Compare commits

..
83 Commits
Author SHA1 Message Date
cupcakearmy 77b7ae1de6 fix(ci): point CLI tests to cli.mjs output and drop removed buildx install input 2026-09-06 23:03:38 +02:00
cupcakearmy be617383f4 fix(ci): drop test:dl-browsers from test:prepare (root-only script broke CI) 2026-09-06 22:54:15 +02:00
cupcakearmy 3ff1f8202b ci: add rust+shared tests, cli-only build, bump action versions 2026-09-06 22:50:24 +02:00
cupcakearmy e81dde63ff chore: remove all lokalise references and badge 2026-09-06 22:46:46 +02:00
cupcakearmy 4f5f829c81 test: add shared api client tests and remove dead backend code 2026-09-06 22:46:40 +02:00
cupcakearmy c78845ca7a docs: add vite-plus tooling todo 2026-09-06 22:29:12 +02:00
cupcakearmy dd213d6b41 chore(web): remove lokalise tooling and scripts 2026-09-06 22:29:07 +02:00
cupcakearmy 849ab7e4c5 chore: upgrade to typescript 7 with tsconfig strictest 2026-09-06 22:29:02 +02:00
cupcakearmy 6a4d40e7be refactor(cli): build with vite-plus instead of tsup 2026-09-06 22:28:58 +02:00
cupcakearmy 2f4ebb90e6 build: add vite-plus, typescript 7 and tsconfig strictest catalog deps 2026-09-06 22:28:55 +02:00
cupcakearmy e0d22283c8 v3 2026-09-06 18:34:07 +02:00
cupcakearmy 062054f450 first v3 2026-07-12 11:36:01 +02:00
cupcakearmy 1f180a2e53 Merge pull request #213 from cupcakearmy/feat/redis-key-prefix
feat: add REDIS_PREFIX env var for sharing a Redis instance
2026-06-25 22:30:59 +02:00
cupcakearmy 6b29c6f069 feat: add REDIS_PREFIX env var for shared Redis instance namespace 2026-06-25 21:21:17 +01:00
cupcakearmy 40f3559533 chore:bump version 2026-06-25 21:01:10 +01:00
cupcakearmy ac686e1935 Merge pull request #209 from unambient/typo-fix
fix typo in localization key
2026-06-25 21:42:38 +02:00
cupcakearmy 2cb984405f Merge pull request #208 from fwa-wup/main
fix #207
2026-06-25 21:40:46 +02:00
maddie 8a000ce131 change localization instances of note_to_big to note_too_big 2026-06-09 10:43:05 +00:00
Fabian W 38987efc8a fix #207 2026-06-09 12:17:58 +02:00
cupcakearmy c3e475c16d Merge pull request #203 from smeinecke/feat/image-paste
feat: add image paste support
2026-06-07 14:20:28 +02:00
cupcakearmy 5ff4d42aa6 fix test 2026-06-07 14:12:02 +02:00
cupcakearmy 9c4fbc30f9 cleanup 2026-06-07 13:53:38 +02:00
cupcakearmy f55925de86 Merge branch 'main' into feat/image-paste 2026-06-07 12:54:32 +02:00
cupcakearmy afbe6aac0f Merge pull request #204 from smeinecke/fix/various
fix: multiple minor fixes (#198, #188, #190, #200)
2026-06-07 12:53:46 +02:00
cupcakearmy e14abeee74 replace license checker package 2026-06-07 11:15:35 +02:00
Stefan Meinecke f5823fb533 fix: clean up whitespace and add alt text to pasted images
Remove trailing whitespace throughout the Create.svelte component and add missing alt attribute to pasted image previews for better accessibility.
2026-06-01 02:35:57 +02:00
Stefan Meinecke 3e3d528d5a feat: add image paste support
Add image paste functionality allowing users to paste images directly
from the clipboard as files. Uses the standard DataTransfer API
(clipboardData.items) for cross-browser compatibility.

On the download page, images are now displayed as previews in addition
to the download option.

Also fix Rust 2024 never-type-fallback compatibility by adding turbofish
type annotations to redis crate calls.
2026-06-01 02:35:57 +02:00
Stefan Meinecke 84ec85e96f docs: add THEME_HOME_LINK environment variable to README files 2026-06-01 02:33:52 +02:00
Stefan Meinecke 905bce0072 fix https://github.com/cupcakearmy/cryptgeon/issues/200 2026-06-01 02:33:35 +02:00
Stefan Meinecke e8c3b53e49 fix: multiple minor fixes (#198, #188, #190)
- https://github.com/cupcakearmy/cryptgeon/issues/198: Replace abandoned license-checker with license-checker-evergreen
- https://github.com/cupcakearmy/cryptgeon/issues/188: Fix Polish locale number formatting by using {n} instead of # in ICU plural forms
- https://github.com/cupcakearmy/cryptgeon/issues/190: Add THEME_HOME_LINK env var to conditionally hide the /home link (defaults to true)
- Fix Rust 2024 never-type-fallback compatibility in store.rs
2026-06-01 02:33:24 +02:00
cupcakearmy d40bbd25ea Merge pull request #180 from ShiroDN/main
Add czech translation
2026-06-01 00:00:27 +02:00
cupcakearmy 339c3ac445 version bump 2026-05-31 23:59:01 +02:00
cupcakearmy e27915db06 Merge branch 'main' into main 2026-05-31 23:58:09 +02:00
cupcakearmy d400cfc8e6 Merge pull request #205 from cupcakearmy/maintenance/2026-05-31
maintenance/2026 05 31
2026-05-31 23:51:42 +02:00
cupcakearmy 198accddeb Merge branch 'main' into main 2026-05-31 23:50:44 +02:00
cupcakearmy 3cbe9fabf2 update docker image 2026-05-31 23:44:28 +02:00
cupcakearmy 2923aab916 cleanup docs 2026-05-31 23:41:02 +02:00
cupcakearmy b5102dc647 cleanup docs 2026-05-31 23:40:48 +02:00
cupcakearmy 12d8b87cc1 cleanup readme 2026-05-31 23:31:36 +02:00
cupcakearmy f42662812f cleanup translations 2026-05-31 23:31:31 +02:00
cupcakearmy a551b16216 frontend cleanup 2026-05-31 23:24:55 +02:00
cupcakearmy 09840dcf0a frontend cleanup 2026-05-31 23:24:46 +02:00
cupcakearmy 24e99b84e0 update gihub action 2026-05-31 22:57:28 +02:00
cupcakearmy 690b955d5d watchexec & breaking changes in axum 0.8 2026-05-31 22:55:11 +02:00
cupcakearmy 9b0155dc9a use mise 2026-05-31 22:24:30 +02:00
cupcakearmy 0a56c4c572 maintenance 2026-05-31 22:24:20 +02:00
cupcakearmy f6bf8c656c Merge pull request #202 from smeinecke/update/redis-to-valkey
Replace Redis with Valkey in docker-compose files
2026-05-31 21:40:46 +02:00
Stefan Meinecke 1a243cc96a Replace Redis with Valkey in docker-compose files and fix Rust 2024 compat
Swap redis:7-alpine images to valkey/valkey:7-alpine across all
docker-compose files and example READMEs. Keep service name as
"redis" so that the default REDIS=redis://redis/ connection string
still resolves correctly in Docker networking.

Also add turbofish type annotations to redis crate calls in store.rs
for Rust 2024 never-type-fallback compatibility, and fix a typo
("notion" -> "note") in an error message.
2026-05-12 18:40:41 +02:00
cupcakearmy 482795dd9a Merge pull request #181 from cupcakearmy/dependabot/cargo/packages/backend/cargo-362f336499
Bump ring from 0.16.20 to 0.17.12 in /packages/backend in the cargo group across 1 directory
2025-03-08 10:34:30 +01:00
dependabot[bot] 2907e7c002 Bump ring in /packages/backend in the cargo group across 1 directory
Bumps the cargo group with 1 update in the /packages/backend directory: [ring](https://github.com/briansmith/ring).


Updates `ring` from 0.16.20 to 0.17.12
- [Changelog](https://github.com/briansmith/ring/blob/main/RELEASES.md)
- [Commits](https://github.com/briansmith/ring/commits)

---
updated-dependencies:
- dependency-name: ring
  dependency-type: direct:production
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-03-07 16:49:50 +00:00
Tomas Leypold 57001e90a4 Add czech translation 2025-03-03 17:07:34 +01:00
cupcakearmy 4cc9d8a758 Merge pull request #179 from larsgerber/main
docs(compose): prevent anonymous volume creation
2025-03-02 21:50:52 +01:00
Lars Gerber d652c4ee1e docs(compose): prevent anonymous volume creation 2025-03-01 21:28:34 +01:00
cupcakearmy 096be03966 Merge pull request #178 from cupcakearmy/176-ram-only
update docs about ram only redis
2025-02-27 20:13:09 +01:00
cupcakearmy c53cde6886 Merge branch 'main' into 176-ram-only 2025-02-27 20:06:56 +01:00
cupcakearmy 0fa5a35dae update some versions 2025-02-27 20:00:38 +01:00
cupcakearmy ebbb4efa04 version bump 2025-02-27 19:40:45 +01:00
cupcakearmy a248440bfd Merge pull request #177 from cupcakearmy/password-eye-toggle
fix: password eye toggle not working
2025-02-27 19:38:37 +01:00
cupcakearmy a1db60d159 update docs about ram only redis 2025-02-27 19:38:07 +01:00
cupcakearmy c2653bee84 fix: password eye toggle not working 2025-02-27 19:28:16 +01:00
cupcakearmy a2d2acc5de Merge pull request #168 from cupcakearmy/dependabot/npm_and_yarn/npm_and_yarn-545022be4d
Bump vite from 6.0.7 to 6.0.9 in the npm_and_yarn group across 1 directory
2025-01-22 17:58:41 +01:00
dependabot[bot] 4cc821150d Bump vite in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `vite` from 6.0.7 to 6.0.9
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v6.0.9/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-type: direct:development
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-21 21:00:55 +00:00
cupcakearmy e7fb844f66 Merge pull request #167 from cupcakearmy/svelte-5
some frontend love
2025-01-18 14:33:46 +01:00
cupcakearmy 567a0bed68 Update README.md 2025-01-18 03:52:13 +01:00
cupcakearmy c13e53404c add csp draft 2025-01-17 18:48:28 +01:00
cupcakearmy 82862f0e3e version bump 2025-01-17 18:13:49 +01:00
cupcakearmy e20f4626e7 Merge remote-tracking branch 'origin/main' into svelte-5 2025-01-17 18:11:34 +01:00
cupcakearmy e440e4b7e0 update to svelte 5 2025-01-17 18:11:26 +01:00
cupcakearmy 808d846737 remove proxy 2025-01-17 18:11:03 +01:00
cupcakearmy 63c16a797b Merge pull request #166 from cupcakearmy/fix-race-condition
fix: introduce locks for delete endpoint to guarantee view counter
2025-01-17 18:01:30 +01:00
cupcakearmy ea50590532 fix: introduce locks for delete endpoint to guarantee view counter 2025-01-17 17:34:32 +01:00
cupcakearmy b22c3122d7 Merge pull request #163 from werewolfboy13/update-redis-link
Update Redis documentation link in Docker Compose file
2025-01-15 16:11:47 +01:00
Marek 18af2b2f45 Update Redis documentation link in Docker Compose file
Fixes #162

---

For more details, open the [Copilot Workspace session](https://copilot-workspace.githubnext.com/cupcakearmy/cryptgeon/issues/162?shareId=XXXX-XXXX-XXXX-XXXX).
2025-01-09 04:08:29 -06:00
cupcakearmy c2b557246b Merge pull request #157 from Jerry-Shr/main
Add Chinese (zh-TW) translations
2025-01-02 09:29:22 +01:00
cupcakearmy df9cd08473 version bump 2025-01-02 09:27:36 +01:00
JerryShr 0b8e1d1b2e Add Chinese (zh-TW) translations 2024-12-05 22:23:44 +08:00
cupcakearmy 70481341b9 Update README.md 2024-10-07 10:58:57 +02:00
cupcakearmy 6271ec1ee9 add basic auth example 2024-10-07 10:58:41 +02:00
cupcakearmy c7ec587a2d bump version 2024-09-27 19:59:39 +00:00
cupcakearmy 3e8e82f51c Merge pull request #153 from scaedufax/imprint_html
Added Option to set a custom HTML Imprint
2024-09-27 21:57:44 +02:00
Uli c314d4b485 Merge branch 'cupcakearmy:main' into imprint_html 2024-09-25 10:19:13 +02:00
Uli Roth 57ea5f0b28 added imprint_html option 2024-09-24 10:25:15 +02:00
Uli Roth fca8761515 Added option to have an imprint
The environment Variable IMPRINT_URL simply adds a /imprint button in footer to the url
2024-09-24 10:15:22 +02:00
104 changed files with 6654 additions and 4771 deletions
Binary file not shown.

