Build on the supported package contract
Use @absolutejs/secure-messaging-federation-webcrypto through its supported public entry points.
@absolutejs/secure-messaging-federation-webcryptov0.0.1betaMessagingWeb Crypto domain signatures and confidential abuse evidence for AbsoluteJS federation.
bun add @absolutejs/secure-messaging-federation-webcryptoStandard Web Crypto providers for AbsoluteJS federation:
ECDSA P-256/SHA-256 domain signatures; and
RSA-OAEP/SHA-256 key wrapping plus AES-256-GCM confidential abuse evidence.
The application owns key generation, private-key custody, domain discovery, rotation, revocation, and the public-key directory. Prefer non-exportable private keys or an HSM/KMS-backed adapter in production.
Evidence is encrypted at the endpoint directly to the chosen moderation public key. The report ID, alleged sender, selected message IDs, authorization, recipient key ID, and format version are authenticated as AES-GCM AAD. This provider emits receiver-asserted; it does not implement or claim cryptographic message franking.
Outcomes
Use @absolutejs/secure-messaging-federation-webcrypto through its supported public entry points.
Hardening checklist
Follow in order
Supported entry points declared by this package manifest.
Package entry point declared in package.json.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.
type WebCryptoFederationSignatureOptions = {
readonly keyId: string;
readonly localDomain: string;
readonly privateKey: CryptoKey;
readonly resolvePublicKey: (input: {
readonly algorithm: typeof SIGNATURE_ALGORITHM;
readonly domain: string;
readonly keyId: string;
}) => Promise<CryptoKey | undefined>;
};@absolutejs/secure-messaging-federation-webcrypto