diff --git a/backend/src/db/seed-data.ts b/backend/src/db/seed-data.ts index 6406e44ab..e484b09b1 100644 --- a/backend/src/db/seed-data.ts +++ b/backend/src/db/seed-data.ts @@ -19,6 +19,9 @@ import { TSecrets, TUserEncryptionKeys } from "./schemas"; export let userPrivateKey: string | undefined; export let userPublicKey: string | undefined; +export let userPrivateKey: string | undefined; +export let userPublicKey: string | undefined; + export const seedData1 = { id: "3dafd81d-4388-432b-a4c5-f735616868c1", email: process.env.TEST_USER_EMAIL || "test@localhost.local", diff --git a/backend/src/db/seeds/1-user.ts b/backend/src/db/seeds/1-user.ts index af40dbbbc..5f9fcd509 100644 --- a/backend/src/db/seeds/1-user.ts +++ b/backend/src/db/seeds/1-user.ts @@ -3,9 +3,12 @@ import { Knex } from "knex"; +// eslint-disable-next-line @typescript-eslint/no-unused-vars +import { generateUserSrpKeys } from "@app/lib/crypto/srp"; + import { AuthMethod } from "../../services/auth/auth-type"; import { TableName } from "../schemas"; -import { generateUserSrpKeys, seedData1 } from "../seed-data"; +import { seedData1 } from "../seed-data"; export async function seed(knex: Knex): Promise { // Deletes ALL existing entries @@ -34,7 +37,7 @@ export async function seed(knex: Knex): Promise { ]) .returning("*"); - const encKeys = await generateUserSrpKeys(seedData1.password); + const encKeys = await generateUserSrpKeys(seedData1.email, seedData1.password); // password: testInfisical@1 await knex(TableName.UserEncryptionKey).insert([ { @@ -64,4 +67,9 @@ export async function seed(knex: Knex): Promise { refreshVersion: 1, lastUsed: new Date() }); + + seedData1.encryptionKeys = { + publicKey: encKeys.publicKey, + privateKey: encKeys.plainPrivateKey + }; } diff --git a/backend/src/db/seeds/3-project.ts b/backend/src/db/seeds/3-project.ts index 0efb6a249..9887373fd 100644 --- a/backend/src/db/seeds/3-project.ts +++ b/backend/src/db/seeds/3-project.ts @@ -14,6 +14,8 @@ export const DEFAULT_PROJECT_ENVS = [ ]; export async function seed(knex: Knex): Promise { + initEnvConfig(); + const appCfg = getConfig(); // Deletes ALL existing entries await knex(TableName.Project).del(); await knex(TableName.Environment).del(); @@ -25,14 +27,38 @@ export async function seed(knex: Knex): Promise { orgId: seedData1.organization.id, slug: "first-project", // @ts-expect-error exluded type id needs to be inserted here to keep it testable - id: seedData1.project.id + id: seedData1.project.id, + version: "v1" }) .returning("*"); - // await knex(TableName.ProjectKeys).insert({ - // projectId: project.id, - // senderId: seedData1.id - // }); + const blindIndex = createSecretBlindIndex(appCfg.ROOT_ENCRYPTION_KEY, appCfg.ENCRYPTION_KEY); + + await knex(TableName.SecretBlindIndex).insert({ + projectId: project.id, + algorithm: blindIndex.algorithm, + keyEncoding: blindIndex.keyEncoding, + saltIV: blindIndex.iv, + encryptedSaltCipherText: blindIndex.ciphertext, + saltTag: blindIndex.tag + }); + + const randomBytes = crypto.randomBytes(16).toString("hex"); // Project key + // const encKeys = await generateUserSrpKeys(seedData1.email, seedData1.password); // User keys + + const { ciphertext: encryptedProjectKey, nonce: encryptedProjectKeyIv } = encryptAsymmetric( + randomBytes, + seedData1.encryptionKeys.publicKey, + seedData1.encryptionKeys.privateKey + ); + + await knex(TableName.ProjectKeys).insert({ + projectId: project.id, + senderId: seedData1.id, + receiverId: seedData1.id, + encryptedKey: encryptedProjectKey, + nonce: encryptedProjectKeyIv + }); await knex(TableName.ProjectMembership).insert({ projectId: project.id,