Repository navigation
Conversation
EncrypterInterface (string in, string out) with an XChaCha20-Poly1305 implementation. Payloads are base64url of a version byte, a random 24 byte nonce and the ciphertext with tag; the version is bound as additional data. Cipher keys are derived with HKDF-SHA256 from configured keys of at least 16 bytes. Keys come from security.encryption_key, a key or a list: the first key encrypts, later keys only decrypt. An empty first entry throws instead of promoting an old key. Cubex registers a lazy EncrypterInterface factory reading the context config. Sodium is suggested (ext-sodium or paragonie/sodium_compat) and checked when an encrypter is constructed. Co-Authored-By: Claude Opus 5.5 <[email protected]>
TomK
force-pushed
the
encryption-sodium
branch
from
September 29, 2026 09:24
7b542a5 to
c0daa4a
Compare
The Windows PHP builds from setup-php do not load sodium by default. Also move actions/checkout to its latest major, v7. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Contributor
Author
|
Superseded by packaged/http#9, which adds the encrypter along with an encrypted cookie handler, so v4 apps get it through packaged/http's CookieJar. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cubex 4 has no encryption primitive, so apps bring their own and have no built-in way to rotate a key. This adds the same design as the 2.x line (#73) in v4 style.
Cubex\Encryption\EncrypterimplementsEncrypterInterface(string in, string out) with XChaCha20-Poly1305. A payload is base64url of a version byte, a random 24-byte nonce and the ciphertext with its tag. The version byte is bound as additional data. The cipher key is derived with HKDF-SHA256 from each configured key, which must be at least 16 bytes.security.encryption_keyis a key or a list. The first key encrypts; later keys only decrypt. An empty first entry throws, so an unset env var can't promote an old key.Encrypter::fromConfig($config)builds one from config.Cubexregisters a lazyEncrypterInterfacefactory that reads the context config, so nothing runs until an encrypter is retrieved.ext-sodiumorparagonie/sodium_compatis listed undersuggestand checked only when an encrypter is constructed. There is no fallback algorithm.ext-sodiumexplicitly, because the Windows PHP builds from setup-php don't load it by default.actions/checkoutalso moves to its latest major, v7.Previous keys are normally compromised, so payloads they decrypt may be forged. Keep the rotation window short.
Test plan
EncrypterTestcovers:Results:
coverage-checkreports 75.34% against a threshold of 70.Encrypterhas 100% coverage.masterat c56e8db without this change has 133 passing tests.EncrypterTestthrew the missing-sodium error. With it enabled, all six jobs (Ubuntu and Windows, PHP 8.2 to 8.4) pass.Rollout
Release 4.28.0 from
masterwithgh release create.🤖 Generated with Claude Code