fix(ui): support secure UUIDs on LAN HTTP
Avoid eager consent component crashes and registration approval failures where crypto.randomUUID is unavailable. Share the companion audio CSPRNG fallback, preserve UUIDv4/session semantics and fail closed without secure randomness. Validation: 24 focused UUID, consent mount, registration recovery and companion audio tests passed. Independent review passed; full UI typecheck/build qualification remains in progress.
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
/** Secure UUIDs also work on LAN HTTP, where randomUUID is unavailable. */
|
||||
export function secureUuid(): string {
|
||||
const source = globalThis.crypto
|
||||
if (typeof source?.randomUUID === 'function') return source.randomUUID()
|
||||
if (typeof source?.getRandomValues !== 'function') {
|
||||
throw new Error('Secure randomness is unavailable.')
|
||||
}
|
||||
const bytes = source.getRandomValues(new Uint8Array(16))
|
||||
bytes[6] = (bytes[6]! & 0x0f) | 0x40
|
||||
bytes[8] = (bytes[8]! & 0x3f) | 0x80
|
||||
const hex = Array.from(bytes, byte => byte.toString(16).padStart(2, '0')).join('')
|
||||
return `${hex.slice(0, 8)}-${hex.slice(8, 12)}-${hex.slice(12, 16)}-${hex.slice(16, 20)}-${hex.slice(20)}`
|
||||
}
|
||||
Reference in New Issue
Block a user