diff options
| author | Levi Durfee <levi.durfee@gmail.com> | 2026-01-08 18:50:19 -0500 |
|---|---|---|
| committer | Levi Durfee <levi.durfee@gmail.com> | 2026-01-08 18:54:54 -0500 |
| commit | 6f706d0d05612d9778ece6414b3427c176214586 (patch) | |
| tree | b25266e973cb17ce4524f56314e621f8644a02aa /internal | |
| parent | dc0d6a4bf3c412aa69c579b74b0586fd61a08508 (diff) | |
Work on comments
Diffstat (limited to 'internal')
| -rw-r--r-- | internal/decrypt.go | 6 | ||||
| -rw-r--r-- | internal/encrypt.go | 3 | ||||
| -rw-r--r-- | internal/goaes.go | 1 |
3 files changed, 7 insertions, 3 deletions
diff --git a/internal/decrypt.go b/internal/decrypt.go index bd1f68b..252b033 100644 --- a/internal/decrypt.go +++ b/internal/decrypt.go @@ -1,17 +1,19 @@ package internal +// Decrypt recreates the kek from a passphrase and a salt, unwraps the dek using +// the kek, decrypts the data using the dek, and then returns the plaintext. func Decrypt(passphrase string, edek WrappedDEK, ct Ciphertext, salt Salt) ([]byte, error) { kek, err := NewKEKFromEnvB64(passphrase, salt) if err != nil { return nil, err } - dek2, err := UnwrapDEK(edek, kek) + dek, err := UnwrapDEK(edek, kek) if err != nil { return nil, err } - pt, err := DecryptData(ct, dek2) + pt, err := DecryptData(ct, dek) if err != nil { return nil, err } diff --git a/internal/encrypt.go b/internal/encrypt.go index 4efa722..5d2c794 100644 --- a/internal/encrypt.go +++ b/internal/encrypt.go @@ -1,5 +1,8 @@ package internal +// Encrypt generates a new salt, creates the kek from the passphrase and the new +// salt, creates a new dek, wraps the dek with the kek, encrypts the data with +// the dek, then returns the edek, salt, and ciphertext. func Encrypt(passphrase string, data []byte) (EncryptedDataPayload, error) { salt, err := NewSalt() if err != nil { diff --git a/internal/goaes.go b/internal/goaes.go index 7bc71f3..2afbbcf 100644 --- a/internal/goaes.go +++ b/internal/goaes.go @@ -74,7 +74,6 @@ func DecryptData(ct Ciphertext, dek DEK) ([]byte, error) { return decryptAEAD([]byte(ct), []byte(dek), aadDataMsg) } -// encryptAEAD returns: nonce || ciphertext func encryptAEAD(plaintext, key, aad []byte) ([]byte, error) { if !validAESKeyLen(len(key)) { return nil, errBadKeyLn |
