Exemple
pkce-challenge 5.0.1: verifyChallenge
Échantillon vérifié pour npm pkce-challenge 5.0.1: verifyChallenge. Le contrat s'est exécuté sur node 22 · linux debian/x64 · docker et a réussi.
sha256:81f2f8802509efa6a2758c0f1a80ab4f37732fd060f806e30a6ad2d2b35a47c6
Ce réseau offre une seule chose : un échantillon qui compile. Il l'a exécuté dans un bac à sable et conservé le reçu signé. Il ne note rien et ne garantit rien : si le même code compile chez vous, il ne l'a pas mesuré.
Combien de clés de signature distinctes ont déposé un reçu de contrat réussi. Une seule, c'est l'auteur ; plus d'une signifie que quelqu'un d'autre l'a compilé aussi. Une clé est auto-générée sans identité enregistrée derrière, donc on compte des clés, pas des personnes.
MIT-0
Preuves d'exécution
L'environnement déclaré et les exécutions signées sont séparés, pour que vous voyiez exactement ce que cet échantillon a exécuté et où.
- Base de preuve
- Contrat signé réussi
- Reçus de vérification
- 1
- Clés de signature qui l’ont compilé
- 1
Environnement déclaré
node 22.23 linux 24 · ubuntu · glibc 2.39 x64 node 22.23 javascript npm
Environnements des exécutions de vérification
| Environnement | Contrat | Étapes | Exécution |
|---|---|---|---|
| node 22 · linux debian/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1node:22@sha256:8a34c4ab3ea2… |
2026-09-17 |
Cas
HOW- Objectif
- verify pkce-challenge.verifyChallenge in pkg:npm/pkce-challenge@5.0.1
- Paquets
- Symboles
-
- pkce-challenge.verifyChallenge
- Environnement
- node 22.23.2
- Créé
- 2026-09-17T00:12:36Z
Contrat
- verifyChallenge returns true when the challenge matches the verifier
- verifyChallenge returns false when the challenge does not match the verifier
- verifyChallenge returns true for the RFC 7636 Appendix B test vector pair
- verifyChallenge returns false when the verifier is altered
- verifyChallenge returns false when the challenge is altered
- verifyChallenge resolves to a boolean promise
Fichiers
- PROMPT.md
- csx.json
- index.js
- package-lock.json
- package.json
- spec.json
- test/contract.mjs
Code source
Clean-room public code sample — generation instructions
Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.
A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.
Goal: verify pkce-challenge.verifyChallenge in pkg:npm/pkce-challenge@5.0.1
Kind: HOW
Use EXACTLY these public packages and versions:
- pkg:npm/pkce-challenge@5.0.1
Demonstrate these symbols/APIs:
- pkce-challenge.verifyChallenge
Rules:
- One focused purpose; the smallest project that proves the goal.
- Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
- Pin every dependency with a lockfile so resolution is reproducible.
- No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
- No personal names, emails, company names, or project identifiers of any kind.
- No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
- Keep it under 200 files and 256KB packed.
{"case":{"caseId":"case:sha256:5c32fac853f14e0b4c8c8017882d9f98fbe6a38ce5cd362c6133319e74678a23","contract":["verifyChallenge returns true when the challenge matches the verifier","verifyChallenge returns false when the challenge does not match the verifier","verifyChallenge returns true for the RFC 7636 Appendix B test vector pair","verifyChallenge returns false when the verifier is altered","verifyChallenge returns false when the challenge is altered","verifyChallenge resolves to a boolean promise"],"goal":"verify pkce-challenge.verifyChallenge in pkg:npm/pkce-challenge@5.0.1","kind":"HOW","packages":["pkg:npm/pkce-challenge@5.0.1"],"schemaVersion":1,"symbols":["pkce-challenge.verifyChallenge"]},"contractCommand":["node","test/contract.mjs"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"npm","executionContext":"node","language":"javascript","libc":"glibc","libcVersion":"2.39","moduleSystem":"esm","os":"linux","osVersionBucket":"24","packageManager":"npm","runtime":"node","runtimeVersion":"22.23.2","schemaVersion":1},"license":"MIT-0","packages":["pkg:npm/pkce-challenge@5.0.1"],"schemaVersion":1,"subject":"pkg:npm/pkce-challenge@5.0.1","symbols":["pkce-challenge.verifyChallenge"],"verifierAdapter":"node-typescript@1"}
import { verifyChallenge } from "pkce-challenge";
/**
* Verifies that a given PKCE code verifier matches the expected code challenge.
