Something went wrong. Try again.
store your secret bits safe from prying eyes
mongodb mongo
Something went wrong. Try again.
Go 100%
README.md
secretbits #
Store your secret bits safe from prying eyes
Transparently encrypt select MongoDB document fields before sending them to a remote cluster and decrypt on the back back in.
import(
sb "tangled.org/softprops.tngl.sh/secretbits"
"go.mongodb.org/mongo-driver/v2"
"go.mongodb.org/mongo-driver/v2/bson"
"go.mongodb.org/mongo-driver/v2/options"
)
type Example struct {
Name string `bson:"_id"`
Secret sb.String `bson:"secret"` // this field will be encrypted before sending to MongoDB cluster
}
func main() {
reg, err := sb.NewRegistry(encryptionKey)
if err {
log.Fatal(err)
}
client, err := mongo.Connect(
options.Client().ApplyURI(uri).SetRegistry(reg)
)
if err != nil {
log.Fatal(err)
}
col := client.Database("simplebits").Collection("examples")
// store document with encrypted field
_ = col.InsertOne(
context.TODO(),
Example {
Name: "exhibitA",
Secret: sb.String("this will be encrypted"),
}
)
// read document back and the encrypted field will be decrypted
_ = col.FindOne(context.TODO(), bson.M{"_id":"exhibitA"})
}
How is this different from csfle?
- It doesn't require Cgo. You can use Go proper.
- It doesn't require register a schema definition with a MongoDB cluster. Your encrypted fields are defined by their type.
- It isn't coupled to complicated key management. How you managed your keys is up to you and your application.
- It's less of a mouthful
Technical Bits
This library uses a FIPS-compliant AEAD encryption cipher called AES-GCM which is encrypts select document fields before sending documents to the server and decrypts them when received on the way back using a bson Registry type Encoder/Decoder combination.
softprops 2026