{"_id":"@avila-tek/mongoose-encryption","_rev":"3-5fa21206dfaa7e824e55263b73186ebf","name":"@avila-tek/mongoose-encryption","dist-tags":{"latest":"1.0.1"},"versions":{"0.1.0":{"name":"@avila-tek/mongoose-encryption","version":"0.1.0","license":"MIT","_id":"@avila-tek/mongoose-encryption@0.1.0","maintainers":[{"name":"avilatek-devops","email":"devops@avilatek.com"},{"name":"zoomelectrico","email":"jose.quevedo2011@gmail.com"},{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},{"name":"santiagofv36","email":"santiagofigueroavasquez@gmail.com"}],"dist":{"shasum":"fe3a7b05d5aa0ec56c917dc1513a51c8dfaa60fb","tarball":"https://registry.npmjs.org/@avila-tek/mongoose-encryption/-/mongoose-encryption-0.1.0.tgz","fileCount":12,"integrity":"sha512-ahyNykD3WPZuSGBr1GYZqy8qWqdp2YLJbBvb25cUzVgr37flfCvOrSywA3K5UrNYIMLSqN6ql5FcjNtAxdk4Zw==","signatures":[{"sig":"MEYCIQCHx5b69TydBnUPONdueKX/VrkGyzkWVJyoFPxYAffoyAIhAKziUv0hodLOSJUDR15ZREPBcitMrw+aZ5laEniOXs0V","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15101},"main":"./src/index.ts","type":"commonjs","gitHead":"541128c2cf4a823a2b340911898d0b722a6eae4a","scripts":{"test":"jest"},"_npmUser":{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},"_npmVersion":"11.6.1","directories":{},"_nodeVersion":"24.11.0","_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","jest":"^30.2.0","dotenv":"^17.2.3","ts-jest":"^29.4.5","ts-node":"^10.9.2","typescript":"^5.9.3","@types/jest":"^30.0.0","@types/node":"^24.10.0","@jest/globals":"^30.2.0","mongodb-memory-server":"^10.3.0"},"peerDependencies":{"mongoose":"^8.19.3"},"_npmOperationalInternal":{"tmp":"tmp/mongoose-encryption_0.1.0_1762872904329_0.7694588246088425","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@avila-tek/mongoose-encryption","version":"1.0.0","license":"MIT","_id":"@avila-tek/mongoose-encryption@1.0.0","maintainers":[{"name":"avilatek-devops","email":"devops@avilatek.com"},{"name":"zoomelectrico","email":"jose.quevedo2011@gmail.com"},{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},{"name":"santiagofv36","email":"santiagofigueroavasquez@gmail.com"}],"bin":{"encrypt":"dist/scripts/cli.js"},"dist":{"shasum":"ef148d3e17c552e2300b82e2b4398541a174155b","tarball":"https://registry.npmjs.org/@avila-tek/mongoose-encryption/-/mongoose-encryption-1.0.0.tgz","fileCount":47,"integrity":"sha512-4JUo4jje4Tv+qY6zlDbeL2vJT3Ph+tdsELxGk/KZ6i1djPHOKtPoM94A9PycKhKH0ISf64/3JIAVClldKtkOow==","signatures":[{"sig":"MEUCIQDnBac3FPRGh++o2PgQ65ZJb4ACMOwp4QrH2IY6af9AMgIgS+STl/9upucsTGHevpke8V9nmMWXNe71rTp9natcZIU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":121947},"main":"./src/index.ts","type":"commonjs","gitHead":"4516743035edf95cf59a7f6cc28a863665bcd452","scripts":{"test":"jest","build":"tsup"},"_npmUser":{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},"_npmVersion":"11.6.1","description":"Security is a main brach in all of our projects, but it can be painfully difficult to implement some times. There are so many things to consider, and so many things that can go wrong in every step. Sometimes this can lead to avoidance and unnecessary prob","directories":{},"_nodeVersion":"24.11.0","dependencies":{"commander":"^14.0.2","@inquirer/prompts":"^8.