createAes256GcmSensitiveValueProtector — @gj-kit/toss-payments-postgresql
@gj-kit/toss-payments-postgresql에서 공개하는 function입니다. package version 0.5.1의 release declaration을 그대로 표시합니다.
검증된 import 예제
섹션 제목: “검증된 import 예제”import { createAes256GcmSensitiveValueProtector } from '@gj-kit/toss-payments-postgresql';시그니처, 매개변수, 반환 타입
섹션 제목: “시그니처, 매개변수, 반환 타입”/** * Builds a `SensitiveValueProtector` that seals values with AES-256-GCM, a fresh random * 12-byte IV per `encrypt`, and the seam context bound as AAD. * * The host keeps key custody and rotation: this function never generates, persists, or * rotates keys. Because the IV is random, NIST SP 800-38D §8.3 caps a single key at 2^32 * `encrypt` invocations — rotate to a new `keyId` well before that; the library does not * count. Key/config misuse throws `TypeError` synchronously at construction; `encrypt` * rejects with `TypeError` for non-string or ill-formed UTF-16 plaintext (lone surrogates * would otherwise be silently replaced with U+FFFD and fail to round-trip); undecryptable * rows reject with `SensitiveValueProtectorError` (`code` is the contract). */declare function createAes256GcmSensitiveValueProtector(options: Aes256GcmSensitiveValueProtectorOptions): SensitiveValueProtector;이 선언은 매개변수, optionality, 제네릭, 반환값, 공개 union/type 계약의 정본입니다. 호출 전 필요한 환경·권한·오류 경계는 패키지 Golden path와 이 subpath의 import 조건을 함께 확인하세요.
Release context
섹션 제목: “Release context”- 패키지:
@gj-kit/toss-payments-postgresql - 버전:
0.5.1 - 공개 entry:
. - 소스: GitHub
구현 주석
섹션 제목: “구현 주석”Builds a SensitiveValueProtector that seals values with AES-256-GCM, a fresh random
12-byte IV per encrypt, and the seam context bound as AAD.
The host keeps key custody and rotation: this function never generates, persists, or
rotates keys. Because the IV is random, NIST SP 800-38D §8.3 caps a single key at 2^32
encrypt invocations — rotate to a new keyId well before that; the library does not
count. Key/config misuse throws TypeError synchronously at construction; encrypt
rejects with TypeError for non-string or ill-formed UTF-16 plaintext (lone surrogates
would otherwise be silently replaced with U+FFFD and fail to round-trip); undecryptable
rows reject with SensitiveValueProtectorError (code is the contract).