using IdentityShroud.Core.Contracts; using IdentityShroud.Core.Security; namespace IdentityShroud.Core.Services; /// /// /// public class DekEncryptionService : IDekEncryptionService { // Note this array is expected to have one item in it most of the during key rotation it will have two // until it is ensured the old key can safely be removed. More then two will work but is not really expected. private readonly KeyEncryptionKey[] _encryptionKeys; private KeyEncryptionKey ActiveKey => _encryptionKeys.Single(k => k.Active); private KeyEncryptionKey GetKey(KekId keyId) => _encryptionKeys.Single(k => k.Id == keyId); public DekEncryptionService(ISecretProvider secretProvider) { _encryptionKeys = secretProvider.GetKeys("master"); } public EncryptedDek Encrypt(ReadOnlySpan plaintext) { var encryptionKey = ActiveKey; byte[] cipher = Encryption.Encrypt(plaintext, encryptionKey.Key); return new (encryptionKey.Id, cipher); } public void Decrypt(EncryptedDek input, Span output) { var encryptionKey = GetKey(input.KekId); Encryption.Decrypt(input.Value, encryptionKey.Key, output); } public int GetDecryptedSize(EncryptedDek input) { return Encryption.GetDecryptedLength(input.Value); } }