This commit is contained in:
2026-07-12 11:36:01 +02:00
parent 1f180a2e53
commit 062054f450
46 changed files with 976 additions and 1691 deletions
+2 -2
View File
@@ -3,7 +3,7 @@
## Requirements
- [mise](https://mise.jdx.dev) — manages pnpm, rust, node (see `mise.toml`)
- docker or [colima](https://github.com/abiosoft/colima) (for redis)
- docker or [colima](https://github.com/abiosoft/colima) (for cache)
## Setup
@@ -18,7 +18,7 @@ pnpm install
pnpm run dev
```
Make sure docker/colima is running. This starts redis, the rust backend, the web client, and the CLI. The app is at [localhost:3000](http://localhost:3000).
Make sure docker/colima is running. This starts the cache (valkey/redis), the rust backend, the web client, and the CLI. The app is at [localhost:3000](http://localhost:3000).
## Tests
+1 -1
View File
@@ -25,6 +25,6 @@ RUN apk add --no-cache curl libgcc
COPY --from=backend /tmp/target/release/cryptgeon .
COPY --from=client /tmp/packages/frontend/build ./frontend
ENV FRONTEND_PATH="./frontend"
ENV REDIS="redis://redis/"
ENV CACHE="redis://cache/"
EXPOSE 8000
ENTRYPOINT [ "/app/cryptgeon" ]
+9 -9
View File
@@ -63,7 +63,7 @@ client side with the <code>key</code> and then sent to the server. data is store
never persisted to disk. the server never sees the encryption key and cannot decrypt the contents
of the notes even if it tried to.
> View counts are guaranteed with one running instance of cryptgeon. Multiple instances connected to the same Redis instance can run into race conditions, where a note might be retrieved more than the view count allows.
> View counts are guaranteed with one running instance of cryptgeon. Multiple instances connected to the same cache instance can run into race conditions, where a note might be retrieved more than the view count allows.
## Screenshot
@@ -73,14 +73,14 @@ of the notes even if it tried to.
| Variable | Default | Description |
| ----------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `REDIS` | `redis://redis/` | Redis URL to connect to. [According to format](https://docs.rs/redis/latest/redis/#connection-parameters) |
| `CACHE` | `redis://cache/` | Cache URL (valkey or redis) to connect to. [According to format](https://docs.rs/redis/latest/redis/#connection-parameters) |
| `SIZE_LIMIT` | `1 KiB` | Max size for body. Accepted values according to [byte-unit](https://docs.rs/byte-unit/). <br> `512 MiB` is the maximum allowed. <br> The frontend will show that number including the ~35% encoding overhead. |
| `MAX_VIEWS` | `100` | Maximal number of views. |
| `MAX_EXPIRATION` | `360` | Maximal expiration in minutes. |
| `ALLOW_ADVANCED` | `true` | Allow custom configuration. If set to `false` all notes will be one view only. |
| `ALLOW_FILES` | `true` | Allow uploading files. If set to `false`, users will only be allowed to create text notes. |
| `ID_LENGTH` | `32` | Set the size of the note `id` in bytes. By default this is `32` bytes. This is useful for reducing link size. _This setting does not affect encryption strength_. |
| `REDIS_PREFIX` | `""` | Optional prefix for all Redis keys. Useful when sharing a Redis instance with other apps via ACL namespaces. |
| `CACHE_PREFIX` | `""` | Optional prefix for all cache keys. Useful when sharing a cache instance with other apps via ACL namespaces. |
| `VERBOSITY` | `warn` | Verbosity level for the backend. [Possible values](https://docs.rs/env_logger/latest/env_logger/#enabling-logging) are: `error`, `warn`, `info`, `debug`, `trace` |
| `THEME_IMAGE` | `""` | Custom image for replacing the logo. Must be publicly reachable |
| `THEME_TEXT` | `""` | Custom text for replacing the description below the logo |
@@ -107,12 +107,12 @@ Docker is the easiest way. There is the [official image here](https://hub.docker
version: "3.8"
services:
redis:
image: redis:7-alpine
cache:
image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: redis-server --save "" --appendonly no
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://redis.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
@@ -121,7 +121,7 @@ services:
app:
image: cupcakearmy/cryptgeon:latest
depends_on:
- redis
- cache
environment:
# Size limit for a single note.
SIZE_LIMIT: 4 MiB
@@ -130,7 +130,7 @@ services:
# Optional health checks
# healthcheck:
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/api/live/"]
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
# interval: 1m
# timeout: 3s
# retries: 2
+3 -3
View File
@@ -2,7 +2,7 @@
# For a production file see: README.md
services:
redis:
cache:
image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
@@ -19,13 +19,13 @@ services:
build: .
env_file: .env.dev
depends_on:
- redis
- cache
restart: unless-stopped
ports:
- 3000:8000
healthcheck:
test: ['CMD', 'curl', '--fail', 'http://127.0.0.1:8000/api/live/']
test: ['CMD', 'curl', '--fail', 'http://127.0.0.1:8000/healthz']
interval: 1m
timeout: 3s
retries: 2
+3 -3
View File
@@ -1,5 +1,5 @@
services:
redis:
cache:
image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
@@ -13,7 +13,7 @@ services:
app:
image: cupcakearmy/cryptgeon:latest
depends_on:
- redis
- cache
environment:
# Size limit for a single note.
SIZE_LIMIT: 4 MiB
@@ -22,7 +22,7 @@ services:
# Optional health checks
# healthcheck:
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/api/live/"]
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
# interval: 1m
# timeout: 3s
# retries: 2
+9 -8
View File
@@ -1,22 +1,23 @@
{
"scripts": {
"dev:docker": "docker compose -f docker-compose.dev.yaml up redis",
"dev:docker": "docker compose -f docker-compose.dev.yaml up cache",
"dev:packages": "pnpm --parallel run dev",
"dev": "run-p dev:*",
"dev": "pnpm --parallel run dev:*",
"docker:up": "docker compose -f docker-compose.dev.yaml up",
"docker:build": "docker compose -f docker-compose.dev.yaml build",
"test": "playwright test --project=chrome --project=firefox --project=safari",
"test:local": "playwright test --project=chrome",
"test:server": "run-s docker:up",
"test:server": "docker compose -f docker-compose.dev.yaml up",
"test:dl-browsers": "playwright install",
"test:prepare": "run-p test:dl-browsers build docker:build",
"test:prepare": "pnpm --parallel run test:dl-browsers build docker:build",
"build": "pnpm run --recursive --filter=!@cryptgeon/backend build"
},
"devDependencies": {
"@playwright/test": "^1.60.0",
"@types/node": "^24.12.4",
"npm-run-all": "^4.1.5",
"shelljs": "^0.8.5"
"@types/node": "^24.12.4"
},
"packageManager": "pnpm@11.5.0"
