This commit is contained in:
2026-09-17 23:00:47 +08:00
parent def731fc5a
commit 8883a5c506
43 changed files with 4530 additions and 1515 deletions
+45
View File
@@ -137,6 +137,51 @@ describe("crypto-store - 设置/解锁/锁定", () => {
});
});
describe("crypto-store - unlockWithKey(密钥句柄恢复)", () => {
it("用 setupVault 返回的密钥可重新解锁,无需口令", async () => {
const storage = createMemoryStorage();
const C = loadCryptoStore(storage);
const key = await C.setupVault("pw", [{ id: "e1", name: "个人", configs: [{ domain: "a.com" }] }]);
await C.lock();
assert.equal(await C.isUnlocked(), false);
// 模拟 SW 重启后从 IndexedDB 取回句柄
const environments = await C.unlockWithKey(key);
assert.equal(environments.length, 1);
assert.equal(environments[0].name, "个人");
assert.equal(await C.isUnlocked(), true);
assert.ok(storage.sessionStore.environments);
// 全程没有明文口令落进任何存储
assert.equal(storage.sessionStore.__autoPwd, undefined);
});
it("密钥与 vault 不匹配时抛错", async () => {
const storage = createMemoryStorage();
const C = loadCryptoStore(storage);
await C.setupVault("pw", [{ id: "e1", name: "x", configs: [] }]);
await C.lock();
const otherKey = await C.deriveKey("别的口令", C.randomBytes(16), C.PBKDF2_ITERATIONS);
await assert.rejects(() => C.unlockWithKey(otherKey));
assert.equal(await C.isUnlocked(), false);
});
it("未设置口令时 unlockWithKey 抛错", async () => {
const C = loadCryptoStore(createMemoryStorage());
const key = await C.deriveKey("pw", C.randomBytes(16), C.PBKDF2_ITERATIONS);
await assert.rejects(() => C.unlockWithKey(key), /尚未设置口令/);
});
it("重设口令后旧句柄失效(背景会据此丢弃句柄)", async () => {
const storage = createMemoryStorage();
const C = loadCryptoStore(storage);
const oldKey = await C.setupVault("old-pw", [{ id: "e1", name: "x", configs: [] }]);
await C.setupVault("new-pw", [{ id: "e1", name: "x", configs: [] }]);
await C.lock();
await assert.rejects(() => C.unlockWithKey(oldKey));
});
});
describe("crypto-store - persistEncrypted", () => {
it("用密钥重新加密 environments 写回 local", async () => {
const storage = createMemoryStorage();