Skip to content

Latest commit

History

70 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Build Status

W3C XML Encryption implementation for node.js (http://www.w3.org/TR/xmlenc-core/)

Usage

npm install xml-encryption

encrypt

varxmlenc=require('xmlenc');varoptions={rsa_pub: fs.readFileSync(__dirname+'/your_rsa.pub'),pem: fs.readFileSync(__dirname+'/your_public_cert.pem'),encryptionAlgorithm: 'http://www.w3.org/2001/04/xmlenc#aes256-cbc',keyEncryptionAlgorighm: 'http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p'};xmlenc.encrypt('content to encrypt',options,function(err,result){console.log(result);}

Result:

<xenc:EncryptedDataType="http://www.w3.org/2001/04/xmlenc#Element"xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:EncryptionMethodAlgorithm="http://www.w3.org/2001/04/xmlenc#aes-256-cbc" />
<KeyInfoxmlns="http://www.w3.org/2000/09/xmldsig#">
<e:EncryptedKeyxmlns:e="http://www.w3.org/2001/04/xmlenc#">
<e:EncryptionMethodAlgorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">
<DigestMethodAlgorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
</e:EncryptionMethod>
<KeyInfo>
<X509Data><X509Certificate>MIIEDzCCAveg... base64 cert... q3uaLvlAUo=</X509Certificate></X509Data>
</KeyInfo>
<e:CipherData>
<e:CipherValue>sGH0hhzkjmLWYYY0gyQMampDM... encrypted symmetric key ...gewHMbtZafk1MHh9A==</e:CipherValue>
</e:CipherData>
</e:EncryptedKey>
</KeyInfo>
<xenc:CipherData>
<xenc:CipherValue>V3Vb1vDl055Lp92zvK..... encrypted content.... kNzP6xTu7/L9EMAeU</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedData>

decrypt

varoptions={key: fs.readFileSync(__dirname+'/your_private_key.key'),};xmlenc.decrypt('<xenc:EncryptedData ..... </xenc:EncryptedData>',options,function(err,result){console.log(result);}// resultdecryptedcontent

Supported algorithms

Currently the library supports:

However, you can fork and implement your own algorithm. The code supports adding more algorithms easily

Issue Reporting

If you have found a bug or if you have a feature request, please report them at this repository issues section. Please do not report security vulnerabilities on the public GitHub issue tracker. The Responsible Disclosure Program details the procedure for disclosing security issues.

Author

Auth0

License

This project is licensed under the MIT license. See the LICENSE file for more info.

About

W3C XML Encryption implementation for node.js (http://www.w3.org/TR/xmlenc-core/)

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages