MCPcopy Create free account
hub / github.com/GoogleCloudPlatform/nodejs-docs-samples / main

Function main

kms/decryptSymmetric.js:17–75  ·  view source on GitHub ↗
(
  projectId = 'my-project',
  locationId = 'us-east1',
  keyRingId = 'my-key-ring',
  keyId = 'my-key',
  ciphertext = Buffer.from('...')
)

Source from the content-addressed store, hash-verified

15'use strict';
16
17async function main(
18 projectId = 'my-project',
19 locationId = 'us-east1',
20 keyRingId = 'my-key-ring',
21 keyId = 'my-key',
22 ciphertext = Buffer.from('...')
23) {
24 // [START kms_decrypt_symmetric]
25 //
26 // TODO(developer): Uncomment these variables before running the sample.
27 //
28 // const projectId = 'my-project';
29 // const locationId = 'us-east1';
30 // const keyRingId = 'my-key-ring';
31 // const keyId = 'my-key';
32 // Ciphertext must be either a Buffer object or a base-64 encoded string
33 // const ciphertext = Buffer.from('...');
34
35 // Imports the Cloud KMS library
36 const {KeyManagementServiceClient} = require('@google-cloud/kms');
37
38 // Instantiates a client
39 const client = new KeyManagementServiceClient();
40
41 // Build the key name
42 const keyName = client.cryptoKeyPath(projectId, locationId, keyRingId, keyId);
43
44 // Optional, but recommended: compute ciphertext's CRC32C.
45 const crc32c = require('fast-crc32c');
46 const ciphertextCrc32c = crc32c.calculate(ciphertext);
47
48 async function decryptSymmetric() {
49 const [decryptResponse] = await client.decrypt({
50 name: keyName,
51 ciphertext: ciphertext,
52 ciphertextCrc32c: {
53 value: ciphertextCrc32c,
54 },
55 });
56
57 // Optional, but recommended: perform integrity verification on decryptResponse.
58 // For more details on ensuring E2E in-transit integrity to and from Cloud KMS visit:
59 // https://cloud.google.com/kms/docs/data-integrity-guidelines
60 if (
61 crc32c.calculate(decryptResponse.plaintext) !==
62 Number(decryptResponse.plaintextCrc32c.value)
63 ) {
64 throw new Error('Decrypt: response corrupted in-transit');
65 }
66
67 const plaintext = decryptResponse.plaintext.toString();
68
69 console.log(`Plaintext: ${plaintext}`);
70 return plaintext;
71 }
72
73 return decryptSymmetric();
74 // [END kms_decrypt_symmetric]

Callers 1

Calls 1

decryptSymmetricFunction · 0.85

Tested by

no test coverage detected