Files
FixIt/assets/js/modules/encryption.ts
T
Cell a96ba665ac refactor(assets)!: rewrite content encryption with AES-256-GCM and PBKDF2 (#806)
* refactor(assets)!: rewrite content encryption with AES-256-GCM and PBKDF2

- Remove legacy Base64 obfuscation layer (content-encryption.html)
- Replace <cipher-text> with <template> for inert content storage
- Single-layer AES-256-GCM encryption via post-build script
- PBKDF2 key derivation (100k iterations) for encryption
- PBKDF2-protected password verification (data-verify-salt)
- Depth-tracking parser for nested shortcode support
- Dev mode: plaintext content used directly without encryption
- Remove crypto-js and xxhash-wasm vendored dependencies

* feat(post-encrypt): prepare package for npm publishing

- Add bin entry, build script, and dist output for npx usage
- Replace @hugo-fixit/shared with standalone implementations
- Add CLI shebang for direct execution
- Add package README with usage documentation
- Remove FIXIT_ENCRYPT_INPUT env var (redundant with --input)
- Add encryption detection warning in assets.html
- Remove Post-build Encryption sections from READMEs

* chore: integrate post-encrypt into build pipeline and use consola

- Replace console with consola for post-encrypt logging
- Improve verification messages (no templates, count, etc.)
- Simplify build scripts: encrypt runs as part of main build
- Update encryption detection warning to use npx command

* feat(assets): add encryption dev warning admonition

- Add danger admonition in single.html for full-page encryption (dev mode only)
- Add encryption detection warning in assets.html console
- Improve post-encrypt verification messages with template count

* feat(assets): improve encryption i18n, cache security, and error handling

- Add encryptionWarning and encryptionCommand i18n keys for all 16 languages
- Store PBKDF2 verification hash in localStorage cache for better security
- Show decryption errors via flashTooltip instead of console only
- Add FixItDecryptor type definitions in global.ts
- Move encryption detection to init/detection-encryption.html with batched warning
- Remove redundant per-page warning from assets.html

* feat(assets): redesign fixit-decryptor UI with card layout

- Page-level: card form with lock icon header, password input with key icon, primary-colored unlock button, circular re-encrypt button
- Shortcode-level: connected input+button design (search bar style) with focus ring sync
- Remove loading spinner, use display:none/flex toggle via .initialized class
- Move lock icon styling to UnoCSS (text-primary text-xl)
- Initialize CellTooltip on re-encrypt button
- Fix JSDoc @param warnings in global.ts

* refactor(assets): unify TOC template and decryptor animations

- TOC always rendered in `<template data-toc>`, containers populated by initToc()
- Moved TOC scroll/resize handling from events.ts to toc.ts (syncTocLayout, syncTocActiveState)
- Removed EventsModule toc dependency, updated public-api.ts constructor
- Removed visibility:hidden from #toc-auto
- Decryptor: form always visible, @starting-style for fade-in on init
- Decryptor: content expand/collapse animation using height + opacity
- Removed encrypted-hidden from TOC elements in single.html

* refactor(assets): add target to fixit:decrypted event and simplify handlers

- Add { target: Element } payload to fixit:decrypted in event-bus.ts
- Remove $content closure from fixit-decryptor init(), use detail.target
- Update content.ts and toc.ts to use detail.target from event

* fix(assets): use eventBus for TOC scroll/resize listeners and eliminate redundant template parsing

- Replace raw window scroll/resize listeners in TocModule with eventBus
  subscriptions (fixit:scroll/fixit:resize), reusing EventsModule's
  throttle and debounce instead of duplicating un-throttled handlers.
- Refactor hasUnencryptedTemplate in post-encrypt to accept the already-
  computed matches array, avoiding a redundant findEncryptionTemplates
  call on the same HTML content.
- Remove crypto-js and xxhash-wasm from README credits.

* style(assets): soften decryptor button background and add form hover shadow

* build(workflow): add post-encrypt step to build script
2026-07-05 23:26:11 +08:00

46 lines
1.6 KiB
TypeScript

import type { CoreService, EncryptionService } from '../core/tokens'
import { eventBus } from '../core/event-bus'
/**
* Encryption module — page decryption via FixItDecryptor and encrypted content toggling.
*
* Responsibilities:
* - Initialize FixItDecryptor for full-page and shortcode-scoped decryption.
* - Toggle visibility of encrypted content sections.
*/
export class EncryptionModule implements EncryptionService {
constructor(private readonly core: CoreService) {}
/**
* Toggle between encrypted-hidden and decrypted-shown classes.
* @param container - The root element containing encrypted elements.
* @param show - `true` to show decrypted content, `false` to hide.
*/
#toggleEncryptedClass(container: Element | Document, show: boolean) {
const fromClass = show ? 'encrypted-hidden' : 'decrypted-shown'
const toClass = show ? 'decrypted-shown' : 'encrypted-hidden'
container.querySelectorAll(`.${fromClass}`).forEach(($element: Element) => {
$element.classList.replace(fromClass, toClass)
})
}
/** Initialize the FixItDecryptor and wire up decryption/re-encryption events. */
setup() {
if (!this.core.config.encryption || !window.FixItDecryptor)
return
const decryptor = new window.FixItDecryptor()
eventBus.on('fixit:decrypted', () => {
this.#toggleEncryptedClass(document, true)
})
eventBus.on('fixit:partial-decrypted', ({ detail }) => {
this.#toggleEncryptedClass(detail.target, true)
})
eventBus.on('fixit:re-encrypt', () => {
this.#toggleEncryptedClass(document, false)
})
decryptor.init(this.core.config.encryption)
}
}