Skip to main content

EncryptionManager

Struct EncryptionManager 

Source
pub struct EncryptionManager { /* private fields */ }
Expand description

Encryption manager for repository

Implementations§

Source§

impl EncryptionManager

Source

pub fn new(config: EncryptionConfig) -> Self

Create new encryption manager

Source

pub fn from_key( config: EncryptionConfig, key: &EncryptionKey, ) -> Result<Self, String>

Build a manager around a key that is already in hand.

rotate-key is why this exists. It has to encrypt with the new key while the key file on disk still describes the old one, and going through initialize there reads that file: either it rejects the new passphrase outright, or it derives the new passphrase against the old salt and writes data that the key file it then saves cannot open.

Source

pub fn new_auto(config: EncryptionConfig, repo_path: &Path) -> Self

Build a manager, initializing it from a non-interactive passphrase source when encryption is enabled and one is available.

Every command builds its object store through ObjectStore::new, which returns Self rather than a Result and must not prompt — Lit is zero-prompt by design. So the passphrase comes from LIT_PASSPHRASE, LIT_PASSPHRASE_FILE or the cache, and nothing else.

With encryption enabled and no source available the manager stays uninitialized on purpose: the first encrypt or decrypt then reports that plainly, which is a better failure than a constructor that cannot explain itself.

Source

pub fn is_encrypted_payload(data: &[u8]) -> bool

Whether data carries our encryption header.

Lets a reader tell ciphertext from content written before encryption was switched on, so a repository part-way through migration stays readable. Nothing we write in the clear begins with this byte: refs hold hex or ref: , the index holds JSON.

Source

pub fn initialize(&mut self, passphrase: &str) -> Result<(), String>

Initialize encryption with passphrase

Source

pub fn initialize_with_cache( &mut self, repo_path: &str, passphrase: Option<&str>, ) -> Result<(), String>

Initialize encryption with passphrase caching support

Source

pub fn encrypt(&self, plaintext: &[u8]) -> Result<Vec<u8>, String>

Encrypt data if encryption is enabled

Source

pub fn decrypt(&self, encrypted: &[u8]) -> Result<Vec<u8>, String>

Decrypt data if encryption is enabled

Source

pub fn is_enabled(&self) -> bool

Check if encryption is enabled

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.