Skip to content

Zeroize transient Web Crypto JWK material on every path #627

Description

@wieslawsoltes

Parent: #102.

Problem

Web Crypto JWK import/export handles secret key material through transient decoded-byte buffers and Base64URL strings. Malformed AES/HMAC JWK input can leave a successfully decoded prefix in ordinary storage before validation fails, and import/export string temporaries are not scrubbed consistently. Large JWK strings can also reach native UTF-8 allocation before algorithm-specific bounds reject them.

Fix

  • Keep partial Base64URL/JWK decoded bytes in zeroizing storage on success and failure.
  • Scrub temporary native import/export strings after use.
  • Enforce AES/HMAC UTF-8 size limits before allocation.
  • Add malformed-prefix regressions and source contracts.
  • Update the pinned provider, licensing/upgrade policy, package documentation, and Code OSS capability ledger.

Acceptance

  • Malformed-prefix AES-GCM and HMAC input is rejected with transient decoded material zeroized.
  • JWK import/export Base64URL temporaries are scrubbed.
  • Oversized input fails before native allocation.
  • Existing provider and algorithm exposure remains unchanged.
  • Provide crypto.subtle through a vetted cross-platform provider #102 stays open for unchanged packaged MCP/connection-secret persistence and reopen acceptance.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions