mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 09:28:36 +00:00
feat(fips): requested changes (function renaming)
This commit is contained in:
@@ -37,7 +37,7 @@ const createServiceToken = async (
|
||||
|
||||
const randomBytes = crypto.randomBytes(16).toString("hex");
|
||||
|
||||
const { ciphertext, iv, tag } = crypto.encryption().encryptSymmetric({
|
||||
const { ciphertext, iv, tag } = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: projectKey,
|
||||
key: randomBytes,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -165,7 +165,7 @@ describe("Service token secret ops", async () => {
|
||||
const serviceTokenInfo = serviceTokenInfoRes.json();
|
||||
const serviceTokenParts = serviceToken.split(".");
|
||||
|
||||
projectKey = crypto.encryption().decryptSymmetric({
|
||||
projectKey = crypto.encryption().symmetric().decrypt({
|
||||
key: serviceTokenParts[3],
|
||||
tag: serviceTokenInfo.tag,
|
||||
ciphertext: serviceTokenInfo.encryptedKey,
|
||||
|
||||
@@ -69,7 +69,10 @@ export async function up(knex: Knex): Promise<void> {
|
||||
|
||||
let encryptedSecretKey = null;
|
||||
if (el.encryptedSecretKey && el.iv && el.tag && el.keyEncoding) {
|
||||
const decyptedSecretKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const decyptedSecretKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||
iv: el.iv,
|
||||
tag: el.tag,
|
||||
@@ -82,7 +85,10 @@ export async function up(knex: Knex): Promise<void> {
|
||||
|
||||
const decryptedUrl =
|
||||
el.urlIV && el.urlTag && el.urlCipherText && el.keyEncoding
|
||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
||||
? crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||
iv: el.urlIV,
|
||||
tag: el.urlTag,
|
||||
|
||||
@@ -63,7 +63,10 @@ export async function up(knex: Knex): Promise<void> {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.inputIV && el.inputTag && el.inputCiphertext && el.keyEncoding
|
||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
||||
? crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||
|
||||
@@ -56,7 +56,10 @@ export async function up(knex: Knex): Promise<void> {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedDataTag && el.encryptedDataIV && el.encryptedData && el.keyEncoding
|
||||
? crypto.encryption().decryptWithRootEncryptionKey({
|
||||
? crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
keyEncoding: el.keyEncoding as SecretKeyEncoding,
|
||||
|
||||
@@ -102,7 +102,10 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||
}
|
||||
|
||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
@@ -113,7 +116,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -132,7 +135,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
|
||||
@@ -75,7 +75,10 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||
}
|
||||
|
||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
@@ -86,7 +89,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
|
||||
@@ -5,12 +5,12 @@ import { crypto, SymmetricKeySize } from "@app/lib/crypto/cryptography";
|
||||
import { selectAllTableCols } from "@app/lib/knex";
|
||||
import { initLogger } from "@app/lib/logger";
|
||||
import { KmsDataKey } from "@app/services/kms/kms-types";
|
||||
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
||||
|
||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||
import { createCircularCache } from "./utils/ring-buffer";
|
||||
import { getMigrationEncryptionServices } from "./utils/services";
|
||||
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
|
||||
|
||||
const BATCH_SIZE = 500;
|
||||
const reencryptSamlConfig = async (knex: Knex) => {
|
||||
@@ -61,7 +61,10 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||
}
|
||||
|
||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
@@ -72,7 +75,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedEntryPoint && el.entryPointIV && el.entryPointTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -91,7 +94,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedIssuer && el.issuerIV && el.issuerTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -110,7 +113,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedCert && el.certIV && el.certTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -224,7 +227,10 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||
}
|
||||
|
||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
@@ -235,7 +241,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedBindDN && el.bindDNIV && el.bindDNTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -254,7 +260,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedBindPass && el.bindPassIV && el.bindPassTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -273,7 +279,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedCACert && el.caCertIV && el.caCertTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -381,7 +387,10 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||
}
|
||||
|
||||
const key = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
@@ -392,7 +401,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedClientId && el.clientIdIV && el.clientIdTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
@@ -411,7 +420,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||
el.encryptedClientSecret && el.clientSecretIV && el.clientSecretTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits256,
|
||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||
|
||||
+23
-10
@@ -84,7 +84,7 @@ export const generateUserSrpKeys = async (password: string) => {
|
||||
ciphertext: encryptedPrivateKey,
|
||||
iv: encryptedPrivateKeyIV,
|
||||
tag: encryptedPrivateKeyTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: privateKey,
|
||||
key,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -98,7 +98,8 @@ export const generateUserSrpKeys = async (password: string) => {
|
||||
tag: protectedKeyTag
|
||||
} = crypto
|
||||
.encryption()
|
||||
.encryptSymmetric({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
|
||||
.symmetric()
|
||||
.encrypt({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
|
||||
|
||||
return {
|
||||
protectedKey,
|
||||
@@ -125,7 +126,10 @@ export const getUserPrivateKey = async (password: string, user: TUserEncryptionK
|
||||
});
|
||||
if (!derivedKey) throw new Error("Failed to derive key from password");
|
||||
|
||||
const key = crypto.encryption().decryptSymmetric({
|
||||
const key = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: user.protectedKey as string,
