Refactor migration to work with conflict/merge update logic

This commit is contained in:
Daniel Hougaard
2024-02-22 05:00:40 +01:00
parent 4657985468
commit 10fbb99a15
2 changed files with 214 additions and 70 deletions
+195 -66
View File
@@ -1,46 +1,45 @@
import crypto from "crypto"; import crypto from "crypto";
import { z } from "zod"; import { z } from "zod";
import { TProjectKeys } from "@app/db/schemas"; import {
import { logger } from "@app/lib/logger"; SecretApprovalRequestsSecretsSchema,
SecretsSchema,
SecretVersionsSchema,
TProjectKeys,
TSecretApprovalRequestsSecrets,
TSecrets,
TSecretVersions
} from "@app/db/schemas";
import { decryptAsymmetric } from "../crypto"; import { decryptAsymmetric } from "../crypto";
export enum SecretDocType { const DecryptedValuesSchema = z.object({
Secret = "secret",
SecretVersion = "secretVersion",
ApprovalSecret = "approvalSecret"
}
export interface TPartialSecret {
id: string;
secretKeyCiphertext: string;
secretKeyIV: string;
secretKeyTag: string;
secretValueCiphertext: string;
secretValueIV: string;
secretValueTag: string;
secretCommentCiphertext?: string | null;
secretCommentIV?: string | null;
secretCommentTag?: string | null;
docType: SecretDocType;
keyEncoding: string;
}
const PartialDecryptedSecretSchema = z.object({
id: z.string(), id: z.string(),
secretKey: z.string(), secretKey: z.string(),
secretValue: z.string(), secretValue: z.string(),
secretComment: z.string().optional(), secretComment: z.string().optional()
docType: z.nativeEnum(SecretDocType)
}); });
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
const decryptSecret = ({ const DecryptedSecretSchema = z.object({
decrypted: DecryptedValuesSchema,
original: SecretsSchema
});
const DecryptedSecretVersionsSchema = z.object({
decrypted: DecryptedValuesSchema,
original: SecretVersionsSchema
});
export const DecryptedSecretApprovalsSchema = z.object({
decrypted: DecryptedValuesSchema,
original: SecretApprovalRequestsSecretsSchema
});
export type DecryptedSecret = z.infer<typeof DecryptedSecretSchema>;
export type DecryptedSecretVersions = z.infer<typeof DecryptedSecretVersionsSchema>;
export type DecryptedSecretApprovals = z.infer<typeof DecryptedSecretApprovalsSchema>;
const decryptCipher = ({
ciphertext, ciphertext,
iv, iv,
tag, tag,
@@ -60,8 +59,62 @@ const decryptSecret = ({
return cleartext; return cleartext;
}; };
const getDecryptedValues = ({
secretKeyCiphertext,
secretKeyIV,
secretKeyTag,
secretValueCiphertext,
secretValueIV,
secretValueTag,
secretCommentCiphertext,
secretCommentIV,
secretCommentTag,
key
}: {
secretKeyCiphertext: string;
secretKeyIV: string;
secretKeyTag: string;
secretValueCiphertext: string;
secretValueIV: string;
secretValueTag: string;
secretCommentCiphertext?: string | null;
secretCommentIV?: string | null;
secretCommentTag?: string | null;
key: string | Buffer;
}) => {
const secretKey = decryptCipher({
ciphertext: secretKeyCiphertext,
iv: secretKeyIV,
tag: secretKeyTag,
key
});
const secretValue = decryptCipher({
ciphertext: secretValueCiphertext,
iv: secretValueIV,
tag: secretValueTag,
key
});
const secretComment =
secretCommentCiphertext && secretCommentIV && secretCommentTag
? decryptCipher({
ciphertext: secretCommentCiphertext,
iv: secretCommentIV,
tag: secretCommentTag,
key
})
: "";
return {
secretKey,
secretValue,
secretComment
};
};
export const decryptSecrets = ( export const decryptSecrets = (
encryptedSecrets: TPartialSecret[], encryptedSecrets: TSecrets[],
privateKey: string, privateKey: string,
latestKey: TProjectKeys & { latestKey: TProjectKeys & {
sender: { sender: {
@@ -76,47 +129,123 @@ export const decryptSecrets = (
privateKey privateKey
}); });
const decryptedSecrets: TPartialDecryptedSecret[] = []; const decryptedSecrets: DecryptedSecret[] = [];
encryptedSecrets.forEach((encSecret) => { encryptedSecrets.forEach((encSecret) => {
try { const decrypted = getDecryptedValues({
const secretKey = decryptSecret({ secretKeyCiphertext: encSecret.secretKeyCiphertext,
ciphertext: encSecret.secretKeyCiphertext, secretKeyIV: encSecret.secretKeyIV,
iv: encSecret.secretKeyIV, secretKeyTag: encSecret.secretKeyTag,
tag: encSecret.secretKeyTag, secretValueCiphertext: encSecret.secretValueCiphertext,
secretValueIV: encSecret.secretValueIV,
secretValueTag: encSecret.secretValueTag,
secretCommentCiphertext: encSecret.secretCommentCiphertext,
secretCommentIV: encSecret.secretCommentIV,
secretCommentTag: encSecret.secretCommentTag,
key key
}); });
const secretValue = decryptSecret({ const decryptedSecret: DecryptedSecret = {
ciphertext: encSecret.secretValueCiphertext, decrypted: {
iv: encSecret.secretValueIV, ...decrypted,
tag: encSecret.secretValueTag, id: encSecret.id
key },
}); original: encSecret
const secretComment =
encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag
? decryptSecret({
ciphertext: encSecret.secretCommentCiphertext,
iv: encSecret.secretCommentIV,
tag: encSecret.secretCommentTag,
key
})
: "";
const decryptedSecret: TPartialDecryptedSecret = {
id: encSecret.id,
secretKey,
secretValue,
secretComment,
docType: encSecret.docType
}; };
decryptedSecrets.push(PartialDecryptedSecretSchema.parse(decryptedSecret)); decryptedSecrets.push(DecryptedSecretSchema.parse(decryptedSecret));
} catch (err) { });
// This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets input array length.
