pub struct DryocSecretBox<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> { /* private fields */ }Expand description
An authenticated secret-key encrypted box, compatible with a libsodium box.
Use with either VecBox or protected::LockedBox type aliases.
Refer to crate::dryocsecretbox for sample usage.
Implementations§
Source§impl<Mac: NewByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: NewBytes + ResizableBytes + Zeroize> DryocSecretBox<Mac, Data>
impl<Mac: NewByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: NewBytes + ResizableBytes + Zeroize> DryocSecretBox<Mac, Data>
Sourcepub fn encrypt<Message: Bytes + ?Sized, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>(
message: &Message,
nonce: &Nonce,
secret_key: &SecretKey,
) -> Result<Self, Error>
pub fn encrypt<Message: Bytes + ?Sized, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>( message: &Message, nonce: &Nonce, secret_key: &SecretKey, ) -> Result<Self, Error>
Encrypts a message using secret_key and returns a new
DryocSecretBox with ciphertext and tag.
§Errors
Returns Error::InvalidLength with ErrorContext::Message if
message is longer than
CRYPTO_SECRETBOX_MESSAGEBYTES_MAX,
or with ErrorContext::Ciphertext if Data’s
ResizableBytes::resize leaves it shorter than message (storage
that cannot grow to the message length).
§Panics
Panics if allocation or resizing panics.
Source§impl<'a, Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + TryFrom<&'a [u8]> + Zeroize, Data: Bytes + From<&'a [u8]> + Zeroize> DryocSecretBox<Mac, Data>
impl<'a, Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + TryFrom<&'a [u8]> + Zeroize, Data: Bytes + From<&'a [u8]> + Zeroize> DryocSecretBox<Mac, Data>
Sourcepub fn from_bytes(bytes: &'a [u8]) -> Result<Self, Error>
pub fn from_bytes(bytes: &'a [u8]) -> Result<Self, Error>
Initializes a DryocSecretBox from a slice. Expects the first
CRYPTO_SECRETBOX_MACBYTES bytes to contain the message
authentication tag, with the remaining bytes containing the
encrypted message.
§Errors
Returns an error if bytes is shorter than one authentication tag or
the tag cannot be converted to Mac.
Source§impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> DryocSecretBox<Mac, Data>
impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> DryocSecretBox<Mac, Data>
Sourcepub fn from_parts(tag: Mac, data: Data) -> Self
pub fn from_parts(tag: Mac, data: Data) -> Self
Returns a new box with tag and data, consuming both.
Sourcepub fn to_vec(&self) -> Vec<u8> ⓘ
Available on crate feature alloc only.
pub fn to_vec(&self) -> Vec<u8> ⓘ
alloc only.Copies self into a new Vec.
Sourcepub fn into_parts(self) -> (Mac, Data)
pub fn into_parts(self) -> (Mac, Data)
Moves the tag and data out of this instance, returning them as a tuple.
Source§impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> DryocSecretBox<Mac, Data>
impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> DryocSecretBox<Mac, Data>
Sourcepub fn decrypt<Output: ResizableBytes + NewBytes, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>(
&self,
nonce: &Nonce,
secret_key: &SecretKey,
) -> Result<Output, Error>
pub fn decrypt<Output: ResizableBytes + NewBytes, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>( &self, nonce: &Nonce, secret_key: &SecretKey, ) -> Result<Output, Error>
Decrypts this box using secret_key.
§Errors
Returns an error if the output storage is shorter than the ciphertext or authentication fails. Authentication fails when the key, nonce, tag, or ciphertext does not match the value used during encryption.
Sourcepub fn to_bytes<Bytes: NewBytes + ResizableBytes>(&self) -> Bytes
pub fn to_bytes<Bytes: NewBytes + ResizableBytes>(&self) -> Bytes
Copies self into the target. Can be used with protected memory.
Source§impl DryocSecretBox<Mac, Vec<u8>>
impl DryocSecretBox<Mac, Vec<u8>>
Sourcepub fn encrypt_to_vecbox<Message: Bytes + ?Sized, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>(
message: &Message,
nonce: &Nonce,
secret_key: &SecretKey,
) -> Result<Self, Error>
Available on crate feature alloc only.
pub fn encrypt_to_vecbox<Message: Bytes + ?Sized, Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>( message: &Message, nonce: &Nonce, secret_key: &SecretKey, ) -> Result<Self, Error>
alloc only.Encrypts a message using secret_key and returns a new
DryocSecretBox with ciphertext and tag.
§Errors
Returns Error::InvalidLength with ErrorContext::Message if
message is longer than
CRYPTO_SECRETBOX_MESSAGEBYTES_MAX.
The Vec storage always resizes, so this is the only error.
Sourcepub fn decrypt_to_vec<Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>(
&self,
nonce: &Nonce,
secret_key: &SecretKey,
) -> Result<Vec<u8>, Error>
Available on crate feature alloc only.
pub fn decrypt_to_vec<Nonce: ByteArray<CRYPTO_SECRETBOX_NONCEBYTES>, SecretKey: ByteArray<CRYPTO_SECRETBOX_KEYBYTES>>( &self, nonce: &Nonce, secret_key: &SecretKey, ) -> Result<Vec<u8>, Error>
alloc only.Decrypts this box using secret_key and returns the plaintext.
§Errors
Returns an error if authentication fails because the key, nonce, tag, or ciphertext does not match.
Trait Implementations§
Source§impl<Mac: Clone + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Clone + Bytes + Zeroize> Clone for DryocSecretBox<Mac, Data>
impl<Mac: Clone + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Clone + Bytes + Zeroize> Clone for DryocSecretBox<Mac, Data>
Source§impl<Mac: Debug + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Debug + Bytes + Zeroize> Debug for DryocSecretBox<Mac, Data>
impl<Mac: Debug + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Debug + Bytes + Zeroize> Debug for DryocSecretBox<Mac, Data>
Source§impl<'de, Mac, Data> Deserialize<'de> for DryocSecretBox<Mac, Data>where
Mac: Deserialize<'de> + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize,
Data: Deserialize<'de> + Bytes + Zeroize,
Available on crate feature serde only.
impl<'de, Mac, Data> Deserialize<'de> for DryocSecretBox<Mac, Data>where
Mac: Deserialize<'de> + ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize,
Data: Deserialize<'de> + Bytes + Zeroize,
serde only.Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Source§impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> PartialEq for DryocSecretBox<Mac, Data>
impl<Mac: ByteArray<CRYPTO_SECRETBOX_MACBYTES> + Zeroize, Data: Bytes + Zeroize> PartialEq for DryocSecretBox<Mac, Data>
Source§impl<Mac, Data> Serialize for DryocSecretBox<Mac, Data>
Available on crate feature serde only.
impl<Mac, Data> Serialize for DryocSecretBox<Mac, Data>
serde only.Source§impl<Mac, Data> Zeroize for DryocSecretBox<Mac, Data>
impl<Mac, Data> Zeroize for DryocSecretBox<Mac, Data>
Auto Trait Implementations§
impl<Mac, Data> Freeze for DryocSecretBox<Mac, Data>
impl<Mac, Data> RefUnwindSafe for DryocSecretBox<Mac, Data>where
Mac: RefUnwindSafe,
Data: RefUnwindSafe,
impl<Mac, Data> Send for DryocSecretBox<Mac, Data>
impl<Mac, Data> Sync for DryocSecretBox<Mac, Data>
impl<Mac, Data> Unpin for DryocSecretBox<Mac, Data>
impl<Mac, Data> UnsafeUnpin for DryocSecretBox<Mac, Data>where
Mac: UnsafeUnpin,
Data: UnsafeUnpin,
impl<Mac, Data> UnwindSafe for DryocSecretBox<Mac, Data>where
Mac: UnwindSafe,
Data: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<'de, T, C> Deserialize<'de, C> for Twhere
C: Config,
T: SchemaRead<'de, C>,
impl<'de, T, C> Deserialize<'de, C> for Twhere
C: Config,
T: SchemaRead<'de, C>,
Source§impl<'de, T> Deserialize<'de> for Twhere
T: SchemaRead<'de, Configuration>,
impl<'de, T> Deserialize<'de> for Twhere
T: SchemaRead<'de, Configuration>,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> DeserializeOwned for Twhere
T: SchemaReadOwned<Configuration>,
impl<T> DeserializeOwned for Twhere
T: SchemaReadOwned<Configuration>,
Source§fn deserialize_from<'de>(src: impl Reader<'de>) -> Result<Self::Dst, ReadError>
fn deserialize_from<'de>(src: impl Reader<'de>) -> Result<Self::Dst, ReadError>
Reader into a new Self::Dst.Source§fn deserialize_from_into<'de>(
src: impl Reader<'de>,
dst: &mut MaybeUninit<Self::Dst>,
) -> Result<(), ReadError>
fn deserialize_from_into<'de>( src: impl Reader<'de>, dst: &mut MaybeUninit<Self::Dst>, ) -> Result<(), ReadError>
Reader into dst.Source§impl<T, C> DeserializeOwned<C> for Twhere
C: Config,
T: SchemaReadOwned<C>,
impl<T, C> DeserializeOwned<C> for Twhere
C: Config,
T: SchemaReadOwned<C>,
Source§fn deserialize_from<'de>(src: impl Reader<'de>) -> Result<Self::Dst, ReadError>
fn deserialize_from<'de>(src: impl Reader<'de>) -> Result<Self::Dst, ReadError>
Reader into a new Self::Dst.Source§fn deserialize_from_into<'de>(
src: impl Reader<'de>,
dst: &mut MaybeUninit<Self::Dst>,
) -> Result<(), ReadError>
fn deserialize_from_into<'de>( src: impl Reader<'de>, dst: &mut MaybeUninit<Self::Dst>, ) -> Result<(), ReadError>
Reader into dst.impl<T, C> SchemaReadOwned<C> for Twhere
C: ConfigCore,
T: for<'de> SchemaRead<'de, C>,
Source§impl<T> Serialize for T
impl<T> Serialize for T
Source§fn serialize(src: &Self::Src) -> Result<Vec<u8>, WriteError>
fn serialize(src: &Self::Src) -> Result<Vec<u8>, WriteError>
alloc only.Vec of bytes.Source§fn serialize_into(dst: impl Writer, src: &Self::Src) -> Result<(), WriteError>
fn serialize_into(dst: impl Writer, src: &Self::Src) -> Result<(), WriteError>
Source§fn serialized_size(src: &Self::Src) -> Result<u64, WriteError>
fn serialized_size(src: &Self::Src) -> Result<u64, WriteError>
Source§impl<T, C> Serialize<C> for T
impl<T, C> Serialize<C> for T
Source§fn serialize(src: &Self::Src, config: C) -> Result<Vec<u8>, WriteError>
fn serialize(src: &Self::Src, config: C) -> Result<Vec<u8>, WriteError>
alloc only.Vec of bytes.