mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 17:27:40 +00:00
Refactor migration to work with conflict/merge update logic
This commit is contained in:
+195
-66
@@ -1,46 +1,45 @@
|
|||||||
import crypto from "crypto";
|
import crypto from "crypto";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { TProjectKeys } from "@app/db/schemas";
|
import {
|
||||||
import { logger } from "@app/lib/logger";
|
SecretApprovalRequestsSecretsSchema,
|
||||||
|
SecretsSchema,
|
||||||
|
SecretVersionsSchema,
|
||||||
|
TProjectKeys,
|
||||||
|
TSecretApprovalRequestsSecrets,
|
||||||
|
TSecrets,
|
||||||
|
TSecretVersions
|
||||||
|
} from "@app/db/schemas";
|
||||||
|
|
||||||
import { decryptAsymmetric } from "../crypto";
|
import { decryptAsymmetric } from "../crypto";
|
||||||
|
|
||||||
export enum SecretDocType {
|
const DecryptedValuesSchema = z.object({
|
||||||
Secret = "secret",
|
|
||||||
SecretVersion = "secretVersion",
|
|
||||||
ApprovalSecret = "approvalSecret"
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface TPartialSecret {
|
|
||||||
id: string;
|
|
||||||
secretKeyCiphertext: string;
|
|
||||||
secretKeyIV: string;
|
|
||||||
secretKeyTag: string;
|
|
||||||
|
|
||||||
secretValueCiphertext: string;
|
|
||||||
secretValueIV: string;
|
|
||||||
secretValueTag: string;
|
|
||||||
|
|
||||||
secretCommentCiphertext?: string | null;
|
|
||||||
secretCommentIV?: string | null;
|
|
||||||
secretCommentTag?: string | null;
|
|
||||||
|
|
||||||
docType: SecretDocType;
|
|
||||||
keyEncoding: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
const PartialDecryptedSecretSchema = z.object({
|
|
||||||
id: z.string(),
|
id: z.string(),
|
||||||
secretKey: z.string(),
|
secretKey: z.string(),
|
||||||
secretValue: z.string(),
|
secretValue: z.string(),
|
||||||
secretComment: z.string().optional(),
|
secretComment: z.string().optional()
|
||||||
|
|
||||||
docType: z.nativeEnum(SecretDocType)
|
|
||||||
});
|
});
|
||||||
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
|
|
||||||
|
|
||||||
const decryptSecret = ({
|
const DecryptedSecretSchema = z.object({
|
||||||
|
decrypted: DecryptedValuesSchema,
|
||||||
|
original: SecretsSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
const DecryptedSecretVersionsSchema = z.object({
|
||||||
|
decrypted: DecryptedValuesSchema,
|
||||||
|
original: SecretVersionsSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const DecryptedSecretApprovalsSchema = z.object({
|
||||||
|
decrypted: DecryptedValuesSchema,
|
||||||
|
original: SecretApprovalRequestsSecretsSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export type DecryptedSecret = z.infer<typeof DecryptedSecretSchema>;
|
||||||
|
export type DecryptedSecretVersions = z.infer<typeof DecryptedSecretVersionsSchema>;
|
||||||
|
export type DecryptedSecretApprovals = z.infer<typeof DecryptedSecretApprovalsSchema>;
|
||||||
|
|
||||||
|
const decryptCipher = ({
|
||||||
ciphertext,
|
ciphertext,
|
||||||
iv,
|
iv,
|
||||||
tag,
|
tag,
|
||||||
@@ -60,8 +59,62 @@ const decryptSecret = ({
|
|||||||
return cleartext;
|
return cleartext;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const getDecryptedValues = ({
|
||||||
|
secretKeyCiphertext,
|
||||||
|
secretKeyIV,
|
||||||
|
secretKeyTag,
|
||||||
|
secretValueCiphertext,
|
||||||
|
secretValueIV,
|
||||||
|
secretValueTag,
|
||||||
|
|
||||||
|
secretCommentCiphertext,
|
||||||
|
secretCommentIV,
|
||||||
|
secretCommentTag,
|
||||||
|
key
|
||||||
|
}: {
|
||||||
|
secretKeyCiphertext: string;
|
||||||
|
secretKeyIV: string;
|
||||||
|
secretKeyTag: string;
|
||||||
|
secretValueCiphertext: string;
|
||||||
|
secretValueIV: string;
|
||||||
|
secretValueTag: string;
|
||||||
|
secretCommentCiphertext?: string | null;
|
||||||
|
secretCommentIV?: string | null;
|
||||||
|
secretCommentTag?: string | null;
|
||||||
|
key: string | Buffer;
|
||||||
|
}) => {
|
||||||
|
const secretKey = decryptCipher({
|
||||||
|
ciphertext: secretKeyCiphertext,
|
||||||
|
iv: secretKeyIV,
|
||||||
|
tag: secretKeyTag,
|
||||||
|
key
|
||||||
|
});
|
||||||
|
|
||||||
|
const secretValue = decryptCipher({
|
||||||
|
ciphertext: secretValueCiphertext,
|
||||||
|
iv: secretValueIV,
|
||||||
|
tag: secretValueTag,
|
||||||
|
key
|
||||||
|
});
|
||||||
|
|
||||||
|
const secretComment =
|
||||||
|
secretCommentCiphertext && secretCommentIV && secretCommentTag
|
||||||
|
? decryptCipher({
|
||||||
|
ciphertext: secretCommentCiphertext,
|
||||||
|
iv: secretCommentIV,
|
||||||
|
tag: secretCommentTag,
|
||||||
|
key
|
||||||
|
})
|
||||||
|
: "";
|
||||||
|
|
||||||
|
return {
|
||||||
|
secretKey,
|
||||||
|
secretValue,
|
||||||
|
secretComment
|
||||||
|
};
|
||||||
|
};
|
||||||
export const decryptSecrets = (
|
export const decryptSecrets = (
|
||||||
encryptedSecrets: TPartialSecret[],
|
encryptedSecrets: TSecrets[],
|
||||||
privateKey: string,
|
privateKey: string,
|
||||||
latestKey: TProjectKeys & {
|
latestKey: TProjectKeys & {
|
||||||
sender: {
|
sender: {
|
||||||
@@ -76,47 +129,123 @@ export const decryptSecrets = (
|
|||||||
privateKey
|
privateKey
|
||||||
});
|
});
|
||||||
|
|
||||||
const decryptedSecrets: TPartialDecryptedSecret[] = [];
|
const decryptedSecrets: DecryptedSecret[] = [];
|
||||||
|
|
||||||
encryptedSecrets.forEach((encSecret) => {
|
encryptedSecrets.forEach((encSecret) => {
|
||||||
try {
|
const decrypted = getDecryptedValues({
|
||||||
const secretKey = decryptSecret({
|
secretKeyCiphertext: encSecret.secretKeyCiphertext,
|
||||||
ciphertext: encSecret.secretKeyCiphertext,
|
secretKeyIV: encSecret.secretKeyIV,
|
||||||
iv: encSecret.secretKeyIV,
|
secretKeyTag: encSecret.secretKeyTag,
|
||||||
tag: encSecret.secretKeyTag,
|
secretValueCiphertext: encSecret.secretValueCiphertext,
|
||||||
|
secretValueIV: encSecret.secretValueIV,
|
||||||
|
secretValueTag: encSecret.secretValueTag,
|
||||||
|
secretCommentCiphertext: encSecret.secretCommentCiphertext,
|
||||||
|
secretCommentIV: encSecret.secretCommentIV,
|
||||||
|
secretCommentTag: encSecret.secretCommentTag,
|
||||||
key
|
key
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = decryptSecret({
|
const decryptedSecret: DecryptedSecret = {
|
||||||
ciphertext: encSecret.secretValueCiphertext,
|
decrypted: {
|
||||||
iv: encSecret.secretValueIV,
|
...decrypted,
|
||||||
tag: encSecret.secretValueTag,
|
id: encSecret.id
|
||||||
key
|
},
|
||||||
});
|
original: encSecret
|
||||||
|
|
||||||
const secretComment =
|
|
||||||
encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag
|
|
||||||
? decryptSecret({
|
|
||||||
ciphertext: encSecret.secretCommentCiphertext,
|
|
||||||
iv: encSecret.secretCommentIV,
|
|
||||||
tag: encSecret.secretCommentTag,
|
|
||||||
key
|
|
||||||
})
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const decryptedSecret: TPartialDecryptedSecret = {
|
|
||||||
id: encSecret.id,
|
|
||||||
secretKey,
|
|
||||||
secretValue,
|
|
||||||
secretComment,
|
|
||||||
docType: encSecret.docType
|
|
||||||
};
|
};
|
||||||
|
|
||||||
decryptedSecrets.push(PartialDecryptedSecretSchema.parse(decryptedSecret));
|
decryptedSecrets.push(DecryptedSecretSchema.parse(decryptedSecret));
|
||||||
} catch (err) {
|
});
|
||||||
// This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets input array length.
|
|
||||||
logger.error(`[${encSecret.id}] - failed to decrypt`, err);
|
return decryptedSecrets;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const decryptSecretVersions = (
|
||||||
|
encryptedSecretVersions: TSecretVersions[],
|
||||||
|
privateKey: string,
|
||||||
|
latestKey: TProjectKeys & {
|
||||||
|
sender: {
|
||||||
|
publicKey: string;
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
) => {
|
||||||
|
const key = decryptAsymmetric({
|
||||||
|
ciphertext: latestKey.encryptedKey,
|
||||||
|
nonce: latestKey.nonce,
|
||||||
|
publicKey: latestKey.sender.publicKey,
|
||||||
|
privateKey
|
||||||
|
});
|
||||||
|
|
||||||
|
const decryptedSecrets: DecryptedSecretVersions[] = [];
|
||||||
|
|
||||||
|
encryptedSecretVersions.forEach((encSecret) => {
|
||||||
|
const decrypted = getDecryptedValues({
|
||||||
|
secretKeyCiphertext: encSecret.secretKeyCiphertext,
|
||||||
|
secretKeyIV: encSecret.secretKeyIV,
|
||||||
|
secretKeyTag: encSecret.secretKeyTag,
|
||||||
|
secretValueCiphertext: encSecret.secretValueCiphertext,
|
||||||
|
secretValueIV: encSecret.secretValueIV,
|
||||||
|
secretValueTag: encSecret.secretValueTag,
|
||||||
|
secretCommentCiphertext: encSecret.secretCommentCiphertext,
|
||||||
|
secretCommentIV: encSecret.secretCommentIV,
|
||||||
|
secretCommentTag: encSecret.secretCommentTag,
|
||||||
|
key
|
||||||
|
});
|
||||||
|
|
||||||
|
const decryptedSecret: DecryptedSecretVersions = {
|
||||||
|
decrypted: {
|
||||||
|
...decrypted,
|
||||||
|
id: encSecret.id
|
||||||
|
},
|
||||||
|
original: encSecret
|
||||||
|
};
|
||||||
|
|
||||||
|
decryptedSecrets.push(DecryptedSecretVersionsSchema.parse(decryptedSecret));
|
||||||
|
});
|
||||||
|
|
||||||
|
return decryptedSecrets;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const decryptSecretApprovals = (
|
||||||
|
encryptedSecretApprovals: TSecretApprovalRequestsSecrets[],
|
||||||
|
privateKey: string,
|
||||||
|
latestKey: TProjectKeys & {
|
||||||
|
sender: {
|
||||||
|
publicKey: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
) => {
|
||||||
|
const key = decryptAsymmetric({
|
||||||
|
ciphertext: latestKey.encryptedKey,
|
||||||
|
nonce: latestKey.nonce,
|
||||||
|
publicKey: latestKey.sender.publicKey,
|
||||||
|
privateKey
|
||||||
|
});
|
||||||
|
|
||||||
|
const decryptedSecrets: DecryptedSecretApprovals[] = [];
|
||||||
|
|
||||||
|
encryptedSecretApprovals.forEach((encSecret) => {
|
||||||
|
const decrypted = getDecryptedValues({
|
||||||
|
secretKeyCiphertext: encSecret.secretKeyCiphertext,
|
||||||
|
secretKeyIV: encSecret.secretKeyIV,
|
||||||
|
secretKeyTag: encSecret.secretKeyTag,
|
||||||
|
secretValueCiphertext: encSecret.secretValueCiphertext,
|
||||||
|
secretValueIV: encSecret.secretValueIV,
|
||||||
|
secretValueTag: encSecret.secretValueTag,
|
||||||
|
secretCommentCiphertext: encSecret.secretCommentCiphertext,
|
||||||
|
secretCommentIV: encSecret.secretCommentIV,
|
||||||
|
secretCommentTag: encSecret.secretCommentTag,
|
||||||
|
key
|
||||||
|
});
|
||||||
|
|
||||||
|
const decryptedSecret: DecryptedSecretApprovals = {
|
||||||
|
decrypted: {
|
||||||
|
...decrypted,
|
||||||
|
id: encSecret.id
|
||||||
|
},
|
||||||
|
original: encSecret
|
||||||
|
};
|
||||||
|
|
||||||
|
decryptedSecrets.push(DecryptedSecretApprovalsSchema.parse(decryptedSecret));
|
||||||
});
|
});
|
||||||
|
|
||||||
return decryptedSecrets;
|
return decryptedSecrets;
|
||||||
|
|||||||
@@ -504,6 +504,21 @@ export const projectQueueFactory = ({
|
|||||||
throw new Error("Parts of the upgrade failed. Some secrets were not updated");
|
throw new Error("Parts of the upgrade failed. Some secrets were not updated");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const secretUpdates = await secretDAL.bulkUpdateNoVersionIncrement(updatedSecrets, tx);
|
||||||
|
const secretVersionUpdates = await secretVersionDAL.bulkUpdateNoVersionIncrement(updatedSecretVersions, tx);
|
||||||
|
const secretApprovalUpdates = await secretApprovalSecretDAL.bulkUpdateNoVersionIncrement(
|
||||||
|
updatedSecretApprovals,
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
|
||||||
|
if (
|
||||||
|
secretUpdates.length !== updatedSecrets.length ||
|
||||||
|
secretVersionUpdates.length !== updatedSecretVersions.length ||
|
||||||
|
secretApprovalUpdates.length !== updatedSecretApprovals.length
|
||||||
|
) {
|
||||||
|
throw new Error("Parts of the upgrade failed. Some secrets were not updated");
|
||||||
|
}
|
||||||
|
|
||||||
await projectDAL.setProjectUpgradeStatus(data.projectId, null, tx);
|
await projectDAL.setProjectUpgradeStatus(data.projectId, null, tx);
|
||||||
|
|
||||||
// await new Promise((resolve) => setTimeout(resolve, 15_000));
|
// await new Promise((resolve) => setTimeout(resolve, 15_000));
|
||||||
|
|||||||
Reference in New Issue
Block a user