NAME

Dancer2::Session::Pg::Cipher::AESGCM - AES-GCM for Dancer2::Session::Pg

VERSION

version 0.001

SYNOPSIS

use Dancer2::Session::Pg ();

my %slot_by_name = (
    0 => { key => $ENV{'SESSION_KEY_0'}, alg => 'AES-256-GCM', active => 1 },
);

# the same thing spelled out, which is only needed to pass arguments
my %slot_by_class = (
    0 => {
        key    => $ENV{'SESSION_KEY_0'},
        alg    => [ 'Dancer2::Session::Pg::Cipher::AESGCM', key_bytes => 32 ],
        active => 1,
    },
);

DESCRIPTION

AES in Galois/Counter Mode, from CryptX, in all three key lengths. The default cipher of Dancer2::Session::Pg: AES-NI makes it the fastest option on essentially every server CPU in use, it is the most widely reviewed choice, and it is the one most likely to be acceptable to whoever audits you.

Does Dancer2::Session::Pg::Cipher. A 96-bit nonce and a 128-bit tag, which is the usual pairing for GCM and the one every other implementation will expect.

ATTRIBUTES

key_bytes

16, 24 or 32, defaulting to 32. Anything else croaks at construction. The value selects the stored cipher id, so it is not a free parameter:

key_bytes   cipher_name     cipher_id
16          AES-128-GCM     1
24          AES-192-GCM     2
32          AES-256-GCM     3

METHODS

See Dancer2::Session::Pg::Cipher for the contract. iv_bytes is 12 and tag_bytes is 16 for every key length.

SEE ALSO

Dancer2::Session::Pg, Dancer2::Session::Pg::Cipher, CryptX

AUTHOR

Mikko Koivunalho <mikko.koivunalho@iki.fi>

LICENSE AND COPYRIGHT

This software is copyright (c) 2026 by Mikko Koivunalho.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.