fix(crypto): support enveloped keys in mutation runtime #2

Merged
phantasy merged 2 commits from feature/wave23-selfhosted-crypto into main 2026-09-27 01:20:02 +00:00
Owner

Summary

  • use one randomness helper for legacy and envelope AES-GCM paths
  • fall back to Convex’s seeded strong Math.random PRNG when Web Crypto randomness is unavailable
  • verify legacy IVs, envelope DEKs, and envelope IVs remain distinct and decrypt correctly

Validation

  • bun run test — 8 passed
  • bun run typecheck — passed
  • bun run build — passed

This follows Convex’s deterministic mutation runtime contract.

## Summary - use one randomness helper for legacy and envelope AES-GCM paths - fall back to Convex’s seeded strong Math.random PRNG when Web Crypto randomness is unavailable - verify legacy IVs, envelope DEKs, and envelope IVs remain distinct and decrypt correctly ## Validation - `bun run test` — 8 passed - `bun run typecheck` — passed - `bun run build` — passed This follows Convex’s deterministic mutation runtime contract.
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
phantasy/secret-manager!2
No description provided.