| |
| scriptlog:lib:core:scriptlogcryptonize [2026/09/26 09:09] – admin admin | scriptlog:lib:core:scriptlogcryptonize [2026/09/26 09:16] (current) – admin admin |
|---|
| ======= Docblock Metadata ======= | ======= Docblock Metadata ======= |
| |
| ^ Tag ^ Value ^ | ^ Tag ^ Value ^ |
| | ''@category'' | Core Class | | | ''@category'' | Core Class | |
| | ''@author'' | M.Noermoehammad | | | ''@author'' | M.Noermoehammad | |
| | ''@license'' | MIT | | | ''@license'' | MIT | |
| | ''@version'' | 1.1 | | | ''@version'' | 1.1 | |
| | ''@since'' | Since Release 1.0 | | | ''@since'' | Since Release 1.0 | |
| |
| ======= Inheritance ======= | ======= Inheritance ======= |
| ======= Constants (4) ======= | ======= Constants (4) ======= |
| |
| ^ Visibility ^ Name ^ Value ^ Line ^ | ^ Visibility ^ Name ^ Value ^ Line ^ |
| | ''-'' | ''METHOD'' | '''AES-256-CBC';'' | 25 | | | ''-'' | ''METHOD'' | '''AES-256-CBC';'' | 25 | |
| | ''-'' | ''ENCRYPTION_KEY_LEN'' | ''32;'' | 26 | | | ''-'' | ''ENCRYPTION_KEY_LEN'' | ''32;'' | 26 | |
| | ''-'' | ''HMAC_KEY_LEN'' | ''32;'' | 27 | | | ''-'' | ''HMAC_KEY_LEN'' | ''32;'' | 27 | |
| | ''-'' | ''TOTAL_KEY_LEN'' | ''64;'' | 28 | | | ''-'' | ''TOTAL_KEY_LEN'' | ''64;'' | 28 | |
| |
| ======= Properties (0) ======= | ======= Properties (0) ======= |
| ======= Methods (18) ======= | ======= Methods (18) ======= |
| |
| ^ Visibility ^ Method ^ Summary ^ Line ^ | ^ Visibility ^ Method ^ Summary ^ Line ^ |
| | public static | ''generateSecretKey()'' | Generate a secure secret key (64 bytes for encryption+HMAC) | 35 | | | public static | ''generateSecretKey()'' | Generate a secure secret key (64 bytes for encryption+HMAC) | 35 | |
| | private static | ''deriveKeys()'' | Derive encryption key and HMAC key from master key | 47 | | | private static | ''deriveKeys()'' | Derive encryption key and HMAC key from master key | 47 | |
| | public static | ''cipherMessage()'' | Encrypt a message using Laminas\Crypt | 82 | | | public static | ''cipherMessage()'' | Encrypt a message using Laminas\Crypt | 82 | |
| | public static | ''decipherMessage()'' | Decrypt a message using Laminas\Crypt | 97 | | | public static | ''decipherMessage()'' | Decrypt a message using Laminas\Crypt | 97 | |
| | public static | ''scriptlogCipher()'' | Encrypt a message using Defuse\Crypto | 112 | | | public static | ''scriptlogCipher()'' | Encrypt a message using Defuse\Crypto | 112 | |
| | public static | ''scriptlogDecipher()'' | Decrypt a message using Defuse\Crypto | 124 | | | public static | ''scriptlogDecipher()'' | Decrypt a message using Defuse\Crypto | 124 | |
| | public static | ''encryptAES()'' | Encrypt data using AES-256-CBC with HMAC authentication | 136 | | | public static | ''encryptAES()'' | Encrypt data using AES-256-CBC with HMAC authentication | 136 | |
| | public static | ''decryptAES()'' | Decrypt data using AES-256-CBC with HMAC authentication | 187 | | | public static | ''decryptAES()'' | Decrypt data using AES-256-CBC with HMAC authentication | 187 | |
| | public static | ''scriptlogCipherKey()'' | Load or generate a Defuse\Crypto key | 262 | | | public static | ''scriptlogCipherKey()'' | Load or generate a Defuse\Crypto key | 262 | |
| | private static | ''updateConfigKeyPath()'' | Update config.php, .env, and database with new key path | 333 | | | private static | ''updateConfigKeyPath()'' | Update config.php, .env, and database with new key path | 333 | |
| | private static | ''updateDatabaseKeyPath()'' | Update defuse_key_path in database settings table | 367 | | | private static | ''updateDatabaseKeyPath()'' | Update defuse_key_path in database settings table | 367 | |
| | private static | ''resolvePath()'' | Resolve a path - returns absolute path as-is, resolves relative from app root | 412 | | | private static | ''resolvePath()'' | Resolve a path - returns absolute path as-is, resolves relative from app root | 412 | |
