• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

rm-hull / zaup2 / 34769300382
92%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 04:41PM UTC
Jobs 1
Files 3
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 04:40PM UTC coverage: 92.0% (-8.0%) from 100.0%
34769300382

push

github

web-flow
WebCrypto Implementation (#933)

## Summary

This PR modernizes the application's cryptography implementation by removing the deprecated `crypto-js` library and replacing it with the browser's native **Web Crypto API**. This improves performance, reduces bundle size, and aligns with modern web standards.

Data compatibility with previously saved data (encrypted using `crypto-js`) is fully maintained through a custom implementation of the OpenSSL `EVP_BytesToKey` derivation process.

## Key Changes

### Core Refactoring
- **Removed `crypto-js`**: The entire `crypto-js` package and its dedicated serializer (`cryptojs-serializer.ts`) have been removed from the project dependencies and source code.
- **Native Web Crypto API Integration**: All AES-CBC encryption and decryption operations are now performed using `crypto.subtle`.
- **MD5 Replacement**: The only remaining use of `crypto-js` was for the MD5 hashes required in the key derivation process. This has been replaced with [`@noble/hashes`](https://github.com/paulmillr/noble-hashes), a modern, audited, and minimal library.

### Compatibility & Migration
- **`WebCryptoSerializer`**: This class now handles both writing and reading of data. Newly encrypted data conforms to the same "Salted__" format used by the old `crypto-js` implementation, ensuring that any data saved by the old system can be decrypted by the new one, and vice-versa (though we have stopped writing new data in that format).
- **Password Validation**: The `WebCryptoSerializer` now includes a mechanism to block serialization if the password has previously failed decryption, preventing accidental overwrites with invalid data.
- **Comprehensive Testing**: Compatibility tests were added to verify bidirectional serialization and deserialization, ensuring data integrity across the transition.

### Supporting Changes
- **`useOtpParameters` Hook**: Updated to exclusively use the new `WebCryptoSerializer`.
- **Error Handling**: Improved to provid... (continued)

5 of 5 branches covered (100.0%)

Branch coverage included in aggregate %.

63 of 71 new or added lines in 1 file covered. (88.73%)

87 of 95 relevant lines covered (91.58%)

13.65 hits per line

Uncovered Changes

Lines Coverage ∆ File
8
89.47
src/utils/serializer/webcrypto-serializer.ts
Jobs
ID Job ID Ran Files Coverage
1 34769300382.1 13 Sep 2026 04:41PM UTC 3
92.0
GitHub Action Run
Source Files on build 34769300382
  • Tree
  • List 3
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #34769300382
  • 9d920e7e on github
  • Prev Build on main (#34767752766)
  • Next Build on main (#34997345980)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc