MCPcopy Create free account
hub / github.com/cloudflare/wildebeest / wrapCryptoKey

Function wrapCryptoKey

backend/src/utils/key-ops.ts:52–71  ·  view source on GitHub ↗
(
	keyToWrap: CryptoKey,
	userKEK: string
)

Source from the content-addressed store, hash-verified

50Wrap the given key.
51*/
52async function wrapCryptoKey(
53 keyToWrap: CryptoKey,
54 userKEK: string
55): Promise<{ wrappedPrivKey: ArrayBuffer; salt: Uint8Array }> {
56 // get the key encryption key
57 const keyMaterial = await getKeyMaterial(userKEK)
58 const salt = crypto.getRandomValues(new Uint8Array(16))
59 const wrappingKey = await getKey(keyMaterial, salt)
60 const bytesToWrap = await crypto.subtle.exportKey('pkcs8', keyToWrap)
61 const wrappedPrivKey = await crypto.subtle.encrypt(
62 {
63 name: 'AES-GCM',
64 iv: salt,
65 },
66 wrappingKey,
67 bytesToWrap as ArrayBuffer
68 )
69
70 return { wrappedPrivKey, salt }
71}
72
73/*
74Generate a new wrapped user key

Callers 1

generateUserKeyFunction · 0.85

Calls 2

getKeyMaterialFunction · 0.85
getKeyFunction · 0.85

Tested by

no test coverage detected