Scriptlog Docs

Scriptlog Documentation

Code reference for the Scriptlog codebase

User Tools

Site Tools


scriptlog:lib:core:scriptlogcryptonize

ScriptlogCryptonize

Layer: Core · Source: lib/core/ScriptlogCryptonize.php:23 (lines 23–608)


class ScriptlogCryptonize

Docblock Metadata

Tag Value
@category Core Class
@author M.Noermoehammad
@license MIT
@version 1.1
@since Since Release 1.0

Inheritance

No parent, interface or trait. This is a root type.

Constants (4)

Visibility Name Value Line
- METHOD 'AES-256-CBC'; 25
- ENCRYPTION_KEY_LEN 32; 26
- HMAC_KEY_LEN 32; 27
- TOTAL_KEY_LEN 64; 28

Properties (0)

None declared.

Methods (18)

Visibility Method Summary Line
public static generateSecretKey() Generate a secure secret key (64 bytes for encryption+HMAC) 35
private static deriveKeys() Derive encryption key and HMAC key from master key 47
public static cipherMessage() Encrypt a message using Laminas\Crypt 82
public static decipherMessage() Decrypt a message using Laminas\Crypt 97
public static scriptlogCipher() Encrypt a message using Defuse\Crypto 112
public static scriptlogDecipher() Decrypt a message using Defuse\Crypto 124
public static encryptAES() Encrypt data using AES-256-CBC with HMAC authentication 136
public static decryptAES() Decrypt data using AES-256-CBC with HMAC authentication 187
public static scriptlogCipherKey() Load or generate a Defuse\Crypto key 262
private static updateConfigKeyPath() Update config.php, .env, and database with new key path 333
private static updateDatabaseKeyPath() Update defuse_key_path in database settings table 367
private static resolvePath() Resolve a path - returns absolute path as-is, resolves relative from app root 412
private static getDefuseKeyPath() Get the Defuse key path - checks config, database, then scans default directory… 427
private static getKeyPathFromDatabase() Get defuse key path from database settings 474
private static generateSecureKey() Generate a new secure key in the default directory 526
private static generateRandomBytes() Generate random bytes securely 553
private static saveKeyToFile() Save encryption key to a file in the given directory 576
private static logError() Log encryption errors 597

generateSecretKey()

public static function generateSecretKey(): string

lines 35–38 (4)

Generate a secure secret key (64 bytes for encryption+HMAC)

Takes no parameters.

Returns: string — string

deriveKeys()

private static function deriveKeys(string $masterKey): array

lines 47–73 (27)

Derive encryption key and HMAC key from master key

Parameter Type Default Description
$masterKey string required The 64-byte master key

Returns: array — array Returns ['encryption' ⇒ string, 'hmac' ⇒ string]

Throws: ''ScriptlogCryptonizeException''

cipherMessage()

public static function cipherMessage(string $message, string $key): string

lines 82–88 (7)

Encrypt a message using Laminas\Crypt

Parameter Type Default Description
$message string required none
$key string required none

Returns: string — string

decipherMessage()

public static function decipherMessage(string $ciphertext, string $key)

lines 97–103 (7)

Decrypt a message using Laminas\Crypt

Parameter Type Default Description
$ciphertext string required none
$key string required none

Returns: (none declared) — string|bool

scriptlogCipher()

public static function scriptlogCipher(string $message, Key $key): string

lines 112–115 (4)

Encrypt a message using Defuse\Crypto

Parameter Type Default Description
$message string required none
$key Key required none

Returns: string — string

scriptlogDecipher()

public static function scriptlogDecipher(string $ciphertext, Key $key): string

lines 124–127 (4)

Decrypt a message using Defuse\Crypto

Parameter Type Default Description
$ciphertext string required none
$key Key required none

Returns: string — string

encryptAES()

public static function encryptAES(string $plaintext, string $masterKey): string

lines 136–177 (42)

Encrypt data using AES-256-CBC with HMAC authentication

Parameter Type Default Description
$plaintext string required none
$masterKey string required 64-byte master key (or 32-byte for backward compat)

Returns: string — string Base64 encoded combined ciphertext

decryptAES()

public static function decryptAES(string $ciphertextBase64, string $masterKey): string

lines 187–255 (69)

Decrypt data using AES-256-CBC with HMAC authentication

Parameter Type Default Description
$ciphertextBase64 string required Base64 encoded combined ciphertext
$masterKey string required 64-byte master key

Returns: string — string

Throws: ''ScriptlogCryptonizeException''

scriptlogCipherKey()

public static function scriptlogCipherKey(): Key

lines 262–326 (65)

Load or generate a Defuse\Crypto key

Takes no parameters.

Returns: Key — Key

updateConfigKeyPath()

private static function updateConfigKeyPath(string $newKeyPath): void

lines 333–359 (27)

Update config.php, .env, and database with new key path

Parameter Type Default Description
$newKeyPath string required Absolute path to the key file

Returns: void

updateDatabaseKeyPath()

private static function updateDatabaseKeyPath(string $newKeyPath, string $configPath): void

lines 367–404 (38)

Update defuse_key_path in database settings table

Parameter Type Default Description
$newKeyPath string required none
$configPath string required none

Returns: void

resolvePath()

private static function resolvePath(string $path): string

lines 412–420 (9)

Resolve a path - returns absolute path as-is, resolves relative from app root

Parameter Type Default Description
$path string required none

Returns: string — string

getDefuseKeyPath()

private static function getDefuseKeyPath(): string

lines 427–466 (40)

Get the Defuse key path - checks config, database, then scans default directory for existing keys

Takes no parameters.

Returns: string — string

getKeyPathFromDatabase()

private static function getKeyPathFromDatabase(string $configPath): ?string

lines 474–518 (45)

Get defuse key path from database settings

Parameter Type Default Description
$configPath string required none

Returns: ?string — string|null

generateSecureKey()

private static function generateSecureKey(string $keyDir): string

lines 526–544 (19)

Generate a new secure key in the default directory

Parameter Type Default Description
$keyDir string required none

Returns: string — string

generateRandomBytes()

private static function generateRandomBytes(int $length): string

lines 553–567 (15)

Generate random bytes securely

Parameter Type Default Description
$length int required none

Returns: string — string

Throws: \RuntimeException

saveKeyToFile()

private static function saveKeyToFile(string $keyAscii, string $keyDir): string

lines 576–590 (15)

Save encryption key to a file in the given directory

Parameter Type Default Description
$keyAscii string required ASCII-safe key string
$keyDir string required Directory to save the key

Returns: string — string Path to the saved key file

logError()

private static function logError(\Throwable $e): void

lines 597–607 (11)

Log encryption errors

Parameter Type Default Description
$e \Throwable required none

Returns: void

Imports

Alias Fully-qualified name
Crypto Defuse\Crypto\Crypto
BadFormatException Defuse\Crypto\Exception\BadFormatException
Key Defuse\Crypto\Key
BlockCipher Laminas\Crypt\BlockCipher

This page is generated from source by 'tools/gendoc'. Edits will be overwritten.

scriptlog/lib/core/scriptlogcryptonize.txt · Last modified: by admin