Skip to content

decrypt

decrypt(key): ReadableWritablePair<Uint8Array<ArrayBufferLike>, Uint8Array<ArrayBufferLike>>

Defined in: packages/filecoin-encryption-envelope/src/aes-gcm-stream.ts:482

Creates a streaming decryptor for a scheme-2 object using either a direct CEK or a KeyResolver.

The writable side accepts the encoded object. The readable side emits each plaintext chunk only after its authentication tag has been verified.

A KeyResolver is called at most once, after the envelope is decoded and before any ciphertext is decrypted. It receives the same EnvelopeInfo reported by parse. The resolver is not called if the stream fails before that point or the readable side is never consumed.

EnvelopeInfo is derived from unauthenticated envelope data, so a resolver must treat it as untrusted input when deciding which key to derive or fetch. Plaintext remains protected by the AEAD authentication performed afterward.

Resolver failures are wrapped in KeyResolutionError; an invalid resolved key is rejected as an invalid CEK.

Input blocks may be reused once their corresponding write() resolves. If decryption later fails, any plaintext already emitted belongs to an incomplete object and must be discarded.

ParameterType
keyUint8Array<ArrayBufferLike> | KeyResolver

ReadableWritablePair<Uint8Array<ArrayBufferLike>, Uint8Array<ArrayBufferLike>>