mirror of
https://github.com/google/nomulus
synced 2026-02-04 12:02:30 +00:00
Expose the functionality to decrypt given data using keyring
This allows us to provide the keyring a blob of encrypted data and a key name, and have it decrypt it for us. Also fixed javadoc length in Keyring.java. It seems like it was using a 80-character length limit. ------------- Created by MOE: https://github.com/google/moe MOE_MIGRATED_REVID=222995542
This commit is contained in:
@@ -205,13 +205,27 @@ public class KmsKeyring implements Keyring {
|
||||
}
|
||||
|
||||
private byte[] getDecryptedData(String keyName) {
|
||||
KmsSecret secret = getSecret(keyName);
|
||||
String encryptedData = getEncryptedData(keyName);
|
||||
return getDecryptedData(keyName, encryptedData);
|
||||
}
|
||||
|
||||
private byte[] getDecryptedData(KmsSecret secret) {
|
||||
String encryptedData = getEncryptedData(secret);
|
||||
return getDecryptedData(secret, encryptedData);
|
||||
}
|
||||
|
||||
private byte[] getDecryptedData(KmsSecret secret, String encryptedData) {
|
||||
try {
|
||||
return kmsConnection.decrypt(secret.getName(), encryptedData);
|
||||
} catch (Exception e) {
|
||||
throw new KeyringException(
|
||||
String.format("CloudKMS decrypt operation failed for secret %s", keyName), e);
|
||||
String.format("CloudKMS decrypt operation failed for secret %s", secret.getName()), e);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public byte[] getDecryptedData(String keyName, String encryptedData) {
|
||||
KmsSecret secret = getSecret(keyName);
|
||||
return getDecryptedData(secret);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user