( keyToWrap: CryptoKey, userKEK: string )
| 50 | Wrap the given key. |
| 51 | */ |
| 52 | async function wrapCryptoKey( |
| 53 | keyToWrap: CryptoKey, |
| 54 | userKEK: string |
| 55 | ): Promise<{ wrappedPrivKey: ArrayBuffer; salt: Uint8Array }> { |
| 56 | // get the key encryption key |
| 57 | const keyMaterial = await getKeyMaterial(userKEK) |
| 58 | const salt = crypto.getRandomValues(new Uint8Array(16)) |
| 59 | const wrappingKey = await getKey(keyMaterial, salt) |
| 60 | const bytesToWrap = await crypto.subtle.exportKey('pkcs8', keyToWrap) |
| 61 | const wrappedPrivKey = await crypto.subtle.encrypt( |
| 62 | { |
| 63 | name: 'AES-GCM', |
| 64 | iv: salt, |
| 65 | }, |
| 66 | wrappingKey, |
| 67 | bytesToWrap as ArrayBuffer |
| 68 | ) |
| 69 | |
| 70 | return { wrappedPrivKey, salt } |
| 71 | } |
| 72 | |
| 73 | /* |
| 74 | Generate a new wrapped user key |
no test coverage detected