@filoz/filecoin-encryption-envelope
Filecoin Encryption Envelope (FIP-1253) - Main Entry Point
Example
Section titled “Example”import * as fee from '@filoz/filecoin-encryption-envelope'
source.pipeThrough(fee.encrypt({ cek })) // chunked stream, the defaultencrypted.pipeThrough(fee.decrypt(cek)) // and backawait fee.decryptRange(object, cek, { offset: 1024, length: 4096 }) // one byte rangefee.aesGcm.encrypt(plaintext, { cek }) // whole-object, opt-infee.constants.ALG_A256KWNamespaces
Section titled “Namespaces”| Namespace | Description |
|---|---|
| aesGcm | - |
| constants | - |
| cose | COSE decode-only inspection surface (FIP-1253): read an untrusted envelope into its typed protected header, unprotected header, and recipient list. See docs/tech-spec.md, “Wire profile” and “CDDL”. |
| errors | - |
| recipients | - |
Interfaces
Section titled “Interfaces”| Interface | Description |
|---|---|
| ByteRange | A byte range over an object’s plaintext, HTTP Range-header style. |
| ChunkedEncryptOptions | Options for one chunked AES-256-GCM STREAM encryption using a direct CEK. |
| ChunkedEnvelopeParams | Cached values from one chunked envelope’s protected header, for range decryption to reuse. |
| RandomAccessSource | One immutable encoded FEE object, readable by byte range. |
| RangeResult | - |
Type Aliases
Section titled “Type Aliases”| Type Alias | Description |
|---|---|
| AppMetadata | Opaque, string-keyed application metadata. Carried but never interpreted. |
| CborValue | CBOR values supported by this profile. |
| EnvelopeInfo | Only the chunked scheme carries params: scheme 1 is decrypted as one complete object, never by range. |
Functions
Section titled “Functions”| Function | Description |
|---|---|
| decrypt | Decrypt a scheme-2 (chunked AES-256-GCM STREAM) object using a direct CEK. |
| decryptRange | Decrypt one byte range of a chunked object using a direct CEK. |
| decryptRangeWith | Like decryptRange, but recovers the CEK from the envelope’s recipients through unwrapper. |
| decryptWith | Decrypt a scheme-2 object using a CEK recovered by unwrapper. |
| encrypt | Creates a streaming encryptor using scheme 2 (chunked AES-256-GCM STREAM) with a direct CEK. |
| parse | Inspect an encoded FEE object without a key: scheme, content type, application metadata, and recipients. Unauthenticated — see above. |