"packageManager": "pnpm@11.5.0",
"engines": {
"node": ">=22"
}
}
+21 -1
View File
@@ -252,7 +252,7 @@ dependencies = [
[[package]]
name = "cryptgeon"
version = "2.9.3"
version = "3.0.0"
dependencies = [
"axum",
"bs62",
@@ -261,6 +261,7 @@ dependencies = [
"lazy_static",
"redis",
"ring",
"rmp-serde",
"serde",
"serde_json",
"tokio",
@@ -1004,6 +1005,25 @@ dependencies = [
"windows-sys 0.52.0",
]
[[package]]
name = "rmp"
version = "0.8.15"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4ba8be72d372b2c9b35542551678538b562e7cf86c3315773cae48dfbfe7790c"
dependencies = [
"num-traits",
]
[[package]]
name = "rmp-serde"
version = "1.3.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "72f81bee8c8ef9b577d1681a70ebbc962c232461e397b22c208c43c04b67a155"
dependencies = [
"rmp",
"serde",
]
[[package]]
name = "rustix"
version = "1.1.4"
+2 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "cryptgeon"
version = "2.9.3"
version = "3.0.0"
authors = ["cupcakearmy <hi@nicco.io>"]
edition = "2024"
rust-version = "1.95"
@@ -20,6 +20,7 @@ redis = { version = "1", features = ["tls-native-tls"] }
# Utility
serde_json = "1"
rmp-serde = "1"
lazy_static = "1"
ring = "0.17"
bs62 = "0.1"
+5 -1
View File
@@ -34,7 +34,7 @@ pub static ref ID_LENGTH: u32 = std::env::var("ID_LENGTH")
.unwrap_or("32".to_string())
.parse()
.unwrap();
pub static ref REDIS_PREFIX: String = std::env::var("REDIS_PREFIX")
pub static ref CACHE_PREFIX: String = std::env::var("CACHE_PREFIX")
.unwrap_or("".to_string())
.parse()
.unwrap();
@@ -50,6 +50,10 @@ pub static ref IMPRINT_HTML: String = std::env::var("IMPRINT_HTML")
.unwrap_or("".to_string())
.parse()
.unwrap();
pub static ref EXTRA_SIZE_LIMIT: usize = std::env::var("EXTRA_SIZE_LIMIT")
.unwrap_or("512".to_string())
.parse()
.unwrap();
}
// THEME
+1 -1
View File
@@ -2,7 +2,7 @@ use crate::store;
use axum::http::StatusCode;
pub async fn report_health() -> (StatusCode,) {
if store::can_reach_redis() {
if store::can_reach_cache() {
return (StatusCode::OK,);
} else {
return (StatusCode::SERVICE_UNAVAILABLE,);
-10
View File
@@ -1,10 +0,0 @@
use std::collections::HashMap;
use std::sync::Arc;
use tokio::sync::Mutex;
#[derive(Clone)]
pub struct SharedState {
pub locks: LockMap,
}
pub type LockMap = Arc<Mutex<HashMap<String, Arc<Mutex<()>>>>>;
+10 -20
View File
@@ -1,13 +1,9 @@
use std::{collections::HashMap, sync::Arc};
use axum::{
Router, ServiceExt,
extract::{DefaultBodyLimit, Request},
routing::{delete, get, post},
};
use dotenv::dotenv;
use lock::SharedState;
use tokio::sync::Mutex;
use tower::Layer;
use tower_http::{
compression::CompressionLayer,
@@ -21,7 +17,6 @@ extern crate lazy_static;
mod config;
mod csp;
mod health;
mod lock;
mod note;
mod status;
mod store;
@@ -30,34 +25,30 @@ mod store;
async fn main() {
dotenv().ok();
let shared_state = SharedState {
locks: Arc::new(Mutex::new(HashMap::new())),
};
if !store::can_reach_redis() {
println!("cannot reach redis");
panic!("cannot reach redis");
if !store::can_reach_cache() {
println!("cannot reach cache");
panic!("cannot reach cache");
}
let notes_routes = Router::new()
.route("/", post(note::create))
.route("/{id}", delete(note::delete))
.route("/{id}", delete(note::view))
.route("/{id}", get(note::preview));
let health_routes = Router::new().route("/live", get(health::report_health));
let health_routes = Router::new().route("/healthz", get(health::report_health));
let status_routes = Router::new().route("/status", get(status::get_status));
let api_routes = Router::new()
let v3_routes = Router::new()
.nest("/notes", notes_routes)
.merge(health_routes)
.merge(status_routes);
let api_routes = Router::new().nest("/v3", v3_routes);
let index = format!("{}{}", config::FRONTEND_PATH.to_string(), "/index.html");
let serve_dir =
ServeDir::new(config::FRONTEND_PATH.to_string()).not_found_service(ServeFile::new(index));
let app = Router::new()
.nest("/api", api_routes)
.merge(health_routes)
.fallback_service(serve_dir)
// Disabled for now, as svelte inlines scripts
// .layer(middleware::from_fn(csp::add_csp_header))
.layer(DefaultBodyLimit::max(*config::LIMIT))
.layer(
CompressionLayer::new()
@@ -65,8 +56,7 @@ async fn main() {
.deflate(true)
.gzip(true)
.zstd(true),
)
.with_state(shared_state);
);
let app = NormalizePathLayer::trim_trailing_slash().layer(app);
+24 -11
View File
@@ -5,22 +5,35 @@ use serde::{Deserialize, Serialize};
use crate::config;
#[derive(Serialize, Deserialize, Clone)]
pub struct Note {
pub meta: String,
pub contents: String,
pub struct NoteMeta {
#[serde(skip_serializing_if = "Option::is_none")]
pub views: Option<u32>,
#[serde(skip_serializing_if = "Option::is_none")]
pub expiration: Option<u32>,
#[serde(default)]
pub extra: Vec<u8>,
}
#[derive(Serialize)]
pub struct NoteInfo {
pub meta: String,
#[derive(Serialize, Deserialize, Clone)]
pub struct CreateRequest {
pub meta: NoteMeta,
pub data: Vec<u8>,
}
#[derive(Serialize)]
pub struct NotePublic {
pub meta: String,
pub contents: String,
#[derive(Serialize, Deserialize)]
pub struct CreateResponse {
pub id: String,
}
#[derive(Serialize, Deserialize)]
pub struct MetaResponse {
pub meta: NoteMeta,
}
#[derive(Serialize, Deserialize)]
pub struct NoteResponse {
pub meta: NoteMeta,
pub data: Vec<u8>,
}
pub fn generate_id() -> String {
@@ -32,5 +45,5 @@ pub fn generate_id() -> String {
let _ = sr.fill(&mut id);
result.push_str(&bs62::encode_data(&id));
}
return result;
result
}
+99 -111
View File
@@ -2,155 +2,143 @@ use axum::{
extract::Path,
http::StatusCode,
response::{IntoResponse, Response},
Json,
body::Bytes,
};
use serde::{Deserialize, Serialize};
use std::{sync::Arc, time::SystemTime};
use tokio::sync::Mutex;
use serde::Deserialize;
use std::time::SystemTime;
use crate::note::{generate_id, Note, NoteInfo};
use crate::note::{CreateRequest, generate_id};
use crate::store;
use crate::{config, lock::SharedState};
use crate::config;
use super::NotePublic;
use super::{CreateResponse, MetaResponse, NoteResponse, NoteMeta};
pub fn now() -> u32 {
pub fn now() -> u64 {
SystemTime::now()
.duration_since(SystemTime::UNIX_EPOCH)
.unwrap()
.as_secs() as u32
.as_secs()
}
#[derive(Deserialize)]
pub struct OneNoteParams {
pub struct NoteParams {
id: String,
}
pub async fn preview(Path(OneNoteParams { id }): Path<OneNoteParams>) -> Response {
let note = store::get(&id);
pub async fn create(body: Bytes) -> Response {
let req: CreateRequest = match rmp_serde::from_slice(&body) {
Ok(r) => r,
Err(_) => return (StatusCode::BAD_REQUEST, "Invalid msgpack").into_response(),
};