|
||||
iv: user.protectedKeyIV as string,
|
||||
tag: user.protectedKeyTag as string,
|
||||
@@ -133,7 +137,10 @@ export const getUserPrivateKey = async (password: string, user: TUserEncryptionK
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const privateKey = crypto.encryption().decryptSymmetric({
|
||||
const privateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: user.encryptedPrivateKey,
|
||||
iv: user.iv,
|
||||
tag: user.tag,
|
||||
@@ -164,7 +171,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
||||
ciphertext: secretKeyCiphertext,
|
||||
iv: secretKeyIV,
|
||||
tag: secretKeyTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: key,
|
||||
key: encKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -175,7 +182,10 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
||||
ciphertext: secretValueCiphertext,
|
||||
iv: secretValueIV,
|
||||
tag: secretValueTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: value ?? "",
|
||||
key: encKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -186,7 +196,10 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
||||
ciphertext: secretCommentCiphertext,
|
||||
iv: secretCommentIV,
|
||||
tag: secretCommentTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: comment ?? "",
|
||||
key: encKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -206,7 +219,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
|
||||
};
|
||||
|
||||
export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
key: decryptKey,
|
||||
ciphertext: encSecret.secretKeyCiphertext,
|
||||
tag: encSecret.secretKeyTag,
|
||||
@@ -214,7 +227,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValue = crypto.encryption().decryptSymmetric({
|
||||
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||
key: decryptKey,
|
||||
ciphertext: encSecret.secretValueCiphertext,
|
||||
tag: encSecret.secretValueTag,
|
||||
@@ -224,7 +237,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
|
||||
|
||||
const secretComment =
|
||||
encSecret.secretCommentIV && encSecret.secretCommentTag && encSecret.secretCommentCiphertext
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
key: decryptKey,
|
||||
ciphertext: encSecret.secretCommentCiphertext,
|
||||
tag: encSecret.secretCommentTag,
|
||||
|
||||
@@ -70,7 +70,7 @@ export async function seed(knex: Knex): Promise<void> {
|
||||
const encKey = process.env.ENCRYPTION_KEY;
|
||||
if (!encKey) throw new Error("Missing ENCRYPTION_KEY");
|
||||
const salt = crypto.randomBytes(16).toString("base64");
|
||||
const secretBlindIndex = crypto.encryption().encryptSymmetric({
|
||||
const secretBlindIndex = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: salt,
|
||||
key: encKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
|
||||
@@ -88,7 +88,7 @@ export const auditLogStreamServiceFactory = ({
|
||||
});
|
||||
|
||||
const encryptedHeaders = headers
|
||||
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||
: undefined;
|
||||
const logStream = await auditLogStreamDAL.create({
|
||||
orgId: actorOrgId,
|
||||
@@ -156,7 +156,7 @@ export const auditLogStreamServiceFactory = ({
|
||||
});
|
||||
|
||||
const encryptedHeaders = headers
|
||||
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
|
||||
: undefined;
|
||||
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
|
||||
url,
|
||||
@@ -210,7 +210,10 @@ export const auditLogStreamServiceFactory = ({
|
||||
const headers =
|
||||
logStream?.encryptedHeadersCiphertext && logStream?.encryptedHeadersIV && logStream?.encryptedHeadersTag
|
||||
? (JSON.parse(
|
||||
crypto.encryption().decryptWithRootEncryptionKey({
|
||||
crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
tag: logStream.encryptedHeadersTag,
|
||||
iv: logStream.encryptedHeadersIV,
|
||||
ciphertext: logStream.encryptedHeadersCiphertext,
|
||||
|
||||
@@ -114,7 +114,10 @@ export const auditLogQueueServiceFactory = async ({
|
||||
const streamHeaders =
|
||||
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
||||
? (JSON.parse(
|
||||
crypto.encryption().decryptWithRootEncryptionKey({
|
||||
crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
||||
iv: encryptedHeadersIV,
|
||||
tag: encryptedHeadersTag,
|
||||
@@ -216,7 +219,10 @@ export const auditLogQueueServiceFactory = async ({
|
||||
const streamHeaders =
|
||||
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
|
||||
? (JSON.parse(
|
||||
crypto.encryption().decryptWithRootEncryptionKey({
|
||||
crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
|
||||
iv: encryptedHeadersIV,
|
||||
tag: encryptedHeadersTag,
|
||||
|
||||
@@ -94,7 +94,10 @@ const addAcceptedUsersToGroup = async ({
|
||||
});
|
||||
}
|
||||
|
||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const botPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||
iv: bot.iv,
|
||||
tag: bot.tag,
|
||||
|
||||
@@ -820,7 +820,7 @@ export const secretApprovalRequestServiceFactory = ({
|
||||
type: SecretType.Shared,
|
||||
references: botKey
|
||||
? getAllNestedSecretReferences(
|
||||
crypto.encryption().decryptSymmetric({
|
||||
crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
@@ -866,7 +866,7 @@ export const secretApprovalRequestServiceFactory = ({
|
||||
]),
|
||||
references: botKey
|
||||
? getAllNestedSecretReferences(
|
||||
crypto.encryption().decryptSymmetric({
|
||||
crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
|
||||
@@ -100,7 +100,7 @@ const getReplicationKeyLockPrefix = (projectId: string, environmentSlug: string,
|
||||
export const getReplicationFolderName = (importId: string) => `${ReservedFolders.SecretReplication}${importId}`;
|
||||
|
||||
const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -108,7 +108,7 @@ const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValue = crypto.encryption().decryptSymmetric({
|
||||
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
|
||||
+4
-1
@@ -372,7 +372,10 @@ export const secretRotationQueueFactory = ({
|
||||
|
||||
const encryptedSecrets = rotationOutputs.map(({ key: outputKey, secretId }) => ({
|
||||
secretId,
|
||||
value: crypto.encryption().encryptSymmetric({
|
||||
value: crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext:
|
||||
typeof newCredential.outputs[outputKey] === "object"
|
||||
? JSON.stringify(newCredential.outputs[outputKey])
|
||||
|
||||
@@ -235,7 +235,7 @@ export const secretRotationServiceFactory = ({
|
||||
secret: {
|
||||
id: output.secret.id,
|
