* Derive a key from password using Argon2id
(password, salt)
| 52 | * Derive a key from password using Argon2id |
| 53 | */ |
| 54 | async function deriveKey(password, salt) { |
| 55 | // Ensure hash-wasm is loaded (initHashWasm returns a promise that resolves when ready) |
| 56 | if (!window.argon2id) { |
| 57 | await window.initHashWasm(); |
| 58 | } |
| 59 | |
| 60 | // Argon2id returns raw bytes (Uint8Array) |
| 61 | const derivedBytes = await window.argon2id({ |
| 62 | password, |
| 63 | salt, |
| 64 | parallelism: ARGON2_PARALLELISM, |
| 65 | iterations: ARGON2_ITERATIONS, |
| 66 | memorySize: ARGON2_MEMORY, |
| 67 | hashLength: ARGON2_HASH_LENGTH, |
| 68 | outputType: 'binary' |
| 69 | }); |
| 70 | |
| 71 | // Import raw bytes as AES-GCM key |
| 72 | return crypto.subtle.importKey( |
| 73 | 'raw', |
| 74 | derivedBytes, |
| 75 | { name: 'AES-GCM' }, |
| 76 | false, |
| 77 | ['encrypt', 'decrypt'] |
| 78 | ); |
| 79 | } |
| 80 | |
| 81 | /** |
| 82 | * Encrypt data with password |