match note {
Ok(Some(n)) => (StatusCode::OK, Json(NoteInfo { meta: n.meta })).into_response(),
Ok(None) => (StatusCode::NOT_FOUND).into_response(),
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
if req.meta.views.is_none() && req.meta.expiration.is_none() {
return (StatusCode::BAD_REQUEST, "At least views or expiration must be set").into_response();
}
}
#[derive(Serialize, Deserialize)]
struct CreateResponse {
id: String,
}
pub async fn create(Json(mut n): Json<Note>) -> Response {
// let mut n = note.into_inner();
let id = generate_id();
// let bad_req = HttpResponse::BadRequest().finish();
if n.views == None && n.expiration == None {
return (
StatusCode::BAD_REQUEST,
"At least views or expiration must be set",
)
.into_response();
if req.meta.extra.len() > *config::EXTRA_SIZE_LIMIT {
return (StatusCode::BAD_REQUEST, "Extra data too large").into_response();
}
let mut meta = req.meta;
if !*config::ALLOW_ADVANCED {
n.views = Some(1);
n.expiration = None;
meta.views = Some(1);
meta.expiration = None;
}
match n.views {
match meta.views {
Some(v) => {
if v > *config::MAX_VIEWS || v < 1 {
return (StatusCode::BAD_REQUEST, "Invalid views").into_response();
}
n.expiration = None; // views overrides expiration
}
_ => {}
None => {}
}
match n.expiration {
let expiration_ts = match meta.expiration {
Some(e) => {
if e > *config::MAX_EXPIRATION || e < 1 {
return (StatusCode::BAD_REQUEST, "Invalid expiration").into_response();
}
let expiration = now() + (e * 60);
n.expiration = Some(expiration);
Some(now() + (e as u64 * 60))
}
None => None,
};
let id = generate_id();
let views = meta.views.map(|v| v as i64);
match store::set(&id, &req.data, views, expiration_ts, &meta.extra) {
Ok(_) => {
let resp = CreateResponse { id };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
}
_ => {}
}
match store::set(&id.clone(), &n.clone()) {
Ok(_) => (StatusCode::OK, Json(CreateResponse { id })).into_response(),
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
}
}
pub async fn delete(
Path(OneNoteParams { id }): Path<OneNoteParams>,
state: axum::extract::State<SharedState>,
) -> Response {
let mut locks_map = state.locks.lock().await;
let lock = locks_map
.entry(id.clone())
.or_insert_with(|| Arc::new(Mutex::new(())))
.clone();
drop(locks_map);
let _guard = lock.lock().await;
let note = store::get(&id);
match note {
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
pub async fn preview(Path(NoteParams { id }): Path<NoteParams>) -> Response {
match store::get_meta(&id) {
Ok(Some((views, expiration, extra))) => {
let meta = NoteMeta {
views: views.map(|v| v as u32),
expiration: expiration.map(|e| e as u32),
extra,
};
let resp = MetaResponse { meta };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
}
Ok(None) => (StatusCode::NOT_FOUND).into_response(),
Ok(Some(note)) => {
let mut changed = note.clone();
if changed.views == None && changed.expiration == None {
return (StatusCode::BAD_REQUEST).into_response();
}
match changed.views {
Some(v) => {
changed.views = Some(v - 1);
let id = id.clone();
if v <= 1 {
match store::del(&id) {
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response();
}
_ => {}
}
} else {
match store::set(&id, &changed.clone()) {
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response();
}
_ => {}
}
}
}
_ => {}
}
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
}
}
let n = now();
match changed.expiration {
Some(e) => {
if e < n {
match store::del(&id.clone()) {
Ok(_) => return (StatusCode::BAD_REQUEST).into_response(),
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response()
}
}
}
}
_ => {}
}
pub async fn view(Path(NoteParams { id }): Path<NoteParams>) -> Response {
let (views, expiration, extra) = match store::get_meta(&id) {
Ok(Some(v)) => v,
_ => return (StatusCode::NOT_FOUND).into_response(),
};
return (
StatusCode::OK,
Json(NotePublic {
contents: changed.contents,
meta: changed.meta,
}),
)
.into_response();
let has_views = views.is_some();
if has_views {
let remaining = match store::decrement_views(&id) {
Ok(r) => r,
Err(_) => return (StatusCode::NOT_FOUND).into_response(),
};
let data = match store::get_data(&id) {
Ok(Some(d)) => d,
_ => return (StatusCode::NOT_FOUND).into_response(),
};
if remaining <= 0 {
let _ = store::del(&id);
}
let meta = NoteMeta {
views: Some(if remaining > 0 { remaining as u32 } else { 0 }),
expiration: expiration.map(|e| e as u32),
extra,
};
let resp = NoteResponse { meta, data };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
} else {
let data = match store::get_data(&id) {
Ok(Some(d)) => d,
_ => return (StatusCode::NOT_FOUND).into_response(),
};
let meta = NoteMeta {
views: None,
expiration: expiration.map(|e| e as u32),
extra,
};
let resp = NoteResponse { meta, data };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
}
}
+65 -46
View File
@@ -1,71 +1,90 @@
use redis;
use redis::Commands;
use crate::config;
use crate::note::now;
use crate::note::Note;
lazy_static! {
static ref REDIS_CLIENT: String = std::env::var("REDIS")
static ref CACHE_URL: String = std::env::var("CACHE")
.unwrap_or("redis://127.0.0.1/".to_string())
.parse()
.unwrap();
}
fn prefixed(id: &String) -> String {
format!("{}{}", config::REDIS_PREFIX.as_str(), id)
fn prefixed(id: &str) -> String {
format!("{}{}", config::CACHE_PREFIX.as_str(), id)
}
fn get_connection() -> Result<redis::Connection, &'static str> {
fn conn() -> Result<redis::Connection, &'static str> {
let client =
redis::Client::open(REDIS_CLIENT.to_string()).map_err(|_| "Unable to connect to redis")?;
client
.get_connection()
.map_err(|_| "Unable to connect to redis")
redis::Client::open(CACHE_URL.to_string()).map_err(|_| "Unable to connect to cache")?;
client.get_connection().map_err(|_| "Unable to connect to cache")
}
pub fn can_reach_redis() -> bool {
let conn = get_connection();
return match conn {
Ok(_) => true,
Err(_) => false,
};
pub fn can_reach_cache() -> bool {
conn().is_ok()
}
pub fn set(id: &String, note: &Note) -> Result<(), &'static str> {
pub fn set(id: &str, data: &[u8], views: Option<i64>, expiration: Option<u64>, extra: &[u8]) -> Result<(), &'static str> {
let key = prefixed(id);
let serialized = serde_json::to_string(&note.clone()).unwrap();
let mut conn = get_connection()?;
let mut c = conn()?;
conn.set::<_, _, ()>(key.as_str(), serialized)
.map_err(|_| "Unable to set note in redis")?;
match note.expiration {
Some(e) => {
let seconds = e - now();
conn.expire::<_, ()>(key.as_str(), seconds as i64)
.map_err(|_| "Unable to set expiration on note")?