||||
version: output.secret.version,
|
||||
secretKey: crypto.encryption().decryptSymmetric({
|
||||
secretKey: crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: output.secret.secretKeyCiphertext,
|
||||
iv: output.secret.secretKeyIV,
|
||||
tag: output.secret.secretKeyTag,
|
||||
|
||||
@@ -237,7 +237,7 @@ export const secretSnapshotServiceFactory = ({
|
||||
snapshotDetails = {
|
||||
...encryptedSnapshotDetails,
|
||||
secretVersions: encryptedSnapshotDetails.secretVersions.map((el) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretKeyCiphertext,
|
||||
iv: el.secretKeyIV,
|
||||
tag: el.secretKeyTag,
|
||||
@@ -259,7 +259,7 @@ export const secretSnapshotServiceFactory = ({
|
||||
let secretValue = "";
|
||||
|
||||
if (canReadValue) {
|
||||
secretValue = crypto.encryption().decryptSymmetric({
|
||||
secretValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
@@ -277,7 +277,7 @@ export const secretSnapshotServiceFactory = ({
|
||||
secretValue,
|
||||
secretComment:
|
||||
el.secretCommentTag && el.secretCommentIV && el.secretCommentCiphertext
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretCommentCiphertext,
|
||||
iv: el.secretCommentIV,
|
||||
tag: el.secretCommentTag,
|
||||
|
||||
@@ -221,7 +221,8 @@ const cryptographyFactory = () => {
|
||||
};
|
||||
};
|
||||
|
||||
const decryptSymmetric = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
|
||||
const symmetric = () => {
|
||||
const decrypt = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
|
||||
let decipher;
|
||||
|
||||
if (keySize === SymmetricKeySize.Bits128) {
|
||||
@@ -240,7 +241,7 @@ const cryptographyFactory = () => {
|
||||
return cleartext;
|
||||
};
|
||||
|
||||
const encryptSymmetric = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
|
||||
const encrypt = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
|
||||
let iv;
|
||||
let cipher;
|
||||
|
||||
@@ -268,7 +269,7 @@ const cryptographyFactory = () => {
|
||||
const encryptionKey = appCfg.ENCRYPTION_KEY;
|
||||
|
||||
if (rootEncryptionKey) {
|
||||
const { iv, tag, ciphertext } = encryptSymmetric({
|
||||
const { iv, tag, ciphertext } = encrypt({
|
||||
plaintext: data,
|
||||
key: rootEncryptionKey,
|
||||
keySize: SymmetricKeySize.Bits256
|
||||
@@ -282,7 +283,7 @@ const cryptographyFactory = () => {
|
||||
};
|
||||
}
|
||||
if (encryptionKey) {
|
||||
const { iv, tag, ciphertext } = encryptSymmetric({
|
||||
const { iv, tag, ciphertext } = encrypt({
|
||||
plaintext: data,
|
||||
key: encryptionKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -313,7 +314,7 @@ const cryptographyFactory = () => {
|
||||
const rootEncryptionKey = appCfg?.ROOT_ENCRYPTION_KEY || process.env.ROOT_ENCRYPTION_KEY;
|
||||
const encryptionKey = appCfg?.ENCRYPTION_KEY || process.env.ENCRYPTION_KEY;
|
||||
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
||||
const data = decryptSymmetric({
|
||||
const data = symmetric().decrypt({
|
||||
key: rootEncryptionKey,
|
||||
iv,
|
||||
tag,
|
||||
@@ -323,7 +324,13 @@ const cryptographyFactory = () => {
|
||||
return data as T;
|
||||
}
|
||||
if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
||||
const data = decryptSymmetric({ key: encryptionKey, iv, tag, ciphertext, keySize: SymmetricKeySize.Bits128 });
|
||||
const data = symmetric().decrypt({
|
||||
key: encryptionKey,
|
||||
iv,
|
||||
tag,
|
||||
ciphertext,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
return data as T;
|
||||
}
|
||||
throw new CryptographyError({
|
||||
@@ -332,11 +339,16 @@ const cryptographyFactory = () => {
|
||||
};
|
||||
|
||||
return {
|
||||
asymmetric,
|
||||
decrypt,
|
||||
encrypt,
|
||||
encryptWithRootEncryptionKey,
|
||||
decryptWithRootEncryptionKey,
|
||||
encryptSymmetric,
|
||||
decryptSymmetric
|
||||
decryptWithRootEncryptionKey
|
||||
};
|
||||
};
|
||||
|
||||
return {
|
||||
asymmetric,
|
||||
symmetric
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -32,11 +32,13 @@ export const buildSecretBlindIndexFromName = async ({
|
||||
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
|
||||
salt = crypto
|
||||
.encryption()
|
||||
.decryptSymmetric({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
|
||||
.symmetric()
|
||||
.decrypt({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
|
||||
} else if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
|
||||
salt = crypto
|
||||
.encryption()
|
||||
.decryptSymmetric({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
|
||||
.symmetric()
|
||||
.decrypt({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
|
||||
}
|
||||
if (!salt) throw new Error("Missing secret blind index key");
|
||||
|
||||
|
||||
@@ -74,7 +74,10 @@ export const generateUserSrpKeys = async (
|
||||
ciphertext: encryptedPrivateKey,
|
||||
iv: encryptedPrivateKeyIV,
|
||||
tag: encryptedPrivateKeyTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: privateKey,
|
||||
key: key.toString("base64"),
|
||||
keySize: SymmetricKeySize.Bits256
|
||||
@@ -86,7 +89,10 @@ export const generateUserSrpKeys = async (
|
||||
ciphertext: protectedKey,
|
||||
iv: protectedKeyIV,
|
||||
tag: protectedKeyTag
|
||||
} = crypto.encryption().encryptSymmetric({
|
||||
} = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: key.toString("hex"),
|
||||
key: derivedKey.toString("base64"),
|
||||
keySize: SymmetricKeySize.Bits256
|
||||
@@ -121,7 +127,10 @@ export const getUserPrivateKey = async (
|
||||
>
|
||||
) => {
|
||||
if (user.encryptionVersion === UserEncryption.V1) {
|
||||
return crypto.encryption().decryptSymmetric({
|
||||
return crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: user.encryptedPrivateKey,
|
||||
iv: user.iv,
|
||||
tag: user.tag,
|
||||
@@ -145,7 +154,7 @@ export const getUserPrivateKey = async (
|
||||
raw: true
|
||||
});
|
||||
if (!derivedKey) throw new Error("Failed to derive key from password");
|
||||
const key = crypto.encryption().decryptSymmetric({
|
||||
const key = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: user.protectedKey,
|
||||
iv: user.protectedKeyIV,
|
||||
tag: user.protectedKeyTag,
|
||||
@@ -153,7 +162,10 @@ export const getUserPrivateKey = async (
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const privateKey = crypto.encryption().decryptSymmetric({
|
||||
const privateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: user.encryptedPrivateKey,
|
||||
iv: user.iv,
|
||||
tag: user.tag,
|
||||
|
||||
@@ -336,7 +336,10 @@ export const authLoginServiceFactory = ({
|
||||
|
||||
const hashedPassword = await crypto.hashing().createHash(password, cfg.SALT_ROUNDS);
|
||||
|
||||
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
const { iv, tag, ciphertext, encoding } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(privateKey);
|
||||
|
||||
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
|
||||
serverPrivateKey: null,
|
||||
|
||||
@@ -222,7 +222,10 @@ export const authPaswordServiceFactory = ({
|
||||
user.serverEncryptedPrivateKeyEncoding &&
|
||||
user.encryptionVersion === UserEncryption.V2
|
||||
) {
|
||||
privateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
privateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
iv: user.serverEncryptedPrivateKeyIV,
|
||||
tag: user.serverEncryptedPrivateKeyTag,
|
||||
ciphertext: user.serverEncryptedPrivateKey,
|
||||
@@ -240,7 +243,7 @@ export const authPaswordServiceFactory = ({
|
||||
privateKey
|
||||
});
|
||||
|
||||
const { tag, iv, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
const { tag, iv, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||
|
||||
await userDAL.updateUserEncryptionByUserId(userId, {
|
||||
hashedPassword: newHashedPassword,
|
||||
|
||||
@@ -201,7 +201,7 @@ export const authSignupServiceFactory = ({
|
||||
tag: encryptedPrivateKeyTag,
|
||||
encryptionVersion: UserEncryption.V2
|
||||
});
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||
const updateduser = await authDAL.transaction(async (tx) => {
|
||||
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
||||
if (!us) throw new Error("User not found");
|
||||
@@ -222,7 +222,10 @@ export const authSignupServiceFactory = ({
|
||||
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
||||
) {
|
||||
// get server generated password
|
||||
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const serverGeneratedPassword = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
||||
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
||||
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
||||
@@ -444,7 +447,7 @@ export const authSignupServiceFactory = ({
|
||||
tag: encryptedPrivateKeyTag,
|
||||
encryptionVersion: 2
|
||||
});
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||
const updateduser = await authDAL.transaction(async (tx) => {
|
||||
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
|
||||
if (!us) throw new Error("User not found");
|
||||
@@ -461,7 +464,10 @@ export const authSignupServiceFactory = ({
|
||||
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
|
||||
) {
|
||||
// get server generated password
|
||||
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const serverGeneratedPassword = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
|
||||
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
|
||||
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
|
||||
|
||||
@@ -98,7 +98,7 @@ export const externalMigrationQueueFactory = ({
|
||||
template: SmtpTemplates.ExternalImportStarted
|
||||
});
|
||||
|
||||
const decrypted = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const decrypted = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
|
||||
ciphertext: data.ciphertext,
|
||||
iv: data.iv,
|
||||
keyEncoding: data.encoding,
|
||||
|
||||
@@ -56,7 +56,7 @@ export const externalMigrationServiceFactory = ({
|
||||
actorAuthMethod
|
||||
});
|
||||
|
||||
const encrypted = crypto.encryption().encryptWithRootEncryptionKey(stringifiedJson);
|
||||
const encrypted = crypto.encryption().symmetric().encryptWithRootEncryptionKey(stringifiedJson);
|
||||
|
||||
await externalMigrationQueue.startImport({
|
||||
actorEmail: user.email!,
|
||||
|
||||
@@ -212,7 +212,10 @@ export const groupProjectServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const botPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||
iv: bot.iv,
|
||||
tag: bot.tag,
|
||||
|
||||
@@ -218,7 +218,7 @@ export const integrationAuthServiceFactory = ({
|
||||
} else {
|
||||
if (!botKey) throw new NotFoundError({ message: `Project bot key for project with ID '${projectId}' not found` });
|
||||
if (tokenExchange.refreshToken) {
|
||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
||||
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenExchange.refreshToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -229,7 +229,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||
}
|
||||
if (tokenExchange.accessToken) {
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenExchange.accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -355,7 +355,7 @@ export const integrationAuthServiceFactory = ({
|
||||
url,
|
||||
updateDoc.metadata as Record<string, string>
|
||||
);
|
||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
||||
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.refreshToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -363,7 +363,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.refreshIV = refreshEncToken.iv;
|
||||
updateDoc.refreshTag = refreshEncToken.tag;
|
||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -377,7 +377,7 @@ export const integrationAuthServiceFactory = ({
|
||||
|
||||
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
||||
if (accessToken) {
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -387,7 +387,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
||||
}
|
||||
if (accessId) {
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: accessId,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -397,7 +397,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
||||
}
|
||||
if (awsAssumeIamRoleArn) {
|
||||
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
|
||||
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: awsAssumeIamRoleArn,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -516,7 +516,7 @@ export const integrationAuthServiceFactory = ({
|
||||
url,
|
||||
updateDoc.metadata as Record<string, string>
|
||||
);
|
||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
||||
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.refreshToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -525,7 +525,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.refreshTag = refreshEncToken.tag;
|
||||
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
|
||||
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -540,7 +540,7 @@ export const integrationAuthServiceFactory = ({
|
||||
|
||||
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
|
||||
if (accessToken) {
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -550,7 +550,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.accessCiphertext = accessEncToken.ciphertext;
|
||||
}
|
||||
if (accessId) {
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: accessId,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -560,7 +560,7 @@ export const integrationAuthServiceFactory = ({
|
||||
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
|
||||
}
|
||||
if (awsAssumeIamRoleArn) {
|
||||
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
|
||||
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: awsAssumeIamRoleArn,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -648,7 +648,7 @@ export const integrationAuthServiceFactory = ({
|
||||
} else {
|
||||
if (!botKey) throw new NotFoundError({ message: "Project bot key not found" });
|
||||
if (integrationAuth.accessTag && integrationAuth.accessIV && integrationAuth.accessCiphertext) {
|
||||
accessToken = crypto.encryption().decryptSymmetric({
|
||||
accessToken = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: integrationAuth.accessCiphertext,
|
||||
iv: integrationAuth.accessIV,
|
||||
tag: integrationAuth.accessTag,
|
||||
@@ -658,7 +658,7 @@ export const integrationAuthServiceFactory = ({
|
||||
}
|
||||
|
||||
if (integrationAuth.refreshCiphertext && integrationAuth.refreshIV && integrationAuth.refreshTag) {
|
||||
const refreshToken = crypto.encryption().decryptSymmetric({
|
||||
const refreshToken = crypto.encryption().symmetric().decrypt({
|
||||
key: botKey,
|
||||
ciphertext: integrationAuth.refreshCiphertext,
|
||||
iv: integrationAuth.refreshIV,
|
||||
@@ -675,13 +675,13 @@ export const integrationAuthServiceFactory = ({
|
||||
integrationAuth.metadata as Record<string, string>
|
||||
);
|
||||
|
||||
const refreshEncToken = crypto.encryption().encryptSymmetric({
|
||||
const refreshEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.refreshToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const accessEncToken = crypto.encryption().encryptSymmetric({
|
||||
const accessEncToken = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: tokenDetails.accessToken,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -701,7 +701,7 @@ export const integrationAuthServiceFactory = ({
|
||||
if (!accessToken) throw new BadRequestError({ message: "Missing access token" });
|
||||
|
||||
if (integrationAuth.accessIdTag && integrationAuth.accessIdIV && integrationAuth.accessIdCiphertext) {
|
||||
accessId = crypto.encryption().decryptSymmetric({
|
||||
accessId = crypto.encryption().symmetric().decrypt({
|
||||
key: botKey,
|
||||
ciphertext: integrationAuth.accessIdCiphertext,
|
||||
iv: integrationAuth.accessIdIV,
|
||||
|
||||
@@ -111,7 +111,7 @@ const getIntegrationSecretsV1 = async (
|
||||
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
||||
|
||||
secrets.forEach((secret) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
|
||||
@@ -144,7 +144,10 @@ export const orgAdminServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const botPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||
iv: bot.iv,
|
||||
tag: bot.tag,
|
||||
|
||||
@@ -508,14 +508,14 @@ export const orgServiceFactory = ({
|
||||
tag: privateKeyTag,
|
||||
encoding: privateKeyKeyEncoding,
|
||||
algorithm: privateKeyAlgorithm
|
||||
} = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||
const {
|
||||
ciphertext: encryptedSymmetricKey,
|
||||
iv: symmetricKeyIV,
|
||||
tag: symmetricKeyTag,
|
||||
encoding: symmetricKeyKeyEncoding,
|
||||
algorithm: symmetricKeyAlgorithm
|
||||
} = crypto.encryption().encryptWithRootEncryptionKey(key);
|
||||
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(key);
|
||||
|
||||
const customerId = await licenseService.generateOrgCustomerId(orgName, userEmail);
|
||||
const organization = await orgDAL.transaction(async (tx) => {
|
||||
@@ -879,6 +879,7 @@ export const orgServiceFactory = ({
|
||||
const serverGeneratedPassword = crypto.randomBytes(32).toString("hex");
|
||||
const { tag, encoding, ciphertext, iv } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(serverGeneratedPassword);
|
||||
const encKeys = await generateUserSrpKeys(inviteeEmail, serverGeneratedPassword);
|
||||
await userDAL.createUserEncryption(
|
||||
@@ -1099,6 +1100,7 @@ export const orgServiceFactory = ({
|
||||
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(newGhostUser.keys.plainPrivateKey);
|
||||
if (autoGeneratedBot) {
|
||||
await projectBotDAL.updateById(
|
||||
@@ -1137,7 +1139,10 @@ export const orgServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const botPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||
iv: bot.iv,
|
||||
tag: bot.tag,
|
||||
|
||||
@@ -7,7 +7,10 @@ import { TProjectDALFactory } from "../project/project-dal";
|
||||
import { TGetPrivateKeyDTO } from "./project-bot-types";
|
||||
|
||||
export const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) => {
|
||||
return crypto.encryption().decryptWithRootEncryptionKey({
|
||||
return crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
|
||||
iv: bot.iv,
|
||||
tag: bot.tag,
|
||||
@@ -46,7 +49,10 @@ export const getBotKeyFnFactory = (
|
||||
projectV1Keys.serverEncryptedPrivateKeyTag &&
|
||||
projectV1Keys.serverEncryptedPrivateKeyEncoding
|
||||
) {
|
||||
userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
userPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
iv: projectV1Keys.serverEncryptedPrivateKeyIV,
|
||||
tag: projectV1Keys.serverEncryptedPrivateKeyTag,
|
||||
ciphertext: projectV1Keys.serverEncryptedPrivateKey,
|
||||
@@ -62,6 +68,7 @@ export const getBotKeyFnFactory = (
|
||||
const botKey = await crypto.encryption().asymmetric().generateKeyPair();
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(botKey.privateKey);
|
||||
const encryptedWorkspaceKey = crypto
|
||||
.encryption()
|
||||
|
||||
@@ -58,6 +58,7 @@ export const projectBotServiceFactory = ({
|
||||
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(keys.privateKey);
|
||||
|
||||
const project = await projectDAL.findById(projectId, tx);
|
||||
|
||||
@@ -114,7 +114,7 @@ export const projectQueueFactory = ({
|
||||
|
||||
await projectDAL.setProjectUpgradeStatus(data.projectId, ProjectUpgradeStatus.InProgress); // Set the status to in progress. This is important to prevent multiple upgrades at the same time.
