PBToolboxAI AcheterBuyKaufenAcquistaComprarComprar

← Historique de tous les composants← History of every component← Versionsverlauf aller Komponenten← Cronologia di tutti i componenti← Historial de todos los componentes← Histórico de todos os componentes

L'historique des versions est publié en anglais.Version history is published in English.Der Versionsverlauf wird auf Englisch veröffentlicht.La cronologia delle versioni è pubblicata in inglese.El historial de versiones se publica en inglés.O histórico de versões é publicado em inglês.

Crypto — version history

n_pbt_crypto · Introduced in 3.0

A non-visual object for hashes, HMAC, password-based or key-based encryption, RSA, ECDSA and Ed25519 signatures, JWT, salted password hashes, two-factor TOTP and DPAPI — with nothing to install. Introduced in 3.0.

4.0 — October 2026 #

New #

  • Keys given as bytes: constants KEYFORMAT_TEXT, KEYFORMAT_HEX, KEYFORMAT_BASE64 and an overload of of_hmac, of_jwt_sign and of_jwt_verify that takes them (a secret supplied encoded, AWS SigV4 signing).
  • of_hmac_verify(algo, key, text, expected {, key_format}) compares a received HMAC (a webhook signature, hex or base64) in constant time.
  • of_jwt_header(token) reads a token's header, and an overload of of_jwt_sign adds members to the header (kid).
  • of_totp_verify(secret, code, ref al_step) returns the accepted time step, so that a code already used can be refused.
  • il_password_hash_rounds: the rounds of of_password_hash, 600,000 by default (the current OWASP figure); values already stored carry their own rounds and still verify.
  • An optional entropy for of_protect and of_unprotect (DPAPI), and the documentation says who can read a protected value back.
  • of_hash is computed natively for every algorithm, without opening a hidden page.
  • The documentation describes the of_encrypt container byte by byte (with a Python example to read it) and the RSA-OAEP settings to use with openssl, Java or .NET.

Fixed #

  • of_jwt_sign with JWT_EDDSA writes "alg":"EdDSA", the registered name that other libraries (jose, PyJWT, jjwt) expect; a token signed by 3.0 still verifies.
  • of_generate_keypair with an unknown kind or size ("ec_p256", 1024) returns -5 with empty PEMs and is_last_error naming the accepted KEY_* (it silently produced an RSA 2048 pair).
  • of_hash_file accepts the algorithm names of_hash accepts (SHA-256 = HASH_SHA256, case and dashes ignored); an unknown algorithm is reported as such, distinct from an unreadable file.
  • of_base64_encode_file on a file too large for the process (over 64 MB in 32-bit, 512 MB in 64-bit) says so (-7) instead of "unreadable file"; a missing file is reported as unreadable.
  • is_last_error is emptied by a successful native call (of_crc32, of_hash in MD5, of_hash_file…); it kept the previous error.
  • An empty HMAC key, a non-numeric exp/nbf in a JWT, an of_password_verify of a value claiming more than 10,000,000 rounds, an unreadable instant for TOTP and an unknown character set for of_random_password are refused at once, with the reason in is_last_error.
  • of_base64_decode_to_file("", path) writes an empty file and returns 0 (it returned -5).
  • The CRC32 of a file that fails to read is an error, no longer a wrong value.
  • Engine messages ("Invalid character", "Invalid keyData") are replaced by messages that say what was wrong.
  • The JWT example of the documentation uses a neutral subject ("sub":"jdoe").

Behavior changes #

  • of_jwt_sign and of_jwt_verify: the algorithm is required and compared exactly (pass it as a constant, n_pbt_crypto.JWT_RS256); a PEM key is never accepted as an HMAC secret (of_hmac included); a header with crit is refused. aud and iss remain for the caller to check.
  • of_jwt_sign refuses an exp in the claims together with a duration al_expires_seconds (the duration silently replaced it).
  • of_encrypt and of_decrypt refuse an empty password; of_password_hash("") is still allowed.
  • il_pbkdf2_rounds outside 1,000 to 10,000,000 makes the call fail (empty string for a text, -5 for a file, bounds in is_last_error) instead of silently falling back to 100,000.
  • of_base64_decode, of_base64url_decode, of_hex_decode, of_decrypt… on bytes that are not UTF-8 text (a PDF, an image) return an empty string and is_last_error pointing to of_base64_decode_to_file or of_decrypt_file, instead of replacement characters.
  • of_sign with an EC key returns a DER signature, the form openssl and Java verify; of_verify reads both DER and the former 64-byte form, and a JWT ES256 stays in its standard form.
  • of_totp_code and of_totp_verify refuse a secret with a character outside base32 (spaces and = tolerated) — a 0 typed for an O gave another secret.
  • of_encrypt_file accepts files up to 64 GB, the limit of an AES-GCM container; beyond, -7.
  • Relative paths are read from the current folder, then the folder where the application started, then next to the EXE, and written to the folder where the application started — the same in the IDE and compiled.
  • of_open returns -2 when the hidden page cannot start, with the reason in is_last_error.
  • See the 3 → 4 migration guide, sections 11.3, 11.5 and 11.8.

3.0 — September 2026 #

New #

  • First release, with nothing to install: hashes SHA-1/256/384/512 and MD5 (of_hash, and of_hash_file for a file of any size), HMAC, CRC32, UUIDs and random values, Base64 (text, file, base64url) and hex.
  • Password-based encryption (of_encrypt / of_decrypt: PBKDF2 + AES-256-GCM in a single base64 string, il_pbkdf2_rounds), for text and for files (of_encrypt_file / of_decrypt_file, same container either way).
  • Explicit keys (of_generate_key, of_encrypt_with_key / of_decrypt_with_key), RSA-OAEP (of_rsa_encrypt / of_rsa_decrypt) and key pairs in PEM (of_generate_keypair: KEY_RSA_2048/3072/4096, KEY_EC_P256, KEY_ED25519) with of_sign / of_verify.
  • JWT (of_jwt_sign, of_jwt_verify, of_jwt_claims: HS256, RS256, ES256, EdDSA, with iat/exp and one minute of tolerance).
  • Salted password hashes (of_password_hash / of_password_verify, constant-time comparison of_equals_constant_time) and of_random_password (CHARSET_*).
  • Two-factor TOTP (RFC 6238: of_totp_secret, of_totp_code, of_totp_verify, of_totp_uri for an authenticator app's QR code).
  • DPAPI (of_protect / of_unprotect, per user or per machine): what goes into an INI file.
  • ipo_owner names the host class; is_last_error says why a call failed.