(key: Buffer, plaintext: string)
| 43 | const deriveKey = (master: string): Buffer => scryptSync(master, KEY_SALT, 32); |
| 44 | |
| 45 | const encryptSecret = (key: Buffer, plaintext: string): Effect.Effect<string, StorageError> => |
| 46 | Effect.try({ |
| 47 | try: () => { |
| 48 | const iv = randomBytes(12); |
| 49 | const cipher = createCipheriv("aes-256-gcm", key, iv); |
| 50 | const ciphertext = Buffer.concat([cipher.update(plaintext, "utf8"), cipher.final()]); |
| 51 | const tag = cipher.getAuthTag(); |
| 52 | return [ |
| 53 | PAYLOAD_VERSION, |
| 54 | iv.toString("base64"), |
| 55 | tag.toString("base64"), |
| 56 | ciphertext.toString("base64"), |
| 57 | ].join("."); |
| 58 | }, |
| 59 | catch: (cause) => new StorageError({ message: "Failed to encrypt secret", cause }), |
| 60 | }); |
| 61 | |
| 62 | const decryptSecret = (key: Buffer, payload: string): Effect.Effect<string, StorageError> => |
| 63 | Effect.try({ |
no test coverage detected