pub struct EncryptionManager { /* private fields */ }Expand description
Encryption manager for repository
Implementations§
Source§impl EncryptionManager
impl EncryptionManager
Sourcepub fn new(config: EncryptionConfig) -> Self
pub fn new(config: EncryptionConfig) -> Self
Create new encryption manager
Sourcepub fn from_key(
config: EncryptionConfig,
key: &EncryptionKey,
) -> Result<Self, String>
pub fn from_key( config: EncryptionConfig, key: &EncryptionKey, ) -> Result<Self, String>
Build a manager around a key that is already in hand.
rotate-key is why this exists. It has to encrypt with the new key
while the key file on disk still describes the old one, and going
through initialize there reads that file: either it rejects the new
passphrase outright, or it derives the new passphrase against the old
salt and writes data that the key file it then saves cannot open.
Sourcepub fn new_auto(config: EncryptionConfig, repo_path: &Path) -> Self
pub fn new_auto(config: EncryptionConfig, repo_path: &Path) -> Self
Build a manager, initializing it from a non-interactive passphrase source when encryption is enabled and one is available.
Every command builds its object store through ObjectStore::new, which
returns Self rather than a Result and must not prompt — Lit is
zero-prompt by design. So the passphrase comes from LIT_PASSPHRASE,
LIT_PASSPHRASE_FILE or the cache, and nothing else.
With encryption enabled and no source available the manager stays uninitialized on purpose: the first encrypt or decrypt then reports that plainly, which is a better failure than a constructor that cannot explain itself.
Sourcepub fn is_encrypted_payload(data: &[u8]) -> bool
pub fn is_encrypted_payload(data: &[u8]) -> bool
Whether data carries our encryption header.
Lets a reader tell ciphertext from content written before encryption
was switched on, so a repository part-way through migration stays
readable. Nothing we write in the clear begins with this byte: refs hold
hex or ref: , the index holds JSON.
Sourcepub fn initialize(&mut self, passphrase: &str) -> Result<(), String>
pub fn initialize(&mut self, passphrase: &str) -> Result<(), String>
Initialize encryption with passphrase
Sourcepub fn initialize_with_cache(
&mut self,
repo_path: &str,
passphrase: Option<&str>,
) -> Result<(), String>
pub fn initialize_with_cache( &mut self, repo_path: &str, passphrase: Option<&str>, ) -> Result<(), String>
Initialize encryption with passphrase caching support
Sourcepub fn encrypt(&self, plaintext: &[u8]) -> Result<Vec<u8>, String>
pub fn encrypt(&self, plaintext: &[u8]) -> Result<Vec<u8>, String>
Encrypt data if encryption is enabled
Sourcepub fn decrypt(&self, encrypted: &[u8]) -> Result<Vec<u8>, String>
pub fn decrypt(&self, encrypted: &[u8]) -> Result<Vec<u8>, String>
Decrypt data if encryption is enabled
Sourcepub fn is_enabled(&self) -> bool
pub fn is_enabled(&self) -> bool
Check if encryption is enabled