Class: SecretBox
Defined in: auth/src/secret-box.ts:117
Seals and opens secrets against a key ring. See the module comment for the envelope and the threat model.
Constructors
Constructor
> new SecretBox(options): SecretBox
Defined in: auth/src/secret-box.ts:123
Parameters
options
Returns
SecretBox
Accessors
activeKeyId
Get Signature
> get activeKeyId(): string
Defined in: auth/src/secret-box.ts:144
The key id new ciphertexts are sealed with.
Returns
string
Methods
isCurrent()
> isCurrent(value): boolean
Defined in: auth/src/secret-box.ts:172
Whether value is already sealed with the active key (nothing to migrate).
Parameters
value
string
Returns
boolean
open()
> open(value, context): string
Defined in: auth/src/secret-box.ts:163
Decrypts a value sealed for context. Throws SecretUnreadableError for anything else — including plaintext and v1: values unless the matching legacy opt-in is set.
Parameters
value
string
context
Returns
string
reseal()
> reseal(value, context): string | null
Defined in: auth/src/secret-box.ts:183
Re-seals value under the active key — for rotation, and for migrating v1: / plaintext values (which requires the legacy opt-in to read them). Returns null when the value is already current, so a caller can skip the write.
Parameters
value
string
context
Returns
string | null
seal()
> seal(plaintext, context): string
Defined in: auth/src/secret-box.ts:149
Encrypts plaintext under the active key, bound to context.
Parameters
plaintext
string
context
Returns
string