@plinthjs/encryption
v0.1.0
Published
Mason encryption + hashing over node:crypto (the Illuminate Encryption/Hashing equivalent).
Maintainers
Readme
@plinthjs/encryption
Authenticated encryption and password hashing for Mason, built on Node's node:crypto — no
native dependencies. The Illuminate\Encryption + Illuminate\Hashing equivalent.
Encryption
Encrypter uses AES-256-GCM with a random 12-byte IV and a verified authentication tag.
import { Encrypter } from '@plinthjs/encryption'
// A 32-byte key, raw or `base64:<...>` (the Laravel APP_KEY convention).
const key = Encrypter.generateKeyBase64()
const cipher = new Encrypter(key)
const payload = cipher.encrypt({ userId: 42, admin: true })
const data = cipher.decrypt<{ userId: number; admin: boolean }>(payload)
// Raw strings (no JSON round-trip):
const token = cipher.encryptString('s3cret')
cipher.decryptString(token) // 's3cret'A tampered payload or a wrong key throws DecryptionError; a wrong-length key throws
InvalidKeyError.
Hashing
Hasher uses scrypt, a memory-hard KDF built into node:crypto. (Laravel defaults to bcrypt /
argon2, both native deps; scrypt is the dependency-free port substitute.) Hashes are
self-describing: scrypt$<N>$<r>$<p>$<saltB64>$<hashB64>.
import { Hasher } from '@plinthjs/encryption'
const hasher = new Hasher()
const hash = hasher.make('correct horse battery staple')
hasher.check('correct horse battery staple', hash) // true
hasher.check('wrong', hash) // false
// Tune cost and detect stale hashes:
hasher.needsRehash(hash, { cost: 32768 }) // trueVerification uses crypto.timingSafeEqual for constant-time comparison.
