Class: Mongo::ClientEncryption
- Inherits:
-
Object
- Object
- Mongo::ClientEncryption
- Defined in:
- lib/mongo/client_encryption.rb
Overview
ClientEncryption encapsulates explicit operations on a key vault collection that cannot be done directly on a MongoClient. It provides an API for explicitly encrypting and decrypting values, and creating data keys.
Instance Method Summary collapse
-
#add_key_alt_name(id, key_alt_name) ⇒ BSON::Document | nil
Adds a key_alt_name for the key in the key vault collection with the given id.
-
#create_data_key(kms_provider, options = {}) ⇒ BSON::Binary
Generates a data key used for encryption/decryption and stores that key in the KMS collection.
-
#create_encrypted_collection(database, coll_name, coll_opts, kms_provider, master_key) ⇒ Array<Operation::Result, Hash>
Create collection with encrypted fields.
-
#decrypt(value) ⇒ Object
Decrypts a value that has already been encrypted.
-
#delete_key(id) ⇒ Operation::Result
Removes the key with the given id from the key vault collection.
-
#encrypt(value, options = {}) ⇒ BSON::Binary
Encrypts a value using the specified encryption key and algorithm.
-
#encrypt_expression(expression, options = {}) ⇒ BSON::Binary
Encrypts a Match Expression or Aggregate Expression to query a range index.
-
#get_key(id) ⇒ BSON::Document | nil
Finds a single key with the given id.
-
#get_key_by_alt_name(key_alt_name) ⇒ BSON::Document | nil
Returns a key in the key vault collection with the given key_alt_name.
-
#get_keys ⇒ Collection::View
(also: #keys)
Returns all keys in the key vault collection.
-
#initialize(key_vault_client, options = {}) ⇒ ClientEncryption
constructor
Create a new ClientEncryption object with the provided options.
-
#remove_key_alt_name(id, key_alt_name) ⇒ BSON::Document | nil
Removes a key_alt_name from a key in the key vault collection with the given id.
-
#rewrap_many_data_key(filter, opts = {}) ⇒ Crypt::RewrapManyDataKeyResult
Decrypts multiple data keys and (re-)encrypts them with a new master_key, or with their current master_key if a new one is not given.
Constructor Details
#initialize(key_vault_client, options = {}) ⇒ ClientEncryption
Create a new ClientEncryption object with the provided options.
52 53 54 55 56 57 58 59 60 61 |
# File 'lib/mongo/client_encryption.rb', line 52 def initialize(key_vault_client, = {}) @encrypter = Crypt::ExplicitEncrypter.new( key_vault_client, [:key_vault_namespace], Crypt::KMS::Credentials.new([:kms_providers]), Crypt::KMS::Validations.([:kms_tls_options]), [:timeout_ms], [:key_expiration_ms] ) end |
Instance Method Details
#add_key_alt_name(id, key_alt_name) ⇒ BSON::Document | nil
Adds a key_alt_name for the key in the key vault collection with the given id.
207 208 209 |
# File 'lib/mongo/client_encryption.rb', line 207 def add_key_alt_name(id, key_alt_name) @encrypter.add_key_alt_name(id, key_alt_name) end |
#create_data_key(kms_provider, options = {}) ⇒ BSON::Binary
Generates a data key used for encryption/decryption and stores that key in the KMS collection. The generated key is encrypted with the KMS master key.
89 90 91 92 93 94 95 |
# File 'lib/mongo/client_encryption.rb', line 89 def create_data_key(kms_provider, = {}) key_document = Crypt::KMS::MasterKeyDocument.new(kms_provider, ) key_alt_names = [:key_alt_names] key_material = [:key_material] @encrypter.create_and_insert_data_key(key_document, key_alt_names, key_material) end |
#create_encrypted_collection(database, coll_name, coll_opts, kms_provider, master_key) ⇒ Array<Operation::Result, Hash>
This method does not update the :encrypted_fields_map in the client's :auto_encryption_options. Therefore, in order to use the collection created by this method with automatic encryption, the user must create a new client after calling this function with the :encrypted_fields returned.
Create collection with encrypted fields.
