Skip to content

add encryption - #47

Merged
wsargent merged 11 commits into
mainfrom
add-encryption
Jan 8, 2026
Merged

wsargent merged 11 commits into
mainfrom
add-encryption

Conversation

@wsargent

@wsargent wsargent commented Jan 8, 2026

Copy link
Copy Markdown
Contributor
  • Add design document for encryption feature
  • feat: create blacklite-codec-encryption module structure
  • feat: add EncryptionException with factory methods
  • feat: add SymmetricEncryption strategy interface
  • feat: implement AES-GCM-256 encryption with IV and authentication
  • feat: add EncryptionMetadata model
  • feat: add EncryptionMetadataRepository for SQLite storage
  • feat: add RSA-OAEP key wrapping for symmetric keys
  • feat: add EncryptionKeyStore for key lifecycle management
  • feat: implement EncryptionCodec with codec wrapper pattern
  • fix: add defensive copying for EncryptionMetadata byte array

wsargent and others added 11 commits January 1, 2026 14:53
- Per-database AES-GCM-256 encryption via codec wrapper pattern
- Optional public key wrapping (RSA-OAEP) for symmetric keys
- Transparent integration with ZStandard dictionary compression
- Private key provider chain (API > env var > config > system property)
- Fail-fast metadata validation on database open
- Archive databases inherit encryption metadata
- Reader tool support with clear error messages
- Zero external dependencies (Java 8 standard library only)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Clone encryptedKey array in constructor to prevent external mutation
- Clone encryptedKey array in getter to prevent caller mutation
- Add test to verify defensive copying works correctly

This prevents potential security issues where key material could be
accidentally modified after construction or retrieval.
@wsargent
wsargent merged commit 9a0b113 into main Jan 8, 2026
2 checks passed
@wsargent
wsargent deleted the add-encryption branch January 8, 2026 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant