AuthEncryptViaAES256

by raddevus

HTML

<script src="https://cdnjs.cloudflare.com/ajax/libs/crypto-js/3.1.2/rollups/aes.js"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/js-sha256/0.9.0/sha256.min.js"></script>
 <p><input type="text" id="password" placeholder="password"></p>
        <input id="clear_text" type="text" placeholder="clear text">
        <button onclick="encryptFromText()">encrypt</button>
        <label for="useIVCheckBox">Use IV (Init Vector)</label>
        <input id="useIVCheckBox" type="checkbox" checked>
        <div id="cipher_output" class="selectable"></div>
        <input id="cipher_text" type="text" placeholder="cipher text">
        <button onclick="decryptFromText()">decrypt</button>
        <div id="cleartext_output"></div>
        <div>
          <button onclick="generateHmac()">Hmac</button>
          <span id="hmac"></span>
        </div>
<div>
<button onclick="validate()">Validate MAC</button>
  <span id="validated"></span>
</div>

CSS

.selectable{
    -webkit-touch-callout: all; /* iOS Safari */
    -webkit-user-select: all; /* Safari */
    -khtml-user-select: all; /* Konqueror HTML */
    -moz-user-select: all; /* Firefox */
    -ms-user-select: all; /* Internet Explorer/Edge */
    user-select: all; /* Chrome and Opera */

}

JavaScript

let iv = null;
let useIV = true;
let Hmac = null;
function encrypt(clearTextData, hashedPwd, useIV){
    if (useIV){
      let randomBytes   = CryptoJS.lib.WordArray.random(128/8).toString();
      iv = CryptoJS.enc.Hex.parse(randomBytes);
      console.log(`iv : ${iv}`);
      // old method (wrong) which used first 16 bytes of key (hashed pwd)
      // CryptoJS.enc.Hex.parse(key);
    message = CryptoJS.AES.encrypt(clearTextData, CryptoJS.enc.Hex.parse(hashedPwd),{iv: iv});
    console.log(`message.iv : ${message.iv}`);
    console.log(`message: ${message}`);
    console.log(`message.ciphertext ${message.ciphertext}`);
    console.log(`message.salt ${message.salt}`);
    }
  else{
    message = CryptoJS.AES.encrypt(clearTextData, hashedPwd );
  }
  
    return message.toString();
}

function decrypt(encryptedData, hashedPwd, useIV){
  let code;  
  if (useIV){
    console.log(`hashedPwd: ${hashedPwd}`);
    // we use original created iv
    // we now use the original _random_ iv which
    // is the correct way.  IV will be passed
    // in the clear to decrypting side
    // let iv = CryptoJS.enc.Hex.parse(key);
    console.log(`iv ${iv}`);
    code = CryptoJS.AES.decrypt(encryptedData, CryptoJS.enc.Hex.parse(hashedPwd),{iv:iv});
    console.log(`code ${code}`);
    //alert (typeof(code));
    console.log(code);
    }
  else{
    console.log("decrypting with no IV");
    code = CryptoJS.AES.decrypt(encryptedData, hashedPwd);
    console.log(code);
    
  }
  let decryptedMessage = "";
  if (code.sigBytes < 0){
    decryptedMessage = `Couldn't decrypt! It is probable that an incorrect password was used.`;
    return decryptedMessage;
  }
  decryptedMessage = code.toString(CryptoJS.enc.Utf8);
  return decryptedMessage;
}

function encryptFromText(){
  useIV = document.querySelector("#useIVCheckBox").checked;
  let clearText = document.querySelector("#clear_text").value;
  let cleartext_pwd = document.querySelector("#password").value
  let hashedPwd =...