{"version":3,"sources":["../src/index.ts"],"sourcesContent":["import { createHmac, randomBytes, timingSafeEqual } from \"node:crypto\";\n\nimport { stringToBytes, validateByteLengthEqual, type CryptoPlugin } from \"@otplib/core\";\n\n/**\n * Node.js crypto module implementation of CryptoPlugin\n *\n * This plugin uses Node.js's built-in crypto module which provides:\n * - OpenSSL-backed HMAC operations\n * - Cryptographically secure random byte generation\n * - Synchronous API for optimal performance\n *\n * @example\n * ```ts\n * import { NodeCryptoPlugin } from '@otplib/plugin-crypto-node';\n *\n * const crypto = new NodeCryptoPlugin();\n * const hmac = await crypto.hmac('sha1', key, data);\n * const random = crypto.randomBytes(20);\n * ```\n */\nexport class NodeCryptoPlugin implements CryptoPlugin {\n  /**\n   * Plugin name for identification\n   */\n  readonly name = \"node\";\n\n  /**\n   * Compute HMAC using Node.js crypto module\n   *\n   * Synchronous implementation using createHmac.\n   *\n   * @param algorithm - Hash algorithm to use\n   * @param key - Secret key\n   * @param data - Data to authenticate\n   * @returns HMAC digest\n   */\n  hmac(algorithm: \"sha1\" | \"sha256\" | \"sha512\", key: Uint8Array, data: Uint8Array): Uint8Array {\n    const hmac = createHmac(algorithm, key);\n    hmac.update(data);\n    return new Uint8Array(hmac.digest());\n  }\n\n  /**\n   * Generate cryptographically secure random bytes\n   *\n   * Uses Node.js's randomBytes which is backed by OpenSSL.\n   *\n   * @param length - Number of bytes to generate\n   * @returns Random bytes\n   */\n  randomBytes(length: number): Uint8Array {\n    return new Uint8Array(randomBytes(length));\n  }\n\n  /**\n   * Constant-time comparison using Node.js crypto.timingSafeEqual\n   *\n   * Uses Node.js's built-in timing-safe comparison which prevents\n   * timing side-channel attacks.\n   *\n   * @param a - First value to compare\n   * @param b - Second value to compare\n   * @returns true if values are equal, false otherwise\n   */\n  constantTimeEqual(a: string | Uint8Array, b: string | Uint8Array): boolean {\n    const bufA = stringToBytes(a);\n    const bufB = stringToBytes(b);\n\n    if (!validateByteLengthEqual(bufA, bufB)) {\n      return false;\n    }\n\n    return timingSafeEqual(bufA, bufB);\n  }\n}\n\n/**\n * Default singleton instance for convenience\n *\n * @example\n * ```ts\n * import { crypto } from '@otplib/plugin-crypto-node';\n *\n * const hmac = crypto.hmac('sha1', key, data);\n * ```\n */\nexport const crypto: CryptoPlugin = Object.freeze(new NodeCryptoPlugin());\n\nexport default NodeCryptoPlugin;\n"],"mappings":"yaAAA,IAAAA,EAAA,GAAAC,EAAAD,EAAA,sBAAAE,EAAA,WAAAC,EAAA,YAAAC,IAAA,eAAAC,EAAAL,GAAA,IAAAM,EAAyD,kBAEzDC,EAA0E,wBAmB7DL,EAAN,KAA+C,CAI3C,KAAO,OAYhB,KAAKM,EAAyCC,EAAiBC,EAA8B,CAC3F,IAAMC,KAAO,cAAWH,EAAWC,CAAG,EACtC,OAAAE,EAAK,OAAOD,CAAI,EACT,IAAI,WAAWC,EAAK,OAAO,CAAC,CACrC,CAUA,YAAYC,EAA4B,CACtC,OAAO,IAAI,cAAW,eAAYA,CAAM,CAAC,CAC3C,CAYA,kBAAkBC,EAAwBC,EAAiC,CACzE,IAAMC,KAAO,iBAAcF,CAAC,EACtBG,KAAO,iBAAcF,CAAC,EAE5B,SAAK,2BAAwBC,EAAMC,CAAI,KAIhC,mBAAgBD,EAAMC,CAAI,EAHxB,EAIX,CACF,EAYab,EAAuB,OAAO,OAAO,IAAID,CAAkB,EAEjEE,EAAQF","names":["index_exports","__export","NodeCryptoPlugin","crypto","index_default","__toCommonJS","import_node_crypto","import_core","algorithm","key","data","hmac","length","a","b","bufA","bufB"]}