Skip to content

BE-924: Encrypt API token secret hashes with AES-256-GCM - #9896

Merged
TimDiekmann merged 11 commits into
mainfrom
t/be-924-seal-api-token-secret-hashes-with-aes-256-siv
Oct 10, 2026
Merged

TimDiekmann merged 11 commits into
mainfrom
t/be-924-seal-api-token-secret-hashes-with-aes-256-siv

Conversation

@TimDiekmann

@TimDiekmann TimDiekmann commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

🌟 Purpose

Storing API tokens needs a value to record for each token's secret. This PR adds it to the token module: the SHA-256 of the secret, encrypted with AES-256-GCM under a key from the Graph's configuration and bound to the token and the row it belongs to. Storing tokens and authenticating requests with them follow in the next PRs.
Relevant document (internal)

🔍 Changes

  • Start with libs/@local/graph/authentication/src/api_token/encryption.rs. api_token.rs moves to api_token/mod.rs without changes, so that the encryption sits next to the format.
  • ApiTokenEncryptionKey holds a 32-byte AES-256-GCM key and its ID, and its Debug output leaves out the key. encrypt turns the SHA-256 of a secret into 60 bytes: a random 12-byte nonce, the ciphertext and the 16-byte tag. decrypt reverses it and fails if the key or the associated data differ.
  • AssociatedData binds the encrypted value to the token and its row: the type and environment codes, the version, the token ID, the actor ID and the web ID, concatenated at fixed widths. HashedApiToken::associated_data builds it for a parsed token. Its fields are public, so it can also be built from a stored row without the token.
  • The store gains the value types ApiTokenEncryptedSecretHash and ApiTokenEncryptionKeyId. The key ID is a UUID.
  • The known-answer test decrypts a value computed independently with OpenSSL's AES-256-GCM under a fixed nonce, not copied from a run.
  • aws-lc-rs becomes a direct dependency of the authentication crate. The Graph already builds it through jsonwebtoken, reqwest and the AWS SDK.
  • Token IDs and secrets now come from AWS-LC's random number generator instead of rand's SysRng, and rand is no longer a dependency of the authentication crate. ApiToken::generate still returns ApiTokenGenerationError if the generator reports a failure.

@TimDiekmann TimDiekmann self-assigned this Oct 2, 2026
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hash Ready Ready Preview Oct 9, 2026 8:12pm UTC
petrinaut Ready Ready Preview Oct 9, 2026 8:12pm UTC
petrinaut-docs Ready Ready Preview Oct 9, 2026 8:12pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
hashdotdesign-tokens Ignored Ignored Preview Oct 9, 2026 8:12pm UTC

Request Review

@github-actions github-actions Bot added area/deps Relates to third-party dependencies (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > backend Owned by the @backend team labels Oct 2, 2026
@TimDiekmann
TimDiekmann deployed to pull-request October 2, 2026 12:18 — with GitHub Actions Active
@TimDiekmann
TimDiekmann deployed to pull-request October 2, 2026 12:18 — with GitHub Actions Active
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.15789% with 18 lines in your changes missing coverage. Please review.
✅ Project coverage is 63.98%. Comparing base (049a8c5) to head (9f621a1).
⚠️ Report is 33 commits behind head on main.

