AuthEncryptViaAES256
by raddevus
HTML
<script src="https://cdnjs.cloudflare.com/ajax/libs/crypto-js/3.1.2/rollups/aes.js"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/js-sha256/0.9.0/sha256.min.js"></script>
<p><input type="text" id="password" placeholder="password"></p>
<input id="clear_text" type="text" placeholder="clear text">
<button onclick="encryptFromText()">encrypt</button>
<label for="useIVCheckBox">Use IV (Init Vector)</label>
<input id="useIVCheckBox" type="checkbox" checked>
<div id="cipher_output" class="selectable"></div>
<input id="cipher_text" type="text" placeholder="cipher text">
<button onclick="decryptFromText()">decrypt</button>
<div id="cleartext_output"></div>
<div>
<button onclick="generateHmac()">Hmac</button>
<span id="hmac"></span>
</div>
<div>
<button onclick="validate()">Validate MAC</button>
<span id="validated"></span>
</div>
CSS
.selectable{
-webkit-touch-callout: all; /* iOS Safari */
-webkit-user-select: all; /* Safari */
-khtml-user-select: all; /* Konqueror HTML */
-moz-user-select: all; /* Firefox */
-ms-user-select: all; /* Internet Explorer/Edge */
user-select: all; /* Chrome and Opera */
}
JavaScript
let iv = null;
let useIV = true;
let Hmac = null;
function encrypt(clearTextData, hashedPwd, useIV){
if (useIV){
let randomBytes = CryptoJS.lib.WordArray.random(128/8).toString();
iv = CryptoJS.enc.Hex.parse(randomBytes);
console.log(`iv : ${iv}`);
// old method (wrong) which used first 16 bytes of key (hashed pwd)
// CryptoJS.enc.Hex.parse(key);
message = CryptoJS.AES.encrypt(clearTextData, CryptoJS.enc.Hex.parse(hashedPwd),{iv: iv});
console.log(`message.iv : ${message.iv}`);
console.log(`message: ${message}`);
console.log(`message.ciphertext ${message.ciphertext}`);
console.log(`message.salt ${message.salt}`);
}
else{
message = CryptoJS.AES.encrypt(clearTextData, hashedPwd );
}
return message.toString();
}
function decrypt(encryptedData, hashedPwd, useIV){
let code;
if (useIV){
console.log(`hashedPwd: ${hashedPwd}`);
// we use original created iv
// we now use the original _random_ iv which
// is the correct way. IV will be passed
// in the clear to decrypting side
// let iv = CryptoJS.enc.Hex.parse(key);
console.log(`iv ${iv}`);
code = CryptoJS.AES.decrypt(encryptedData, CryptoJS.enc.Hex.parse(hashedPwd),{iv:iv});
console.log(`code ${code}`);
//alert (typeof(code));
console.log(code);
}
else{
console.log("decrypting with no IV");
code = CryptoJS.AES.decrypt(encryptedData, hashedPwd);
console.log(code);
}
let decryptedMessage = "";
if (code.sigBytes < 0){
decryptedMessage = `Couldn't decrypt! It is probable that an incorrect password was used.`;
return decryptedMessage;
}
decryptedMessage = code.toString(CryptoJS.enc.Utf8);
return decryptedMessage;
}
function encryptFromText(){
useIV = document.querySelector("#useIVCheckBox").checked;
let clearText = document.querySelector("#clear_text").value;
let cleartext_pwd = document.querySelector("#password").value
let hashedPwd =...