npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@kummahiih/circle-enroll

v0.1.3

Published

Browser enroll assets (PBKDF2 + WebAuthn PRF) for page-scoped password hashes used by private-circle and hello-circle

Readme

@kummahiih/circle-enroll

Browser enroll assets for page-scoped PBKDF2 / WebAuthn-PRF password hashes.

Used by @kummahiih/private-circle and hello-circle.

Assets

| File | Role | |------|------| | assets/enroll.html | Enrollment UI (password or passkey) | | assets/enroll.css | Styles (same-origin file; no inline CSS) | | assets/enroll-core.js | PBKDF2 path + shared helpers | | assets/enroll-prf.js | WebAuthn PRF path | | assets/enroll-json.md | JSON schema v1 + same-origin PRF notes |

JSON schema v1 matches private-circle enrollment format.

Lock pageId (gated sites)

Public copy (npx circle-enroll copy / circle-enroll.vercel.app) stays editable: the pageId field is shown and can be prefilled with ?page=.

When private-circle encrypt copies enroll into dist/, it stamps the root element:

<html lang="fi" data-page-id="my-site" data-lock-page-id="1">

Then applyPageIdLock hides the pageId input and the #pageId-fixed chip. The hidden #pageId input stays filled so the PRF script does not change. Encrypt default is lock-on; --no-lock-page-id leaves the field editable.

Install

npm install @kummahiih/circle-enroll

CLI

npx circle-enroll copy --out <dir>

Writes enroll.html, enroll.css, enroll-core.js, and enroll-prf.js into the target directory.

WebAuthn PRF support

See docs/WEBAUTHN_PRF_SUPPORT.md and the full matrix in private-circle.

Rough minimums: Chrome/Edge 116+, Safari 18+ (platform only), Firefox 135+. Enroll and gate must share origin for PRF.

Operator runbook (production)

  1. Same-origin enroll for PRF — Host enroll.html on the same origin as the gated page. WebAuthn credentials are RP-ID bound; a public enroll host on a different domain works for PBKDF2 only.
  2. Prefer WebAuthn-PRF for high-value circles (smaller offline attack surface). Keep a password backup enrollment if recovery after passkey loss is required.
  3. Hashes hygiene — Never commit real user hashes to public git; never publish enroll JSON with dist/. Demo sites may ship labeled public demo hashes only.
  4. Rotate on leak — If hashes may have leaked together with published masks, rotate the build key K and re-enroll everyone.

Full detail: docs/THREAT_MODEL.md and @kummahiih/private-circle security notes.

Content Security Policy (strict)

Same-origin static assets only — not third-party CDNs, not inline code, not nonces.

| Directive | Value | Assets | |-----------|--------|--------| | script-src | 'self' | enroll-core.js, enroll-prf.js | | style-src | 'self' | enroll.css | | connect-src | 'none' | No network on enroll | | 'unsafe-inline' / 'unsafe-eval' | not used | — | | Nonces / 'strict-dynamic' | not used | Need dynamic HTML; break offline static hosting |

Default meta CSP on enroll.html:

default-src 'none'; base-uri 'none'; form-action 'none';
script-src 'self'; style-src 'self'; connect-src 'none';
img-src 'none'; font-src 'none'; object-src 'none'; frame-ancestors 'none'

Prefer the HTTP CSP header (e.g. Vercel headers) as the source of truth; keep the meta tag aligned or omit it.

Consumption

private-circle

@kummahiih/private-circle resolves enroll assets from this package when encrypting or running init. Gate assets (gate.js / gate.css) stay in private-circle. Encrypt stamps data-page-id from --page-id unless --no-lock-page-id.

hello-circle / your site

npx circle-enroll copy --out dist

Serve enroll on the same origin as the gated page for WebAuthn-PRF unlock.

License

Apache-2.0