mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 22:27:22 +00:00
feat(fips): requested changes (function renaming)
This commit is contained in:
@@ -37,7 +37,7 @@ const createServiceToken = async (
|
|||||||
|
|
||||||
const randomBytes = crypto.randomBytes(16).toString("hex");
|
const randomBytes = crypto.randomBytes(16).toString("hex");
|
||||||
|
|
||||||
const { ciphertext, iv, tag } = crypto.encryption().encryptSymmetric({
|
const { ciphertext, iv, tag } = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: projectKey,
|
plaintext: projectKey,
|
||||||
key: randomBytes,
|
key: randomBytes,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -165,7 +165,7 @@ describe("Service token secret ops", async () => {
|
|||||||
const serviceTokenInfo = serviceTokenInfoRes.json();
|
const serviceTokenInfo = serviceTokenInfoRes.json();
|
||||||
const serviceTokenParts = serviceToken.split(".");
|
const serviceTokenParts = serviceToken.split(".");
|
||||||
|
|
||||||
projectKey = crypto.encryption().decryptSymmetric({
|
projectKey = crypto.encryption().symmetric().decrypt({
|
||||||
key: serviceTokenParts[3],
|
key: serviceTokenParts[3],
|
||||||
tag: serviceTokenInfo.tag,
|
tag: serviceTokenInfo.tag,
|
||||||
ciphertext: serviceTokenInfo.encryptedKey,
|
ciphertext: serviceTokenInfo.encryptedKey,
|
||||||
|
|||||||
@@ -69,12 +69,15 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
|
|
||||||
let encryptedSecretKey = null;
|
let encryptedSecretKey = null;
|
||||||
if (el.encryptedSecretKey && el.iv && el.tag && el.keyEncoding) {
|
if (el.encryptedSecretKey && el.iv && el.tag && el.keyEncoding) {
|
||||||
const decyptedSecretKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const decyptedSecretKey = crypto
|
||||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: el.iv,
|
.symmetric()
|
||||||
tag: el.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: el.encryptedSecretKey
|
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: el.iv,
|
||||||
|
tag: el.tag,
|
||||||
|
ciphertext: el.encryptedSecretKey
|
||||||
|
});
|
||||||
encryptedSecretKey = projectKmsService.encryptor({
|
encryptedSecretKey = projectKmsService.encryptor({
|
||||||
plainText: Buffer.from(decyptedSecretKey, "utf8")
|
plainText: Buffer.from(decyptedSecretKey, "utf8")
|
||||||
}).cipherTextBlob;
|
}).cipherTextBlob;
|
||||||
@@ -82,12 +85,15 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
|
|
||||||
const decryptedUrl =
|
const decryptedUrl =
|
||||||
el.urlIV && el.urlTag && el.urlCipherText && el.keyEncoding
|
el.urlIV && el.urlTag && el.urlCipherText && el.keyEncoding
|
||||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
? crypto
|
||||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: el.urlIV,
|
.symmetric()
|
||||||
tag: el.urlTag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: el.urlCipherText
|
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||||
})
|
iv: el.urlIV,
|
||||||
|
tag: el.urlTag,
|
||||||
|
ciphertext: el.urlCipherText
|
||||||
|
})
|
||||||
: null;
|
: null;
|
||||||
|
|
||||||
const encryptedUrl = projectKmsService.encryptor({
|
const encryptedUrl = projectKmsService.encryptor({
|
||||||
|
|||||||
@@ -63,20 +63,23 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.inputIV && el.inputTag && el.inputCiphertext && el.keyEncoding
|
el.inputIV && el.inputTag && el.inputCiphertext && el.keyEncoding
|
||||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
? crypto
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
.encryption()
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
.symmetric()
|
||||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
.decryptWithRootEncryptionKey({
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
iv: el.inputIV,
|
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
tag: el.inputTag,
|
iv: el.inputIV,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
ciphertext: el.inputCiphertext
|
tag: el.inputTag,
|
||||||
})
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
ciphertext: el.inputCiphertext
|
||||||
|
})
|
||||||
: "";
|
: "";
|
||||||
|
|
||||||
const encryptedInput = projectKmsService.encryptor({
|
const encryptedInput = projectKmsService.encryptor({
|
||||||
|
|||||||
@@ -56,20 +56,23 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedDataTag && el.encryptedDataIV && el.encryptedData && el.keyEncoding
|
el.encryptedDataTag && el.encryptedDataIV && el.encryptedData && el.keyEncoding
|
||||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
? crypto
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
.encryption()
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
.symmetric()
|
||||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
.decryptWithRootEncryptionKey({
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
iv: el.encryptedDataIV,
|
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
tag: el.encryptedDataTag,
|
iv: el.encryptedDataIV,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
ciphertext: el.encryptedData
|
tag: el.encryptedDataTag,
|
||||||
})
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
ciphertext: el.encryptedData
|
||||||
|
})
|
||||||
: "";
|
: "";
|
||||||
|
|
||||||
const encryptedRotationData = projectKmsService.encryptor({
|
const encryptedRotationData = projectKmsService.encryptor({
|
||||||
|
|||||||
@@ -102,18 +102,21 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
const key = crypto
|
||||||
ciphertext: encryptedSymmetricKey,
|
.encryption()
|
||||||
iv: symmetricKeyIV,
|
.symmetric()
|
||||||
tag: symmetricKeyTag,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
ciphertext: encryptedSymmetricKey,
|
||||||
});
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
const decryptedTokenReviewerJwt =
|
const decryptedTokenReviewerJwt =
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
|
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -132,7 +135,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
|||||||
@@ -75,18 +75,21 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
|||||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
const key = crypto
|
||||||
ciphertext: encryptedSymmetricKey,
|
.encryption()
|
||||||
iv: symmetricKeyIV,
|
.symmetric()
|
||||||
tag: symmetricKeyTag,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
ciphertext: encryptedSymmetricKey,
|
||||||
});
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
const decryptedCertificate =
|
const decryptedCertificate =
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
|||||||
@@ -5,12 +5,12 @@ import { crypto, SymmetricKeySize } from "@app/lib/crypto/cryptography";
|
|||||||
import { selectAllTableCols } from "@app/lib/knex";
|
import { selectAllTableCols } from "@app/lib/knex";
|
||||||
import { initLogger } from "@app/lib/logger";
|
import { initLogger } from "@app/lib/logger";
|
||||||
import { KmsDataKey } from "@app/services/kms/kms-types";
|
import { KmsDataKey } from "@app/services/kms/kms-types";
|
||||||
|
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
||||||
|
|
||||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { createCircularCache } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
const reencryptSamlConfig = async (knex: Knex) => {
|
const reencryptSamlConfig = async (knex: Knex) => {
|
||||||
@@ -61,18 +61,21 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
const key = crypto
|
||||||
ciphertext: encryptedSymmetricKey,
|
.encryption()
|
||||||
iv: symmetricKeyIV,
|
.symmetric()
|
||||||
tag: symmetricKeyTag,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
ciphertext: encryptedSymmetricKey,
|
||||||
});
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
const decryptedEntryPoint =
|
const decryptedEntryPoint =
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedEntryPoint && el.entryPointIV && el.entryPointTag
|
el.encryptedEntryPoint && el.entryPointIV && el.entryPointTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -91,7 +94,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedIssuer && el.issuerIV && el.issuerTag
|
el.encryptedIssuer && el.issuerIV && el.issuerTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -110,7 +113,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedCert && el.certIV && el.certTag
|
el.encryptedCert && el.certIV && el.certTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -224,18 +227,21 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
const key = crypto
|
||||||
ciphertext: encryptedSymmetricKey,
|
.encryption()
|
||||||
iv: symmetricKeyIV,
|
.symmetric()
|
||||||
tag: symmetricKeyTag,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
ciphertext: encryptedSymmetricKey,
|
||||||
});
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
const decryptedBindDN =
|
const decryptedBindDN =
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedBindDN && el.bindDNIV && el.bindDNTag
|
el.encryptedBindDN && el.bindDNIV && el.bindDNTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -254,7 +260,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedBindPass && el.bindPassIV && el.bindPassTag
|
el.encryptedBindPass && el.bindPassIV && el.bindPassTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -273,7 +279,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedCACert && el.caCertIV && el.caCertTag
|
el.encryptedCACert && el.caCertIV && el.caCertTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -381,18 +387,21 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
|||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
const key = crypto
|
||||||
ciphertext: encryptedSymmetricKey,
|
.encryption()
|
||||||
iv: symmetricKeyIV,
|
.symmetric()
|
||||||
tag: symmetricKeyTag,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
ciphertext: encryptedSymmetricKey,
|
||||||
});
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
const decryptedClientId =
|
const decryptedClientId =
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedClientId && el.clientIdIV && el.clientIdTag
|
el.encryptedClientId && el.clientIdIV && el.clientIdTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
@@ -411,7 +420,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
|||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
el.encryptedClientSecret && el.clientSecretIV && el.clientSecretTag
|
el.encryptedClientSecret && el.clientSecretIV && el.clientSecretTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits256,
|
keySize: SymmetricKeySize.Bits256,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
|||||||
+43
-30
@@ -84,7 +84,7 @@ export const generateUserSrpKeys = async (password: string) => {
|
|||||||
ciphertext: encryptedPrivateKey,
|
ciphertext: encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag
|
tag: encryptedPrivateKeyTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: privateKey,
|
plaintext: privateKey,
|
||||||
key,
|
key,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -98,7 +98,8 @@ export const generateUserSrpKeys = async (password: string) => {
|
|||||||
tag: protectedKeyTag
|
tag: protectedKeyTag
|
||||||
} = crypto
|
} = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
.encryptSymmetric({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
|
.symmetric()
|
||||||
|
.encrypt({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
|
||||||
|
|
||||||
return {
|
return {
|
||||||
protectedKey,
|
protectedKey,
|
||||||
@@ -125,21 +126,27 @@ export const getUserPrivateKey = async (password: string, user: TUserEncryptionK
|
|||||||
});
|
});
|
||||||
if (!derivedKey) throw new Error("Failed to derive key from password");
|
if (!derivedKey) throw new Error("Failed to derive key from password");
|
||||||
|
|
||||||
const key = crypto.encryption().decryptSymmetric({
|
const key = crypto
|
||||||
ciphertext: user.protectedKey as string,
|
.encryption()
|
||||||
iv: user.protectedKeyIV as string,
|
.symmetric()
|
||||||
tag: user.protectedKeyTag as string,
|
.decrypt({
|
||||||
key: derivedKey,
|
ciphertext: user.protectedKey as string,
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: user.protectedKeyIV as string,
|
||||||
});
|
tag: user.protectedKeyTag as string,
|
||||||
|
key: derivedKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const privateKey = crypto.encryption().decryptSymmetric({
|
const privateKey = crypto
|
||||||
ciphertext: user.encryptedPrivateKey,
|
.encryption()
|
||||||
iv: user.iv,
|
.symmetric()
|
||||||
tag: user.tag,
|
.decrypt({
|
||||||
key: Buffer.from(key, "hex"),
|
ciphertext: user.encryptedPrivateKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: user.iv,
|
||||||
});
|
tag: user.tag,
|
||||||
|
key: Buffer.from(key, "hex"),
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
return privateKey;
|
return privateKey;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -164,7 +171,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
|||||||
ciphertext: secretKeyCiphertext,
|
ciphertext: secretKeyCiphertext,
|
||||||
iv: secretKeyIV,
|
iv: secretKeyIV,
|
||||||
tag: secretKeyTag
|
tag: secretKeyTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: key,
|
plaintext: key,
|
||||||
key: encKey,
|
key: encKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -175,22 +182,28 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
|||||||
ciphertext: secretValueCiphertext,
|
ciphertext: secretValueCiphertext,
|
||||||
iv: secretValueIV,
|
iv: secretValueIV,
|
||||||
tag: secretValueTag
|
tag: secretValueTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto
|
||||||
plaintext: value ?? "",
|
.encryption()
|
||||||
key: encKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: value ?? "",
|
||||||
|
key: encKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
// encrypt comment
|
// encrypt comment
|
||||||
const {
|
const {
|
||||||
ciphertext: secretCommentCiphertext,
|
ciphertext: secretCommentCiphertext,
|
||||||
iv: secretCommentIV,
|
iv: secretCommentIV,
|
||||||
tag: secretCommentTag
|
tag: secretCommentTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto
|
||||||
plaintext: comment ?? "",
|
.encryption()
|
||||||
key: encKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: comment ?? "",
|
||||||
|
key: encKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
secretKeyCiphertext,
|
secretKeyCiphertext,
|
||||||
@@ -206,7 +219,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
|||||||
};
|
};
|
||||||
|
|
||||||
export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
key: decryptKey,
|
key: decryptKey,
|
||||||
ciphertext: encSecret.secretKeyCiphertext,
|
ciphertext: encSecret.secretKeyCiphertext,
|
||||||
tag: encSecret.secretKeyTag,
|
tag: encSecret.secretKeyTag,
|
||||||
@@ -214,7 +227,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
|||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = crypto.encryption().decryptSymmetric({
|
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||||
key: decryptKey,
|
key: decryptKey,
|
||||||
ciphertext: encSecret.secretValueCiphertext,
|
ciphertext: encSecret.secretValueCiphertext,
|
||||||
tag: encSecret.secretValueTag,
|
tag: encSecret.secretValueTag,
|
||||||
@@ -224,7 +237,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
|||||||
|
|
||||||
const secretComment =
|
const secretComment =
|
||||||
encSecret.secretCommentIV && encSecret.secretCommentTag && encSecret.secretCommentCiphertext
|
encSecret.secretCommentIV && encSecret.secretCommentTag && encSecret.secretCommentCiphertext
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
key: decryptKey,
|
key: decryptKey,
|
||||||
ciphertext: encSecret.secretCommentCiphertext,
|
ciphertext: encSecret.secretCommentCiphertext,
|
||||||
tag: encSecret.secretCommentTag,
|
tag: encSecret.secretCommentTag,
|
||||||
|
|||||||
@@ -70,7 +70,7 @@ export async function seed(knex: Knex): Promise<void> {
|
|||||||
const encKey = process.env.ENCRYPTION_KEY;
|
const encKey = process.env.ENCRYPTION_KEY;
|
||||||
if (!encKey) throw new Error("Missing ENCRYPTION_KEY");
|
if (!encKey) throw new Error("Missing ENCRYPTION_KEY");
|
||||||
const salt = crypto.randomBytes(16).toString("base64");
|
const salt = crypto.randomBytes(16).toString("base64");
|
||||||
const secretBlindIndex = crypto.encryption().encryptSymmetric({
|
const secretBlindIndex = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: salt,
|
plaintext: salt,
|
||||||
key: encKey,
|
key: encKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
|||||||
@@ -88,7 +88,7 @@ export const auditLogStreamServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
const encryptedHeaders = headers
|
const encryptedHeaders = headers
|
||||||
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||||
: undefined;
|
: undefined;
|
||||||
const logStream = await auditLogStreamDAL.create({
|
const logStream = await auditLogStreamDAL.create({
|
||||||
orgId: actorOrgId,
|
orgId: actorOrgId,
|
||||||
@@ -156,7 +156,7 @@ export const auditLogStreamServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
const encryptedHeaders = headers
|
const encryptedHeaders = headers
|
||||||
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||||
: undefined;
|
: undefined;
|
||||||
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
||||||
url,
|
url,
|
||||||
@@ -210,12 +210,15 @@ export const auditLogStreamServiceFactory = ({
|
|||||||
const headers =
|
const headers =
|
||||||
logStream?.encryptedHeadersCiphertext && logStream?.encryptedHeadersIV && logStream?.encryptedHeadersTag
|
logStream?.encryptedHeadersCiphertext && logStream?.encryptedHeadersIV && logStream?.encryptedHeadersTag
|
||||||
? (JSON.parse(
|
? (JSON.parse(
|
||||||
crypto.encryption().decryptWithRootEncryptionKey({
|
crypto
|
||||||
tag: logStream.encryptedHeadersTag,
|
.encryption()
|
||||||
iv: logStream.encryptedHeadersIV,
|
.symmetric()
|
||||||
ciphertext: logStream.encryptedHeadersCiphertext,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: logStream.encryptedHeadersKeyEncoding as SecretKeyEncoding
|
tag: logStream.encryptedHeadersTag,
|
||||||
})
|
iv: logStream.encryptedHeadersIV,
|
||||||
|
ciphertext: logStream.encryptedHeadersCiphertext,
|
||||||
|
keyEncoding: logStream.encryptedHeadersKeyEncoding as SecretKeyEncoding
|
||||||
|
})
|
||||||
) as LogStreamHeaders[])
|
) as LogStreamHeaders[])
|
||||||
: undefined;
|
: undefined;
|
||||||
|
|
||||||
|
|||||||
@@ -114,12 +114,15 @@ export const auditLogQueueServiceFactory = async ({
|
|||||||
const streamHeaders =
|
const streamHeaders =
|
||||||
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
||||||
? (JSON.parse(
|
? (JSON.parse(
|
||||||
crypto.encryption().decryptWithRootEncryptionKey({
|
crypto
|
||||||
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: encryptedHeadersIV,
|
.symmetric()
|
||||||
tag: encryptedHeadersTag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: encryptedHeadersCiphertext
|
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
||||||
})
|
iv: encryptedHeadersIV,
|
||||||
|
tag: encryptedHeadersTag,
|
||||||
|
ciphertext: encryptedHeadersCiphertext
|
||||||
|
})
|
||||||
) as LogStreamHeaders[])
|
) as LogStreamHeaders[])
|
||||||
: [];
|
: [];
|
||||||
|
|
||||||
@@ -216,12 +219,15 @@ export const auditLogQueueServiceFactory = async ({
|
|||||||
const streamHeaders =
|
const streamHeaders =
|
||||||
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
||||||
? (JSON.parse(
|
? (JSON.parse(
|
||||||
crypto.encryption().decryptWithRootEncryptionKey({
|
crypto
|
||||||
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: encryptedHeadersIV,
|
.symmetric()
|
||||||
tag: encryptedHeadersTag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: encryptedHeadersCiphertext
|
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
||||||
})
|
iv: encryptedHeadersIV,
|
||||||
|
tag: encryptedHeadersTag,
|
||||||
|
ciphertext: encryptedHeadersCiphertext
|
||||||
|
})
|
||||||
) as LogStreamHeaders[])
|
) as LogStreamHeaders[])
|
||||||
: [];
|
: [];
|
||||||
|
|
||||||
|
|||||||
@@ -94,12 +94,15 @@ const addAcceptedUsersToGroup = async ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const botPrivateKey = crypto
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: bot.iv,
|
.symmetric()
|
||||||
tag: bot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: bot.encryptedPrivateKey
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: bot.iv,
|
||||||
|
tag: bot.tag,
|
||||||
|
ciphertext: bot.encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
const plaintextProjectKey = crypto.encryption().asymmetric().decrypt({
|
const plaintextProjectKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: ghostUserLatestKey.encryptedKey,
|
ciphertext: ghostUserLatestKey.encryptedKey,
|
||||||
|
|||||||
@@ -820,7 +820,7 @@ export const secretApprovalRequestServiceFactory = ({
|
|||||||
type: SecretType.Shared,
|
type: SecretType.Shared,
|
||||||
references: botKey
|
references: botKey
|
||||||
? getAllNestedSecretReferences(
|
? getAllNestedSecretReferences(
|
||||||
crypto.encryption().decryptSymmetric({
|
crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
@@ -866,7 +866,7 @@ export const secretApprovalRequestServiceFactory = ({
|
|||||||
]),
|
]),
|
||||||
references: botKey
|
references: botKey
|
||||||
? getAllNestedSecretReferences(
|
? getAllNestedSecretReferences(
|
||||||
crypto.encryption().decryptSymmetric({
|
crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
|
|||||||
@@ -100,7 +100,7 @@ const getReplicationKeyLockPrefix = (projectId: string, environmentSlug: string,
|
|||||||
export const getReplicationFolderName = (importId: string) => `${ReservedFolders.SecretReplication}${importId}`;
|
export const getReplicationFolderName = (importId: string) => `${ReservedFolders.SecretReplication}${importId}`;
|
||||||
|
|
||||||
const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
|
const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -108,7 +108,7 @@ const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
|
|||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = crypto.encryption().decryptSymmetric({
|
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
|
|||||||
+11
-8
@@ -372,14 +372,17 @@ export const secretRotationQueueFactory = ({
|
|||||||
|
|
||||||
const encryptedSecrets = rotationOutputs.map(({ key: outputKey, secretId }) => ({
|
const encryptedSecrets = rotationOutputs.map(({ key: outputKey, secretId }) => ({
|
||||||
secretId,
|
secretId,
|
||||||
value: crypto.encryption().encryptSymmetric({
|
value: crypto
|
||||||
plaintext:
|
.encryption()
|
||||||
typeof newCredential.outputs[outputKey] === "object"
|
.symmetric()
|
||||||
? JSON.stringify(newCredential.outputs[outputKey])
|
.encrypt({
|
||||||
: String(newCredential.outputs[outputKey]),
|
plaintext:
|
||||||
key: botKey,
|
typeof newCredential.outputs[outputKey] === "object"
|
||||||
keySize: SymmetricKeySize.Bits128
|
? JSON.stringify(newCredential.outputs[outputKey])
|
||||||
})
|
: String(newCredential.outputs[outputKey]),
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
})
|
||||||
}));
|
}));
|
||||||
|
|
||||||
// map the final values to output keys in the board
|
// map the final values to output keys in the board
|
||||||
|
|||||||
@@ -235,7 +235,7 @@ export const secretRotationServiceFactory = ({
|
|||||||
secret: {
|
secret: {
|
||||||
id: output.secret.id,
|
id: output.secret.id,
|
||||||
version: output.secret.version,
|
version: output.secret.version,
|
||||||
secretKey: crypto.encryption().decryptSymmetric({
|
secretKey: crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: output.secret.secretKeyCiphertext,
|
ciphertext: output.secret.secretKeyCiphertext,
|
||||||
iv: output.secret.secretKeyIV,
|
iv: output.secret.secretKeyIV,
|
||||||
tag: output.secret.secretKeyTag,
|
tag: output.secret.secretKeyTag,
|
||||||
|
|||||||
@@ -237,7 +237,7 @@ export const secretSnapshotServiceFactory = ({
|
|||||||
snapshotDetails = {
|
snapshotDetails = {
|
||||||
...encryptedSnapshotDetails,
|
...encryptedSnapshotDetails,
|
||||||
secretVersions: encryptedSnapshotDetails.secretVersions.map((el) => {
|
secretVersions: encryptedSnapshotDetails.secretVersions.map((el) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretKeyCiphertext,
|
ciphertext: el.secretKeyCiphertext,
|
||||||
iv: el.secretKeyIV,
|
iv: el.secretKeyIV,
|
||||||
tag: el.secretKeyTag,
|
tag: el.secretKeyTag,
|
||||||
@@ -259,7 +259,7 @@ export const secretSnapshotServiceFactory = ({
|
|||||||
let secretValue = "";
|
let secretValue = "";
|
||||||
|
|
||||||
if (canReadValue) {
|
if (canReadValue) {
|
||||||
secretValue = crypto.encryption().decryptSymmetric({
|
secretValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
@@ -277,7 +277,7 @@ export const secretSnapshotServiceFactory = ({
|
|||||||
secretValue,
|
secretValue,
|
||||||
secretComment:
|
secretComment:
|
||||||
el.secretCommentTag && el.secretCommentIV && el.secretCommentCiphertext
|
el.secretCommentTag && el.secretCommentIV && el.secretCommentCiphertext
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretCommentCiphertext,
|
ciphertext: el.secretCommentCiphertext,
|
||||||
iv: el.secretCommentIV,
|
iv: el.secretCommentIV,
|
||||||
tag: el.secretCommentTag,
|
tag: el.secretCommentTag,
|
||||||
|
|||||||
@@ -221,122 +221,134 @@ const cryptographyFactory = () => {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
const decryptSymmetric = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
|
const symmetric = () => {
|
||||||
let decipher;
|
const decrypt = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
|
||||||
|
let decipher;
|
||||||
|
|
||||||
if (keySize === SymmetricKeySize.Bits128) {
|
if (keySize === SymmetricKeySize.Bits128) {
|
||||||
// Not ideal: 128-bit hex key (32 chars) gets interpreted as 32 UTF-8 bytes (256 bits)
|
// Not ideal: 128-bit hex key (32 chars) gets interpreted as 32 UTF-8 bytes (256 bits)
|
||||||
// This works but reduces effective key entropy from 256 to 128 bits
|
// This works but reduces effective key entropy from 256 to 128 bits
|
||||||
decipher = crypto.createDecipheriv(SecretEncryptionAlgo.AES_256_GCM, key, Buffer.from(iv, "base64"));
|
decipher = crypto.createDecipheriv(SecretEncryptionAlgo.AES_256_GCM, key, Buffer.from(iv, "base64"));
|
||||||
} else {
|
} else {
|
||||||
const secretKey = crypto.createSecretKey(key, "base64");
|
const secretKey = crypto.createSecretKey(key, "base64");
|
||||||
decipher = crypto.createDecipheriv(SecretEncryptionAlgo.AES_256_GCM, secretKey, Buffer.from(iv, "base64"));
|
decipher = crypto.createDecipheriv(SecretEncryptionAlgo.AES_256_GCM, secretKey, Buffer.from(iv, "base64"));
|
||||||
}
|
}
|
||||||
|
|
||||||
decipher.setAuthTag(Buffer.from(tag, "base64"));
|
decipher.setAuthTag(Buffer.from(tag, "base64"));
|
||||||
let cleartext = decipher.update(ciphertext, "base64", "utf8");
|
let cleartext = decipher.update(ciphertext, "base64", "utf8");
|
||||||
cleartext += decipher.final("utf8");
|
cleartext += decipher.final("utf8");
|
||||||
|
|
||||||
return cleartext;
|
return cleartext;
|
||||||
};
|
};
|
||||||
|
|
||||||
const encryptSymmetric = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
|
const encrypt = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
|
||||||
let iv;
|
let iv;
|
||||||
let cipher;
|
let cipher;
|
||||||
|
|
||||||
if (keySize === SymmetricKeySize.Bits128) {
|
if (keySize === SymmetricKeySize.Bits128) {
|
||||||
iv = crypto.randomBytes(BLOCK_SIZE_BYTES_16);
|
iv = crypto.randomBytes(BLOCK_SIZE_BYTES_16);
|
||||||
cipher = crypto.createCipheriv(SecretEncryptionAlgo.AES_256_GCM, key, iv);
|
cipher = crypto.createCipheriv(SecretEncryptionAlgo.AES_256_GCM, key, iv);
|
||||||
} else {
|
} else {
|
||||||
iv = crypto.randomBytes(IV_BYTES_SIZE);
|
iv = crypto.randomBytes(IV_BYTES_SIZE);
|
||||||
cipher = crypto.createCipheriv(SecretEncryptionAlgo.AES_256_GCM, crypto.createSecretKey(key, "base64"), iv);
|
cipher = crypto.createCipheriv(SecretEncryptionAlgo.AES_256_GCM, crypto.createSecretKey(key, "base64"), iv);
|
||||||
}
|
}
|
||||||
|
|
||||||
let ciphertext = cipher.update(plaintext, "utf8", "base64");
|
let ciphertext = cipher.update(plaintext, "utf8", "base64");
|
||||||
ciphertext += cipher.final("base64");
|
ciphertext += cipher.final("base64");
|
||||||
|
|
||||||
|
return {
|
||||||
|
ciphertext,
|
||||||
|
iv: iv.toString("base64"),
|
||||||
|
tag: cipher.getAuthTag().toString("base64")
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
const encryptWithRootEncryptionKey = (data: string) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
const rootEncryptionKey = appCfg.ROOT_ENCRYPTION_KEY;
|
||||||
|
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
||||||
|
|
||||||
|
if (rootEncryptionKey) {
|
||||||
|
const { iv, tag, ciphertext } = encrypt({
|
||||||
|
plaintext: data,
|
||||||
|
key: rootEncryptionKey,
|
||||||
|
keySize: SymmetricKeySize.Bits256
|
||||||
|
});
|
||||||
|
return {
|
||||||
|
iv,
|
||||||
|
tag,
|
||||||
|
ciphertext,
|
||||||
|
algorithm: SecretEncryptionAlgo.AES_256_GCM,
|
||||||
|
encoding: SecretKeyEncoding.BASE64
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (encryptionKey) {
|
||||||
|
const { iv, tag, ciphertext } = encrypt({
|
||||||
|
plaintext: data,
|
||||||
|
key: encryptionKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
return {
|
||||||
|
iv,
|
||||||
|
tag,
|
||||||
|
ciphertext,
|
||||||
|
algorithm: SecretEncryptionAlgo.AES_256_GCM,
|
||||||
|
encoding: SecretKeyEncoding.UTF8
|
||||||
|
};
|
||||||
|
}
|
||||||
|
throw new CryptographyError({
|
||||||
|
message: "Missing both encryption keys"
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
const decryptWithRootEncryptionKey = <T = string>({
|
||||||
|
keyEncoding,
|
||||||
|
ciphertext,
|
||||||
|
tag,
|
||||||
|
iv
|
||||||
|
}: Omit<TDecryptSymmetricInput, "key" | "keySize"> & {
|
||||||
|
keyEncoding: SecretKeyEncoding;
|
||||||
|
}) => {
|
||||||
|
const appCfg = getConfig();
|
||||||
|
// the or gate is used used in migration
|
||||||
|
const rootEncryptionKey = appCfg?.ROOT_ENCRYPTION_KEY || process.env.ROOT_ENCRYPTION_KEY;
|
||||||
|
const encryptionKey = appCfg?.ENCRYPTION_KEY || process.env.ENCRYPTION_KEY;
|
||||||
|
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
||||||
|
const data = symmetric().decrypt({
|
||||||
|
key: rootEncryptionKey,
|
||||||
|
iv,
|
||||||
|
tag,
|
||||||
|
ciphertext,
|
||||||
|
keySize: SymmetricKeySize.Bits256
|
||||||
|
});
|
||||||
|
return data as T;
|
||||||
|
}
|
||||||
|
if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
||||||
|
const data = symmetric().decrypt({
|
||||||
|
key: encryptionKey,
|
||||||
|
iv,
|
||||||
|
tag,
|
||||||
|
ciphertext,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
return data as T;
|
||||||
|
}
|
||||||
|
throw new CryptographyError({
|
||||||
|
message: "Missing both encryption keys"
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
ciphertext,
|
decrypt,
|
||||||
iv: iv.toString("base64"),
|
encrypt,
|
||||||
tag: cipher.getAuthTag().toString("base64")
|
encryptWithRootEncryptionKey,
|
||||||
|
decryptWithRootEncryptionKey
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
const encryptWithRootEncryptionKey = (data: string) => {
|
|
||||||
const appCfg = getConfig();
|
|
||||||
const rootEncryptionKey = appCfg.ROOT_ENCRYPTION_KEY;
|
|
||||||
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
|
||||||
|
|
||||||
if (rootEncryptionKey) {
|
|
||||||
const { iv, tag, ciphertext } = encryptSymmetric({
|
|
||||||
plaintext: data,
|
|
||||||
key: rootEncryptionKey,
|
|
||||||
keySize: SymmetricKeySize.Bits256
|
|
||||||
});
|
|
||||||
return {
|
|
||||||
iv,
|
|
||||||
tag,
|
|
||||||
ciphertext,
|
|
||||||
algorithm: SecretEncryptionAlgo.AES_256_GCM,
|
|
||||||
encoding: SecretKeyEncoding.BASE64
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (encryptionKey) {
|
|
||||||
const { iv, tag, ciphertext } = encryptSymmetric({
|
|
||||||
plaintext: data,
|
|
||||||
key: encryptionKey,
|
|
||||||
keySize: SymmetricKeySize.Bits128
|
|
||||||
});
|
|
||||||
return {
|
|
||||||
iv,
|
|
||||||
tag,
|
|
||||||
ciphertext,
|
|
||||||
algorithm: SecretEncryptionAlgo.AES_256_GCM,
|
|
||||||
encoding: SecretKeyEncoding.UTF8
|
|
||||||
};
|
|
||||||
}
|
|
||||||
throw new CryptographyError({
|
|
||||||
message: "Missing both encryption keys"
|
|
||||||
});
|
|
||||||
};
|
|
||||||
|
|
||||||
const decryptWithRootEncryptionKey = <T = string>({
|
|
||||||
keyEncoding,
|
|
||||||
ciphertext,
|
|
||||||
tag,
|
|
||||||
iv
|
|
||||||
}: Omit<TDecryptSymmetricInput, "key" | "keySize"> & {
|
|
||||||
keyEncoding: SecretKeyEncoding;
|
|
||||||
}) => {
|
|
||||||
const appCfg = getConfig();
|
|
||||||
// the or gate is used used in migration
|
|
||||||
const rootEncryptionKey = appCfg?.ROOT_ENCRYPTION_KEY || process.env.ROOT_ENCRYPTION_KEY;
|
|
||||||
const encryptionKey = appCfg?.ENCRYPTION_KEY || process.env.ENCRYPTION_KEY;
|
|
||||||
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
|
||||||
const data = decryptSymmetric({
|
|
||||||
key: rootEncryptionKey,
|
|
||||||
iv,
|
|
||||||
tag,
|
|
||||||
ciphertext,
|
|
||||||
keySize: SymmetricKeySize.Bits256
|
|
||||||
});
|
|
||||||
return data as T;
|
|
||||||
}
|
|
||||||
if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
|
||||||
const data = decryptSymmetric({ key: encryptionKey, iv, tag, ciphertext, keySize: SymmetricKeySize.Bits128 });
|
|
||||||
return data as T;
|
|
||||||
}
|
|
||||||
throw new CryptographyError({
|
|
||||||
message: "Missing both encryption keys"
|
|
||||||
});
|
|
||||||
};
|
|
||||||
|
|
||||||
return {
|
return {
|
||||||
asymmetric,
|
asymmetric,
|
||||||
encryptWithRootEncryptionKey,
|
symmetric
|
||||||
