Securityv0.1.5
@tekir/encryption
AES-256-GCM encryption and decryption via Web Crypto API.
Installation
$
bun add @tekir/encryptionFeatures
- AES-256-GCM encryption via Web Crypto API
- PBKDF2 key derivation from app key
- encrypt() and decrypt() with base64 output
- Works on Node.js 18+, Bun, Deno, and edge runtimes
- EncryptionProvider for DI registration
Quick Example
TypeScript
import { Encryption } from '@tekir/encryption'
const enc = new Encryption(process.env.APP_KEY!)
const encrypted = await enc.encrypt({ userId: 1 })
const decrypted = await enc.decrypt(encrypted)Changelog
v0.1.5LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.4July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.3July 16, 2026
- Legacy ciphertext whose IV starts with the version byte is decoded correctly, and APP_KEY environment fallback no longer assumes a Node-style global
process.
v0.1.2June 13, 2026
- Each encryption now generates a fresh 16-byte random salt and embeds it in the payload, with key derivation bound to that salt. The same
APP_KEYproduces a different key per ciphertext, closing precompute/rainbow attacks and key sharing across installs. - The constructor now validates
APP_KEYfor a minimum length and basic entropy and throws a clear error otherwise. - A
decryptJSON-parse failure now throws the same generic error as a decryption failure (the JSON hint is log-only), so it does not signal payload structure to an attacker. - Found and fixed with Fable.
v0.1.1May 8, 2026
Encryption.decrypt<T>defaultsTtoanyinstead ofunknown. Round-tripped values are usable directly without a generic argument; pass an explicit type when narrowing back to a specific shape (enc.decrypt<User>(token)).
v0.1.0April 1, 2026
- Initial release