Repository navigation
Expand file tree
/
Copy pathWebCryptHMAC.test.js
More file actions
95 lines (75 loc) · 3.33 KB
/
Copy pathWebCryptHMAC.test.js
File metadata and controls
95 lines (75 loc) · 3.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
// __tests__/WebCryptHMAC.test.js
import { WebCrypt } from "../src/WebCrypt.js";
describe("WebCrypt HMAC Tests", () => {
const wc = new WebCrypt();
const PASSWORD = "test-password-2025";
test("generateHmacKey() creates valid HMAC key", async () => {
const key = await wc.generateHmacKey(PASSWORD);
expect(key).toBeDefined();
expect(key.type).toBe("secret");
expect(key.algorithm.name).toBe("HMAC");
});
test("computeHmac() and verifyHmac() work correctly with string data", async () => {
const key = await wc.generateHmacKey(PASSWORD);
const data = "Test message for HMAC";
const hmac = await wc.computeHmac(data, key);
expect(typeof hmac).toBe("string");
expect(hmac).toBeTruthy();
const isValid = await wc.verifyHmac(data, hmac, key);
expect(isValid).toBe(true);
});
test("computeHmac() and verifyHmac() work correctly with ArrayBuffer data", async () => {
const key = await wc.generateHmacKey(PASSWORD);
const data = new TextEncoder().encode("Test message for HMAC as ArrayBuffer");
const hmac = await wc.computeHmac(data, key);
expect(typeof hmac).toBe("string");
expect(hmac).toBeTruthy();
const isValid = await wc.verifyHmac(data, hmac, key);
expect(isValid).toBe(true);
});
test("verifyHmac() rejects tampered data", async () => {
const key = await wc.generateHmacKey(PASSWORD);
const data = "Original message";
const tamperedData = "Tampered message";
const hmac = await wc.computeHmac(data, key);
const isValid = await wc.verifyHmac(tamperedData, hmac, key);
expect(isValid).toBe(false);
});
test("verifyHmac() rejects invalid HMAC format", async () => {
const key = await wc.generateHmacKey(PASSWORD);
const data = "Test message";
// Invalid base64 string
try {
const isValid = await wc.verifyHmac(data, "invalid-base64", key);
expect(isValid).toBe(false);
} catch (error) {
// This might throw an error when trying to decode invalid base64, which is also acceptable
expect(true).toBe(true); // Just make sure test passes
}
});
test("generateHmacKey() with different passwords creates different keys", async () => {
const key1 = await wc.generateHmacKey("password1");
const key2 = await wc.generateHmacKey("password2");
// Keys should be different
expect(key1).not.toBe(key2);
});
test("generateHmacKey() with same password produces consistent keys and verifies HMAC tags across instances", async () => {
const wc1 = new WebCrypt();
const wc2 = new WebCrypt();
const key1 = await wc1.generateHmacKey(PASSWORD);
const key2 = await wc2.generateHmacKey(PASSWORD);
const data = "Cross-instance authentication payload";
const tag1 = await wc1.computeHmac(data, key1);
// Key derived from same password in separate instance must verify tag
const isValid = await wc2.verifyHmac(data, tag1, key2);
expect(isValid).toBe(true);
});
test("generateHmacKey() supports custom salts", async () => {
const customSalt = "my-custom-salt-123";
const keyA = await wc.generateHmacKey(PASSWORD, "SHA-256", customSalt);
const keyB = await wc.generateHmacKey(PASSWORD, "SHA-256", customSalt);
const tagA = await wc.computeHmac("salt test", keyA);
const isValid = await wc.verifyHmac("salt test", tagA, keyB);
expect(isValid).toBe(true);
});
});