Documentation
¶
Overview ¶
Package secrets provides authenticated encryption (AES-256-GCM) for secret values stored at rest — MCP HTTP headers and stdio env vars. The key comes from CHATZ_SECRETS_KEY (base64, 32 bytes). Plaintext secrets never touch the DB; only sealed blobs (nonce-prefixed ciphertext) do.
Index ¶
Constants ¶
const (
// KeySize is the AES-256 key length in bytes.
KeySize = 32
)
Variables ¶
var ( // ErrInvalidKey is returned when the AEAD key is not exactly KeySize bytes. ErrInvalidKey = errors.New("secrets: key must be 32 bytes") // ErrCiphertextTooShort is returned when a value to Open is shorter than // the nonce prefix — it can't be authentic ciphertext. ErrCiphertextTooShort = errors.New("secrets: ciphertext too short") // ErrNotConfigured is returned when a nil Box (no CHATZ_SECRETS_KEY set) // is asked to seal or open a non-empty secret. Boot still succeeds without // a key; only storing/reading a secret needs one — so a plaintext secret is // never written when encryption is unavailable. ErrNotConfigured = errors.New("secrets: no encryption key configured") )
Secrets errors. Declared with errors.New so they stay comparable across ctxerrors.Wrap layers via errors.Is.
Functions ¶
This section is empty.
Types ¶
type Box ¶
type Box struct {
// contains filtered or unexported fields
}
Box seals and opens secret values with a single AEAD key.
func NewFromBase64 ¶
NewFromBase64 builds a Box from a base64-encoded 32-byte key (the CHATZ_SECRETS_KEY form). Generate one with `openssl rand -base64 32`.
func (*Box) Open ¶
Open decrypts a nonce||ciphertext blob produced by Seal. A tampered blob or wrong key fails authentication and returns an error. A nil Box (no key configured) returns ErrNotConfigured.
func (*Box) OpenMap ¶
OpenMap opens a blob produced by SealMap. A nil/empty blob returns a nil map (the "no secrets" case), not an error.