MCPcopy Create free account
hub / github.com/GoogleCloudPlatform/nodejs-docs-samples / main

Function main

kms/decryptAsymmetric.js:17–89  ·  view source on GitHub ↗
(
  projectId = 'my-project',
  locationId = 'us-east1',
  keyRingId = 'my-key-ring',
  keyId = 'my-key',
  versionId = '123',
  ciphertext = Buffer.from('...')
)

Source from the content-addressed store, hash-verified

15'use strict';
16
17async function main(
18 projectId = 'my-project',
19 locationId = 'us-east1',
20 keyRingId = 'my-key-ring',
21 keyId = 'my-key',
22 versionId = '123',
23 ciphertext = Buffer.from('...')
24) {
25 // [START kms_decrypt_asymmetric]
26 //
27 // TODO(developer): Uncomment these variables before running the sample.
28 //
29 // const projectId = 'my-project';
30 // const locationId = 'us-east1';
31 // const keyRingId = 'my-key-ring';
32 // const keyId = 'my-key';
33 // const versionId = '123';
34 // const ciphertext = Buffer.from('...');
35
36 // Imports the Cloud KMS library
37 const {KeyManagementServiceClient} = require('@google-cloud/kms');
38
39 // Instantiates a client
40 const client = new KeyManagementServiceClient();
41
42 // Build the key version name
43 const versionName = client.cryptoKeyVersionPath(
44 projectId,
45 locationId,
46 keyRingId,
47 keyId,
48 versionId
49 );
50
51 // Optional, but recommended: compute plaintext's CRC32C.
52 const crc32c = require('fast-crc32c');
53 const ciphertextCrc32c = crc32c.calculate(ciphertext);
54
55 async function decryptAsymmetric() {
56 const [decryptResponse] = await client.asymmetricDecrypt({
57 name: versionName,
58 ciphertext: ciphertext,
59 ciphertextCrc32c: {
60 value: ciphertextCrc32c,
61 },
62 });
63
64 // Optional, but recommended: perform integrity verification on decryptResponse.
65 // For more details on ensuring E2E in-transit integrity to and from Cloud KMS visit:
66 // https://cloud.google.com/kms/docs/data-integrity-guidelines
67 if (!decryptResponse.verifiedCiphertextCrc32c) {
68 throw new Error('AsymmetricDecrypt: request corrupted in-transit');
69 }
70 if (
71 crc32c.calculate(decryptResponse.plaintext) !==
72 Number(decryptResponse.plaintextCrc32c.value)
73 ) {
74 throw new Error('AsymmetricDecrypt: response corrupted in-transit');

Callers 1

Calls 1

decryptAsymmetricFunction · 0.85

Tested by

no test coverage detected