Skip to main content

Crypto

Runtime: any — Web Crypto (globalThis.crypto), in Node.js ≥ 22, modern browsers and edge runtimes

Hashing, HMAC, base64 and random hex on top of Web Crypto, so it runs anywhere. hashString and hmacHash are async because crypto.subtle is, and they support SHA-1/256/384/512 only — Web Crypto has no md5. These are one-way digests and encodings, not encryption and not password storage: hashString with SHA-256 is the wrong tool for passwords (use argon2 or bcrypt). randomHex comes from crypto.getRandomValues — use it for tokens, session ids and reset links (randomHex(32) for 64 hex chars), unlike the Math.random-based helpers in random.

Example​

import { hashString, hmacHash } from '@rtorcato/js-common/crypto'

// Verify an inbound webhook by recomputing the signature over the raw body.
const expected = await hmacHash(rawBody, process.env.WEBHOOK_SECRET)
if (expected !== signatureHeader) throw new Error('bad signature')

await hashString('user-42:prefs') // 64 hex chars — a stable cache key

For an attacker-supplied signature, compare with node:crypto's timingSafeEqual rather than !==, which leaks how many characters matched.

Import​

import { base64Decode, base64Encode, hashString } from '@rtorcato/js-common/crypto'

Exports​

NameSummary
base64DecodeDecodes a base64 string to a UTF-8 string.
base64EncodeEncodes a string (as UTF-8) to base64.
hashStringHashes a string using the specified algorithm.
hmacHashCreates an HMAC hash of a string using a secret and algorithm.
randomHexGenerates a cryptographically secure random hex string of the specified length (in bytes).

See also​

  • security — password strength, script stripping
  • uuid — generate and validate UUIDs
  • random — random ints, floats, strings and array picks