UNPKG

tlsn-wasm

Version:

A core WebAssembly package for TLSNotary.

534 lines (495 loc) 16.3 kB
/* tslint:disable */ /* eslint-disable */ /** * A byte range paired with a hash algorithm for commitment. * * Uses explicit `start`/`end` fields (rather than `Range<usize>`) for * clean JS/TS interop via tsify. Converted to the sdk-core `CommitRange` * (which uses `Range<usize>`) in [`super::prover::convert_commit_range`]. */ export interface CommitRange { /** * Start of the byte range (inclusive). */ start: number; /** * End of the byte range (exclusive). */ end: number; /** * Hash algorithm to use for this range. */ algorithm: HashAlgorithm; } /** * Connection information. */ export interface ConnectionInfo { /** * Unix timestamp of the connection. */ time: number; /** * TLS version used. */ version: TlsVersion; /** * Transcript length information. */ transcript_length: TranscriptLength; } /** * Full transcript of sent and received data. */ export interface Transcript { /** * Data sent to the server. */ sent: number[]; /** * Data received from the server. */ recv: number[]; } /** * HTTP method. */ export type Method = "GET" | "POST" | "PUT" | "DELETE"; /** * HTTP request body. */ export type Body = JsonValue; /** * HTTP request. */ export interface HttpRequest { /** * Request URI. */ uri: string; /** * HTTP method. */ method: Method; /** * Request headers. */ headers: Map<string, number[]>; /** * Optional request body. */ body: Body | undefined; } /** * HTTP response. */ export interface HttpResponse { /** * HTTP status code. */ status: number; /** * Response headers. */ headers: [string, number[]][]; } /** * Hash algorithm for hash-commitment actions. */ export type HashAlgorithm = "BLAKE3" | "SHA256" | "KECCAK256"; /** * Network setting for protocol optimization. */ export type NetworkSetting = "Bandwidth" | "Latency"; /** * Opening for a single hash-committed range. * * Pairs the commitment hash with the blinder used to produce it, so the * caller can later prove `H(plaintext || blinder) == hash` without rerunning * MPC-TLS. Range and algorithm are not repeated — they live on the input * `CommitRange` at the same index. */ export interface HashOpening { /** * The commitment hash digest. */ hash: number[]; /** * The blinder (16 bytes) used to compute the commitment. */ blinder: number[]; } /** * Output from the verifier. */ export interface VerifierOutput { /** * Server name (if revealed). */ server_name: string | undefined; /** * Connection information. */ connection_info: ConnectionInfo; /** * Partial transcript (if revealed). */ transcript: PartialTranscript | undefined; } /** * Output of `Prover.reveal()`. * * Mirrors the input `Commit`: `sent[i]` opens `commit.sent[i]`, likewise for * `recv`. Both arrays are empty when no commit was supplied. */ export interface RevealOutput { /** * Openings for `commit.sent`, in input order. */ sent: HashOpening[]; /** * Openings for `commit.recv`, in input order. */ recv: HashOpening[]; } /** * Partial transcript with authenticated ranges. */ export interface PartialTranscript { /** * Data sent to the server. */ sent: number[]; /** * Authenticated ranges of sent data. */ sent_authed: { start: number; end: number }[]; /** * Data received from the server. */ recv: number[]; /** * Authenticated ranges of received data. */ recv_authed: { start: number; end: number }[]; } /** * Protocol mode for the prover. */ export type ProverMode = "Mpc" | "Proxy"; /** * Ranges of data to hash-commit. */ export interface Commit { /** * Ranges of sent data to commit, each with its own algorithm. */ sent: CommitRange[]; /** * Ranges of received data to commit, each with its own algorithm. */ recv: CommitRange[]; } /** * Ranges of data to reveal. */ export interface Reveal { /** * Ranges of sent data to reveal. */ sent: { start: number; end: number }[]; /** * Ranges of received data to reveal. */ recv: { start: number; end: number }[]; /** * Whether to reveal the server identity. */ server_identity: boolean; } /** * TLS version. */ export type TlsVersion = "V1_2" | "V1_3"; /** * Transcript length information. */ export interface TranscriptLength { /** * Bytes sent. */ sent: number; /** * Bytes received. */ recv: number; } export interface CrateLogFilter { level: LoggingLevel; name: string; } export interface LoggingConfig { level: LoggingLevel | undefined; crate_filters: CrateLogFilter[] | undefined; span_events: SpanEvent[] | undefined; } export interface ProverConfig { server_name: string; mode: ProverMode; max_sent_data: number; max_sent_records: number | undefined; max_recv_data_online: number | undefined; max_recv_data: number; max_recv_records_online: number | undefined; defer_decryption_from_start: boolean | undefined; network: NetworkSetting; client_auth: [number[][], number[]] | undefined; /** * Custom root certificates (DER-encoded) for TLS server verification. * * If not provided, Mozilla root certificates are used. */ root_certs: number[][] | undefined; } export interface VerifierConfig { max_sent_data: number; max_recv_data: number; max_sent_records: number | undefined; max_recv_records_online: number | undefined; /** * Custom root certificates (DER-encoded) for TLS server verification. * * If not provided, Mozilla root certificates are used. */ root_certs: number[][] | undefined; } export type LoggingLevel = "Off" | "Trace" | "Debug" | "Info" | "Warn" | "Error"; export type SpanEvent = "New" | "Close" | "Active"; /** * Prover for the TLSNotary protocol. * * The prover connects to both a verifier and a target server, executing the * MPC-TLS protocol to generate verifiable proofs of the TLS session. */ export class Prover { free(): void; [Symbol.dispose](): void; /** * Creates a new Prover with the given configuration. */ constructor(config: ProverConfig); /** * Reveals data to the verifier and finalizes the protocol. * * Optionally accepts a `Commit` object with ranges to hash-commit. * Pass `undefined` or omit the second argument for reveal-only proofs. * * Returns a `RevealOutput` with one `CommitmentOpening` per * hash-committed range (`{ direction, ranges, algorithm, hash, blinder * }`), in the same order as the input `Commit`. The `commitments` * array is empty when no commit was supplied. */ reveal(reveal: Reveal, commit?: Commit | null): Promise<RevealOutput>; /** * Sends an HTTP request to the server. * * # Arguments * * * `server_io` - An IoChannel connected to the server. Must be provided * in MPC mode. Must be `None` in proxy mode, where the connection is * routed through the verifier. * * `request` - The HTTP request to send. */ send_request(server_io: IoChannel | null | undefined, request: HttpRequest): Promise<HttpResponse>; /** * Sets a progress callback that receives structured progress updates. * * The callback receives a single argument: `{ step: string, progress: * number, message: string }`. * * Steps emitted: `MPC_SETUP`, `CONNECTING_TO_SERVER`, `SENDING_REQUEST`, * `REQUEST_COMPLETE`, `REVEAL`, `FINALIZED`. */ set_progress_callback(callback: Function): void; /** * Sets up the prover with the verifier. * * This performs all MPC setup prior to establishing the connection to the * application server. * * # Arguments * * * `verifier_io` - A JavaScript object implementing the IoChannel * interface, connected to the verifier. */ setup(verifier_io: IoChannel): Promise<void>; /** * Returns the transcript of the TLS session. */ transcript(): Transcript; } /** * Global spawner which spawns closures into web workers. */ export class Spawner { private constructor(); free(): void; [Symbol.dispose](): void; intoRaw(): number; /** * Runs the spawner. */ run(url: string): Promise<void>; } /** * Verifier for the TLSNotary protocol. * * The verifier participates in the MPC-TLS protocol with the prover, * verifying the authenticity of the TLS session without seeing the * full plaintext. */ export class Verifier { free(): void; [Symbol.dispose](): void; /** * Connects to the prover. * * # Arguments * * * `prover_io` - A JavaScript object implementing the IoChannel * interface, connected to the prover. */ connect(prover_io: IoChannel): Promise<void>; /** * Creates a new Verifier with the given configuration. */ constructor(config: VerifierConfig); /** * Runs the verifier until the TLS connection is closed. * * In proxy mode, `set_server_socket()` must be called first. */ run(): Promise<void>; /** * Provides the server socket for proxy mode. * * Must be called between `setup()` and `run()` when `setup` returned a * server name. * * # Arguments * * * `server_io` - A JavaScript object implementing the IoChannel * interface, connected to the server. */ set_server_socket(server_io: IoChannel): void; /** * Performs the commitment handshake with the prover. * * Returns the server name in proxy mode, or null/undefined for MPC * mode. When a server name is returned, call `set_server_socket()` * with a connection to that server before calling `run()`. */ setup(): Promise<string | undefined>; /** * Verifies the connection and finalizes the protocol. */ verify(): Promise<VerifierOutput>; } export class WorkerData { private constructor(); free(): void; [Symbol.dispose](): void; } /** * Parses HTTP request/response transcripts and maps handlers to byte ranges. * * This is the WASM wrapper around `tlsn_sdk_core::compute_reveal`. * * # Arguments * * * `sent` - Raw bytes of the HTTP request (sent data). * * `recv` - Raw bytes of the HTTP response (received data). * * `handlers` - Array of handler objects (deserialized from JS). * * # Returns * * A `ComputeRevealOutput` object containing: * - `sentRanges` / `recvRanges`: byte ranges for `Prover.reveal()` * - `sentRangesWithHandlers` / `recvRangesWithHandlers`: ranges annotated with * handlers * - `commit` (optional): ranges to hash-commit, with per-range algorithm */ export function compute_reveal(sent: Uint8Array, recv: