wasm-v26.1.22
·
193 commits
to master
since this release
Add nonce incrementor for per-field encryption Implement 96-bit nonce derivation to prevent nonce reuse in AES-CTR mode. Each field gets a unique nonce via: nonceStart + (recordIndex * 65536 + fieldId) Breaking changes: - EncryptionHeader.iv replaced with nonceStart (12 bytes) - Header version bumped to 2 - EncryptionContext now requires nonceStart parameter New APIs: - generateNonceStart() - CSPRNG 12-byte nonce generation - deriveNonce(nonceStart, recordIndex) - 96-bit big-endian addition - EncryptionContext: getNonceStart(), getRecordIndex(), setRecordIndex(), nextRecordIndex(), deriveFieldNonce() Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>