Skip to main content

Encryptor

Struct Encryptor 

Source
pub struct Encryptor { /* private fields */ }
Expand description

Encrypts and decrypts column values with keys derived from SECRET_KEY_BASE.

Models use it through Encrypted and Deterministic; use it directly for values outside a model (a job argument, an API token to call another service).

§Examples

use ocre::encryption::Encryptor;

let secret = "a".repeat(64);
let encryptor = Encryptor::new(&secret, &[]).unwrap();
let stored = encryptor.encrypt("123-45-6789");
assert!(stored.starts_with("v1:"));
assert_ne!(stored, encryptor.encrypt("123-45-6789")); // a random nonce each time
assert_eq!(encryptor.decrypt(&stored).unwrap(), "123-45-6789");
// Deterministic: the same text for the same value, so it can be looked up.
assert_eq!(encryptor.encrypt_deterministic("ada@example.com"), encryptor.encrypt_deterministic("ada@example.com"));

Implementations§

Source§

impl Encryptor

Source

pub fn new(secret: &str, previous: &[&str]) -> Result<Self>

Derives the keys from the current secret and the previous ones (newest first).

Each secret must be 64 characters or more, like SECRET_KEY_BASE.

§Errors

Error::Internal naming the fix when a secret is too short.

§Examples
use ocre::encryption::Encryptor;

let (old, new) = ("o".repeat(64), "n".repeat(64));
let stored = Encryptor::new(&old, &[]).unwrap().encrypt("secret");
let rotated = Encryptor::new(&new, &[old.as_str()]).unwrap();
assert_eq!(rotated.decrypt(&stored).unwrap(), "secret");
assert!(Encryptor::new("short", &[]).is_err());
Source

pub fn encrypt(&self, plaintext: &str) -> String

Encrypts plaintext with a random nonce: v1: plus URL-safe base64.

§Examples
let encryptor = ocre::encryption::Encryptor::new(&"k".repeat(64), &[]).unwrap();
assert_eq!(encryptor.decrypt(&encryptor.encrypt("")).unwrap(), "");
Source

pub fn encrypt_deterministic(&self, plaintext: &str) -> String

Encrypts plaintext so that equal values give equal texts (see Deterministic).

§Examples
let encryptor = ocre::encryption::Encryptor::new(&"k".repeat(64), &[]).unwrap();
let a = encryptor.encrypt_deterministic("ada@example.com");
assert_ne!(a, encryptor.encrypt_deterministic("bob@example.com"));
assert_eq!(encryptor.decrypt(&a).unwrap(), "ada@example.com");
Source

pub fn deterministic_candidates(&self, plaintext: &str) -> Vec<String>

The deterministic texts of plaintext under every key, current first: look rows up with Query::is_in during a key rotation.

§Examples
use ocre::encryption::Encryptor;

let (old, new) = ("o".repeat(64), "n".repeat(64));
let stored = Encryptor::new(&old, &[]).unwrap().encrypt_deterministic("ada@example.com");
let rotated = Encryptor::new(&new, &[old.as_str()]).unwrap();
let candidates = rotated.deterministic_candidates("ada@example.com");
assert_eq!(candidates.len(), 2);
assert!(candidates.contains(&stored));
Source

pub fn decrypt(&self, ciphertext: &str) -> Result<String>

Decrypts a value from encrypt or encrypt_deterministic, with the current key or a previous one.

§Errors

Error::Internal when ciphertext is not an encrypted value, was changed, or was encrypted with a key that is neither current nor previous. The message never contains the value.

§Examples
let encryptor = ocre::encryption::Encryptor::new(&"k".repeat(64), &[]).unwrap();
assert!(encryptor.decrypt("plain text").is_err());
Source

pub fn decrypt_or_plaintext(&self, text: &str) -> Result<String>

Like decrypt, but a value without the v1: prefix is returned as is: read a column while a data migration encrypts its existing rows (Rails’ support_unencrypted_data).

§Errors

Error::Internal when an encrypted value does not decrypt.

§Examples
let encryptor = ocre::encryption::Encryptor::new(&"k".repeat(64), &[]).unwrap();
assert_eq!(encryptor.decrypt_or_plaintext("not yet encrypted").unwrap(), "not yet encrypted");

Trait Implementations§

Source§

impl Clone for Encryptor

Source§

fn clone(&self) -> Encryptor

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Encryptor

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> FromRef<T> for T
where T: Clone,

§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<S, T> Upcast<T> for S
where T: UpcastFrom<S> + ?Sized, S: ?Sized,

Source§

fn upcast(&self) -> &T
where Self: ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider ref type within the Wasm bindgen generics type system. Read more
Source§

fn upcast_into(self) -> T
where Self: Sized + ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider type within the Wasm bindgen generics type system. Read more
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V