평문 환경 숙의 연습 해시 보정
This commit is contained in:
parent
21461ab323
commit
ba5e6326d5
9 changed files with 262 additions and 14 deletions
|
|
@ -477,12 +477,18 @@ test.describe("G4 숙의 연습", () => {
|
|||
);
|
||||
const episodeBody = submitted[0].episode as {
|
||||
episode_id: string;
|
||||
attempts: Array<{ attempt_id: string }>;
|
||||
attempts: Array<{
|
||||
attempt_id: string;
|
||||
utterance_template_id?: string | null;
|
||||
}>;
|
||||
};
|
||||
expect(episodeBody.episode_id).toMatch(/^oas-g4-episode-[a-f0-9-]+$/);
|
||||
expect(episodeBody.attempts[0].attempt_id).toMatch(
|
||||
/^oas-g4-attempt-[a-f0-9-]+$/,
|
||||
);
|
||||
expect(episodeBody.attempts[0].utterance_template_id).toBe(
|
||||
"utterance-sha256:c06db0f06811c540ea7d985c7d4e3b880e978e33524128538d6f0ab7b23362aa",
|
||||
);
|
||||
|
||||
await card.getByRole("button", { name: /05:04.*발화로 이동/ }).click();
|
||||
await expect(page.getByRole("tab", { name: "축어록" })).toHaveAttribute(
|
||||
|
|
|
|||
|
|
@ -11,6 +11,24 @@ import { expect, test } from "@playwright/test";
|
|||
* context.
|
||||
*/
|
||||
const UUID_V4 = /^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/;
|
||||
const SHA256_VECTORS = [
|
||||
{
|
||||
value: "",
|
||||
digest: "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
|
||||
},
|
||||
{
|
||||
value: "abc",
|
||||
digest: "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad",
|
||||
},
|
||||
{
|
||||
value: "a".repeat(56),
|
||||
digest: "b35439a4ac6f0948b6d6f9e3c6af0f5f590ce20f1bde7090ef7970686ec6738a",
|
||||
},
|
||||
{
|
||||
value: "지금 이 이야기를 조금 더 다뤄도 괜찮을까요?",
|
||||
digest: "c06db0f06811c540ea7d985c7d4e3b880e978e33524128538d6f0ab7b23362aa",
|
||||
},
|
||||
] as const;
|
||||
|
||||
test.describe("insecure-context idempotency keys", () => {
|
||||
test("randomUuid keeps working when crypto.randomUUID is unavailable", async ({
|
||||
|
|
@ -83,6 +101,78 @@ test.describe("insecure-context idempotency keys", () => {
|
|||
expect(new Set(values).size).toBe(2);
|
||||
});
|
||||
|
||||
test("sha256Hex matches known vectors when crypto.subtle is unavailable", async ({
|
||||
page,
|
||||
}) => {
|
||||
await page.addInitScript(() => {
|
||||
Object.defineProperty(globalThis.crypto, "subtle", {
|
||||
value: undefined,
|
||||
configurable: true,
|
||||
});
|
||||
});
|
||||
await page.goto("/");
|
||||
|
||||
const probe = await page.evaluate(async (vectors) => {
|
||||
const module = await import("/src/lib/sha256.ts");
|
||||
return {
|
||||
subtlePresent: typeof globalThis.crypto.subtle,
|
||||
digests: await Promise.all(
|
||||
vectors.map(({ value }) => module.sha256Hex(value)),
|
||||
),
|
||||
};
|
||||
}, SHA256_VECTORS);
|
||||
|
||||
expect(probe.subtlePresent).toBe("undefined");
|
||||
expect(probe.digests).toEqual(
|
||||
SHA256_VECTORS.map(({ digest }) => digest),
|
||||
);
|
||||
});
|
||||
|
||||
test("sha256Hex falls back when a partial subtle implementation throws", async ({
|
||||
page,
|
||||
}) => {
|
||||
await page.addInitScript(() => {
|
||||
let digestCalls = 0;
|
||||
Object.defineProperty(globalThis, "__sha256DigestCalls", {
|
||||
configurable: true,
|
||||
get: () => digestCalls,
|
||||
});
|
||||
Object.defineProperty(globalThis.crypto, "subtle", {
|
||||
configurable: true,
|
||||
value: {
|
||||
digest: async () => {
|
||||
digestCalls += 1;
|
||||
throw new DOMException(
|
||||
"partial Web Crypto implementation",
|
||||
"NotSupportedError",
|
||||
);
|
||||
},
|
||||
},
|
||||
});
|
||||
});
|
||||
await page.goto("/");
|
||||
|
||||
const probe = await page.evaluate(async (vectors) => {
|
||||
const module = await import("/src/lib/sha256.ts");
|
||||
const digests = await Promise.all(
|
||||
vectors.map(({ value }) => module.sha256Hex(value)),
|
||||
);
|
||||
return {
|
||||
subtlePresent: typeof globalThis.crypto.subtle,
|
||||
digestCalls: (
|
||||
globalThis as typeof globalThis & { __sha256DigestCalls: number }
|
||||
).__sha256DigestCalls,
|
||||
digests,
|
||||
};
|
||||
}, SHA256_VECTORS);
|
||||
|
||||
expect(probe.subtlePresent).toBe("object");
|
||||
expect(probe.digestCalls).toBe(SHA256_VECTORS.length);
|
||||
expect(probe.digests).toEqual(
|
||||
SHA256_VECTORS.map(({ digest }) => digest),
|
||||
);
|
||||
});
|
||||
|
||||
test("no product source calls crypto.randomUUID without the fallback", async () => {
|
||||
const { readFileSync, readdirSync, statSync } = await import("node:fs");
|
||||
const path = await import("node:path");
|
||||
|
|
@ -105,4 +195,28 @@ test.describe("insecure-context idempotency keys", () => {
|
|||
walk(root);
|
||||
expect(offenders).toEqual([]);
|
||||
});
|
||||
|
||||
test("no product source calls subtle.digest outside the sha256 fallback", async () => {
|
||||
const { readFileSync, readdirSync, statSync } = await import("node:fs");
|
||||
const path = await import("node:path");
|
||||
const root = path.join(process.cwd(), "src");
|
||||
const fallbackPath = path.join("lib", "sha256.ts");
|
||||
const offenders: string[] = [];
|
||||
const walk = (dir: string) => {
|
||||
for (const entry of readdirSync(dir)) {
|
||||
const full = path.join(dir, entry);
|
||||
if (statSync(full).isDirectory()) {
|
||||
walk(full);
|
||||
continue;
|
||||
}
|
||||
if (!/\.(ts|tsx)$/.test(entry)) continue;
|
||||
if (full.endsWith(fallbackPath)) continue;
|
||||
if (/\bsubtle\s*\??\.\s*digest\s*\(/.test(readFileSync(full, "utf8"))) {
|
||||
offenders.push(path.relative(root, full));
|
||||
}
|
||||
}
|
||||
};
|
||||
walk(root);
|
||||
expect(offenders).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
|
|
|||
116
apps/web/src/lib/sha256.ts
Normal file
116
apps/web/src/lib/sha256.ts
Normal file
|
|
@ -0,0 +1,116 @@
|
|||
const SHA256_INITIAL = new Uint32Array([
|
||||
0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, 0x510e527f,
|
||||
0x9b05688c, 0x1f83d9ab, 0x5be0cd19,
|
||||
]);
|
||||
|
||||
const SHA256_ROUND = new Uint32Array([
|
||||
0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b,
|
||||
0x59f111f1, 0x923f82a4, 0xab1c5ed5, 0xd807aa98, 0x12835b01,
|
||||
0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7,
|
||||
0xc19bf174, 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc,
|
||||
0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da, 0x983e5152,
|
||||
0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147,
|
||||
0x06ca6351, 0x14292967, 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc,
|
||||
0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
|
||||
0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819,
|
||||
0xd6990624, 0xf40e3585, 0x106aa070, 0x19a4c116, 0x1e376c08,
|
||||
0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f,
|
||||
0x682e6ff3, 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208,
|
||||
0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2,
|
||||
]);
|
||||
|
||||
function rotateRight(value: number, bits: number): number {
|
||||
return (value >>> bits) | (value << (32 - bits));
|
||||
}
|
||||
|
||||
function bytesToHex(bytes: Uint8Array): string {
|
||||
return Array.from(bytes, (byte) => byte.toString(16).padStart(2, "0")).join(
|
||||
"",
|
||||
);
|
||||
}
|
||||
|
||||
function portableSha256(bytes: Uint8Array): string {
|
||||
const paddedLength = Math.ceil((bytes.length + 9) / 64) * 64;
|
||||
const padded = new Uint8Array(paddedLength);
|
||||
padded.set(bytes);
|
||||
padded[bytes.length] = 0x80;
|
||||
|
||||
const view = new DataView(padded.buffer);
|
||||
const bitLength = bytes.length * 8;
|
||||
view.setUint32(paddedLength - 8, Math.floor(bitLength / 0x100000000));
|
||||
view.setUint32(paddedLength - 4, bitLength >>> 0);
|
||||
|
||||
const state = new Uint32Array(SHA256_INITIAL);
|
||||
const words = new Uint32Array(64);
|
||||
for (let offset = 0; offset < paddedLength; offset += 64) {
|
||||
for (let index = 0; index < 16; index += 1) {
|
||||
words[index] = view.getUint32(offset + index * 4);
|
||||
}
|
||||
for (let index = 16; index < 64; index += 1) {
|
||||
const previous = words[index - 15];
|
||||
const recent = words[index - 2];
|
||||
const sigma0 =
|
||||
rotateRight(previous, 7) ^
|
||||
rotateRight(previous, 18) ^
|
||||
(previous >>> 3);
|
||||
const sigma1 =
|
||||
rotateRight(recent, 17) ^
|
||||
rotateRight(recent, 19) ^
|
||||
(recent >>> 10);
|
||||
words[index] =
|
||||
(words[index - 16] + sigma0 + words[index - 7] + sigma1) >>> 0;
|
||||
}
|
||||
|
||||
let a = state[0];
|
||||
let b = state[1];
|
||||
let c = state[2];
|
||||
let d = state[3];
|
||||
let e = state[4];
|
||||
let f = state[5];
|
||||
let g = state[6];
|
||||
let h = state[7];
|
||||
for (let index = 0; index < 64; index += 1) {
|
||||
const sum1 = rotateRight(e, 6) ^ rotateRight(e, 11) ^ rotateRight(e, 25);
|
||||
const choose = (e & f) ^ (~e & g);
|
||||
const temporary1 =
|
||||
(h + sum1 + choose + SHA256_ROUND[index] + words[index]) >>> 0;
|
||||
const sum0 = rotateRight(a, 2) ^ rotateRight(a, 13) ^ rotateRight(a, 22);
|
||||
const majority = (a & b) ^ (a & c) ^ (b & c);
|
||||
const temporary2 = (sum0 + majority) >>> 0;
|
||||
h = g;
|
||||
g = f;
|
||||
f = e;
|
||||
e = (d + temporary1) >>> 0;
|
||||
d = c;
|
||||
c = b;
|
||||
b = a;
|
||||
a = (temporary1 + temporary2) >>> 0;
|
||||
}
|
||||
|
||||
state[0] = (state[0] + a) >>> 0;
|
||||
state[1] = (state[1] + b) >>> 0;
|
||||
state[2] = (state[2] + c) >>> 0;
|
||||
state[3] = (state[3] + d) >>> 0;
|
||||
state[4] = (state[4] + e) >>> 0;
|
||||
state[5] = (state[5] + f) >>> 0;
|
||||
state[6] = (state[6] + g) >>> 0;
|
||||
state[7] = (state[7] + h) >>> 0;
|
||||
}
|
||||
|
||||
return Array.from(state, (word) => word.toString(16).padStart(8, "0")).join(
|
||||
"",
|
||||
);
|
||||
}
|
||||
|
||||
export async function sha256Hex(value: string): Promise<string> {
|
||||
const bytes = new TextEncoder().encode(value);
|
||||
const subtle = globalThis.crypto?.subtle;
|
||||
if (subtle) {
|
||||
try {
|
||||
return bytesToHex(new Uint8Array(await subtle.digest("SHA-256", bytes)));
|
||||
} catch {
|
||||
// Some embedded or insecure runtimes expose Web Crypto partially.
|
||||
}
|
||||
}
|
||||
return portableSha256(bytes);
|
||||
}
|
||||
|
|
@ -20,6 +20,7 @@ import {
|
|||
} from "./deliberatePracticeApi";
|
||||
import "./deliberate-practice.css";
|
||||
import { randomUuid } from "../../lib/uuid";
|
||||
import { sha256Hex } from "../../lib/sha256";
|
||||
|
||||
interface PracticeTurn {
|
||||
id: string;
|
||||
|
|
@ -195,14 +196,7 @@ function splitCounterevidence(value: string): string[] {
|
|||
|
||||
async function phraseFingerprint(phrase: string): Promise<string> {
|
||||
const normalized = phrase.normalize("NFKC").trim().replace(/\s+/g, " ");
|
||||
const digest = await crypto.subtle.digest(
|
||||
"SHA-256",
|
||||
new TextEncoder().encode(normalized),
|
||||
);
|
||||
const hex = Array.from(new Uint8Array(digest), (byte) =>
|
||||
byte.toString(16).padStart(2, "0"),
|
||||
).join("");
|
||||
return `utterance-sha256:${hex}`;
|
||||
return `utterance-sha256:${await sha256Hex(normalized)}`;
|
||||
}
|
||||
|
||||
function turnForEvidence(
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue