tlsRecord(): Coder<TlsRecord>
Creates a coder for a TLS record layer header and fragment (RFC 8446 section 5.1).
The fragment's length is derived from the header's length field
(fragment.length === length), so length must match the fragment you
provide when encoding — nothing recomputes it for you. The fragment is
treated as opaque bytes: this coder does not parse handshake messages,
validate content types or versions, decompress, or decrypt.
Decode a known ClientHello-shaped record header
Decode a known ClientHello-shaped record header
import { assertEquals } from "@std/assert"; import { tlsRecord, TLS_CONTENT_TYPE, TLS_VERSION } from "@binstruct/tls-record"; // deno-fmt-ignore const wire = new Uint8Array([ 0x16, // type = handshake 0x03, 0x01, // legacyVersion = TLS 1.0 0x00, 0x02, // length = 2 0xde, 0xad, // fragment ]); const [decoded, read] = tlsRecord().decode(wire); assertEquals(read, wire.length); assertEquals(decoded.contentType, TLS_CONTENT_TYPE.handshake); assertEquals(decoded.legacyVersion, TLS_VERSION.TLS1_0); assertEquals(decoded.length, 2); assertEquals(decoded.fragment, new Uint8Array([0xde, 0xad]));
Empty application data record
Empty application data record
import { assertEquals } from "@std/assert"; import { tlsRecord, TLS_CONTENT_TYPE, TLS_RECORD_HEADER_SIZE, TLS_VERSION } from "@binstruct/tls-record"; const coder = tlsRecord(); const buffer = new Uint8Array(TLS_RECORD_HEADER_SIZE); const written = coder.encode({ contentType: TLS_CONTENT_TYPE.applicationData, legacyVersion: TLS_VERSION.TLS1_2, length: 0, fragment: new Uint8Array(0), }, buffer); const [decoded] = coder.decode(buffer); assertEquals(written, TLS_RECORD_HEADER_SIZE); assertEquals(decoded.fragment.length, 0);