Documentation

EncryptionAdapter extends IndirectAdapter
in package
implements FilesystemAdapter, PublicUrlGenerator

Read onlyYes
FinalYes

Encrypts every file with XChaCha20-Poly1305 before it is handed to the underlying adapter and decrypts it again when it is read back.

Stored files use the following body format:

[version:1 byte][nonce:24 bytes][ciphertext + tag]

The additional authenticated data is path independent, which means files keep their ciphertext when they are moved or copied.

Table of Contents

Interfaces

FilesystemAdapter
PublicUrlGenerator

Constants

HEADER_SIZE  : int = self::PREFIX_SIZE + SODIUM_CRYPTO_AEAD_XCHACHA2...
Total number of bytes a stored file is larger than its plaintext: the version, the nonce and the Poly1305 tag that is appended to the ciphertext.
VERSION  : int = 1
ADDITIONAL_DATA  : string = 'collecthor/flysystem-adapters/encryption'
Fixed additional authenticated data. It is intentionally not derived from the path so that moving or copying an encrypted file does not invalidate it.
PREFIX_SIZE  : int = 1 + SODIUM_CRYPTO_AEAD_XCHACHA20POLY1305_IETF_N...
One byte for the version and 24 bytes for the nonce, preceding the ciphertext.

Properties

$base  : FilesystemAdapter
$key  : string

Methods

__construct()  : mixed
copy()  : void
createDirectory()  : void
delete()  : void
deleteDirectory()  : void
directoryExists()  : bool
fileExists()  : bool
fileSize()  : FileAttributes
The underlying adapter reports the size of the ciphertext. Since the header has a fixed size it is subtracted so that the reported size matches the original contents.
lastModified()  : FileAttributes
listContents()  : iterable<string|int, StorageAttributes>
mimeType()  : FileAttributes
move()  : void
publicUrl()  : string
read()  : string
readStream()  : resource
setVisibility()  : void
visibility()  : FileAttributes
write()  : void
writeStream()  : void
getAdapter()  : FilesystemAdapter
preparePath()  : string
decrypt()  : string
encrypt()  : string
readAll()  : string
stringToStream()  : resource
stripHeader()  : FileAttributes

Constants

HEADER_SIZE

Total number of bytes a stored file is larger than its plaintext: the version, the nonce and the Poly1305 tag that is appended to the ciphertext.

public int HEADER_SIZE = self::PREFIX_SIZE + SODIUM_CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES

ADDITIONAL_DATA

Fixed additional authenticated data. It is intentionally not derived from the path so that moving or copying an encrypted file does not invalidate it.

private string ADDITIONAL_DATA = 'collecthor/flysystem-adapters/encryption'

PREFIX_SIZE

One byte for the version and 24 bytes for the nonce, preceding the ciphertext.

private int PREFIX_SIZE = 1 + SODIUM_CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES

Properties

Methods

__construct()

public __construct(FilesystemAdapter $base, string $key) : mixed
Parameters
$base : FilesystemAdapter
$key : string

copy()

public copy(string $source, string $destination, Config $config) : void
Parameters
$source : string
$destination : string
$config : Config

createDirectory()

public createDirectory(string $path, Config $config) : void
Parameters
$path : string
$config : Config

deleteDirectory()

public deleteDirectory(string $path) : void
Parameters
$path : string

directoryExists()

public directoryExists(string $path) : bool
Parameters
$path : string
Return values
bool

fileExists()

public fileExists(string $path) : bool
Parameters
$path : string
Return values
bool

fileSize()

The underlying adapter reports the size of the ciphertext. Since the header has a fixed size it is subtracted so that the reported size matches the original contents.

public fileSize(string $path) : FileAttributes
Parameters
$path : string
Return values
FileAttributes

lastModified()

public lastModified(string $path) : FileAttributes
Parameters
$path : string
Return values
FileAttributes

listContents()

public listContents(string $path, bool $deep) : iterable<string|int, StorageAttributes>
Parameters
$path : string
$deep : bool
Return values
iterable<string|int, StorageAttributes>

mimeType()

public mimeType(string $path) : FileAttributes
Parameters
$path : string
Return values
FileAttributes

move()

public move(string $source, string $destination, Config $config) : void
Parameters
$source : string
$destination : string
$config : Config

publicUrl()

public publicUrl(string $path, Config $config) : string
Parameters
$path : string
$config : Config
Return values
string

read()

public read(string $path) : string
Parameters
$path : string
Return values
string

readStream()

public readStream(string $path) : resource
Parameters
$path : string
Return values
resource

setVisibility()

public setVisibility(string $path, string $visibility) : void
Parameters
$path : string
$visibility : string

visibility()

public visibility(string $path) : FileAttributes
Parameters
$path : string
Return values
FileAttributes

write()

public write(string $path, string $contents, Config $config) : void
Parameters
$path : string
$contents : string
$config : Config

writeStream()

public writeStream(string $path, resource $contents, Config $config) : void
Parameters
$path : string
$contents : resource
$config : Config

getAdapter()

protected getAdapter(string $rawPath, string $preparedPath) : FilesystemAdapter
Parameters
$rawPath : string
$preparedPath : string
Return values
FilesystemAdapter

preparePath()

protected preparePath(string $path) : string
Parameters
$path : string
Return values
string

decrypt()

private decrypt(string $path, string $payload) : string
Parameters
$path : string
$payload : string
Return values
string

encrypt()

private encrypt(string $plaintext) : string
Parameters
$plaintext : string
Return values
string

readAll()

private static readAll(resource $stream) : string
Parameters
$stream : resource
Return values
string

stringToStream()

private static stringToStream(string $contents) : resource
Parameters
$contents : string
Return values
resource

stripHeader()

private static stripHeader(FileAttributes $attributes) : FileAttributes
Parameters
$attributes : FileAttributes
Return values
FileAttributes
On this page

Search results