Before

Width:  |  Height:  |  Size: 30 KiB

+12 -15
View File
@@ -10,35 +10,32 @@ jobs:
cli: cli:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v3 - uses: actions/checkout@v7
- uses: pnpm/action-setup@v2 - uses: pnpm/action-setup@v6
- uses: actions/setup-node@v3 - uses: actions/setup-node@v7
with: with:
cache: 'pnpm' cache: 'pnpm'
node-version-file: '.nvmrc' node-version-file: '.nvmrc'
registry-url: 'https://registry.npmjs.org' registry-url: 'https://registry.npmjs.org'
- run: | - run: |
pnpm install --frozen-lockfile pnpm install
pnpm run build pnpm --filter cryptgeon build
- run: npm publish - run: pnpm publish --filter cryptgeon
working-directory: ./packages/cli
env: env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
docker: docker:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v3 - uses: actions/checkout@v7
- uses: docker/setup-qemu-action@v2 - uses: docker/setup-qemu-action@v4
- uses: docker/setup-buildx-action@v2 - uses: docker/setup-buildx-action@v4
with:
install: true
- name: Docker Labels - name: Docker Labels
id: meta id: meta
uses: docker/metadata-action@v4 uses: docker/metadata-action@v6
with: with:
images: cupcakearmy/cryptgeon images: cupcakearmy/cryptgeon
tags: | tags: |
@@ -46,12 +43,12 @@ jobs:
type=semver,pattern={{major}}.{{minor}} type=semver,pattern={{major}}.{{minor}}
type=semver,pattern={{major}} type=semver,pattern={{major}}
- name: Login to DockerHub - name: Login to DockerHub
uses: docker/login-action@v2 uses: docker/login-action@v4
with: with:
username: ${{ secrets.DOCKERHUB_USERNAME }} username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }} password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Build and push - name: Build and push
uses: docker/build-push-action@v4 uses: docker/build-push-action@v7
with: with:
platforms: linux/amd64,linux/arm64 platforms: linux/amd64,linux/arm64
push: true push: true
+12 -9
View File
@@ -10,31 +10,34 @@ jobs:
test: test:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v7
# Node # Node
- uses: pnpm/action-setup@v4 - uses: pnpm/action-setup@v6
- uses: actions/setup-node@v4 - uses: actions/setup-node@v7
with: with:
cache: 'pnpm' cache: 'pnpm'
node-version-file: '.nvmrc' node-version-file: '.nvmrc'
# Docker # Docker
- uses: docker/setup-qemu-action@v3 - uses: docker/setup-qemu-action@v4
- uses: docker/setup-buildx-action@v3 - uses: docker/setup-buildx-action@v4
with:
install: true
- name: Prepare - name: Prepare
run: | run: |
pnpm install pnpm install
pnpm exec playwright install --with-deps pnpm exec playwright install --with-deps
pnpm run test:prepare pnpm run test:prepare
- name: Rust tests
run: cargo test --manifest-path packages/backend/Cargo.toml
- name: Shared tests
run: pnpm --filter @cryptgeon/shared test
- name: Run your tests - name: Run your tests
run: pnpm test run: pnpm test
- uses: actions/upload-artifact@v4 - uses: actions/upload-artifact@v7
if: ${{ !cancelled() }} if: ${{ !cancelled() }}
with: with:
name: playwright-report name: playwright-report
+1 -1
View File
@@ -1 +1 @@
v22.7.0 v26
+47
View File
@@ -0,0 +1,47 @@
# Contributing
## Requirements
- [mise](https://mise.jdx.dev) — manages pnpm, rust, node (see `mise.toml`)
- docker or [colima](https://github.com/abiosoft/colima) (for cache)
## Setup
```bash
mise install
pnpm install
```
## Development
```bash
pnpm run dev
```
Make sure docker/colima is running. This starts the cache (valkey/redis), the rust backend, the web client, and the CLI. The app is at [localhost:3000](http://localhost:3000).
## Tests
End-to-end tests with Playwright.
```sh
pnpm run test:prepare
pnpm run test:local
```
## Release
1. Update version across packages:
```sh
./version.mjs <semver>
```
2. Create and push the tag:
```sh
git tag v<semver>
git push --tags
```
The CI workflow publishes the CLI to npm and the Docker image to Docker Hub automatically.
+4 -4
View File
@@ -1,5 +1,5 @@
# FRONTEND # FRONTEND
FROM node:22-alpine as client FROM node:24-alpine AS client
ENV PNPM_HOME="/pnpm" ENV PNPM_HOME="/pnpm"
ENV PATH="$PNPM_HOME:$PATH" ENV PATH="$PNPM_HOME:$PATH"
RUN corepack enable RUN corepack enable
@@ -11,7 +11,7 @@ RUN pnpm run build
# BACKEND # BACKEND
FROM rust:1.80-alpine as backend FROM rust:1.95-alpine AS backend
WORKDIR /tmp WORKDIR /tmp
RUN apk add --no-cache libc-dev openssl-dev alpine-sdk RUN apk add --no-cache libc-dev openssl-dev alpine-sdk
COPY ./packages/backend ./ COPY ./packages/backend ./
@@ -19,12 +19,12 @@ RUN RUSTFLAGS="-Ctarget-feature=-crt-static" cargo build --release
# RUNNER # RUNNER
FROM alpine:3.19 FROM alpine:3
WORKDIR /app WORKDIR /app
RUN apk add --no-cache curl libgcc RUN apk add --no-cache curl libgcc
COPY --from=backend /tmp/target/release/cryptgeon . COPY --from=backend /tmp/target/release/cryptgeon .
COPY --from=client /tmp/packages/frontend/build ./frontend COPY --from=client /tmp/packages/frontend/build ./frontend
ENV FRONTEND_PATH="./frontend" ENV FRONTEND_PATH="./frontend"
ENV REDIS="redis://redis/" ENV CACHE="redis://cache/"
EXPOSE 8000 EXPOSE 8000
ENTRYPOINT [ "/app/cryptgeon" ] ENTRYPOINT [ "/app/cryptgeon" ]
+21 -57
View File
@@ -11,7 +11,6 @@
<br/><br/> <br/><br/>
<a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a> <a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a>
<a href=""><img src="./.github/lokalise.png" height="50">
<a title="Install cryptgeon Raycast Extension" href="https://www.raycast.com/cupcakearmy/cryptgeon"><img src="https://www.raycast.com/cupcakearmy/cryptgeon/install_button@2x.png?v=1.1" height="64" alt="" style="height: 64px;"></a> <a title="Install cryptgeon Raycast Extension" href="https://www.raycast.com/cupcakearmy/cryptgeon"><img src="https://www.raycast.com/cupcakearmy/cryptgeon/install_button@2x.png?v=1.1" height="64" alt="" style="height: 64px;"></a>
<br/><br/> <br/><br/>
@@ -23,8 +22,6 @@ _cryptgeon_ is a secure, open source sharing note or file service inspired by [_
It includes a server, a web page and a CLI client. It includes a server, a web page and a CLI client.
> 🌍 If you want to translate the project feel free to reach out to me. > 🌍 If you want to translate the project feel free to reach out to me.
>
> Thanks to [Lokalise](https://lokalise.com/) for providing free access to their platform.
## Live Service / Demo ## Live Service / Demo
@@ -63,6 +60,8 @@ client side with the <code>key</code> and then sent to the server. data is store
never persisted to disk. the server never sees the encryption key and cannot decrypt the contents never persisted to disk. the server never sees the encryption key and cannot decrypt the contents
of the notes even if it tried to. of the notes even if it tried to.
> View counts are guaranteed with one running instance of cryptgeon. Multiple instances connected to the same cache instance can run into race conditions, where a note might be retrieved more than the view count allows.
## Screenshot ## Screenshot
![screenshot](./design/Screens.png) ![screenshot](./design/Screens.png)
@@ -71,19 +70,23 @@ of the notes even if it tried to.
| Variable | Default | Description | | Variable | Default | Description |
| ----------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | ----------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `REDIS` | `redis://redis/` | Redis URL to connect to. [According to format](https://docs.rs/redis/latest/redis/#connection-parameters) | | `CACHE` | `redis://cache/` | Cache URL (valkey or redis) to connect to. [According to format](https://docs.rs/redis/latest/redis/#connection-parameters) |
| `SIZE_LIMIT` | `1 KiB` | Max size for body. Accepted values according to [byte-unit](https://docs.rs/byte-unit/). <br> `512 MiB` is the maximum allowed. <br> The frontend will show that number including the ~35% encoding overhead. | | `SIZE_LIMIT` | `1 KiB` | Max size for body. Accepted values according to [byte-unit](https://docs.rs/byte-unit/). <br> `512 MiB` is the maximum allowed. <br> The frontend will show that number including the ~35% encoding overhead. |
| `MAX_VIEWS` | `100` | Maximal number of views. | | `MAX_VIEWS` | `100` | Maximal number of views. |
| `MAX_EXPIRATION` | `360` | Maximal expiration in minutes. | | `MAX_EXPIRATION` | `360` | Maximal expiration in minutes. |
| `ALLOW_ADVANCED` | `true` | Allow custom configuration. If set to `false` all notes will be one view only. | | `ALLOW_ADVANCED` | `true` | Allow custom configuration. If set to `false` all notes will be one view only. |
| `ALLOW_FILES` | `true` | Allow uploading files. If set to `false`, users will only be allowed to create text notes. | | `ALLOW_FILES` | `true` | Allow uploading files. If set to `false`, users will only be allowed to create text notes. |
| `ID_LENGTH` | `32` | Set the size of the note `id` in bytes. By default this is `32` bytes. This is useful for reducing link size. _This setting does not affect encryption strength_. | | `ID_LENGTH` | `32` | Set the size of the note `id` in bytes. By default this is `32` bytes. This is useful for reducing link size. _This setting does not affect encryption strength_. |
| `CACHE_PREFIX` | `""` | Optional prefix for all cache keys. Useful when sharing a cache instance with other apps via ACL namespaces. |
| `VERBOSITY` | `warn` | Verbosity level for the backend. [Possible values](https://docs.rs/env_logger/latest/env_logger/#enabling-logging) are: `error`, `warn`, `info`, `debug`, `trace` | | `VERBOSITY` | `warn` | Verbosity level for the backend. [Possible values](https://docs.rs/env_logger/latest/env_logger/#enabling-logging) are: `error`, `warn`, `info`, `debug`, `trace` |
| `THEME_IMAGE` | `""` | Custom image for replacing the logo. Must be publicly reachable | | `THEME_IMAGE` | `""` | Custom image for replacing the logo. Must be publicly reachable |
| `THEME_TEXT` | `""` | Custom text for replacing the description below the logo | | `THEME_TEXT` | `""` | Custom text for replacing the description below the logo |
| `THEME_PAGE_TITLE` | `""` | Custom text the page title | | `THEME_PAGE_TITLE` | `""` | Custom text the page title |
| `THEME_FAVICON` | `""` | Custom url for the favicon. Must be publicly reachable | | `THEME_FAVICON` | `""` | Custom url for the favicon. Must be publicly reachable |
| `THEME_NEW_NOTE_NOTICE` | `true` | Show the message about how notes are stored in the memory and may be evicted after creating a new note. Defaults to `true`. | | `THEME_NEW_NOTE_NOTICE` | `true` | Show the message about how notes are stored in the memory and may be evicted after creating a new note. Defaults to `true`. |
| `THEME_HOME_LINK` | `true` | Show the `/home` link in the footer. Defaults to `true`. |
| `IMPRINT_URL` | `""` | Custom url for an Imprint hosted somewhere else. Must be publicly reachable. Takes precedence above `IMPRINT_HTML`. |
| `IMPRINT_HTML` | `""` | Alternative to `IMPRINT_URL`, this can be used to specify the HTML code to show on `/imprint`. Only `IMPRINT_HTML` or `IMPRINT_URL` should be specified, not both. |
## Deployment ## Deployment
@@ -98,19 +101,24 @@ Docker is the easiest way. There is the [official image here](https://hub.docker
```yaml ```yaml
# docker-compose.yml # docker-compose.yml
version: '3.8' version: "3.8"
services: services:
redis: cache:
image: redis:7-alpine image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise. # Set a size limit. See link below on how to customise.
# https://redis.io/docs/manual/eviction/ # https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# command: redis-server --maxmemory 1gb --maxmemory-policy allkeys-lru # --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
depends_on: depends_on:
- redis - cache
environment: environment:
# Size limit for a single note. # Size limit for a single note.
SIZE_LIMIT: 4 MiB SIZE_LIMIT: 4 MiB
@@ -119,7 +127,7 @@ services:
# Optional health checks # Optional health checks
# healthcheck: # healthcheck:
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/api/live/"] # test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
# interval: 1m # interval: 1m
# timeout: 3s # timeout: 3s
# retries: 2 # retries: 2
@@ -154,53 +162,9 @@ There is a [guide](https://mariushosting.com/how-to-install-cryptgeon-on-your-sy
- Italian by [@nicfab](https://notes.nicfab.eu/it/posts/cryptgeon/) - Italian by [@nicfab](https://notes.nicfab.eu/it/posts/cryptgeon/)
- English by [@nicfab](https://notes.nicfab.eu/en/posts/cryptgeon/) - English by [@nicfab](https://notes.nicfab.eu/en/posts/cryptgeon/)
## Development ## Contributing
**Requirements** See [CONTRIBUTING.md](./CONTRIBUTING.md).
- `pnpm`: `>=9`
- `node`: `>=22`
- `rust`: edition `2021`
**Install**
```bash
pnpm install
# Also you need cargo watch if you don't already have it installed.
# https://lib.rs/crates/cargo-watch
cargo install cargo-watch
```
**Run**
Make sure you have docker running.
```bash
pnpm run dev
```
Running `pnpm run dev` in the root folder will start the following things:
- redis docker container
- rust backend
- client
- cli
You can see the app under [localhost:3000](http://localhost:3000).
> There is a Postman collection with some example requests [available in the repo](./Cryptgeon.postman_collection.json)
### Tests
Tests are end to end tests written with Playwright.
```sh
pnpm run test:prepare
# Use the test or test:local script. The local version only runs in one browser for quicker development.
pnpm run test:local
```
## Security ## Security
+16 -57
View File
@@ -11,7 +11,6 @@
<br/><br/> <br/><br/>
<a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a> <a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a>
<a href=""><img src="./.github/lokalise.png" height="50">
<br/><br/> <br/><br/>
[EN](README.md) | [简体中文](README_zh-CN.md) | ES [EN](README.md) | [简体中文](README_zh-CN.md) | ES
@@ -22,8 +21,6 @@ _cryptgeon_ es un servicio seguro y de código abierto para compartir notas o ar
Incluye un servidor, una página web y una interfaz de línea de comandos (CLI, por sus siglas en inglés). Incluye un servidor, una página web y una interfaz de línea de comandos (CLI, por sus siglas en inglés).
> 🌍 Si quieres traducir este proyecto no dudes en ponerte en contacto conmigo. > 🌍 Si quieres traducir este proyecto no dudes en ponerte en contacto conmigo.
>
> Gracias a [Lokalise](https://lokalise.com/) por darnos acceso gratis a su plataforma.
## Demo ## Demo
@@ -43,7 +40,7 @@ Puedes revisar la documentación sobre el CLI en este [readme](./packages/cli/RE
- enviar texto o archivos - enviar texto o archivos
- el servidor no puede desencriptar el contenido debido a que la encriptación se hace del lado del cliente - el servidor no puede desencriptar el contenido debido a que la encriptación se hace del lado del cliente
- restriccion de vistas o de tiempo - restricción de vistas o de tiempo
- en memoria, sin persistencia - en memoria, sin persistencia
- compatibilidad obligatoria con el modo oscuro - compatibilidad obligatoria con el modo oscuro
@@ -66,34 +63,40 @@ se usa para guardar y recuperar la nota. Después la nota es encriptada con la <
| `MAX_VIEWS` | `100` | Número máximo de vistas. | | `MAX_VIEWS` | `100` | Número máximo de vistas. |
| `MAX_EXPIRATION` | `360` | Tiempo máximo de expiración en minutos. | | `MAX_EXPIRATION` | `360` | Tiempo máximo de expiración en minutos. |
| `ALLOW_ADVANCED` | `true` | Permitir configuración personalizada. Si se establece en `false` todas las notas serán de una sola vista. | | `ALLOW_ADVANCED` | `true` | Permitir configuración personalizada. Si se establece en `false` todas las notas serán de una sola vista. |
| `ID_LENGTH` | `32` | Establece el tamaño en bytes de la `id` de la nota. Por defecto es de `32` bytes. Esto es util para reducir el tamaño del link. _Esta configuración no afecta el nivel de encriptación_. | | `ID_LENGTH` | `32` | Establece el tamaño en bytes de la `id` de la nota. Por defecto es de `32` bytes. Esto es útil para reducir el tamaño del link. _Esta configuración no afecta el nivel de encriptación_. |
| `VERBOSITY` | `warn` | Nivel de verbosidad del backend. [Posibles valores](https://docs.rs/env_logger/latest/env_logger/#enabling-logging): `error`, `warn`, `info`, `debug`, `trace` | | `VERBOSITY` | `warn` | Nivel de verbosidad del backend. [Posibles valores](https://docs.rs/env_logger/latest/env_logger/#enabling-logging): `error`, `warn`, `info`, `debug`, `trace` |
| `THEME_IMAGE` | `""` | Imagen personalizada para reemplazar el logo. Debe ser accesible públicamente. | | `THEME_IMAGE` | `""` | Imagen personalizada para reemplazar el logo. Debe ser accesible públicamente. |
| `THEME_TEXT` | `""` | Texto personalizado para reemplazar la descripción bajo el logo. | | `THEME_TEXT` | `""` | Texto personalizado para reemplazar la descripción bajo el logo. |
| `THEME_PAGE_TITLE` | `""` | Texto personalizado para el título | | `THEME_PAGE_TITLE` | `""` | Texto personalizado para el título |
| `THEME_FAVICON` | `""` | Url personalizada para el favicon. Debe ser accesible públicamente. | | `THEME_FAVICON` | `""` | Url personalizada para el favicon. Debe ser accesible públicamente. |
| `THEME_HOME_LINK` | `true` | Mostrar el enlace `/home` en el pie de página. El valor predeterminado es `true`. |
## Despliegue ## Despliegue
> ℹ️ Se requiere `https` de lo contrario el navegador no soportará las funciones de encriptacón. > ℹ️ Se requiere `https` de lo contrario el navegador no soportará las funciones de encriptación.
> ℹ️ Hay un endpoint para verificar el estado, lo encontramos en `/api/health/`. Regresa un código 200 o 503. > ℹ️ Hay un endpoint para verificar el estado, lo encontramos en `/api/health/`. Regresa un código 200 o 503.
### Docker ### Docker
Docker es la manera más fácil. Aquí encontramos [la imágen oficial](https://hub.docker.com/r/cupcakearmy/cryptgeon). Docker es la manera más fácil. Aquí encontramos [la imagen oficial](https://hub.docker.com/r/cupcakearmy/cryptgeon).
```yaml ```yaml
# docker-compose.yml # docker-compose.yml
version: '3.8' version: "3.8"
services: services:
redis: redis:
image: redis:7-alpine image: redis:7-alpine
# This is required to stay in RAM only.
command: redis-server --save "" --appendonly no
# Set a size limit. See link below on how to customise. # Set a size limit. See link below on how to customise.
# https://redis.io/docs/manual/eviction/ # https://redis.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# command: redis-server --maxmemory 1gb --maxmemory-policy allkeys-lru # --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
@@ -136,57 +139,13 @@ Hay una [guía](https://mariushosting.com/how-to-install-cryptgeon-on-your-synol
- En inglés, por [DB Tech](https://www.youtube.com/watch?v=S0jx7wpOfNM) [Previous Video](https://www.youtube.com/watch?v=JhpIatD06vE) - En inglés, por [DB Tech](https://www.youtube.com/watch?v=S0jx7wpOfNM) [Previous Video](https://www.youtube.com/watch?v=JhpIatD06vE)
- En alemán, por [ApfelCast](https://www.youtube.com/watch?v=84ZMbE9AkHg) - En alemán, por [ApfelCast](https://www.youtube.com/watch?v=84ZMbE9AkHg)
## Desarrollo ## Contribuir
**Requisitos** Ver [CONTRIBUTING.md](./CONTRIBUTING.md).
- `pnpm`: `>=6`
- `node`: `>=18`
- `rust`: edition `2021`
**Instalación**
```bash
pnpm install
# También necesitas cargo-watch, si no lo tienes instalado.
# https://lib.rs/crates/cargo-watch
cargo install cargo-watch
```
**Ejecutar**
Asegurate de que docker se esté ejecutando.
```bash
pnpm run dev
```
Ejecutando `pnpm run dev` en la carpeta raíz iniciará lo siguiente:
- redis docker container
- rust backend
- client
- cli
Puedes ver la app en [localhost:3000](http://localhost:3000).
> Existe una colección de Postman con algunas peticiones de ejemplo [disponible en el repo](./Cryptgeon.postman_collection.json)
### Tests
Los tests son end-to-end tests escritos con Playwright.
```sh
pnpm run test:prepare
# Usa el script test o test:local. La versión local solo corre en el navegador para acelerar el desarrollo.
pnpm run test:local
```
## Seguridad ## Seguridad
Por favor dirigite a la sección de seguridad [aquí](./SECURITY.md). Por favor dirígete a la sección de seguridad [aquí](./SECURITY.md).
--- ---
+30 -62
View File
@@ -11,7 +11,6 @@
<br/> <br/>
<a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a> <a href="https://www.producthunt.com/posts/cryptgeon?utm_source=badge-featured&utm_medium=badge&utm_souce=badge-cryptgeon" target="_blank"><img src="https://api.producthunt.com/widgets/embed-image/v1/featured.svg?post_id=295189&theme=light" alt="Cryptgeon - Securely share self-destructing notes | Product Hunt" height="50" /></a>
<a href=""><img src="./.github/lokalise.png" height="50">
<br/> <br/>
[EN](README.md) | 简体中文 | [ES](README_ES.md) [EN](README.md) | 简体中文 | [ES](README_ES.md)
@@ -21,8 +20,6 @@
_加密鸽_ 是一个受 [_PrivNote_](https://privnote.com)项目启发的安全、开源共享密信和文件共享服务器 _加密鸽_ 是一个受 [_PrivNote_](https://privnote.com)项目启发的安全、开源共享密信和文件共享服务器
> 🌍 如果你想翻译此项目请随时与我联系. > 🌍 如果你想翻译此项目请随时与我联系.
>
> 感谢 [Lokalise](https://lokalise.com/) 提供免费的平台服务支持
## 演示示例 ## 演示示例
@@ -47,15 +44,16 @@ _加密鸽_ 是一个受 [_PrivNote_](https://privnote.com)项目启发的安全
## 环境变量 ## 环境变量
| 变量名称 | 默认值 | 描述 | | 变量名称 | 默认值 | 描述 |
| ----------------- | ---------------- | --------------------------------------------------------------------------------- | | ---------------- | ---------------- | --------------------------------------------------------------------------------- |
| `REDIS` | `redis://redis/` | Redis 连接 URL。 | | `REDIS` | `redis://redis/` | Redis 连接 URL。 |
| `SIZE_LIMIT` | `1 KiB` | 最大请求体(body)限制。有关支持的数值请查看 [字节单位](https://docs.rs/byte-unit/) | | `SIZE_LIMIT` | `1 KiB` | 最大请求体(body)限制。有关支持的数值请查看 [字节单位](https://docs.rs/byte-unit/) |
| `MAX_VIEWS` | `100` | 密信最多查看次数限制 | | `MAX_VIEWS` | `100` | 密信最多查看次数限制 |
| ` MAX_EXPIRATION` | `360` | 密信最长过期时间限制(分钟) | | `MAX_EXPIRATION` | `360` | 密信最长过期时间限制(分钟) |
| `ALLOW_ADVANCED` | `true` | 是否允许自定义设置,该项如果设为`false`,则不会显示自定义设置模块 | | `ALLOW_ADVANCED` | `true` | 是否允许自定义设置,该项如果设为`false`,则不会显示自定义设置模块 |
| `THEME_IMAGE` | `""` | 自定义 Logo 图片,你在这里填写的的图片链接必须是可以公开访问的。 | | `THEME_IMAGE` | `""` | 自定义 Logo 图片,你在这里填写的的图片链接必须是可以公开访问的。 |
| `THEME_TEXT` | `""` | 自定义在 Logo 下方的文本。 | | `THEME_TEXT` | `""` | 自定义在 Logo 下方的文本。 |
| `THEME_HOME_LINK` | `true` | 是否在页脚显示 `/home` 链接。默认为 `true`。 |
## 部署 ## 部署
@@ -69,11 +67,19 @@ Docker 是最简单的部署方式。这里是[官方镜像的地址](https://hu
```yaml ```yaml
# docker-compose.yml # docker-compose.yml
version: '3.8' version: "3.8"
services: services:
redis: redis:
image: redis:7-alpine image: redis:7-alpine
# This is required to stay in RAM only.
command: redis-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://redis.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
@@ -99,7 +105,7 @@ services:
- 域名 `example.org` - 域名 `example.org`
```yaml ```yaml
version: '3.8' version: "3.8"
networks: networks:
proxy: proxy:
@@ -108,7 +114,14 @@ networks:
services: services:
redis: redis:
image: redis:7-alpine image: redis:7-alpine
restart: unless-stopped # This is required to stay in RAM only.
command: redis-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://redis.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
@@ -125,54 +138,9 @@ services:
- traefik.http.routers.cryptgeon.tls.certresolver=le - traefik.http.routers.cryptgeon.tls.certresolver=le
``` ```
## 开发 ## 贡献
**环境要求** 参见 [CONTRIBUTING.md](./CONTRIBUTING.md)。
- `pnpm`: `>=6`
- `node`: `>=14`
- `rust`: edition `2021`
**安装**
```bash
pnpm install
pnpm --prefix frontend install
# 你还需要安装CargoWatch.
# https://lib.rs/crates/cargo-watch
cargo install cargo-watch
```
**运行**
确保你的 Docker 正在运行
```bash
pnpm run dev
```
在根目录执行 `pnpm run dev` 会开启下列服务:
- 一个 redis docker 容器
- 无热重载的 rust 后端
- 可热重载的客户端
你可以通过 3000 端口进入该应用,即 [localhost:3000](http://localhost:3000).
## 测试
这些测试是用 Playwright 实现的一些端到端测试用例。
```sh
pnpm run test:prepare
docker compose up redis -d
pnpm run test:server
# 在另一个终端中:
# 使用test或者test:local script。为了更快的开发,本地版本只会在一个浏览器中运行。
pnpm run test:local
```
###### Attributions ###### Attributions
+12 -4
View File
@@ -2,8 +2,16 @@
# For a production file see: README.md # For a production file see: README.md
services: services:
redis: cache:
image: redis:7-alpine image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
ports: ports:
- 6379:6379 - 6379:6379
@@ -11,13 +19,13 @@ services:
build: . build: .
env_file: .env.dev env_file: .env.dev
depends_on: depends_on:
- redis - cache
restart: unless-stopped restart: unless-stopped
ports: ports:
- 3000:8000 - 3000:8000
healthcheck: healthcheck:
test: ['CMD', 'curl', '--fail', 'http://127.0.0.1:8000/api/live/'] test: ['CMD', 'curl', '--fail', 'http://127.0.0.1:8000/healthz']
interval: 1m interval: 1m
timeout: 3s timeout: 3s
retries: 2 retries: 2
+11 -6
View File
@@ -1,14 +1,19 @@
services: services:
redis: cache:
image: redis:7-alpine image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise. # Set a size limit. See link below on how to customise.
# https://redis.io/docs/manual/eviction/ # https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# command: redis-server --maxmemory 1gb --maxmemory-policy allkeys-lru # --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
depends_on: depends_on:
- redis - cache
environment: environment:
# Size limit for a single note. # Size limit for a single note.
SIZE_LIMIT: 4 MiB SIZE_LIMIT: 4 MiB
@@ -17,7 +22,7 @@ services:
# Optional health checks # Optional health checks
# healthcheck: # healthcheck:
# test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/api/live/"] # test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
# interval: 1m # interval: 1m
# timeout: 3s # timeout: 3s
# retries: 2 # retries: 2
+6
View File
@@ -0,0 +1,6 @@
# Todo
- also update readmes in other languages
- use catalog install for common deps (typescript, vite, tsdown, etc. ) please suggest.
- move formatting, linting, type checking and git hooks to vite-plus (uses oxlint, oxfmt, vitest and git hook dispatcher)
- re-add CSP (Content-Security-Policy) into axum router ( (was in csp.rs, removed as unused)
+66
View File
@@ -0,0 +1,66 @@
# v3 Breaking Changes
A list of changes users and operators need to consider when upgrading from v2 to v3.
## API
- All note endpoints moved under `/api/v3/notes/` (was `/api/notes/`)
- Status endpoint moved to `/api/v3/status` (was `/api/status`)
- All request/response bodies are now **MessagePack** (`Content-Type: application/msgpack`), not JSON
- Health check moved to `/healthz` (was `/api/live`)
- Notes can now have **both** `views` and `expiration` set simultaneously (previously mutually exclusive)
## API payload structure
The wire format changed entirely. v2 used:
```json
{ "contents": "<encrypted string>", "meta": "<stringified JSON>", "views": 5, "expiration": 30 }
```
v3 uses msgpack:
```
{ meta: { views?, expiration?, extra? }, data: <encrypted bytes> }
```
- `meta.extra` holds client-opaque data (e.g. scrypt derivation params), size-limited (default 512 bytes)
- `data` is the encrypted blob — the server never inspects its contents
- The encrypted inner payload is itself msgpack: `{ type: "text", data: string }` or `{ type: "files", data: [{ name, mime, size, data }] }`
## Environment variables
| v2 | v3 |
| ------------------- | -------------------- |
| `REDIS` | `CACHE` |
| `REDIS_PREFIX` | `CACHE_PREFIX` |
| _(new)_ | `EXTRA_SIZE_LIMIT` |
The `CACHE` env var accepts any RESP-compatible URL (valkey or redis).
`EXTRA_SIZE_LIMIT` (default `512`) limits the `extra` field size in bytes.
## Docker / Compose
- The `redis` service in docker-compose is renamed to `cache`
- Healthcheck URL updated: `http://127.0.0.1:8000/api/live/` → `http://127.0.0.1:8000/healthz`
- The default image stays `valkey/valkey:7-alpine` but operators can swap for any redis-compatible image
