(password: string, plaintext: string)
| 1089 | // Envelope format: [salt:16][iv:12][ciphertext:n][authTag:16] |
| 1090 | |
| 1091 | async function encryptMessage(password: string, plaintext: string): Promise<Uint8Array> { |
| 1092 | const salt = crypto.randomBytes(16); |
| 1093 | const key = await deriveKey(password, salt); |
| 1094 | |
| 1095 | const { transform, getParams } = createAes256GcmEncryptTransform(key); |
| 1096 | const ciphertext = await Stream.bytes(Stream.pull(Stream.from(plaintext), transform)); |
| 1097 | const params = getParams(); |
| 1098 | |
| 1099 | // Build envelope |
| 1100 | const envelope = new Uint8Array(16 + 12 + ciphertext.length + 16); |
| 1101 | envelope.set(salt, 0); |
| 1102 | envelope.set(params.iv, 16); |
| 1103 | envelope.set(ciphertext, 28); |
| 1104 | envelope.set(params.authTag!, 28 + ciphertext.length); |
| 1105 | |
| 1106 | return envelope; |
| 1107 | } |
| 1108 | |
| 1109 | async function decryptMessage(password: string, envelope: Uint8Array): Promise<string> { |
| 1110 | const salt = envelope.slice(0, 16); |
no test coverage detected