}
None => {}
};
Ok(())
}
c.hset::<_, _, _, ()>(&key, "data", data).map_err(|_| "Unable to set note")?;
c.hset::<_, _, _, ()>(&key, "extra", extra).map_err(|_| "Unable to set note")?;
pub fn get(id: &String) -> Result<Option<Note>, &'static str> {
let key = prefixed(id);
let mut conn = get_connection()?;
let value: Option<String> = conn.get(key.as_str()).map_err(|_| "Could not load note in redis")?;
match value {
None => return Ok(None),
Some(s) => {
let deserialize: Note = serde_json::from_str(&s).unwrap();
return Ok(Some(deserialize));
}
if let Some(v) = views {
c.hset::<_, _, _, ()>(&key, "views", v).map_err(|_| "Unable to set note")?;
}
if let Some(e) = expiration {
let now = std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.unwrap()
.as_secs();
let ttl = e.saturating_sub(now);
c.expire::<_, ()>(&key, ttl as i64).map_err(|_| "Unable to set expiration")?;
}
}
pub fn del(id: &String) -> Result<(), &'static str> {
Ok(())
}
pub fn get_meta(id: &str) -> Result<Option<(Option<i64>, Option<u64>, Vec<u8>)>, &'static str> {
let key = prefixed(id);
let mut conn = get_connection()?;
conn.del::<_, ()>(key.as_str()).map_err(|_| "Unable to delete note in redis")?;
let mut c = conn()?;
let exists: bool = c.exists::<_, bool>(&key).map_err(|_| "Cache error")?;
if !exists {
return Ok(None);
}
let views: Option<i64> = c.hget::<_, _, Option<i64>>(&key, "views").map_err(|_| "Cache error")?;
let expiration: Option<u64> = c.hget::<_, _, Option<u64>>(&key, "expiration").map_err(|_| "Cache error")?;
let extra: Vec<u8> = c.hget::<_, _, Vec<u8>>(&key, "extra").unwrap_or_default();
Ok(Some((views, expiration, extra)))
}
pub fn get_data(id: &str) -> Result<Option<Vec<u8>>, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let data: Option<Vec<u8>> = c.hget::<_, _, Option<Vec<u8>>>(&key, "data").map_err(|_| "Cache error")?;
Ok(data)
}
pub fn has_views(id: &str) -> Result<bool, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let has: bool = c.hexists::<_, _, bool>(&key, "views").map_err(|_| "Cache error")?;
Ok(has)
}
pub fn decrement_views(id: &str) -> Result<i64, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let result: i64 = c.hincr::<_, _, _, i64>(&key, "views", -1).map_err(|_| "Cache error")?;
Ok(result)
}
pub fn del(id: &str) -> Result<(), &'static str> {
let key = prefixed(id);
let mut c = conn()?;
c.del::<_, ()>(&key).map_err(|_| "Unable to delete note")?;
Ok(())
}
+4 -3
View File
@@ -4,12 +4,13 @@ import pkg from './package.json' with { type: 'json' }
const watch = process.argv.slice(2)[0] === '--watch'
await build({
entry: ['src/index.ts', 'src/cli.ts', 'src/shared/shared.ts'],
entry: ['src/index.ts', 'src/cli.ts'],
dts: true,
minify: true,
format: ['esm', 'cjs'],
target: 'es2020',
format: ['esm'],
target: 'es2022',
clean: true,
noExternal: ['@cryptgeon/shared'],
define: { VERSION: `"${pkg.version}"` },
watch,
})
+14 -17
View File
@@ -1,6 +1,6 @@
{
"name": "cryptgeon",
"version": "2.9.3",
"version": "3.0.0",
"homepage": "https://github.com/cupcakearmy/cryptgeon",
"repository": {
"type": "git",
@@ -9,39 +9,36 @@
},
"type": "module",
"exports": {
".": "./dist/index.js",
"./shared": {
"import": "./dist/shared/shared.js",
"types": "./dist/shared/shared.d.ts"
}
".": "./dist/index.js"
},
"types": "./dist/index.d.ts",
"bin": {
"cryptgeon": "./dist/cli.cjs"
"cryptgeon": "./dist/cli.js"
},
"files": [
"dist"
],
"scripts": {
"bin": "run-s build package",
"build": "tsc && node build.js",
"build": "node build.js",
"dev": "node build.js --watch",
"prepublishOnly": "run-s build"
},
"devDependencies": {
"dependencies": {
"@cryptgeon/shared": "workspace:*",
"@msgpack/msgpack": "^3.1.3",
"@commander-js/extra-typings": "^12.1.0",
"@types/inquirer": "^9.0.9",
"@types/mime": "^4.0.0",
"@types/node": "^20.19.41",
"commander": "^12.1.0",
"inquirer": "^9.3.8",
"mime": "^4.1.0",
"occulto": "^2.0.6",
"pretty-bytes": "^6.1.1",
"pretty-bytes": "^6.1.1"
},
"devDependencies": {
"@types/inquirer": "^9.0.9",
"@types/node": "^22.15.3",
"commander": "^12.1.0",
"tsup": "^8.5.1",
"typescript": "^5.9.3"
},
"engines": {
"node": ">=18"
"node": ">=22"
}
}
+32 -45
View File
@@ -1,51 +1,42 @@
import inquirer from 'inquirer'
import { access, constants, writeFile } from 'node:fs/promises'
import { basename, resolve } from 'node:path'
import { AES, Hex } from 'occulto'
import { decode } from '@msgpack/msgpack'
import pretty from 'pretty-bytes'
import { Adapters } from '../shared/adapters.js'
import { API } from '../shared/api.js'
import { decrypt, deriveKey, setServer, getServer, info, get } from '@cryptgeon/shared'
export async function download(url: URL, all: boolean, suggestedPassword?: string) {
API.setOptions({ server: url.origin })
setServer(url.origin)
const id = url.pathname.split('/')[2]
const preview = await API.info(id).catch(() => {
throw new Error('Note does not exist or is expired')
})
const meta = await info(id)
if (!meta) throw new Error('Note does not exist or is expired')
// Password
let password: string
const derivation = preview?.meta.derivation
if (derivation) {
let key: Uint8Array
if (meta.extra && meta.extra.length > 0) {
if (suggestedPassword) {
password = suggestedPassword
const derivation = decode(meta.extra) as any
key = deriveKey(suggestedPassword, new Uint8Array(derivation.salt))
} else {
const response = await inquirer.prompt([
{
type: 'password',
message: 'Note password',
name: 'password',
},
{ type: 'password', message: 'Note password', name: 'password' },
])
password = response.password
const derivation = decode(meta.extra) as any
key = deriveKey(response.password, new Uint8Array(derivation.salt))
}
} else {
password = url.hash.slice(1)
const hex = url.hash.slice(1)
key = new Uint8Array(Buffer.from(hex, 'hex'))
}
const key = derivation ? (await AES.derive(password, derivation))[0] : Hex.decode(password)
const note = await API.get(id)
const note = await get(id)
if (!note) throw new Error('Could not load note')
const couldNotDecrypt = new Error('Could not decrypt note. Probably an invalid password')
switch (note.meta.type) {
case 'file':
const files = await Adapters.Files.decrypt(note.contents, key).catch(() => {
throw couldNotDecrypt
})
if (!files) {
throw new Error('No files found in note')
}
const decrypted = decrypt(note.data, key)
const content = decode(decrypted) as any
switch (content.type) {
case 'files':
const files: { name: string; data: Uint8Array }[] = content.data
let selected: typeof files
if (all) {
selected = files
@@ -55,36 +46,32 @@ export async function download(url: URL, all: boolean, suggestedPassword?: strin
type: 'checkbox',
message: 'What files should be saved?',
name: 'names',
choices: files.map((file) => ({
value: file.name,
name: `${file.name} - ${file.type} - ${pretty(file.size, { binary: true })}`,
choices: files.map((f) => ({
value: f.name,
name: `${f.name} - ${pretty(f.data.length, { binary: true })}`,
checked: true,
})),
},
])
selected = files.filter((file) => names.includes(file.name))
selected = files.filter((f) => names.includes(f.name))
}
if (!selected.length) throw new Error('No files selected')
await Promise.all(
selected.map(async (file) => {
let filename = resolve(file.name)
selected.map(async (f) => {
let filename = resolve(f.name)
try {
// If exists -> prepend timestamp to not overwrite the current file
await access(filename, constants.R_OK)
filename = resolve(`${Date.now()}-${file.name}`)
filename = resolve(`${Date.now()}-${f.name}`)
} catch {}
await writeFile(filename, file.contents)
await writeFile(filename, f.data)
console.log(`Saved: ${basename(filename)}`)
})
)
break
case 'text':
const plaintext = await Adapters.Text.decrypt(note.contents, key).catch(() => {
throw couldNotDecrypt
})
console.log(plaintext)
console.log(content.data)
break
default:
throw new Error('Unknown content type')
}
}
+29 -32
View File
@@ -1,46 +1,43 @@
import { readFile, stat } from 'node:fs/promises'
import { basename } from 'node:path'
import { encode } from '@msgpack/msgpack'
import mime from 'mime'
import { AES, Hex } from 'occulto'
import { Adapters } from '../shared/adapters.js'
import { API, FileDTO, Note, NoteMeta } from '../shared/api.js'
import { encrypt, generateKey, deriveKey, randomBytes, setServer, getServer, create, utf8ToBytes } from '@cryptgeon/shared'
export type UploadOptions = Pick<Note, 'views' | 'expiration'> & { password?: string }
export type UploadOptions = { views?: number; expiration?: number; password?: string }
export async function upload(input: string | string[], options: UploadOptions): Promise<string> {
const { password, ...noteOptions } = options
const derived = options.password ? await AES.derive(options.password) : undefined
const key = derived ? derived[0] : await AES.generateKey()
let contents: string
let type: NoteMeta['type']
if (typeof input === 'string') {
contents = await Adapters.Text.encrypt(input, key)
type = 'text'
let key: Uint8Array
let extra = new Uint8Array()
if (password) {
const salt = randomBytes(16)
key = deriveKey(password, salt)
extra = encode({ salt, N: 32768, r: 8, p: 1 })
} else {
const files: FileDTO[] = await Promise.all(
input.map(async (path) => {
const data = new Uint8Array(await readFile(path))
const stats = await stat(path)
const extension = path.substring(path.indexOf('.') + 1)
const type = mime.getType(extension) ?? 'application/octet-stream'
return {
name: basename(path),
size: stats.size,
contents: data,
type,
} satisfies FileDTO
})
)
contents = await Adapters.Files.encrypt(files, key)
type = 'file'
key = generateKey()
}
// Create the actual note and upload it.
