basalt / drives/src / DriveSecretBox
Class: DriveSecretBox
Defined in: drives/src/secret-box.ts:86
Seals and opens credential blobs against a key ring.
The first key in the ring is the active one: everything new is sealed with it. Every other key stays readable, which is what makes rotation a rolling change rather than a migration — add the new key at the front, let reseal move rows over as they are touched, and drop the old key once no row references it.
Constructors
Constructor
> new DriveSecretBox(ring): DriveSecretBox
Defined in: drives/src/secret-box.ts:90
Parameters
ring
readonly DriveEncryptionKey[]
Returns
DriveSecretBox
Accessors
activeKeyId
Get Signature
> get activeKeyId(): string
Defined in: drives/src/secret-box.ts:114
The key id new ciphertexts are sealed with.
Returns
string
Methods
keyIdOf()
> keyIdOf(envelope): string | null
Defined in: drives/src/secret-box.ts:168
Which key id sealed this envelope, without decrypting it.
Parameters
envelope
string
Returns
string | null
open()
> open(envelope, context): string
Defined in: drives/src/secret-box.ts:135
Decrypts an envelope. Throws DriveSecretMalformedError for anything that is not a well-formed envelope or whose tag does not verify — including a blob bound to a different tenant, connection or provider. There is no path that returns the input unchanged.
Parameters
envelope
string
context
Returns
string
reseal()
> reseal(envelope, context): string | null
Defined in: drives/src/secret-box.ts:178
Re-seals an envelope under the active key when it is not already, for rolling rotation. Returns null when nothing needed to change, so a caller can skip the write.
Parameters
envelope
string
context
Returns
string | null
seal()
> seal(plaintext, context): string
Defined in: drives/src/secret-box.ts:119
Encrypts plaintext, binding it to context.
Parameters
plaintext
string
context
Returns
string