| | private static | ''getDefuseKeyPath()'' | Get the Defuse key path - checks config, database, then scans default directory… | 427 | | | private static | ''getDefuseKeyPath()'' | Get the Defuse key path - checks config, database, then scans default directory… | 427 | |
| | private static | ''getKeyPathFromDatabase()'' | Get defuse key path from database settings | 474 | | | private static | ''getKeyPathFromDatabase()'' | Get defuse key path from database settings | 474 | |
| | private static | ''generateSecureKey()'' | Generate a new secure key in the default directory | 526 | | | private static | ''generateSecureKey()'' | Generate a new secure key in the default directory | 526 | |
| | private static | ''generateRandomBytes()'' | Generate random bytes securely | 553 | | | private static | ''generateRandomBytes()'' | Generate random bytes securely | 553 | |
| | private static | ''saveKeyToFile()'' | Save encryption key to a file in the given directory | 576 | | | private static | ''saveKeyToFile()'' | Save encryption key to a file in the given directory | 576 | |
| | private static | ''logError()'' | Log encryption errors | 597 | | | private static | ''logError()'' | Log encryption errors | 597 | |
| |
| |
| Derive encryption key and HMAC key from master key | Derive encryption key and HMAC key from master key |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$masterKey'' | ''string'' | //required// | The 64-byte master key | | | ''$masterKey'' | ''string'' | //required// | The 64-byte master key | |
| |
| **Returns:** ''array'' — array Returns ['encryption' => string, 'hmac' => string] | **Returns:** ''array'' — array Returns ['encryption' => string, 'hmac' => string] |
| Encrypt a message using Laminas\Crypt | Encrypt a message using Laminas\Crypt |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$message'' | ''string'' | //required// | //none// | | | ''$message'' | ''string'' | //required// | //none// | |
| | ''$key'' | ''string'' | //required// | //none// | | | ''$key'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Decrypt a message using Laminas\Crypt | Decrypt a message using Laminas\Crypt |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$ciphertext'' | ''string'' | //required// | //none// | | | ''$ciphertext'' | ''string'' | //required// | //none// | |
| | ''$key'' | ''string'' | //required// | //none// | | | ''$key'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''(none declared)'' — string|bool | **Returns:** ''(none declared)'' — string|bool |
| Encrypt a message using Defuse\Crypto | Encrypt a message using Defuse\Crypto |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$message'' | ''string'' | //required// | //none// | | | ''$message'' | ''string'' | //required// | //none// | |
| | ''$key'' | ''Key'' | //required// | //none// | | | ''$key'' | ''Key'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Decrypt a message using Defuse\Crypto | Decrypt a message using Defuse\Crypto |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$ciphertext'' | ''string'' | //required// | //none// | | | ''$ciphertext'' | ''string'' | //required// | //none// | |
| | ''$key'' | ''Key'' | //required// | //none// | | | ''$key'' | ''Key'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Encrypt data using AES-256-CBC with HMAC authentication | Encrypt data using AES-256-CBC with HMAC authentication |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$plaintext'' | ''string'' | //required// | //none// | | | ''$plaintext'' | ''string'' | //required// | //none// | |
| | ''$masterKey'' | ''string'' | //required// | 64-byte master key (or 32-byte for backward compat) | | | ''$masterKey'' | ''string'' | //required// | 64-byte master key (or 32-byte for backward compat) | |
| |
| **Returns:** ''string'' — string Base64 encoded combined ciphertext | **Returns:** ''string'' — string Base64 encoded combined ciphertext |
