fix(crypto): use Convex seeded randomness for IVs #1

Merged
phantasy merged 3 commits from feature/wave23-selfhosted-crypto into main 2026-09-27 01:09:38 +00:00
Owner

Summary

  • merge current canonical main into the self-hosted app-side encryption branch
  • replace the timestamp/plaintext-derived AES-GCM IV fallback with Convex seeded Math.random output
  • add a regression test that forces unavailable Web Crypto randomness and freezes time

Validation

  • bun run test — 8 passed
  • bun run typecheck — passed
  • bun run build — passed

Convex documents Math.random as a seeded strong PRNG for deterministic mutations.

## Summary - merge current canonical main into the self-hosted app-side encryption branch - replace the timestamp/plaintext-derived AES-GCM IV fallback with Convex seeded Math.random output - add a regression test that forces unavailable Web Crypto randomness and freezes time ## Validation - `bun run test` — 8 passed - `bun run typecheck` — passed - `bun run build` — passed Convex documents Math.random as a seeded strong PRNG for deterministic mutations.
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
phantasy/secret-manager!1
No description provided.