const note: Note = { ...noteOptions, contents, meta: { type, derivation: derived?.[1] } }
const result = await API.create(note)
let url = `${API.getOptions().server}/note/${result.id}`
if (!derived) url += `#${Hex.encode(key)}`
let inner: Uint8Array
if (typeof input === 'string') {
inner = encode({ type: 'text', data: input })
} else {
const files = await Promise.all(
input.map(async (path) => {
const data = new Uint8Array(await readFile(path))
const extension = path.substring(path.indexOf('.') + 1)
const type = mime.getType(extension) ?? 'application/octet-stream'
return { name: basename(path), mime: type, size: data.length, data }
})
)
inner = encode({ type: 'files', data: files })
}
const data = encrypt(inner, key)
const result = await create({ meta: { ...noteOptions, extra }, data })
let url = `${getServer()}/note/${result.id}`
if (!password) url += `#${Buffer.from(key).toString('hex')}`
return url
}
+9 -12
View File
@@ -5,7 +5,7 @@ import prettyBytes from 'pretty-bytes'
import { download } from './actions/download.js'
import { upload } from './actions/upload.js'
import { API } from './shared/api.js'
import { setServer, status } from '@cryptgeon/shared'
import { parseFile, parseNumber } from './utils/parsers.js'
import { getStdin } from './utils/stdin.js'
import { checkConstrains, exit } from './utils/utils.js'
@@ -33,15 +33,12 @@ program
.description('show information about the server')
.addOption(server)
.action(async (options) => {
API.setOptions({ server: options.server })
const response = await API.status()
const formatted = {
...response,
max_size: prettyBytes(response.max_size),
}
for (const key of Object.keys(formatted)) {
if (key.startsWith('theme_')) delete formatted[key as keyof typeof formatted]
}
setServer(options.server)
const response = await status()
const formatted = Object.fromEntries(
Object.entries({ ...response, max_size: prettyBytes(response.max_size as number) })
.filter(([key]) => !key.startsWith('theme_'))
)
console.table(formatted)
})
@@ -54,7 +51,7 @@ send
.addOption(minutes)
.addOption(password)
.action(async (files, options) => {
API.setOptions({ server: options.server })
setServer(options.server)
await checkConstrains(options)
options.password ||= await getStdin()
try {
@@ -72,7 +69,7 @@ send
.addOption(minutes)
.addOption(password)
.action(async (text, options) => {
API.setOptions({ server: options.server })
setServer(options.server)
await checkConstrains(options)
options.password ||= await getStdin()
try {
-2
View File
@@ -1,4 +1,2 @@
export * from './actions/download.js'
export * from './actions/upload.js'
export * from './shared/adapters.js'
export * from './shared/api.js'
-61
View File
@@ -1,61 +0,0 @@
import { AES, Bytes, type TypedArray } from 'occulto'
import type { EncryptedFileDTO, FileDTO } from './api'
abstract class CryptAdapter<T> {
abstract encrypt(plaintext: T, key: TypedArray): Promise<string>
abstract decrypt(ciphertext: string, key: TypedArray): Promise<T>
}
class CryptTextAdapter implements CryptAdapter<string> {
async encrypt(plaintext: string, key: TypedArray) {
return await AES.encrypt(Bytes.encode(plaintext), key)
}
async decrypt(ciphertext: string, key: TypedArray) {
return Bytes.decode(await AES.decrypt(ciphertext, key))
}
}
class CryptBlobAdapter implements CryptAdapter<TypedArray> {
async encrypt(plaintext: TypedArray, key: TypedArray) {
return await AES.encrypt(plaintext, key)
}
async decrypt(ciphertext: string, key: TypedArray) {
return await AES.decrypt(ciphertext, key)
// const plaintext = await AES.decrypt(ciphertext, key)
// return new Blob([plaintext], { type: 'application/octet-stream' })
}
}
class CryptFilesAdapter implements CryptAdapter<FileDTO[]> {
async encrypt(plaintext: FileDTO[], key: TypedArray) {
const adapter = new CryptBlobAdapter()
const data: Promise<EncryptedFileDTO>[] = plaintext.map(async (file) => ({
name: file.name,
size: file.size,
type: file.type,
contents: await adapter.encrypt(file.contents, key),
}))
return JSON.stringify(await Promise.all(data))
}
async decrypt(ciphertext: string, key: TypedArray) {
const adapter = new CryptBlobAdapter()
const data: EncryptedFileDTO[] = JSON.parse(ciphertext)
const files: FileDTO[] = await Promise.all(
data.map(async (file) => ({
name: file.name,
size: file.size,
type: file.type,
contents: await adapter.decrypt(file.contents, key),
}))
)
return files
}
}
export const Adapters = {
Text: new CryptTextAdapter(),
Blob: new CryptBlobAdapter(),
Files: new CryptFilesAdapter(),
}
-141
View File
@@ -1,141 +0,0 @@
import type { KeyData, TypedArray } from 'occulto'
export type NoteMeta = {
type: 'text' | 'file'
derivation?: KeyData
}
export type Note = {
contents: string
meta: NoteMeta
views?: number
expiration?: number
}
export type NoteInfo = Pick<Note, 'meta'>
export type NotePublic = Pick<Note, 'contents' | 'meta'>
export type NoteCreate = Omit<Note, 'meta'> & { meta: string }
export type FileDTO = Pick<File, 'name' | 'size' | 'type'> & {
contents: TypedArray
}
export type EncryptedFileDTO = Omit<FileDTO, 'contents'> & {
contents: string
}
type ClientOptions = {
server: string
}
type CallOptions = {
url: string
method: string
body?: any
}
export class PayloadToLargeError extends Error {}
export let client: ClientOptions = {
server: '',
}
function setOptions(options: Partial<ClientOptions>) {
client = { ...client, ...options }
}
function getOptions(): ClientOptions {
return client
}
async function call(options: CallOptions) {
const url = client.server + '/api/' + options.url
const response = await fetch(url, {
method: options.method,
body: options.body === undefined ? undefined : JSON.stringify(options.body),
mode: 'cors',
headers: {
'Content-Type': 'application/json',
},
})
if (!response.ok) {
if (response.status === 413) throw new PayloadToLargeError()
else throw new Error('API call failed')
}
return response.json()
}
async function create(note: Note) {
const { meta, ...rest } = note
const body: NoteCreate = {
...rest,
meta: JSON.stringify(meta),
}
const data = await call({
url: 'notes/',
method: 'post',
body,
})
return data as { id: string }
}
async function get(id: string): Promise<NotePublic> {
const data = await call({
url: `notes/${id}`,
method: 'delete',
})
const { contents, meta } = data
const note = {
contents,
meta: JSON.parse(meta),
} satisfies NotePublic
if (note.meta.derivation) note.meta.derivation.salt = new Uint8Array(Object.values(note.meta.derivation.salt))