|
||||
|
||||
const userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const userPrivateKey = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
|
||||
keyEncoding: data.encryptedPrivateKey.keyEncoding,
|
||||
ciphertext: data.encryptedPrivateKey.encryptedKey,
|
||||
iv: data.encryptedPrivateKey.encryptedKeyIv,
|
||||
@@ -316,6 +316,7 @@ export const projectQueueFactory = ({
|
||||
// Encrypt the bot private key (which is the same as the ghost user)
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||
|
||||
// 5. Create a bot for the project
|
||||
@@ -337,7 +338,10 @@ export const projectQueueFactory = ({
|
||||
tx
|
||||
);
|
||||
|
||||
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const botPrivateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
keyEncoding: newBot.keyEncoding as SecretKeyEncoding,
|
||||
iv: newBot.iv,
|
||||
tag: newBot.tag,
|
||||
@@ -356,19 +360,25 @@ export const projectQueueFactory = ({
|
||||
const updatedSecretApprovals: TSecretApprovalRequestsSecrets[] = [];
|
||||
const updatedIntegrationAuths: TIntegrationAuths[] = [];
|
||||
for (const rawSecret of decryptedSecrets) {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: rawSecret.decrypted.secretKey,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecret.decrypted.secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecret.decrypted.secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -399,19 +409,25 @@ export const projectQueueFactory = ({
|
||||
}
|
||||
|
||||
for (const rawSecretVersion of decryptedSecretVersions) {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: rawSecretVersion.decrypted.secretKey,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecretVersion.decrypted.secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecretVersion.decrypted.secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -442,17 +458,23 @@ export const projectQueueFactory = ({
|
||||
}
|
||||
|
||||
for (const rawSecretApproval of decryptedApprovalSecrets) {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: rawSecretApproval.decrypted.secretKey,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecretApproval.decrypted.secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: rawSecretApproval.decrypted.secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -483,17 +505,17 @@ export const projectQueueFactory = ({
|
||||
}
|
||||
|
||||
for (const integrationAuth of decryptedIntegrationAuths) {
|
||||
const access = crypto.encryption().encryptSymmetric({
|
||||
const access = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: integrationAuth.decrypted.access,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const accessId = crypto.encryption().encryptSymmetric({
|
||||
const accessId = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: integrationAuth.decrypted.accessId,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const refresh = crypto.encryption().encryptSymmetric({
|
||||
const refresh = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: integrationAuth.decrypted.refresh,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
|
||||
@@ -379,6 +379,7 @@ export const projectServiceFactory = ({
|
||||
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||
|
||||
// 5. Create & a bot for the project
|
||||
@@ -822,7 +823,7 @@ export const projectServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
const encryptedPrivateKey = crypto.encryption().encryptWithRootEncryptionKey(userPrivateKey);
|
||||
const encryptedPrivateKey = crypto.encryption().symmetric().encryptWithRootEncryptionKey(userPrivateKey);
|
||||
|
||||
await projectQueue.upgradeProject({
|
||||
projectId,
|
||||
|
||||
@@ -234,14 +234,14 @@ export const interpolateSecrets = ({ projectId, secretEncKey, secretDAL, folderD
|
||||
const secrets = await secretDAL.findByFolderId(folder.id);
|
||||
|
||||
const decryptedSec = secrets.reduce<Record<string, string>>((prev, secret) => {
|
||||
const decryptedSecretKey = crypto.encryption().decryptSymmetric({
|
||||
const decryptedSecretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
key: secretEncKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const decryptedSecretValue = crypto.encryption().decryptSymmetric({
|
||||
const decryptedSecretValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
@@ -363,7 +363,7 @@ export const decryptSecretRaw = (
|
||||
},
|
||||
key: string
|
||||
) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -372,7 +372,7 @@ export const decryptSecretRaw = (
|
||||
});
|
||||
|
||||
const secretValue = !secret.secretValueHidden
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
@@ -384,7 +384,7 @@ export const decryptSecretRaw = (
|
||||
let secretComment = "";
|
||||
|
||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||
secretComment = crypto.encryption().decryptSymmetric({
|
||||
secretComment = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretCommentCiphertext,
|
||||
iv: secret.secretCommentIV,
|
||||
tag: secret.secretCommentTag,
|
||||
@@ -879,18 +879,24 @@ export const createManySecretsRawFnFactory = ({
|
||||
});
|
||||
|
||||
const inputSecrets = secrets.map((secret) => {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: secret.secretName,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secret.secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secret.secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -1078,18 +1084,24 @@ export const updateManySecretsRawFnFactory = ({
|
||||
throw new BadRequestError({ message: "New secret name cannot be empty" });
|
||||
}
|
||||
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: secret.secretName,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secret.secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secret.secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -1176,7 +1188,7 @@ export const decryptSecretWithBot = (
