Encrypted form (P4)
A form whose answers are encrypted in the browser with the receiver's public key.
The receiver
The receiver's page makes an X25519 key pair and keeps the private key in IndexedDB. The form link has the public key after the #, so the key never reaches a server log.
Sending an answer
The form makes a new key pair for each answer, combines its private key with the receiver's public key, and turns the result into an AES-GCM key with HKDF. The envelope holds the form's public key, the salt, the nonce and the ciphertext. The form's private key is thrown away, so after sending not even the sender's browser can open the answer.
The server
In this prototype the server is the browser's local storage. The receiver's page shows every envelope as it is stored, and opens each one with the private key.
Previous: Ask the chart (P3). Next: Passkey sign-in (P5).