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","jest":"^30.2.0","tsup":"^8.5.0","dotenv":"^17.2.3","ts-jest":"^29.4.5","ts-node":"^10.9.2","typescript":"^5.9.3","@types/jest":"^30.0.0","@types/node":"^24.10.0","@jest/globals":"^30.2.0","mongodb-memory-server":"^10.3.0"},"peerDependencies":{"mongoose":"^8.19.3"},"_npmOperationalInternal":{"tmp":"tmp/mongoose-encryption_1.0.0_1763491705123_0.029217690063797264","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@avila-tek/mongoose-encryption","version":"1.0.1","type":"commonjs","license":"MIT","main":"./dist/index.js","scripts":{"test":"jest","build":"tsup"},"bin":{"encrypt":"dist/scripts/cli.js"},"devDependencies":{"@jest/globals":"^30.2.0","@types/jest":"^30.0.0","@types/node":"^24.10.0","dotenv":"^17.2.3","jest":"^30.2.0","mongodb-memory-server":"^10.3.0","ts-jest":"^29.4.5","ts-node":"^10.9.2","tsup":"^8.5.0","tsx":"^4.20.6","typescript":"^5.9.3"},"peerDependencies":{"mongoose":"^8.19.3"},"dependencies":{"@inquirer/prompts":"^8.0.1","commander":"^14.0.2"},"gitHead":"4b7eba79a0013773f597a0b5ab8bc458796cf144","_id":"@avila-tek/mongoose-encryption@1.0.1","description":"Security is a main brach in all of our projects, but it can be painfully difficult to implement some times. There are so many things to consider, and so many things that can go wrong in every step. Sometimes this can lead to avoidance and unnecessary prob","_nodeVersion":"24.11.0","_npmVersion":"11.6.1","dist":{"integrity":"sha512-y34Hi90mTEs9YW2A7/tmDJ3u/1r26QBoVzrUN06gnS+l0a64BxBE97XAlRx0vp2AM9Zo2dE0ePYY5/obEA7kTA==","shasum":"3d36ee1152d4fc6d891d78debda1f7f99eda2edd","tarball":"https://registry.npmjs.org/@avila-tek/mongoose-encryption/-/mongoose-encryption-1.0.1.tgz","fileCount":47,"unpackedSize":121936,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC8RflA3lIheUYRoeJeAhSgnYxSdsCwwqTNCbKz4Mt3AQIgHnnhAtwFHdxiX4P5kqIs2/pPBUC32fCLVi29HVbkn1Y="}]},"_npmUser":{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},"directories":{},"maintainers":[{"name":"avilatek-devops","email":"devops@avilatek.com"},{"name":"zoomelectrico","email":"jose.quevedo2011@gmail.com"},{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},{"name":"santiagofv36","email":"santiagofigueroavasquez@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mongoose-encryption_1.0.1_1764614637265_0.5756650597181636"},"_hasShrinkwrap":false}},"time":{"created":"2025-11-11T14:55:04.216Z","modified":"2025-12-01T18:43:57.707Z","0.1.0":"2025-11-11T14:55:04.498Z","1.0.0":"2025-11-18T18:48:25.324Z","1.0.1":"2025-12-01T18:43:57.435Z"},"license":"MIT","description":"Security is a main brach in all of our projects, but it can be painfully difficult to implement some times. There are so many things to consider, and so many things that can go wrong in every step. Sometimes this can lead to avoidance and unnecessary prob","maintainers":[{"name":"avilatek-devops","email":"devops@avilatek.com"},{"name":"zoomelectrico","email":"jose.quevedo2011@gmail.com"},{"name":"manuelmendoza","email":"manuelmendozalmeid@gmail.com"},{"name":"santiagofv36","email":"santiagofigueroavasquez@gmail.com"}],"readme":"## Security ASAP (Security As Simple As Possible)\n\nSecurity is a main brach in all of our projects, but it can be painfully difficult to implement some times. There are so many things to consider, and so many things that can go wrong in every step. Sometimes this can lead to avoidance and unnecessary problems.\n\nThis library is our way of contributing to this problem in the mongoose ecosystem, facilitating field encryption through schema definitions and easy setups.\n\n## Getting started\n\n### Installation\n\nYou can add our library to your project by doing any of this commands:\n\n**NPM**\n\n```bash\nnpm install @avila-tek/mongoose-encryption\n```\n\n**Yarn**\n\n```bash\nyarn add @avila-tek/mongoose-encryption\n```\n\n### Integration\n\nLet's assume you have `User` model, and you just found out some fields are recommended to be encrypted as the PIIs they happen to be. With our library, the problem is solved in just a couple of lines!