return note
}
async function info(id: string): Promise<NoteInfo> {
const data = await call({
url: `notes/${id}`,
method: 'get',
})
const { meta } = data
const note = {
meta: JSON.parse(meta),
} satisfies NoteInfo
if (note.meta.derivation) note.meta.derivation.salt = new Uint8Array(Object.values(note.meta.derivation.salt))
return note
}
export type Status = {
version: string
max_size: number
max_views: number
max_expiration: number
allow_advanced: boolean
allow_files: boolean
imprint_url: string
imprint_html: string
theme_image: string
theme_text: string
theme_favicon: string
theme_page_title: string
theme_new_note_notice: boolean
theme_home_link: boolean
}
async function status() {
const data = await call({
url: 'status/',
method: 'get',
})
return data as Status
}
export const API = {
setOptions,
getOptions,
create,
get,
info,
status,
}
-2
View File
@@ -1,2 +0,0 @@
export * from './adapters.js'
export * from './api.js'
+7 -9
View File
@@ -1,5 +1,5 @@
import { exit as exitNode } from 'node:process'
import { API } from '../shared/api.js'
import { status } from '@cryptgeon/shared'
export function exit(message: string) {
console.error(message)
@@ -7,13 +7,11 @@ export function exit(message: string) {
}
export async function checkConstrains(constrains: { views?: number; minutes?: number }) {
const { views, minutes } = constrains
if (views && minutes) exit('cannot set view and minutes constrains simultaneously')
if (!views && !minutes) constrains.views = 1
if (!constrains.views && !constrains.minutes) constrains.views = 1
const response = await API.status()
if (views && views > response.max_views)
exit(`Only a maximum of ${response.max_views} views allowed. ${views} given.`)
if (minutes && minutes > response.max_expiration)
exit(`Only a maximum of ${response.max_expiration} minutes allowed. ${minutes} given.`)
const response = await status()
if (constrains.views && constrains.views > (response.max_views as number))
exit(`Only a maximum of ${response.max_views} views allowed. ${constrains.views} given.`)
if (constrains.minutes && constrains.minutes > (response.max_expiration as number))
exit(`Only a maximum of ${response.max_expiration} minutes allowed. ${constrains.minutes} given.`)
}
+1 -2
View File
@@ -29,9 +29,8 @@
"vite": "^8.0.14"
},
"dependencies": {
"@cryptgeon/shared": "workspace:*",
"@fontsource/fira-mono": "^5.2.7",
"cryptgeon": "workspace:*",
"occulto": "^2.0.6",
"pretty-bytes": "^7.1.0",
"uqr": "^0.1.3"
}
+20 -3
View File
@@ -1,8 +1,25 @@
import { API, type Status } from 'cryptgeon/shared'
import { status as apiStatus } from '@cryptgeon/shared'
import { writable } from 'svelte/store'
export const status = writable<null | Status>(null)
export type StatusInfo = {
version: string
max_size: number
max_views: number
max_expiration: number
allow_advanced: boolean
allow_files: boolean
imprint_url: string
imprint_html: string
theme_image: string
theme_text: string
theme_page_title: string
theme_favicon: string
theme_new_note_notice: boolean
theme_home_link: boolean
}
export const status = writable<null | StatusInfo>(null)
export async function init() {
status.set(await API.status())
status.set((await apiStatus()) as StatusInfo)
}
@@ -4,10 +4,9 @@
import { status } from '$lib/stores/status'
import Switch from '$lib/ui/Switch.svelte'
import TextInput from '$lib/ui/TextInput.svelte'
import type { Note } from 'cryptgeon/shared'
interface Props {
note: Note
note: { views: number; expiration: number }
timeExpiration?: boolean
customPassword?: string | null
}
@@ -3,7 +3,7 @@
import Button from '$lib/ui/Button.svelte'
import MaxSize from '$lib/ui/MaxSize.svelte'
import type { FileDTO } from 'cryptgeon/shared'
import type { FileDTO } from '@cryptgeon/shared'
interface Props {
label?: string
@@ -16,9 +16,9 @@
async function fileToDTO(file: File): Promise<FileDTO> {
return {
name: file.name,
mime: file.type,
size: file.size,
type: file.type,
contents: new Uint8Array(await file.arrayBuffer()),
data: new Uint8Array(await file.arrayBuffer()),
}
}
@@ -1,7 +1,7 @@
<script lang="ts">
import { t } from 'svelte-intl-precompile'
import Button from '$lib/ui/Button.svelte'
import type { FileDTO } from 'cryptgeon/shared'
import type { FileDTO } from '@cryptgeon/shared'
interface Props {
files: FileDTO[]
@@ -12,7 +12,7 @@
let previewUrls: string[] = $state([])
$effect(() => {
const urls = files.map((f) => URL.createObjectURL(new Blob([f.contents], { type: f.type })))
const urls = files.map((f) => URL.createObjectURL(new Blob([f.data.slice(0)], { type: f.mime })))
previewUrls = urls
return () => {
for (const url of urls) URL.revokeObjectURL(url)
@@ -36,12 +36,12 @@
<div class="files-grid">
{#each files as entry, index}
<div class="file-preview">
{#if isImage(entry.type)}
{#if isImage(entry.mime)}
<img src={previewUrls[index]} class="preview-img" alt={entry.name} />
{:else}
<div class="file-icon">
<div class="file-extension">
{entry.name.split('.').pop()?.toUpperCase() || entry.type}
{entry.name.split('.').pop()?.toUpperCase() || entry.mime}
</div>
</div>
{/if}
+11 -9
View File
@@ -1,5 +1,8 @@
<script lang="ts" module>
export type DecryptedNote = Omit<NotePublic, 'contents'> & { contents: any }
export type DecryptedNote = {
meta: { type: 'text' | 'file' }
contents: any
}
function saveAs(file: File) {
const url = window.URL.createObjectURL(file)
@@ -20,7 +23,7 @@
import Button from '$lib/ui/Button.svelte'
import { copy } from '$lib/utils'
import type { FileDTO, NotePublic } from 'cryptgeon/shared'
import type { FileDTO } from '@cryptgeon/shared'
interface Props {
note: DecryptedNote
@@ -31,10 +34,9 @@
const RE_URL = /[A-Za-z]+:\/\/([A-Z a-z0-9\-._~:\/?#\[\]@!$&'()*+,;%=])+/g
let files: FileDTO[] = $state([])
async function downloadFile(file: FileDTO) {
// @ts-ignore
const f = new File([file.contents], file.name, {
type: file.type,
async function downloadFile(file: FileDTO) {
const f = new File([file.data.slice(0)], file.name, {
type: file.mime,
})
saveAs(f)
}
@@ -78,12 +80,12 @@
<button onclick={() => downloadFile(file)}>
<b>↓ {file.name}</b>
</button>
<small> {file.type} - {prettyBytes(file.size)}</small>
<small> {file.mime} - {prettyBytes(file.size ?? file.data.length)}</small>
</div>
{#if file.type.startsWith('image/')}
{#if file.mime.startsWith('image/')}
{#key file.name}
<img
src={URL.createObjectURL(new File([file.contents], file.name, { type: file.type }))}