|
||||
>,
|
||||
key: string
|
||||
) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -1184,7 +1196,7 @@ export const decryptSecretWithBot = (
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValue = crypto.encryption().decryptSymmetric({
|
||||
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
@@ -1195,7 +1207,7 @@ export const decryptSecretWithBot = (
|
||||
let secretComment = "";
|
||||
|
||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||
secretComment = crypto.encryption().decryptSymmetric({
|
||||
secretComment = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretCommentCiphertext,
|
||||
iv: secret.secretCommentIV,
|
||||
tag: secret.secretCommentTag,
|
||||
|
||||
@@ -503,7 +503,7 @@ export const secretQueueFactory = ({
|
||||
const secrets = await secretDAL.findByFolderId(dto.folderId);
|
||||
await Promise.allSettled(
|
||||
secrets.map(async (secret) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -511,7 +511,7 @@ export const secretQueueFactory = ({
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretValue = crypto.encryption().decryptSymmetric({
|
||||
const secretValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
@@ -528,7 +528,7 @@ export const secretQueueFactory = ({
|
||||
content[secretKey] = { value: expandedSecretValue || "" };
|
||||
|
||||
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
|
||||
const commentValue = crypto.encryption().decryptSymmetric({
|
||||
const commentValue = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretCommentCiphertext,
|
||||
iv: secret.secretCommentIV,
|
||||
tag: secret.secretCommentTag,
|
||||
@@ -954,7 +954,10 @@ export const secretQueueFactory = ({
|
||||
integrationAuth.awsAssumeIamRoleArnIV &&
|
||||
integrationAuth.awsAssumeIamRoleArnCipherText
|
||||
) {
|
||||
awsAssumeRoleArn = crypto.encryption().decryptSymmetric({
|
||||
awsAssumeRoleArn = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: integrationAuth.awsAssumeIamRoleArnCipherText,
|
||||
iv: integrationAuth.awsAssumeIamRoleArnIV,
|
||||
tag: integrationAuth.awsAssumeIamRoleArnTag,
|
||||
@@ -1241,6 +1244,7 @@ export const secretQueueFactory = ({
|
||||
);
|
||||
const { iv, tag, ciphertext, encoding, algorithm } = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
|
||||
await projectBotDAL.updateById(
|
||||
bot.id,
|
||||
@@ -1275,14 +1279,14 @@ export const secretQueueFactory = ({
|
||||
|
||||
await secretV2BridgeDAL.batchInsert(
|
||||
projectV1Secrets.map((el) => {
|
||||
const key = crypto.encryption().decryptSymmetric({
|
||||
const key = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretKeyCiphertext,
|
||||
iv: el.secretKeyIV,
|
||||
tag: el.secretKeyTag,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const value = crypto.encryption().decryptSymmetric({
|
||||
const value = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
@@ -1291,7 +1295,7 @@ export const secretQueueFactory = ({
|
||||
});
|
||||
const comment =
|
||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretCommentCiphertext,
|
||||
iv: el.secretCommentIV,
|
||||
tag: el.secretCommentTag,
|
||||
@@ -1346,14 +1350,14 @@ export const secretQueueFactory = ({
|
||||
});
|
||||
if (projectV3SecretVersionsGroupById[el.id]) return;
|
||||
|
||||
const key = crypto.encryption().decryptSymmetric({
|
||||
const key = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretKeyCiphertext,
|
||||
iv: el.secretKeyIV,
|
||||
tag: el.secretKeyTag,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const value = crypto.encryption().decryptSymmetric({
|
||||
const value = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
@@ -1362,7 +1366,7 @@ export const secretQueueFactory = ({
|
||||
});
|
||||
const comment =
|
||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretCommentCiphertext,
|
||||
iv: el.secretCommentIV,
|
||||
tag: el.secretCommentTag,
|
||||
@@ -1408,14 +1412,14 @@ export const secretQueueFactory = ({
|
||||
);
|
||||
Object.values(latestSecretVersionByFolder).forEach((el) => {
|
||||
if (projectV3SecretVersionsGroupById[el.id]) return;
|
||||
const key = crypto.encryption().decryptSymmetric({
|
||||
const key = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretKeyCiphertext,
|
||||
iv: el.secretKeyIV,
|
||||
tag: el.secretKeyTag,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const value = crypto.encryption().decryptSymmetric({
|
||||
const value = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretValueCiphertext,
|
||||
iv: el.secretValueIV,
|
||||
tag: el.secretValueTag,
|
||||
@@ -1424,7 +1428,7 @@ export const secretQueueFactory = ({
|
||||
});
|
||||
const comment =
|
||||
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.secretCommentCiphertext,
|
||||
iv: el.secretCommentIV,
|
||||
tag: el.secretCommentTag,
|
||||
@@ -1496,7 +1500,7 @@ export const secretQueueFactory = ({
|
||||
projectV1IntegrationAuths.map((el) => {
|
||||
const accessToken =
|
||||
el.accessIV && el.accessTag && el.accessCiphertext
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.accessCiphertext,
|
||||
iv: el.accessIV,
|
||||
tag: el.accessTag,
|
||||
@@ -1506,7 +1510,7 @@ export const secretQueueFactory = ({
|
||||
: undefined;
|
||||
const accessId =
|
||||
el.accessIdIV && el.accessIdTag && el.accessIdCiphertext
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.accessIdCiphertext,
|
||||
iv: el.accessIdIV,
|
||||
tag: el.accessIdTag,
|
||||
@@ -1516,7 +1520,7 @@ export const secretQueueFactory = ({
|
||||
: undefined;
|
||||
const refreshToken =
|
||||
el.refreshIV && el.refreshTag && el.refreshCiphertext
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.refreshCiphertext,
|
||||
