refactor(js): extract TOTP module + add RFC 6238 tests (§3.1)

Fourth slice of the app.js split. Moves TOTP (base32Decode, generateTOTP,
parseOtpAuthUri) plus the TOTP-secret and custom-field AES-GCM wrappers to
js/app.totp.js. Loads before app.js (pure declarations), after app.crypto.js
(uses encryptPwd/decryptPwd). Also called by app.import.js and app.sync.js
via shared global scope.

- Byte-for-byte identical extraction; no duplicate const; syntax OK on all
  five app parts.
- NEW: js/tests/totp.test.js — 13 tests including the 5 RFC 6238 Appendix B
  reference vectors (generateTOTP reads Date.now(), so each case stubs the
  sandbox clock to the vector's fixed time), base32 decode edge cases, and
  parseOtpAuthUri. Extraction AND new coverage in one slice.
- Suite: 42 → 55 tests, all green.
- Assets regenerated (manifest now embeds all 6 ordered JS files:
  argon2 → crypto → totp → import → app → sync); also fixes the previous
  import commit's not-yet-rebuilt manifest.
- Delphi build artifacts (*.vrc, *.$manifest) gitignored.

app.js: 11936 → 10138 lines (4 modules extracted, ~1800 lines).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
r-zakarya
2026-07-05 16:35:29 +01:00
parent 97a19836a0
commit 5fc07aed7a
12 changed files with 253 additions and 124 deletions
+6 -2
View File
@@ -233,9 +233,13 @@ réécriture des call-sites, risque quasi nul vs conversion en modules ES).
`doImport`/`doExport`) — byte-for-byte identique, couvert par les 14 tests
CSV, chargé AVANT app.js (pures déclarations). Pattern + règles d'ordre
documentés dans CLAUDE.md « Découpage frontend ».
- `app.js` : 11 936 → **10 253 lignes** (crypto + sync + import sortis).
- `js/app.totp.js` extrait (TOTP RFC 6238 + crypto TOTP/custom-fields) —
byte-for-byte identique, chargé AVANT app.js. **+13 tests TOTP (vecteurs
RFC 6238)** ajoutés en même temps → extraction *et* nouvelle couverture.
- `app.js` : 11 936 → **10 138 lignes** (crypto + totp + sync + import sortis).
- Suite de tests : 42 → **55 tests**.
- Reste à extraire (grosses sections cohésives) : slideover, settings,
quicksearch, autofill, auto-backup…
quicksearch, autofill, auto-backup, favicons
-`node --check` en pré-étape de `BuildAssets.ps1` : **déjà fait** (cf. §3.2).
### 3.2 🟡 Aucun test automatisé — **partiellement adressé (2026-07-04)**