1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
|
package internal
func Encrypt(data []byte) (EncryptedDataPayload, error) {
kek, salt, err := NewKEKFromEnvB64("GOAES_PASSPHRASE")
if err != nil {
return EncryptedDataPayload{}, err
}
dek, err := NewDEK()
if err != nil {
return EncryptedDataPayload{}, err
}
edek, err := WrapDEK(dek, kek)
if err != nil {
return EncryptedDataPayload{}, err
}
ct, err := EncryptData(data, dek)
if err != nil {
return EncryptedDataPayload{}, err
}
return EncryptedDataPayload{
DEK: edek,
Salt: salt,
Payload: ct,
}, nil
}
|