Looks useful. I am seeing though
message[pre_encryption]
with my unencrypted message in the POST data?
message[pre_encryption]
with my unencrypted message in the POST data?
Edit: fixed. If anybody thinks of anything else, please let me know. This is as much of a learning exercise as anything for me.
I'm glad if this has been a good learning experience for you (may I suggest another?†), but real secure systems aren't, to steal a phrase from Richard Stallman, "debugged into existence": they start from a foundation of a secure, well-considered design and are verified piece by piece as the system is assembled.