decryptWithRootEncryptionKey,
|
|
||||||
encryptSymmetric,
|
|
||||||
decryptSymmetric
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -32,11 +32,13 @@ export const buildSecretBlindIndexFromName = async ({
|
|||||||
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
||||||
salt = crypto
|
salt = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
.decryptSymmetric({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
|
.symmetric()
|
||||||
|
.decrypt({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
|
||||||
} else if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
} else if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
||||||
salt = crypto
|
salt = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
.decryptSymmetric({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
|
.symmetric()
|
||||||
|
.decrypt({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
|
||||||
}
|
}
|
||||||
if (!salt) throw new Error("Missing secret blind index key");
|
if (!salt) throw new Error("Missing secret blind index key");
|
||||||
|
|
||||||
|
|||||||
@@ -74,11 +74,14 @@ export const generateUserSrpKeys = async (
|
|||||||
ciphertext: encryptedPrivateKey,
|
ciphertext: encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag
|
tag: encryptedPrivateKeyTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto
|
||||||
plaintext: privateKey,
|
.encryption()
|
||||||
key: key.toString("base64"),
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits256
|
.encrypt({
|
||||||
});
|
plaintext: privateKey,
|
||||||
|
key: key.toString("base64"),
|
||||||
|
keySize: SymmetricKeySize.Bits256
|
||||||
|
});
|
||||||
|
|
||||||
// create the protected key by encrypting the symmetric key
|
// create the protected key by encrypting the symmetric key
|
||||||
// [key] with the derived key
|
// [key] with the derived key
|
||||||
@@ -86,11 +89,14 @@ export const generateUserSrpKeys = async (
|
|||||||
ciphertext: protectedKey,
|
ciphertext: protectedKey,
|
||||||
iv: protectedKeyIV,
|
iv: protectedKeyIV,
|
||||||
tag: protectedKeyTag
|
tag: protectedKeyTag
|
||||||
} = crypto.encryption().encryptSymmetric({
|
} = crypto
|
||||||
plaintext: key.toString("hex"),
|
.encryption()
|
||||||
key: derivedKey.toString("base64"),
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits256
|
.encrypt({
|
||||||
});
|
plaintext: key.toString("hex"),
|
||||||
|
key: derivedKey.toString("base64"),
|
||||||
|
keySize: SymmetricKeySize.Bits256
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
protectedKey,
|
protectedKey,
|
||||||
@@ -121,13 +127,16 @@ export const getUserPrivateKey = async (
|
|||||||
>
|
>
|
||||||
) => {
|
) => {
|
||||||
if (user.encryptionVersion === UserEncryption.V1) {
|
if (user.encryptionVersion === UserEncryption.V1) {
|
||||||
return crypto.encryption().decryptSymmetric({
|
return crypto
|
||||||
ciphertext: user.encryptedPrivateKey,
|
.encryption()
|
||||||
iv: user.iv,
|
.symmetric()
|
||||||
tag: user.tag,
|
.decrypt({
|
||||||
key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0"),
|
ciphertext: user.encryptedPrivateKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: user.iv,
|
||||||
});
|
tag: user.tag,
|
||||||
|
key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0"),
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
}
|
}
|
||||||
if (
|
if (
|
||||||
user.encryptionVersion === UserEncryption.V2 &&
|
user.encryptionVersion === UserEncryption.V2 &&
|
||||||
@@ -145,7 +154,7 @@ export const getUserPrivateKey = async (
|
|||||||
raw: true
|
raw: true
|
||||||
});
|
});
|
||||||
if (!derivedKey) throw new Error("Failed to derive key from password");
|
if (!derivedKey) throw new Error("Failed to derive key from password");
|
||||||
const key = crypto.encryption().decryptSymmetric({
|
const key = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: user.protectedKey,
|
ciphertext: user.protectedKey,
|
||||||
iv: user.protectedKeyIV,
|
iv: user.protectedKeyIV,
|
||||||
tag: user.protectedKeyTag,
|
tag: user.protectedKeyTag,
|
||||||
@@ -153,13 +162,16 @@ export const getUserPrivateKey = async (
|
|||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const privateKey = crypto.encryption().decryptSymmetric({
|
const privateKey = crypto
|
||||||
ciphertext: user.encryptedPrivateKey,
|
.encryption()
|
||||||
iv: user.iv,
|
.symmetric()
|
||||||
tag: user.tag,
|
.decrypt({
|
||||||
key: Buffer.from(key, "hex"),
|
ciphertext: user.encryptedPrivateKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: user.iv,
|
||||||
});
|
tag: user.tag,
|
||||||
|
key: Buffer.from(key, "hex"),
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
return privateKey;
|
return privateKey;
|
||||||
}
|
}
|
||||||
throw new Error(`GetUserPrivateKey: Encryption version not found`);
|
throw new Error(`GetUserPrivateKey: Encryption version not found`);
|
||||||
|
|||||||
@@ -336,7 +336,10 @@ export const authLoginServiceFactory = ({
|
|||||||
|
|
||||||
const hashedPassword = await crypto.hashing().createHash(password, cfg.SALT_ROUNDS);
|
const hashedPassword = await crypto.hashing().createHash(password, cfg.SALT_ROUNDS);
|
||||||
|
|
||||||
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
const { iv, tag, ciphertext, encoding } = crypto
|
||||||
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encryptWithRootEncryptionKey(privateKey);
|
||||||
|
|
||||||
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
|
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
|
||||||
serverPrivateKey: null,
|
serverPrivateKey: null,
|
||||||
|
|||||||
@@ -222,12 +222,15 @@ export const authPaswordServiceFactory = ({
|
|||||||
user.serverEncryptedPrivateKeyEncoding &&
|
user.serverEncryptedPrivateKeyEncoding &&
|
||||||
user.encryptionVersion === UserEncryption.V2
|
user.encryptionVersion === UserEncryption.V2
|
||||||
) {
|
) {
|
||||||
privateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
privateKey = crypto
|
||||||
iv: user.serverEncryptedPrivateKeyIV,
|
.encryption()
|
||||||
tag: user.serverEncryptedPrivateKeyTag,
|
.symmetric()
|
||||||
ciphertext: user.serverEncryptedPrivateKey,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: user.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
iv: user.serverEncryptedPrivateKeyIV,
|
||||||
});
|
tag: user.serverEncryptedPrivateKeyTag,
|
||||||
|
ciphertext: user.serverEncryptedPrivateKey,
|
||||||
|
keyEncoding: user.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
} else {
|
} else {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Cannot reset password without current credentials or recovery method",
|
message: "Cannot reset password without current credentials or recovery method",
|
||||||
@@ -240,7 +243,7 @@ export const authPaswordServiceFactory = ({
|
|||||||
privateKey
|
privateKey
|
||||||
});
|
});
|
||||||
|
|
||||||
const { tag, iv, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
const { tag, iv, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||||
|
|
||||||
await userDAL.updateUserEncryptionByUserId(userId, {
|
await userDAL.updateUserEncryptionByUserId(userId, {
|
||||||
hashedPassword: newHashedPassword,
|
hashedPassword: newHashedPassword,
|
||||||
|
|||||||
@@ -201,7 +201,7 @@ export const authSignupServiceFactory = ({
|
|||||||
tag: encryptedPrivateKeyTag,
|
tag: encryptedPrivateKeyTag,
|
||||||
encryptionVersion: UserEncryption.V2
|
encryptionVersion: UserEncryption.V2
|
||||||
});
|
});
|
||||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||||
const updateduser = await authDAL.transaction(async (tx) => {
|
const updateduser = await authDAL.transaction(async (tx) => {
|
||||||
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
||||||
if (!us) throw new Error("User not found");
|
if (!us) throw new Error("User not found");
|
||||||
@@ -222,12 +222,15 @@ export const authSignupServiceFactory = ({
|
|||||||
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
||||||
) {
|
) {
|
||||||
// get server generated password
|
// get server generated password
|
||||||
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
|
const serverGeneratedPassword = crypto
|
||||||
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
.encryption()
|
||||||
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
.symmetric()
|
||||||
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
||||||
});
|
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
||||||
|
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
||||||
|
keyEncoding: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
const serverGeneratedPrivateKey = await getUserPrivateKey(serverGeneratedPassword, {
|
const serverGeneratedPrivateKey = await getUserPrivateKey(serverGeneratedPassword, {
|
||||||
...systemGeneratedUserEncryptionKey
|
...systemGeneratedUserEncryptionKey
|
||||||
});
|
});
|
||||||
@@ -444,7 +447,7 @@ export const authSignupServiceFactory = ({
|
|||||||
tag: encryptedPrivateKeyTag,
|
tag: encryptedPrivateKeyTag,
|
||||||
encryptionVersion: 2
|
encryptionVersion: 2
|
||||||
});
|
});
|
||||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||||
const updateduser = await authDAL.transaction(async (tx) => {
|
const updateduser = await authDAL.transaction(async (tx) => {
|
||||||
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
||||||
if (!us) throw new Error("User not found");
|
if (!us) throw new Error("User not found");
|
||||||
@@ -461,12 +464,15 @@ export const authSignupServiceFactory = ({
|
|||||||
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
||||||
) {
|
) {
|
||||||
// get server generated password
|
// get server generated password
|
||||||
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
|
const serverGeneratedPassword = crypto
|
||||||
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
.encryption()
|
||||||
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
.symmetric()
|
||||||
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
||||||
});
|
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
||||||
|
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
||||||
|
keyEncoding: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
const serverGeneratedPrivateKey = await getUserPrivateKey(serverGeneratedPassword, {
|
const serverGeneratedPrivateKey = await getUserPrivateKey(serverGeneratedPassword, {
|
||||||
...systemGeneratedUserEncryptionKey
|
...systemGeneratedUserEncryptionKey
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -98,7 +98,7 @@ export const externalMigrationQueueFactory = ({
|
|||||||
template: SmtpTemplates.ExternalImportStarted
|
template: SmtpTemplates.ExternalImportStarted
|
||||||
});
|
});
|
||||||
|
|
||||||
const decrypted = crypto.encryption().decryptWithRootEncryptionKey({
|
const decrypted = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
|
||||||
ciphertext: data.ciphertext,
|
ciphertext: data.ciphertext,
|
||||||
iv: data.iv,
|
iv: data.iv,
|
||||||
keyEncoding: data.encoding,
|
keyEncoding: data.encoding,
|
||||||
|
|||||||
@@ -56,7 +56,7 @@ export const externalMigrationServiceFactory = ({
|
|||||||
actorAuthMethod
|
actorAuthMethod
|
||||||
});
|
});
|
||||||
|
|
||||||
const encrypted = crypto.encryption().encryptWithRootEncryptionKey(stringifiedJson);
|