\n\n```ts\nimport mongoose from 'mongoose';\nimport encryptionPlugin from '@avila-tek/mongoose-encryption';\n\nconst userSchema = new mongoose.Schema({\n  firstName: String,\n  lastName: String,\n  dni: {\n    number: String,\n  },\n  phones: [\n    {\n      number: String,\n      label: String,\n    },\n  ],\n  secretValues: [String],\n});\n\nuserSchema.plugin(encryptionPlugin, {\n  key: '<secret key>',\n  algorithm: 'aes-256-gcm',\n  fields: [\n    'firstName',\n    'lastName',\n    'dni.number',\n    'phones.number',\n    'secretValues',\n  ],\n  collectionName: 'users',\n});\n\nconst User = mongoose.model('User', userSchema);\n```\n\n#### Fields\n\nFields input allows many use cases:\n\n- Simple fields (`firstName`)\n- Nested fields (`dni.number`)\n- Array nested fields (`phones.number`)\n- Array fields (`secretValues`)\n\n#### Algorithms\n\nThese are the accepted algorithms at the moment, but we will continue to expand this list further:\n\n- AES-256-GCM: `aes-256-gcm`\n- AES-128-GCM: `aes-128-gcm`\n- ChaCha20-Poly1305: `chacha20-poly1305`\n\n#### Collection Name\n\nNon-deterministic algorithms help us keep our data even more encrypted. By adding extra fields to the process, we can ensure different results even when the input value is the same. We selected this few extra fields:\n\n- Record ID: The MongoID of the document being handled.\n- Field Name: The field being encrypted.\n- Collection Name: The collection where the document is located.\n\nThe latter is the one you will be providing in the setup. As soon as the first document is encrypted with this value, it cannot be changed. We know this is not great, so we are working on it.\n\n#### The key\n\nLast but not least, the secret key must be in **Base64** and it has to match the intended algorithm:\n\n- AES-256-GCM: 256 bit key (32 bytes)\n- AES-128-GCM: 128 bit key (16 bytes)\n- ChaCha20-Poly1305: 256 bit key (32 bytes)\n\nYou can easily create these fields by running one OpenSSL command:\n\n**256 bit key (32 bytes)**\n\n```bash\nopenssl base64 rand 32\n```\n\n**128 bit key (16 bytes)**\n\n```bash\nopenssl base64 rand 16\n```\n\n### Legacy collections\n\nFor preexisting collections with unencrypted data, the process of adding this library can seem like a big problem, specially for production environments. That's why we added a CLI tool to help developers process their data in a secure way.\n\nBy running the next command, you can interact with your database, collections and specifications very easily:\n\n```bash\nnpx encrypt init\n```\n\nYou can add some flags to the command so things are even faster, but the tool will ask you for any missing information.\n\n| Flag           | Type   | Description                                                                          |\n| -------------- | ------ | ------------------------------------------------------------------------------------ |\n| `--uri`        | string | MongoDB connection URI to the target database.                                       |\n| `--collection` | string | Collection name where documents should be encrypted.                                 |\n| `--fields`     | string | Comma-separated list of fields to encrypt (supports nested paths like `dni.number`). |\n| `--key`        | string | Encryption key used to encrypt/decrypt data. Keep this value secure.                 |\n| `--algorithm`  | string | Encryption algorithm to use (`aes-256-gcm`, `aes-128-gcm`, or `chacha20-poly1305`).  |\n\nThe CLI will take care of the rest and your data will be encrypted right away. Improvements for this feature will be added on to make it more secure, so please use this with caution for now.\n","readmeFilename":"README.md"}