use openvtc_core::config::{
derive_passphrase_key,
secured_config::{unlock_code_decrypt, unlock_code_encrypt},
};
fn main() {
let key = derive_passphrase_key(b"my-secure-passphrase", b"example-context-v1")
.expect("Key derivation should succeed");
println!("Derived 32-byte key from passphrase (Argon2id)");
println!("Key (hex): {}", hex::encode(key));
let plaintext = b"Hello from OpenVTC! This is sensitive configuration data.";
let ciphertext = unlock_code_encrypt(&key, plaintext).expect("Encryption should succeed");
println!(
"\nPlaintext ({} bytes): {:?}",
plaintext.len(),
std::str::from_utf8(plaintext).unwrap()
);
println!(
"Ciphertext ({} bytes): [nonce(12) + encrypted + auth_tag(16)]",
ciphertext.len()
);
let decrypted = unlock_code_decrypt(&key, &ciphertext).expect("Decryption should succeed");
assert_eq!(decrypted, plaintext);
println!(
"\nDecrypted successfully: {:?}",
std::str::from_utf8(&decrypted).unwrap()
);
let ciphertext2 = unlock_code_encrypt(&key, plaintext).expect("Encryption should succeed");
assert_ne!(ciphertext, ciphertext2);
println!("\nSecond encryption of same data produces different ciphertext (random nonce)");
let key_a = derive_passphrase_key(b"same-passphrase", b"context-a")
.expect("Key derivation should succeed");
let key_b = derive_passphrase_key(b"same-passphrase", b"context-b")
.expect("Key derivation should succeed");
assert_ne!(key_a, key_b);
println!("Domain separation: same passphrase + different context = different keys");
}