feat(auth): bring opaque (RFC 9807) auth

OPAQUE (RFC 9807) implementation (using `opaque-ke` crate)

    with opaque authentfication, server will never receive the password (in the auth=password mode)
    this is a must have to create trust with users to permit end to end encryption in the future
    (we cannot know if user use the same password/passphrase for his asymetric key or his oxicloud auth,
    this is why server must never have the password)

    pass1: prepare server
This commit is contained in:
Edouard Vanbelle
2026-07-26 15:04:31 +02:00
parent d76803f602
commit 0e395ae15f
19 changed files with 1570 additions and 7 deletions
+3
View File
@@ -45,5 +45,8 @@
"vite": "^6.4.3",
"vite-plugin-istanbul": "^8.0.0",
"vitest": "^4.1.9"
},
"dependencies": {
"@serenity-kit/opaque": "^1.1.0"
}
}