const encrypted = crypto.encryption().symmetric().encryptWithRootEncryptionKey(stringifiedJson);
|
||||||
|
|
||||||
await externalMigrationQueue.startImport({
|
await externalMigrationQueue.startImport({
|
||||||
actorEmail: user.email!,
|
actorEmail: user.email!,
|
||||||
|
|||||||
@@ -212,12 +212,15 @@ export const groupProjectServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const botPrivateKey = crypto
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: bot.iv,
|
.symmetric()
|
||||||
tag: bot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: bot.encryptedPrivateKey
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: bot.iv,
|
||||||
|
tag: bot.tag,
|
||||||
|
ciphertext: bot.encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
const plaintextProjectKey = crypto.encryption().asymmetric().decrypt({
|
const plaintextProjectKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: ghostUserLatestKey.encryptedKey,
|
ciphertext: ghostUserLatestKey.encryptedKey,
|
||||||
|
|||||||
@@ -218,7 +218,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
} else {
|
} else {
|
||||||
if (!botKey) throw new NotFoundError({ message: `Project bot key for project with ID '${projectId}' not found` });
|
if (!botKey) throw new NotFoundError({ message: `Project bot key for project with ID '${projectId}' not found` });
|
||||||
if (tokenExchange.refreshToken) {
|
if (tokenExchange.refreshToken) {
|
||||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenExchange.refreshToken,
|
plaintext: tokenExchange.refreshToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -229,7 +229,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||||
}
|
}
|
||||||
if (tokenExchange.accessToken) {
|
if (tokenExchange.accessToken) {
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenExchange.accessToken,
|
plaintext: tokenExchange.accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -355,7 +355,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
url,
|
url,
|
||||||
updateDoc.metadata as Record<string, string>
|
updateDoc.metadata as Record<string, string>
|
||||||
);
|
);
|
||||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.refreshToken,
|
plaintext: tokenDetails.refreshToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -363,7 +363,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.refreshIV = refreshEncToken.iv;
|
updateDoc.refreshIV = refreshEncToken.iv;
|
||||||
updateDoc.refreshTag = refreshEncToken.tag;
|
updateDoc.refreshTag = refreshEncToken.tag;
|
||||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.accessToken,
|
plaintext: tokenDetails.accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -377,7 +377,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
|
|
||||||
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
||||||
if (accessToken) {
|
if (accessToken) {
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: accessToken,
|
plaintext: accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -387,7 +387,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
||||||
}
|
}
|
||||||
if (accessId) {
|
if (accessId) {
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: accessId,
|
plaintext: accessId,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -397,7 +397,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
||||||
}
|
}
|
||||||
if (awsAssumeIamRoleArn) {
|
if (awsAssumeIamRoleArn) {
|
||||||
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
|
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: awsAssumeIamRoleArn,
|
plaintext: awsAssumeIamRoleArn,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -516,7 +516,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
url,
|
url,
|
||||||
updateDoc.metadata as Record<string, string>
|
updateDoc.metadata as Record<string, string>
|
||||||
);
|
);
|
||||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.refreshToken,
|
plaintext: tokenDetails.refreshToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -525,7 +525,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.refreshTag = refreshEncToken.tag;
|
updateDoc.refreshTag = refreshEncToken.tag;
|
||||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||||
|
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.accessToken,
|
plaintext: tokenDetails.accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -540,7 +540,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
|
|
||||||
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
||||||
if (accessToken) {
|
if (accessToken) {
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: accessToken,
|
plaintext: accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -550,7 +550,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
||||||
}
|
}
|
||||||
if (accessId) {
|
if (accessId) {
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: accessId,
|
plaintext: accessId,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -560,7 +560,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
||||||
}
|
}
|
||||||
if (awsAssumeIamRoleArn) {
|
if (awsAssumeIamRoleArn) {
|
||||||
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
|
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: awsAssumeIamRoleArn,
|
plaintext: awsAssumeIamRoleArn,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -648,7 +648,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
} else {
|
} else {
|
||||||
if (!botKey) throw new NotFoundError({ message: "Project bot key not found" });
|
if (!botKey) throw new NotFoundError({ message: "Project bot key not found" });
|
||||||
if (integrationAuth.accessTag && integrationAuth.accessIV && integrationAuth.accessCiphertext) {
|
if (integrationAuth.accessTag && integrationAuth.accessIV && integrationAuth.accessCiphertext) {
|
||||||
accessToken = crypto.encryption().decryptSymmetric({
|
accessToken = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: integrationAuth.accessCiphertext,
|
ciphertext: integrationAuth.accessCiphertext,
|
||||||
iv: integrationAuth.accessIV,
|
iv: integrationAuth.accessIV,
|
||||||
tag: integrationAuth.accessTag,
|
tag: integrationAuth.accessTag,
|
||||||
@@ -658,7 +658,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (integrationAuth.refreshCiphertext && integrationAuth.refreshIV && integrationAuth.refreshTag) {
|
if (integrationAuth.refreshCiphertext && integrationAuth.refreshIV && integrationAuth.refreshTag) {
|
||||||
const refreshToken = crypto.encryption().decryptSymmetric({
|
const refreshToken = crypto.encryption().symmetric().decrypt({
|
||||||
key: botKey,
|
key: botKey,
|
||||||
ciphertext: integrationAuth.refreshCiphertext,
|
ciphertext: integrationAuth.refreshCiphertext,
|
||||||
iv: integrationAuth.refreshIV,
|
iv: integrationAuth.refreshIV,
|
||||||
@@ -675,13 +675,13 @@ export const integrationAuthServiceFactory = ({
|
|||||||
integrationAuth.metadata as Record<string, string>
|
integrationAuth.metadata as Record<string, string>
|
||||||
);
|
);
|
||||||
|
|
||||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.refreshToken,
|
plaintext: tokenDetails.refreshToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: tokenDetails.accessToken,
|
plaintext: tokenDetails.accessToken,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
@@ -701,7 +701,7 @@ export const integrationAuthServiceFactory = ({
|
|||||||
if (!accessToken) throw new BadRequestError({ message: "Missing access token" });
|
if (!accessToken) throw new BadRequestError({ message: "Missing access token" });
|
||||||
|
|
||||||
if (integrationAuth.accessIdTag && integrationAuth.accessIdIV && integrationAuth.accessIdCiphertext) {
|
if (integrationAuth.accessIdTag && integrationAuth.accessIdIV && integrationAuth.accessIdCiphertext) {
|
||||||
accessId = crypto.encryption().decryptSymmetric({
|
accessId = crypto.encryption().symmetric().decrypt({
|
||||||
key: botKey,
|
key: botKey,
|
||||||
ciphertext: integrationAuth.accessIdCiphertext,
|
ciphertext: integrationAuth.accessIdCiphertext,
|
||||||
iv: integrationAuth.accessIdIV,
|
iv: integrationAuth.accessIdIV,
|
||||||
|
|||||||
@@ -111,7 +111,7 @@ const getIntegrationSecretsV1 = async (
|
|||||||
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
||||||
|
|
||||||
secrets.forEach((secret) => {
|
secrets.forEach((secret) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
|
|||||||
@@ -144,12 +144,15 @@ export const orgAdminServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const botPrivateKey = crypto
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: bot.iv,
|
.symmetric()
|
||||||
tag: bot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: bot.encryptedPrivateKey
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: bot.iv,
|
||||||
|
tag: bot.tag,
|
||||||
|
ciphertext: bot.encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
const userEncryptionKey = await userDAL.findUserEncKeyByUserId(actorId);
|
const userEncryptionKey = await userDAL.findUserEncKeyByUserId(actorId);
|
||||||
if (!userEncryptionKey)
|
if (!userEncryptionKey)
|
||||||
|
|||||||
@@ -508,14 +508,14 @@ export const orgServiceFactory = ({
|
|||||||
tag: privateKeyTag,
|
tag: privateKeyTag,
|
||||||
encoding: privateKeyKeyEncoding,
|
encoding: privateKeyKeyEncoding,
|
||||||
algorithm: privateKeyAlgorithm
|
algorithm: privateKeyAlgorithm
|
||||||
} = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||||
const {
|
const {
|
||||||
ciphertext: encryptedSymmetricKey,
|
ciphertext: encryptedSymmetricKey,
|
||||||
iv: symmetricKeyIV,
|
iv: symmetricKeyIV,
|
||||||
tag: symmetricKeyTag,
|
tag: symmetricKeyTag,
|
||||||
encoding: symmetricKeyKeyEncoding,
|
encoding: symmetricKeyKeyEncoding,
|
||||||
algorithm: symmetricKeyAlgorithm
|
algorithm: symmetricKeyAlgorithm
|
||||||
} = crypto.encryption().encryptWithRootEncryptionKey(key);
|
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(key);
|
||||||
|
|
||||||
const customerId = await licenseService.generateOrgCustomerId(orgName, userEmail);
|
const customerId = await licenseService.generateOrgCustomerId(orgName, userEmail);
|
||||||
const organization = await orgDAL.transaction(async (tx) => {
|
const organization = await orgDAL.transaction(async (tx) => {
|
||||||
@@ -879,6 +879,7 @@ export const orgServiceFactory = ({
|
|||||||
const serverGeneratedPassword = crypto.randomBytes(32).toString("hex");
|
const serverGeneratedPassword = crypto.randomBytes(32).toString("hex");
|
||||||
const { tag, encoding, ciphertext, iv } = crypto
|
const { tag, encoding, ciphertext, iv } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(serverGeneratedPassword);
|
.encryptWithRootEncryptionKey(serverGeneratedPassword);
|
||||||
const encKeys = await generateUserSrpKeys(inviteeEmail, serverGeneratedPassword);
|
const encKeys = await generateUserSrpKeys(inviteeEmail, serverGeneratedPassword);
|
||||||
await userDAL.createUserEncryption(
|
await userDAL.createUserEncryption(
|
||||||
@@ -1099,6 +1100,7 @@ export const orgServiceFactory = ({
|
|||||||
|
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(newGhostUser.keys.plainPrivateKey);
|
.encryptWithRootEncryptionKey(newGhostUser.keys.plainPrivateKey);
|
||||||
if (autoGeneratedBot) {
|
if (autoGeneratedBot) {
|
||||||
await projectBotDAL.updateById(
|
await projectBotDAL.updateById(
|
||||||
@@ -1137,12 +1139,15 @@ export const orgServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const botPrivateKey = crypto
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: bot.iv,
|
.symmetric()
|
||||||
tag: bot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: bot.encryptedPrivateKey
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: bot.iv,
|
||||||
|
tag: bot.tag,
|
||||||
|
ciphertext: bot.encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
const newWsMembers = assignWorkspaceKeysToMembers({
|
const newWsMembers = assignWorkspaceKeysToMembers({
|
||||||
decryptKey: ghostUserLatestKey,
|
decryptKey: ghostUserLatestKey,
|
||||||
|
|||||||
@@ -7,12 +7,15 @@ import { TProjectDALFactory } from "../project/project-dal";
|
|||||||
import { TGetPrivateKeyDTO } from "./project-bot-types";
|
import { TGetPrivateKeyDTO } from "./project-bot-types";
|
||||||
|
|
||||||
export const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) => {
|
export const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) => {
|
||||||
return crypto.encryption().decryptWithRootEncryptionKey({
|
return crypto
|
||||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: bot.iv,
|
.symmetric()
|
||||||
tag: bot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: bot.encryptedPrivateKey
|
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: bot.iv,
|
||||||
|
tag: bot.tag,
|
||||||
|
ciphertext: bot.encryptedPrivateKey
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getBotKeyFnFactory = (
|
export const getBotKeyFnFactory = (
|
||||||
@@ -46,12 +49,15 @@ export const getBotKeyFnFactory = (
|
|||||||
projectV1Keys.serverEncryptedPrivateKeyTag &&
|
projectV1Keys.serverEncryptedPrivateKeyTag &&
|
||||||
projectV1Keys.serverEncryptedPrivateKeyEncoding
|
projectV1Keys.serverEncryptedPrivateKeyEncoding
|
||||||
) {
|
) {
|
||||||
userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
userPrivateKey = crypto
|
||||||
iv: projectV1Keys.serverEncryptedPrivateKeyIV,
|
.encryption()
|
||||||
tag: projectV1Keys.serverEncryptedPrivateKeyTag,
|
.symmetric()
|
||||||
ciphertext: projectV1Keys.serverEncryptedPrivateKey,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: projectV1Keys.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
iv: projectV1Keys.serverEncryptedPrivateKeyIV,
|
||||||
});
|
tag: projectV1Keys.serverEncryptedPrivateKeyTag,
|
||||||
|
ciphertext: projectV1Keys.serverEncryptedPrivateKey,
|
||||||
|
keyEncoding: projectV1Keys.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
}
|
}
|
||||||
const workspaceKey = crypto.encryption().asymmetric().decrypt({
|
const workspaceKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: projectV1Keys.projectEncryptedKey,
|
ciphertext: projectV1Keys.projectEncryptedKey,
|
||||||
@@ -62,6 +68,7 @@ export const getBotKeyFnFactory = (
|
|||||||
const botKey = await crypto.encryption().asymmetric().generateKeyPair();
|
const botKey = await crypto.encryption().asymmetric().generateKeyPair();
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(botKey.privateKey);
|
.encryptWithRootEncryptionKey(botKey.privateKey);
|
||||||
const encryptedWorkspaceKey = crypto
|
const encryptedWorkspaceKey = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
|||||||
@@ -58,6 +58,7 @@ export const projectBotServiceFactory = ({
|
|||||||
|
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(keys.privateKey);
|
.encryptWithRootEncryptionKey(keys.privateKey);
|
||||||
|
|
||||||
const project = await projectDAL.findById(projectId, tx);
|
const project = await projectDAL.findById(projectId, tx);
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ export const projectQueueFactory = ({
|
|||||||
|
|
||||||
await projectDAL.setProjectUpgradeStatus(data.projectId, ProjectUpgradeStatus.InProgress); // Set the status to in progress. This is important to prevent multiple upgrades at the same time.
|
await projectDAL.setProjectUpgradeStatus(data.projectId, ProjectUpgradeStatus.InProgress); // Set the status to in progress. This is important to prevent multiple upgrades at the same time.
|
||||||
|
|
||||||
const userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const userPrivateKey = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
|
||||||
keyEncoding: data.encryptedPrivateKey.keyEncoding,
|
keyEncoding: data.encryptedPrivateKey.keyEncoding,
|
||||||
ciphertext: data.encryptedPrivateKey.encryptedKey,
|
ciphertext: data.encryptedPrivateKey.encryptedKey,
|
||||||
iv: data.encryptedPrivateKey.encryptedKeyIv,
|
iv: data.encryptedPrivateKey.encryptedKeyIv,
|
||||||
@@ -316,6 +316,7 @@ export const projectQueueFactory = ({
|
|||||||
// Encrypt the bot private key (which is the same as the ghost user)
|
// Encrypt the bot private key (which is the same as the ghost user)
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||||
|
|
||||||
// 5. Create a bot for the project
|
// 5. Create a bot for the project
|
||||||
@@ -337,12 +338,15 @@ export const projectQueueFactory = ({
|
|||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
|
|
||||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const botPrivateKey = crypto
|
||||||
keyEncoding: newBot.keyEncoding as SecretKeyEncoding,
|
.encryption()
|
||||||
iv: newBot.iv,
|
.symmetric()
|
||||||
tag: newBot.tag,
|
.decryptWithRootEncryptionKey({
|
||||||
ciphertext: newBot.encryptedPrivateKey
|
keyEncoding: newBot.keyEncoding as SecretKeyEncoding,
|
||||||
});
|
iv: newBot.iv,
|
||||||
|
tag: newBot.tag,
|
||||||
|
ciphertext: newBot.encryptedPrivateKey
|
||||||
|
});
|
||||||
|
|
||||||
const botKey = crypto.encryption().asymmetric().decrypt({
|
const botKey = crypto.encryption().asymmetric().decrypt({
|
||||||
ciphertext: newBot.encryptedProjectKey!,
|
ciphertext: newBot.encryptedProjectKey!,
|
||||||
@@ -356,23 +360,29 @@ export const projectQueueFactory = ({
|
|||||||
const updatedSecretApprovals: TSecretApprovalRequestsSecrets[] = [];
|
const updatedSecretApprovals: TSecretApprovalRequestsSecrets[] = [];
|
||||||
const updatedIntegrationAuths: TIntegrationAuths[] = [];
|
const updatedIntegrationAuths: TIntegrationAuths[] = [];
|
||||||
for (const rawSecret of decryptedSecrets) {
|
for (const rawSecret of decryptedSecrets) {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: rawSecret.decrypted.secretKey,
|
plaintext: rawSecret.decrypted.secretKey,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: rawSecret.decrypted.secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: rawSecret.decrypted.secretValue || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
const secretCommentEncrypted = crypto
|
||||||
plaintext: rawSecret.decrypted.secretComment || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: rawSecret.decrypted.secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const payload: TSecrets = {
|
const payload: TSecrets = {
|
||||||
...rawSecret.original,
|
...rawSecret.original,
|
||||||
@@ -399,23 +409,29 @@ export const projectQueueFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
for (const rawSecretVersion of decryptedSecretVersions) {
|
for (const rawSecretVersion of decryptedSecretVersions) {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: rawSecretVersion.decrypted.secretKey,
|
plaintext: rawSecretVersion.decrypted.secretKey,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: rawSecretVersion.decrypted.secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: rawSecretVersion.decrypted.secretValue || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
const secretCommentEncrypted = crypto
|
||||||
plaintext: rawSecretVersion.decrypted.secretComment || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: rawSecretVersion.decrypted.secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const payload: TSecretVersions = {
|
const payload: TSecretVersions = {
|
||||||
...rawSecretVersion.original,
|
...rawSecretVersion.original,
|
||||||
@@ -442,21 +458,27 @@ export const projectQueueFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
for (const rawSecretApproval of decryptedApprovalSecrets) {
|
for (const rawSecretApproval of decryptedApprovalSecrets) {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: rawSecretApproval.decrypted.secretKey,
|
plaintext: rawSecretApproval.decrypted.secretKey,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: rawSecretApproval.decrypted.secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: rawSecretApproval.decrypted.secretValue || "",
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
key: botKey,
|
||||||
plaintext: rawSecretApproval.decrypted.secretComment || "",
|
keySize: SymmetricKeySize.Bits128
|
||||||
key: botKey,
|
});
|
||||||
keySize: SymmetricKeySize.Bits128
|
const secretCommentEncrypted = crypto
|
||||||
});
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encrypt({
|
||||||
|
plaintext: rawSecretApproval.decrypted.secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const payload: TSecretApprovalRequestsSecrets = {
|
const payload: TSecretApprovalRequestsSecrets = {
|
||||||
...rawSecretApproval.original,
|
...rawSecretApproval.original,
|
||||||
@@ -483,17 +505,17 @@ export const projectQueueFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
for (const integrationAuth of decryptedIntegrationAuths) {
|
for (const integrationAuth of decryptedIntegrationAuths) {
|
||||||
const access = crypto.encryption().encryptSymmetric({
|
const access = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: integrationAuth.decrypted.access,
|
plaintext: integrationAuth.decrypted.access,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const accessId = crypto.encryption().encryptSymmetric({
|
const accessId = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: integrationAuth.decrypted.accessId,
|
plaintext: integrationAuth.decrypted.accessId,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const refresh = crypto.encryption().encryptSymmetric({
|
const refresh = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: integrationAuth.decrypted.refresh,
|
plaintext: integrationAuth.decrypted.refresh,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
|||||||
@@ -379,6 +379,7 @@ export const projectServiceFactory = ({
|
|||||||
|
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||||
|
|
||||||
// 5. Create & a bot for the project
|
// 5. Create & a bot for the project
|
||||||
@@ -822,7 +823,7 @@ export const projectServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const encryptedPrivateKey = crypto.encryption().encryptWithRootEncryptionKey(userPrivateKey);
|
const encryptedPrivateKey = crypto.encryption().symmetric().encryptWithRootEncryptionKey(userPrivateKey);
|
||||||
|
|
||||||
await projectQueue.upgradeProject({
|
await projectQueue.upgradeProject({
|
||||||
projectId,
|
projectId,
|
||||||
|
|||||||
@@ -234,14 +234,14 @@ export const interpolateSecrets = ({ projectId, secretEncKey, secretDAL, folderD
|
|||||||
const secrets = await secretDAL.findByFolderId(folder.id);
|
const secrets = await secretDAL.findByFolderId(folder.id);
|
||||||
|
|
||||||
const decryptedSec = secrets.reduce<Record<string, string>>((prev, secret) => {
|
const decryptedSec = secrets.reduce<Record<string, string>>((prev, secret) => {