src={URL.createObjectURL(new File([file.data.slice(0)], file.name, { type: file.mime }))}
alt={file.name}
class="preview"
/>
@@ -1,7 +1,7 @@
<script lang="ts">
import Icon from '$lib/ui/Icon.svelte'
import { copy as copyFN } from '$lib/utils'
import { getRandomBytes, Hex } from 'occulto'
import { randomBytes, bytesToHex } from '@cryptgeon/shared'
import type { HTMLInputAttributes } from 'svelte/elements'
interface Props {
@@ -35,7 +35,7 @@
}
async function randomFN() {
value = Hex.encode(await getRandomBytes(32))
value = bytesToHex(randomBytes(32))
}
</script>
+37 -40
View File
@@ -1,5 +1,10 @@
<script lang="ts">
import { AES, Hex } from 'occulto'
import {
deriveKey, generateKey, encrypt, randomBytes,
bytesToHex, encode,
create as apiCreate,
type FileDTO, type ServerNote
} from '@cryptgeon/shared'
import { t } from 'svelte-intl-precompile'
import { blur } from 'svelte/transition'
@@ -14,14 +19,8 @@
import Result, { type NoteResult } from '$lib/ui/NoteResult.svelte'
import Switch from '$lib/ui/Switch.svelte'
import TextArea from '$lib/ui/TextArea.svelte'
import { Adapters, API, PayloadToLargeError, type FileDTO, type Note } from 'cryptgeon/shared'
let note: Note = $state({
contents: '',
meta: { type: 'text' },
views: 1,
expiration: 60,
})
let note: { views: number; expiration: number } = $state({ views: 1, expiration: 60 })
let files: FileDTO[] = $state([])
let result: NoteResult | null = $state(null)
let advanced = $state(false)
@@ -31,6 +30,7 @@
let description = $state('')
let loading: string | null = $state(null)
let isPasting = $state(false)
let textContent = $state('')
$effect(() => {
if (!advanced) {
@@ -50,13 +50,7 @@
})
$effect(() => {
note.meta.type = isFile ? 'file' : 'text'
})
$effect(() => {
if (!isFile) {
note.contents = ''
}
if (!isFile) textContent = ''
})
async function handlePaste(e: ClipboardEvent) {
@@ -98,11 +92,12 @@
const name =
file.name || `pasted-file-${Date.now()}-${Math.round(Math.random() * 1000)}${ext}`
const renamed = new File([file], name, { type: file.type })
const data = new Uint8Array(await renamed.arrayBuffer())
return {
name: renamed.name,
mime: renamed.type,
size: renamed.size,
type: renamed.type,
contents: new Uint8Array(await renamed.arrayBuffer()),
data,
}
})
)
@@ -122,40 +117,42 @@
try {
loading = $t('common.encrypting')
const derived = customPassword && (await AES.derive(customPassword))
const key = derived ? derived[0] : await AES.generateKey()
const salt = customPassword ? randomBytes(16) : null
const key = customPassword
? deriveKey(customPassword, salt!)
: generateKey()
const data: Note = {
contents: '',
meta: note.meta,
}
if (derived) data.meta.derivation = derived[1]
let inner: Uint8Array
if (isFile) {
if (files.length === 0) throw new EmptyContentError()
data.contents = await Adapters.Files.encrypt(files, key)
inner = encode({ type: 'files', data: files })
} else {
if (note.contents === '') throw new EmptyContentError()
data.contents = await Adapters.Text.encrypt(note.contents, key)
if (textContent === '') throw new EmptyContentError()
inner = encode({ type: 'text', data: textContent })
}
const data = encrypt(inner, key)
const extra = customPassword
? encode({ salt: salt!, N: 32768, r: 8, p: 1 })
: new Uint8Array()
const serverNote: ServerNote = {
meta: {
...(timeExpiration ? { expiration: parseInt(note.expiration as any) } : { views: parseInt(note.views as any) }),
extra,
},
data,
}
if (timeExpiration) data.expiration = parseInt(note.expiration as any)
else data.views = parseInt(note.views as any)
loading = $t('common.uploading')
const response = await API.create(data)
const response = await apiCreate(serverNote)
result = {
id: response.id,
password: customPassword ? undefined : Hex.encode(key),
password: customPassword ? undefined : bytesToHex(key),
}
notify.success($t('home.messages.note_created'))
} catch (e) {
if (e instanceof PayloadToLargeError) {
notify.error($t('home.errors.note_too_big'))
} else if (e instanceof EmptyContentError) {
notify.error($t('home.errors.empty_content'))
} else {
console.error(e)
notify.error($t('home.errors.note_error'))
}
console.error(e)
notify.error($t('home.errors.note_error'))
} finally {
loading = null
}
@@ -183,7 +180,7 @@
<TextArea
data-testid="text-field"
label={$t('common.note')}
bind:value={note.contents}
bind:value={textContent}
placeholder="..."
/>
{/if}
@@ -1,5 +1,5 @@
<script lang="ts">
import { AES, Hex } from 'occulto'
import { deriveKey, hexToBytes, decrypt, decode, info, get as apiGet, type FileDTO } from '@cryptgeon/shared'
import { onMount } from 'svelte'
import { t } from 'svelte-intl-precompile'
@@ -7,7 +7,6 @@
import Loader from '$lib/ui/Loader.svelte'
import ShowNote, { type DecryptedNote } from '$lib/ui/ShowNote.svelte'
import TextInput from '$lib/ui/TextInput.svelte'
import { Adapters, API, type NoteMeta } from 'cryptgeon/shared'
import type { PageData } from './$types'
interface Props {
@@ -20,7 +19,7 @@
let password: string | null = $state<string | null>(null)
let note: DecryptedNote | null = $state(null)
let exists = $state(false)
let meta: NoteMeta | null = $state(null)
let hasExtra = $state(false)
let loading: string | null = $state(null)
let error: string | null = $state(null)
@@ -28,13 +27,16 @@
let valid = $derived(!!password?.length)
onMount(async () => {
// Check if note exists
try {
loading = $t('common.loading')
password = window.location.hash.slice(1)
const note = await API.info(id)
meta = note.meta
exists = true
const meta = await info(id)
if (meta) {
hasExtra = !!meta.extra?.length
exists = true
} else {
exists = false
}
} catch {
exists = false
} finally {
@@ -42,9 +44,6 @@
}
})
/**
* Get the actual contents of the note and decrypt it.
*/
async function show(e: SubmitEvent) {
e.preventDefault()
try {
@@ -53,26 +52,43 @@
return
}
// Load note
error = null
loading = $t('common.downloading')
const data = await API.get(id)
const serverNote = await apiGet(id)
if (!serverNote) {
error = $t('show.errors.not_found')
return
}
loading = $t('common.decrypting')
const derived = meta?.derivation && (await AES.derive(password!, meta.derivation))
const key = derived ? derived[0] : Hex.decode(password!)
switch (data.meta.type) {
let key: Uint8Array
if (hasExtra && serverNote.meta.extra && serverNote.meta.extra.length > 0) {
const derivation = decode(serverNote.meta.extra) as any
key = deriveKey(password!, new Uint8Array(derivation.salt))
} else {
key = hexToBytes(password!)
