← all modules

Sky.Core.Crypto

Sky.Core.Crypto
  Sky.Core.Crypto — hash + MAC + signature + symmetric-cipher +

Values
  aesGcmDecrypt : Secret -> String -> Result Error String
      `aesGcmDecrypt key encoded` — decrypt the output of
  aesGcmEncrypt : Secret -> String -> Task Error String
      `aesGcmEncrypt key plaintext` — encrypt under AES-256-GCM.
  aesKeyFromPassword : Secret -> String -> Secret
      `aesKeyFromPassword password salt` — derive a 32-byte
  chacha20Decrypt : Secret -> String -> Result Error String
      `chacha20Decrypt key encoded` — decrypt the output of
  chacha20Encrypt : Secret -> String -> Task Error String
      `chacha20Encrypt key plaintext` — encrypt under
  chacha20Poly1305Open : Secret -> String -> String -> String -> Result Error String
      `chacha20Poly1305Open key nonce associatedData sealed` — the inverse of
  chacha20Poly1305Seal : Secret -> String -> String -> String -> Result Error String
      `chacha20Poly1305Seal key nonce associatedData plaintext` — IETF
  chachaKeyFromPassword : Secret -> String -> Secret
      `chachaKeyFromPassword password salt` — same as
  constantTimeEqual : String -> String -> Bool
      Constant-time string compare — use when comparing secrets (tokens,
  hmacSha256 : String -> String -> String
      `hmacSha256 key message` → hex HMAC-SHA256.
  hmacSha512 : String -> String -> String
      `hmacSha512 key message` → hex HMAC-SHA512.
  keyFromPasswordStrong : { iterations : Int , salt : String } -> Secret -> Task Error Secret
      `keyFromPasswordStrong { iterations, salt } password` — derive a
  md5 : String -> String
      MD5 — retained for legacy interoperability only. Not secure.
  randomBytes : Int -> Task Error String
      `randomBytes n` — `n` bytes (1..1024) of OS entropy, returned
  randomToken : Int -> Task Error String
      `randomToken n` — `n` bytes (1..1024) of OS entropy, returned as
  rsaSha256Sign : String -> String -> Result Error String
      `rsaSha256Sign pemPrivateKey message` → a standard-base64
  rsaSha256Verify : String -> String -> String -> Bool
      `rsaSha256Verify pemPublicKey message base64Signature` → is the
  sha1 : String -> String
      SHA-1 — for interop only (git object ids, legacy webhook
  sha256 : String -> String
  sha512 : String -> String
  xchacha20Poly1305Open : Secret -> String -> String -> String -> Result Error String
      `xchacha20Poly1305Open key nonce associatedData sealed` — the inverse of
  xchacha20Poly1305Seal : Secret -> String -> String -> String -> Result Error String
      `xchacha20Poly1305Seal key nonce associatedData plaintext` —
  xchachaOpen : Secret -> String -> Result Error String
      `xchachaOpen key sealed` — decrypt the output of `xchachaSeal`. `Err`
  xchachaOpenWith : Secret -> String -> String -> Result Error String
      `xchachaOpenWith key associatedData sealed` — decrypt the output of
  xchachaSeal : Secret -> String -> Task Error String
      `xchachaSeal key plaintext` — encrypt under XChaCha20-Poly1305
  xchachaSealWith : Secret -> String -> String -> Task Error String
      `xchachaSealWith key associatedData plaintext` — as `xchachaSeal`, and