Commit 773bdd175d0 for nodejs
commit 773bdd175d0bd10e339dc7099e5bd32056d7408b
Author: Filip Skokan <panva.ip@gmail.com>
Date: Sun Oct 4 21:16:34 2026 +0200
crypto: remove select Web Crypto warnings
Remove ExperimentalWarning from algorithms and methods that are on their
way to an unflagged browser implementation.
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/66312
Reviewed-By: James M Snell <jasnell@gmail.com>
diff --git a/lib/internal/crypto/util.js b/lib/internal/crypto/util.js
index d1f1cdc9b4f..7602e375bc3 100644
--- a/lib/internal/crypto/util.js
+++ b/lib/internal/crypto/util.js
@@ -575,26 +575,19 @@ function getConditionalAlgorithms() {
};
}
-// Experimental algorithms
-const experimentalAlgorithms = [
+// Experimental algorithms that emit warnings.
+const experimentalAlgorithmsWithWarnings = [
'AES-OCB',
'Argon2d',
'Argon2i',
'Argon2id',
- 'ChaCha20-Poly1305',
'cSHAKE128',
'cSHAKE256',
'Ed448',
'KMAC128',
'KMAC256',
- 'ML-DSA-44',
- 'ML-DSA-65',
- 'ML-DSA-87',
'ML-KEM-512',
- 'ML-KEM-768',
- 'ML-KEM-1024',
'MLKEM768-P256',
- 'MLKEM768-X25519',
'MLKEM1024-P384',
'SHA3-256',
'SHA3-384',
@@ -604,6 +597,14 @@ const experimentalAlgorithms = [
'KT128',
'KT256',
'X448',
+ // Ships unflagged in Chromium >= 155
+ // 'ChaCha20-Poly1305'
+ // 'ML-DSA-44'
+ // 'ML-DSA-65'
+ // 'ML-DSA-87'
+ // 'ML-KEM-768'
+ // 'ML-KEM-1024'
+ // 'MLKEM768-X25519'
];
// Transform the algorithm definitions into the operation-keyed structure
@@ -632,8 +633,8 @@ function createSupportedAlgorithms(algorithmDefs) {
nameMap[operation] ||= new SafeMap();
nameMap[operation].set(StringPrototypeToUpperCase(algorithmName), algorithmName);
- // Add experimental warnings for experimental algorithms
- if (ArrayPrototypeIncludes(experimentalAlgorithms, algorithmName)) {
+ // Add warnings for select experimental algorithms
+ if (ArrayPrototypeIncludes(experimentalAlgorithmsWithWarnings, algorithmName)) {
ObjectDefineProperty(result[operation], algorithmName, {
get() {
emitExperimentalWarning(`The ${algorithmName} Web Crypto API algorithm`);
diff --git a/lib/internal/crypto/webcrypto.js b/lib/internal/crypto/webcrypto.js
index 02318f93dc9..7ca945cb4f2 100644
--- a/lib/internal/crypto/webcrypto.js
+++ b/lib/internal/crypto/webcrypto.js
@@ -74,7 +74,6 @@ const {
} = require('internal/crypto/util');
const {
- emitExperimentalWarning,
kEnumerableProperty,
lazyDOMException,
setOwnProperty,
@@ -1473,7 +1472,6 @@ function getPublicKey(key, keyUsages) {
}
function getPublicKeyImpl(key, keyUsages) {
- emitExperimentalWarning('The getPublicKey Web Crypto API method');
const prefix = prepareSubtleMethod(this, 'getPublicKey', arguments.length, 2);
let i = 0;
key = convertSubtleArgument(prefix, 'CryptoKey', key, i++);
@@ -1501,7 +1499,6 @@ function encapsulateBits(encapsulationAlgorithm, encapsulationKey) {
}
function encapsulateBitsImpl(encapsulationAlgorithm, encapsulationKey) {
- emitExperimentalWarning('The encapsulateBits Web Crypto API method');
const prefix = prepareSubtleMethod(
this, 'encapsulateBits', arguments.length, 2);
let i = 0;
@@ -1563,7 +1560,6 @@ function encapsulateKeyImpl(
sharedKeyAlgorithm,
extractable,
keyUsages) {
- emitExperimentalWarning('The encapsulateKey Web Crypto API method');
const prefix = prepareSubtleMethod(
this, 'encapsulateKey', arguments.length, 5);
let i = 0;
@@ -1642,7 +1638,6 @@ function decapsulateBits(decapsulationAlgorithm, decapsulationKey, ciphertext) {
}
function decapsulateBitsImpl(decapsulationAlgorithm, decapsulationKey, ciphertext) {
- emitExperimentalWarning('The decapsulateBits Web Crypto API method');
const prefix = prepareSubtleMethod(
this, 'decapsulateBits', arguments.length, 3);
let i = 0;
@@ -1707,7 +1702,6 @@ function decapsulateKeyImpl(
sharedKeyAlgorithm,
extractable,
keyUsages) {
- emitExperimentalWarning('The decapsulateKey Web Crypto API method');
const prefix = prepareSubtleMethod(
this, 'decapsulateKey', arguments.length, 6);
let i = 0;
@@ -1785,7 +1779,6 @@ class SubtleCrypto {
// Implements https://wicg.github.io/webcrypto-modern-algos/#SubtleCrypto-method-supports
static supports(operation, algorithm, lengthOrAdditionalAlgorithm = null) {
- emitExperimentalWarning('The supports Web Crypto API method');
webidl ??= require('internal/crypto/webidl');
const prefix = "Failed to execute 'supports' on 'SubtleCrypto'";
webidl.requiredArguments(arguments.length, 2, { prefix });
diff --git a/test/parallel/test-webcrypto-prototype-pollution.mjs b/test/parallel/test-webcrypto-prototype-pollution.mjs
index f485cb076f1..d4433ca938f 100644
--- a/test/parallel/test-webcrypto-prototype-pollution.mjs
+++ b/test/parallel/test-webcrypto-prototype-pollution.mjs
@@ -20,8 +20,8 @@ const TypedArrayPrototype = Object.getPrototypeOf(Uint8Array.prototype);
const data = new TextEncoder().encode('prototype pollution');
const modulusLength = getFips() === 1 ? 2048 : 1024;
-// Avoids SubtleCrypto.supports(), which warns and invokes the registry's
-// experimental-algorithm getters.
+// Avoids SubtleCrypto.supports(), which can invoke the registry's
+// experimental-algorithm warning getters.
function supports(operation, name) {
return Object.hasOwn(kSupportedAlgorithms[operation] ?? {}, name);
}