{"_id":"@dcsv-io/d2-encryption-abstractions","_rev":"2-66a4e1e583758bf06bd1bc75a22a75c6","name":"@dcsv-io/d2-encryption-abstractions","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.1":{"name":"@dcsv-io/d2-encryption-abstractions","version":"0.1.1","_id":"@dcsv-io/d2-encryption-abstractions@0.1.1","maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"dist":{"shasum":"c40f41f4bce425f3e412a0bb3e1157ca9ca91fb0","tarball":"https://registry.npmjs.org/@dcsv-io/d2-encryption-abstractions/-/d2-encryption-abstractions-0.1.1.tgz","fileCount":19,"integrity":"sha512-cnmrIVX+X8v07S98qe6E9bYKyEqQCseXH4+sX8/0x792AUcJiWY7FcdbS0LVaLYwOTehRMDmAKmMecvpX6PZmA==","signatures":[{"sig":"MEUCIQCC0CL3B28cLdcOcSla1t8P3EgZk8zAjF/ROr2d/U9+PwIgDTZAFI6YryBiTW4C9domZWdwkz7cMVveCYY26GMjq08=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41448},"main":"./dist/index.js","type":"module","_from":"file:bundle/npm/dcsv-io-d2-encryption-abstractions-0.1.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -b","prebuild":"node ../scripts/run-ts-codegen.mjs src/encryption-domains-emit.ts && node ../scripts/run-ts-codegen.mjs src/encryption-frame-emit.ts && node ../scripts/run-ts-codegen.mjs src/encryption-frame-sealed-emit.ts","test:coverage":"vitest run --coverage","type-check:test":"tsc -p tsconfig.test.json"},"_npmUser":{"name":"dcsv-tristan","email":"tristan@dcsv.io"},"_resolved":"/home/runner/work/D2-Public/D2-Public/bundle/npm/dcsv-io-d2-encryption-abstractions-0.1.1.tgz","_integrity":"sha512-cnmrIVX+X8v07S98qe6E9bYKyEqQCseXH4+sX8/0x792AUcJiWY7FcdbS0LVaLYwOTehRMDmAKmMecvpX6PZmA==","_npmVersion":"11.16.0","description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"vitest":"4.0.18","typescript":"5.9.3","@vitest/coverage-v8":"4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/d2-encryption-abstractions_0.1.1_1784262816373_0.4558767071812766","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@dcsv-io/d2-encryption-abstractions","version":"0.1.2","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"devDependencies":{"@vitest/coverage-v8":"4.0.18","typescript":"5.9.3","vitest":"4.0.18"},"scripts":{"prebuild":"node ../scripts/run-ts-codegen.mjs src/encryption-domains-emit.ts && node ../scripts/run-ts-codegen.mjs src/encryption-frame-emit.ts && node ../scripts/run-ts-codegen.mjs src/encryption-frame-sealed-emit.ts","build":"tsc -b","test":"vitest run","test:coverage":"vitest run --coverage","type-check:test":"tsc -p tsconfig.test.json"},"_id":"@dcsv-io/d2-encryption-abstractions@0.1.2","description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","_integrity":"sha512-Cae+MgXcWY9RJd1nNEjgzTsuwImsVRC9sUnETtVy5HnxE5gr/VjoPpEsDmMarZhuUwtCS95xJhl4XOlhar9qDg==","_resolved":"/home/runner/work/D2-Public/D2-Public/bundle/npm/dcsv-io-d2-encryption-abstractions-0.1.2.tgz","_from":"file:bundle/npm/dcsv-io-d2-encryption-abstractions-0.1.2.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-Cae+MgXcWY9RJd1nNEjgzTsuwImsVRC9sUnETtVy5HnxE5gr/VjoPpEsDmMarZhuUwtCS95xJhl4XOlhar9qDg==","shasum":"a7694754631084a1cc5b3220b9f46bfe1d0980a8","tarball":"https://registry.npmjs.org/@dcsv-io/d2-encryption-abstractions/-/d2-encryption-abstractions-0.1.2.tgz","fileCount":19,"unpackedSize":41468,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIH95XI5C70/tdjGAcQJdVkzeO1f5UPjbTHN4ShS9hO+tAiB6CPXJtk1g0XXV+NoHqdZfsL17UvGS3sD2HcbX4hbrrA=="}]},"_npmUser":{"name":"dcsv-tristan","email":"tristan@dcsv.io"},"directories":{},"maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/d2-encryption-abstractions_0.1.2_1784286862908_0.054099547663970515"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-17T04:33:36.208Z","modified":"2026-07-17T11:14:23.202Z","0.1.1":"2026-07-17T04:33:36.507Z","0.1.2":"2026-07-17T11:14:23.034Z"},"description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"readme":"<!