cryptox

package
v0.5.7 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package cryptox protects personal data at rest: field encryption, blind indexes to search encrypted values, and random tokens stored as hashes. It is pure — keys come from the project, nothing touches the database or the network.

Every purpose takes its own key, so a leaked index key reveals no ciphertext and the other way round. Keys are 32 random bytes in base64: openssl rand -base64 32.

Index

Constants

View Source
const KeySize = 32

KeySize is the size of every key.

Variables

View Source
var ErrOpen = errors.New("cryptox: cannot open the sealed value")

ErrOpen means the value is damaged or was sealed with another key.

Functions

func Equal

func Equal(a, b []byte) bool

Equal compares hashes in constant time.

func HashToken

func HashToken(token string) []byte

HashToken is SHA-256 of a token. A token is long and random, so it needs no salt.

func NewKey

func NewKey() (string, error)

NewKey returns a random key in standard base64, the form ParseKey reads.

func NewToken

func NewToken() (token string, hash []byte, err error)

NewToken returns 32 random bytes in URL base64 to hand out and their hash to store.

func ParseKey

func ParseKey(raw string) ([]byte, error)

ParseKey decodes a key in standard or URL base64, padded or not, and checks its size.

Types

type MAC

type MAC struct {
	// contains filtered or unexported fields
}

MAC is HMAC-SHA256 under a server key. As a blind index it finds a record by a value stored only encrypted; as a hash of a short secret, such as a six digit code, it cannot be brute forced without the key, unlike a plain hash.

func NewMAC

func NewMAC(key []byte) (*MAC, error)

NewMAC checks the key.

func (*MAC) Sum

func (m *MAC) Sum(parts ...[]byte) []byte

Sum returns the MAC of the parts written one after another. The parts are not delimited: when more than one varies in length, make them fixed size first.

type Sealer

type Sealer struct {
	// contains filtered or unexported fields
}

Sealer encrypts values with AES-256-GCM: version, nonce, ciphertext with its tag.

func NewSealer

func NewSealer(key []byte) (*Sealer, error)

NewSealer checks the key.

func (*Sealer) Open

func (s *Sealer) Open(sealed []byte) ([]byte, error)

Open decrypts what Seal produced.

func (*Sealer) Seal

func (s *Sealer) Seal(plain []byte) ([]byte, error)

Seal encrypts plain. Sealing the same value twice gives different results: search by value goes through a blind index.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL