You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Electron中暴露Node.js Crypto的cipher.update()函数

解决Electron中通过contextBridge暴露crypto的cipher.update方法问题

直接暴露createCipheriv返回的Cipher实例在渲染进程中无法访问其update、final等方法,因为Electron的contextBridge限制了跨上下文的复杂对象访问。下面提供两种可行的解决方案:

方案一:封装完整加密/解密逻辑(推荐)

将整个加密流程封装成函数直接暴露,避免在渲染进程中操作Cipher实例,更安全且实现简单。

修改后的preload.js代码:

// preload.js
const { contextBridge } = require('electron');
const nodeCrypto = require('crypto');

contextBridge.exposeInMainWorld('nodeCrypto', {
    randomBytes: (size) => nodeCrypto.randomBytes(size),
    scryptSync: (...args) => nodeCrypto.scryptSync(...args),
    // 封装AES-GCM加密逻辑
    encryptAesGcm: (password, data, salt) => {
        // AES-256需要32字节密钥,这里调整scrypt输出长度
        const key = nodeCrypto.scryptSync(password, salt, 32);
        const cipher = nodeCrypto.createCipheriv("aes-256-gcm", key, salt);
        const encrypted = Buffer.concat([cipher.update(data), cipher.final()]);
        // GCM模式必须保存认证标签用于解密
        const authTag = cipher.getAuthTag();
        return { encrypted, authTag };
    },
    // 封装AES-GCM解密逻辑
    decryptAesGcm: (password, encryptedData, salt, authTag) => {
        const key = nodeCrypto.scryptSync(password, salt, 32);
        const decipher = nodeCrypto.createDecipheriv("aes-256-gcm", key, salt);
        decipher.setAuthTag(authTag);
        const decrypted = Buffer.concat([decipher.update(encryptedData), decipher.final()]);
        return decrypted;
    }
});

渲染进程使用示例:

function encrypt(data) {
    const salt = nodeCrypto.randomBytes(16);
    const { encrypted, authTag } = nodeCrypto.encryptAesGcm('password', data, salt);
    // 需将salt、encrypted、authTag一同存储/传输
    return { salt, encrypted, authTag };
}

function decrypt(salt, encrypted, authTag) {
    const decryptedData = nodeCrypto.decryptAesGcm('password', encrypted, salt, authTag);
    return decryptedData.toString();
}

方案二:包装Cipher实例的方法

如果需要在渲染进程中分步调用update和final,可以在preload中包装Cipher实例,只暴露所需方法。

修改后的preload.js代码:

// preload.js
const { contextBridge } = require('electron');
const nodeCrypto = require('crypto');

contextBridge.exposeInMainWorld('nodeCrypto', {
    randomBytes: (size) => nodeCrypto.randomBytes(size),
    scryptSync: (...args) => nodeCrypto.scryptSync(...args),
    createCipheriv: (...args) => {
        const cipher = nodeCrypto.createCipheriv(...args);
        // 包装并暴露需要的方法
        return {
            update: (data, inputEncoding, outputEncoding) => cipher.update(data, inputEncoding, outputEncoding),
            final: (outputEncoding) => cipher.final(outputEncoding),
            getAuthTag: () => cipher.getAuthTag()
        };
    },
    createDecipheriv: (...args) => {
        const decipher = nodeCrypto.createDecipheriv(...args);
        return {
            update: (data, inputEncoding, outputEncoding) => decipher.update(data, inputEncoding, outputEncoding),
            final: (outputEncoding) => decipher.final(outputEncoding),
            setAuthTag: (tag) => decipher.setAuthTag(tag)
        };
    }
});

渲染进程使用示例(符合你的期望写法):

function encrypt(data) {
    const salt = nodeCrypto.randomBytes(16);
    // AES-256需要32字节密钥,调整scrypt输出长度
    const key = nodeCrypto.scryptSync('password', salt, 32);
    const cipher = nodeCrypto.createCipheriv("aes-256-gcm", key, salt);
    const encryptedData = Buffer.concat([cipher.update(data), cipher.final()]);
    const authTag = cipher.getAuthTag();
    return { salt, encryptedData, authTag };
}

注意事项

  • 移除原preload中重复的const { contextBridge } = require('electron');代码
  • AES-256算法需要32字节密钥,原代码中scryptSync返回64字节需调整为32字节
  • GCM模式必须保存并传递authTag才能完成解密

内容的提问来源于stack exchange,提问作者Sam Seith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 02:15:34