pub struct EncryptionManager { /* private fields */ }Expand description
Encryption manager for repository
Implementations§
Source§impl EncryptionManager
impl EncryptionManager
Sourcepub fn new(config: EncryptionConfig) -> Self
pub fn new(config: EncryptionConfig) -> Self
Create new encryption manager
Sourcepub fn new_auto(config: EncryptionConfig, repo_path: &Path) -> Self
pub fn new_auto(config: EncryptionConfig, repo_path: &Path) -> Self
Build a manager, initializing it from a non-interactive passphrase source when encryption is enabled and one is available.
Every command builds its object store through ObjectStore::new, which
returns Self rather than a Result and must not prompt — Lit is
zero-prompt by design. So the passphrase comes from LIT_PASSPHRASE,
LIT_PASSPHRASE_FILE or the cache, and nothing else.
With encryption enabled and no source available the manager stays uninitialized on purpose: the first encrypt or decrypt then reports that plainly, which is a better failure than a constructor that cannot explain itself.
Sourcepub fn initialize(&mut self, passphrase: &str) -> Result<(), String>
pub fn initialize(&mut self, passphrase: &str) -> Result<(), String>
Initialize encryption with passphrase
Sourcepub fn initialize_with_cache(
&mut self,
repo_path: &str,
passphrase: Option<&str>,
) -> Result<(), String>
pub fn initialize_with_cache( &mut self, repo_path: &str, passphrase: Option<&str>, ) -> Result<(), String>
Initialize encryption with passphrase caching support
Sourcepub fn encrypt(&self, plaintext: &[u8]) -> Result<Vec<u8>, String>
pub fn encrypt(&self, plaintext: &[u8]) -> Result<Vec<u8>, String>
Encrypt data if encryption is enabled
Sourcepub fn decrypt(&self, encrypted: &[u8]) -> Result<Vec<u8>, String>
pub fn decrypt(&self, encrypted: &[u8]) -> Result<Vec<u8>, String>
Decrypt data if encryption is enabled
Sourcepub fn is_enabled(&self) -> bool
pub fn is_enabled(&self) -> bool
Check if encryption is enabled