--\nCopyright (c) DCSV. Licensed under the Apache License, Version 2.0.\n-->\n\n# @dcsv-io/d2-encryption-abstractions\n\nD2 encryption-domain identifiers + encryption-frame binary layout constants (symmetric version-1 AND sealed version-2). Mirrors .NET `DcsvIo.D2.Encryption.EncryptionDomains`, the `DcsvIo.D2.Encryption.EncryptionFrameLayout` byte-offset layout, and the `DcsvIo.D2.Encryption.SealedFrameLayout` sealed layout — all spec-driven.\n\n## Install\n\n```bash\npnpm add @dcsv-io/d2-encryption-abstractions\n```\n\n## Public API\n\n| Export                        | Source                         | Mirror                                              |\n| ----------------------------- | ------------------------------ | --------------------------------------------------- |\n| `EncryptionDomains`           | `encryption-domains.g.ts`      | `DcsvIo.D2.Encryption.EncryptionDomains`            |\n| `EncryptionDomain`            | `encryption-domains.g.ts`      | n/a (TS-only union type)                            |\n| `ALL_ENCRYPTION_DOMAINS`      | `encryption-domains.g.ts`      | `DcsvIo.D2.Encryption.EncryptionDomains.AllDomains` |\n| `EncryptionFrame`             | `encryption-frame.g.ts`        | `DcsvIo.D2.Encryption.EncryptionFrameLayout`        |\n| `EncryptionFrameField`        | `encryption-frame.g.ts`        | n/a (TS-only union type)                            |\n| `ALL_ENCRYPTION_FRAME_FIELDS` | `encryption-frame.g.ts`        | n/a (TS-only enumeration)                           |\n| `SealedFrame`                 | `encryption-frame-sealed.g.ts` | `DcsvIo.D2.Encryption.SealedFrameLayout`            |\n| `SealedFrameField`            | `encryption-frame-sealed.g.ts` | n/a (TS-only union type)                            |\n| `ALL_SEALED_FRAME_FIELDS`     | `encryption-frame-sealed.g.ts` | n/a (TS-only enumeration)                           |\n\n## Codegen workflow\n\n`prebuild` regenerates catalogs when a generator is available. Generated files (`*.g.ts`) are committed to git.\n\n## When to reach for this catalog\n\n- `EncryptionDomains`: any TS code that needs to refer to a keyring domain identifier — ops tooling (`d2 keys`), TS-side encryption pipelines, RabbitMQ subscribers that route on domain. The `PLAINTEXT` sentinel is included as a closed-catalog entry so callers can distinguish \"no encryption\" from \"encryption with the X domain.\"\n- `EncryptionFrame`: TS-side reader for the on-wire symmetric encryption frame produced by `DcsvIo.D2.Encryption.EncryptedBodyComposer`. The frame layout is binary (`[version:1][kid_len:1][kid:UTF-8][nonce:12][ct+tag]`); this catalog exposes the field-byte-offsets and lengths a parser needs.\n- `SealedFrame`: TS-side reader for the on-wire SEALED (version-2, asymmetric ECDH-ES hybrid) encryption frame (`[version:2][recipient_kid_len:1][recipient_kid:UTF-8][eph_pub_len:2 BE][eph_pub:SPKI][nonce:12][ct+tag]`). The leading version byte discriminates the two families; a reader dispatches on it and uses the matching catalog.\n\n## Spec contracts\n\n- `contracts/encryption-domains/encryption-domains.spec.json` — closed enum of domain identifiers (`audit` / `notifications` / `courier` + `plaintext` sentinel).\n- `contracts/encryption-frame/encryption-frame.spec.json` — closed catalog of symmetric (version-1) frame field offsets + byte lengths.\n- `contracts/encryption-frame-sealed/encryption-frame-sealed.spec.json` — closed catalog of sealed (version-2) frame field offsets + byte lengths, including the 2-byte big-endian ephemeral-public-key length prefix + cap.\n\n## Dependencies\n\nNone at runtime — pure constants. DevDeps: `vitest` + `@vitest/coverage-v8` + `typescript`.\n","readmeFilename":"README.md"}