## CLI (`cryptgeon` npm package)
- Dropped `occulto` dependency — now uses `@noble/ciphers` + `@noble/hashes` internally
- Encryption changed from AES to **XChaCha20-Poly1305**
- The local `shared/` module removed — now imports from `@cryptgeon/shared` (workspace-internal)
- Notes created with v2 (AES) are **not readable** by v3 and vice versa
## Frontend
- Dropped `occulto` dependency
- Package import changed from `cryptgeon/shared` to `@cryptgeon/shared`
- Notes created in v2 are not accessible from the v3 frontend
## Storage
- Cache storage format changed from JSON blobs to hashes with atomic `HINCRBY` for view counting
- The per-note lock (`lock.rs`) is removed — no longer needed
- Existing v2 notes in cache are **not migrated** and will be inaccessible after upgrade
- Ensure cache is empty (or flush) before deploying v3
+323
View File
@@ -0,0 +1,323 @@
# v3 Plan
> Status: **Draft** — agreed on architecture, schema open for iteration.
>
> See also: [v3 Breaking Changes](./v3-breaking-changes.md) for the upgrade guide.
## Goals
- **XChaCha20-Poly1305** for encryption (replaces AES/`occulto`)
- **MessagePack** for all API request/response bodies (replaces JSON)
- **LZ4 compression** for note payloads (client-side, before encryption — pure JS, no wasm)
- **Cache hashes** (valkey or redis, both speak RESP) for storage — replaces JSON-blob-per-key
- **Clean break** from v1 — no backward compatibility, no v1 routes
- Remove all Redis references (env vars, service names, docs) in favor of the generic "cache" naming, so operators can choose valkey or redis
- Shared TypeScript package as the single source of truth for crypto + API client + types
## Non-goals
- Keeping v1 alive alongside v3
- Changing the backend language/framework (stays Rust + axum)
- Changing storage backend (stays valkey or redis via the `redis` crate — no separate crate)
- Publishing `@cryptgeon/shared` as a standalone npm package (workspace-internal for now)
---
## 1. Shared package — `@cryptgeon/shared`
Location: `packages/shared` (currently empty).
ESM-only, TypeScript-only. Consumed by both `packages/cli` and `packages/frontend` via workspace dependency.
### Dependencies
- `@noble/ciphers` — XChaCha20-Poly1305
- `@noble/hashes` — scrypt
- `@msgpack/msgpack` — encode/decode
- `lz4js` — LZ4 compression (pure JS, no wasm)
- `ky` — HTTP client
### Structure
```
packages/shared/src/
index.ts # re-exports
crypto.ts # key derivation, encrypt, decrypt
compression.ts # LZ4 compress / decompress
types.ts # Note, NoteMetadata, FileDTO, Status, etc.
api.ts # high-level client: create, info, view, status
api.test.ts # tests
crypto.test.ts # tests
compression.test.ts # tests
```
### `crypto.ts`
- `deriveKey(password: string): Uint8Array` — scrypt, N=2^15, r=8, p=1, dkLen=32, fixed app-specific salt
- `generateKey(): Uint8Array` — `randomBytes(32)`
- `encrypt(data: Uint8Array, key: Uint8Array): Uint8Array` — `managedNonce(xchacha20poly1305)(key).encrypt(data)`
- `decrypt(ciphertext: Uint8Array, key: Uint8Array): Uint8Array` — `managedNonce(xchacha20poly1305)(key).decrypt(ciphertext)`
> **Note (carried over from msgpack branch):** the v2 stub had a bug — `decrypt` passed `key` as a second arg to `chacha.decrypt`, which only takes ciphertext. v3 must not repeat this.
### `compression.ts`
- `compress(data: Uint8Array): Uint8Array` — LZ4 block format
- `decompress(data: Uint8Array): Uint8Array` — LZ4 block format
Compression is a **client-only** concern. The server never sees or knows about compression — it stores the encrypted `data` blob as opaque bytes. The pipeline is:
```
msgpack encode → LZ4 compress → XChaCha20-Poly1305 encrypt
XChaCha20-Poly1305 decrypt → LZ4 decompress → msgpack decode
```
Compression runs on the plaintext (inner msgpack), never on ciphertext — encrypted data is high-entropy and incompressible. Always-on for v3 (all clients share the same package, no interop flag needed).
### `api.ts`
High-level client. All requests/responses are msgpack (`Content-Type: application/msgpack`). Methods:
- `setOptions({ server })` / `getOptions()`
- `create(note, key): Promise<{ id: string }>` — encodes msgpack, compresses (LZ4), encrypts, POST `/api/v3/notes/`
- `info(id): Promise<NoteInfo>` — GET `/api/v3/notes/{id}`, returns metadata only (no `data`)
- `view(id, key): Promise<NotePublic>` — DELETE `/api/v3/notes/{id}`, decrypts `data`, decompresses (LZ4), decodes msgpack
- `status(): Promise<Status>` — GET `/api/v3/status` (still JSON — server config, not note data)
---
## 2. Backend (Rust)
### 2.1 Storage — `store.rs` rewrite
Switch from JSON-blob-per-key to **cache hashes** (valkey or redis, both speak RESP):
```
Key: {CACHE_PREFIX}{id}
Fields:
views (i32) # remaining views, or absent
expiration (u32) # unix timestamp, or absent
type ("text"|"file")
derivation (msgpack bytes, optional) # scrypt salt+params if password-based
data (bytes) # encrypted msgpack blob
```
Functions:
- `set(id, note)` → `HSET` all fields + `EXPIRE` (if time-limited)
- `get_meta(id)` → `HMGET views expiration type derivation` — never touches `data` (cheap preview)
- `get_data(id)` → `HGET data` — only when consuming
- `decrement_view(id)` → `HINCRBY views -1` — **atomic**, see 2.2
- `del(id)` → `DEL`
- `can_reach_cache()` — health check (renamed from `can_reach_redis`)
Use `rmp-serde` for msgpack (de)serialization of note structs.
### 2.2 Remove `lock.rs`
The per-id `Mutex` map in `SharedState` existed only because the consume endpoint did non-atomic read-modify-write on `views`. With `HINCRBY` this is atomic at the cache level.
- Delete `packages/backend/src/lock.rs`
- Remove `SharedState` from `main.rs` (the `.with_state(shared_state)` call)
- Remove the lock map + `Arc`/`Mutex` imports
### 2.3 Rewrite `note/`
- `model.rs` — msgpack-compatible structs (derive `Serialize`/`Deserialize` for `rmp-serde`)
- `routes.rs` — three handlers:
#### `create` — `POST /api/v3/notes/`
- Accepts `application/msgpack` body (raw `Bytes`)
- Deserialize with rmp-serde
- Validate:
- At least one of `views`/`expiration` must be set
- `views` ≤ `MAX_VIEWS` and ≥ 1
- `expiration` ≤ `MAX_EXPIRATION` (minutes) and ≥ 1
- If `ALLOW_ADVANCED=false`: force `views=1, expiration=None`
- Store via `store::set`
- Return `{ id }` as msgpack
#### `preview` (info) — `GET /api/v3/notes/{id}`
- `store::get_meta(id)` — does not load `data`
- Return metadata as msgpack (no `data` field)
- `404` if not found
#### `view` (consume) — `DELETE /api/v3/notes/{id}`
- If `views` is set:
- `HINCRBY views -1` (atomic)
- If result ≤ 0: `HGET data`, `DEL` key, return data
- If result > 0: `HGET data`, return data (note survives for remaining views)
- If `views` is not set (time-only):
- `HGET data`, `DEL` key, return data
- Expiration handled lazily by cache (`EXPIRE` on the key) — no manual `if e < n` check on read
### 2.4 Config — `config.rs`
Rename:
- `REDIS` env → `CACHE`
- `REDIS_PREFIX` → `CACHE_PREFIX`
- `REDIS_CLIENT` static → `CACHE_CLIENT`
Everything else stays.
### 2.5 Health — `health/mod.rs`
- Rename `can_reach_redis` → `can_reach_cache`. Update panic message in `main.rs`.
- Move route from `/api/live` to `/healthz` (k8s standard). Not under `/api/v3/` — health checks are infrastructure, not API surface.
### 2.6 Status — `status/mod.rs`
Keep as JSON. It's server configuration, not note data — msgpack adds nothing. Frontend fetches once on load.
### 2.7 Dependencies — `Cargo.toml`
- Add `rmp-serde` (msgpack)
- Remove `serde_json` if no longer used (status endpoint still uses `Json<T>` which needs `serde_json` — keep)
- Keep `redis` crate (RESP client, works with valkey and redis)
---
## 3. "Both" constraint (views AND expiration)
New in v3: a note can have **both** `views` and `expiration` set simultaneously.
Implementation:
- `views` decremented via `HINCRBY views -1` on each consume
- `expiration` set via key-level `EXPIRE` (unix timestamp → seconds remaining)
- Whichever trips first removes the note:
- Views hit 0 → we `DEL` on the last consume
- Time expires → cache lazily removes the key
- No read-time expiration check needed in application code
---
## 4. Infra / docs cleanup
- `docker-compose.dev.yaml`: rename `redis` service → `cache` (image stays `valkey/valkey:7-alpine`, operators can swap for redis)
- `docker-compose.yaml` (if present): same
- `Dockerfile`: `ENV REDIS=...` → `ENV CACHE=...`
- `package.json` (root): `dev:docker` script service name
- `README.md`, `README_ES.md`, `README_zh-CN.md`, `CONTRIBUTING.md`, `CHANGELOG.md`, `examples/*` — replace "redis" with "cache" (or "valkey/redis" where context calls for naming the implementation)
- `Cryptgeon.postman_collection.json` — update content types to `application/msgpack`
- `.env.dev` — update `REDIS` → `CACHE` if present
- Healthcheck URLs: update all `/api/live` references → `/healthz` (docker-compose files, README, postman collection)
---
## 5. CLI (`packages/cli`)
- Drop `occulto` dependency
- Delete `packages/cli/src/shared/` (api.ts, adapters.ts, shared.ts) — replaced by `@cryptgeon/shared`
- `actions/upload.ts` and `actions/download.ts` call into `@cryptgeon/shared` API client
- Package still published as `cryptgeon` on npm
- `@cryptgeon/shared` stays workspace-internal (not published) for now
---
## 6. Frontend (`packages/frontend`)
- Drop `occulto` dependency
- Import from `@cryptgeon/shared` instead of `cryptgeon/shared`
- Update `package.json`: `"cryptgeon": "workspace:*"` → `"@cryptgeon/shared": "workspace:*"`
- Update files:
- `src/lib/views/Create.svelte`
- `src/lib/ui/ShowNote.svelte`
- `src/lib/ui/FileUpload.svelte`
- `src/lib/ui/PastedFilesPreview.svelte`
- `src/lib/ui/AdvancedParameters.svelte`
- `src/lib/stores/status.ts`
- `src/routes/note/[id]/+page.svelte`
---
## 7. msgpack note schema — "matrioshka" design
The server is **agnostic to the content**. It only sees an outer envelope with metadata and an opaque encrypted blob. The content type (text vs. files) lives inside the encrypted inner layer, invisible to the server.
### Outer layer (server-visible)
```
{
meta: {
expiration: u32? # optional, unix timestamp
views: u32? # optional, remaining view count
extra: bytes? # optional, client-opaque, size-limited
}
data: bytes # encrypted inner msgpack blob
}
```
- `meta.expiration` / `meta.views`: at least one must be set; both can be set simultaneously (see section 3)
- `meta.extra`: opaque client-owned data the server stores and returns verbatim in preview, but never interprets. Used for `derivation` (scrypt salt + params) so the client knows at preview time whether to prompt for a password. Size-limited (e.g. 512 bytes) to prevent abuse.
### Inner layer (encrypted, client-only)
Inside the encrypted `data` blob, after decryption, is a msgpack union:
```
# Text note
{ type: "text", data: string }
# File note
{ type: "files", data: [{ name: string, mime: string, data: bytes }] }
```
The server never sees this structure — it stores/retrieves `data` as opaque bytes.
The inner msgpack blob is **LZ4-compressed before encryption** (see `compression.ts`). Full client pipeline: `msgpack encode → lz4 compress → xchacha20poly1305 encrypt`, reversed on consume. The server is unaware of compression — it only ever handles the encrypted `data` bytes.
### Endpoints
#### `POST /api/v3/notes/` — create
**Request** (msgpack): outer layer `{ meta: { expiration?, views?, extra? }, data }`
**Response** (msgpack): `{ id: string }`
#### `GET /api/v3/notes/{id}` — preview / info
**Response** (msgpack): `{ meta: { expiration?, views?, extra? } }`
Returns metadata only — does not load `data` from cache. Client inspects `meta.extra` to determine key derivation strategy (password vs. URL-fragment key) before consuming.
#### `DELETE /api/v3/notes/{id}` — view / consume
**Response** (msgpack): `{ meta: { expiration?, views?, extra? }, data: bytes }`
Returns the full envelope. Client decrypts `data` using key derived from `meta.extra` (if present) or URL fragment, then decodes the inner msgpack to get text/files.
#### `GET /api/v3/status` — server config
**Response** (JSON, not msgpack): server configuration, not note data. Kept as JSON for simplicity.
### Valkey hash field layout
```
Key: {CACHE_PREFIX}{id}
Fields:
views (i32) # remaining views, or absent
expiration (u32) # unix timestamp, or absent
extra (bytes) # client-opaque, size-limited
data (bytes) # encrypted msgpack blob
```
`get_meta(id)` does `HMGET views expiration extra` — never touches `data`.
---
## 8. Implementation order
1. Shared package scaffolding (package.json, tsconfig, vitest config)
2. `crypto.ts` + tests
3. `compression.ts` + tests
4. `types.ts`
5. Backend: config rename + store rewrite + remove lock.rs
6. Backend: note routes rewrite (msgpack)
7. `api.ts` in shared (client) + tests
8. CLI rewrite (drop shared/, use @cryptgeon/shared)
9. Frontend migration
10. Infra/docs cleanup (cache rename, compose, Dockerfile)
11. Integration tests (playwright)
+9 -1
View File
@@ -2,7 +2,15 @@ version: '3.8'
services: services:
redis: redis:
image: redis:7-alpine image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
+9 -2
View File
@@ -108,8 +108,15 @@ networks:
services: services:
redis: redis:
image: redis:7-alpine image: valkey/valkey:7-alpine
restart: unless-stopped # This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
+58 -3
View File
@@ -2,7 +2,7 @@
Assumptions: Assumptions:
- Traefik 2 installed. - Traefik 2/3 installed.
- External proxy docker network `proxy`. - External proxy docker network `proxy`.
- A certificate resolver `le`. - A certificate resolver `le`.
- A https entrypoint `secure`. - A https entrypoint `secure`.
@@ -17,8 +17,15 @@ networks:
services: services:
redis: redis:
image: redis:7-alpine image: valkey/valkey:7-alpine
restart: unless-stopped # This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
app: app:
image: cupcakearmy/cryptgeon:latest image: cupcakearmy/cryptgeon:latest
@@ -34,3 +41,51 @@ services:
- traefik.http.routers.cryptgeon.entrypoints=secure - traefik.http.routers.cryptgeon.entrypoints=secure
- traefik.http.routers.cryptgeon.tls.certresolver=le - traefik.http.routers.cryptgeon.tls.certresolver=le
``` ```
## With basic auth
Some times it's useful to hide the service behind auth. This is easily achieved with traefik middleware. Many reverse proxies support similar features, so while traefik is used in this example, other reverse proxies can do the same.
```yaml
services:
traefik:
image: traefik:v3.0
command:
- "--api.insecure=true"
- "--providers.docker=true"
- "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80"
ports:
- "80:80"
volumes:
- "/var/run/docker.sock:/var/run/docker.sock:ro"
redis:
image: valkey/valkey:7-alpine
# This is required to stay in RAM only.
command: valkey-server --save "" --appendonly no
# Set a size limit. See link below on how to customise.
# https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
# --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
# This prevents the creation of an anonymous volume.
tmpfs:
- /data
cryptgeon:
image: cupcakearmy/cryptgeon
depends_on:
- redis
labels:
- "traefik.enable=true"
- "traefik.http.routers.cryptgeon.rule=Host(`cryptgeon.localhost`)"
- "traefik.http.routers.cryptgeon.entrypoints=web"
- "traefik.http.routers.cryptgeon.middlewares=cryptgeon-auth"
- "traefik.http.middlewares.cryptgeon-auth.basicauth.users=user:$$2y$$05$$juUw0zgc5ebvJ00MFPVVLujF6P.rcEMbGZ99Jfq6ZWEa1dgetacEq"
```
```bash
docker compose up -d
```
1. Open http://cryptgeon.localhost
2. Log in with `user` and `secret`
+11
View File
@@ -0,0 +1,11 @@
[tools]
pnpm = "11.5.0"
rust = "1.95"
watchexec = "latest"
# Node loaded below from .nvmrc
[settings]
idiomatic_version_file_enable_tools = ["node"]
[env]
SIZE_LIMIT = "100mb"
+11 -9
View File
@@ -1,21 +1,23 @@
{ {
"scripts": { "scripts": {
"dev:docker": "docker compose -f docker-compose.dev.yaml up redis", "dev:docker": "docker compose -f docker-compose.dev.yaml up cache",
"dev:packages": "pnpm --parallel run dev", "dev:packages": "pnpm --parallel run dev",
"dev": "run-p dev:*", "dev": "pnpm --parallel run /dev/",
"docker:up": "docker compose -f docker-compose.dev.yaml up", "docker:up": "docker compose -f docker-compose.dev.yaml up",
"docker:build": "docker compose -f docker-compose.dev.yaml build", "docker:build": "docker compose -f docker-compose.dev.yaml build",
"test": "playwright test --project=chrome --project=firefox --project=safari", "test": "playwright test --project=chrome --project=firefox --project=safari",
"test:local": "playwright test --project=chrome", "test:local": "playwright test --project=chrome",
"test:server": "run-s docker:up", "test:server": "docker compose -f docker-compose.dev.yaml up",
"test:prepare": "run-p build docker:build", "test:dl-browsers": "playwright install",
"test:prepare": "pnpm run build && pnpm run docker:build",
"build": "pnpm run --recursive --filter=!@cryptgeon/backend build" "build": "pnpm run --recursive --filter=!@cryptgeon/backend build"
}, },
"devDependencies": { "devDependencies": {
"@playwright/test": "^1.46.1", "@playwright/test": "^1.62.1",
"@types/node": "^22.5.0", "@types/node": "^24.13.3"
"npm-run-all": "^4.1.5",
"shelljs": "^0.8.5"
}, },
"packageManager": "pnpm@9.11.0" "packageManager": "pnpm@11.5.0",
"engines": {
"node": ">=22"
}
} }
+800 -428
View File
File diff suppressed because it is too large Load Diff
+11 -10
View File
@@ -1,9 +1,9 @@
[package] [package]
name = "cryptgeon" name = "cryptgeon"
version = "2.8.2" version = "3.0.0"
authors = ["cupcakearmy <hi@nicco.io>"] authors = ["cupcakearmy <hi@nicco.io>"]
edition = "2021" edition = "2024"
rust-version = "1.80" rust-version = "1.95"
[[bin]] [[bin]]
name = "cryptgeon" name = "cryptgeon"
@@ -11,17 +11,18 @@ path = "src/main.rs"
[dependencies] [dependencies]
# Core # Core
axum = "0.7.5" axum = "0.8"
serde = { version = "1.0.208", features = ["derive"] } serde = { version = "1", features = ["derive"] }
tokio = { version = "1.39.3", features = ["full"] } tokio = { version = "1", features = ["full"] }
tower = "0.5.0" tower = "0.5"
tower-http = { version = "0.5.2", features = ["full"] } tower-http = { version = "0.6", features = ["full"] }
redis = { version = "0.25.2", features = ["tls-native-tls"] } redis = { version = "1", features = ["tls-native-tls"] }
# Utility # Utility
serde_json = "1" serde_json = "1"
rmp-serde = "1"
lazy_static = "1" lazy_static = "1"
ring = "0.16" ring = "0.17"
bs62 = "0.1" bs62 = "0.1"
byte-unit = "4" byte-unit = "4"
dotenv = "0.15" dotenv = "0.15"
+1 -1
View File
@@ -2,7 +2,7 @@
"private": true, "private": true,
"name": "@cryptgeon/backend", "name": "@cryptgeon/backend",
"scripts": { "scripts": {
"dev": "cargo watch -x 'run --bin cryptgeon'", "dev": "watchexec -r -e rs cargo run",
"build": "cargo build --release", "build": "cargo build --release",
"test:server": "SIZE_LIMIT=10MiB LISTEN_ADDR=0.0.0.0:3000 cargo run", "test:server": "SIZE_LIMIT=10MiB LISTEN_ADDR=0.0.0.0:3000 cargo run",
"test:prepare": "cargo build" "test:prepare": "cargo build"
+20
View File
@@ -34,10 +34,26 @@ pub static ref ID_LENGTH: u32 = std::env::var("ID_LENGTH")
.unwrap_or("32".to_string()) .unwrap_or("32".to_string())
.parse() .parse()
.unwrap(); .unwrap();
pub static ref CACHE_PREFIX: String = std::env::var("CACHE_PREFIX")
.unwrap_or("".to_string())
.parse()
.unwrap();
pub static ref ALLOW_FILES: bool = std::env::var("ALLOW_FILES") pub static ref ALLOW_FILES: bool = std::env::var("ALLOW_FILES")
.unwrap_or("true".to_string()) .unwrap_or("true".to_string())
.parse() .parse()
.unwrap(); .unwrap();
pub static ref IMPRINT_URL: String = std::env::var("IMPRINT_URL")
.unwrap_or("".to_string())
.parse()
.unwrap();
pub static ref IMPRINT_HTML: String = std::env::var("IMPRINT_HTML")
.unwrap_or("".to_string())
.parse()
.unwrap();
pub static ref EXTRA_SIZE_LIMIT: usize = std::env::var("EXTRA_SIZE_LIMIT")
.unwrap_or("512".to_string())
.parse()
.unwrap();
} }
// THEME // THEME
@@ -62,4 +78,8 @@ lazy_static! {
.unwrap_or("true".to_string()) .unwrap_or("true".to_string())
.parse() .parse()
.unwrap(); .unwrap();
pub static ref THEME_HOME_LINK: bool = std::env::var("THEME_HOME_LINK")
.unwrap_or("true".to_string())
.parse()
.unwrap();
} }
+1 -1
View File
@@ -2,7 +2,7 @@ use crate::store;
use axum::http::StatusCode; use axum::http::StatusCode;
pub async fn report_health() -> (StatusCode,) { pub async fn report_health() -> (StatusCode,) {
if store::can_reach_redis() { if store::can_reach_cache() {
return (StatusCode::OK,); return (StatusCode::OK,);
} else { } else {
return (StatusCode::SERVICE_UNAVAILABLE,); return (StatusCode::SERVICE_UNAVAILABLE,);
+12 -10
View File
@@ -1,7 +1,7 @@
use axum::{ use axum::{
Router, ServiceExt,
extract::{DefaultBodyLimit, Request}, extract::{DefaultBodyLimit, Request},
routing::{delete, get, post}, routing::{delete, get, post},
Router, ServiceExt,
}; };
use dotenv::dotenv; use dotenv::dotenv;
use tower::Layer; use tower::Layer;
@@ -24,27 +24,29 @@ mod store;
async fn main() { async fn main() {
dotenv().ok(); dotenv().ok();
if !store::can_reach_redis() { if !store::can_reach_cache() {
println!("cannot reach redis"); println!("cannot reach cache");
panic!("canont reach redis"); panic!("cannot reach cache");
} }
let notes_routes = Router::new() let notes_routes = Router::new()
.route("/", post(note::create)) .route("/", post(note::create))
.route("/:id", delete(note::delete)) .route("/{id}", delete(note::view))
.route("/:id", get(note::preview)); .route("/{id}", get(note::preview));
let health_routes = Router::new().route("/live", get(health::report_health)); let health_routes = Router::new().route("/healthz", get(health::report_health));
let status_routes = Router::new().route("/status", get(status::get_status)); let status_routes = Router::new().route("/status", get(status::get_status));
let api_routes = Router::new() let v3_routes = Router::new()
.nest("/notes", notes_routes) .nest("/notes", notes_routes)
.nest("/", health_routes) .merge(status_routes);
.nest("/", status_routes);
let api_routes = Router::new().nest("/v3", v3_routes);
let index = format!("{}{}", config::FRONTEND_PATH.to_string(), "/index.html"); let index = format!("{}{}", config::FRONTEND_PATH.to_string(), "/index.html");
let serve_dir = let serve_dir =
ServeDir::new(config::FRONTEND_PATH.to_string()).not_found_service(ServeFile::new(index)); ServeDir::new(config::FRONTEND_PATH.to_string()).not_found_service(ServeFile::new(index));
let app = Router::new() let app = Router::new()
.nest("/api", api_routes) .nest("/api", api_routes)
.merge(health_routes)
.fallback_service(serve_dir) .fallback_service(serve_dir)
.layer(DefaultBodyLimit::max(*config::LIMIT)) .layer(DefaultBodyLimit::max(*config::LIMIT))
.layer( .layer(
+24 -11
View File
@@ -5,22 +5,35 @@ use serde::{Deserialize, Serialize};
use crate::config; use crate::config;
#[derive(Serialize, Deserialize, Clone)] #[derive(Serialize, Deserialize, Clone)]
pub struct Note { pub struct NoteMeta {
pub meta: String, #[serde(skip_serializing_if = "Option::is_none")]
pub contents: String,
pub views: Option<u32>, pub views: Option<u32>,
#[serde(skip_serializing_if = "Option::is_none")]
pub expiration: Option<u32>, pub expiration: Option<u32>,
#[serde(default)]
pub extra: Vec<u8>,
} }
#[derive(Serialize)] #[derive(Serialize, Deserialize, Clone)]
pub struct NoteInfo { pub struct CreateRequest {
pub meta: String, pub meta: NoteMeta,
pub data: Vec<u8>,
} }
#[derive(Serialize)] #[derive(Serialize, Deserialize)]
pub struct NotePublic { pub struct CreateResponse {
pub meta: String, pub id: String,
pub contents: String, }
#[derive(Serialize, Deserialize)]
pub struct MetaResponse {
pub meta: NoteMeta,
}
#[derive(Serialize, Deserialize)]
pub struct NoteResponse {
pub meta: NoteMeta,
pub data: Vec<u8>,
} }
pub fn generate_id() -> String { pub fn generate_id() -> String {
@@ -32,5 +45,5 @@ pub fn generate_id() -> String {
let _ = sr.fill(&mut id); let _ = sr.fill(&mut id);
result.push_str(&bs62::encode_data(&id)); result.push_str(&bs62::encode_data(&id));
} }
return result; result
} }
+98 -100
View File
@@ -2,145 +2,143 @@ use axum::{
extract::Path, extract::Path,
http::StatusCode, http::StatusCode,
response::{IntoResponse, Response}, response::{IntoResponse, Response},
Json, body::Bytes,
}; };
use serde::{Deserialize, Serialize}; use serde::Deserialize;
use std::time::SystemTime; use std::time::SystemTime;
use crate::config; use crate::note::{CreateRequest, generate_id};
use crate::note::{generate_id, Note, NoteInfo};
use crate::store; use crate::store;
use crate::config;
use super::NotePublic; use super::{CreateResponse, MetaResponse, NoteResponse, NoteMeta};
pub fn now() -> u32 { pub fn now() -> u64 {
SystemTime::now() SystemTime::now()
.duration_since(SystemTime::UNIX_EPOCH) .duration_since(SystemTime::UNIX_EPOCH)
.unwrap() .unwrap()
.as_secs() as u32 .as_secs()
} }
#[derive(Deserialize)] #[derive(Deserialize)]
pub struct OneNoteParams { pub struct NoteParams {
id: String, id: String,
} }
pub async fn preview(Path(OneNoteParams { id }): Path<OneNoteParams>) -> Response { pub async fn create(body: Bytes) -> Response {
let note = store::get(&id); let req: CreateRequest = match rmp_serde::from_slice(&body) {
Ok(r) => r,
Err(_) => return (StatusCode::BAD_REQUEST, "Invalid msgpack").into_response(),
};
match note { if req.meta.views.is_none() && req.meta.expiration.is_none() {
Ok(Some(n)) => (StatusCode::OK, Json(NoteInfo { meta: n.meta })).into_response(), return (StatusCode::BAD_REQUEST, "At least views or expiration must be set").into_response();
Ok(None) => (StatusCode::NOT_FOUND).into_response(),
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
} }
}
#[derive(Serialize, Deserialize)] if req.meta.extra.len() > *config::EXTRA_SIZE_LIMIT {
struct CreateResponse { return (StatusCode::BAD_REQUEST, "Extra data too large").into_response();
id: String,
}
pub async fn create(Json(mut n): Json<Note>) -> Response {
// let mut n = note.into_inner();
let id = generate_id();
// let bad_req = HttpResponse::BadRequest().finish();
if n.views == None && n.expiration == None {
return (
StatusCode::BAD_REQUEST,
"At least views or expiration must be set",
)
.into_response();
} }
let mut meta = req.meta;
if !*config::ALLOW_ADVANCED { if !*config::ALLOW_ADVANCED {
n.views = Some(1); meta.views = Some(1);
n.expiration = None; meta.expiration = None;
} }
match n.views {
match meta.views {
Some(v) => { Some(v) => {
if v > *config::MAX_VIEWS || v < 1 { if v > *config::MAX_VIEWS || v < 1 {
return (StatusCode::BAD_REQUEST, "Invalid views").into_response(); return (StatusCode::BAD_REQUEST, "Invalid views").into_response();
} }
n.expiration = None; // views overrides expiration
} }
_ => {} None => {}
} }
match n.expiration {
let expiration_ts = match meta.expiration {
Some(e) => { Some(e) => {
if e > *config::MAX_EXPIRATION || e < 1 { if e > *config::MAX_EXPIRATION || e < 1 {
return (StatusCode::BAD_REQUEST, "Invalid expiration").into_response(); return (StatusCode::BAD_REQUEST, "Invalid expiration").into_response();
} }
let expiration = now() + (e * 60); Some(now() + (e as u64 * 60))
n.expiration = Some(expiration); }
None => None,
};
let id = generate_id();
let views = meta.views.map(|v| v as i64);
match store::set(&id, &req.data, views, expiration_ts, &meta.extra) {
Ok(_) => {
let resp = CreateResponse { id };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
} }
_ => {}
}
match store::set(&id.clone(), &n.clone()) {
Ok(_) => (StatusCode::OK, Json(CreateResponse { id })).into_response(),
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(), Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
} }
} }
pub async fn delete(Path(OneNoteParams { id }): Path<OneNoteParams>) -> Response { pub async fn preview(Path(NoteParams { id }): Path<NoteParams>) -> Response {
