summaryrefslogtreecommitdiff
path: root/internal/encrypt.go
blob: bc3bf7fbb00448f281acad70b26ad67fdf746ed0 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
package internal

import (
	"github.com/joho/godotenv"
)

func Encrypt(data []byte) (EncryptedDataPayload, error) {
	godotenv.Load()

	kek, err := NewKEKFromEnvB64("SECRET_KEY")
	if err != nil {
		return EncryptedDataPayload{}, err
	}

	dek, err := NewDEK()
	if err != nil {
		return EncryptedDataPayload{}, err
	}

	edek, err := WrapDEK(dek, kek)
	if err != nil {
		return EncryptedDataPayload{}, err
	}

	ct, err := EncryptData(data, dek)
	if err != nil {
		return EncryptedDataPayload{}, err
	}

	return EncryptedDataPayload{
		DEK:     edek,
		Payload: ct,
	}, nil
}