feat(cookie): add AES-256-GCM encrypted cookie support#4818
Open
brunorodmoreira wants to merge 5 commits intohonojs:mainfrom
Open
feat(cookie): add AES-256-GCM encrypted cookie support#4818brunorodmoreira wants to merge 5 commits intohonojs:mainfrom
brunorodmoreira wants to merge 5 commits intohonojs:mainfrom
Conversation
Add serializeEncrypted and parseEncrypted to cookie utils using AES-256-GCM via Web Crypto API with HKDF-SHA256 key derivation.
Add setEncryptedCookie, getEncryptedCookie, generateEncryptedCookie with full prefix support and comprehensive test coverage.
- Use non-empty HKDF salt for stronger key derivation - Cache CryptoKey across multiple cookie decryptions - Bind ciphertext to cookie name via AES-GCM additional data (AAD) - Use loop-based base64 encoding to avoid stack overflow on large payloads - Wrap decodeURIComponent in try/catch for malformed cookie values
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4817
Summary
setEncryptedCookie,getEncryptedCookie,generateEncryptedCookiehelpers using AES-256-GCM encryption via Web Crypto APIserializeEncrypted,parseEncryptedlow-level utils withEncryptedCookietypesetSignedCookie/getSignedCookie)Crypto design
crypto.subtle)base64(iv || ciphertext || authTag)The author should do the following, if applicable
bun run format:fix && bun run lint:fixto format the codeTest plan
undefinedfalsefalsefalse(AAD binding)generateEncryptedCookiewith and without options