let note = store::get(&id); match store::get_meta(&id) {
match note { Ok(Some((views, expiration, extra))) => {
// Err(e) => HttpResponse::InternalServerError().body(e.to_string()), let meta = NoteMeta {
// Ok(None) => return HttpResponse::NotFound().finish(), views: views.map(|v| v as u32),
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(), expiration: expiration.map(|e| e as u32),
extra,
};
let resp = MetaResponse { meta };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
}
Ok(None) => (StatusCode::NOT_FOUND).into_response(), Ok(None) => (StatusCode::NOT_FOUND).into_response(),
Ok(Some(note)) => { Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()).into_response(),
let mut changed = note.clone(); }
if changed.views == None && changed.expiration == None { }
return (StatusCode::BAD_REQUEST).into_response();
}
match changed.views {
Some(v) => {
changed.views = Some(v - 1);
let id = id.clone();
if v <= 1 {
match store::del(&id) {
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response();
}
_ => {}
}
} else {
match store::set(&id, &changed.clone()) {
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response();
}
_ => {}
}
}
}
_ => {}
}
let n = now(); pub async fn view(Path(NoteParams { id }): Path<NoteParams>) -> Response {
match changed.expiration { let (views, expiration, extra) = match store::get_meta(&id) {
Some(e) => { Ok(Some(v)) => v,
if e < n { _ => return (StatusCode::NOT_FOUND).into_response(),
match store::del(&id.clone()) { };
Ok(_) => return (StatusCode::BAD_REQUEST).into_response(),
Err(e) => {
return (StatusCode::INTERNAL_SERVER_ERROR, e.to_string())
.into_response()
}
}
}
}
_ => {}
}
return ( let has_views = views.is_some();
StatusCode::OK,
Json(NotePublic { if has_views {
contents: changed.contents, let remaining = match store::decrement_views(&id) {
meta: changed.meta, Ok(r) => r,
}), Err(_) => return (StatusCode::NOT_FOUND).into_response(),
) };
.into_response();
let data = match store::get_data(&id) {
Ok(Some(d)) => d,
_ => return (StatusCode::NOT_FOUND).into_response(),
};
if remaining <= 0 {
let _ = store::del(&id);
} }
let meta = NoteMeta {
views: Some(if remaining > 0 { remaining as u32 } else { 0 }),
expiration: expiration.map(|e| e as u32),
extra,
};
let resp = NoteResponse { meta, data };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
} else {
let data = match store::get_data(&id) {
Ok(Some(d)) => d,
_ => return (StatusCode::NOT_FOUND).into_response(),
};
let meta = NoteMeta {
views: None,
expiration: expiration.map(|e| e as u32),
extra,
};
let resp = NoteResponse { meta, data };
let bytes = rmp_serde::to_vec_named(&resp).unwrap();
(StatusCode::OK, Bytes::from(bytes)).into_response()
} }
} }
+6
View File
@@ -12,12 +12,15 @@ pub struct Status {
pub max_expiration: u32, pub max_expiration: u32,
pub allow_advanced: bool, pub allow_advanced: bool,
pub allow_files: bool, pub allow_files: bool,
pub imprint_url: String,
pub imprint_html: String,
// Theme // Theme
pub theme_image: String, pub theme_image: String,
pub theme_text: String, pub theme_text: String,
pub theme_page_title: String, pub theme_page_title: String,
pub theme_favicon: String, pub theme_favicon: String,
pub theme_new_note_notice: bool, pub theme_new_note_notice: bool,
pub theme_home_link: bool,
} }
pub async fn get_status() -> (StatusCode, Json<Status>) { pub async fn get_status() -> (StatusCode, Json<Status>) {
@@ -28,7 +31,10 @@ pub async fn get_status() -> (StatusCode, Json<Status>) {
max_expiration: *config::MAX_EXPIRATION, max_expiration: *config::MAX_EXPIRATION,
allow_advanced: *config::ALLOW_ADVANCED, allow_advanced: *config::ALLOW_ADVANCED,
allow_files: *config::ALLOW_FILES, allow_files: *config::ALLOW_FILES,
imprint_url: config::IMPRINT_URL.to_string(),
imprint_html: config::IMPRINT_HTML.to_string(),
theme_new_note_notice: *config::THEME_NEW_NOTE_NOTICE, theme_new_note_notice: *config::THEME_NEW_NOTE_NOTICE,
theme_home_link: *config::THEME_HOME_LINK,
theme_image: config::THEME_IMAGE.to_string(), theme_image: config::THEME_IMAGE.to_string(),
theme_text: config::THEME_TEXT.to_string(), theme_text: config::THEME_TEXT.to_string(),
theme_page_title: config::THEME_PAGE_TITLE.to_string(), theme_page_title: config::THEME_PAGE_TITLE.to_string(),
+63 -43
View File
@@ -1,63 +1,83 @@
use redis;
use redis::Commands; use redis::Commands;
use crate::note::now; use crate::config;
use crate::note::Note;
lazy_static! { lazy_static! {
static ref REDIS_CLIENT: String = std::env::var("REDIS") static ref CACHE_URL: String = std::env::var("CACHE")
.unwrap_or("redis://127.0.0.1/".to_string()) .unwrap_or("redis://127.0.0.1/".to_string())
.parse() .parse()
.unwrap(); .unwrap();
} }
fn get_connection() -> Result<redis::Connection, &'static str> { fn prefixed(id: &str) -> String {
format!("{}{}", config::CACHE_PREFIX.as_str(), id)
}
fn conn() -> Result<redis::Connection, &'static str> {
let client = let client =
redis::Client::open(REDIS_CLIENT.to_string()).map_err(|_| "Unable to connect to redis")?; redis::Client::open(CACHE_URL.to_string()).map_err(|_| "Unable to connect to cache")?;
client client.get_connection().map_err(|_| "Unable to connect to cache")
.get_connection()
.map_err(|_| "Unable to connect to redis")
} }
pub fn can_reach_redis() -> bool { pub fn can_reach_cache() -> bool {
let conn = get_connection(); conn().is_ok()
return match conn {
Ok(_) => true,
Err(_) => false,
};
} }
pub fn set(id: &String, note: &Note) -> Result<(), &'static str> { pub fn set(id: &str, data: &[u8], views: Option<i64>, expiration: Option<u64>, extra: &[u8]) -> Result<(), &'static str> {
let serialized = serde_json::to_string(&note.clone()).unwrap(); let key = prefixed(id);
let mut conn = get_connection()?; let mut c = conn()?;
conn.set(id, serialized) c.hset::<_, _, _, ()>(&key, "data", data).map_err(|_| "Unable to set note")?;
.map_err(|_| "Unable to set note in redis")?; c.hset::<_, _, _, ()>(&key, "extra", extra).map_err(|_| "Unable to set note")?;
match note.expiration {
Some(e) => {
let seconds = e - now();
conn.expire(id, seconds as i64)
.map_err(|_| "Unable to set expiration on notion")?
}
None => {}
};
Ok(())
}
pub fn get(id: &String) -> Result<Option<Note>, &'static str> { if let Some(v) = views {
let mut conn = get_connection()?; c.hset::<_, _, _, ()>(&key, "views", v).map_err(|_| "Unable to set note")?;
let value: Option<String> = conn.get(id).map_err(|_| "Could not load note in redis")?; }
match value { if let Some(e) = expiration {
None => return Ok(None), let now = std::time::SystemTime::now()
Some(s) => { .duration_since(std::time::UNIX_EPOCH)
let deserialize: Note = serde_json::from_str(&s).unwrap(); .unwrap()
return Ok(Some(deserialize)); .as_secs();
} let ttl = e.saturating_sub(now);
c.expire::<_, ()>(&key, ttl as i64).map_err(|_| "Unable to set expiration")?;
} }
}
pub fn del(id: &String) -> Result<(), &'static str> { Ok(())
let mut conn = get_connection()?; }
conn.del(id).map_err(|_| "Unable to delete note in redis")?;
pub fn get_meta(id: &str) -> Result<Option<(Option<i64>, Option<u64>, Vec<u8>)>, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let exists: bool = c.exists::<_, bool>(&key).map_err(|_| "Cache error")?;
if !exists {
return Ok(None);
}
let views: Option<i64> = c.hget::<_, _, Option<i64>>(&key, "views").map_err(|_| "Cache error")?;
let expiration: Option<u64> = c.hget::<_, _, Option<u64>>(&key, "expiration").map_err(|_| "Cache error")?;
let extra: Vec<u8> = c.hget::<_, _, Vec<u8>>(&key, "extra").unwrap_or_default();
Ok(Some((views, expiration, extra)))
}
pub fn get_data(id: &str) -> Result<Option<Vec<u8>>, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let data: Option<Vec<u8>> = c.hget::<_, _, Option<Vec<u8>>>(&key, "data").map_err(|_| "Cache error")?;
Ok(data)
}
pub fn decrement_views(id: &str) -> Result<i64, &'static str> {
let key = prefixed(id);
let mut c = conn()?;
let result: i64 = c.hincr::<_, _, _, i64>(&key, "views", -1).map_err(|_| "Cache error")?;
Ok(result)
}
pub fn del(id: &str) -> Result<(), &'static str> {
let key = prefixed(id);
let mut c = conn()?;
c.del::<_, ()>(&key).map_err(|_| "Unable to delete note")?;
Ok(()) Ok(())
} }
-15
View File
@@ -1,15 +0,0 @@
import { build } from 'tsup'
import pkg from './package.json' with { type: 'json' }
const watch = process.argv.slice(2)[0] === '--watch'
await build({
entry: ['src/index.ts', 'src/cli.ts', 'src/shared/shared.ts'],
dts: true,
minify: true,
format: ['esm', 'cjs'],
target: 'es2020',
clean: true,
define: { VERSION: `"${pkg.version}"` },
watch,
})
+20 -22
View File
@@ -1,6 +1,6 @@
{ {
"name": "cryptgeon", "name": "cryptgeon",
"version": "2.8.2", "version": "3.0.0",
"homepage": "https://github.com/cupcakearmy/cryptgeon", "homepage": "https://github.com/cupcakearmy/cryptgeon",
"repository": { "repository": {
"type": "git", "type": "git",
@@ -9,39 +9,37 @@
}, },
"type": "module", "type": "module",
"exports": { "exports": {
".": "./dist/index.js", ".": "./dist/index.mjs"
"./shared": {
"import": "./dist/shared/shared.js",
"types": "./dist/shared/shared.d.ts"
}
}, },
"types": "./dist/index.d.ts", "types": "./dist/index.d.mts",
"bin": { "bin": {
"cryptgeon": "./dist/cli.cjs" "cryptgeon": "./dist/cli.mjs"
}, },
"files": [ "files": [
"dist" "dist"
], ],
"scripts": { "scripts": {
"bin": "run-s build package", "build": "vp pack",
"build": "tsc && node build.js", "dev": "vp pack --watch",
"dev": "node build.js --watch",
"prepublishOnly": "run-s build" "prepublishOnly": "run-s build"
}, },
"devDependencies": { "dependencies": {
"@cryptgeon/shared": "workspace:*",
"@msgpack/msgpack": "^3.1.3",
"@commander-js/extra-typings": "^12.1.0", "@commander-js/extra-typings": "^12.1.0",
"@types/inquirer": "^9.0.7", "inquirer": "^9.3.8",
"@types/mime": "^4.0.0", "mime": "^4.1.0",
"@types/node": "^20.11.24", "pretty-bytes": "^6.1.1"
},
"devDependencies": {
"@tsconfig/strictest": "catalog:",
"@types/inquirer": "^9.0.9",
"@types/node": "^22.15.3",
"commander": "^12.1.0", "commander": "^12.1.0",
"inquirer": "^9.2.15", "typescript": "catalog:",
"mime": "^4.0.1", "vite-plus": "catalog:"
"occulto": "^2.0.6",
"pretty-bytes": "^6.1.1",
"tsup": "^8.2.4",
"typescript": "^5.3.3"
}, },
"engines": { "engines": {
"node": ">=18" "node": ">=22"
} }
} }
+33 -45
View File
@@ -1,51 +1,43 @@
import inquirer from 'inquirer' import inquirer from 'inquirer'
import { access, constants, writeFile } from 'node:fs/promises' import { access, constants, writeFile } from 'node:fs/promises'
import { basename, resolve } from 'node:path' import { basename, resolve } from 'node:path'
import { AES, Hex } from 'occulto' import { decode } from '@msgpack/msgpack'
import pretty from 'pretty-bytes' import pretty from 'pretty-bytes'
import { Adapters } from '../shared/adapters.js' import { decrypt, deriveKey, setServer, info, get, decompress } from '@cryptgeon/shared'
import { API } from '../shared/api.js'
export async function download(url: URL, all: boolean, suggestedPassword?: string) { export async function download(url: URL, all: boolean, suggestedPassword?: string) {
API.setOptions({ server: url.origin }) setServer(url.origin)
const id = url.pathname.split('/')[2] const id = url.pathname.split('/')[2]
const preview = await API.info(id).catch(() => { if (!id) throw new Error('Invalid URL')
throw new Error('Note does not exist or is expired') const meta = await info(id)
}) if (!meta) throw new Error('Note does not exist or is expired')
// Password let key: Uint8Array
let password: string if (meta.extra && meta.extra.length > 0) {
const derivation = preview?.meta.derivation
if (derivation) {
if (suggestedPassword) { if (suggestedPassword) {
password = suggestedPassword const derivation = decode(meta.extra) as any
key = deriveKey(suggestedPassword, new Uint8Array(derivation.salt))
} else { } else {
const response = await inquirer.prompt([ const response = await inquirer.prompt([
{ { type: 'password', message: 'Note password', name: 'password' },
type: 'password',
message: 'Note password',
name: 'password',
},
]) ])
password = response.password const derivation = decode(meta.extra) as any
key = deriveKey(response.password, new Uint8Array(derivation.salt))
} }
} else { } else {
password = url.hash.slice(1) const hex = url.hash.slice(1)
key = new Uint8Array(Buffer.from(hex, 'hex'))
} }
const key = derivation ? (await AES.derive(password, derivation))[0] : Hex.decode(password) const note = await get(id)
const note = await API.get(id) if (!note) throw new Error('Could not load note')
const couldNotDecrypt = new Error('Could not decrypt note. Probably an invalid password') const decrypted = decrypt(note.data, key)
switch (note.meta.type) { const content = decode(decompress(decrypted)) as any
case 'file':
const files = await Adapters.Files.decrypt(note.contents, key).catch(() => {
throw couldNotDecrypt
})
if (!files) {
throw new Error('No files found in note')
}
switch (content.type) {
case 'files':
const files: { name: string; data: Uint8Array }[] = content.data
let selected: typeof files let selected: typeof files
if (all) { if (all) {
selected = files selected = files
@@ -55,36 +47,32 @@ export async function download(url: URL, all: boolean, suggestedPassword?: strin
type: 'checkbox', type: 'checkbox',
message: 'What files should be saved?', message: 'What files should be saved?',
name: 'names', name: 'names',
choices: files.map((file) => ({ choices: files.map((f) => ({
value: file.name, value: f.name,
name: `${file.name} - ${file.type} - ${pretty(file.size, { binary: true })}`, name: `${f.name} - ${pretty(f.data.length, { binary: true })}`,
checked: true, checked: true,
})), })),
}, },
]) ])
selected = files.filter((file) => names.includes(file.name)) selected = files.filter((f) => names.includes(f.name))
} }
if (!selected.length) throw new Error('No files selected') if (!selected.length) throw new Error('No files selected')
await Promise.all( await Promise.all(
selected.map(async (file) => { selected.map(async (f) => {
let filename = resolve(file.name) let filename = resolve(f.name)
try { try {
// If exists -> prepend timestamp to not overwrite the current file
await access(filename, constants.R_OK) await access(filename, constants.R_OK)
filename = resolve(`${Date.now()}-${file.name}`) filename = resolve(`${Date.now()}-${f.name}`)
} catch {} } catch {}
await writeFile(filename, file.contents) await writeFile(filename, f.data)
console.log(`Saved: ${basename(filename)}`) console.log(`Saved: ${basename(filename)}`)
}) })
) )
break break
case 'text': case 'text':
const plaintext = await Adapters.Text.decrypt(note.contents, key).catch(() => { console.log(content.data)
throw couldNotDecrypt
})
console.log(plaintext)
break break
default:
throw new Error('Unknown content type')
} }
} }
+30 -33
View File
@@ -1,46 +1,43 @@
import { readFile, stat } from 'node:fs/promises' import { readFile } from 'node:fs/promises'
import { basename } from 'node:path' import { basename } from 'node:path'
import { encode } from '@msgpack/msgpack'
import mime from 'mime' import mime from 'mime'
import { AES, Hex } from 'occulto' import { encrypt, generateKey, deriveKey, randomBytes, getServer, create, compress } from '@cryptgeon/shared'
import { Adapters } from '../shared/adapters.js'
import { API, FileDTO, Note, NoteMeta } from '../shared/api.js'
export type UploadOptions = Pick<Note, 'views' | 'expiration'> & { password?: string } export type UploadOptions = { views?: number; expiration?: number; password?: string }
export async function upload(input: string | string[], options: UploadOptions): Promise<string> { export async function upload(input: string | string[], options: UploadOptions): Promise<string> {
const { password, ...noteOptions } = options const { password, ...noteOptions } = options
const derived = options.password ? await AES.derive(options.password) : undefined
const key = derived ? derived[0] : await AES.generateKey()
let contents: string let key: Uint8Array
let type: NoteMeta['type'] let extra = new Uint8Array()
if (typeof input === 'string') { if (password) {
contents = await Adapters.Text.encrypt(input, key) const salt = randomBytes(16)
type = 'text' key = deriveKey(password, salt)
extra = encode({ salt, N: 32768, r: 8, p: 1 })
} else { } else {
const files: FileDTO[] = await Promise.all( key = generateKey()
input.map(async (path) => {
const data = new Uint8Array(await readFile(path))
const stats = await stat(path)
const extension = path.substring(path.indexOf('.') + 1)
const type = mime.getType(extension) ?? 'application/octet-stream'
return {
name: basename(path),
size: stats.size,
contents: data,
type,
} satisfies FileDTO
})
)
contents = await Adapters.Files.encrypt(files, key)
type = 'file'
} }
// Create the actual note and upload it. let inner: Uint8Array
const note: Note = { ...noteOptions, contents, meta: { type, derivation: derived?.[1] } } if (typeof input === 'string') {
const result = await API.create(note) inner = encode({ type: 'text', data: input })
let url = `${API.getOptions().server}/note/${result.id}` } else {
if (!derived) url += `#${Hex.encode(key)}` const files = await Promise.all(
input.map(async (path) => {
const data = new Uint8Array(await readFile(path))
const extension = path.substring(path.indexOf('.') + 1)
const type = mime.getType(extension) ?? 'application/octet-stream'
return { name: basename(path), mime: type, size: data.length, data }
})
)
inner = encode({ type: 'files', data: files })
}
const data = encrypt(compress(inner), key)
const result = await create({ meta: { ...noteOptions, extra }, data })
let url = `${getServer()}/note/${result.id}`
if (!password) url += `#${Buffer.from(key).toString('hex')}`
return url return url
} }
+21 -15
View File
@@ -5,7 +5,7 @@ import prettyBytes from 'pretty-bytes'
import { download } from './actions/download.js' import { download } from './actions/download.js'
import { upload } from './actions/upload.js' import { upload } from './actions/upload.js'
import { API } from './shared/api.js' import { setServer, status } from '@cryptgeon/shared'
import { parseFile, parseNumber } from './utils/parsers.js' import { parseFile, parseNumber } from './utils/parsers.js'
import { getStdin } from './utils/stdin.js' import { getStdin } from './utils/stdin.js'
import { checkConstrains, exit } from './utils/utils.js' import { checkConstrains, exit } from './utils/utils.js'
@@ -21,7 +21,8 @@ const views = new Option('-v --views <number>', 'Amount of views before getting
const minutes = new Option('-m --minutes <number>', 'Minutes before the note expires').argParser(parseNumber) const minutes = new Option('-m --minutes <number>', 'Minutes before the note expires').argParser(parseNumber)
// Node 18 guard // Node 18 guard
parseInt(process.version.slice(1).split(',')[0]) < 18 && exit('Node 18 or higher is required') const major = Number(process.version.slice(1).split('.')[0])
if (!Number.isFinite(major) || major < 18) exit('Node 18 or higher is required')
// @ts-ignore // @ts-ignore
const version: string = VERSION const version: string = VERSION
@@ -33,15 +34,12 @@ program
.description('show information about the server') .description('show information about the server')
.addOption(server) .addOption(server)
.action(async (options) => { .action(async (options) => {
API.setOptions({ server: options.server }) setServer(options.server!)
const response = await API.status() const response = await status()
const formatted = { const formatted = Object.fromEntries(
...response, Object.entries({ ...response, max_size: prettyBytes(response.max_size) })
max_size: prettyBytes(response.max_size), .filter(([key]) => !key.startsWith('theme_'))
} )
for (const key of Object.keys(formatted)) {
if (key.startsWith('theme_')) delete formatted[key as keyof typeof formatted]
}
console.table(formatted) console.table(formatted)
}) })
@@ -54,11 +52,15 @@ send
.addOption(minutes) .addOption(minutes)
.addOption(password) .addOption(password)
.action(async (files, options) => { .action(async (files, options) => {
API.setOptions({ server: options.server }) setServer(options.server!)
await checkConstrains(options) await checkConstrains(options)
options.password ||= await getStdin() options.password ||= await getStdin()
try { try {
const url = await upload(files, { views: options.views, expiration: options.minutes, password: options.password }) const url = await upload(files, {
...(options.views !== undefined ? { views: options.views } : {}),
...(options.minutes !== undefined ? { expiration: options.minutes } : {}),
password: options.password,
})
console.log(`Note created:\n\n${url}`) console.log(`Note created:\n\n${url}`)
} catch { } catch {
exit('Could not create note') exit('Could not create note')
@@ -72,11 +74,15 @@ send
.addOption(minutes) .addOption(minutes)
.addOption(password) .addOption(password)
.action(async (text, options) => { .action(async (text, options) => {
API.setOptions({ server: options.server }) setServer(options.server!)
await checkConstrains(options) await checkConstrains(options)
options.password ||= await getStdin() options.password ||= await getStdin()
try { try {
const url = await upload(text, { views: options.views, expiration: options.minutes, password: options.password }) const url = await upload(text, {
...(options.views !== undefined ? { views: options.views } : {}),
...(options.minutes !== undefined ? { expiration: options.minutes } : {}),
password: options.password,
})
console.log(`Note created:\n\n${url}`) console.log(`Note created:\n\n${url}`)
} catch { } catch {
exit('Could not create note') exit('Could not create note')
-2
View File
@@ -1,4 +1,2 @@
export * from './actions/download.js' export * from './actions/download.js'
export * from './actions/upload.js' export * from './actions/upload.js'
export * from './shared/adapters.js'
export * from './shared/api.js'
-61
View File
@@ -1,61 +0,0 @@
import { AES, Bytes, type TypedArray } from 'occulto'
import type { EncryptedFileDTO, FileDTO } from './api'
abstract class CryptAdapter<T> {
abstract encrypt(plaintext: T, key: TypedArray): Promise<string>
abstract decrypt(ciphertext: string, key: TypedArray): Promise<T>
}
class CryptTextAdapter implements CryptAdapter<string> {
async encrypt(plaintext: string, key: TypedArray) {
return await AES.encrypt(Bytes.encode(plaintext), key)
}
async decrypt(ciphertext: string, key: TypedArray) {
return Bytes.decode(await AES.decrypt(ciphertext, key))
}
}
class CryptBlobAdapter implements CryptAdapter<TypedArray> {
async encrypt(plaintext: TypedArray, key: TypedArray) {
return await AES.encrypt(plaintext, key)
}
async decrypt(ciphertext: string, key: TypedArray) {
return await AES.decrypt(ciphertext, key)
// const plaintext = await AES.decrypt(ciphertext, key)
// return new Blob([plaintext], { type: 'application/octet-stream' })
}
}
class CryptFilesAdapter implements CryptAdapter<FileDTO[]> {
async encrypt(plaintext: FileDTO[], key: TypedArray) {
const adapter = new CryptBlobAdapter()
const data: Promise<EncryptedFileDTO>[] = plaintext.map(async (file) => ({
name: file.name,
size: file.size,
type: file.type,
contents: await adapter.encrypt(file.contents, key),
}))
return JSON.stringify(await Promise.all(data))
}
async decrypt(ciphertext: string, key: TypedArray) {
const adapter = new CryptBlobAdapter()
const data: EncryptedFileDTO[] = JSON.parse(ciphertext)
const files: FileDTO[] = await Promise.all(
data.map(async (file) => ({
name: file.name,
size: file.size,
type: file.type,
contents: await adapter.decrypt(file.contents, key),
}))
)
return files
}
}
export const Adapters = {
Text: new CryptTextAdapter(),
Blob: new CryptBlobAdapter(),
Files: new CryptFilesAdapter(),
}
-138
View File
@@ -1,138 +0,0 @@
import type { KeyData, TypedArray } from 'occulto'
export type NoteMeta = {
type: 'text' | 'file'
derivation?: KeyData
}
export type Note = {
contents: string
meta: NoteMeta
views?: number
expiration?: number
}
export type NoteInfo = Pick<Note, 'meta'>
export type NotePublic = Pick<Note, 'contents' | 'meta'>
export type NoteCreate = Omit<Note, 'meta'> & { meta: string }
export type FileDTO = Pick<File, 'name' | 'size' | 'type'> & {
contents: TypedArray
}
export type EncryptedFileDTO = Omit<FileDTO, 'contents'> & {
contents: string
}
type ClientOptions = {
server: string
}
type CallOptions = {
url: string
method: string
body?: any
}
export class PayloadToLargeError extends Error {}
export let client: ClientOptions = {
server: '',
}
function setOptions(options: Partial<ClientOptions>) {
client = { ...client, ...options }
}
function getOptions(): ClientOptions {
return client
}
async function call(options: CallOptions) {
const url = client.server + '/api/' + options.url
const response = await fetch(url, {
method: options.method,
body: options.body === undefined ? undefined : JSON.stringify(options.body),
mode: 'cors',
headers: {
'Content-Type': 'application/json',
},
})
if (!response.ok) {
if (response.status === 413) throw new PayloadToLargeError()
else throw new Error('API call failed')
}
return response.json()
}
async function create(note: Note) {
const { meta, ...rest } = note
const body: NoteCreate = {
...rest,
meta: JSON.stringify(meta),
}
const data = await call({
url: 'notes/',
method: 'post',
body,
})
return data as { id: string }
}
async function get(id: string): Promise<NotePublic> {
const data = await call({
url: `notes/${id}`,
method: 'delete',
})
const { contents, meta } = data
const note = {
contents,
meta: JSON.parse(meta),
} satisfies NotePublic
if (note.meta.derivation) note.meta.derivation.salt = new Uint8Array(Object.values(note.meta.derivation.salt))
return note
}
async function info(id: string): Promise<NoteInfo> {
const data = await call({
url: `notes/${id}`,
method: 'get',
})
const { meta } = data
const note = {
meta: JSON.parse(meta),
} satisfies NoteInfo
if (note.meta.derivation) note.meta.derivation.salt = new Uint8Array(Object.values(note.meta.derivation.salt))
return note
}
export type Status = {
version: string
max_size: number
max_views: number
max_expiration: number
allow_advanced: boolean
allow_files: boolean
theme_image: string
theme_text: string
theme_favicon: string
theme_page_title: string
theme_new_note_notice: boolean
}
async function status() {
const data = await call({
url: 'status/',
method: 'get',
})
return data as Status
}
export const API = {
setOptions,
getOptions,
create,
get,
info,
status,
}
-2
View File
@@ -1,2 +0,0 @@
export * from './adapters.js'
export * from './api.js'
+7 -9
View File
@@ -1,5 +1,5 @@
import { exit as exitNode } from 'node:process' import { exit as exitNode } from 'node:process'
import { API } from '../shared/api.js' import { status } from '@cryptgeon/shared'
export function exit(message: string) { export function exit(message: string) {
console.error(message) console.error(message)
@@ -7,13 +7,11 @@ export function exit(message: string) {
} }
export async function checkConstrains(constrains: { views?: number; minutes?: number }) { export async function checkConstrains(constrains: { views?: number; minutes?: number }) {
const { views, minutes } = constrains if (!constrains.views && !constrains.minutes) constrains.views = 1
if (views && minutes) exit('cannot set view and minutes constrains simultaneously')
if (!views && !minutes) constrains.views = 1
const response = await API.status() const response = await status()
if (views && views > response.max_views) if (constrains.views && constrains.views > response.max_views)
exit(`Only a maximum of ${response.max_views} views allowed. ${views} given.`) exit(`Only a maximum of ${response.max_views} views allowed. ${constrains.views} given.`)
if (minutes && minutes > response.max_expiration) if (constrains.minutes && constrains.minutes > response.max_expiration)
exit(`Only a maximum of ${response.max_expiration} minutes allowed. ${minutes} given.`) exit(`Only a maximum of ${response.max_expiration} minutes allowed. ${constrains.minutes} given.`)
} }
+5 -4
View File
@@ -1,13 +1,14 @@
{ {
"extends": "@tsconfig/strictest/tsconfig.json",
"compilerOptions": { "compilerOptions": {
"target": "es2022", "target": "esnext",
"module": "es2022", "module": "esnext",
"moduleResolution": "Bundler", "moduleResolution": "Bundler",
"declaration": true, "declaration": true,
"emitDeclarationOnly": true, "emitDeclarationOnly": true,
"strict": true,
"outDir": "./dist", "outDir": "./dist",
"rootDir": "./src", "rootDir": "./src",
"allowSyntheticDefaultImports": true "allowSyntheticDefaultImports": true
} },
"exclude": ["vite.config.ts"]
} }
+14
View File
@@ -0,0 +1,14 @@
import { defineConfig } from "vite-plus";
import pkg from "./package.json" with { type: "json" };
export default defineConfig({
pack: {
entry: ["src/index.ts", "src/cli.ts"],
dts: true,
minify: true,
format: ["esm"],
target: "es2023",
deps: { alwaysBundle: ["**"] },
define: { VERSION: JSON.stringify(pkg.version) },
},
});
+15 -6
View File
@@ -1,8 +1,17 @@
├─ MIT: 13 ├─ MIT: 324
├─ ISC: 2 ├─ ISC: 84
├─ BSD-3-Clause: 1 ├─ Apache-2.0: 21
├─ (MPL-2.0 OR Apache-2.0): 1 ├─ BlueOak-1.0.0: 14
├─ BSD-2-Clause: 1 ├─ BSD-3-Clause: 6
├─ BSD-2-Clause: 4
├─ OFL-1.1: 1
├─ Python-2.0: 1
├─ CC-BY-4.0: 1
├─ UNKNOWN: 1
├─ MPL-2.0: 1
├─ CC-BY-3.0: 1
├─ CC0-1.0: 1
├─ (MIT AND CC-BY-3.0): 1
├─ 0BSD: 1 ├─ 0BSD: 1
└─ Apache-2.0: 1 └─ (MIT OR CC0-1.0): 1
1 ├─ MIT: 13 ├─ MIT: 324
2 ├─ ISC: 2 ├─ ISC: 84
3 ├─ BSD-3-Clause: 1 ├─ Apache-2.0: 21
4 ├─ (MPL-2.0 OR Apache-2.0): 1 ├─ BlueOak-1.0.0: 14
5 ├─ BSD-2-Clause: 1 ├─ BSD-3-Clause: 6
6 ├─ BSD-2-Clause: 4
7 ├─ OFL-1.1: 1
8 ├─ Python-2.0: 1
9 ├─ CC-BY-4.0: 1
10 ├─ UNKNOWN: 1
11 ├─ MPL-2.0: 1
12 ├─ CC-BY-3.0: 1
13 ├─ CC0-1.0: 1
14 ├─ (MIT AND CC-BY-3.0): 1
15 ├─ 0BSD: 1 ├─ 0BSD: 1
16 └─ Apache-2.0: 1 └─ (MIT OR CC0-1.0): 1
17
+61
View File
@@ -0,0 +1,61 @@
{
"common": {
"note": "poznámka",
"file": "soubor",
"advanced": "pokročilé",
"create": "vytvořit",
"loading": "načítání",
"mode": "režim",
"views": "{n, plural, =0 {zobrazení} =1 {1 zobrazení} other {# zobrazení}}",
"minutes": "{n, plural, =0 {minut} =1 {1 minuta} other {# minutách}}",
"max": "max",
"share_link": "sdílet odkaz",
"copy_clipboard": "zkopírovat do schránky",
"copied_to_clipboard": "zkopírováno do schránky",
"encrypting": "šifrování",
"decrypting": "dešifrování",
"uploading": "nahrávání",
"downloading": "stahování",
"qr_code": "QR kód",
"password": "heslo"
},
"home": {
"intro": "Jednoduše posílejte <i>plně šifrované</i> a zabezpečené poznámky nebo soubory jediným kliknutím. Stačí vytvořit poznámku a sdílet odkaz.",
"explanation": "Poznámka vyprší a bude zničena po {n}.",
"new_note": "Nová poznámka",
"new_note_notice": "<b>Dostupnost:</b><br />Poznámka není zaručeně uchována, protože je uložena pouze v paměti RAM. Pokud se paměť zaplní, nejstarší poznámky budou automaticky smazány.<br />(Obvykle to nebývá problém, ale je dobré o tom vědět.)",
"errors": {
"note_too_big": "Poznámku nelze vytvořit. Je příliš velká.",
"note_error": "Poznámku nelze vytvořit. Zkuste to prosím znovu.",
"max": "Max: {n}",
"empty_content": "Poznámka je prázdná."
},
"messages": {
"note_created": "Poznámka byla vytvořena."
},
"advanced": {
"explanation": "Ve výchozím nastavení se pro každou poznámku generuje bezpečné heslo. Pokud chcete, můžete si nastavit vlastní heslo, které nebude součástí odkazu.",
"custom_password": "Vlastní heslo"
},
"pasting": "Vkládání...",
"pasted_files": "Vložené soubory",
"remove": "Odstranit"
},
"show": {
"errors": {
"not_found": "Poznámka nebyla nalezena nebo již byla smazána.",
"decryption_failed": "Špatné heslo. Nelze dešifrovat. Odkaz je pravděpodobně poškozen. Poznámka byla zničena.",
"unsupported_type": "Nepodporovaný typ poznámky."
},
"explanation": "Klikněte níže pro zobrazení a následné smazání poznámky, pokud bylo dosaženo limitu zobrazení.",
"show_note": "Zobrazit poznámku",
"warning_will_not_see_again": "Tuto poznámku již <b>nebudete</b> moci znovu zobrazit.",
"download_all": "Stáhnout vše",
"links_found": "Odkazy nalezené v poznámce:"
},
"file_upload": {
"selected_files": "Vybrané soubory",
"no_files_selected": "Žádné soubory nevybrány",
"clear": "Vymazat"
}
}
+5 -2
View File
@@ -25,7 +25,7 @@
"new_note": "Neue Notiz", "new_note": "Neue Notiz",
"new_note_notice": "<b>Wichtiger Hinweis zur Verfügbarkeit:</b><br />Es kann nicht garantiert werden, dass diese Notiz gespeichert wird, da diese <b>ausschließlich im Speicher</b> gehalten werden. Ist dieser voll, werden die ältesten Notizen entfernt.<br />(Wahrscheinlich gibt es keine derartigen Probleme, seien Sie nur vorgewarnt).", "new_note_notice": "<b>Wichtiger Hinweis zur Verfügbarkeit:</b><br />Es kann nicht garantiert werden, dass diese Notiz gespeichert wird, da diese <b>ausschließlich im Speicher</b> gehalten werden. Ist dieser voll, werden die ältesten Notizen entfernt.<br />(Wahrscheinlich gibt es keine derartigen Probleme, seien Sie nur vorgewarnt).",
"errors": { "errors": {
"note_to_big": "Notiz konnte nicht erstellt werden, da sie zu groß ist.", "note_too_big": "Notiz konnte nicht erstellt werden, da sie zu groß ist.",
"note_error": "Notiz konnte nicht erstellt werden. Bitte versuchen Sie es erneut.", "note_error": "Notiz konnte nicht erstellt werden. Bitte versuchen Sie es erneut.",
"max": "max: {n}", "max": "max: {n}",
"empty_content": "Notiz ist leer." "empty_content": "Notiz ist leer."
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "Standardmäßig wird für jede Notiz ein generiertes, sicheres Passwort verwendet. Alternativ können Sie ein eigenes Kennwort festlegen, welches nicht im Link enthalten ist.", "explanation": "Standardmäßig wird für jede Notiz ein generiertes, sicheres Passwort verwendet. Alternativ können Sie ein eigenes Kennwort festlegen, welches nicht im Link enthalten ist.",
"custom_password": "Benutzerdefiniertes Passwort" "custom_password": "Benutzerdefiniertes Passwort"
} },
"pasting": "Einfügen...",
"pasted_files": "Eingefügte Dateien",
"remove": "Entfernen"
}, },
"show": { "show": {
"errors": { "errors": {
+5 -2
View File
@@ -25,7 +25,7 @@
"new_note": "new note", "new_note": "new note",
"new_note_notice": "<b>availability:</b><br />the note is not guaranteed to be stored as everything is kept in ram, if it fills up the oldest notes will be removed.<br />(you probably will be fine, just be warned.)", "new_note_notice": "<b>availability:</b><br />the note is not guaranteed to be stored as everything is kept in ram, if it fills up the oldest notes will be removed.<br />(you probably will be fine, just be warned.)",
"errors": { "errors": {
"note_to_big": "could not create note. note is too big", "note_too_big": "could not create note. note is too big",
"note_error": "could not create note. please try again.", "note_error": "could not create note. please try again.",
"max": "max: {n}", "max": "max: {n}",
"empty_content": "note is empty." "empty_content": "note is empty."
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "By default, a securely generated password is used for each note. You can however also choose your own password, which is not included in the link.", "explanation": "By default, a securely generated password is used for each note. You can however also choose your own password, which is not included in the link.",
"custom_password": "custom password" "custom_password": "custom password"
} },
"pasting": "Pasting...",
"pasted_files": "Pasted Files",
"remove": "Remove"
}, },
"show": { "show": {
"errors": { "errors": {
+5 -2
View File
@@ -25,7 +25,7 @@
"new_note": "nueva nota", "new_note": "nueva nota",
"new_note_notice": "<b>disponibilidad:</b><br />no se garantiza que la nota se almacene, ya que todo se guarda en la memoria RAM, si se llena se eliminarán las notas más antiguas.<br />(probablemente estará bien, solo está advertido.)", "new_note_notice": "<b>disponibilidad:</b><br />no se garantiza que la nota se almacene, ya que todo se guarda en la memoria RAM, si se llena se eliminarán las notas más antiguas.<br />(probablemente estará bien, solo está advertido.)",
"errors": { "errors": {
"note_to_big": "no se pudo crear la nota. la nota es demasiado grande", "note_too_big": "no se pudo crear la nota. la nota es demasiado grande",
"note_error": "No se ha podido crear la nota. Por favor, inténtelo de nuevo.", "note_error": "No se ha podido crear la nota. Por favor, inténtelo de nuevo.",
"max": "max: {n}", "max": "max: {n}",
"empty_content": "la nota está vacía." "empty_content": "la nota está vacía."
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "Por defecto, se utiliza una contraseña generada de forma segura para cada nota. No obstante, también puede elegir su propia contraseña, la cual no se incluye en el enlace.", "explanation": "Por defecto, se utiliza una contraseña generada de forma segura para cada nota. No obstante, también puede elegir su propia contraseña, la cual no se incluye en el enlace.",
"custom_password": "contraseña personalizada" "custom_password": "contraseña personalizada"
} },
"pasting": "Pegando...",
"pasted_files": "Archivos pegados",
"remove": "Eliminar"
}, },
"show": { "show": {
"errors": { "errors": {
+5 -2
View File
@@ -25,7 +25,7 @@
"new_note": "nouvelle note", "new_note": "nouvelle note",
"new_note_notice": "<b>disponibilité :</b><br />il n'est pas garanti que la note reste stockée car tout est conservé dans la mémoire vive; si elle se remplit, les notes les plus anciennes seront supprimées.<br />(tout ira probablement bien, soyez juste averti.)", "new_note_notice": "<b>disponibilité :</b><br />il n'est pas garanti que la note reste stockée car tout est conservé dans la mémoire vive; si elle se remplit, les notes les plus anciennes seront supprimées.<br />(tout ira probablement bien, soyez juste averti.)",
"errors": { "errors": {
"note_to_big": "Impossible de créer une note. La note est trop grande.", "note_too_big": "Impossible de créer une note. La note est trop grande.",
"note_error": "n'a pas pu créer de note. Veuillez réessayer.", "note_error": "n'a pas pu créer de note. Veuillez réessayer.",
"max": "max: {n}", "max": "max: {n}",
"empty_content": "La note est vide." "empty_content": "La note est vide."
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "Par défaut, un mot de passe généré de manière sécurisée est utilisé pour chaque note. Vous pouvez toutefois choisir votre propre mot de passe, qui n'est pas inclus dans le lien.", "explanation": "Par défaut, un mot de passe généré de manière sécurisée est utilisé pour chaque note. Vous pouvez toutefois choisir votre propre mot de passe, qui n'est pas inclus dans le lien.",
"custom_password": "mot de passe personnalisé" "custom_password": "mot de passe personnalisé"
} },
"pasting": "Collage...",
"pasted_files": "Fichiers collés",
"remove": "Supprimer"
}, },
"show": { "show": {
"errors": { "errors": {
+6 -3
View File
@@ -5,7 +5,7 @@
"advanced": "avanzato", "advanced": "avanzato",
"create": "crea", "create": "crea",
"loading": "carica", "loading": "carica",
"mode": "modalita", "mode": "modalità",
"views": "{n, plural, =0 {viste} =1 {1 vista} other {# viste}}", "views": "{n, plural, =0 {viste} =1 {1 vista} other {# viste}}",
"minutes": "{n, plural, =0 {minuti} =1 {1 minuto} other {# minuti}}", "minutes": "{n, plural, =0 {minuti} =1 {1 minuto} other {# minuti}}",
"max": "max", "max": "max",
@@ -25,7 +25,7 @@
"new_note": "nuova nota", "new_note": "nuova nota",
"new_note_notice": "<b>disponibilità:</b><br />la nota non è garantita per essere memorizzata come tutto è tenuto in ram, se si riempie le note più vecchie saranno rimosse.<br />(probabilmente andrà bene, basta essere avvertiti).", "new_note_notice": "<b>disponibilità:</b><br />la nota non è garantita per essere memorizzata come tutto è tenuto in ram, se si riempie le note più vecchie saranno rimosse.<br />(probabilmente andrà bene, basta essere avvertiti).",
"errors": { "errors": {
"note_to_big": "impossibile creare una nota. la nota è troppo grande", "note_too_big": "impossibile creare una nota. la nota è troppo grande",
"note_error": "Impossibile creare la nota. Riprova.", "note_error": "Impossibile creare la nota. Riprova.",
"max": "max: {n}", "max": "max: {n}",
"empty_content": "la nota è vuota." "empty_content": "la nota è vuota."
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "Per impostazione predefinita, per ogni nota viene utilizzata una password generata in modo sicuro. È tuttavia possibile scegliere la propria password, che non è inclusa nel link.", "explanation": "Per impostazione predefinita, per ogni nota viene utilizzata una password generata in modo sicuro. È tuttavia possibile scegliere la propria password, che non è inclusa nel link.",
"custom_password": "password personalizzata" "custom_password": "password personalizzata"
} },
"pasting": "Incollando...",
"pasted_files": "File incollati",
"remove": "Rimuovi"
}, },
"show": { "show": {
"errors": { "errors": {
+7 -4
View File
@@ -17,7 +17,7 @@
"uploading": "アップロード中", "uploading": "アップロード中",
"downloading": "ダウンロード中", "downloading": "ダウンロード中",
"qr_code": "QRコード", "qr_code": "QRコード",
"password": "暗号" "password": "パスワード"
}, },
"home": { "home": {
"intro": "<i>完全に暗号化された</i> 、安全なメモやファイルをワンクリックで簡単に送信できます。メモを作成してリンクを共有するだけです。", "intro": "<i>完全に暗号化された</i> 、安全なメモやファイルをワンクリックで簡単に送信できます。メモを作成してリンクを共有するだけです。",
@@ -25,7 +25,7 @@
"new_note": "新しいメモ", "new_note": "新しいメモ",
"new_note_notice": "<b>可用性: </b> <br />すべてが RAM に保持されるため、メモが保存されるとは限りません。いっぱいになると、最も古いメモが削除されます。 <br /> (大丈夫だと思いますが、ご了承ください。)", "new_note_notice": "<b>可用性: </b> <br />すべてが RAM に保持されるため、メモが保存されるとは限りません。いっぱいになると、最も古いメモが削除されます。 <br /> (大丈夫だと思いますが、ご了承ください。)",
"errors": { "errors": {
"note_to_big": "メモを作成できませんでした。メモが大きすぎる", "note_too_big": "メモを作成できませんでした。メモが大きすぎる",
"note_error": "メモを作成できませんでした。もう一度お試しください。", "note_error": "メモを作成できませんでした。もう一度お試しください。",
"max": "最大ファイルサイズ: {n}", "max": "最大ファイルサイズ: {n}",
"empty_content": "メモは空です。" "empty_content": "メモは空です。"
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "デフォルトでは、安全に生成されたパスワードが各ノートに使用されます。しかし、リンクに含まれない独自のパスワードを選択することもできます。", "explanation": "デフォルトでは、安全に生成されたパスワードが各ノートに使用されます。しかし、リンクに含まれない独自のパスワードを選択することもできます。",
"custom_password": "カスタムパスワード" "custom_password": "カスタムパスワード"
} },
"pasting": "貼り付け中...",
"pasted_files": "貼り付けたファイル",
"remove": "削除"
}, },
"show": { "show": {
"errors": { "errors": {
@@ -46,7 +49,7 @@
}, },
"explanation": "カウンターが上限に達した場合、ノートの表示と削除を行うには、以下をクリックします。", "explanation": "カウンターが上限に達した場合、ノートの表示と削除を行うには、以下をクリックします。",
"show_note": "メモを表示", "show_note": "メモを表示",
"warning_will_not_see_again": "あなた <b>できません</b> このノートをもう一度見る", "warning_will_not_see_again": "このノートを再度表示することは<b>できません</b>",
"download_all": "すべてダウンロード", "download_all": "すべてダウンロード",
"links_found": "メモ内にあるリンク:" "links_found": "メモ内にあるリンク:"
}, },
+8 -5
View File
@@ -6,8 +6,8 @@
"create": "utwórz", "create": "utwórz",
"loading": "ładowanie", "loading": "ładowanie",
"mode": "tryb", "mode": "tryb",
"views": "{n, plural, =0 {wyświetleń} =1 {1 wyświetlenie} other {# wyświetleń}}", "views": "{n, plural, =0 {wyświetleń} =1 {1 wyświetlenie} other {{n} wyświetleń}}",
"minutes": "{n, plural, =0 {minut} =1 {1 minuta} other {# minuty}}", "minutes": "{n, plural, =0 {minut} =1 {1 minuta} other {{n} minuty}}",
"max": "maks.", "max": "maks.",
"share_link": "link udostępniania", "share_link": "link udostępniania",
"copy_clipboard": "kopiuj do schowka", "copy_clipboard": "kopiuj do schowka",
@@ -25,9 +25,9 @@
"new_note": "nowa notatka", "new_note": "nowa notatka",
"new_note_notice": "<b>dostępność:</b><br />nie ma gwarancji, że notatka będzie przechowywana, ponieważ wszystko jest przechowywane w pamięci RAM, jeśli się zapełni, najstarsze notatki zostaną usunięte.<br />(prawdopodobnie nic się nie stanie, ale warto ostrzec.)", "new_note_notice": "<b>dostępność:</b><br />nie ma gwarancji, że notatka będzie przechowywana, ponieważ wszystko jest przechowywane w pamięci RAM, jeśli się zapełni, najstarsze notatki zostaną usunięte.<br />(prawdopodobnie nic się nie stanie, ale warto ostrzec.)",
"errors": { "errors": {
"note_to_big": "nie można utworzyć notatki. notatka jest za duża", "note_too_big": "nie można utworzyć notatki. notatka jest za duża",
"note_error": "nie można utworzyć notatki. spróbuj ponownie.", "note_error": "nie można utworzyć notatki. spróbuj ponownie.",
"max": "maks .: {n}", "max": "maks.: {n}",
"empty_content": "notatka jest pusta." "empty_content": "notatka jest pusta."
}, },
"messages": { "messages": {
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "Domyślnie dla każdej notatki używane jest bezpiecznie wygenerowane hasło. Możesz jednak wybrać własne hasło, które nie jest uwzględnione w linku.", "explanation": "Domyślnie dla każdej notatki używane jest bezpiecznie wygenerowane hasło. Możesz jednak wybrać własne hasło, które nie jest uwzględnione w linku.",
"custom_password": "własne hasło" "custom_password": "własne hasło"
} },
"pasting": "Wklejanie...",
"pasted_files": "Wklejone pliki",
"remove": "Usuń"
}, },
"show": { "show": {
"errors": { "errors": {
+59 -56
View File
@@ -1,58 +1,61 @@
{ {
"common": { "common": {
"note": "заметка", "note": "заметка",
"file": "файл", "file": "файл",
"advanced": "расширенные", "advanced": "расширенные",
"create": "создать", "create": "создать",
"loading": "загрузка", "loading": "загрузка",
"mode": "режим", "mode": "режим",
"views": "{n, plural, =0 {просмотры} =1 {1 просмотр} other {# просмотры}}", "views": "{n, plural, =0 {просмотры} =1 {1 просмотр} other {# просмотры}}",
"minutes": "{n, plural, =0 {минут} =1 {1 минута} other {# минуты}}", "minutes": "{n, plural, =0 {минут} =1 {1 минута} other {# минуты}}",
"max": "макс", "max": "макс",
"share_link": "поделиться ссылкой", "share_link": "поделиться ссылкой",
"copy_clipboard": "скопировать в буфер обмена", "copy_clipboard": "скопировать в буфер обмена",
"copied_to_clipboard": "скопировано в буфер обмена", "copied_to_clipboard": "скопировано в буфер обмена",
"encrypting": "шифрование", "encrypting": "шифрование",
"decrypting": "расшифровка", "decrypting": "расшифровка",
"uploading": "загрузка", "uploading": "загрузка",
"downloading": "скачивание", "downloading": "скачивание",
"qr_code": "qr код", "qr_code": "qr код",
"password": "пароль" "password": "пароль"
}, },
"home": { "home": {
"intro": "Легко отправляйте <i>полностью зашифрованные</i> защищенные заметки или файлы одним щелчком мыши. Просто создайте заметку и поделитесь ссылкой.", "intro": "Легко отправляйте <i>полностью зашифрованные</i> защищенные заметки или файлы одним щелчком мыши. Просто создайте заметку и поделитесь ссылкой.",
"explanation": "заметка истечет и будет уничтожена после {type}.", "explanation": "заметка истечет и будет уничтожена после {type}.",
"new_note": "новая заметка", "new_note": "новая заметка",
"new_note_notice": "<b>доступность:</b><br />сохранение заметки не гарантируется, поскольку все хранится в оперативной памяти; если она заполнится, самые старые заметки будут удалены.<br />( вероятно, все будет в порядке, просто будьте осторожны.)", "new_note_notice": "<b>доступность:</b><br />сохранение заметки не гарантируется, поскольку все хранится в оперативной памяти; если она заполнится, самые старые заметки будут удалены.<br />( вероятно, все будет в порядке, просто будьте осторожны.)",
"errors": { "errors": {
"note_to_big": "нельзя создать новую заметку. заметка слишком большая", "note_too_big": "нельзя создать новую заметку. заметка слишком большая",
"note_error": "нельзя создать новую заметку. пожалйста попробуйте позднее.", "note_error": "нельзя создать новую заметку. пожалуйста попробуйте позже.",
"max": "макс: {n}", "max": "макс: {n}",
"empty_content": "пустая заметка." "empty_content": "пустая заметка."
}, },
"messages": { "messages": {
"note_created": "заметка создана." "note_created": "заметка создана."
}, },
"advanced": { "advanced": {
"explanation": "По умолчанию для каждой заметки используется безопасно сгенерированный пароль. Однако вы также можете выбрать свой собственный пароль, который не включен в ссылку.", "explanation": "По умолчанию для каждой заметки используется безопасно сгенерированный пароль. Однако вы также можете выбрать свой собственный пароль, который не включен в ссылку.",
"custom_password": "пользовательский пароль" "custom_password": "пользовательский пароль"
} },
}, "pasting": "Вставка...",
"show": { "pasted_files": "Вставленные файлы",
"errors": { "remove": "Удалить"
"not_found": "заметка не найдена или была удалена.", },
"decryption_failed": "неправильный пароль. не смог расшифровать. возможно ссылка битая. записка уничтожена.", "show": {
"unsupported_type": "неподдерживаемый тип заметки." "errors": {
}, "not_found": "заметка не найдена или была удалена.",
"explanation": "щелкните ниже, чтобы показать и удалить примечание, если счетчик достиг предела", "decryption_failed": "неправильный пароль. не смог расшифровать. возможно ссылка битая. заметка уничтожена.",
"show_note": "показать заметку", "unsupported_type": "неподдерживаемый тип заметки."
"warning_will_not_see_again": "вы <b>не сможете</b> больше просмотреть заметку.", },
"download_all": "скачать всё", "explanation": "щелкните ниже, чтобы показать и удалить заметку, если счетчик достиг предела",
"links_found": "ссылки внутри заметки:" "show_note": "показать заметку",
}, "warning_will_not_see_again": "вы <b>не сможете</b> больше просмотреть заметку.",
"file_upload": { "download_all": "скачать всё",
"selected_files": "Выбранные файлы", "links_found": "ссылки внутри заметки:"
"no_files_selected": "Файлы не выбраны", },
"clear": "Сброс" "file_upload": {
} "selected_files": "Выбранные файлы",
"no_files_selected": "Файлы не выбраны",
"clear": "Сброс"
}
} }
+61
View File
@@ -0,0 +1,61 @@
{
"common": {
"note": "筆記",
"file": "檔案",
"advanced": "進階",
"create": "創建",
"loading": "載入中",
"mode": "模式",
"views": "{n, plural, =0 {瀏覽次數} =1 {1 次瀏覽} other {# 次瀏覽}}",
"minutes": "{n, plural, =0 {分鐘} =1 {1 分鐘} other {# 分鐘}}",
"max": "最大",
"share_link": "分享連結",
"copy_clipboard": "複製到剪貼板",
"copied_to_clipboard": "已複製到剪貼板",
"encrypting": "加密中",
"decrypting": "解密中",
"uploading": "上傳中",
"downloading": "下載中",
"qr_code": "QR 碼",
"password": "密碼"
},
"home": {
"intro": "輕鬆地以一鍵傳送<i>完全加密</i>的安全筆記或檔案。只需創建筆記並分享連結。",
"explanation": "筆記將在 {type} 後過期並被銷毀。",
"new_note": "新筆記",
"new_note_notice": "<b>可用性:</b><br />筆記不保證被儲存,因為所有內容都保留在 RAM 中,如果 RAM 填滿,最舊的筆記將被移除。<br />(您可能會沒事,只是提醒一下。)",
"errors": {
"note_too_big": "無法創建筆記。筆記過大",
"note_error": "無法創建筆記。請再試一次。",
"max": "最大值:{n}",
"empty_content": "筆記內容為空。"
},
"messages": {
"note_created": "筆記已創建。"
},
"advanced": {
"explanation": "預設情況下,每個筆記都會使用安全生成的密碼。您也可以選擇自己的密碼,該密碼不會包含在連結中。",
"custom_password": "自定義密碼"
},
"pasting": "正在粘貼...",
"pasted_files": "粘貼的檔案",
"remove": "移除"
},
"show": {
"errors": {
"not_found": "筆記未找到或已被刪除。",
"decryption_failed": "密碼錯誤。無法解密。可能是連結已損壞。筆記已被銷毀。",
"unsupported_type": "不支持的筆記類型。"
},
"explanation": "如果計數器達到限制,請點擊下方以顯示並刪除筆記",
"show_note": "顯示筆記",
"warning_will_not_see_again": "您將<b>無法</b>再次查看筆記。",
"download_all": "全部下載",
"links_found": "在筆記中找到的連結:"
},
"file_upload": {
"selected_files": "已選擇的檔案",
"no_files_selected": "未選擇檔案",
"clear": "重置"
}
}
+5 -2
View File
@@ -25,7 +25,7 @@
"new_note": "新建密信", "new_note": "新建密信",
"new_note_notice": "<b>提醒:</b><br>密信保存在内存中,如果内存满了,则最早的密信将被删除以释放内存,因此不保证该密信的可用性。一般不会出现这种情况,无需担心。", "new_note_notice": "<b>提醒:</b><br>密信保存在内存中,如果内存满了,则最早的密信将被删除以释放内存,因此不保证该密信的可用性。一般不会出现这种情况,无需担心。",
"errors": { "errors": {
"note_to_big": "创建失败,密信过大。", "note_too_big": "创建失败,密信过大。",
"note_error": "创建失败,请稍后重试。", "note_error": "创建失败,请稍后重试。",
"max": "次数上限:{n}", "max": "次数上限:{n}",
"empty_content": "密信不能为空。" "empty_content": "密信不能为空。"
@@ -36,7 +36,10 @@
"advanced": { "advanced": {
"explanation": "默认情况下,每个笔记都使用安全生成的密码。但是,您也可以选择您自己的密码,该密码未包含在链接中。", "explanation": "默认情况下,每个笔记都使用安全生成的密码。但是,您也可以选择您自己的密码,该密码未包含在链接中。",
"custom_password": "自定义密码" "custom_password": "自定义密码"
} },
"pasting": "正在粘贴...",
"pasted_files": "粘贴的文件",
"remove": "移除"
}, },
"show": { "show": {
"errors": { "errors": {
+15 -19
View File
@@ -7,31 +7,27 @@
"build": "vite build", "build": "vite build",
"preview": "vite preview", "preview": "vite preview",
"check": "svelte-check --tsconfig tsconfig.json", "check": "svelte-check --tsconfig tsconfig.json",
"licenses": "license-checker --summary > licenses.csv", "licenses": "license-checker-rseidelsohn --summary > licenses.csv",
"locale:download": "node scripts/locale.js",
"test:prepare": "pnpm run build" "test:prepare": "pnpm run build"
}, },
"type": "module", "type": "module",
"devDependencies": { "devDependencies": {
"@lokalise/node-api": "^12.1.0", "@sveltejs/adapter-static": "^3.0.10",
"@sveltejs/adapter-static": "^3.0.1", "@sveltejs/kit": "^2.61.1",
"@sveltejs/kit": "^2.5.2", "@sveltejs/vite-plugin-svelte": "^7.1.2",
"@sveltejs/vite-plugin-svelte": "^3.0.2", "@zerodevx/svelte-toast": "^0.9.6",
"@zerodevx/svelte-toast": "^0.9.5", "license-checker-rseidelsohn": "^5.0.1",
"adm-zip": "^0.5.10", "svelte": "^5.55.9",
"dotenv": "^16.4.5", "svelte-check": "^4.4.8",
"svelte": "^4.2.12",
"svelte-check": "^3.6.6",
"svelte-intl-precompile": "^0.12.3", "svelte-intl-precompile": "^0.12.3",
"tslib": "^2.6.2", "tslib": "^2.8.1",
"typescript": "^5.3.3", "typescript": "^6.0.3",
"vite": "^5.1.7" "vite": "^8.0.14"
}, },
"dependencies": { "dependencies": {
"cryptgeon": "workspace:*", "@cryptgeon/shared": "workspace:*",
"@fontsource/fira-mono": "^5.0.8", "@fontsource/fira-mono": "^5.2.7",
"occulto": "^2.0.6", "pretty-bytes": "^7.1.0",
"pretty-bytes": "^6.1.1", "uqr": "^0.1.3"
"qrious": "^4.0.2"
} }
} }
-59
View File
@@ -1,59 +0,0 @@
import { LokaliseApi } from '@lokalise/node-api'
import AdmZip from 'adm-zip'
import dotenv from 'dotenv'
import https from 'https'
dotenv.config()
function exit(msg) {
console.error(msg)
process.exit(1)
}
const apiKey = process.env.LOKALISE_API_KEY
const project_id = process.env.LOKALISE_PROJECT
if (!apiKey) exit('No API Key set for Lokalize! Set with "LOKALISE_API_KEY"')
if (!project_id) exit('No project id set for Lokalize! Set with "LOKALISE_PROJECT"')
const client = new LokaliseApi({ apiKey })
const WGet = (url) =>
new Promise((done) => {
https
.get(url, (res) => {
const data = []
res
.on('data', (chunk) => {
data.push(chunk)
})
.on('end', () => {
let buffer = Buffer.concat(data)
done(buffer)
})
})
.on('error', (err) => {
console.log('download error:', err)
})
})
async function download() {
// For details see: https://app.lokalise.com/api2docs/curl/#transition-download-files-post
const download = await client.files().download(project_id, {
format: 'json',
indentation: 'tab',
json_unescaped_slashes: true,
original_filenames: false,
bundle_structure: '%LANG_ISO%.%FORMAT%',
export_sort: 'first_added',
export_empty_as: 'skip',
add_newline_eof: true,
replace_breaks: false,
})
const buffered = await WGet(download.bundle_url)
const zip = new AdmZip(buffered)
zip.extractAllTo('./locales', true)
}
download().catch((e) => {
console.error(e)
process.exit(1)
})
@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512" <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"
><title>Contrast</title><path ><title>Contrast</title><path
d="M256 32C132.29 32 32 132.29 32 256s100.29 224 224 224 224-100.29 224-224S379.71 32 256 32zM128.72 383.28A180 180 0 01256 76v360a178.82 178.82 0 01-127.28-52.72z" d="M256 32C132.29 32 32 132.29 32 256s100.29 224 224 224 224-100.29 224-224S379.71 32 256 32zM128.72 383.28A180 180 0 01256 76v360a178.82 178.82 0 01-127.28-52.72z"

