Struct RecordWithNonce
pub struct RecordWithNonce {
pub record: EncryptedRecord,
pub selector: [u8; 16],
}Expand description
A Decryptable pairing an EncryptedRecord with the tokenized
selector that binds it.
The SteVec envelope wire format stores one key header per document and ties
each entry to its stored selector instead of the data key’s IV. A consumer
decrypting such an entry reconstructs the record from the header + the
entry’s ciphertext and pairs it with the entry’s 16-byte selector here. The
selector is the single source of both bindings: the AEAD nonce is its first
12 bytes (Decryptable::nonce_override) and the full 16 bytes are bound
into the AAD (Decryptable::aad_selector), so the ciphertext is
authenticated against the entire selector. Every decrypt pipeline honours
both.
Fields§
§record: EncryptedRecord§selector: [u8; 16]Trait Implementations§
§impl Debug for RecordWithNonce
impl Debug for RecordWithNonce
§impl Decryptable for RecordWithNonce
impl Decryptable for RecordWithNonce
type Error = Infallible
§fn retrieve_key_payload<'a>(
&'a self,
) -> Result<RetrieveKeyPayload<'a>, Self::Error>
fn retrieve_key_payload<'a>( &'a self, ) -> Result<RetrieveKeyPayload<'a>, Self::Error>
The payload used to retrieve the key for decryption.
§fn into_encrypted_record(self) -> Result<EncryptedRecord, Self::Error>
fn into_encrypted_record(self) -> Result<EncryptedRecord, Self::Error>
Convert the record into an EncryptedRecord.
§fn nonce_override(&self) -> Option<[u8; 12]>
fn nonce_override(&self) -> Option<[u8; 12]>
The explicit AEAD nonce for this record, when the wire format derives
it from something other than the data key’s IV. SteVec entries under
the envelope wire format derive it from the entry’s stored selector
(
nonce = selector_bytes[..12]); classic records return None and
decrypt with the IV-derived nonce.§fn aad_selector(&self) -> Option<[u8; 16]>
fn aad_selector(&self) -> Option<[u8; 16]>
The full 16-byte tokenized selector to bind into the AEAD AAD, when the
wire format ties the ciphertext to a selector. The nonce only covers the
first 12 selector bytes, so binding all 16 here authenticates the whole
selector — a stored selector cannot be mutated (even in its last 4
bytes) without the entry failing to decrypt. SteVec entries return their
selector; classic records return
None and add nothing to the AAD.Auto Trait Implementations§
impl Freeze for RecordWithNonce
impl RefUnwindSafe for RecordWithNonce
impl Send for RecordWithNonce
impl Sync for RecordWithNonce
impl Unpin for RecordWithNonce
impl UnsafeUnpin for RecordWithNonce
impl UnwindSafe for RecordWithNonce
Blanket Implementations§
impl<T> AuthStrategyBounds for T
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more