# Vendored third-party assets The SPA is served under a CSP that forbids every external host, so anything it uses has to live here. Each entry records exactly what was taken and from where, so it can be checked or rebuilt without guesswork. ## argon2.min.js | | | |---|---| | Package | `argon2-browser` 1.18.0 (npm) | | Source | https://registry.npmjs.org/argon2-browser/-/argon2-browser-1.18.0.tgz | | Tarball sha256 | `cdb11795a4971bde095fe6b836aa424de50c4558ed4b9505bc74111eee7f6d35` | | Tarball sha1 (npm dist.shasum) | `f35820211e0a431aed7f82b9348477234be69bec` | | File taken | `package/dist/argon2-bundled.min.js` | | File sha256 | `77c64b946baf1a5116dc591f4b9965d636b1b455f75edd2d4a587cb75e01687b` | The bundled build carries the WebAssembly inline as base64, so there is no second request and nothing to locate at runtime. **Why it is here at all:** WebCrypto has no memory-hard KDF. The encrypted keypair bundle is protected by the passphrase alone and rests on every node whose group its owner joins (finding C4), so PBKDF2 — compute-only, and therefore cheap on a GPU — was the wrong tool for it. Measured through this build on the dev machine: Argon2id 128 MB / t=3 / p=1 takes ~640 ms, against ~240 ms for PBKDF2-SHA512 at 600k, for a memory cost a GPU cannot ignore. ### argon2.wasm The same build's standalone WebAssembly, sha256 `0c2149886c13e4eae4a6ca25ee71d47423c5c8740a874cf04ff816d1b2c901d7`. The browser never requests it — `argon2.min.js` carries the same bytes inline as a data URL. It is kept because the cross-language parity test drives the vendored library under node, where the emscripten loader takes its file path instead of the inline copy, and a test that cannot run is a test that stops being true. ## htm-preact.js | | | |---|---| | Package | `htm` 3.1.1 (npm) — Apache-2.0 | | Source | https://registry.npmjs.org/htm/-/htm-3.1.1.tgz | | Tarball sha256 | `2425b9bee11409177bcabc7f32e319926fc6690c1701c0b257c88bdff2d5ba90` | | Tarball sha1 (npm dist.shasum) | `49266582be0dc66ed2235d5ea892307cc0c24b78` | | File taken | `package/preact/standalone.module.js` | | File sha256 | `72284e8e9079c87817145df1110f74e8a2aa040b2fc384922e18dfcb46fc1fd7` | htm's "standalone" build: htm and Preact 10 (MIT) with its hooks, in one ES module, so the SPA has a component model without a bundler or a second request. The same bytes ship in htm 3.1.0; this entry was identified after the fact, by matching the committed file against both releases. ## Licences `LICENSES.txt`, beside these files, carries the licence text of each of them; the MIT and Apache licences both ask for it to travel with every copy. A file added here adds its licence there.