logger.error(`[${encSecret.id}] - failed to decrypt`, err); return decryptedSecrets;
};
export const decryptSecretVersions = (
encryptedSecretVersions: TSecretVersions[],
privateKey: string,
latestKey: TProjectKeys & {
sender: {
publicKey: string;
};
} }
) => {
const key = decryptAsymmetric({
ciphertext: latestKey.encryptedKey,
nonce: latestKey.nonce,
publicKey: latestKey.sender.publicKey,
privateKey
});
const decryptedSecrets: DecryptedSecretVersions[] = [];
encryptedSecretVersions.forEach((encSecret) => {
const decrypted = getDecryptedValues({
secretKeyCiphertext: encSecret.secretKeyCiphertext,
secretKeyIV: encSecret.secretKeyIV,
secretKeyTag: encSecret.secretKeyTag,
secretValueCiphertext: encSecret.secretValueCiphertext,
secretValueIV: encSecret.secretValueIV,
secretValueTag: encSecret.secretValueTag,
secretCommentCiphertext: encSecret.secretCommentCiphertext,
secretCommentIV: encSecret.secretCommentIV,
secretCommentTag: encSecret.secretCommentTag,
key
});
const decryptedSecret: DecryptedSecretVersions = {
decrypted: {
...decrypted,
id: encSecret.id
},
original: encSecret
};
decryptedSecrets.push(DecryptedSecretVersionsSchema.parse(decryptedSecret));
});
return decryptedSecrets;
};
export const decryptSecretApprovals = (
encryptedSecretApprovals: TSecretApprovalRequestsSecrets[],
privateKey: string,
latestKey: TProjectKeys & {
sender: {
publicKey: string;
};
}
) => {
const key = decryptAsymmetric({
ciphertext: latestKey.encryptedKey,
nonce: latestKey.nonce,
publicKey: latestKey.sender.publicKey,
privateKey
});
const decryptedSecrets: DecryptedSecretApprovals[] = [];
encryptedSecretApprovals.forEach((encSecret) => {
const decrypted = getDecryptedValues({
secretKeyCiphertext: encSecret.secretKeyCiphertext,
secretKeyIV: encSecret.secretKeyIV,
secretKeyTag: encSecret.secretKeyTag,
secretValueCiphertext: encSecret.secretValueCiphertext,
secretValueIV: encSecret.secretValueIV,
secretValueTag: encSecret.secretValueTag,
secretCommentCiphertext: encSecret.secretCommentCiphertext,
secretCommentIV: encSecret.secretCommentIV,
secretCommentTag: encSecret.secretCommentTag,
key
});
const decryptedSecret: DecryptedSecretApprovals = {
decrypted: {
...decrypted,
id: encSecret.id
},
original: encSecret
};
decryptedSecrets.push(DecryptedSecretApprovalsSchema.parse(decryptedSecret));
}); });
return decryptedSecrets; return decryptedSecrets;
@@ -504,6 +504,21 @@ export const projectQueueFactory = ({
throw new Error("Parts of the upgrade failed. Some secrets were not updated"); throw new Error("Parts of the upgrade failed. Some secrets were not updated");
} }
const secretUpdates = await secretDAL.bulkUpdateNoVersionIncrement(updatedSecrets, tx);
const secretVersionUpdates = await secretVersionDAL.bulkUpdateNoVersionIncrement(updatedSecretVersions, tx);
const secretApprovalUpdates = await secretApprovalSecretDAL.bulkUpdateNoVersionIncrement(
updatedSecretApprovals,
tx
);
if (
secretUpdates.length !== updatedSecrets.length ||
secretVersionUpdates.length !== updatedSecretVersions.length ||
secretApprovalUpdates.length !== updatedSecretApprovals.length
) {
throw new Error("Parts of the upgrade failed. Some secrets were not updated");
}
await projectDAL.setProjectUpgradeStatus(data.projectId, null, tx); await projectDAL.setProjectUpgradeStatus(data.projectId, null, tx);
// await new Promise((resolve) => setTimeout(resolve, 15_000)); // await new Promise((resolve) => setTimeout(resolve, 15_000));