package envelope import ( "bytes" "fmt" ) // magic prefixes every sealed ciphertext, ahead of the version byte. The // leading NUL guarantees that printable-text plaintext can never carry it, so a // text secret accidentally stored in the ciphertext column fails the header // check instead of passing as sealed data. It is a tripwire for mistakes, not a // defense against forgery (the GCM auth tag is the integrity guarantee). var magic = [4]byte{0x00, 'E', 'N', 'V'} // version is the ciphertext framing version, following the magic. const version = 1 // headerLen is the magic prefix plus the version byte. const headerLen = len(magic) + 1 // IsSealed reports whether b carries the sealed-data header (magic + known // version). Storage code checks this before persisting, so plaintext or a // mis-sourced byte slice cannot be written to a ciphertext column. func IsSealed(b []byte) bool { return validHeader(b) == nil } func validHeader(ct []byte) error { if len(ct) < headerLen { return fmt.Errorf("envelope: ciphertext too short") } if !bytes.Equal(ct[:len(magic)], magic[:]) { return fmt.Errorf("envelope: bad magic (not sealed data?)") } if ct[len(magic)] != version { return fmt.Errorf("envelope: unknown framing version %d", ct[len(magic)]) } return nil }