secrets

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package secrets seals values kept in the database, the webhook signing secrets, with a key stored next to the CA: a copy of the database alone is not enough to forge signatures.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Sealed

func Sealed(s string) bool

Sealed reports whether s was produced by Seal.

Types

type Box

type Box struct {
	// contains filtered or unexported fields
}

Box seals and opens values with AES-256-GCM.

func Load

func Load(dir string) (*Box, error)

Load reads the key in dir, creating it (mode 0600) on first use.

func (*Box) Open

func (b *Box) Open(stored string) (string, error)

Open returns the plain value. A value not sealed (written before sealing existed) is returned as is; a nil Box opens nothing.

func (*Box) Seal

func (b *Box) Seal(plain string) (string, error)

Seal returns plain encrypted, as text for a database column.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL