Documentation
¶
Index ¶
- Constants
- Variables
- func AesCBCDeB58(s string, key []byte) []byte
- func AesCBCDeB64(s string, key []byte) []byte
- func AesCBCDeHex(s string, key []byte) []byte
- func AesCBCDePKCS7B58(s string, key []byte) []byte
- func AesCBCDePKCS7B64(s string, key []byte) []byte
- func AesCBCDePKCS7Hex(s string, key []byte) []byte
- func AesCBCDePKCS7StringB58(s string, key []byte) string
- func AesCBCDePKCS7StringB64(s string, key []byte) string
- func AesCBCDePKCS7StringHex(s string, key []byte) string
- func AesCBCDeStringB58(s string, key []byte) string
- func AesCBCDeStringB64(s string, key []byte) string
- func AesCBCDeStringHex(s string, key []byte) string
- func AesCBCDecrypt(asPKCS7 bool, ciphertext, key []byte, ivs ...[]byte) (plaintext []byte)
- func AesCBCDecryptE(asPKCS7 bool, ciphertext, key []byte, ivs ...[]byte) ([]byte, error)
- func AesCBCEnB58(b, key []byte) string
- func AesCBCEnB64(b, key []byte) string
- func AesCBCEnHex(b, key []byte) string
- func AesCBCEnPKCS7B58(b, key []byte) string
- func AesCBCEnPKCS7B64(b, key []byte) string
- func AesCBCEnPKCS7Hex(b, key []byte) string
- func AesCBCEnPKCS7StringB58(s string, key []byte) string
- func AesCBCEnPKCS7StringB64(s string, key []byte) string
- func AesCBCEnPKCS7StringHex(s string, key []byte) string
- func AesCBCEnStringB58(s string, key []byte) string
- func AesCBCEnStringB64(s string, key []byte) string
- func AesCBCEnStringHex(s string, key []byte) string
- func AesCBCEncrypt(asPKCS7 bool, plaintext, key []byte, ivs ...[]byte) (ciphertext []byte)
- func AesCBCEncryptE(asPKCS7 bool, plaintext, key []byte, ivs ...[]byte) ([]byte, error)
- func Decrypt(value, secret string) string
- func Encrypt(value, secret string) string
- func GetCertificate(network, addr string, timeout time.Duration, tlsConf *tls.Config) (*x509.Certificate, error)
- func GetenvDecrypt(key string, secret string) string
- func Open(ciphertext, key []byte) ([]byte, error)
- func OpenString(ciphertext string, key []byte) (string, error)
- func Padding(b []byte, bSize int, pkcs7 bool) []byte
- func Seal(plaintext, key []byte) ([]byte, error)
- func SealString(plaintext string, key []byte) (string, error)
- func SetenvEncrypt(key, value, secret string) (string, error)
- func UnPadding(b []byte, pkcs7 bool) []byte
Examples ¶
Constants ¶
const ( // AES128KeySize 是 Seal / Open 接受的 AES-128 密钥长度. AES128KeySize = 16 // AES256KeySize 是 Seal / Open 推荐的 AES-256 密钥长度. AES256KeySize = 32 )
Variables ¶
var ( // ErrInvalidKey 表示密钥长度不是 16 或 32 字节. // 调用方应使用独立随机密钥或 HKDF / Argon2 派生结果, 不要传入口令或 MD5Hex(secret). ErrInvalidKey = errors.New("invalid AEAD key") // ErrInvalidCiphertext 表示密文过短、文本编码损坏、密钥错误或认证失败. // Open / OpenString 在这些情况下不返回部分明文. ErrInvalidCiphertext = errors.New("invalid AEAD ciphertext") )
var ( ErrInvalidParam = errors.New("invalid parameter") ErrInvalidCert = errors.New("invalid certificate") )
Functions ¶
func AesCBCDePKCS7B58 ¶
AesCBCDePKCS7B58 解密, Pkcs7Padding
func AesCBCDePKCS7B64 ¶
AesCBCDePKCS7B64 解密, Pkcs7Padding
func AesCBCDePKCS7Hex ¶
AesCBCDePKCS7Hex 解密, Pkcs7Padding
func AesCBCDePKCS7StringB58 ¶
AesCBCDePKCS7StringB58 解密, Pkcs7Padding
func AesCBCDePKCS7StringB64 ¶
AesCBCDePKCS7StringB64 解密, Pkcs7Padding
func AesCBCDePKCS7StringHex ¶
AesCBCDePKCS7StringHex 解密, Pkcs7Padding
func AesCBCDeStringB58 ¶
AesCBCDeStringB58 解密, ZerosPadding
func AesCBCDeStringB64 ¶
AesCBCDeStringB64 解密, ZerosPadding
func AesCBCDeStringHex ¶
AesCBCDeStringHex 解密, ZerosPadding
func AesCBCDecrypt ¶
AesCBCDecrypt AES-CBC 解密, 忽略底层错误. Decrypt 走 Zeros padding 且不传 IV, 失败时返回空切片.
func AesCBCDecryptE ¶
AesCBCDecryptE AES-CBC 解密, 密码分组链接模式 (Cipher Block Chaining (CBC)). IV 规则与 AesCBCEncryptE 相同. Zeros padding 去不掉明文末尾的 0x00; 全零块依赖 recover 避免 UnPadding 越界, 调用方仍应把空结果当失败.
func AesCBCEnPKCS7B58 ¶
AesCBCEnPKCS7B58 加密, Pkcs7Padding
func AesCBCEnPKCS7B64 ¶
AesCBCEnPKCS7B64 加密, Pkcs7Padding
func AesCBCEnPKCS7Hex ¶
AesCBCEnPKCS7Hex 加密, Pkcs7Padding
func AesCBCEnPKCS7StringB58 ¶
AesCBCEnPKCS7StringB58 加密, Pkcs7Padding
func AesCBCEnPKCS7StringB64 ¶
AesCBCEnPKCS7StringB64 加密, Pkcs7Padding
func AesCBCEnPKCS7StringHex ¶
AesCBCEnPKCS7StringHex 加密, Pkcs7Padding
func AesCBCEnStringB58 ¶
AesCBCEnStringB58 加密, ZerosPadding
func AesCBCEnStringB64 ¶
AesCBCEnStringB64 加密, ZerosPadding
func AesCBCEnStringHex ¶
AesCBCEnStringHex 加密, ZerosPadding
func AesCBCEncrypt ¶
AesCBCEncrypt AES-CBC 加密, 忽略底层错误. Encrypt 走 Zeros padding 且不传 IV, 失败时返回空切片.
func AesCBCEncryptE ¶
AesCBCEncryptE AES-CBC 加密, 密码分组链接模式 (Cipher Block Chaining (CBC)). key 长度必须是 16 / 24 / 32; 非法长度返回错误. asPKCS7: false 为 ZerosPadding, true 为 Pkcs7Padding. 未传 IV 或 IV 长度不等于 BlockSize 时使用 key[:blockSize]. Encrypt 固定走 ZerosPadding 且不传 IV, 该默认值是已发布密文契约.
func Encrypt ¶
Encrypt 是确定性配置包装, 不是通用加密, 也不是 AEAD. 算法: secret 做 MD5Hex 得到 32 字节 AES-256 密钥, AES-CBC + Zeros padding, 默认 IV 为 key[:16], 输出 base58. secret 为空时原样返回明文. 同一明文+同一密钥永远得到同一密文; 错误被吞掉, 失败时可能返回空串. 已有 BASE_SECRET_KEY 和业务密钥依赖该输出, 不能改算法或编码.
func GetCertificate ¶
func GetCertificate(network, addr string, timeout time.Duration, tlsConf *tls.Config) (*x509.Certificate, error)
GetCertificate 获取 TLS 服务返回的首张证书. addr 支持主机名、显式 host:port 和 https:// 前缀; 未指定端口时使用 443. tlsConf 为 nil 时使用系统信任根, 调用方需要为私有 CA 显式提供配置.
func GetenvDecrypt ¶
GetenvDecrypt 读取环境变量 key, 再用 Decrypt 还原. 缺失变量、错误密钥或损坏密文通常得到空串, 由调用方判断是否拒绝启动.
func Open ¶ added in v1.2.1
Open 解开 Seal 产出的密文.
输入必须是 nonce(12) || ciphertext || tag(16). 密钥必须与 Seal 时完全相同. 密文过短、被改、密钥错误或认证失败都返回 ErrInvalidCiphertext, 不返回部分明文.
func OpenString ¶ added in v1.2.1
OpenString 解开 SealString 产出的文本密文. 只接受不带填充的 Raw URL Base64; 标准 Base64、填充 '-' / '_' 变体或损坏文本返回 ErrInvalidCiphertext.
func Seal ¶ added in v1.2.1
Seal 用 AES-GCM 封装明文, 返回 nonce || ciphertext || tag.
这是 pkg 推荐的通用加密入口, 不是 Encrypt 的升级版. 配置密钥、环境变量和 BASE_SECRET_KEY 必须继续使用 Encrypt / Decrypt / GetenvDecrypt.
契约:
- key 必须是 16 或 32 字节; 推荐 32 字节 AES-256. 非法长度返回 ErrInvalidKey.
- nonce 固定 12 字节, 来自 crypto/rand, 每次调用都重新生成并写在密文最前面.
- 同一明文 + 同一密钥会得到不同密文; 同一密钥可以解开这些密文, 得到同一明文.
- 不接受调用方传入 nonce, 也不把上下文拼进 key. 需要绑定租户或路由时再使用后续 WithAD.
- nil 与空明文都合法, 结果仍包含 nonce 和 tag, 长度至少 28 字节.
- 失败返回 error, 不吞错, 不返回半段密文.
Example ¶
ExampleSeal 演示二进制封装: 同一密钥可解开每次都不同的密文.
package main
import (
"crypto/rand"
"fmt"
"github.com/fufuok/pkg/xcrypto"
)
func main() {
key := make([]byte, xcrypto.AES256KeySize)
if _, err := rand.Read(key); err != nil {
panic(err)
}
first, err := xcrypto.Seal([]byte("hello"), key)
if err != nil {
panic(err)
}
second, err := xcrypto.Seal([]byte("hello"), key)
if err != nil {
panic(err)
}
plain, err := xcrypto.Open(first, key)
if err != nil {
panic(err)
}
fmt.Println(string(plain))
fmt.Println(len(first) == 12+5+16)
fmt.Println(len(first) == len(second))
fmt.Println(string(first) != string(second))
}
Output: hello true true true
func SealString ¶ added in v1.2.1
SealString 封装明文字符串, 再做 base64.RawURLEncoding. 二进制布局与 Seal 相同; 适合放入 URL、Cookie 或文本配置, 不适合替代 Encrypt.
Example ¶
ExampleSealString 演示文本封装, 输出可放入 URL 或配置值.
package main
import (
"crypto/rand"
"fmt"
"github.com/fufuok/pkg/xcrypto"
)
func main() {
key := make([]byte, xcrypto.AES256KeySize)
if _, err := rand.Read(key); err != nil {
panic(err)
}
sealed, err := xcrypto.SealString("redis-password", key)
if err != nil {
panic(err)
}
plain, err := xcrypto.OpenString(sealed, key)
if err != nil {
panic(err)
}
fmt.Println(plain)
fmt.Println(len(sealed) > 0)
}
Output: redis-password true
func SetenvEncrypt ¶
SetenvEncrypt 用 Encrypt 加密 value 后写入环境变量 key. 返回值是写入后的密文; 仅 os.Setenv 失败时返回错误, 加密失败会被吞成空串或原文.
Types ¶
This section is empty.