Skip to content

Use @profullstack/encrypt for message encryption (0.5.7, qc 0.4.5) - #290

Merged
ralyodio merged 1 commit into
masterfrom
refactor/use-profullstack-encrypt
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
refactor/use-profullstack-encrypt

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Anthony: "do it", meaning switch qrypt.chat and qc to @profullstack/encrypt instead of their own copies of the crypto.

What changed: PostQuantumEncryptionService.encryptForRecipient / decryptFromSender now call encrypt/decrypt from @profullstack/encrypt 0.1.0 for the cipher itself: ML-KEM + HKDF-SHA-256 + ChaCha20-Poly1305 in the v3 envelope.

Everything qrypt.chat-specific stays where it was:

  • key header stripping and the strict size checks, with their "Nuclear Key Reset" hints
  • the 1024/768 key choice
  • the long legacy field names
  • the legacy AES message, and the "try 1024 then 768" path for envelopes with no algorithm
  • the friendly result strings in place of throws

These two methods are used by the web app, qc, qc's MCP server and the CLI login key handoff, so all of them now run on the shared library. About 240 lines of duplicated crypto are removed.

Verification

  • New tests/crypto/profullstack-encrypt-interop.test.js (6 tests):
    • app ↔ library in both directions
    • ML-KEM-768 keys
    • long field names
    • every friendly result (not JSON, legacy AES, format error, someone else's message)
    • a wrong-size key rejected
    • raw mlkem keys
  • The library's own tests decrypt an envelope made by the previous qrypt.chat code, so messages already stored keep opening.
  • 688/688 vitest; next build and the qc bundle build pass. The qc bundle keeps @profullstack/encrypt external, and it is listed in qc's dependencies.

Note: messaging and crypto are Preshy's area; Anthony asked for this directly.

🤖 Generated with Claude Code

PostQuantumEncryptionService.encryptForRecipient/decryptFromSender keep
qrypt.chat's key handling (header stripping, size checks, 1024/768 key
choice, legacy field names, friendly results) and hand the cipher itself
(ML-KEM + HKDF-SHA-256 + ChaCha20-Poly1305, v3 envelope) to the shared
library. The web app, qc, its MCP server and the CLI login handoff all go
through these two methods. ~240 lines of duplicated crypto removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

MEDIUM: 9 | LOW: 4

Severity Rule Location
MEDIUM redos-nested-quantifier src/app/api/profile/update/route.js:73
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:38
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:66
MEDIUM js-unescaped-html-sink src/app/faq/page.jsx:57
MEDIUM js-unescaped-html-sink src/app/layout.jsx:137
MEDIUM js-unescaped-html-sink src/app/layout.jsx:141
MEDIUM js-unescaped-html-sink src/app/page.jsx:47
MEDIUM redos-nested-quantifier src/lib/auth/dns-name.js:88
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:121
LOW secret-generic-credential src/app/api/auth/register-anon/route.test.js:32
LOW secret-jwt tests/debug-sms.js:10
LOW secret-generic-credential tests/private-key-import-export.test.js:252
LOW secret-generic-credential tests/private-key-import-export.test.js:264

Snippets are redacted; ThreatCrush never prints matched credential material.

@socket-security

Copy link
Copy Markdown
Contributor

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​profullstack/​encrypt@​0.1.07410010090100

View full report

@ralyodio
ralyodio merged commit a114c96 into master Oct 6, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant