Complete the core zero-knowledge property: all user data (medications, appointments, profile names) is now client-encrypted via AES-GCM; the server stores and returns opaque ciphertext and can never decrypt it. Frontend crypto module (Web Crypto API, no deps): - crypto/keys.ts: double-PBKDF2 derivation from the password — an auth secret (base64, sent to the server as the 'password') and an encryption key (AES-GCM CryptoKey, kept in memory only, never transmitted). In-memory key store. - crypto/cipher.ts: AES-GCM encrypt/decrypt + JSON convenience wrappers. Auth split: login/register now derive the auth secret + enc key from the password BEFORE the API call. Only the auth secret (not the raw password) is sent to the server. The server's PBKDF2 stays as-is (it hashes whatever it receives) but can never derive the enc key. Backend — server treats all data blobs as opaque: - Medication: removed MedicationData + flat MedicationResponse; new MedicationResponse echoes metadata + encrypted_data blob. Create/update accept opaque blobs (whole-blob replace). MedicationData struct deleted. - Appointment: same opaque treatment; status moved to a top-level document field so it remains filterable without decryption. AppointmentData struct deleted. - Profile: name is now an opaque encrypted blob (name_data/name_iv). Auto-created profile starts empty; client sets it. - EncryptedFieldWire shared wire type across medication/appointment. Frontend — decrypt-on-read, encrypt-on-write: - Stores derive the enc key on login/register; decrypt wire responses into domain objects on load; encrypt domain data into blobs on create/update. - API client returns wire types (opaque blobs); components consume decrypted domain data (mostly unchanged — the store does the crypto). - Updated store tests for the ZK contract (derive a real key, mock wire responses). - 20 frontend tests pass, build clean. Backend: 21 tests pass (removed MedicationData/appointment-data deser tests; opaque-blob echo tests added), clippy 0 warnings. KNOWN LIMITATIONS (Phase 2): forgotten password = data loss (no recovery wrapping yet). Page reload requires re-entering the password to re-derive the enc key (in-memory only, by design). No data migration (no real data existed).
81 lines
2.1 KiB
TypeScript
81 lines
2.1 KiB
TypeScript
/**
|
|
* AES-GCM encrypt/decrypt over the Web Crypto API (no dependencies).
|
|
*
|
|
* Ciphertext and IV are returned as base64 strings so they map directly onto
|
|
* the backend's `EncryptedField { data, iv, auth_tag }` wire shape.
|
|
*/
|
|
|
|
const encoder = new TextEncoder();
|
|
const decoder = new TextDecoder();
|
|
const b64 = {
|
|
encode(bytes: Uint8Array): string {
|
|
let bin = '';
|
|
for (const b of bytes) bin += String.fromCharCode(b);
|
|
return btoa(bin);
|
|
},
|
|
decode(str: string): Uint8Array {
|
|
const bin = atob(str);
|
|
const bytes = new Uint8Array(bin.length);
|
|
for (let i = 0; i < bin.length; i++) bytes[i] = bin.charCodeAt(i);
|
|
return bytes;
|
|
},
|
|
};
|
|
|
|
/** Random 12-byte IV for AES-GCM. */
|
|
function randomIv(): Uint8Array {
|
|
return crypto.getRandomValues(new Uint8Array(12));
|
|
}
|
|
|
|
export interface CipherPayload {
|
|
/** base64 ciphertext */
|
|
data: string;
|
|
/** base64 12-byte IV */
|
|
iv: string;
|
|
}
|
|
|
|
/** Encrypt a UTF-8 string under the given AES-GCM key. */
|
|
export async function encrypt(
|
|
plaintext: string,
|
|
key: CryptoKey,
|
|
): Promise<CipherPayload> {
|
|
const iv = randomIv();
|
|
const ciphertext = await crypto.subtle.encrypt(
|
|
{ name: 'AES-GCM', iv: iv as BufferSource },
|
|
key,
|
|
encoder.encode(plaintext) as BufferSource,
|
|
);
|
|
return {
|
|
data: b64.encode(new Uint8Array(ciphertext)),
|
|
iv: b64.encode(iv),
|
|
};
|
|
}
|
|
|
|
/** Decrypt a base64 payload. Throws on tamper / wrong key. */
|
|
export async function decrypt(
|
|
payload: CipherPayload,
|
|
key: CryptoKey,
|
|
): Promise<string> {
|
|
const iv = b64.decode(payload.iv);
|
|
const plaintext = await crypto.subtle.decrypt(
|
|
{ name: 'AES-GCM', iv: iv as BufferSource },
|
|
key,
|
|
b64.decode(payload.data) as BufferSource,
|
|
);
|
|
return decoder.decode(plaintext);
|
|
}
|
|
|
|
/** Encrypt a JSON-serializable object. */
|
|
export async function encryptJson<T>(
|
|
obj: T,
|
|
key: CryptoKey,
|
|
): Promise<CipherPayload> {
|
|
return encrypt(JSON.stringify(obj), key);
|
|
}
|
|
|
|
/** Decrypt a payload and JSON.parse into T. Throws on tamper / wrong key / bad JSON. */
|
|
export async function decryptJson<T>(
|
|
payload: CipherPayload,
|
|
key: CryptoKey,
|
|
): Promise<T> {
|
|
return JSON.parse(await decrypt(payload, key)) as T;
|
|
}
|