1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465 |
- <?php
- /**
- * @copyright Copyright (c) 2016, ownCloud, Inc.
- *
- * @author Lukas Reschke <lukas@statuscode.ch>
- * @author Morris Jobke <hey@morrisjobke.de>
- *
- * @license AGPL-3.0
- *
- * This code is free software: you can redistribute it and/or modify
- * it under the terms of the GNU Affero General Public License, version 3,
- * as published by the Free Software Foundation.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU Affero General Public License for more details.
- *
- * You should have received a copy of the GNU Affero General Public License, version 3,
- * along with this program. If not, see <http://www.gnu.org/licenses/>
- *
- */
- namespace OCP\Security;
- /**
- * Class Crypto provides a high-level encryption layer using AES-CBC. If no key has been provided
- * it will use the secret defined in config.php as key. Additionally the message will be HMAC'd.
- *
- * Usage:
- * $encryptWithDefaultPassword = \OC::$server->getCrypto()->encrypt('EncryptedText');
- * $encryptWithCustomPassword = \OC::$server->getCrypto()->encrypt('EncryptedText', 'password');
- *
- * @package OCP\Security
- * @since 8.0.0
- */
- interface ICrypto {
- /**
- * @param string $message The message to authenticate
- * @param string $password Password to use (defaults to `secret` in config.php)
- * @return string Calculated HMAC
- * @since 8.0.0
- */
- public function calculateHMAC($message, $password = '');
- /**
- * Encrypts a value and adds an HMAC (Encrypt-Then-MAC)
- * @param string $plaintext
- * @param string $password Password to encrypt, if not specified the secret from config.php will be taken
- * @return string Authenticated ciphertext
- * @since 8.0.0
- */
- public function encrypt($plaintext, $password = '');
- /**
- * Decrypts a value and verifies the HMAC (Encrypt-Then-Mac)
- * @param string $authenticatedCiphertext
- * @param string $password Password to encrypt, if not specified the secret from config.php will be taken
- * @return string plaintext
- * @throws \Exception If the HMAC does not match
- * @since 8.0.0
- */
- public function decrypt($authenticatedCiphertext, $password = '');
- }
|