Press n or j to go to the next uncovered block, b, p or k for the previous block.
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 | 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x | /*!
* Copyright (c) 2026 The Triauth Authors (https://www.triauth.org/)
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* SPDX-License-Identifier: Apache-2.0
*/
/**
* The global triauth-js configuration, exposed as `Triauth.config` and shared by reference with every internal module.
* Each API method also takes a per-call override object as its last argument, and an unknown key in either place is
* rejected with error 103. The `logger` and `resolver` defaults are filled in by the entry module.
* The global `config` object should not be mutated while API calls are in flight.
*
* @type {{
* requireSecure: boolean,
* resolver: (object|null),
* logger: (object|null),
* randomSource: (function(Uint8Array): void|null),
* maximalAllowedClientClockDrift: number,
* maximalAllowedServerClockDrift: number,
* authTimeout: number,
* pingTimeout: number,
* attestTimeout: number,
* signTimeout: number,
* stampTimeout: number,
* cid: (string|false|null)
* }}
*/
export const config = {
// When true, all challenge-response API methods (authenticate, ping, attest, sign, stamp), Triauth.check,
// and Triauth.verify require a successful result to be DNSSEC-secure: any otherwise-valid response that was
// not reported DNSSEC-validated (`secure !== true`) is rejected with error 404 ("Your domain does not
// support DNSSEC, which is required to continue."). Leave false (default) to inspect the `secure` property yourself and stay
// interoperable with non-DNSSEC domains; set true for mission-critical systems that demand strict
// cryptographic assurance.
requireSecure: false,
resolver: null,
logger: null,
// Source of cryptographic randomness used to generate challenge nonces. Must be a function that
// fills a given `Uint8Array` in place with random bytes (same shape as `crypto.getRandomValues`).
// Leave as null to use `crypto.getRandomValues` from the Web Crypto API (default). You may
// override this with a higher-entropy or hardware-backed RNG, or - in test scenarios - with
// a deterministic byte stream to make nonces reproducible.
randomSource: null,
// The maximal allowed clock drift between the current clock (e.g., server time), and the end-user's clock (as seen by the web browser and Triauth Authenticator app),
// including network round-trip time and any request pre-processing delays.
// Applied when checking timestamps generated by the user's device (e.g., the `ts` embedded in signatures).
maximalAllowedClientClockDrift: 30 * 1e3,
// The maximal allowed clock drift between your own servers - e.g., when, due to load balancing, a challenge
// is generated (stage 1) and verified (stage 3) by two different hosts with imperfectly synchronized clocks.
// Applied when checking timestamps generated by your own servers (the challenge `iat` freshness window).
// Keep it small: well-managed (NTP-synchronized) fleets stay within milliseconds of each other.
maximalAllowedServerClockDrift: 5 * 1e3,
// Timeout for the user to approve the request before it is considered expired (basing on challenge `iat` time, widened by `maximalAllowedServerClockDrift`).
authTimeout: 3 * 60e3,
pingTimeout: 15e3,
attestTimeout: 15 * 60e3,
signTimeout: 30 * 60e3,
stampTimeout: 15e3,
// The correlation id, emitted by the logger to trace related log entries across the system. Three modes:
// - null (default): "autofill" - the logger mints a fresh id for each API call (shown as `[cid:...]`).
// - false: explicit opt-out - no `[cid:...]` tag is emitted.
// - string: use this exact id for the call.
cid: null
};
/**
* Frozen snapshot of the recognized `Triauth.config` keys, captured at module load.
*
* The public API methods use this to reject config overrides that carry an unknown key (error 103).
*
* @type {ReadonlyArray<string>}
*/
export const KNOWN_CONFIG_KEYS = Object.freeze(Object.keys(config));
|