pub struct EncryptionKey { /* private fields */ }Expand description
A public key: encryption and wrapping, secret-free to hold.
Implementations§
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub async fn encrypt(
&self,
label: Option<Vec<u8>>,
plaintext: Vec<u8>,
) -> Result<Vec<u8>, Error>
pub async fn encrypt( &self, label: Option<Vec<u8>>, plaintext: Vec<u8>, ) -> Result<Vec<u8>, Error>
Encrypt a plaintext bounded by the key. label is optional
context bound into the padding: decryption succeeds only
under the same label (WebCrypto’s RsaOaepParams.label).
A plaintext above the key’s bound fails error.extension
— origin "polymorph:webcrypto", name "message-too-long" —
the signal to switch to hybrid wrapping (encrypt a symmetric
key, wrap the payload under it).
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub async fn wrap(
&self,
label: Option<Vec<u8>>,
input: WrapInput,
) -> Result<Vec<u8>, Error>
pub async fn wrap( &self, label: Option<Vec<u8>>, input: WrapInput, ) -> Result<Vec<u8>, Error>
Wrap key material serialized as a wrap-input (see the
wrapping interface): the material transits neither caller.
The serialized form must fit the key’s bound — symmetric-key
JWKs do, private-key serializations generally do not — else
error.extension "message-too-long", as on encrypt.
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub fn algorithm_name(&self) -> String
pub fn algorithm_name(&self) -> String
The registry name of the algorithm family this key is bound
to, e.g. "RSA-OAEP" (WebCrypto’s KeyAlgorithm.name).
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub fn algorithm_hash(&self) -> Option<String>
pub fn algorithm_hash(&self) -> Option<String>
The digest bound at mint, e.g. "SHA-256".
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub fn algorithm_length(&self) -> Option<u32>
pub fn algorithm_length(&self) -> Option<u32>
The key’s length in bits for algorithms parameterized by one (the RSA modulus length).
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
pub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
The public exponent for RSA-family keys, as WebCrypto’s
RsaKeyAlgorithm.publicExponent denominates it: the
exponent’s big-endian bytes ([1, 0, 1] for 65537). none
for algorithms without one.
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
pub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
The public key material, in the minting interface’s documented
public format; algorithms without a raw public form (the RSA
family) fail error.unsupported. No extractability gate —
public keys are unconditionally exportable — but still
fallible: a provider may hold a handle it can use but not
read (see README.md, “Extractability”).
Source§impl EncryptionKey
impl EncryptionKey
Source§impl EncryptionKey
impl EncryptionKey
Sourcepub async fn export_key_jwk(&self) -> Result<String, Error>
pub async fn export_key_jwk(&self) -> Result<String, Error>
The public key as a JWK. See mac-key.export-key-jwk for the
package-wide JWK contract; the same fallibility applies.