import { describe, expect, test } from "bun:test"; import { decrypt, encrypt } from "./crypto"; describe("crypto (AES-256-GCM)", () => { test("round-trips content with the correct password", async () => { const data = new TextEncoder().encode("hello zbin 🔐 multi-byte"); const enc = await encrypt(data, "correct horse battery staple"); const dec = await decrypt(enc, "correct horse battery staple"); expect(new TextDecoder().decode(dec)).toBe("hello zbin 🔐 multi-byte"); }); test("wire format is salt[16] | iv[12] | ciphertext+tag", async () => { const enc = await encrypt(new Uint8Array([1, 2, 3]), "pw"); // 16 (salt) + 12 (iv) + 3 (plaintext) + 16 (GCM tag) expect(enc.length).toBe(16 + 12 + 3 + 16); }); test("rejects a wrong password (authenticated)", async () => { const enc = await encrypt(new Uint8Array([1, 2, 3]), "right"); await expect(decrypt(enc, "wrong")).rejects.toThrow(); }); test("rejects tampered ciphertext", async () => { const enc = await encrypt(new Uint8Array([9, 9, 9]), "pw"); enc[enc.length - 1] ^= 0xff; // flip a tag byte await expect(decrypt(enc, "pw")).rejects.toThrow(); }); });