Skip to content

@filoz/filecoin-encryption-envelope

Filecoin Encryption Envelope (FIP-1253) - Main Entry Point

import * as fee from '@filoz/filecoin-encryption-envelope'
source.pipeThrough(fee.encrypt({ cek })) // chunked stream, the default
encrypted.pipeThrough(fee.decrypt(cek)) // and back
await fee.decryptRange(object, cek, { offset: 1024, length: 4096 }) // one byte range
fee.aesGcm.encrypt(plaintext, { cek }) // whole-object, opt-in
fee.constants.ALG_A256KW
NamespaceDescription
aesGcm-
constants-
coseCOSE decode-only inspection surface (FIP-1253): read an untrusted envelope into its typed protected header, unprotected header, and recipient list. See docs/tech-spec.md, “Wire profile” and “CDDL”.
errors-
recipients-
InterfaceDescription
ByteRangeA byte range over an object’s plaintext, HTTP Range-header style.
ChunkedEncryptOptionsOptions for one chunked AES-256-GCM STREAM encryption using a direct CEK.
ChunkedEnvelopeParamsCached values from one chunked envelope’s protected header, for range decryption to reuse.
RandomAccessSourceOne immutable encoded FEE object, readable by byte range.
RangeResult-
Type AliasDescription
AppMetadataOpaque, string-keyed application metadata. Carried but never interpreted.
CborValueCBOR values supported by this profile.
EnvelopeInfoOnly the chunked scheme carries params: scheme 1 is decrypted as one complete object, never by range.
FunctionDescription
decryptDecrypt a scheme-2 (chunked AES-256-GCM STREAM) object using a direct CEK.
decryptRangeDecrypt one byte range of a chunked object using a direct CEK.
decryptRangeWithLike decryptRange, but recovers the CEK from the envelope’s recipients through unwrapper.
decryptWithDecrypt a scheme-2 object using a CEK recovered by unwrapper.
encryptCreates a streaming encryptor using scheme 2 (chunked AES-256-GCM STREAM) with a direct CEK.
parseInspect an encoded FEE object without a key: scheme, content type, application metadata, and recipients. Unauthenticated — see above.