Avoid eager consent component crashes and registration approval failures where crypto.randomUUID is unavailable. Share the companion audio CSPRNG fallback, preserve UUIDv4/session semantics and fail closed without secure randomness. Validation: 24 focused UUID, consent mount, registration recovery and companion audio tests passed. Independent review passed; full UI typecheck/build qualification remains in progress.
14 lines
674 B
TypeScript
14 lines
674 B
TypeScript
/** Secure UUIDs also work on LAN HTTP, where randomUUID is unavailable. */
|
|
export function secureUuid(): string {
|
|
const source = globalThis.crypto
|
|
if (typeof source?.randomUUID === 'function') return source.randomUUID()
|
|
if (typeof source?.getRandomValues !== 'function') {
|
|
throw new Error('Secure randomness is unavailable.')
|
|
}
|
|
const bytes = source.getRandomValues(new Uint8Array(16))
|
|
bytes[6] = (bytes[6]! & 0x0f) | 0x40
|
|
bytes[8] = (bytes[8]! & 0x3f) | 0x80
|
|
const hex = Array.from(bytes, byte => byte.toString(16).padStart(2, '0')).join('')
|
|
return `${hex.slice(0, 8)}-${hex.slice(8, 12)}-${hex.slice(12, 16)}-${hex.slice(16, 20)}-${hex.slice(20)}`
|
|
}
|