HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulelibsodium-bindings-0.0.1.1Haskell2010

LibSodium.Bindings.Secretbox

  • 10 values

Introduction

0 declarations

This API allows encrypting a message using a secret key and a nonce. The ciphertext is accompanied by an authentication tag.

It comes in two flavours:

easy

Both the ciphertext and authentication tag are stored in the same buffer.

detached

The ciphertext and authentication tag may be stored in separate buffers.

The same key is used for both encryption and decryption, so it must be kept secret. A key can be generated using the cryptoSecretboxKeygen primitive.

Each message must use a unique nonce, which may be generated with the randombytesBuf primitive. The nonce does not need to be kept secret but should never be reused with the same secret key.

For more information see the upstream docs: https://doc.libsodium.org/secret-key_cryptography/secretbox

Secretbox

0 declarations

Keygen

Easy

valuecryptoSecretboxEasy
  1. :: Ptr CUChar

    A pointer to the buffer that will hold the ciphertext. The length of the ciphertext is the length of the message in bytes plus cryptoSecretboxMACBytes bytes.

  2. -> Ptr CUChar

    A pointer to the buffer holding the message to be encrypted.

  3. -> CULLong

    The length of the message in bytes.

  4. -> Ptr CUChar

    A pointer to the nonce of size cryptoSecretboxNonceBytes bytes.

  5. -> Ptr CUChar

    A pointer to the secret key of size cryptoSecretboxKeyBytes bytes.

  6. -> IO CInt

    Returns 0 on success and -1 on error.

#

Encrypt a message using a secret key and nonce.

The message and ciphertext buffers may overlap enabling in-place encryption, but note that the ciphertext will be cryptoSecretboxMACBytes bytes longer than the message.

See: crytpo_secretbox_easy()

valuecryptoSecretboxOpenEasy
  1. :: Ptr CUChar

    A pointer to the buffer that will hold the decrypted message. The length of the message is the length of the ciphertext in bytes minus cryptoSecretboxMACBytes bytes.

  2. -> Ptr CUChar

    A pointer to the buffer holding the ciphertext to be verified and decrypted.

  3. -> CULLong

    The length of the ciphertext in bytes.

  4. -> Ptr CUChar

    A pointer to the nonce of size cryptoSecretboxNonceBytes bytes.

  5. -> Ptr CUChar

    A pointer to the secret key of size cryptoSecretboxKeyBytes bytes.

  6. -> IO CInt

    Returns 0 on success and -1 on error.

#

Verify and decrypt ciphertext using a secret key and nonce.

The message and ciphertext buffers may overlap enabling in-place decryption, but note that the message will be cryptoSecretboxMACBytes bytes shorter than the ciphertext.

See: crypto_secretbox_open_easy()

Detached

valuecryptoSecretboxDetached
  1. :: Ptr CUChar

    A pointer to the buffer that will hold the ciphertext. This will have the same length as the message.

  2. -> Ptr CUChar

    A pointer to the buffer that will hold the authentication tag. This will be of length cryptoSecretboxMACBytes bytes.

  3. -> Ptr CUChar

    A pointer to the buffer holding the message to be encrypted.

  4. -> CULLong

    The length of the message in bytes.

  5. -> Ptr CUChar

    A pointer to the nonce of size cryptoSecretboxNonceBytes bytes.

  6. -> Ptr CUChar

    A pointer to the secret key of size cryptoSecretboxKeyBytes bytes.

  7. -> IO CInt

    Returns 0 on success and -1 on error.

#

Encrypt a message using a secret key and nonce.

See: crypto_secretbox_detached()

valuecryptoSecretboxOpenDetached
  1. :: Ptr CUChar

    A pointer to the buffer that will hold the decrypted message. This will have the same length as the ciphertext.

  2. -> Ptr CUChar

    A pointer to the buffer holding the ciphertext to be decrypted.

  3. -> Ptr CUChar

    A pointer to the buffer holding the authentication tag to be verified.

  4. -> CULLong

    The length of the ciphertext in bytes.

  5. -> Ptr CUChar

    A pointer to the nonce of size cryptoSecretboxNonceBytes bytes.

  6. -> Ptr CUChar

    A pointer to the secret key of size cryptoSecretboxKeyBytes bytes.

  7. -> IO CInt

    Returns 0 on success and -1 on error.

#

Verify and decrypt ciphertext using a secret key and nonce

See: crypto_secretbox_open_detached()

Constants