feat(fips): requested changes (function renaming)

This commit is contained in:
Daniel Hougaard
2025-07-14 21:48:13 +04:00
parent dad5153f61
commit 260ef05644
39 changed files with 718 additions and 531 deletions
@@ -37,7 +37,7 @@ const createServiceToken = async (
const randomBytes = crypto.randomBytes(16).toString("hex");
const { ciphertext, iv, tag } = crypto.encryption().encryptSymmetric({
const { ciphertext, iv, tag } = crypto.encryption().symmetric().encrypt({
plaintext: projectKey,
key: randomBytes,
keySize: SymmetricKeySize.Bits128
@@ -165,7 +165,7 @@ describe("Service token secret ops", async () => {
const serviceTokenInfo = serviceTokenInfoRes.json();
const serviceTokenParts = serviceToken.split(".");
projectKey = crypto.encryption().decryptSymmetric({
projectKey = crypto.encryption().symmetric().decrypt({
key: serviceTokenParts[3],
tag: serviceTokenInfo.tag,
ciphertext: serviceTokenInfo.encryptedKey,
@@ -69,7 +69,10 @@ export async function up(knex: Knex): Promise<void> {
let encryptedSecretKey = null;
if (el.encryptedSecretKey && el.iv && el.tag && el.keyEncoding) {
const decyptedSecretKey = crypto.encryption().decryptWithRootEncryptionKey({
const decyptedSecretKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: el.keyEncoding as SecretKeyEncoding,
iv: el.iv,
tag: el.tag,
@@ -82,7 +85,10 @@ export async function up(knex: Knex): Promise<void> {
const decryptedUrl =
el.urlIV && el.urlTag && el.urlCipherText && el.keyEncoding
? crypto.encryption().decryptWithRootEncryptionKey({
? crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: el.keyEncoding as SecretKeyEncoding,
iv: el.urlIV,
tag: el.urlTag,
@@ -63,7 +63,10 @@ export async function up(knex: Knex): Promise<void> {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.inputIV && el.inputTag && el.inputCiphertext && el.keyEncoding
? crypto.encryption().decryptWithRootEncryptionKey({
? crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
keyEncoding: el.keyEncoding as SecretKeyEncoding,
@@ -56,7 +56,10 @@ export async function up(knex: Knex): Promise<void> {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedDataTag && el.encryptedDataIV && el.encryptedData && el.keyEncoding
? crypto.encryption().decryptWithRootEncryptionKey({
? crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
keyEncoding: el.keyEncoding as SecretKeyEncoding,
@@ -102,7 +102,10 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
orgEncryptionRingBuffer.push(orgId, orgKmsService);
}
const key = crypto.encryption().decryptWithRootEncryptionKey({
const key = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
@@ -113,7 +116,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -132,7 +135,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -75,7 +75,10 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
orgEncryptionRingBuffer.push(orgId, orgKmsService);
}
const key = crypto.encryption().decryptWithRootEncryptionKey({
const key = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
@@ -86,7 +89,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -5,12 +5,12 @@ import { crypto, SymmetricKeySize } from "@app/lib/crypto/cryptography";
import { selectAllTableCols } from "@app/lib/knex";
import { initLogger } from "@app/lib/logger";
import { KmsDataKey } from "@app/services/kms/kms-types";
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
import { SecretKeyEncoding, TableName } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config";
import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services";
import { superAdminDALFactory } from "@app/services/super-admin/super-admin-dal";
const BATCH_SIZE = 500;
const reencryptSamlConfig = async (knex: Knex) => {
@@ -61,7 +61,10 @@ const reencryptSamlConfig = async (knex: Knex) => {
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
}
const key = crypto.encryption().decryptWithRootEncryptionKey({
const key = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
@@ -72,7 +75,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedEntryPoint && el.entryPointIV && el.entryPointTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -91,7 +94,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedIssuer && el.issuerIV && el.issuerTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -110,7 +113,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCert && el.certIV && el.certTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -224,7 +227,10 @@ const reencryptLdapConfig = async (knex: Knex) => {
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
}
const key = crypto.encryption().decryptWithRootEncryptionKey({
const key = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
@@ -235,7 +241,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedBindDN && el.bindDNIV && el.bindDNTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -254,7 +260,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedBindPass && el.bindPassIV && el.bindPassTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -273,7 +279,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCACert && el.caCertIV && el.caCertTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -381,7 +387,10 @@ const reencryptOidcConfig = async (knex: Knex) => {
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
}
const key = crypto.encryption().decryptWithRootEncryptionKey({
const key = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
