Class: Yes::Core::DataEncryptor

Inherits:
Object
  • Object
show all
Defined in:
lib/yes/core/data_encryptor.rb

Overview

Encrypts event data attributes using a key from the key repository.

Examples:

encryptor = DataEncryptor.new(data: event.data, schema: event.class.encryption_schema, repository: repo)
encryptor.call
encryptor.encrypted_data
encryptor.

Constant Summary collapse

CIPHERTEXT_KEY =

Data key holding the ciphertext of all encrypted attributes. Its presence means the data is currently encrypted: it is written here and removed by Yes::Core::DataDecryptor.

'es_encrypted'

Instance Attribute Summary collapse

Instance Method Summary collapse

Instance Attribute Details

#encrypted_data ⇒ Hash (readonly)

Returns the encrypted data.

Returns:

  • (Hash) —

    the encrypted data



18
19
20
# File 'lib/yes/core/data_encryptor.rb', line 18

def encrypted_data
  @encrypted_data
end

#encryption_metadata ⇒ Hash (readonly)

Returns the encryption metadata (key, iv, attributes).

Returns:

  • (Hash) —

    the encryption metadata (key, iv, attributes)



21
22
23
# File 'lib/yes/core/data_encryptor.rb', line 21

def 
  @encryption_metadata
end

Instance Method Details

#call ⇒ Hash

Encrypts the data attributes specified in the schema.

Returns:

  • (Hash) —

    the encrypted data



26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
# File 'lib/yes/core/data_encryptor.rb', line 26

def call
  return encrypted_data if .empty?

  key_id = [:key]
  res = key_repository.find(key_id)
  res = key_repository.create(key_id) if res.failure?
  key = res.value!

  [:iv] = key.attributes[:iv]
  encrypt_attributes(
    key:,
    data: encrypted_data,
    attributes: [:attributes].map(&:to_s)
  )
end