/** * TOTP Encryption Service * * Provides AES-256-GCM encryption/decryption for TOTP secrets. * Secrets are encrypted before storage in Neo4j and decrypted for TOTP validation. * * Format: IV (12 bytes) + AuthTag (16 bytes) + Ciphertext (base64 encoded) */ export declare class TotpEncryptionService { private readonly algorithm; private readonly ivLength; private readonly authTagLength; /** * Get the encryption key from config. * The key must be exactly 32 bytes (256 bits) for AES-256. */ private getKey; /** * Encrypt a TOTP secret using AES-256-GCM. * * @param plaintext - The TOTP secret to encrypt (typically base32-encoded) * @returns The encrypted secret as a base64-encoded string containing IV, auth tag, and ciphertext */ encrypt(plaintext: string): string; /** * Decrypt a TOTP secret encrypted with AES-256-GCM. * * @param ciphertext - The base64-encoded encrypted secret (IV + AuthTag + Ciphertext) * @returns The decrypted TOTP secret * @throws Error if decryption fails (invalid key, corrupted data, or tampered data) */ decrypt(ciphertext: string): string; /** * Verify that the encryption system is properly configured. * Performs a round-trip encryption/decryption test. * * @returns true if encryption is working correctly * @throws Error if encryption is not properly configured */ verify(): boolean; } //# sourceMappingURL=totp-encryption.service.d.ts.map