If :encryption_fields contains a keyId with a null value, a data key will be automatically generated and assigned to keyId value.
294 295 296 297 298 299 300 301 302 303 304 305 |
# File 'lib/mongo/client_encryption.rb', line 294 def create_encrypted_collection(database, coll_name, coll_opts, kms_provider, master_key) raise ArgumentError, 'coll_opts must contain :encrypted_fields' unless coll_opts[:encrypted_fields] encrypted_fields = create_data_keys(coll_opts[:encrypted_fields], kms_provider, master_key) begin new_coll_opts = coll_opts.dup.merge(encrypted_fields: encrypted_fields) [ database[coll_name].create(new_coll_opts), encrypted_fields ] rescue Mongo::Error => e raise Error::CryptError, "Error creating collection with encrypted fields \ #{encrypted_fields}: #{e.class}: #{e.}" end end |
#decrypt(value) ⇒ Object
Decrypts a value that has already been encrypted.
196 197 198 |
# File 'lib/mongo/client_encryption.rb', line 196 def decrypt(value) @encrypter.decrypt(value) end |
#delete_key(id) ⇒ Operation::Result
Removes the key with the given id from the key vault collection.
217 218 219 |
# File 'lib/mongo/client_encryption.rb', line 217 def delete_key(id) @encrypter.delete_key(id) end |
#encrypt(value, options = {}) ⇒ BSON::Binary
The result of explicit encryption with the "Indexed", "Range", or "String" algorithm must be processed by the server to insert or query. To insert or query with such a payload, use a Mongo::Client configured with :auto_encryption_options. The :bypass_query_analysis option may be true; the :bypass_auto_encryption option must be false.
The "substring" query type is unstable and subject to backwards breaking changes.
The :key_id and :key_alt_name options are mutually exclusive. Only one is required to perform explicit encryption.
Encrypts a value using the specified encryption key and algorithm.
146 147 148 |
# File 'lib/mongo/client_encryption.rb', line 146 def encrypt(value, = {}) @encrypter.encrypt(value, ) end |
#encrypt_expression(expression, options = {}) ⇒ BSON::Binary
The :key_id and :key_alt_name options are mutually exclusive. Only one is required to perform explicit encryption.
Encrypts a Match Expression or Aggregate Expression to query a range index.
Only supported when queryType is "range" and algorithm is "Range". @note: The Range algorithm is experimental only. It is not intended for public use. It is subject to breaking changes.
@param [ Hash ] options
186 187 188 |
# File 'lib/mongo/client_encryption.rb', line 186 def encrypt_expression(expression, = {}) @encrypter.encrypt_expression(expression, ) end |
#get_key(id) ⇒ BSON::Document | nil
Finds a single key with the given id.
227 228 229 |
# File 'lib/mongo/client_encryption.rb', line 227 def get_key(id) @encrypter.get_key(id) end |
#get_key_by_alt_name(key_alt_name) ⇒ BSON::Document | nil
Returns a key in the key vault collection with the given key_alt_name.
237 238 239 |
# File 'lib/mongo/client_encryption.rb', line 237 def get_key_by_alt_name(key_alt_name) @encrypter.get_key_by_alt_name(key_alt_name) end |
#get_keys ⇒ Collection::View Also known as: keys
Returns all keys in the key vault collection.
244 245 246 |
# File 'lib/mongo/client_encryption.rb', line 244 def get_keys @encrypter.get_keys end |
#remove_key_alt_name(id, key_alt_name) ⇒ BSON::Document | nil
Removes a key_alt_name from a key in the key vault collection with the given id.
256 257 258 |
# File 'lib/mongo/client_encryption.rb', line 256 def remove_key_alt_name(id, key_alt_name) @encrypter.remove_key_alt_name(id, key_alt_name) end |
#rewrap_many_data_key(filter, opts = {}) ⇒ Crypt::RewrapManyDataKeyResult
Decrypts multiple data keys and (re-)encrypts them with a new master_key, or with their current master_key if a new one is not given.
271 272 273 |
# File 'lib/mongo/client_encryption.rb', line 271 def rewrap_many_data_key(filter, opts = {}) @encrypter.rewrap_many_data_key(filter, opts) end |