Before

Width:  |  Height:  |  Size: 287 B

After

Width:  |  Height:  |  Size: 316 B

@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512" <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"
><title>Copy</title><path ><title>Copy</title><path
d="M456 480H136a24 24 0 01-24-24V128a16 16 0 0116-16h328a24 24 0 0124 24v320a24 24 0 01-24 24z" d="M456 480H136a24 24 0 01-24-24V128a16 16 0 0116-16h328a24 24 0 0124 24v320a24 24 0 01-24 24z"

Before

Width:  |  Height:  |  Size: 325 B

After

Width:  |  Height:  |  Size: 354 B

@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512" <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"
><title>Dice</title><path ><title>Dice</title><path
d="M48 366.92L240 480V284L48 170zM192 288c8.84 0 16 10.75 16 24s-7.16 24-16 24-16-10.75-16-24 7.16-24 16-24zm-96 32c8.84 0 16 10.75 16 24s-7.16 24-16 24-16-10.75-16-24 7.16-24 16-24zM272 284v196l192-113.08V170zm48 140c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm0-88c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm96 32c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm0-88c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm32 77.64zM256 32L64 144l192 112 192-112zm0 120c-13.25 0-24-7.16-24-16s10.75-16 24-16 24 7.16 24 16-10.75 16-24 16z" d="M48 366.92L240 480V284L48 170zM192 288c8.84 0 16 10.75 16 24s-7.16 24-16 24-16-10.75-16-24 7.16-24 16-24zm-96 32c8.84 0 16 10.75 16 24s-7.16 24-16 24-16-10.75-16-24 7.16-24 16-24zM272 284v196l192-113.08V170zm48 140c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm0-88c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm96 32c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm0-88c-8.84 0-16-10.75-16-24s7.16-24 16-24 16 10.75 16 24-7.16 24-16 24zm32 77.64zM256 32L64 144l192 112 192-112zm0 120c-13.25 0-24-7.16-24-16s10.75-16 24-16 24 7.16 24 16-10.75 16-24 16z"

Before

Width:  |  Height:  |  Size: 736 B

After

Width:  |  Height:  |  Size: 765 B

@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512" <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"
><title>Eye</title><circle cx="256" cy="256" r="64" /><path ><title>Eye</title><circle cx="256" cy="256" r="64" /><path
d="M394.82 141.18C351.1 111.2 304.31 96 255.76 96c-43.69 0-86.28 13-126.59 38.48C88.52 160.23 48.67 207 16 256c26.42 44 62.56 89.24 100.2 115.18C159.38 400.92 206.33 416 255.76 416c49 0 95.85-15.07 139.3-44.79C433.31 345 469.71 299.82 496 256c-26.38-43.43-62.9-88.56-101.18-114.82zM256 352a96 96 0 1196-96 96.11 96.11 0 01-96 96z" d="M394.82 141.18C351.1 111.2 304.31 96 255.76 96c-43.69 0-86.28 13-126.59 38.48C88.52 160.23 48.67 207 16 256c26.42 44 62.56 89.24 100.2 115.18C159.38 400.92 206.33 416 255.76 416c49 0 95.85-15.07 139.3-44.79C433.31 345 469.71 299.82 496 256c-26.38-43.43-62.9-88.56-101.18-114.82zM256 352a96 96 0 1196-96 96.11 96.11 0 01-96 96z"

Before

Width:  |  Height:  |  Size: 483 B

After

Width:  |  Height:  |  Size: 512 B

@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512" <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"
><title>Eye Off</title><path ><title>Eye Off</title><path
d="M63.998 86.004l21.998-21.998L448 426.01l-21.998 21.998zM259.34 192.09l60.57 60.57a64.07 64.07 0 00-60.57-60.57zM252.66 319.91l-60.57-60.57a64.07 64.07 0 0060.57 60.57z" d="M63.998 86.004l21.998-21.998L448 426.01l-21.998 21.998zM259.34 192.09l60.57 60.57a64.07 64.07 0 00-60.57-60.57zM252.66 319.91l-60.57-60.57a64.07 64.07 0 0060.57 60.57z"

Before

Width:  |  Height:  |  Size: 732 B

After

Width:  |  Height:  |  Size: 761 B

+20 -3
View File
@@ -1,8 +1,25 @@
import { API, type Status } from 'cryptgeon/shared' import { status as apiStatus } from '@cryptgeon/shared'
import { writable } from 'svelte/store' import { writable } from 'svelte/store'
export const status = writable<null | Status>(null) export type StatusInfo = {
version: string
max_size: number
max_views: number
max_expiration: number
allow_advanced: boolean
allow_files: boolean
imprint_url: string
imprint_html: string
theme_image: string
theme_text: string
theme_page_title: string
theme_favicon: string
theme_new_note_notice: boolean
theme_home_link: boolean
}
export const status = writable<null | StatusInfo>(null)
export async function init() { export async function init() {
status.set(await API.status()) status.set((await apiStatus()) as StatusInfo)
} }
@@ -1,10 +1,17 @@
<script lang="ts"> <script lang="ts">
export let title: string import type { Snippet } from 'svelte'
interface Props {
title: string
children?: Snippet
}
let { title, children }: Props = $props()
</script> </script>
<p> <p>
<b>▶ {title}</b> <b>▶ {title}</b>
<slot /> {@render children?.()}
</p> </p>
<style> <style>
@@ -4,15 +4,24 @@
import { status } from '$lib/stores/status' import { status } from '$lib/stores/status'
import Switch from '$lib/ui/Switch.svelte' import Switch from '$lib/ui/Switch.svelte'
import TextInput from '$lib/ui/TextInput.svelte' import TextInput from '$lib/ui/TextInput.svelte'
import type { Note } from 'cryptgeon/shared'
export let note: Note interface Props {
export let timeExpiration = false note: { views: number; expiration: number }
export let customPassword: string | null = null timeExpiration?: boolean
customPassword?: string | null
}
let hasCustomPassword = false let {
note = $bindable(),
timeExpiration = $bindable(false),
customPassword = $bindable(null),
}: Props = $props()
$: if (!hasCustomPassword) customPassword = null let hasCustomPassword = $state(false)
$effect(() => {
if (!hasCustomPassword) customPassword = null
})
</script> </script>
<div class="flex col"> <div class="flex col">
+11 -1
View File
@@ -1,4 +1,14 @@
<button {...$$restProps} on:click><slot /></button> <script lang="ts">
import type { HTMLButtonAttributes } from 'svelte/elements'
interface Props {
children?: import('svelte').Snippet
}
let { children, ...rest }: HTMLButtonAttributes & Props = $props()
</script>
<button {...rest}>{@render children?.()}</button>
<style> <style>
button { button {
@@ -1,42 +0,0 @@
<script lang="ts">
// @ts-ignore
import QR from 'qrious'
import { t } from 'svelte-intl-precompile'
import { getCSSVariable } from '$lib/utils'
export let value: string
let canvas: HTMLCanvasElement
$: {
new QR({
value,
level: 'Q',
size: 800,
background: getCSSVariable('--ui-bg-0'),
foreground: getCSSVariable('--ui-text-0'),
element: canvas,
})
}
</script>
<small>{$t('common.qr_code')}</small>
<div>
<canvas bind:this={canvas} />
</div>
<style>
div {
padding: 0.5rem;
width: fit-content;
border: 2px solid var(--ui-bg-1);
background-color: var(--ui-bg-0);
margin-top: 0.125rem;
}
canvas {
width: 100%;
height: auto;
}
</style>
+13 -8
View File
@@ -3,17 +3,22 @@
import Button from '$lib/ui/Button.svelte' import Button from '$lib/ui/Button.svelte'
import MaxSize from '$lib/ui/MaxSize.svelte' import MaxSize from '$lib/ui/MaxSize.svelte'
import type { FileDTO } from 'cryptgeon/shared' import type { FileDTO } from '@cryptgeon/shared'
export let label: string = '' interface Props {
export let files: FileDTO[] = [] label?: string
files?: FileDTO[]
[key: string]: any
}
let { label = '', files = $bindable([]), ...rest }: Props = $props()
async function fileToDTO(file: File): Promise<FileDTO> { async function fileToDTO(file: File): Promise<FileDTO> {
return { return {
name: file.name, name: file.name,
mime: file.type,
size: file.size, size: file.size,
type: file.type, data: new Uint8Array(await file.arrayBuffer()),
contents: new Uint8Array(await file.arrayBuffer()),
} }
} }
@@ -35,7 +40,7 @@
<small> <small>
{label} {label}
</small> </small>
<input {...$$restProps} type="file" on:change={onInput} multiple /> <input {...rest} type="file" onchange={onInput} multiple />
<div class="box"> <div class="box">
{#if files.length} {#if files.length}
<div> <div>
@@ -45,8 +50,8 @@
{file.name} {file.name}
</div> </div>
{/each} {/each}
<div class="spacer" /> <div class="spacer"></div>
<Button on:click={clear}>{$t('file_upload.clear')}</Button> <Button onclick={clear}>{$t('file_upload.clear')}</Button>
</div> </div>
{:else} {:else}
<div> <div>
+10 -4
View File
@@ -1,9 +1,10 @@
<script lang="ts" context="module"> <script lang="ts" module>
import IconContrast from '$lib/icons/IconContrast.svelte' import IconContrast from '$lib/icons/IconContrast.svelte'
import IconCopy from '$lib/icons/IconCopy.svelte' import IconCopy from '$lib/icons/IconCopy.svelte'
import IconDice from '$lib/icons/IconDice.svelte' import IconDice from '$lib/icons/IconDice.svelte'
import IconEye from '$lib/icons/IconEye.svelte' import IconEye from '$lib/icons/IconEye.svelte'
import IconEyeOff from '$lib/icons/IconEyeOff.svelte' import IconEyeOff from '$lib/icons/IconEyeOff.svelte'
import type { HTMLButtonAttributes } from 'svelte/elements'
const map = { const map = {
contrast: IconContrast, contrast: IconContrast,
@@ -15,12 +16,17 @@
</script> </script>
<script lang="ts"> <script lang="ts">
export let icon: keyof typeof map interface Props {
icon: keyof typeof map
}
let { icon, ...rest }: HTMLButtonAttributes & Props = $props()
</script> </script>
<button type="button" on:click {...$$restProps}> <button type="button" {...rest}>
{#if map[icon]} {#if map[icon]}
<svelte:component this={map[icon]} /> {@const SvelteComponent = map[icon]}
<SvelteComponent />
{/if} {/if}
</button> </button>
@@ -1,3 +1,5 @@
<script lang="ts"></script>
<svg <svg
version="1.1" version="1.1"
xmlns="http://www.w3.org/2000/svg" xmlns="http://www.w3.org/2000/svg"

