n\n// 1. Encrypt\nconst blob = await encrypt(\"my secret note\", \"correct horse battery staple\");\n// → \"Q2qf...base64...\" (salt|iv|ciphertext+tag)\n\n// 2. Decrypt\nconst plain = await decrypt(blob, \"correct horse battery staple\");\n\n// 3. Generate\nconst pw = generatePassword({ length: 24, symbols: true, excludeAmbiguous: true });\n\n// 4. Audit strength\nconst { label, entropyBits, crackTimeSeconds } = estimateStrength(pw);\n```\n\n## Cryptographic details\n\n| Parameter        | Value                          |\n|------------------|--------------------------------|\n| Cipher           | AES-256-GCM                    |\n| Key size         | 256 bits                       |\n| IV size          | 96 bits (random per encrypt)   |\n| Auth tag         | 128 bits (built into GCM)      |\n| KDF              | PBKDF2-HMAC-SHA-256            |\n| KDF iterations   | 250 000                        |\n| Salt size        | 128 bits (random per encrypt)  |\n| Payload format   | `base64(salt ‖ iv ‖ ciphertext+tag)` |\n| RNG              | `crypto.getRandomValues` (CSPRNG, rejection-sampled) |\n\n### What this protects against\n\n- **Server compromise**: ciphertext alone is useless without the user's master password.\n- **Tampering**: GCM authentication tag fails decryption on any modification.\n- **Rainbow tables**: per-record salt + 250k PBKDF2 iterations.\n- **Modulo bias** in the password generator (rejection sampling).\n\n### What this does NOT protect against\n\n- A compromised client device (keylogger, malicious extension).\n- A weak master password — entropy ultimately depends on the user.\n- Side-channel attacks on shared hardware.\n\n## Audit & contribute\n\nThis code is intentionally small (< 400 LOC) so it can be audited in an afternoon. PRs that improve security, performance, or test coverage are welcome.\n\n- 🐛 [Report a vulnerability](mailto:info@calatayud-digital-solutions.es) (responsible disclosure, please don't open public issues for sec bugs)\n- 💬 [Open an issue](https://github.com/Calatayud-Digital-Solutions/lockdownkeys-crypto/issues)\n\n## License\n\n**AGPL-3.0-or-later** — if you run a modified version as a network service, you must publish your changes. See [LICENSE](./LICENSE).\n\nFor commercial licenses without the AGPL network clause, contact info@calatayud-digital-solutions.es.\n\n---\n\nBuilt with ❤️ by [Calatayud Digital Solutions](https://lockdownkeys.com).\n","readmeFilename":"README.md"}