Clamp to maximum password length
[skeletonkey.git] / core.js
1 /* Copyright (c) 2012 Robert Sesek <http://robert.sesek.com>
2 *
3 * Permission is hereby granted, free of charge, to any person obtaining a copy
4 * of this software and associated documentation files (the "Software"), to
5 * deal in the Software without restriction, including without limitation the
6 * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
7 * sell copies of the Software, and to permit persons to whom the Software is
8 * furnished to do so, subject to the following conditions:
9 *
10 * The above copyright notice and this permission notice shall be included in
11 * all copies or substantial portions of the Software.
12 *
13 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
14 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
15 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
16 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
17 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
18 * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
19 * DEALINGS IN THE SOFTWARE.
20 */
21
22 (function main() {
23 if (typeof chrome !== 'undefined') {
24 // TODO: load the extension JS
25 } else {
26 // TODO: load the hosted JS
27 }
28
29 document.addEventListener('DOMContentLoaded', function() {
30 var controller = new SkeletonKey(document);
31 });
32 })();
33
34 /**
35 * SkeletonKey is view controller for generating secure passwords.
36 *
37 * @param {HTMLDocument} doc The document on which to operate.
38 */
39 var SkeletonKey = SkeletonKey || function(doc) {
40 this._master = doc.getElementById('master');
41 this._sitekey = doc.getElementById('sitekey');
42 this._username = doc.getElementById('username');
43 this._password = doc.getElementById('password');
44 this._generateButton = doc.getElementById('generate');
45
46 this._options = new SkeletonKeyOptions();
47
48 this._init();
49 };
50
51 /**
52 * The number of iterations to perform in PBKDF2.
53 * @const {int}
54 */
55 SkeletonKey.prototype.ITERATIONS = 1000;
56 /**
57 * The size of the key, in bytes.
58 * @const {int}
59 */
60 SkeletonKey.prototype.KEYSIZE = 256/32;
61
62 /**
63 * Initializes event handlers for the page.
64 * @private
65 */
66 SkeletonKey.prototype._init = function() {
67 this._generateButton.onclick = this._onGenerate.bind(this);
68
69 this._master.onkeyup = this._nextFieldInterceptor.bind(this);
70 this._sitekey.onkeyup = this._nextFieldInterceptor.bind(this);
71 this._username.onkeyup = this._nextFieldInterceptor.bind(this);
72
73 this._password.onclick = this._selectPassword.bind(this);
74 this._password.labels[0].onclick = this._selectPassword.bind(this);
75
76 this._initChromeExtension();
77
78 this._master.focus();
79 };
80
81 /**
82 * Event handler for generating a new password.
83 * @param {Event} e
84 * @private
85 */
86 SkeletonKey.prototype._onGenerate = function(e) {
87 var salt = this._username.value + '@' + this._sitekey.value;
88
89 // |key| is a WordArray of 32-bit words.
90 var key = CryptoJS.PBKDF2(this._master.value, salt,
91 {keySize: this.KEYSIZE, iterations: this.ITERATIONS});
92
93 var hexString = key.toString();
94 hexString = this._capitalizeKey(hexString);
95
96 var maxLength = this._options.getMaximumPasswordLength();
97 if (hexString.length > maxLength)
98 hexString = hexString.substr(0, maxLength);
99
100 this._password.value = hexString;
101 this._selectPassword();
102 };
103
104 /**
105 * Takes a HEX string and returns a mixed-case string.
106 * @param {string} key
107 * @return string
108 * @private
109 */
110 SkeletonKey.prototype._capitalizeKey = function(key) {
111 // |key| is too long for a decent password, so try and use the second half of
112 // it as the basis for capitalizing the key.
113 var capsSource = null;
114 var keyLength = key.length;
115 if (keyLength / 2 <= this._options.getMinimumPasswordLength()) {
116 capsSouce = key.substr(0, keyLength - this._options.getMinimumPasswordLength());
117 } else {
118 capsSource = key.substr(keyLength / 2);
119 }
120
121 if (!capsSource || capsSource.length < 1) {
122 return key;
123 }
124
125 key = key.substr(0, capsSource.length);
126 var capsSourceLength = capsSource.length;
127
128 var j = 0;
129 var newKey = "";
130 for (var i = 0; i < key.length; i++) {
131 var c = key.charCodeAt(i);
132 // If this is not a lowercase letter or there's no more source, skip.
133 if (c < 0x61 || c > 0x7A || j >= capsSourceLength) {
134 newKey += key[i];
135 continue;
136 }
137
138 var makeCap = capsSource.charCodeAt(j++) % 2;
139 if (makeCap)
140 newKey += String.fromCharCode(c - 0x20);
141 else
142 newKey += key[i];
143 }
144
145 return newKey;
146 };
147
148 /**
149 * Checks if the given key event is from the enter key and moves onto the next
150 * field or generates the password.
151 * @param {Event} e
152 * @private
153 */
154 SkeletonKey.prototype._nextFieldInterceptor = function(e) {
155 if (e.keyCode != 0xD)
156 return;
157
158 if (this._master.value == "") {
159 this._master.focus();
160 } else if (this._sitekey.value == "") {
161 this._sitekey.focus();
162 } else if (this._username.value == "") {
163 this._username.focus();
164 } else {
165 this._generateButton.click();
166 }
167 };
168
169 /**
170 * Selects the contents of the generated password.
171 * @private
172 */
173 SkeletonKey.prototype._selectPassword = function() {
174 this._password.focus();
175 this._password.select();
176 };
177
178 /**
179 * Initalizes the Chrome extension pieces if running inside chrome.
180 * @private
181 */
182 SkeletonKey.prototype._initChromeExtension = function() {
183 return;
184 if (typeof chrome == 'undefined' || typeof chrome.extension == 'undefined')
185 return;
186
187 // getCurrent is undefined for backround pages. Need content script.
188 chrome.tabs.getCurrent(function (tab) {
189 if (tab == null)
190 return;
191
192 var url = tab.url;
193 if (url == null || url == "")
194 return;
195
196 var siteKey = url.search(/https?:\/\/(www.?|login|accounts?)\.(.*)\.(com?|net|org|edu|biz|info)?.*/);
197 console.log(siteKey);
198 });
199 };