|
||||||
const decryptedSecretKey = crypto.encryption().decryptSymmetric({
|
const decryptedSecretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
key: secretEncKey,
|
key: secretEncKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const decryptedSecretValue = crypto.encryption().decryptSymmetric({
|
const decryptedSecretValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
@@ -363,7 +363,7 @@ export const decryptSecretRaw = (
|
|||||||
},
|
},
|
||||||
key: string
|
key: string
|
||||||
) => {
|
) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -372,7 +372,7 @@ export const decryptSecretRaw = (
|
|||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = !secret.secretValueHidden
|
const secretValue = !secret.secretValueHidden
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
@@ -384,7 +384,7 @@ export const decryptSecretRaw = (
|
|||||||
let secretComment = "";
|
let secretComment = "";
|
||||||
|
|
||||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||||
secretComment = crypto.encryption().decryptSymmetric({
|
secretComment = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretCommentCiphertext,
|
ciphertext: secret.secretCommentCiphertext,
|
||||||
iv: secret.secretCommentIV,
|
iv: secret.secretCommentIV,
|
||||||
tag: secret.secretCommentTag,
|
tag: secret.secretCommentTag,
|
||||||
@@ -879,22 +879,28 @@ export const createManySecretsRawFnFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
const inputSecrets = secrets.map((secret) => {
|
const inputSecrets = secrets.map((secret) => {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: secret.secretName,
|
plaintext: secret.secretName,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: secret.secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secret.secretValue || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
const secretCommentEncrypted = crypto
|
||||||
plaintext: secret.secretComment || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secret.secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
type: secret.type,
|
type: secret.type,
|
||||||
@@ -1078,22 +1084,28 @@ export const updateManySecretsRawFnFactory = ({
|
|||||||
throw new BadRequestError({ message: "New secret name cannot be empty" });
|
throw new BadRequestError({ message: "New secret name cannot be empty" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: secret.secretName,
|
plaintext: secret.secretName,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: secret.secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secret.secretValue || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
const secretCommentEncrypted = crypto
|
||||||
plaintext: secret.secretComment || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secret.secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
type: secret.type,
|
type: secret.type,
|
||||||
@@ -1176,7 +1188,7 @@ export const decryptSecretWithBot = (
|
|||||||
>,
|
>,
|
||||||
key: string
|
key: string
|
||||||
) => {
|
) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -1184,7 +1196,7 @@ export const decryptSecretWithBot = (
|
|||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = crypto.encryption().decryptSymmetric({
|
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
@@ -1195,7 +1207,7 @@ export const decryptSecretWithBot = (
|
|||||||
let secretComment = "";
|
let secretComment = "";
|
||||||
|
|
||||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||||
secretComment = crypto.encryption().decryptSymmetric({
|
secretComment = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretCommentCiphertext,
|
ciphertext: secret.secretCommentCiphertext,
|
||||||
iv: secret.secretCommentIV,
|
iv: secret.secretCommentIV,
|
||||||
tag: secret.secretCommentTag,
|
tag: secret.secretCommentTag,
|
||||||
|
|||||||
@@ -503,7 +503,7 @@ export const secretQueueFactory = ({
|
|||||||
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
||||||
await Promise.allSettled(
|
await Promise.allSettled(
|
||||||
secrets.map(async (secret) => {
|
secrets.map(async (secret) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -511,7 +511,7 @@ export const secretQueueFactory = ({
|
|||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValue = crypto.encryption().decryptSymmetric({
|
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
@@ -528,7 +528,7 @@ export const secretQueueFactory = ({
|
|||||||
content[secretKey] = { value: expandedSecretValue || "" };
|
content[secretKey] = { value: expandedSecretValue || "" };
|
||||||
|
|
||||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||||
const commentValue = crypto.encryption().decryptSymmetric({
|
const commentValue = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretCommentCiphertext,
|
ciphertext: secret.secretCommentCiphertext,
|
||||||
iv: secret.secretCommentIV,
|
iv: secret.secretCommentIV,
|
||||||
tag: secret.secretCommentTag,
|
tag: secret.secretCommentTag,
|
||||||
@@ -954,13 +954,16 @@ export const secretQueueFactory = ({
|
|||||||
integrationAuth.awsAssumeIamRoleArnIV &&
|
integrationAuth.awsAssumeIamRoleArnIV &&
|
||||||
integrationAuth.awsAssumeIamRoleArnCipherText
|
integrationAuth.awsAssumeIamRoleArnCipherText
|
||||||
) {
|
) {
|
||||||
awsAssumeRoleArn = crypto.encryption().decryptSymmetric({
|
awsAssumeRoleArn = crypto
|
||||||
ciphertext: integrationAuth.awsAssumeIamRoleArnCipherText,
|
.encryption()
|
||||||
iv: integrationAuth.awsAssumeIamRoleArnIV,
|
.symmetric()
|
||||||
tag: integrationAuth.awsAssumeIamRoleArnTag,
|
.decrypt({
|
||||||
key: botKey as string,
|
ciphertext: integrationAuth.awsAssumeIamRoleArnCipherText,
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: integrationAuth.awsAssumeIamRoleArnIV,
|
||||||
});
|
tag: integrationAuth.awsAssumeIamRoleArnTag,
|
||||||
|
key: botKey as string,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const suffixedSecrets: typeof secrets = {};
|
const suffixedSecrets: typeof secrets = {};
|
||||||
@@ -1241,6 +1244,7 @@ export const secretQueueFactory = ({
|
|||||||
);
|
);
|
||||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||||
.encryption()
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||||
await projectBotDAL.updateById(
|
await projectBotDAL.updateById(
|
||||||
bot.id,
|
bot.id,
|
||||||
@@ -1275,14 +1279,14 @@ export const secretQueueFactory = ({
|
|||||||
|
|
||||||
await secretV2BridgeDAL.batchInsert(
|
await secretV2BridgeDAL.batchInsert(
|
||||||
projectV1Secrets.map((el) => {
|
projectV1Secrets.map((el) => {
|
||||||
const key = crypto.encryption().decryptSymmetric({
|
const key = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretKeyCiphertext,
|
ciphertext: el.secretKeyCiphertext,
|
||||||
iv: el.secretKeyIV,
|
iv: el.secretKeyIV,
|
||||||
tag: el.secretKeyTag,
|
tag: el.secretKeyTag,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const value = crypto.encryption().decryptSymmetric({
|
const value = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
@@ -1291,7 +1295,7 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
const comment =
|
const comment =
|
||||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretCommentCiphertext,
|
ciphertext: el.secretCommentCiphertext,
|
||||||
iv: el.secretCommentIV,
|
iv: el.secretCommentIV,
|
||||||
tag: el.secretCommentTag,
|
tag: el.secretCommentTag,
|
||||||
@@ -1346,14 +1350,14 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
if (projectV3SecretVersionsGroupById[el.id]) return;
|
if (projectV3SecretVersionsGroupById[el.id]) return;
|
||||||
|
|
||||||
const key = crypto.encryption().decryptSymmetric({
|
const key = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretKeyCiphertext,
|
ciphertext: el.secretKeyCiphertext,
|
||||||
iv: el.secretKeyIV,
|
iv: el.secretKeyIV,
|
||||||
tag: el.secretKeyTag,
|
tag: el.secretKeyTag,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const value = crypto.encryption().decryptSymmetric({
|
const value = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
@@ -1362,7 +1366,7 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
const comment =
|
const comment =
|
||||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretCommentCiphertext,
|
ciphertext: el.secretCommentCiphertext,
|
||||||
iv: el.secretCommentIV,
|
iv: el.secretCommentIV,
|
||||||
tag: el.secretCommentTag,
|
tag: el.secretCommentTag,
|
||||||
@@ -1408,14 +1412,14 @@ export const secretQueueFactory = ({
|
|||||||
);
|
);
|
||||||
Object.values(latestSecretVersionByFolder).forEach((el) => {
|
Object.values(latestSecretVersionByFolder).forEach((el) => {
|
||||||
if (projectV3SecretVersionsGroupById[el.id]) return;
|
if (projectV3SecretVersionsGroupById[el.id]) return;
|
||||||
const key = crypto.encryption().decryptSymmetric({
|
const key = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretKeyCiphertext,
|
ciphertext: el.secretKeyCiphertext,
|
||||||
iv: el.secretKeyIV,
|
iv: el.secretKeyIV,
|
||||||
tag: el.secretKeyTag,
|
tag: el.secretKeyTag,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const value = crypto.encryption().decryptSymmetric({
|
const value = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretValueCiphertext,
|
ciphertext: el.secretValueCiphertext,
|
||||||
iv: el.secretValueIV,
|
iv: el.secretValueIV,
|
||||||
tag: el.secretValueTag,
|
tag: el.secretValueTag,
|
||||||
@@ -1424,7 +1428,7 @@ export const secretQueueFactory = ({
|
|||||||
});
|
});
|
||||||
const comment =
|
const comment =
|
||||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.secretCommentCiphertext,
|
ciphertext: el.secretCommentCiphertext,
|
||||||
iv: el.secretCommentIV,
|
iv: el.secretCommentIV,
|
||||||
tag: el.secretCommentTag,
|
tag: el.secretCommentTag,
|
||||||
@@ -1496,7 +1500,7 @@ export const secretQueueFactory = ({
|
|||||||
projectV1IntegrationAuths.map((el) => {
|
projectV1IntegrationAuths.map((el) => {
|
||||||
const accessToken =
|
const accessToken =
|
||||||
el.accessIV && el.accessTag && el.accessCiphertext
|
el.accessIV && el.accessTag && el.accessCiphertext
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.accessCiphertext,
|
ciphertext: el.accessCiphertext,
|
||||||
iv: el.accessIV,
|
iv: el.accessIV,
|
||||||
tag: el.accessTag,
|
tag: el.accessTag,
|
||||||
@@ -1506,7 +1510,7 @@ export const secretQueueFactory = ({
|
|||||||
: undefined;
|
: undefined;
|
||||||
const accessId =
|
const accessId =
|
||||||
el.accessIdIV && el.accessIdTag && el.accessIdCiphertext
|
el.accessIdIV && el.accessIdTag && el.accessIdCiphertext
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.accessIdCiphertext,
|
ciphertext: el.accessIdCiphertext,
|
||||||
iv: el.accessIdIV,
|
iv: el.accessIdIV,
|
||||||
tag: el.accessIdTag,
|
tag: el.accessIdTag,
|
||||||
@@ -1516,7 +1520,7 @@ export const secretQueueFactory = ({
|
|||||||
: undefined;
|
: undefined;
|
||||||
const refreshToken =
|
const refreshToken =
|
||||||
el.refreshIV && el.refreshTag && el.refreshCiphertext
|
el.refreshIV && el.refreshTag && el.refreshCiphertext
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.refreshCiphertext,
|
ciphertext: el.refreshCiphertext,
|
||||||
iv: el.refreshIV,
|
iv: el.refreshIV,
|
||||||
tag: el.refreshTag,
|
tag: el.refreshTag,
|
||||||