Before

Width:  |  Height:  |  Size: 784 B

After

Width:  |  Height:  |  Size: 813 B

+14 -7
View File
@@ -1,4 +1,4 @@
<script lang="ts" context="module"> <script lang="ts" module>
export type NoteResult = { export type NoteResult = {
id: string id: string
password?: string password?: string
@@ -10,12 +10,19 @@
import { status } from '$lib/stores/status' import { status } from '$lib/stores/status'
import Button from '$lib/ui/Button.svelte' import Button from '$lib/ui/Button.svelte'
import TextInput from '$lib/ui/TextInput.svelte' import TextInput from '$lib/ui/TextInput.svelte'
import Canvas from './Canvas.svelte' import QR from './QR.svelte'
export let result: NoteResult interface Props {
result: NoteResult
}
let url = `${window.location.origin}/note/${result.id}` let { result }: Props = $props()
if (result.password) url += `#${result.password}`
let url = $derived.by(() => {
let url = `${window.location.origin}/note/${result.id}`
if (result.password) url += `#${result.password}`
return url
})
function reset() { function reset() {
window.location.reload() window.location.reload()
@@ -32,7 +39,7 @@
/> />
<div> <div>
<Canvas value={url} /> <QR value={url} />
</div> </div>
{#if $status?.theme_new_note_notice} {#if $status?.theme_new_note_notice}
@@ -41,7 +48,7 @@
</p> </p>
{/if} {/if}
<br /> <br />
<Button on:click={reset}>{$t('home.new_note')}</Button> <Button onclick={reset}>{$t('home.new_note')}</Button>
<style> <style>
div { div {
@@ -0,0 +1,155 @@
<script lang="ts">
import { t } from 'svelte-intl-precompile'
import Button from '$lib/ui/Button.svelte'
import type { FileDTO } from '@cryptgeon/shared'
interface Props {
files: FileDTO[]
}
let { files = $bindable([]) }: Props = $props()
let previewUrls: string[] = $state([])
$effect(() => {
const urls = files.map((f) => URL.createObjectURL(new Blob([f.data.slice(0)], { type: f.mime })))
previewUrls = urls
return () => {
for (const url of urls) URL.revokeObjectURL(url)
}
})
function remove(index: number) {
const removed = files[index]
URL.revokeObjectURL(previewUrls[index])
files = files.toSpliced(index, 1)
}
function isImage(type: string) {
return type.startsWith('image/')
}
</script>
{#if files.length > 0}
<div class="pasted-files-preview">
<h4>{$t('home.pasted_files')}</h4>
<div class="files-grid">
{#each files as entry, index}
<div class="file-preview">
{#if isImage(entry.mime)}
<img src={previewUrls[index]} class="preview-img" alt={entry.name} />
{:else}
<div class="file-icon">
<div class="file-extension">
{entry.name.split('.').pop()?.toUpperCase() || entry.mime}
</div>
</div>
{/if}
<div class="file-name">{entry.name}</div>
<div class="file-actions">
<Button onclick={() => remove(index)}>
{$t('home.remove')}
</Button>
</div>
</div>
{/each}
</div>
</div>
{/if}
<style>
.pasted-files-preview {
margin-top: 1rem;
padding: 1rem;
border: 1px dashed #ccc;
border-radius: 4px;
background-color: #fafafa;
}
.pasted-files-preview h4 {
margin-top: 0;
margin-bottom: 0.5rem;
color: #333;
}
.files-grid {
display: flex;
flex-wrap: wrap;
gap: 1rem;
}
.file-preview {
position: relative;
text-align: center;
width: 150px;
}
.preview-img {
max-width: 150px;
max-height: 150px;
border-radius: 4px;
box-shadow: 0 2px 8px rgba(0,0,0,0.1);
}
.file-icon {
width: 150px;
height: 150px;
display: flex;
align-items: center;
justify-content: center;
border: 1px solid #e0e0e0;
border-radius: 4px;
background: #f5f5f5;
box-shadow: 0 2px 8px rgba(0,0,0,0.1);
}
.file-extension {
font-size: 1.2rem;
font-weight: bold;
color: #666;
padding: 0.25rem 0.5rem;
border: 1px solid #ccc;
border-radius: 4px;
background: white;
}
.file-name {
font-size: 0.75rem;
color: #666;
margin-top: 0.25rem;
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
max-width: 150px;
}
.file-actions {
margin-top: 0.5rem;
}
@media (max-width: 640px) {
.pasted-files-preview {
margin-top: 0.5rem;
padding: 0.5rem;
}
.preview-img, .file-icon {
max-width: 120px;
max-height: 120px;
width: 120px;
height: 120px;
}
.file-preview {
width: 120px;
}
.file-name {
max-width: 120px;
}
.files-grid {
gap: 0.5rem;
}
}
</style>
+45
View File
@@ -0,0 +1,45 @@
<script lang="ts">
import { getCSSVariable } from '$lib/utils'
import { t } from 'svelte-intl-precompile'
import { renderSVG } from 'uqr'
interface Props {
value: string
}
let { value }: Props = $props()
let qr: string | null = $state(null)
$effect(() => {
qr = renderSVG(value, {
ecc: 'Q',
blackColor: getCSSVariable('--ui-bg-0'),
whiteColor: getCSSVariable('--ui-text-0'),
})
})
</script>
<small>{$t('common.qr_code')}</small>
<div>
{#if qr}
{@html qr}
{/if}
</div>
<style>
div {
padding: 0.25rem;
width: fit-content;
border: 2px solid var(--ui-bg-1);
background-color: var(--ui-bg-0);
margin-top: 0.125rem;
overflow: hidden;
aspect-ratio: 1;
}
div :global(svg) {
width: 100%;
height: auto;
}
</style>
+48 -23
View File
@@ -1,5 +1,8 @@
<script lang="ts" context="module"> <script lang="ts" module>
export type DecryptedNote = Omit<NotePublic, 'contents'> & { contents: any } export type DecryptedNote = {
meta: { type: 'text' | 'file' }
contents: any
}
function saveAs(file: File) { function saveAs(file: File) {
const url = window.URL.createObjectURL(file) const url = window.URL.createObjectURL(file)
@@ -20,31 +23,35 @@
import Button from '$lib/ui/Button.svelte' import Button from '$lib/ui/Button.svelte'
import { copy } from '$lib/utils' import { copy } from '$lib/utils'
import type { FileDTO, NotePublic } from 'cryptgeon/shared' import type { FileDTO } from '@cryptgeon/shared'
export let note: DecryptedNote interface Props {
note: DecryptedNote
}
let { note }: Props = $props()
const RE_URL = /[A-Za-z]+:\/\/([A-Z a-z0-9\-._~:\/?#\[\]@!$&'()*+,;%=])+/g const RE_URL = /[A-Za-z]+:\/\/([A-Z a-z0-9\-._~:\/?#\[\]@!$&'()*+,;%=])+/g
let files: FileDTO[] = [] let files: FileDTO[] = $state([])
$: if (note.meta.type === 'file') { async function downloadFile(file: FileDTO) {
files = note.contents const f = new File([file.data.slice(0)], file.name, {
} type: file.mime,
$: download = () => {
for (const file of files) {
downloadFile(file)
}
}
async function downloadFile(file: FileDTO) {
const f = new File([file.contents], file.name, {
type: file.type,
}) })
saveAs(f) saveAs(f)
} }
$: links = typeof note.contents === 'string' ? note.contents.match(RE_URL) : [] $effect(() => {
if (note.meta.type === 'file') {
files = note.contents
}
})
let download = $derived(() => {
for (const file of files) {
downloadFile(file)
}
})
let links = $derived(typeof note.contents === 'string' ? note.contents.match(RE_URL) : [])
</script> </script>
<p class="error-text">{@html $t('show.warning_will_not_see_again')}</p> <p class="error-text">{@html $t('show.warning_will_not_see_again')}</p>
@@ -53,7 +60,7 @@
<div class="note"> <div class="note">
{note.contents} {note.contents}
</div> </div>
<Button on:click={() => copy(note.contents)}>{$t('common.copy_clipboard')}</Button> <Button onclick={() => copy(note.contents)}>{$t('common.copy_clipboard')}</Button>
{#if links && links.length} {#if links && links.length}
<div class="links"> <div class="links">
@@ -70,13 +77,22 @@
{:else} {:else}
{#each files as file} {#each files as file}
<div class="note file"> <div class="note file">
<button on:click={() => downloadFile(file)}> <button onclick={() => downloadFile(file)}>
<b>↓ {file.name}</b> <b>↓ {file.name}</b>
</button> </button>
<small> {file.type} - {prettyBytes(file.size)}</small> <small> {file.mime} - {prettyBytes(file.size ?? file.data.length)}</small>
</div> </div>
{#if file.mime.startsWith('image/')}
{#key file.name}
<img
src={URL.createObjectURL(new File([file.data.slice(0)], file.name, { type: file.mime }))}
alt={file.name}
class="preview"
/>
{/key}
{/if}
{/each} {/each}
<Button on:click={download}>{$t('show.download_all')}</Button> <Button onclick={download}>{$t('show.download_all')}</Button>
{/if} {/if}
</div> </div>
@@ -125,4 +141,13 @@
margin-bottom: 0.5rem; margin-bottom: 0.5rem;
word-wrap: break-word; word-wrap: break-word;
} }
.preview {
display: block;
max-width: 100%;
max-height: 60vh;
margin-bottom: 0.5rem;
border-radius: 0.25rem;
border: 2px solid var(--ui-bg-1);
}
</style> </style>
+10 -5
View File
@@ -1,13 +1,18 @@
<script lang="ts"> <script lang="ts">
export let label: string = '' interface Props {
export let value: boolean label?: string
export let color = true value: boolean
color?: boolean
[key: string]: any
}
let { label = '', value = $bindable(), color = true, ...rest }: Props = $props()
</script> </script>
<label {...$$restProps}> <label {...rest}>
<small>{label}</small> <small>{label}</small>
<input type="checkbox" bind:checked={value} /> <input type="checkbox" bind:checked={value} />
<span class:color class="slider" /> <span class:color class="slider"></span>
</label> </label>
<style> <style>
+8 -3
View File
@@ -1,11 +1,16 @@
<script lang="ts"> <script lang="ts">
export let label: string = '' interface Props {
export let value: string label?: string
value: string
[key: string]: any
}
let { label = '', value = $bindable(), ...rest }: Props = $props()
</script> </script>
<label> <label>
<small> <small>
{label} {label}
</small> </small>
<textarea class="box" {...$$restProps} bind:value /> <textarea class="box" {...rest} bind:value></textarea>
</label> </label>
+34 -24
View File
@@ -1,60 +1,70 @@
<script lang="ts"> <script lang="ts">
import Icon from '$lib/ui/Icon.svelte' import Icon from '$lib/ui/Icon.svelte'
import { copy as copyFN } from '$lib/utils' import { copy as copyFN } from '$lib/utils'
import { getRandomBytes, Hex } from 'occulto' import { randomBytes, bytesToHex } from '@cryptgeon/shared'
import type { HTMLInputAttributes } from 'svelte/elements'
export let label: string = '' interface Props {
export let value: any label?: string
export let validate: (value: any) => boolean | string = () => true value: any
export let copy: boolean = false validate?: (value: any) => boolean | string
export let random: boolean = false copy?: boolean
random?: boolean
const initialType = $$restProps.type
const isPassword = initialType === 'password'
let hidden = true
$: valid = validate(value)
$: if (isPassword) {
value
$$restProps.type = hidden ? initialType : 'text'
} }
let {
label = '',
value = $bindable(),
validate = () => true,
copy = false,
random = false,
...rest
}: HTMLInputAttributes & Props = $props()
// svelte-ignore state_referenced_locally
const initialType = $state(rest.type)
const isPassword = initialType === 'password'
let hidden = $state(true)
let valid = $derived(validate(value))
let type = $derived(isPassword ? (hidden ? 'password' : 'text') : rest.type)
function toggle() { function toggle() {
console.debug('toggle')
hidden = !hidden hidden = !hidden
} }
async function randomFN() { async function randomFN() {
value = Hex.encode(await getRandomBytes(32)) value = bytesToHex(randomBytes(32))
} }
</script> </script>
<label> <label>
<small class:disabled={$$restProps.disabled}> <small class:disabled={rest.disabled}>
{label} {label}
{#if valid !== true} {#if valid !== true}
<span class="error-text">{valid}</span> <span class="error-text">{valid}</span>
{/if} {/if}
</small> </small>
<input bind:value {...$$restProps} class:valid={valid === true} /> <input bind:value {...rest} {type} autocomplete="off" class:valid={valid === true} />
<div class="icons"> <div class="icons">
{#if isPassword} {#if isPassword}
<Icon <Icon
disabled={$$restProps.disabled} disabled={rest.disabled}
class="icon" class="icon"
icon={hidden ? 'eye' : 'eye-off'} icon={hidden ? 'eye' : 'eye-off'}
on:click={toggle} onclick={toggle}
/> />
{/if} {/if}
{#if random} {#if random}
<Icon disabled={$$restProps.disabled} class="icon" icon="dice" on:click={randomFN} /> <Icon disabled={rest.disabled} class="icon" icon="dice" onclick={randomFN} />
{/if} {/if}
{#if copy} {#if copy}
<Icon <Icon
disabled={$$restProps.disabled} disabled={rest.disabled}
class="icon" class="icon"
icon="copy" icon="copy"
on:click={() => copyFN(value.toString())} onclick={() => copyFN(value.toString())}
/> />
{/if} {/if}
</div> </div>
+10 -13
View File
@@ -1,24 +1,21 @@
<script lang="ts" context="module"> <script lang="ts" module>
import { writable } from 'svelte/store' import { writable } from 'svelte/store'
enum Theme { const themes = ['dark', 'light', 'auto'] as const
Dark = 'dark', type Theme = (typeof themes)[number]
Light = 'light',
Auto = 'auto',
}
const NextTheme = { const NextTheme: Record<Theme, Theme> = {
[Theme.Auto]: Theme.Light, auto: 'light',
[Theme.Light]: Theme.Dark, light: 'dark',
[Theme.Dark]: Theme.Auto, dark: 'auto',
} }
function init(): Theme { function init(): Theme {
if (typeof window !== 'undefined') { if (typeof window !== 'undefined') {
const saved = window.localStorage.getItem('theme') as Theme const saved = window.localStorage.getItem('theme') as Theme
if (Object.values(Theme).includes(saved)) return saved if (themes.includes(saved)) return saved
} }
return Theme.Auto return 'auto'
} }
export const theme = writable<Theme>(init()) export const theme = writable<Theme>(init())
@@ -40,7 +37,7 @@
} }
</script> </script>
<button on:click={change}> <button onclick={change}>
<Icon class="icon" icon="contrast" /> <Icon class="icon" icon="contrast" />
{$theme} {$theme}
</button> </button>
+173 -60
View File
@@ -1,5 +1,10 @@
<script lang="ts"> <script lang="ts">
import { AES, Hex } from 'occulto' import {
deriveKey, generateKey, encrypt, randomBytes,
bytesToHex, encode, compress,
create as apiCreate,
type FileDTO, type ServerNote
} from '@cryptgeon/shared'
import { t } from 'svelte-intl-precompile' import { t } from 'svelte-intl-precompile'
import { blur } from 'svelte/transition' import { blur } from 'svelte/transition'
@@ -10,32 +15,31 @@
import FileUpload from '$lib/ui/FileUpload.svelte' import FileUpload from '$lib/ui/FileUpload.svelte'
import Loader from '$lib/ui/Loader.svelte' import Loader from '$lib/ui/Loader.svelte'
import MaxSize from '$lib/ui/MaxSize.svelte' import MaxSize from '$lib/ui/MaxSize.svelte'
import PastedFilesPreview from '$lib/ui/PastedFilesPreview.svelte'
import Result, { type NoteResult } from '$lib/ui/NoteResult.svelte' import Result, { type NoteResult } from '$lib/ui/NoteResult.svelte'
import Switch from '$lib/ui/Switch.svelte' import Switch from '$lib/ui/Switch.svelte'
import TextArea from '$lib/ui/TextArea.svelte' import TextArea from '$lib/ui/TextArea.svelte'
import { Adapters, API, PayloadToLargeError, type FileDTO, type Note } from 'cryptgeon/shared'
let note: Note = { let note: { views: number; expiration: number } = $state({ views: 1, expiration: 60 })
contents: '', let files: FileDTO[] = $state([])
meta: { type: 'text' }, let result: NoteResult | null = $state(null)
views: 1, let advanced = $state(false)
expiration: 60, let isFile = $state(false)
} let timeExpiration = $state(false)
let files: FileDTO[] let customPassword: string | null = $state(null)
let result: NoteResult | null = null let description = $state('')
let advanced = false let loading: string | null = $state(null)
let isFile = false let isPasting = $state(false)
let timeExpiration = false let textContent = $state('')
let customPassword: string | null = null
let description = ''
let loading: string | null = null
$: if (!advanced) { $effect(() => {
note.views = 1 if (!advanced) {
timeExpiration = false note.views = 1
} timeExpiration = false
}
})
$: { $effect(() => {
description = $t('home.explanation', { description = $t('home.explanation', {
values: { values: {
type: $t(timeExpiration ? 'common.minutes' : 'common.views', { type: $t(timeExpiration ? 'common.minutes' : 'common.views', {
@@ -43,54 +47,117 @@
}), }),
}, },
}) })
} })
$: note.meta.type = isFile ? 'file' : 'text' $effect(() => {
if (!isFile) textContent = ''
})
$: if (!isFile) { async function handlePaste(e: ClipboardEvent) {
note.contents = '' const data = e.clipboardData
if (!data) return
const raw: File[] = []
if (data.files.length) {
raw.push(...Array.from(data.files))
}
for (let i = 0; i < data.items.length; i++) {
const item = data.items[i]
if (item.kind === 'file') {
const file = item.getAsFile()
if (file) raw.push(file)
}
}
if (raw.length === 0) return
e.preventDefault()
const seen = new Set<string>()
const pasted: File[] = []
for (const f of raw) {
const key = `${f.name}|${f.size}`
if (!seen.has(key)) {
seen.add(key)
pasted.push(f)
}
}
isPasting = true
const dtos: FileDTO[] = await Promise.all(
pasted.map(async (file) => {
const ext = file.name.includes('.') ? '' : `.${file.type.split('/')[1] || 'bin'}`
const name =
file.name || `pasted-file-${Date.now()}-${Math.round(Math.random() * 1000)}${ext}`
const renamed = new File([file], name, { type: file.type })
const data = new Uint8Array(await renamed.arrayBuffer())
return {
name: renamed.name,
mime: renamed.type,
size: renamed.size,
data,
}
})
)
if (dtos.length > 0) {
if (!isFile) isFile = true
files = [...files, ...dtos]
}
isPasting = false
} }
class EmptyContentError extends Error {} class EmptyContentError extends Error {}
async function submit() { async function submit(e: SubmitEvent) {
e.preventDefault()
try { try {
loading = $t('common.encrypting') loading = $t('common.encrypting')
const derived = customPassword && (await AES.derive(customPassword)) const salt = customPassword ? randomBytes(16) : null
const key = derived ? derived[0] : await AES.generateKey() const key = customPassword
? deriveKey(customPassword, salt!)
: generateKey()
const data: Note = { let inner: Uint8Array
contents: '',
meta: note.meta,
}
if (derived) data.meta.derivation = derived[1]
if (isFile) { if (isFile) {
if (files.length === 0) throw new EmptyContentError() if (files.length === 0) throw new EmptyContentError()
data.contents = await Adapters.Files.encrypt(files, key) inner = encode({ type: 'files', data: files })
} else { } else {
if (note.contents === '') throw new EmptyContentError() if (textContent === '') throw new EmptyContentError()
data.contents = await Adapters.Text.encrypt(note.contents, key) inner = encode({ type: 'text', data: textContent })
}
const originalSize =inner.byteLength
const compressed = compress(inner)
const compresseedSize= compressed.byteLength
console.debug({originalSize, compresseedSize, ratio: originalSize/compresseedSize})
const data = encrypt(compress(inner), key)
const extra = customPassword
? encode({ salt: salt!, N: 32768, r: 8, p: 1 })
: new Uint8Array()
const serverNote: ServerNote = {
meta: {
...(timeExpiration ? { expiration: parseInt(note.expiration as any) } : { views: parseInt(note.views as any) }),
extra,
},
data,
} }
if (timeExpiration) data.expiration = parseInt(note.expiration as any)
else data.views = parseInt(note.views as any)
loading = $t('common.uploading') loading = $t('common.uploading')
const response = await API.create(data) const response = await apiCreate(serverNote)
result = { result = {
id: response.id, id: response.id,
password: customPassword ? undefined : Hex.encode(key), password: customPassword ? undefined : bytesToHex(key),
} }
notify.success($t('home.messages.note_created')) notify.success($t('home.messages.note_created'))
} catch (e) { } catch (e) {
if (e instanceof PayloadToLargeError) { console.error(e)
notify.error($t('home.errors.note_to_big')) notify.error($t('home.errors.note_error'))
} else if (e instanceof EmptyContentError) {
notify.error($t('home.errors.empty_content'))
} else {
console.error(e)
notify.error($t('home.errors.note_error'))
}
} finally { } finally {
loading = null loading = null
} }
@@ -103,18 +170,28 @@
<p> <p>
{@html $status?.theme_text || $t('home.intro')} {@html $status?.theme_text || $t('home.intro')}
</p> </p>
<form on:submit|preventDefault={submit}> <form onsubmit={submit} onpaste={handlePaste}>
<fieldset disabled={loading !== null}> <fieldset disabled={loading !== null}>
{#if isFile} <div class="paste-indicator">
<FileUpload data-testid="file-upload" label={$t('common.file')} bind:files /> {#if isPasting}
{:else} <div class="pasting-overlay">
<TextArea <div class="pasting-spinner"></div>
data-testid="text-field" <span>{$t('home.pasting')}</span>
label={$t('common.note')} </div>
bind:value={note.contents} {/if}
placeholder="..." {#if isFile}
/> <FileUpload data-testid="file-upload" label={$t('common.file')} bind:files />
{/if} {:else}
<TextArea
data-testid="text-field"
label={$t('common.note')}
bind:value={textContent}
placeholder="..."
/>
{/if}
<PastedFilesPreview bind:files />
</div>
<div class="bottom"> <div class="bottom">
{#if $status?.allow_files} {#if $status?.allow_files}
@@ -132,7 +209,7 @@
bind:value={advanced} bind:value={advanced}
/> />
{/if} {/if}
<div class="grow" /> <div class="grow"></div>
<div class="tr"> <div class="tr">
<small>{$t('common.max')}: <MaxSize /> </small> <small>{$t('common.max')}: <MaxSize /> </small>
<br /> <br />
@@ -173,4 +250,40 @@
.grow { .grow {
flex: 1; flex: 1;
} }
.paste-indicator {
position: relative;
min-height: 200px;
}
.pasting-overlay {
position: absolute;
top: 0;
left: 0;
right: 0;
bottom: 0;
background: rgba(0, 0, 0, 0.5);
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
color: white;
z-index: 10;
}
.pasting-spinner {
width: 24px;
height: 24px;
border: 2px solid rgba(255, 255, 255, 0.3);
border-top: 2px solid white;
border-radius: 50%;
animation: spin 1s linear infinite;
margin-bottom: 0.5rem;
}
@keyframes spin {
to {
transform: rotate(360deg);
}
}
</style> </style>
@@ -1,12 +1,20 @@
<script lang="ts"> <script lang="ts">
import ThemeToggle from '$lib/ui/ThemeToggle.svelte' import ThemeToggle from '$lib/ui/ThemeToggle.svelte'
import { status } from '$lib/stores/status'
</script> </script>
<footer> <footer>
<ThemeToggle /> <ThemeToggle />
<nav> <nav>
<a href="/">/home</a> {#if $status?.theme_home_link !== false}
<a href="/">/home</a>
{/if}
<a href="/about">/about</a> <a href="/about">/about</a>
{#if $status?.imprint_url}
<a href={$status.imprint_url} target="_blank" rel="noopener noreferrer">/imprint</a>
{:else if $status?.imprint_html}
<a href="/imprint">/imprint</a>
{/if}
<a href="https://github.com/cupcakearmy/cryptgeon" target="_blank" rel="noopener noreferrer"> <a href="https://github.com/cupcakearmy/cryptgeon" target="_blank" rel="noopener noreferrer">
code code
</a> </a>
@@ -7,8 +7,10 @@
</script> </script>
<header> <header>
<a on:click={reset} href="/"> <a onclick={reset} href="/">
{#if $status?.theme_image} {#if $status === null}
<!-- waiting for status to load to avoid flashing default logo -->
{:else if $status.theme_image}
<img alt="logo" src={$status.theme_image} /> <img alt="logo" src={$status.theme_image} />
{:else} {:else}
<svg <svg
+6 -1
View File
@@ -8,6 +8,11 @@
import { init as initStores, status } from '$lib/stores/status' import { init as initStores, status } from '$lib/stores/status'
import Footer from '$lib/views/Footer.svelte' import Footer from '$lib/views/Footer.svelte'
import Header from '$lib/views/Header.svelte' import Header from '$lib/views/Header.svelte'
interface Props {
children?: import('svelte').Snippet
}
let { children }: Props = $props()
onMount(() => { onMount(() => {
initStores() initStores()
@@ -22,7 +27,7 @@
{#await waitLocale() then _} {#await waitLocale() then _}
<main> <main>
<Header /> <Header />
<slot /> {@render children?.()}
</main> </main>
<SvelteToast /> <SvelteToast />
@@ -45,18 +45,7 @@
</span> </span>
</AboutParagraph> </AboutParagraph>
<AboutParagraph title="translations"> <AboutParagraph title="attribution">
<span
>translations are managed on <a
href="https://lokalise.com/"
target="_blank"
rel="noopener noreferrer">Lokalise</a
>, which granted an open source license to use the paid version. If you are interested in
helping translating don't hesitate to contact me!
</span>
</AboutParagraph>
<AboutParagraph title="attribution">
<span> <span>
icons made by <a href="https://www.freepik.com" title="Freepik">freepik</a> from icons made by <a href="https://www.freepik.com" title="Freepik">freepik</a> from
<a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a> <a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a>
@@ -0,0 +1,33 @@
<script lang="ts">
import { goto } from '$app/navigation'
import { status } from '$lib/stores/status'
status.subscribe((config) => {
if (config != null) {
if (config.imprint_url) {
window.location.href = config.imprint_url
} else if (config.imprint_html == '') {
goto('/about')
}
}
})
</script>
<svelte:head>
<title>Imprint</title>
</svelte:head>
<section class="content">
{#if $status?.imprint_html}
{@html $status.imprint_html}
{/if}
</section>
<style>
section {
width: 100%;
display: flex;
flex-direction: column;
gap: 2rem;
}
</style>
@@ -1,5 +1,5 @@
<script lang="ts"> <script lang="ts">
import { AES, Hex } from 'occulto' import { deriveKey, hexToBytes, decrypt, decode, decompress, info, get as apiGet, type FileDTO } from '@cryptgeon/shared'
import { onMount } from 'svelte' import { onMount } from 'svelte'
import { t } from 'svelte-intl-precompile' import { t } from 'svelte-intl-precompile'
@@ -7,30 +7,36 @@
import Loader from '$lib/ui/Loader.svelte' import Loader from '$lib/ui/Loader.svelte'
import ShowNote, { type DecryptedNote } from '$lib/ui/ShowNote.svelte' import ShowNote, { type DecryptedNote } from '$lib/ui/ShowNote.svelte'
import TextInput from '$lib/ui/TextInput.svelte' import TextInput from '$lib/ui/TextInput.svelte'
import { Adapters, API, type NoteMeta } from 'cryptgeon/shared'
import type { PageData } from './$types' import type { PageData } from './$types'
export let data: PageData interface Props {
data: PageData
}
let id = data.id let { data }: Props = $props()
let password: string | null = null
let note: DecryptedNote | null = null
let exists = false
let meta: NoteMeta | null = null
let loading: string | null = null let id = $derived(data.id)
let error: string | null = null let password: string | null = $state<string | null>(null)
let note: DecryptedNote | null = $state(null)
let exists = $state(false)
let hasExtra = $state(false)
$: valid = !!password?.length let loading: string | null = $state(null)
let error: string | null = $state(null)
let valid = $derived(!!password?.length)
onMount(async () => { onMount(async () => {
// Check if note exists
try { try {
loading = $t('common.loading') loading = $t('common.loading')
password = window.location.hash.slice(1) password = window.location.hash.slice(1)
const note = await API.info(id) const meta = await info(id)
meta = note.meta if (meta) {
exists = true hasExtra = !!meta.extra?.length
exists = true
} else {
exists = false
}
} catch { } catch {
exists = false exists = false
} finally { } finally {
@@ -38,36 +44,51 @@
} }
}) })
/** async function show(e: SubmitEvent) {
* Get the actual contents of the note and decrypt it. e.preventDefault()
*/
async function show() {
try { try {
if (!valid) { if (!valid) {
error = $t('show.errors.no_password') error = $t('show.errors.no_password')
return return
} }
// Load note
error = null error = null
loading = $t('common.downloading') loading = $t('common.downloading')
const data = await API.get(id) const serverNote = await apiGet(id)
if (!serverNote) {
error = $t('show.errors.not_found')
return
}
loading = $t('common.decrypting') loading = $t('common.decrypting')
const derived = meta?.derivation && (await AES.derive(password!, meta.derivation)) let key: Uint8Array
const key = derived ? derived[0] : Hex.decode(password!) if (hasExtra && serverNote.meta.extra && serverNote.meta.extra.length > 0) {
switch (data.meta.type) { const derivation = decode(serverNote.meta.extra) as any
key = deriveKey(password!, new Uint8Array(derivation.salt))
} else {
key = hexToBytes(password!)
}
const decrypted = decrypt(serverNote.data, key)
const content = decode(decompress(decrypted)) as any
switch (content.type) {
case 'text': case 'text':
note = { note = {
meta: { type: 'text' }, meta: { type: 'text' },
contents: await Adapters.Text.decrypt(data.contents, key), contents: content.data,
}
break
case 'file':
note = {
meta: { type: 'file' },
contents: await Adapters.Files.decrypt(data.contents, key),
} }
break break
case 'files':
const files = (content.data as any[]).map((f: any) => ({
...f,
data: f.data instanceof Uint8Array ? f.data : new Uint8Array(f.data as any),
}))
note = {
meta: { type: 'file' },
contents: files,
}
break
default: default:
error = $t('show.errors.unsupported_type') error = $t('show.errors.unsupported_type')
return return
@@ -86,10 +107,10 @@
{:else if note && !error} {:else if note && !error}
<ShowNote {note} /> <ShowNote {note} />
{:else} {:else}
<form on:submit|preventDefault={show}> <form onsubmit={show}>
<fieldset> <fieldset>
<p>{$t('show.explanation')}</p> <p>{$t('show.explanation')}</p>
{#if meta?.derivation} {#if hasExtra}
<TextInput <TextInput
data-testid="show-note-password" data-testid="show-note-password"
type="password" type="password"
+3 -2
View File
@@ -2,6 +2,7 @@
"extends": "./.svelte-kit/tsconfig.json", "extends": "./.svelte-kit/tsconfig.json",
"compilerOptions": { "compilerOptions": {
"strict": true, "strict": true,
"allowSyntheticDefaultImports": true "allowSyntheticDefaultImports": true,
} "skipLibCheck": true,
},
} }
+10 -7
View File
@@ -1,14 +1,17 @@
import { sveltekit } from '@sveltejs/kit/vite' import { sveltekit } from '@sveltejs/kit/vite'
import precompileIntl from 'svelte-intl-precompile/sveltekit-plugin' import precompileIntl from 'svelte-intl-precompile/sveltekit-plugin'
import { defineConfig } from 'vite'
const port = 8001 const port = 3000
/** @type {import('vite').UserConfig} */ export default defineConfig({
const config = {
clearScreen: false, clearScreen: false,
server: { port }, server: {
port,
proxy: {
'/api': 'http://localhost:8000',
},
},
preview: { port }, preview: { port },
plugins: [sveltekit(), precompileIntl('locales')], plugins: [sveltekit(), precompileIntl('locales')],
} })
export default config
-12
View File
@@ -1,12 +0,0 @@
{
"private": true,
"name": "@cryptgeon/proxy",
"type": "module",
"main": "./proxy.js",
"scripts": {
"dev": "node ."
},
"dependencies": {
"http-proxy": "^1.18.1"
}
}
-16
View File
@@ -1,16 +0,0 @@
import http from 'http'
import httpProxy from 'http-proxy'
const proxy = httpProxy.createProxyServer()
proxy.on('error', function (err, req, res) {
console.error(err)
res.writeHead(500, { 'Content-Type': 'text/plain' })
res.end('500 Internal Server Error')
})
const server = http.createServer(function (req, res) {
const target = req.url.startsWith('/api/') ? 'http://127.0.0.1:8000' : 'http://localhost:8001'
proxy.web(req, res, { target, proxyTimeout: 250, timeout: 250 })
})
server.listen(3000)
console.log('Proxy on http://localhost:3000')
+25
View File
@@ -0,0 +1,25 @@
{
"name": "@cryptgeon/shared",
"private": true,
"version": "0.0.0",
"type": "module",
"exports": {
".": "./src/index.ts"
},
"dependencies": {
"@msgpack/msgpack": "^3.1.3",
"@noble/ciphers": "^2.4.0",
"@noble/hashes": "^2.4.0",
"lz4js": "^0.2.0"
},
"devDependencies": {
"@tsconfig/strictest": "catalog:",
"@types/lz4js": "^0.2.2",
"typescript": "catalog:",
"vitest": "^4.1.11"
},
"scripts": {
"test": "vitest run",
"test:watch": "vitest"
}
}
+75
View File
@@ -0,0 +1,75 @@
import { describe, expect, it, vi } from 'vitest'
import { encode, decode } from '@msgpack/msgpack'
import { setServer, getServer, create, info, get, status } from './api'
const server = 'http://example.test'
const created = encode({ id: 'abc123' })
const metaOut = encode({ meta: { views: 3, extra: Buffer.from('040506','hex') } })
const dataOut = encode({ meta: { views: 0 },data: Buffer.from('090909','hex') })
function mockFetch(body: Uint8Array) {
return vi.fn().mockResolvedValue({
ok: true,
status: 200,
arrayBuffer: async () => body.buffer.slice(body.byteOffset, body.byteOffset + body.byteLength),
json: async () => ({}),
})
}
function copyBuffer(buf: Uint8Array) {
return buf.buffer.slice(buf.byteOffset, buf.byteOffset + buf.byteLength)
}
describe('api client', () => {
it('setServer trims trailing slashes', () => {
setServer('http://x.test///')
expect(getServer()).toBe('http://x.test')
})
it('create POSTs msgpack note and returns id', async () => {
setServer(server)
const fetchMock = mockFetch(created)
vi.stubGlobal('fetch', fetchMock)
const note = { meta: { views: 5 },data: Buffer.from('010203','hex') }
const result = await create(note)
const url = fetchMock.mock.calls[0]![0]!
const init = fetchMock.mock.calls[0]![1]!
expect(url).toBe(server + '/api/v3/notes')
expect(init.method).toBe('POST')
expect(init.headers).toEqual({ 'content-type': 'application/msgpack' })
const sent = decode(new Uint8Array(copyBuffer(init.body))) as { meta?: { views?: number } }
expect(sent?.meta?.views).toBe(5)
expect(result).toEqual({ id: 'abc123' })
vi.unstubAllGlobals()
})
it('info GETs meta', async () => {
setServer(server)
const fetchMock = mockFetch(metaOut)
vi.stubGlobal('fetch', fetchMock)
const result = await info('id1')
expect(result?.views).toBe(3)
vi.unstubAllGlobals()
})
it('get DELETEs and parses data', async () => {
setServer(server)
const fetchMock = mockFetch(dataOut)
vi.stubGlobal('fetch', fetchMock)
const result = await get('id2')
expect(result?.meta?.views).toBe(0)
const init = fetchMock.mock.calls[0]![1]!
expect(init.method).toBe('DELETE')
vi.unstubAllGlobals()
})
it('status GETs JSON config', async () => {
setServer(server)
const fetchMock = mockFetch(new Uint8Array())
vi.stubGlobal('fetch', fetchMock)
await status()
const url = fetchMock.mock.calls[0]![0]!
expect(url).toBe(server + '/api/v3/status')
vi.unstubAllGlobals()
})
})
+58
View File
@@ -0,0 +1,58 @@
import { encode, decode } from "@msgpack/msgpack";
import type { ServerNote, Status } from "./types.js";
let server = "";
export function setServer(url: string) {
server = url.replace(/\/+$/, "");
}
export function getServer() {
return server;
}
function api(path: string) {
return `${server}/api/v3/${path}`;
}
export async function create(note: ServerNote): Promise<{ id: string }> {
const res = await fetch(api("notes"), {
method: "POST",
headers: { "content-type": "application/msgpack" },
body: encode(note),
});
if (!res.ok) throw new Error("create failed");
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
if (typeof data?.id !== "string") throw new Error("invalid response");
return { id: data.id };
}
export async function info(id: string): Promise<ServerNote["meta"] | null> {
const res = await fetch(api(`notes/${id}`));
if (!res.ok) return null;
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
const meta = data?.meta as ServerNote["meta"] | undefined;
if (!meta) return null;
if (meta.extra && !(meta.extra instanceof Uint8Array)) meta.extra = new Uint8Array(meta.extra as any);
return meta;
}
export async function get(id: string): Promise<ServerNote | null> {
const res = await fetch(api(`notes/${id}`), { method: "DELETE" });
if (!res.ok) return null;
const buf = await res.arrayBuffer();
const data = decode(new Uint8Array(buf)) as any;
const meta = data.meta as ServerNote["meta"];
if (meta?.extra && !(meta.extra instanceof Uint8Array)) meta.extra = new Uint8Array(meta.extra as any);
const d = data.data;
return { meta, data: d instanceof Uint8Array ? d : new Uint8Array(d) } satisfies ServerNote;
}
export async function status(): Promise<Status> {
const res = await fetch(api("status"));
if (!res.ok) throw new Error("status failed");
return res.json();
}
+26
View File
@@ -0,0 +1,26 @@
import { describe, expect, it } from "vitest";
import { compress, decompress, utf8ToBytes } from "./index";
describe("compression", () => {
it("round-trips small text", () => {
const data = utf8ToBytes("hello world");
const compressed = compress(data);
const decompressed = decompress(compressed);
expect(decompressed).toEqual(data);
});
it("round-trips highly compressible data", () => {
const data = utf8ToBytes("a".repeat(10_000));
const compressed = compress(data);
expect(compressed.length).toBeLessThan(data.length);
const decompressed = decompress(compressed);
expect(decompressed).toEqual(data);
});
it("round-trips arbitrary bytes", () => {
const data = new Uint8Array([0, 128, 255, 1, 2, 3, 200, 100]);
const compressed = compress(data);
const decompressed = decompress(compressed);
expect(decompressed).toEqual(data);
});
});
+9
View File
@@ -0,0 +1,9 @@
import LZ4 from "lz4js";
export function compress(data: Uint8Array): Uint8Array {
return LZ4.compress(data);
}
export function decompress(data: Uint8Array): Uint8Array {
return LZ4.decompress(data);
}
+26
View File
@@ -0,0 +1,26 @@
import { describe, expect, it } from "vitest";
import { deriveKey, encrypt, decrypt, generateKey, utf8ToBytes, randomBytes } from "./crypto";
describe("crypto", () => {
it("encrypts and decrypts with generated key", () => {
const data = utf8ToBytes("hello world");
const key = generateKey();
const enc = encrypt(data, key);
const dec = decrypt(enc, key);
expect(dec).toEqual(data);
});
it("encrypts and decrypts with derived key", () => {
const data = utf8ToBytes("secret message");
const salt = randomBytes(16);
const key = deriveKey("password123", salt);
const enc = encrypt(data, key);
const dec = decrypt(enc, key);
expect(dec).toEqual(data);
});
it("derived key has same length as generated", () => {
const salt = randomBytes(16);
expect(deriveKey("test", salt).length).toBe(generateKey().length);
});
});
+32
View File
@@ -0,0 +1,32 @@
import { xchacha20poly1305 } from "@noble/ciphers/chacha.js";
import { managedNonce, randomBytes } from "@noble/ciphers/utils.js";
import { scrypt } from "@noble/hashes/scrypt.js";
export {
bytesToUtf8,
utf8ToBytes,
hexToBytes,
bytesToHex,
randomBytes,
} from "@noble/ciphers/utils.js";
const N = 2 ** 15;
const KEY_SIZE = 32;
export function generateKey(): Uint8Array {
return randomBytes(KEY_SIZE);
}
export function deriveKey(password: string, salt: Uint8Array): Uint8Array {
return scrypt(password, salt, { N, r: 8, p: 1, dkLen: KEY_SIZE });
}
export function encrypt(data: Uint8Array, key: Uint8Array): Uint8Array {
const chacha = managedNonce(xchacha20poly1305)(key);
return chacha.encrypt(data);
}
export function decrypt(data: Uint8Array, key: Uint8Array): Uint8Array {
const chacha = managedNonce(xchacha20poly1305)(key);
return chacha.decrypt(data);
}
+5
View File
@@ -0,0 +1,5 @@
export * from "./crypto.js";
export * from "./types.js";
export * from "./api.js";
export * from "./compression.js";
export { encode, decode } from "@msgpack/msgpack";
+38
View File
@@ -0,0 +1,38 @@
export type NoteMeta = {
expiration?: number;
views?: number;
extra?: Uint8Array;
};
export type ServerNote = {
meta: NoteMeta;
data: Uint8Array;
};
export type NoteContent =
| { type: "text"; data: string }
| { type: "files"; data: FileDTO[] };
export type FileDTO = {
name: string;
mime: string;
size: number;
data: Uint8Array;
};
export type Status = {
version: string;
max_size: number;
max_views: number;
max_expiration: number;
allow_advanced: boolean;
allow_files: boolean;
imprint_url: string;
imprint_html: string;
theme_image: string;
theme_text: string;
theme_page_title: string;
theme_favicon: string;
theme_new_note_notice: boolean;
theme_home_link: boolean;
};
+9
View File
@@ -0,0 +1,9 @@
{
"extends": "@tsconfig/strictest/tsconfig.json",
"compilerOptions": {
"target": "ESNext",
"module": "ESNext",
"moduleResolution": "bundler",
"noEmit": true
}
}
+7
View File
@@ -0,0 +1,7 @@
import { defineConfig } from "vitest/config";
export default defineConfig({
test: {
environment: "node",
},
});
+3440 -3110
View File
File diff suppressed because it is too large Load Diff
+10
View File
@@ -1,2 +1,12 @@
packages: packages:
- "packages/**" - "packages/**"
catalog:
vite-plus: ^0.3.0
typescript: ^7.0.2
"@tsconfig/strictest": ^2.0.8
allowBuilds:
esbuild: true
minimumReleaseAge: 10080 # One week

Some files were not shown because too many files have changed in this diff Show More