Skip to content

basalt / auth/src / SecretBox

Class: SecretBox ​

Defined in: auth/src/secret-box.ts:117

Seals and opens secrets against a key ring. See the module comment for the envelope and the threat model.

Constructors ​

Constructor ​

> new SecretBox(options): SecretBox

Defined in: auth/src/secret-box.ts:123

Parameters ​

options ​

SecretBoxOptions

Returns ​

SecretBox

Accessors ​

activeKeyId ​

Get Signature ​

> get activeKeyId(): string

Defined in: auth/src/secret-box.ts:144

The key id new ciphertexts are sealed with.

Returns ​

string

Methods ​

isCurrent() ​

> isCurrent(value): boolean

Defined in: auth/src/secret-box.ts:172

Whether value is already sealed with the active key (nothing to migrate).

Parameters ​

value ​

string

Returns ​

boolean


open() ​

> open(value, context): string

Defined in: auth/src/secret-box.ts:163

Decrypts a value sealed for context. Throws SecretUnreadableError for anything else — including plaintext and v1: values unless the matching legacy opt-in is set.

Parameters ​

value ​

string

context ​

SecretContext

Returns ​

string


reseal() ​

> reseal(value, context): string | null

Defined in: auth/src/secret-box.ts:183

Re-seals value under the active key — for rotation, and for migrating v1: / plaintext values (which requires the legacy opt-in to read them). Returns null when the value is already current, so a caller can skip the write.

Parameters ​

value ​

string

context ​

SecretContext

Returns ​

string | null


seal() ​

> seal(plaintext, context): string

Defined in: auth/src/secret-box.ts:149

Encrypts plaintext under the active key, bound to context.

Parameters ​

plaintext ​

string

context ​

SecretContext

Returns ​

string

Released under the MIT License.