@@ -1526,7 +1530,7 @@ export const secretQueueFactory = ({
|
|||||||
: undefined;
|
: undefined;
|
||||||
const awsAssumeRoleArn =
|
const awsAssumeRoleArn =
|
||||||
el.awsAssumeIamRoleArnCipherText && el.awsAssumeIamRoleArnIV && el.awsAssumeIamRoleArnTag
|
el.awsAssumeIamRoleArnCipherText && el.awsAssumeIamRoleArnIV && el.awsAssumeIamRoleArnTag
|
||||||
? crypto.encryption().decryptSymmetric({
|
? crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: el.awsAssumeIamRoleArnCipherText,
|
ciphertext: el.awsAssumeIamRoleArnCipherText,
|
||||||
iv: el.awsAssumeIamRoleArnIV,
|
iv: el.awsAssumeIamRoleArnIV,
|
||||||
tag: el.awsAssumeIamRoleArnTag,
|
tag: el.awsAssumeIamRoleArnTag,
|
||||||
|
|||||||
@@ -158,13 +158,16 @@ export const secretServiceFactory = ({
|
|||||||
return (el: { ciphertext?: string; iv: string; tag: string }) =>
|
return (el: { ciphertext?: string; iv: string; tag: string }) =>
|
||||||
projectBot?.botKey
|
projectBot?.botKey
|
||||||
? getAllNestedSecretReferences(
|
? getAllNestedSecretReferences(
|
||||||
crypto.encryption().decryptSymmetric({
|
crypto
|
||||||
ciphertext: el.ciphertext || "",
|
.encryption()
|
||||||
iv: el.iv,
|
.symmetric()
|
||||||
tag: el.tag,
|
.decrypt({
|
||||||
key: projectBot.botKey,
|
ciphertext: el.ciphertext || "",
|
||||||
keySize: SymmetricKeySize.Bits128
|
iv: el.iv,
|
||||||
})
|
tag: el.tag,
|
||||||
|
key: projectBot.botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
})
|
||||||
)
|
)
|
||||||
: undefined;
|
: undefined;
|
||||||
};
|
};
|
||||||
@@ -1695,21 +1698,27 @@ export const secretServiceFactory = ({
|
|||||||
name: "bot_not_found_error"
|
name: "bot_not_found_error"
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: secretName,
|
plaintext: secretName,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secretValue || "",
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
key: botKey,
|
||||||
plaintext: secretComment || "",
|
keySize: SymmetricKeySize.Bits128
|
||||||
key: botKey,
|
});
|
||||||
keySize: SymmetricKeySize.Bits128
|
const secretCommentEncrypted = crypto
|
||||||
});
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encrypt({
|
||||||
|
plaintext: secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
if (policy) {
|
if (policy) {
|
||||||
const approval = await secretApprovalRequestService.generateSecretApprovalRequest({
|
const approval = await secretApprovalRequestService.generateSecretApprovalRequest({
|
||||||
policy,
|
policy,
|
||||||
@@ -1875,22 +1884,31 @@ export const secretServiceFactory = ({
|
|||||||
name: "bot_not_found_error"
|
name: "bot_not_found_error"
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secretValue || "",
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
key: botKey,
|
||||||
plaintext: secretComment || "",
|
keySize: SymmetricKeySize.Bits128
|
||||||
key: botKey,
|
});
|
||||||
keySize: SymmetricKeySize.Bits128
|
const secretCommentEncrypted = crypto
|
||||||
});
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encrypt({
|
||||||
|
plaintext: secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto
|
||||||
plaintext: newSecretName || secretName,
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: newSecretName || secretName,
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
|
||||||
if (policy) {
|
if (policy) {
|
||||||
const approval = await secretApprovalRequestService.generateSecretApprovalRequest({
|
const approval = await secretApprovalRequestService.generateSecretApprovalRequest({
|
||||||
@@ -2137,21 +2155,27 @@ export const secretServiceFactory = ({
|
|||||||
|
|
||||||
const sanitizedSecrets = inputSecrets.map(
|
const sanitizedSecrets = inputSecrets.map(
|
||||||
({ secretComment, secretKey, metadata, tagIds, secretValue, skipMultilineEncoding }) => {
|
({ secretComment, secretKey, metadata, tagIds, secretValue, skipMultilineEncoding }) => {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||||
plaintext: secretKey,
|
plaintext: secretKey,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
});
|
});
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
const secretValueEncrypted = crypto
|
||||||
plaintext: secretValue || "",
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: secretValue || "",
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
key: botKey,
|
||||||
plaintext: secretComment || "",
|
keySize: SymmetricKeySize.Bits128
|
||||||
key: botKey,
|
});
|
||||||
keySize: SymmetricKeySize.Bits128
|
const secretCommentEncrypted = crypto
|
||||||
});
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encrypt({
|
||||||
|
plaintext: secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
return {
|
return {
|
||||||
secretName: secretKey,
|
secretName: secretKey,
|
||||||
skipMultilineEncoding,
|
skipMultilineEncoding,
|
||||||
@@ -2303,21 +2327,30 @@ export const secretServiceFactory = ({
|
|||||||
secretReminderNote,
|
secretReminderNote,
|
||||||
secretReminderRepeatDays
|
secretReminderRepeatDays
|
||||||
}) => {
|
}) => {
|
||||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
const secretKeyEncrypted = crypto
|
||||||
plaintext: newSecretName || secretKey,
|
.encryption()
|
||||||
key: botKey,
|
.symmetric()
|
||||||
keySize: SymmetricKeySize.Bits128
|
.encrypt({
|
||||||
});
|
plaintext: newSecretName || secretKey,
|
||||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
key: botKey,
|
||||||
plaintext: secretValue || "",
|
keySize: SymmetricKeySize.Bits128
|
||||||
key: botKey,
|
});
|
||||||
keySize: SymmetricKeySize.Bits128
|
const secretValueEncrypted = crypto
|
||||||
});
|
.encryption()
|
||||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
.symmetric()
|
||||||
plaintext: secretComment || "",
|
.encrypt({
|
||||||
key: botKey,
|
plaintext: secretValue || "",
|
||||||
keySize: SymmetricKeySize.Bits128
|
key: botKey,
|
||||||
});
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
|
const secretCommentEncrypted = crypto
|
||||||
|
.encryption()
|
||||||
|
.symmetric()
|
||||||
|
.encrypt({
|
||||||
|
plaintext: secretComment || "",
|
||||||
|
key: botKey,
|
||||||
|
keySize: SymmetricKeySize.Bits128
|
||||||
|
});
|
||||||
return {
|
return {
|
||||||
secretName: secretKey,
|
secretName: secretKey,
|
||||||
newSecretName,
|
newSecretName,
|
||||||
@@ -2528,7 +2561,7 @@ export const secretServiceFactory = ({
|
|||||||
});
|
});
|
||||||
|
|
||||||
return secretVersions.map((el) => {
|
return secretVersions.map((el) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -2850,7 +2883,7 @@ export const secretServiceFactory = ({
|
|||||||
secrets.map(({ id, secretValueCiphertext, secretValueIV, secretValueTag }) => ({
|
secrets.map(({ id, secretValueCiphertext, secretValueIV, secretValueTag }) => ({
|
||||||
secretId: id,
|
secretId: id,
|
||||||
references: getAllNestedSecretReferences(
|
references: getAllNestedSecretReferences(
|
||||||
crypto.encryption().decryptSymmetric({
|
crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secretValueCiphertext,
|
ciphertext: secretValueCiphertext,
|
||||||
iv: secretValueIV,
|
iv: secretValueIV,
|
||||||
tag: secretValueTag,
|
tag: secretValueTag,
|
||||||
@@ -2955,7 +2988,7 @@ export const secretServiceFactory = ({
|
|||||||
const destinationActions = [ProjectPermissionSecretActions.Create, ProjectPermissionSecretActions.Edit] as const;
|
const destinationActions = [ProjectPermissionSecretActions.Create, ProjectPermissionSecretActions.Edit] as const;
|
||||||
|
|
||||||
const decryptedSourceSecrets = sourceSecrets.map((secret) => {
|
const decryptedSourceSecrets = sourceSecrets.map((secret) => {
|
||||||
const secretKey = crypto.encryption().decryptSymmetric({
|
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
@@ -2996,7 +3029,7 @@ export const secretServiceFactory = ({
|
|||||||
return {
|
return {
|
||||||
...secret,
|
...secret,
|
||||||
secretKey,
|
secretKey,
|
||||||
secretValue: crypto.encryption().decryptSymmetric({
|
secretValue: crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
@@ -3022,14 +3055,14 @@ export const secretServiceFactory = ({
|
|||||||
const decryptedDestinationSecrets = destinationSecretsFromDB.map((secret) => {
|
const decryptedDestinationSecrets = destinationSecretsFromDB.map((secret) => {
|
||||||
return {
|
return {
|
||||||
...secret,
|
...secret,
|
||||||
secretKey: crypto.encryption().decryptSymmetric({
|
secretKey: crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretKeyCiphertext,
|
ciphertext: secret.secretKeyCiphertext,
|
||||||
iv: secret.secretKeyIV,
|
iv: secret.secretKeyIV,
|
||||||
tag: secret.secretKeyTag,
|
tag: secret.secretKeyTag,
|
||||||
key: botKey,
|
key: botKey,
|
||||||
keySize: SymmetricKeySize.Bits128
|
keySize: SymmetricKeySize.Bits128
|
||||||
}),
|
}),
|
||||||
secretValue: crypto.encryption().decryptSymmetric({
|
secretValue: crypto.encryption().symmetric().decrypt({
|
||||||
ciphertext: secret.secretValueCiphertext,
|
ciphertext: secret.secretValueCiphertext,
|
||||||
iv: secret.secretValueIV,
|
iv: secret.secretValueIV,
|
||||||
tag: secret.secretValueTag,
|
tag: secret.secretValueTag,
|
||||||
|
|||||||
@@ -501,7 +501,7 @@ export const superAdminServiceFactory = ({
|
|||||||
|
|
||||||
const hashedPassword = await crypto.hashing().createHash(password, appCfg.SALT_ROUNDS);
|
const hashedPassword = await crypto.hashing().createHash(password, appCfg.SALT_ROUNDS);
|
||||||
|
|
||||||
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
const { iv, tag, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||||
const userInfo = await userDAL.transaction(async (tx) => {
|
const userInfo = await userDAL.transaction(async (tx) => {
|
||||||
const newUser = await userDAL.create(
|
const newUser = await userDAL.create(
|
||||||
{
|
{
|
||||||
@@ -587,7 +587,7 @@ export const superAdminServiceFactory = ({
|
|||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(password);
|
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(password);
|
||||||
const encKeys = await generateUserSrpKeys(sanitizedEmail, password);
|
const encKeys = await generateUserSrpKeys(sanitizedEmail, password);
|
||||||
|
|
||||||
const userEnc = await userDAL.createUserEncryption(
|
const userEnc = await userDAL.createUserEncryption(
|
||||||
|
|||||||
@@ -218,12 +218,15 @@ export const userServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: `Private key for user with ID '${userId}' not found` });
|
throw new NotFoundError({ message: `Private key for user with ID '${userId}' not found` });
|
||||||
}
|
}
|
||||||
|
|
||||||
const privateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
const privateKey = crypto
|
||||||
ciphertext: user.serverEncryptedPrivateKey,
|
.encryption()
|
||||||
tag: user.serverEncryptedPrivateKeyTag,
|
.symmetric()
|
||||||
iv: user.serverEncryptedPrivateKeyIV,
|
.decryptWithRootEncryptionKey({
|
||||||
keyEncoding: user.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
ciphertext: user.serverEncryptedPrivateKey,
|
||||||
});
|
tag: user.serverEncryptedPrivateKeyTag,
|
||||||
|
iv: user.serverEncryptedPrivateKeyIV,
|
||||||
|
keyEncoding: user.serverEncryptedPrivateKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
return privateKey;
|
return privateKey;
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user