Skip to content

basalt / drives/src / DriveSecretBox

Class: DriveSecretBox ​

Defined in: drives/src/secret-box.ts:86

Seals and opens credential blobs against a key ring.

The first key in the ring is the active one: everything new is sealed with it. Every other key stays readable, which is what makes rotation a rolling change rather than a migration — add the new key at the front, let reseal move rows over as they are touched, and drop the old key once no row references it.

Constructors ​

Constructor ​

> new DriveSecretBox(ring): DriveSecretBox

Defined in: drives/src/secret-box.ts:90

Parameters ​

ring ​

readonly DriveEncryptionKey[]

Returns ​

DriveSecretBox

Accessors ​

activeKeyId ​

Get Signature ​

> get activeKeyId(): string

Defined in: drives/src/secret-box.ts:114

The key id new ciphertexts are sealed with.

Returns ​

string

Methods ​

keyIdOf() ​

> keyIdOf(envelope): string | null

Defined in: drives/src/secret-box.ts:168

Which key id sealed this envelope, without decrypting it.

Parameters ​

envelope ​

string

Returns ​

string | null


open() ​

> open(envelope, context): string

Defined in: drives/src/secret-box.ts:135

Decrypts an envelope. Throws DriveSecretMalformedError for anything that is not a well-formed envelope or whose tag does not verify — including a blob bound to a different tenant, connection or provider. There is no path that returns the input unchanged.

Parameters ​

envelope ​

string

context ​

DriveSecretContext

Returns ​

string


reseal() ​

> reseal(envelope, context): string | null

Defined in: drives/src/secret-box.ts:178

Re-seals an envelope under the active key when it is not already, for rolling rotation. Returns null when nothing needed to change, so a caller can skip the write.

Parameters ​

envelope ​

string

context ​

DriveSecretContext

Returns ​

string | null


seal() ​

> seal(plaintext, context): string

Defined in: drives/src/secret-box.ts:119

Encrypts plaintext, binding it to context.

Parameters ​

plaintext ​

string

context ​

DriveSecretContext

Returns ​

string

Released under the MIT License.