Skip to content

EventLogEncryption

Cryptographic service for encrypted event-log replication.

EventLogEncryption turns local journal entries into encrypted remote payloads and decrypts encrypted changes received from a server. It also hashes byte data and creates event-log identities, so remote replication can use storage or transport that should not see plaintext event data.

6 exports Added in v4.0.0 Source

Encryption

Creates an EventLogEncryption service backed by the Web Crypto SubtleCrypto APIs from the supplied Crypto implementation.

Signature

declare function makeEncryptionSubtle(crypto: Crypto): Effect<{
readonly decrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<EncryptedRemoteEntry>) => Effect<Array<RemoteEntry>>;
readonly encrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<Entry>) => Effect<{
readonly encryptedEntries: readonly Array<Uint8Array<ArrayBuffer>>;
readonly iv: Uint8Array<ArrayBuffer>;
}>;
readonly generateIdentity: Effect<{
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}>;
readonly sha256: (data: Uint8Array) => Effect<Uint8Array<ArrayBufferLike>>;
readonly sha256String: (data: Uint8Array) => Effect<string>;
}>

Layers

layerSubtle

Added in v4.0.0 Source

Provides EventLogEncryption using globalThis.crypto.

Signature

declare const layerSubtle: Layer.Layer<EventLogEncryption>;

Models

Schema for an encrypted journal entry paired with the id of the original entry.

Signature

declare const EncryptedEntry: Struct<{
readonly encryptedEntry: Transferable<
instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>
>;
readonly entryId: brand<
instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>,
"effect/eventlog/EventJournal/EntryId"
>;
}>;

Schema for encrypted entries exchanged with a remote event-log server.

Signature

declare const EncryptedRemoteEntry: Struct<{
readonly encryptedEntry: Transferable<
instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>
>;
readonly entryId: brand<
instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>,
"effect/eventlog/EventJournal/EntryId"
>;
readonly iv: Transferable<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>>;
readonly sequence: Natural;
}>;

EncryptedRemoteEntry interface

Added in v4.0.0 Source

Type of an encrypted remote entry, including its remote sequence number, initialization vector, entry id, and encrypted entry bytes.

Signature

interface EncryptedRemoteEntry extends Type<typeof EncryptedRemoteEntry> {}

Services

Service that provides identity generation, entry encryption and decryption, and SHA-256 hashing for event-log replication.

When to use

Use to provide cryptographic operations required by encrypted event-log replication.

Signature

declare class EventLogEncryption extends Shape<"effect/eventlog/EventLogEncryption", {
readonly decrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<EncryptedRemoteEntry>) => Effect<Array<RemoteEntry>>;
readonly encrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<Entry>) => Effect<{
readonly encryptedEntries: readonly Array<Uint8Array<ArrayBuffer>>;
readonly iv: Uint8Array<ArrayBuffer>;
}>;
readonly generateIdentity: Effect<{
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}>;
readonly sha256: (data: Uint8Array) => Effect<Uint8Array<ArrayBufferLike>>;
readonly sha256String: (data: Uint8Array) => Effect<string>;
}, this> {
constructor(_: never);
}