import { describe, expect, it } from 'vitest' import type { AuthorizedDeviceContext } from 'relay-contracts' import { unwrapAeadKey } from '../src/aead-key.js' import { deriveContentKey } from '../src/replay-key.js' import { buildClientHandshake, MemoryDevicePinStore } from '../src/keystore.js' import { createHostHandshake } from '../src/handshake.js' import { nobleEd25519Signer } from '../src/ed25519.js' import { boundProofProvider, makeHostIdentity, verifyBoundProof, bytesToHex } from './helpers.js' import * as publicSurface from '../src/index.js' function ctxFor(hostContentSecret: Uint8Array): AuthorizedDeviceContext { return { deviceAuthProofProvider: boundProofProvider(), pinStore: new MemoryDevicePinStore(), hostContentSecret, } } describe('T11 multi-device adapters (authenticated channel, NOT a QR)', () => { it('two authorized contexts (same secret) each complete a handshake + derive matching K_content', async () => { const id = makeHostIdentity() const secret = new Uint8Array(32).fill(0x55) const mkHost = () => createHostHandshake({ signer: nobleEd25519Signer(id.privateKey), agentPubkey: id.agentPubkey, supported: ['xchacha20-poly1305', 'aes-256-gcm'], verifyDeviceProof: async (p, b) => verifyBoundProof(p, b), }) for (const label of ['deviceA', 'deviceB']) { const ch = buildClientHandshake(ctxFor(secret), 'h1', ['xchacha20-poly1305']) const host = mkHost() const hello = await ch.start() const hostHello = await host.onClientHello(hello) const result = await ch.onHostHello(hostHello, id.agentPubkey) expect(result.aead).toBe('xchacha20-poly1305') expect(label).toBeTruthy() } const kA = deriveContentKey({ hostContentSecret: secret, sessionId: 's', alg: 'aes-256-gcm' }) const kB = deriveContentKey({ hostContentSecret: secret, sessionId: 's', alg: 'aes-256-gcm' }) expect(bytesToHex(unwrapAeadKey(kA).raw)).toBe(bytesToHex(unwrapAeadKey(kB).raw)) }) it('no-QR assertion: the public surface exposes NO key→string/QR serializer', () => { const names = Object.keys(publicSurface) const forbidden = names.filter((n) => /qr|serializekey|exportkey|keytostring|tosharestring/i.test(n)) expect(forbidden).toEqual([]) }) it('INV3: a context whose proof is unbound is rejected by the host gate (no session)', async () => { const id = makeHostIdentity() const ctx: AuthorizedDeviceContext = { deviceAuthProofProvider: { async proofFor() { return 'static-bearer-token' } }, pinStore: new MemoryDevicePinStore(), hostContentSecret: new Uint8Array(32), } const ch = buildClientHandshake(ctx, 'h1', ['aes-256-gcm']) const host = createHostHandshake({ signer: nobleEd25519Signer(id.privateKey), agentPubkey: id.agentPubkey, supported: ['aes-256-gcm'], verifyDeviceProof: async (p, b) => verifyBoundProof(p, b), }) await expect(host.onClientHello(await ch.start())).rejects.toBeTruthy() }) })