Crypto Lib
    Preparing search index...

    Class SecureBuffer

    A buffer that zeros its contents on destroy().

    Use this for holding sensitive key material in memory. Call destroy() when the key is no longer needed to minimize the window during which key bytes are accessible in the process address space.

    Note: JavaScript's garbage collector may copy the underlying ArrayBuffer during compaction, so this is a best-effort mitigation, not a guarantee.

    import { SecureBuffer } from "@sebastienrousseau/crypto-lib";

    const key = new SecureBuffer(randomBytes(32));
    doSomething(key.expose());
    key.destroy();
    Index
    • Create a new SecureBuffer from raw bytes or a hex string.

      Parameters

      • data: string | Uint8Array<ArrayBufferLike>

        The key material as a Uint8Array or hex-encoded string.

      Returns SecureBuffer

      const buf = new SecureBuffer("abcdef0123456789".repeat(4));
      
    • get length(): number

      Number of bytes in the buffer.

      Returns number

    • get isDestroyed(): boolean

      Whether the buffer has been destroyed.

      Returns boolean

    • Get the raw bytes.

      Returns Uint8Array

      The underlying Uint8Array.

      If the buffer has already been destroyed.

      const buf = new SecureBuffer(new Uint8Array([1, 2, 3]));
      buf.expose(); // Uint8Array([1, 2, 3])
    • Get hex-encoded string.

      Returns string

      The buffer contents as a lowercase hex string.

      If the buffer has already been destroyed.

      const buf = new SecureBuffer(new Uint8Array([0xab, 0xcd]));
      buf.toHex(); // "abcd"
    • Zero the buffer and mark as destroyed.

      After calling this method, any subsequent calls to expose() or toHex() will throw a CryptoError.

      Returns void

      const buf = new SecureBuffer(new Uint8Array(32));
      buf.destroy();
      buf.isDestroyed; // true