Files with missing lines Patch % Lines
libs/@local/graph/store/rust/src/api_token.rs 0.00% 12 Missing ⚠️
...l/graph/authentication/src/api_token/encryption.rs 96.52% 4 Missing ⚠️
...s/@local/graph/authentication/src/api_token/mod.rs 95.23% 1 Missing ⚠️
.../@local/graph/authentication/src/kratos/session.rs 75.00% 1 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff             @@
##             main    #9896       +/-   ##
===========================================
- Coverage   66.53%   63.98%    -2.55%     
===========================================
  Files        1954      740     -1214     
  Lines      215400    99649   -115751     
  Branches     8429     2203     -6226     
===========================================
- Hits       143313    63764    -79549     
+ Misses      70484    35247    -35237     
+ Partials     1603      638      -965     
Flag Coverage Δ
antsi ?
apps.hash-ai-worker-ts ?
apps.hash-api ?
apps.hash-graph ?
blockprotocol.type-system ?
durable-kernel ?
error-stack ?
harpc-codec ?
harpc-net ?
harpc-tower ?
harpc-types ?
harpc-wire-protocol ?
hash-codec ?
hash-config ?
hash-graph 14.11% <ø> (ø)
hash-graph-api 36.80% <ø> (ø)
hash-graph-atlas 80.00% <ø> (ø)
hash-graph-authentication 97.53% <95.71%> (-0.10%) ⬇️
hash-graph-authorization ?
hash-graph-embeddings ?
hash-graph-postgres-store 31.96% <ø> (-0.01%) ⬇️
hash-graph-store 51.48% <0.00%> (-0.12%) ⬇️
hash-graph-temporal-versioning ?
hash-graph-types ?
hash-graph-validation 85.37% <ø> (ø)
hash-middleware ?
hashql-ast ?
hashql-compiletest 28.71% <ø> (ø)
hashql-core ?
hashql-diagnostics ?
hashql-eval 79.77% <ø> (ø)
hashql-hir ?
hashql-mir ?
hashql-syntax-jexpr ?
local.claude-hooks ?
local.harpc-client ?
local.hash-backend-utils ?
local.hash-graph-sdk ?
local.hash-isomorphic-utils ?
problematic ?
rust.antsi ?
rust.error-stack ?
rust.harpc-codec ?
rust.harpc-net ?
rust.harpc-tower ?
rust.harpc-types ?
rust.harpc-wire-protocol ?
rust.hash-codec ?
rust.hash-config ?
rust.hash-graph-api ?
rust.hash-graph-atlas ?
rust.hash-graph-authentication ?
rust.hash-graph-authorization ?
rust.hash-graph-embeddings ?
rust.hash-graph-postgres-store ?
rust.hash-graph-store ?
rust.hash-graph-temporal-versioning ?
rust.hash-graph-types ?
rust.hash-graph-validation ?
rust.hash-middleware ?
rust.hashql-ast ?
rust.hashql-compiletest ?
rust.hashql-core ?
rust.hashql-diagnostics ?
rust.hashql-eval ?
rust.hashql-hir ?
rust.hashql-mir ?
rust.hashql-syntax-jexpr ?
rust.problematic ?

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@codspeed

codspeed Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

⚠️ 6 benchmarks measured no execution time

Nothing ran under measurement, usually because the compiler removed the code under test. These results are not comparable, so they count as unchanged.

Preventing compiler optimizations

✅ 98 untouched benchmarks


Comparing t/be-924-seal-api-token-secret-hashes-with-aes-256-siv (9f621a1) with main (51755b6)

Open in CodSpeed

@TimDiekmann
TimDiekmann marked this pull request as ready for review October 2, 2026 12:29
Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:29
@cursor

cursor Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Introduces cryptographic storage format and associated-data encoding that must stay stable for existing encrypted rows; changes RNG source for token issuance and session-cache keys.

Overview
Adds AES-256-GCM encryption for API token secret hashes before persistence, using a new ApiTokenEncryptionKey and associated data (token type, environment, version, token ID, actor ID, web ID) so ciphertext is bound to the token row.

The graph store gains ApiTokenEncryptedSecretHash (60-byte nonce + ciphertext + tag) and ApiTokenEncryptionKeyId. Token generation and the Kratos session-cache HMAC key now use aws-lc-rs for random bytes; rand is dropped from the authentication crate. Tests include an OpenSSL cross-check for decrypt and coverage for associated-data mismatches.

Reviewed by Cursor Bugbot for commit 9f621a1. Bugbot is set up for automated code reviews on this repo. Configure here.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The persistent cryptographic format and key-handling boundary warrant final human security review despite no identified defects.

Review effort: Balanced
Findings: None

What changed in this PR

Adds AES-256-SIV encryption for API token secret hashes, binding ciphertext to token and ownership metadata.

