Copy the local key vault (src/, tests/) verbatim from alknet/crates/alknet-vault and create a standalone Cargo.toml (workspace-inherited fields inlined). Port the architecture docs (specs, ADRs 018-026, OQs 020-022) from alknet's nested multi-crate layout to a flat single-crate layout, fixing relative link paths. ADR and OQ numbers are preserved from alknet; a subsequent pass will renumber them to a per-project sequence (001, 002, ...) and rebrand alknet-vault -> alkvault (crate name, lib name, prose), updating the cross-references to non-vault alknet ADRs (003, 005, 008, 010, 014, 064) that are referenced in the copied docs but not copied over. Build, 108 tests, and clippy all pass clean.
59 lines
1.9 KiB
Rust
59 lines
1.9 KiB
Rust
//! Integration tests for AES-256-GCM encryption and decryption.
|
|
//!
|
|
//! These tests verify round-trip encryption, key version handling,
|
|
//! and wire format compatibility.
|
|
|
|
use alknet_vault::encryption::CURRENT_KEY_VERSION;
|
|
use alknet_vault::service::VaultServiceHandle;
|
|
|
|
#[test]
|
|
fn test_encrypt_decrypt_round_trip_via_service() {
|
|
let service = VaultServiceHandle::new();
|
|
service.unlock_new(24).unwrap();
|
|
|
|
let plaintext = "sk-proj-abc123xyz789";
|
|
|
|
let encrypted = service.encrypt(plaintext, CURRENT_KEY_VERSION).unwrap();
|
|
let decrypted = service.decrypt(&encrypted).unwrap();
|
|
|
|
assert_eq!(decrypted, plaintext);
|
|
}
|
|
|
|
#[test]
|
|
fn test_encrypt_produces_different_ciphertext_each_time() {
|
|
let service = VaultServiceHandle::new();
|
|
service.unlock_new(24).unwrap();
|
|
|
|
let plaintext = "same input different ciphertexts";
|
|
|
|
let encrypted1 = service.encrypt(plaintext, CURRENT_KEY_VERSION).unwrap();
|
|
let encrypted2 = service.encrypt(plaintext, CURRENT_KEY_VERSION).unwrap();
|
|
|
|
// Different IVs mean different ciphertexts
|
|
assert_ne!(encrypted1.iv, encrypted2.iv);
|
|
assert_ne!(encrypted1.data, encrypted2.data);
|
|
// But same key version
|
|
assert_eq!(encrypted1.key_version, encrypted2.key_version);
|
|
}
|
|
|
|
#[test]
|
|
fn test_encrypted_data_serialization() {
|
|
let service = VaultServiceHandle::new();
|
|
service.unlock_new(24).unwrap();
|
|
|
|
let plaintext = "test serialization";
|
|
let encrypted = service.encrypt(plaintext, CURRENT_KEY_VERSION).unwrap();
|
|
|
|
// Verify EncryptedData serializes to JSON
|
|
let json = serde_json::to_string(&encrypted).unwrap();
|
|
assert!(json.contains("key_version"));
|
|
assert!(json.contains("salt"));
|
|
assert!(json.contains("iv"));
|
|
assert!(json.contains("data"));
|
|
|
|
// Verify round-trip through JSON
|
|
let deserialized: alknet_vault::encryption::EncryptedData =
|
|
serde_json::from_str(&json).unwrap();
|
|
assert_eq!(deserialized, encrypted);
|
|
}
|