Skip to main content

EncryptedRecord

Struct EncryptedRecord 

pub struct EncryptedRecord {
    pub iv: Iv,
    pub ciphertext: Vec<u8>,
    pub tag: Vec<u8>,
    pub descriptor: String,
    pub keyset_id: Option<Uuid>,
    pub decryption_policy: Option<DecryptionPolicy>,
}
Expand description

Represents an encrypted record for storage in the database. Implements serialization and deserialization so you can use it with any serde-compatible format however convenience methods are provided for CBOR, MessagePack, Hex, and Base85 encoding.

Fields§

§iv: Iv§ciphertext: Vec<u8>§tag: Vec<u8>§descriptor: String§keyset_id: Option<Uuid>§decryption_policy: Option<DecryptionPolicy>

Decryption policy with server-generated MAC (tag_version=1 only).

Implementations§

§

impl EncryptedRecord

pub fn to_vec(&self) -> Result<Vec<u8>, DecryptError>

👎Deprecated since 0.12.4:

Use to_cbor_bytes or to_mp_bytes instead

Serialize the record to a Vec<u8> using CBOR encoding

pub fn to_cbor_bytes(&self) -> Result<Vec<u8>, DecryptError>

Serialize the record to a Vec<u8> using CBOR encoding

pub fn to_mp_bytes(&self) -> Result<Vec<u8>, DecryptError>

Serialize the record to a Vec<u8> using MessagePack encoding

pub fn to_hex(&self) -> Result<String, DecryptError>

👎Deprecated since 0.12.4:

Use to_cbor_hex or to_mp_base85 instead

Serialize the record using CBOR and convert to a hex-encoded string

pub fn to_cbor_hex(&self) -> Result<String, DecryptError>

Serialize the record using CBOR and convert to a hex-encoded string

pub fn to_mp_base85(&self) -> Result<String, DecryptError>

Serialize the record using MessagePack and convert to a base85-encoded string

pub fn from_slice(bytes: &[u8]) -> Result<Self, DecryptError>

👎Deprecated since 0.12.4:

Use from_cbor_bytes or from_mp_bytes instead

Deserialize a record from a slice of bytes encoded using CBOR

pub fn from_cbor_bytes(bytes: &[u8]) -> Result<Self, DecryptError>

Deserialize a record from a slice of bytes encoded using CBOR

pub fn from_mp_bytes(bytes: &[u8]) -> Result<Self, DecryptError>

Deserialize a record from a slice of bytes encoded using MessagePack

pub fn from_hex(hexstr: impl AsRef<[u8]>) -> Result<Self, DecryptError>

👎Deprecated since 0.12.4:

Use from_cbor_hex or from_mp_base85 instead

Deserialize a record from a hex-encoded string of bytes encoded using CBOR

pub fn from_cbor_hex(hexstr: &str) -> Result<Self, DecryptError>

Deserialize a record from a hex-encoded string of bytes encoded using CBOR

pub fn from_mp_base85(base85str: &str) -> Result<Self, DecryptError>

Deserialize a record from a base85-encoded string of bytes encoded using MessagePack

pub fn with_context<'a>(self, context: Context) -> WithContext<'a>

Add a context to the record to prepare it for decryption.

Trait Implementations§

§

impl Clone for EncryptedRecord

§

fn clone(&self) -> EncryptedRecord

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
§

impl Debug for EncryptedRecord

§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
§

impl Decryptable for EncryptedRecord

§

type Error = Infallible

§

fn keyset_id(&self) -> Option<Uuid>

The keyset ID associated with the record, if any.
§

fn retrieve_key_payload(&self) -> Result<RetrieveKeyPayload<'_>, Self::Error>

The payload used to retrieve the key for decryption.
§

fn into_encrypted_record(self) -> Result<EncryptedRecord, Self::Error>

Convert the record into an EncryptedRecord.
§

fn nonce_override(&self) -> Option<[u8; 12]>

The explicit AEAD nonce for this record, when the wire format derives it from something other than the data key’s IV. SteVec entries under the envelope wire format derive it from the entry’s stored selector (nonce = selector_bytes[..12]); classic records return None and decrypt with the IV-derived nonce.
§

fn aad_selector(&self) -> Option<[u8; 16]>

The full 16-byte tokenized selector to bind into the AEAD AAD, when the wire format ties the ciphertext to a selector. The nonce only covers the first 12 selector bytes, so binding all 16 here authenticates the whole selector — a stored selector cannot be mutated (even in its last 4 bytes) without the entry failing to decrypt. SteVec entries return their selector; classic records return None and add nothing to the AAD.
§

impl<'de> Deserialize<'de> for EncryptedRecord

§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
§

impl Display for EncryptedRecord

§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
§

impl<'a> From<&'a EncryptedRecord> for RetrieveKeyPayload<'a>

§

fn from(record: &'a EncryptedRecord) -> Self

Converts to this type from the input type.
§

impl Serialize for EncryptedRecord

§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AuthStrategyBounds for T
where T: Send + Sync + 'static,

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: Rng + ?Sized, Self: FakeBase<U>,

Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: Rng + ?Sized, Self: FakeBase<U>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T> ToStringFallible for T
where T: Display,

Source§

fn try_to_string(&self) -> Result<String, TryReserveError>

ToString::to_string, but without panic on OOM.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> ValidateIp for T
where T: ToString,

Source§

fn validate_ipv4(&self) -> bool

Validates whether the given string is an IP V4
Source§

fn validate_ipv6(&self) -> bool

Validates whether the given string is an IP V6
Source§

fn validate_ip(&self) -> bool

Validates whether the given string is an IP
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more