}
const decrypted = decrypt(serverNote.data, key)
const content = decode(decrypted) as any
switch (content.type) {
case 'text':
note = {
meta: { type: 'text' },
contents: await Adapters.Text.decrypt(data.contents, key),
}
break
case 'file':
note = {
meta: { type: 'file' },
contents: await Adapters.Files.decrypt(data.contents, key),
contents: content.data,
}
break
case 'files':
const files = (content.data as any[]).map((f: any) => ({
...f,
data: f.data instanceof Uint8Array ? f.data : new Uint8Array(f.data as any),
}))
note = {
meta: { type: 'file' },
contents: files,
}
break
default:
error = $t('show.errors.unsupported_type')
return
@@ -94,7 +110,7 @@
<form onsubmit={show}>
<fieldset>
<p>{$t('show.explanation')}</p>
{#if meta?.derivation}
{#if hasExtra}
<TextInput
data-testid="show-note-password"
type="password"
+22
View File
@@ -0,0 +1,22 @@
{
"name": "@cryptgeon/shared",
"private": true,
"version": "0.0.0",
"type": "module",
"exports": {
".": "./src/index.ts"
},
"dependencies": {
"@msgpack/msgpack": "^3.1.3",
"@noble/ciphers": "^2.2.0",
"@noble/hashes": "^2.2.0"
},
"devDependencies": {
"typescript": "^5.9.3",
"vitest": "^4.1.7"
},
"scripts": {
"test": "vitest run",
"test:watch": "vitest"
}
}
+58
View File
@@ -0,0 +1,58 @@
import { encode, decode } from "@msgpack/msgpack";
import type { ServerNote } from "./types.js";
let server = "";
export function setServer(url: string) {
server = url.replace(/\/+$/, "");
}
export function getServer() {
return server;
}
function api(path: string) {
return `${server}/api/v3/${path}`;
}
export async function create(note: ServerNote): Promise<{ id: string }> {
const res = await fetch(api("notes"), {
method: "POST",
headers: { "content-type": "application/msgpack" },
body: encode(note),
});
if (!res.ok) throw new Error("create failed");
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
if (typeof data?.id !== "string") throw new Error("invalid response");
return { id: data.id };
}
export async function info(id: string): Promise<ServerNote["meta"] | null> {
const res = await fetch(api(`notes/${id}`));
if (!res.ok) return null;
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
const meta = data?.meta as ServerNote["meta"] | undefined;
if (!meta) return null;
if (meta.extra && !(meta.extra instanceof Uint8Array)) meta.extra = new Uint8Array(meta.extra as any);
return meta;
}
export async function get(id: string): Promise<ServerNote | null> {
const res = await fetch(api(`notes/${id}`), { method: "DELETE" });
if (!res.ok) return null;
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
const meta = data.meta as ServerNote["meta"];
if (meta?.extra && !(meta.extra instanceof Uint8Array)) meta.extra = new Uint8Array(meta.extra as any);
const d = data.data;
return { meta, data: d instanceof Uint8Array ? d : new Uint8Array(d) } satisfies ServerNote;
}
export async function status(): Promise<Record<string, unknown>> {
const res = await fetch(api("status"));
if (!res.ok) throw new Error("status failed");
return res.json();
}
+26
View File
@@ -0,0 +1,26 @@
import { describe, expect, it } from "vitest";
import { deriveKey, encrypt, decrypt, generateKey, utf8ToBytes, randomBytes } from "./crypto";
describe("crypto", () => {
it("encrypts and decrypts with generated key", () => {
const data = utf8ToBytes("hello world");
const key = generateKey();
const enc = encrypt(data, key);
const dec = decrypt(enc, key);
expect(dec).toEqual(data);
});
it("encrypts and decrypts with derived key", () => {
const data = utf8ToBytes("secret message");
const salt = randomBytes(16);
const key = deriveKey("password123", salt);
const enc = encrypt(data, key);
const dec = decrypt(enc, key);
expect(dec).toEqual(data);
});
it("derived key has same length as generated", () => {
const salt = randomBytes(16);
expect(deriveKey("test", salt).length).toBe(generateKey().length);
});
});
+41
View File
@@ -0,0 +1,41 @@
import { xchacha20poly1305 } from "@noble/ciphers/chacha.js";
import { managedNonce, randomBytes, utf8ToBytes } from "@noble/ciphers/utils.js";
import { scrypt } from "@noble/hashes/scrypt.js";
export { bytesToUtf8, utf8ToBytes } from "@noble/ciphers/utils.js";
export { randomBytes } from "@noble/ciphers/utils.js";
const N = 2 ** 15;
const KEY_SIZE = 32;
export function generateKey(): Uint8Array {
return randomBytes(KEY_SIZE);
}
export function deriveKey(password: string, salt: Uint8Array): Uint8Array {
return scrypt(password, salt, { N, r: 8, p: 1, dkLen: KEY_SIZE });
}
export function encrypt(data: Uint8Array, key: Uint8Array): Uint8Array {
const chacha = managedNonce(xchacha20poly1305)(key);
return chacha.encrypt(data);
}
export function decrypt(data: Uint8Array, key: Uint8Array): Uint8Array {
const chacha = managedNonce(xchacha20poly1305)(key);
return chacha.decrypt(data);
}
export function bytesToHex(bytes: Uint8Array): string {
return Array.from(bytes)
.map((b) => b.toString(16).padStart(2, "0"))
.join("");
}
export function hexToBytes(hex: string): Uint8Array {
const bytes = new Uint8Array(hex.length / 2);
for (let i = 0; i < bytes.length; i++) {
bytes[i] = Number.parseInt(hex.slice(i * 2, i * 2 + 2), 16);
}
return bytes;
}
+4
View File
@@ -0,0 +1,4 @@
export * from "./crypto.js";
export * from "./types.js";
export * from "./api.js";
export { encode, decode } from "@msgpack/msgpack";
+21
View File
@@ -0,0 +1,21 @@
export type NoteMeta = {
expiration?: number;
views?: number;
extra?: Uint8Array;
};
export type ServerNote = {
meta: NoteMeta;
data: Uint8Array;
};
export type NoteContent =
| { type: "text"; data: string }
| { type: "files"; data: FileDTO[] };
export type FileDTO = {
name: string;
mime: string;
size: number;
data: Uint8Array;
};
+10
View File
@@ -0,0 +1,10 @@
{
"compilerOptions": {
"target": "ESNext",
"module": "ESNext",
"moduleResolution": "bundler",
"strict": true,
"noEmit": true,
"skipLibCheck": true
}
}
+7
View File
@@ -0,0 +1,7 @@
import { defineConfig } from "vitest/config";
export default defineConfig({
test: {
environment: "node",
},
});
+284 -1020
View File
File diff suppressed because it is too large Load Diff
+5 -2
View File
@@ -33,7 +33,10 @@ async function createNote(page: Page, options: CreatePage): Promise<void> {
await fileChooser.setFiles(options.files)
}
if (options.views || options.expiration || options.password) await page.getByTestId('switch-advanced').click()
if (options.views || options.expiration || options.password) {
await page.getByTestId('switch-advanced').waitFor({ state: 'visible', timeout: 10000 })
await page.getByTestId('switch-advanced').click()
}
if (options.views) {
await page.getByTestId('field-views').fill(options.views.toString())
}
@@ -97,7 +100,7 @@ export async function checkLinkDoesNotExist(page: Page, link: string) {
}
export async function CLI(...args: string[]) {
return await exec('./packages/cli/dist/cli.cjs', args, {
return await exec('./packages/cli/dist/cli.js', args, {
env: {
...process.env,
CRYPTGEON_SERVER: 'http://localhost:3000',
+8 -6
View File
@@ -1,10 +1,9 @@
#!/usr/bin/env node
import shelljs from 'shelljs'
import { readFileSync, writeFileSync } from 'node:fs'
import { execSync } from 'node:child_process'
const VERSION = process.argv[2]
// https://semver.org/#is-there-a-suggested-regular-expression-regex-to-check-a-semver-string
const semver =
/^(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\.(?:0|[1-9]\d*|\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\+([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?$/gm
if (!semver.test(VERSION)) {
@@ -12,9 +11,12 @@ if (!semver.test(VERSION)) {
process.exit(1)
}
// CLI
shelljs.sed('-i', /"version": ".*"/, `"version": "${process.argv[2]}"`, './packages/cli/package.json')
function sed(file, pattern, replacement) {
const content = readFileSync(file, 'utf-8')
writeFileSync(file, content.replace(pattern, replacement))
}
sed('./packages/cli/package.json', /"version": ".*"/, `"version": "${VERSION}"`)
sed('./packages/backend/Cargo.toml', /^version = ".*"$/m, `version = "${VERSION}"`)
// Backend
shelljs.sed('-i', /^version = ".*"$/m, `version = "${process.argv[2]}"`, './packages/backend/Cargo.toml')
execSync('cargo check -p cryptgeon', { cwd: './packages/backend' })