*
* @param {string} codeVerifier - The PKCE code verifier string.
* @param {string} expectedChallenge - The expected base64url-encoded SHA-256 challenge.
* @returns {Promise<boolean>} True if the challenge matches the verifier, false otherwise.
*/
export async function isChallengeValid(codeVerifier, expectedChallenge) {
return await verifyChallenge(codeVerifier, expectedChallenge);
}
export { verifyChallenge };
export default verifyChallenge;
{
"name": "sample-pkce-challenge-verify-challenge",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "sample-pkce-challenge-verify-challenge",
"version": "1.0.0",
"dependencies": {
"pkce-challenge": "5.0.1"
}
},
"node_modules/pkce-challenge": {
"version": "5.0.1",
"resolved": "https://registry.npmjs.org/pkce-challenge/-/pkce-challenge-5.0.1.tgz",
"integrity": "sha512-wQ0b/W4Fr01qtpHlqSqspcj3EhBvimsdh0KlHhH8HRZnMsEa0ea2fTULOXOS9ccQr3om+GcGRk4e+isrZWV8qQ==",
"license": "MIT",
"engines": {
"node": ">=16.20.0"
}
}
}
}
{
"name": "sample-pkce-challenge-verify-challenge",
"version": "1.0.0",
"private": true,
"type": "module",
"description": "Clean-room code sample for pkce-challenge.verifyChallenge in pkce-challenge@5.0.1",
"main": "index.js",
"dependencies": {
"pkce-challenge": "5.0.1"
}
}
{
"schemaVersion": 1,
"goal": "verify pkce-challenge.verifyChallenge in pkg:npm/pkce-challenge@5.0.1",
"kind": "HOW",
"packages": [
"pkg:npm/pkce-challenge@5.0.1"
],
"symbols": [
"pkce-challenge.verifyChallenge"
]
}
import assert from "node:assert/strict";
import { createHash } from "node:crypto";
import { verifyChallenge } from "pkce-challenge";
async function run() {
// Reference test vector from RFC 7636 Appendix B
const rfcVerifier = "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk";
const rfcExpectedChallenge = "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM";
// Arbitrary custom verifier and its expected SHA-256 base64url challenge
const customVerifier = "sample_verifier_string_for_pkce_contract_test_12345";
const customChallenge = createHash("sha256")
.update(customVerifier)
.digest("base64url");
// 1. verifyChallenge returns true when the challenge matches the verifier
const customMatches = await verifyChallenge(customVerifier, customChallenge);
assert.equal(customMatches, true);
// 2. verifyChallenge returns false when the challenge does not match the verifier
const customMismatches = await verifyChallenge(customVerifier, "mismatched_challenge_value_1234567890abcdef");
assert.equal(customMismatches, false);
// 3. verifyChallenge returns true for the RFC 7636 Appendix B test vector pair
const rfcMatches = await verifyChallenge(rfcVerifier, rfcExpectedChallenge);
assert.equal(rfcMatches, true);
// 4. verifyChallenge returns false when the verifier is altered
const alteredVerifier = "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXz";
const alteredVerifierResult = await verifyChallenge(alteredVerifier, rfcExpectedChallenge);
assert.equal(alteredVerifierResult, false);
// 5. verifyChallenge returns false when the challenge is altered
const alteredChallenge = "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cz";
const alteredChallengeResult = await verifyChallenge(rfcVerifier, alteredChallenge);
assert.equal(alteredChallengeResult, false);
// 6. verifyChallenge resolves to a boolean promise
const resultPromise = verifyChallenge(customVerifier, customChallenge);
assert.ok(resultPromise instanceof Promise);
const boolResult = await resultPromise;
assert.equal(typeof boolResult, "boolean");
console.log("All pkce-challenge.verifyChallenge contract checks passed.");
}
await run();
Seeder d'origine
anonyme