-
Notifications
You must be signed in to change notification settings - Fork 64
/
armor62_encrypt.go
82 lines (73 loc) · 2.91 KB
/
armor62_encrypt.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
// Copyright 2015 Keybase, Inc. All rights reserved. Use of
// this source code is governed by the included BSD license.
package saltpack
import (
"bytes"
"io"
)
type closeForwarder []io.WriteCloser
func (c closeForwarder) Write(b []byte) (int, error) {
return c[0].Write(b)
}
func (c closeForwarder) Close() error {
for _, w := range c {
if e := w.Close(); e != nil {
return e
}
}
return nil
}
func newEncryptArmor62Stream(version Version, ciphertext io.Writer, sender BoxSecretKey, receivers []BoxPublicKey, ephemeralKeyCreator EphemeralKeyCreator, rng encryptRNG, brand string) (plaintext io.WriteCloser, err error) {
enc, err := NewArmor62EncoderStream(ciphertext, MessageTypeEncryption, brand)
if err != nil {
return nil, err
}
out, err := newEncryptStream(version, enc, sender, receivers, ephemeralKeyCreator, rng)
if err != nil {
return nil, err
}
return closeForwarder([]io.WriteCloser{out, enc}), nil
}
// NewEncryptArmor62Stream creates a stream that consumes plaintext data.
// It will write out encrypted data to the io.Writer passed in as ciphertext.
// The encryption is from the specified sender, and is encrypted for the
// given receivers.
//
// The "brand" is the optional "brand" string to put into the header
// and footer.
//
// The ciphertext is additionally armored with the recommended armor62-style format.
//
// If initialization succeeds, returns an io.WriteCloser that accepts
// plaintext data to be encrypted and a nil error. Otherwise, returns
// nil and the initialization error.
func NewEncryptArmor62Stream(version Version, ciphertext io.Writer, sender BoxSecretKey, receivers []BoxPublicKey, brand string) (plaintext io.WriteCloser, err error) {
ephemeralKeyCreator, err := receiversToEphemeralKeyCreator(receivers)
if err != nil {
return nil, err
}
return newEncryptArmor62Stream(version, ciphertext, sender, receivers, ephemeralKeyCreator, defaultEncryptRNG{}, brand)
}
func encryptArmor62Seal(version Version, plaintext []byte, sender BoxSecretKey, receivers []BoxPublicKey, ephemeralKeyCreator EphemeralKeyCreator, rng encryptRNG, brand string) (string, error) {
var buf bytes.Buffer
enc, err := newEncryptArmor62Stream(version, &buf, sender, receivers, ephemeralKeyCreator, rng, brand)
if err != nil {
return "", err
}
if _, err := enc.Write(plaintext); err != nil {
return "", err
}
if err := enc.Close(); err != nil {
return "", err
}
return buf.String(), nil
}
// EncryptArmor62Seal is the non-streaming version of NewEncryptArmor62Stream, which
// inputs a plaintext (in bytes) and output a ciphertext (as a string).
func EncryptArmor62Seal(version Version, plaintext []byte, sender BoxSecretKey, receivers []BoxPublicKey, brand string) (string, error) {
ephemeralKeyCreator, err := receiversToEphemeralKeyCreator(receivers)
if err != nil {
return "", err
}
return encryptArmor62Seal(version, plaintext, sender, receivers, ephemeralKeyCreator, defaultEncryptRNG{}, brand)
}