Documentation
¶
Overview ¶
Package cryptox protects personal data at rest: field encryption, blind indexes to search encrypted values, and random tokens stored as hashes. It is pure — keys come from the project, nothing touches the database or the network.
Every purpose takes its own key, so a leaked index key reveals no ciphertext and the other way round. Keys are 32 random bytes in base64: openssl rand -base64 32.
Index ¶
Constants ¶
const KeySize = 32
KeySize is the size of every key.
Variables ¶
var ErrOpen = errors.New("cryptox: cannot open the sealed value")
ErrOpen means the value is damaged or was sealed with another key.
Functions ¶
Types ¶
type MAC ¶
type MAC struct {
// contains filtered or unexported fields
}
MAC is HMAC-SHA256 under a server key. As a blind index it finds a record by a value stored only encrypted; as a hash of a short secret, such as a six digit code, it cannot be brute forced without the key, unlike a plain hash.