import { C as CipherSuite } from './ratchet-crypto-Bu7ZATDd.js'; /** * Configuration for {@link SimpleKex}. * * @remarks * **NOT FOR PRODUCTION** — see class-level warning. */ interface SimpleKexConfig { /** * Shared password known to all participants. * * For testing, any string works. For a real deployment you MUST migrate to a * proper key-agreement protocol instead. */ sharedSecret: string; /** * PBKDF2 salt. Defaults to a library-wide constant. * * Production users MUST supply a unique, randomly generated salt per room. * Reusing the default salt across rooms allows cross-room key correlation. */ salt?: Uint8Array; /** * PBKDF2 iteration count. Defaults to 600_000. * * Lower values speed up tests but reduce brute-force resistance. * Do not lower below 100_000 in any code that touches real user data. */ iterations?: number; /** * RFC 9605 §4.5 cipher suite to use for chain-key derivation. * * Determines the KDF hash (SHA-256 for suite 4, SHA-512 for suite 5) and the * chain-key / PBKDF2 output length. Defaults to suite 4 (`AES_128_GCM_SHA256`). * * All parties in a room MUST agree on the same suite. */ suite?: CipherSuite; /** * Explicit acknowledgement that SimpleKex is insecure for production use * (issue #51). When `false` (default), the constructor logs a one-time * console.warn reminding the caller that SimpleKex has no forward secrecy, * no membership consensus, and no revocation. Set to `true` to suppress the * warning — the caller acknowledges these limitations. * * Note: strict-FIPS mode (`enableStrictFips`) ALWAYS forbids SimpleKex * regardless of this flag. */ acknowledgeInsecure?: boolean; } /** * Reference shared-password KEX adapter. * * @remarks * **⚠ NOT FOR PRODUCTION ⚠** * * SimpleKex derives epoch chain keys from a shared password: * - Epoch 0 (suite 4): `PBKDF2-SHA-256(password, salt, iterations)` → 32-byte ChainKey * - Epoch 0 (suite 5): `PBKDF2-SHA-512(password, salt, iterations)` → 64-byte ChainKey * - Epoch N: `HKDF-(prevChainKey, info="sframe-simple-kex/epoch/{N}")` → suite-sized ChainKey * * This has **no forward secrecy**, **no membership consensus**, and **no * revocation**. It is suitable only for demos and local development. * Production deployments MUST plug in MLS or another real group-key-agreement * protocol through the library's KeyChannel interface. * * @example * ```ts * import { SimpleKex } from 'sframe-ratchet/kex-simple'; * import { deriveSenderKeys, sframeEncrypt, sframeDecrypt } from 'sframe-ratchet'; * * const kex = new SimpleKex({ sharedSecret: 'demo-password' }); * const chainKey = await kex.initialEpoch(); * * const aliceKey = await deriveSenderKeys(chainKey, 0, 0); * const bobKey = await deriveSenderKeys(chainKey, 0, 1); * * const frame = await sframeEncrypt(new TextEncoder().encode('hello'), aliceKey, 0n); * const opened = await sframeDecrypt(frame, ({ peerIndex }) => peerIndex === 0 ? aliceKey : null); * console.log(new TextDecoder().decode(opened)); // 'hello' * ``` */ declare class SimpleKex { private readonly _secret; private readonly _salt; private readonly _iterations; readonly suite: CipherSuite; constructor(config: SimpleKexConfig); /** * Derive the initial chain key (epoch 0) from the shared password via PBKDF2. * * Hash algorithm and output length are determined by the configured cipher suite: * - Suite 4 (`AES_128_GCM_SHA256`): PBKDF2-SHA-256, 32-byte output * - Suite 5 (`AES_256_GCM_SHA512`): PBKDF2-SHA-512, 64-byte output * * @returns Suite-sized chain key suitable for {@link deriveSenderKeys}. * * @remarks **NOT FOR PRODUCTION** — see class-level warning. */ initialEpoch(): Promise; /** * Derive the chain key for epoch `newEpoch` from the previous epoch's chain * key via HKDF using the suite's hash. * * Domain-separated by epoch number so each epoch yields distinct key * material even if the chain keys were somehow observed. * * @param prev Suite-sized chain key from epoch `newEpoch - 1`. * @param newEpoch The epoch number being advanced to (>= 1). * @returns Suite-sized chain key for the new epoch. * * @remarks **NOT FOR PRODUCTION** — see class-level warning. */ rotateEpoch(prev: Uint8Array, newEpoch: number): Uint8Array; } export { SimpleKex, type SimpleKexConfig };