Changes:

  • Adds encryption/decryption APIs and associated-data binding.
  • Adds encrypted-hash and encryption-key identifier types.
  • Adds the aes-siv dependency and cryptographic known-answer tests.
File Description
Cargo.toml Registers aes-siv with zeroization enabled.
Cargo.lock Records resolved cryptographic dependencies.
libs/​@local/​graph/​authentication/​Cargo.toml Adds the crate dependency.
libs/​@local/​graph/​authentication/​src/​api_token/​mod.rs Exposes encryption APIs and constructs associated data.
libs/​@local/​graph/​authentication/​src/​api_token/​encryption.rs Implements authenticated encryption, decryption, and tests.
libs/​@local/​graph/​store/​rust/​src/​api_token.rs Adds encrypted-hash and key-ID value types.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread libs/@local/graph/authentication/src/api_token/encryption.rs
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Benchmark results

hash-graph-benches – Integrations

policy_resolution_large

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2002 $$29.5 \mathrm{ms} \pm 327 \mathrm{μs}\left({\color{gray}2.61 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.91 \mathrm{ms} \pm 43.4 \mathrm{μs}\left({\color{red}8.59 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 1002 $$15.0 \mathrm{ms} \pm 145 \mathrm{μs}\left({\color{gray}3.62 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 3314 $$47.3 \mathrm{ms} \pm 489 \mathrm{μs}\left({\color{gray}0.690 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$16.8 \mathrm{ms} \pm 206 \mathrm{μs}\left({\color{gray}4.53 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 1527 $$27.6 \mathrm{ms} \pm 307 \mathrm{μs}\left({\color{gray}4.32 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 2078 $$31.8 \mathrm{ms} \pm 310 \mathrm{μs}\left({\color{red}9.40 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$4.34 \mathrm{ms} \pm 35.3 \mathrm{μs}\left({\color{red}9.30 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 1033 $$16.4 \mathrm{ms} \pm 146 \mathrm{μs}\left({\color{red}6.88 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_medium

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 102 $$4.40 \mathrm{ms} \pm 41.3 \mathrm{μs}\left({\color{red}11.0 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.41 \mathrm{ms} \pm 31.8 \mathrm{μs}\left({\color{red}8.41 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 52 $$3.82 \mathrm{ms} \pm 35.4 \mathrm{μs}\left({\color{red}6.65 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 269 $$5.91 \mathrm{ms} \pm 57.6 \mathrm{μs}\left({\color{gray}3.48 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$3.85 \mathrm{ms} \pm 39.7 \mathrm{μs}\left({\color{gray}1.24 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 108 $$4.60 \mathrm{ms} \pm 48.2 \mathrm{μs}\left({\color{gray}0.249 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 133 $$5.25 \mathrm{ms} \pm 52.2 \mathrm{μs}\left({\color{red}10.9 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.97 \mathrm{ms} \pm 34.4 \mathrm{μs}\left({\color{red}11.6 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 63 $$4.71 \mathrm{ms} \pm 54.6 \mathrm{μs}\left({\color{red}7.93 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_none

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2 $$3.00 \mathrm{ms} \pm 26.0 \mathrm{μs}\left({\color{red}7.22 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.02 \mathrm{ms} \pm 32.4 \mathrm{μs}\left({\color{red}11.2 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 2 $$3.04 \mathrm{ms} \pm 32.1 \mathrm{μs}\left({\color{red}9.64 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 8 $$3.23 \mathrm{ms} \pm 26.9 \mathrm{μs}\left({\color{gray}2.86 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.13 \mathrm{ms} \pm 30.3 \mathrm{μs}\left({\color{red}7.21 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 3 $$3.48 \mathrm{ms} \pm 42.6 \mathrm{μs}\left({\color{red}10.1 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_small

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 52 $$3.38 \mathrm{ms} \pm 30.2 \mathrm{μs}\left({\color{red}6.77 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$2.98 \mathrm{ms} \pm 25.8 \mathrm{μs}\left({\color{gray}4.05 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 26 $$3.17 \mathrm{ms} \pm 28.6 \mathrm{μs}\left({\color{gray}4.32 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 94 $$3.87 \mathrm{ms} \pm 33.9 \mathrm{μs}\left({\color{red}7.78 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$3.35 \mathrm{ms} \pm 33.2 \mathrm{μs}\left({\color{red}6.88 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 27 $$3.70 \mathrm{ms} \pm 42.1 \mathrm{μs}\left({\color{red}9.76 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 66 $$3.80 \mathrm{ms} \pm 42.3 \mathrm{μs}\left({\color{red}5.84 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.29 \mathrm{ms} \pm 29.2 \mathrm{μs}\left({\color{red}5.25 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 29 $$3.54 \mathrm{ms} \pm 29.4 \mathrm{μs}\left({\color{gray}3.84 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_complete

Function Value Mean Flame graphs
entity_by_id;one_depth 1 entities $$33.7 \mathrm{ms} \pm 292 \mathrm{μs}\left({\color{gray}3.62 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 10 entities $$55.3 \mathrm{ms} \pm 542 \mathrm{μs}\left({\color{lightgreen}-22.964 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 25 entities $$37.0 \mathrm{ms} \pm 306 \mathrm{μs}\left({\color{gray}1.62 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 5 entities $$40.9 \mathrm{ms} \pm 252 \mathrm{μs}\left({\color{gray}2.66 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 50 entities $$44.7 \mathrm{ms} \pm 271 \mathrm{μs}\left({\color{gray}4.97 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 1 entities $$35.1 \mathrm{ms} \pm 250 \mathrm{μs}\left({\color{gray}1.37 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 10 entities $$244 \mathrm{ms} \pm 1.26 \mathrm{ms}\left({\color{lightgreen}-43.359 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 25 entities $$95.9 \mathrm{ms} \pm 688 \mathrm{μs}\left({\color{gray}-1.953 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 5 entities $$82.0 \mathrm{ms} \pm 557 \mathrm{μs}\left({\color{gray}2.05 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 50 entities $$289 \mathrm{ms} \pm 1.32 \mathrm{ms}\left({\color{gray}0.724 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 1 entities $$11.2 \mathrm{ms} \pm 97.8 \mathrm{μs}\left({\color{gray}3.74 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 10 entities $$11.3 \mathrm{ms} \pm 87.3 \mathrm{μs}\left({\color{red}6.40 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 25 entities $$11.2 \mathrm{ms} \pm 83.4 \mathrm{μs}\left({\color{gray}2.48 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 5 entities $$11.5 \mathrm{ms} \pm 89.0 \mathrm{μs}\left({\color{red}6.35 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 50 entities $$11.3 \mathrm{ms} \pm 79.1 \mathrm{μs}\left({\color{gray}3.71 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_linkless

Function Value Mean Flame graphs
entity_by_id 1 entities $$11.2 \mathrm{ms} \pm 96.8 \mathrm{μs}\left({\color{gray}3.79 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10 entities $$11.1 \mathrm{ms} \pm 117 \mathrm{μs}\left({\color{gray}1.76 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 100 entities $$11.3 \mathrm{ms} \pm 114 \mathrm{μs}\left({\color{gray}3.19 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 1000 entities $$11.3 \mathrm{ms} \pm 98.7 \mathrm{μs}\left({\color{gray}0.742 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10000 entities $$11.5 \mathrm{ms} \pm 102 \mathrm{μs}\left({\color{gray}1.90 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity

Function Value Mean Flame graphs
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/block/v/1 $$11.6 \mathrm{ms} \pm 95.4 \mathrm{μs}\left({\color{gray}-3.551 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/book/v/1 $$11.5 \mathrm{ms} \pm 86.4 \mathrm{μs}\left({\color{gray}-2.720 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/building/v/1 $$11.2 \mathrm{ms} \pm 89.0 \mathrm{μs}\left({\color{gray}-3.470 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/organization/v/1 $$11.4 \mathrm{ms} \pm 70.4 \mathrm{μs}\left({\color{gray}-4.712 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/page/v/2 $$11.5 \mathrm{ms} \pm 111 \mathrm{μs}\left({\color{gray}-4.387 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/person/v/1 $$11.4 \mathrm{ms} \pm 89.4 \mathrm{μs}\left({\color{gray}-3.228 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/playlist/v/1 $$11.9 \mathrm{ms} \pm 91.8 \mathrm{μs}\left({\color{gray}0.793 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/song/v/1 $$11.5 \mathrm{ms} \pm 93.9 \mathrm{μs}\left({\color{lightgreen}-5.053 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/uk-address/v/1 $$11.5 \mathrm{ms} \pm 99.1 \mathrm{μs}\left({\color{lightgreen}-5.602 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity_type

Function Value Mean Flame graphs
get_entity_type_by_id Account ID: bf5a9ef5-dc3b-43cf-a291-6210c0321eba $$8.28 \mathrm{ms} \pm 62.0 \mathrm{μs}\left({\color{gray}-1.544 \mathrm{\%}}\right) $$ Flame Graph

representative_read_multiple_entities

Function Value Mean Flame graphs
entity_by_property traversal_paths=0 0 $$59.2 \mathrm{ms} \pm 479 \mathrm{μs}\left({\color{gray}-3.534 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$114 \mathrm{ms} \pm 609 \mathrm{μs}\left({\color{gray}0.392 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$65.5 \mathrm{ms} \pm 612 \mathrm{μs}\left({\color{gray}-3.843 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$76.1 \mathrm{ms} \pm 659 \mathrm{μs}\left({\color{gray}-2.026 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$85.4 \mathrm{ms} \pm 800 \mathrm{μs}\left({\color{gray}-2.482 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$90.7 \mathrm{ms} \pm 680 \mathrm{μs}\left({\color{gray}-1.785 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=0 0 $$49.8 \mathrm{ms} \pm 317 \mathrm{μs}\left({\color{gray}4.62 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$81.0 \mathrm{ms} \pm 651 \mathrm{μs}\left({\color{red}7.02 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$57.6 \mathrm{ms} \pm 560 \mathrm{μs}\left({\color{red}6.05 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$66.3 \mathrm{ms} \pm 611 \mathrm{μs}\left({\color{red}5.61 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$69.1 \mathrm{ms} \pm 581 \mathrm{μs}\left({\color{red}8.57 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$69.1 \mathrm{ms} \pm 619 \mathrm{μs}\left({\color{red}6.62 \mathrm{\%}}\right) $$

scenarios

Function Value Mean Flame graphs
full_test query-limited $$115 \mathrm{ms} \pm 784 \mathrm{μs}\left({\color{gray}-4.324 \mathrm{\%}}\right) $$ Flame Graph
full_test query-unlimited $$126 \mathrm{ms} \pm 826 \mathrm{μs}\left({\color{gray}-3.955 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-limited $$25.2 \mathrm{ms} \pm 205 \mathrm{μs}\left({\color{red}10.6 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-unlimited $$524 \mathrm{ms} \pm 2.26 \mathrm{ms}\left({\color{gray}-1.393 \mathrm{\%}}\right) $$ Flame Graph

@TimDiekmann
TimDiekmann requested a review from a team October 5, 2026 07:53
@TimDiekmann
TimDiekmann added this pull request to stack #9927 October 5, 2026 18:51
@TimDiekmann TimDiekmann changed the title BE-924: Encrypt API token secret hashes with AES-256-SIV BE-924: Encrypt API token secret hashes with AES-256-GCM Oct 7, 2026
@TimDiekmann
TimDiekmann requested a review from a team as a code owner October 7, 2026 15:37
@vercel
vercel Bot temporarily deployed to Preview – petrinaut October 7, 2026 15:37 Inactive

@indietyp indietyp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 question, 2 minor non-blocking notes/comments.

Comment thread libs/@local/graph/store/rust/src/api_token.rs
Comment thread libs/@local/graph/authentication/src/api_token/encryption.rs
Comment thread libs/@local/graph/authentication/src/api_token/mod.rs Outdated
@TimDiekmann
TimDiekmann added this pull request to the merge queue Oct 10, 2026
Merged via the queue into main with commit 56805ee Oct 10, 2026
216 checks passed
@TimDiekmann
TimDiekmann deleted the t/be-924-seal-api-token-secret-hashes-with-aes-256-siv branch October 10, 2026 09:32

This branch was successfully deployed

5 active (2 outdated) deployments
Preview – hash — 9f621a11 Deployed Oct 9, 2026 by vercel[bot]
Preview – petrinaut-docs — 9f621a11 Deployed Oct 9, 2026 by vercel[bot]
Preview – petrinaut — 9f621a11 Deployed Oct 9, 2026 by vercel[bot]
Preview – hashdotdesign-tokens — 1c95bfe1 Deployed Oct 9, 2026 by vercel[bot]
pull-request — 59fa5fac Deployed Oct 2, 2026 by TimDiekmann via Sourcemaps (@apps/hash-integration-worker) #38004
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/deps Relates to third-party dependencies (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > backend Owned by the @backend team

Development

Successfully merging this pull request may close these issues.

4 participants