Graphorin API reference v0.15.1
Graphorin API reference / @graphorin/security / / EncryptedFileSecretsStore
Class: EncryptedFileSecretsStore
Defined in: packages/security/src/secrets/stores/encrypted-file.ts:60
Stable
SecretsStore backed by an AES-256-GCM bundle on disk.
Implements
Constructors
Constructor
new EncryptedFileSecretsStore(opts): EncryptedFileSecretsStore;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:77
Parameters
| Parameter | Type |
|---|---|
opts | EncryptedFileSecretsStoreOptions |
Returns
EncryptedFileSecretsStore
Properties
| Property | Modifier | Type | Defined in |
|---|---|---|---|
kind | readonly | "encrypted-file" | packages/security/src/secrets/stores/encrypted-file.ts:61 |
Methods
delete()
delete(key, _scope?): Promise<void>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:149
Parameters
| Parameter | Type |
|---|---|
key | string |
_scope? | SessionScope |
Returns
Promise<void>
Implementation of
get()
get(key, _scope?): Promise<SecretValue | null>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:97
Returns the secret if it exists, null otherwise.
Parameters
| Parameter | Type |
|---|---|
key | string |
_scope? | SessionScope |
Returns
Promise<SecretValue | null>
Implementation of
list()
list(_scope?): Promise<readonly SecretMetadata[]>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:189
Returns metadata about every key - never the values themselves.
Parameters
| Parameter | Type |
|---|---|
_scope? | SessionScope |
Returns
Promise<readonly SecretMetadata[]>
Implementation of
rekey()
rekey(newPassphrase): Promise<void>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:179
Stable
Re-encrypt the whole bundle under a new passphrase.
Reads the bundle with the current passphrase (a wrong passphrase or a tampered bundle fails the GCM auth check and propagates), then atomically rewrites it keyed from newPassphrase. Every write uses a fresh random salt and nonce, so a rekey also rotates the KDF salt. On success the instance switches to the new passphrase for all subsequent operations.
The store takes no ownership of either SecretValue: it disposes neither the old nor the new passphrase - lifecycle stays with the caller. A missing bundle file propagates as ENOENT (there is nothing to rekey; set() a first secret instead).
Parameters
| Parameter | Type |
|---|---|
newPassphrase | SecretValue |
Returns
Promise<void>
require()
require(key, _scope?): Promise<SecretValue>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:119
Returns the secret or throws. Implementations enforce the per-tool secretsAllowed ACL: if the current tool context disallows key, throw SecretAccessDeniedError.
Parameters
| Parameter | Type |
|---|---|
key | string |
_scope? | SessionScope |
Returns
Promise<SecretValue>
Implementation of
set()
set(
key,
value,
opts?): Promise<void>;Defined in: packages/security/src/secrets/stores/encrypted-file.ts:132
Persist a secret. Implementations auto-wrap a plain string into a SecretValue so callers don't have to.
Parameters
| Parameter | Type |
|---|---|
key | string |
value | | string | SecretValue |
opts? | SecretsSetOptions |
Returns
Promise<void>