iv: el.refreshIV,
|
||||
tag: el.refreshTag,
|
||||
@@ -1526,7 +1530,7 @@ export const secretQueueFactory = ({
|
||||
: undefined;
|
||||
const awsAssumeRoleArn =
|
||||
el.awsAssumeIamRoleArnCipherText && el.awsAssumeIamRoleArnIV && el.awsAssumeIamRoleArnTag
|
||||
? crypto.encryption().decryptSymmetric({
|
||||
? crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: el.awsAssumeIamRoleArnCipherText,
|
||||
iv: el.awsAssumeIamRoleArnIV,
|
||||
tag: el.awsAssumeIamRoleArnTag,
|
||||
|
||||
@@ -158,7 +158,10 @@ export const secretServiceFactory = ({
|
||||
return (el: { ciphertext?: string; iv: string; tag: string }) =>
|
||||
projectBot?.botKey
|
||||
? getAllNestedSecretReferences(
|
||||
crypto.encryption().decryptSymmetric({
|
||||
crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decrypt({
|
||||
ciphertext: el.ciphertext || "",
|
||||
iv: el.iv,
|
||||
tag: el.tag,
|
||||
@@ -1695,17 +1698,23 @@ export const secretServiceFactory = ({
|
||||
name: "bot_not_found_error"
|
||||
});
|
||||
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: secretName,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -1875,18 +1884,27 @@ export const secretServiceFactory = ({
|
||||
name: "bot_not_found_error"
|
||||
});
|
||||
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: newSecretName || secretName,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -2137,17 +2155,23 @@ export const secretServiceFactory = ({
|
||||
|
||||
const sanitizedSecrets = inputSecrets.map(
|
||||
({ secretComment, secretKey, metadata, tagIds, secretValue, skipMultilineEncoding }) => {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
|
||||
plaintext: secretKey,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -2303,17 +2327,26 @@ export const secretServiceFactory = ({
|
||||
secretReminderNote,
|
||||
secretReminderRepeatDays
|
||||
}) => {
|
||||
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretKeyEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: newSecretName || secretKey,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretValueEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretValue || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
});
|
||||
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
|
||||
const secretCommentEncrypted = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.encrypt({
|
||||
plaintext: secretComment || "",
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
@@ -2528,7 +2561,7 @@ export const secretServiceFactory = ({
|
||||
});
|
||||
|
||||
return secretVersions.map((el) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -2850,7 +2883,7 @@ export const secretServiceFactory = ({
|
||||
secrets.map(({ id, secretValueCiphertext, secretValueIV, secretValueTag }) => ({
|
||||
secretId: id,
|
||||
references: getAllNestedSecretReferences(
|
||||
crypto.encryption().decryptSymmetric({
|
||||
crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secretValueCiphertext,
|
||||
iv: secretValueIV,
|
||||
tag: secretValueTag,
|
||||
@@ -2955,7 +2988,7 @@ export const secretServiceFactory = ({
|
||||
const destinationActions = [ProjectPermissionSecretActions.Create, ProjectPermissionSecretActions.Edit] as const;
|
||||
|
||||
const decryptedSourceSecrets = sourceSecrets.map((secret) => {
|
||||
const secretKey = crypto.encryption().decryptSymmetric({
|
||||
const secretKey = crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
@@ -2996,7 +3029,7 @@ export const secretServiceFactory = ({
|
||||
return {
|
||||
...secret,
|
||||
secretKey,
|
||||
secretValue: crypto.encryption().decryptSymmetric({
|
||||
secretValue: crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
@@ -3022,14 +3055,14 @@ export const secretServiceFactory = ({
|
||||
const decryptedDestinationSecrets = destinationSecretsFromDB.map((secret) => {
|
||||
return {
|
||||
...secret,
|
||||
secretKey: crypto.encryption().decryptSymmetric({
|
||||
secretKey: crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretKeyCiphertext,
|
||||
iv: secret.secretKeyIV,
|
||||
tag: secret.secretKeyTag,
|
||||
key: botKey,
|
||||
keySize: SymmetricKeySize.Bits128
|
||||
}),
|
||||
secretValue: crypto.encryption().decryptSymmetric({
|
||||
secretValue: crypto.encryption().symmetric().decrypt({
|
||||
ciphertext: secret.secretValueCiphertext,
|
||||
iv: secret.secretValueIV,
|
||||
tag: secret.secretValueTag,
|
||||
|
||||
@@ -501,7 +501,7 @@ export const superAdminServiceFactory = ({
|
||||
|
||||
const hashedPassword = await crypto.hashing().createHash(password, appCfg.SALT_ROUNDS);
|
||||
|
||||
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
|
||||
const { iv, tag, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
|
||||
const userInfo = await userDAL.transaction(async (tx) => {
|
||||
const newUser = await userDAL.create(
|
||||
{
|
||||
@@ -587,7 +587,7 @@ export const superAdminServiceFactory = ({
|
||||
},
|
||||
tx
|
||||
);
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(password);
|
||||
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(password);
|
||||
const encKeys = await generateUserSrpKeys(sanitizedEmail, password);
|
||||
|
||||
const userEnc = await userDAL.createUserEncryption(
|
||||
|
||||
@@ -218,7 +218,10 @@ export const userServiceFactory = ({
|
||||
throw new NotFoundError({ message: `Private key for user with ID '${userId}' not found` });
|
||||
}
|
||||
|
||||
const privateKey = crypto.encryption().decryptWithRootEncryptionKey({
|
||||
const privateKey = crypto
|
||||
.encryption()
|
||||
.symmetric()
|
||||
.decryptWithRootEncryptionKey({
|
||||
ciphertext: user.serverEncryptedPrivateKey,
|
||||
tag: user.serverEncryptedPrivateKeyTag,
|
||||
iv: user.serverEncryptedPrivateKeyIV,
|
||||
|
||||
Reference in New Issue
Block a user