Skip to content

decryptRange

decryptRange(source, cek, range, options?): Promise<RangeResult>

Defined in: packages/filecoin-encryption-envelope/src/range/decrypt.ts:267

Decrypt one byte range of a chunked object using a direct CEK.

The promise settles with every result field — rangeLength, totalPlaintextLength, ciphertextSpan, includesFinalChunk — known before any ciphertext is fetched, so a caller can send response headers first. ciphertextSpan is one contiguous request, opened lazily on the stream’s first read; each chunk’s plaintext is released only after its own tag verifies.

cek is borrowed until this promise settles; source is borrowed until stream closes or errors. Pass options.params from parse() on this same object version to skip re-reading the envelope. A mismatch isn’t guaranteed to be caught: most fail authentication, but versions that differ only outside the protected header and the chunks read can still decrypt.

Truncation: a declared plaintext_length catches a size mismatch before any fetch. A range that includes the presumed final chunk catches truncation via that chunk’s authenticated last_flag. A range stopping short of the end, on an object with neither, can’t tell.

If stream errors, discard everything already read from it.

ParameterType
sourceUint8Array<ArrayBufferLike> | RandomAccessSource
cekUint8Array
rangeByteRange
options?RangeDecryptOptions

Promise<RangeResult>