pub struct Encrypted<T>(/* private fields */);Expand description
A field stored encrypted (AES-256-GCM under APP_KEY), read and written
as a plain T in Rust: a national id number, a bank account, a
third-party API secret. Laravel’s encrypted cast.
use renox::db::Encrypted;
#[derive(Model, serde::Serialize, Default)]
#[model(table = "suppliers")]
struct Supplier {
id: i64,
name: String,
bank_account: Encrypted<String>, // a TEXT column holding the sealed value
api_key: Option<Encrypted<String>>,
}
let supplier = Supplier::create(&db, Supplier {
name: "Corner Coffee".into(),
bank_account: Encrypted::new("BCA 123-456-789".into()),
..Default::default()
}).await?;
assert_eq!(*supplier.bank_account, "BCA 123-456-789"); // `Deref` to the valueThe value is sealed with the key of the Db that writes it
and opened with the key of the one that reads it (the app’s APP_KEY,
set at boot), so it works the same in handlers, jobs, commands, seeders
and tests. Each write uses a fresh nonce, so the column can’t be searched
or indexed: look rows up by another column. Changing APP_KEY makes the
values unreadable. T is stored as JSON, so any serde type works.
Debug prints Encrypted(..), never the value; Serialize writes the
plain value (for your JSON and templates, where you decide to show it).
Implementations§
Trait Implementations§
Source§impl<'de, T: Deserialize<'de>> Deserialize<'de> for Encrypted<T>
impl<'de, T: Deserialize<'de>> Deserialize<'de> for Encrypted<T>
Source§fn deserialize<D: Deserializer<'de>>(deserializer: D) -> Result<Self, D::Error>
fn deserialize<D: Deserializer<'de>>(deserializer: D) -> Result<Self, D::Error>
impl<T: Eq> Eq for Encrypted<T>
Source§impl<T: Ord> Ord for Encrypted<T>
impl<T: Ord> Ord for Encrypted<T>
1.21.0 (const: unstable) · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
1.21.0 (const: unstable) · Source§fn min(self, other: Self) -> Selfwhere
Self: Sized,
fn min(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl<T: PartialOrd> PartialOrd for Encrypted<T>
impl<T: PartialOrd> PartialOrd for Encrypted<T>
impl<T: PartialEq> StructuralPartialEq for Encrypted<T>
Source§impl<T: Serialize> ToDbValue for Encrypted<T>
impl<T: Serialize> ToDbValue for Encrypted<T>
Source§fn to_db_value(&self) -> DbValue
fn to_db_value(&self) -> DbValue
The plain value as JSON; the statement seals it with its database’s key when it runs.
Auto Trait Implementations§
impl<T> Freeze for Encrypted<T>where
T: Freeze,
impl<T> RefUnwindSafe for Encrypted<T>where
T: RefUnwindSafe,
impl<T> Send for Encrypted<T>where
T: Send,
impl<T> Sync for Encrypted<T>where
T: Sync,
impl<T> Unpin for Encrypted<T>where
T: Unpin,
impl<T> UnsafeUnpin for Encrypted<T>where
T: UnsafeUnpin,
impl<T> UnwindSafe for Encrypted<T>where
T: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Comparable<K> for Q
impl<Q, K> Comparable<K> for Q
impl<R> CryptoRng for R
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
impl<T> Formattable for T
impl<T> FromDb for T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreimpl<T> Parsable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
impl<R> RngCore for Rwhere
R: Rng,
Source§impl<R> RngExt for R
impl<R> RngExt for R
Source§fn random<T>(&mut self) -> Twhere
StandardUniform: Distribution<T>,
fn random<T>(&mut self) -> Twhere
StandardUniform: Distribution<T>,
StandardUniform distribution. Read moreSource§fn random_iter<T>(self) -> Iter<StandardUniform, Self, T> ⓘ
fn random_iter<T>(self) -> Iter<StandardUniform, Self, T> ⓘ
Source§fn random_range<T, R>(&mut self, range: R) -> Twhere
T: SampleUniform,
R: SampleRange<T>,
fn random_range<T, R>(&mut self, range: R) -> Twhere
T: SampleUniform,
R: SampleRange<T>,
Source§fn random_bool(&mut self, p: f64) -> bool
fn random_bool(&mut self, p: f64) -> bool
p of being true. Read moreSource§fn random_ratio(&mut self, numerator: u32, denominator: u32) -> bool
fn random_ratio(&mut self, numerator: u32, denominator: u32) -> bool
numerator/denominator of being
true. Read more