Expand description
Tenant-scoped encrypted BLOB persistence for tee capture payloads.
The tee stores redacted request and response bodies as opaque binary payloads. This module keeps those payloads encrypted at rest with a tenant-provided 32-byte key and a per-blob ChaCha20-Poly1305 nonce. Authentication failures on read are surfaced as errors and do not return plaintext.
Structs§
- Blob
Handle - Opaque handle returned after a blob is written.
- Encrypted
Blob - Ciphertext plus the unique nonce required for decryption.
- Sqlite
Encrypted Blob Store - SQLite-backed encrypted BLOB store.
- Tenant
Id - Tenant identifier used to isolate encrypted BLOB rows.
- Tenant
Key - Tenant-scoped 256-bit AEAD key.
Enums§
- Blob
Store Error - Errors returned by SQLite encrypted BLOB persistence.
- Decrypt
Error - Decryption failure. Authentication failure is intentionally coarse so callers cannot distinguish a wrong key from ciphertext tampering.
- Encrypt
Error - Encryption failure surfaced without panicking in public helpers.
Functions§
- decrypt_
blob - Decrypt
blobwith the tenant key. - encrypt_
blob - Encrypt
plaintextwith the tenant key.