Uint8Array, handlers: any): any; /** * Initializes the module. */ export function initialize(logging_config: LoggingConfig | null | undefined, thread_count: number): Promise<void>; /** * Starts the thread spawner on a dedicated worker thread. */ export function startSpawner(): Promise<any>; export function web_spawn_recover_spawner(spawner: number): Spawner; export function web_spawn_start_worker(worker: number): void; export type InitInput = RequestInfo | URL | Response | BufferSource | WebAssembly.Module; export interface InitOutput { readonly __wbg_prover_free: (a: number, b: number) => void; readonly __wbg_verifier_free: (a: number, b: number) => void; readonly compute_reveal: (a: number, b: number, c: number, d: number, e: any) => [number, number, number]; readonly initialize: (a: number, b: number) => any; readonly prover_new: (a: any) => [number, number, number]; readonly prover_reveal: (a: number, b: any, c: number) => any; readonly prover_send_request: (a: number, b: number, c: any) => any; readonly prover_set_progress_callback: (a: number, b: any) => void; readonly prover_setup: (a: number, b: any) => any; readonly prover_transcript: (a: number) => [number, number, number]; readonly verifier_connect: (a: number, b: any) => any; readonly verifier_new: (a: any) => [number, number, number]; readonly verifier_run: (a: number) => any; readonly verifier_set_server_socket: (a: number, b: any) => [number, number]; readonly verifier_setup: (a: number) => any; readonly verifier_verify: (a: number) => any; readonly __wbg_spawner_free: (a: number, b: number) => void; readonly __wbg_workerdata_free: (a: number, b: number) => void; readonly spawner_intoRaw: (a: number) => number; readonly spawner_run: (a: number, b: number, c: number) => any; readonly startSpawner: () => any; readonly web_spawn_recover_spawner: (a: number) => number; readonly web_spawn_start_worker: (a: number) => void; readonly ring_core_0_17_14__bn_mul_mont: (a: number, b: number, c: number, d: number, e: number, f: number) => void; readonly wasm_bindgen_4c831161ffc18f38___convert__closures_____invoke___wasm_bindgen_4c831161ffc18f38___JsValue__core_104fa5104cbe979c___result__Result_____wasm_bindgen_4c831161ffc18f38___JsError___true_: (a: number, b: number, c: any) => [number, number]; readonly wasm_bindgen_4c831161ffc18f38___convert__closures_____invoke___js_sys_aaafd26f4c58237a___Function_fn_wasm_bindgen_4c831161ffc18f38___JsValue_____wasm_bindgen_4c831161ffc18f38___sys__Undefined___js_sys_aaafd26f4c58237a___Function_fn_wasm_bindgen_4c831161ffc18f38___JsValue_____wasm_bindgen_4c831161ffc18f38___sys__Undefined_______true_: (a: number, b: number, c: any, d: any) => void; readonly wasm_bindgen_4c831161ffc18f38___convert__closures_____invoke___wasm_bindgen_4c831161ffc18f38___JsValue______true_: (a: number, b: number, c: any) => void; readonly wasm_bindgen_4c831161ffc18f38___convert__closures_____invoke___js_sys_aaafd26f4c58237a___futures__task__wait_async_polyfill__MessageEvent______true_: (a: number, b: number, c: any) => void; readonly memory: WebAssembly.Memory; readonly __wbindgen_malloc: (a: number, b: number) => number; readonly __wbindgen_realloc: (a: number, b: number, c: number, d: number) => number; readonly __wbindgen_exn_store: (a: number) => void; readonly __externref_table_alloc: () => number; readonly __wbindgen_externrefs: WebAssembly.Table; readonly __wbindgen_free: (a: number, b: number, c: number) => void; readonly __wbindgen_destroy_closure: (a: number, b: number) => void; readonly __externref_table_dealloc: (a: number) => void; readonly __wbindgen_thread_destroy: (a?: number, b?: number, c?: number) => void; readonly __wbindgen_start: (a: number) => void; } export type SyncInitInput = BufferSource | WebAssembly.Module; /** * Instantiates the given `module`, which can either be bytes or * a precompiled `WebAssembly.Module`. * * @param {{ module: SyncInitInput, memory?: WebAssembly.Memory, thread_stack_size?: number }} module - Passing `SyncInitInput` directly is deprecated. * @param {WebAssembly.Memory} memory - Deprecated. * * @returns {InitOutput} */ export function initSync(module: { module: SyncInitInput, memory?: WebAssembly.Memory, thread_stack_size?: number } | SyncInitInput, memory?: WebAssembly.Memory): InitOutput; /** * If `module_or_path` is {RequestInfo} or {URL}, makes a request and * for everything else, calls `WebAssembly.instantiate` directly. * * @param {{ module_or_path: InitInput | Promise<InitInput>, memory?: WebAssembly.Memory, thread_stack_size?: number }} module_or_path - Passing `InitInput` directly is deprecated. * @param {WebAssembly.Memory} memory - Deprecated. * * @returns {Promise<InitOutput>} */ export default function __wbg_init (module_or_path?: { module_or_path: InitInput | Promise<InitInput>, memory?: WebAssembly.Memory, thread_stack_size?: number } | InitInput | Promise<InitInput>, memory?: WebAssembly.Memory): Promise<InitOutput>;