npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@lazy-random/cross-crypto

v2.0.1

Published

在 Node.js 與瀏覽器環境之間以單一 API 取得加密安全亂數 (Cryptographically Secure Random) 的跨環境 (Cross-environment) 工具

Downloads

280

Readme

@lazy-random/cross-crypto

在 Node.js 與瀏覽器環境之間,以單一 API 取得加密安全的亂數 (Cryptographically Secure Random Number) 的跨環境 (Cross-environment) 工具套件。

套件會惰性 (Lazy) 解析目前環境可用的 crypto 實作並快取 (Cache) 起來,讓上層程式不需要自行判斷執行環境。

特色 (Features)

  • 單一 API 同時適用於 Node.js 的 require('crypto') 與瀏覽器的 global.crypto
  • 以閉包 (Closure) 快取解析結果,只初始化一次,避免重複載入
  • 瀏覽器環境若只有 getRandomValues,會自動補上 (Polyfill) randomBytes
  • 同時支援同步回傳與 callback 兩種呼叫方式
  • 額外導出 ICryptoLike 介面 (Interface),方便自行注入 (Inject) 相容實作

安裝 (Installation)

yarn add @lazy-random/cross-crypto
yarn-tool add @lazy-random/cross-crypto
yt add @lazy-random/cross-crypto

使用方式 (Usage)

import crossCrypto, { randomBytes } from '@lazy-random/cross-crypto'

// 取得目前環境可用的 crypto 實例(會被快取,重複呼叫不會重新初始化)
const crypto = crossCrypto()

// 同步取得 16 個位元組 (Bytes)
const buf = randomBytes(16)

// 也可以使用 callback 風格
crypto.randomBytes(8, (err, buf) =>
{
	if (err)
	{
		throw err
	}

	console.log(buf)
})

CommonJS 的用法:

const { crossCrypto, randomBytes } = require('@lazy-random/cross-crypto')

const bytes = randomBytes(32)

API 文件

crossCrypto()

回傳目前環境可用的 ICryptoLike 實例;解析結果會在閉包內快取,後續呼叫直接回傳同一份實例。

  • 回傳值 (Returns):ICryptoLike
  • 例外 (Throws):Error — 環境完全不支援 crypto 時拋出 not support crypto

randomBytes(size[, callback])

取得加密安全的隨機位元組 (Random Bytes),內部等同於 crossCrypto().randomBytes(size, callback)。

| 參數 (Parameter) | 型別 (Type) | 說明 | | --- | --- | --- | | size | number | 要產生的位元組數 | | callback | (err: Error \| null, buf: Buffer) => void | 選擇性的完成回呼 (Callback) |

  • 回傳值 (Returns):Buffer

在瀏覽器環境透過 getRandomValues 補齊時,單次 size 上限為 65536,超過會拋出 requested too many random bytes。

ICryptoLike

描述 crypto 的最小共同介面 (Minimal Common Interface):

  • randomBytes(size, callback?):必填 (Required)
  • getRandomValues?(array):選填 (Optional),瀏覽器環境提供

開發 (Development)

pnpm run build
pnpm run lint
pnpm run test:jest

變更日誌 (Changelog)

請見 CHANGELOG.md。

常見問題 (FAQ)

在瀏覽器中為什麼會得到 Buffer?

瀏覽器路徑的 randomBytes polyfill 會以 Buffer.from 包裝產生的位元組,以保持與 Node.js 相同的回傳型別,讓上層程式不需要分支處理。

可以自行注入其他 crypto 實作嗎?

可以,只要物件符合 ICryptoLike 介面即可;不過本套件的 crossCrypto() 目前只解析 require('crypto') 與全域 (Global) 的 crypto/msCrypto。

相關資源 (Resources)