// Vestibule admin wizard — production implementation. // // Two-phase UI: // Phase A (auth gate): // - No admin password set → setup view (first run) // - Admin password set → enter view (returning) // Phase B (wizard): // - Six steps, navigated with prev/next // - Final step shows JSON review and save button // // Credential split (two passwords, two surfaces): // Admin password — gates this wizard. PBKDF2-SHA-256, 100k // iterations, 16-byte salt, in-browser via Web Crypto. // Kiosk unlock password — releases the session. Argon2id in // usher, file storage at 0600 (see helper/src/crypto.rs). const PBKDF2_ITERATIONS = 100_000; const PBKDF2_HASH = "SHA-256"; const PBKDF2_KEYLEN_BITS = 256; const SALT_BYTES = 16; const MIN_PASSWORD_LENGTH = 8; const TOTAL_STEPS = 6; // URL policy engine — shared with the background script. Loaded via //