| Decrypt data using AES-256-CBC with HMAC authentication | Decrypt data using AES-256-CBC with HMAC authentication |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$ciphertextBase64'' | ''string'' | //required// | Base64 encoded combined ciphertext | | | ''$ciphertextBase64'' | ''string'' | //required// | Base64 encoded combined ciphertext | |
| | ''$masterKey'' | ''string'' | //required// | 64-byte master key | | | ''$masterKey'' | ''string'' | //required// | 64-byte master key | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Update config.php, .env, and database with new key path | Update config.php, .env, and database with new key path |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$newKeyPath'' | ''string'' | //required// | Absolute path to the key file | | | ''$newKeyPath'' | ''string'' | //required// | Absolute path to the key file | |
| |
| **Returns:** ''void'' | **Returns:** ''void'' |
| Update defuse_key_path in database settings table | Update defuse_key_path in database settings table |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$newKeyPath'' | ''string'' | //required// | //none// | | | ''$newKeyPath'' | ''string'' | //required// | //none// | |
| | ''$configPath'' | ''string'' | //required// | //none// | | | ''$configPath'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''void'' | **Returns:** ''void'' |
| Resolve a path - returns absolute path as-is, resolves relative from app root | Resolve a path - returns absolute path as-is, resolves relative from app root |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$path'' | ''string'' | //required// | //none// | | | ''$path'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Get defuse key path from database settings | Get defuse key path from database settings |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$configPath'' | ''string'' | //required// | //none// | | | ''$configPath'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''?string'' — string|null | **Returns:** ''?string'' — string|null |
| Generate a new secure key in the default directory | Generate a new secure key in the default directory |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$keyDir'' | ''string'' | //required// | //none// | | | ''$keyDir'' | ''string'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Generate random bytes securely | Generate random bytes securely |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$length'' | ''int'' | //required// | //none// | | | ''$length'' | ''int'' | //required// | //none// | |
| |
| **Returns:** ''string'' — string | **Returns:** ''string'' — string |
| Save encryption key to a file in the given directory | Save encryption key to a file in the given directory |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$keyAscii'' | ''string'' | //required// | ASCII-safe key string | | | ''$keyAscii'' | ''string'' | //required// | ASCII-safe key string | |
| | ''$keyDir'' | ''string'' | //required// | Directory to save the key | | | ''$keyDir'' | ''string'' | //required// | Directory to save the key | |
| |
| **Returns:** ''string'' — string Path to the saved key file | **Returns:** ''string'' — string Path to the saved key file |
| Log encryption errors | Log encryption errors |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$e'' | ''\Throwable'' | //required// | //none// | | | ''$e'' | ''\Throwable'' | //required// | //none// | |
| |
| **Returns:** ''void'' | **Returns:** ''void'' |
| ======= Imports ======= | ======= Imports ======= |
| |
| ^ Alias ^ Fully-qualified name ^ | ^ Alias ^ Fully-qualified name ^ |
| | ''Crypto'' | ''Defuse\Crypto\Crypto'' | | | ''Crypto'' | ''Defuse\Crypto\Crypto'' | |
| | ''BadFormatException'' | ''Defuse\Crypto\Exception\BadFormatException'' | | | ''BadFormatException'' | ''Defuse\Crypto\Exception\BadFormatException'' | |
| | ''Key'' | ''Defuse\Crypto\Key'' | | | ''Key'' | ''Defuse\Crypto\Key'' | |
| | ''BlockCipher'' | ''Laminas\Crypt\BlockCipher'' | | | ''BlockCipher'' | ''Laminas\Crypt\BlockCipher'' | |
| |
| |