@@ -392,7 +401,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedClientId && el.clientIdIV && el.clientIdTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
@@ -411,7 +420,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedClientSecret && el.clientSecretIV && el.clientSecretTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key,
keySize: SymmetricKeySize.Bits256,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
+23 -10
View File
@@ -84,7 +84,7 @@ export const generateUserSrpKeys = async (password: string) => {
ciphertext: encryptedPrivateKey,
iv: encryptedPrivateKeyIV,
tag: encryptedPrivateKeyTag
} = crypto.encryption().encryptSymmetric({
} = crypto.encryption().symmetric().encrypt({
plaintext: privateKey,
key,
keySize: SymmetricKeySize.Bits128
@@ -98,7 +98,8 @@ export const generateUserSrpKeys = async (password: string) => {
tag: protectedKeyTag
} = crypto
.encryption()
.encryptSymmetric({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
.symmetric()
.encrypt({ plaintext: key.toString("hex"), key: derivedKey, keySize: SymmetricKeySize.Bits128 });
return {
protectedKey,
@@ -125,7 +126,10 @@ export const getUserPrivateKey = async (password: string, user: TUserEncryptionK
});
if (!derivedKey) throw new Error("Failed to derive key from password");
const key = crypto.encryption().decryptSymmetric({
const key = crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: user.protectedKey as string,
iv: user.protectedKeyIV as string,
tag: user.protectedKeyTag as string,
@@ -133,7 +137,10 @@ export const getUserPrivateKey = async (password: string, user: TUserEncryptionK
keySize: SymmetricKeySize.Bits128
});
const privateKey = crypto.encryption().decryptSymmetric({
const privateKey = crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: user.encryptedPrivateKey,
iv: user.iv,
tag: user.tag,
@@ -164,7 +171,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
ciphertext: secretKeyCiphertext,
iv: secretKeyIV,
tag: secretKeyTag
} = crypto.encryption().encryptSymmetric({
} = crypto.encryption().symmetric().encrypt({
plaintext: key,
key: encKey,
keySize: SymmetricKeySize.Bits128
@@ -175,7 +182,10 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
ciphertext: secretValueCiphertext,
iv: secretValueIV,
tag: secretValueTag
} = crypto.encryption().encryptSymmetric({
} = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: value ?? "",
key: encKey,
keySize: SymmetricKeySize.Bits128
@@ -186,7 +196,10 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
ciphertext: secretCommentCiphertext,
iv: secretCommentIV,
tag: secretCommentTag
} = crypto.encryption().encryptSymmetric({
} = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: comment ?? "",
key: encKey,
keySize: SymmetricKeySize.Bits128
@@ -206,7 +219,7 @@ export const encryptSecret = (encKey: string, key: string, value?: string, comme
};
export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
key: decryptKey,
ciphertext: encSecret.secretKeyCiphertext,
tag: encSecret.secretKeyTag,
@@ -214,7 +227,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
keySize: SymmetricKeySize.Bits128
});
const secretValue = crypto.encryption().decryptSymmetric({
const secretValue = crypto.encryption().symmetric().decrypt({
key: decryptKey,
ciphertext: encSecret.secretValueCiphertext,
tag: encSecret.secretValueTag,
@@ -224,7 +237,7 @@ export const decryptSecret = (decryptKey: string, encSecret: TSecrets) => {
const secretComment =
encSecret.secretCommentIV && encSecret.secretCommentTag && encSecret.secretCommentCiphertext
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
key: decryptKey,
ciphertext: encSecret.secretCommentCiphertext,
tag: encSecret.secretCommentTag,
+1 -1
View File
@@ -70,7 +70,7 @@ export async function seed(knex: Knex): Promise<void> {
const encKey = process.env.ENCRYPTION_KEY;
if (!encKey) throw new Error("Missing ENCRYPTION_KEY");
const salt = crypto.randomBytes(16).toString("base64");
const secretBlindIndex = crypto.encryption().encryptSymmetric({
const secretBlindIndex = crypto.encryption().symmetric().encrypt({
plaintext: salt,
key: encKey,
keySize: SymmetricKeySize.Bits128
@@ -88,7 +88,7 @@ export const auditLogStreamServiceFactory = ({
});
const encryptedHeaders = headers
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
: undefined;
const logStream = await auditLogStreamDAL.create({
orgId: actorOrgId,
@@ -156,7 +156,7 @@ export const auditLogStreamServiceFactory = ({
});
const encryptedHeaders = headers
? crypto.encryption().encryptWithRootEncryptionKey(JSON.stringify(headers))
? crypto.encryption().symmetric().encryptWithRootEncryptionKey(JSON.stringify(headers))
: undefined;
const updatedLogStream = await auditLogStreamDAL.updateById(id, {
url,
@@ -210,7 +210,10 @@ export const auditLogStreamServiceFactory = ({
const headers =
logStream?.encryptedHeadersCiphertext && logStream?.encryptedHeadersIV && logStream?.encryptedHeadersTag
? (JSON.parse(
crypto.encryption().decryptWithRootEncryptionKey({
crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
tag: logStream.encryptedHeadersTag,
iv: logStream.encryptedHeadersIV,
ciphertext: logStream.encryptedHeadersCiphertext,
@@ -114,7 +114,10 @@ export const auditLogQueueServiceFactory = async ({
const streamHeaders =
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
? (JSON.parse(
crypto.encryption().decryptWithRootEncryptionKey({
crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
iv: encryptedHeadersIV,
tag: encryptedHeadersTag,
@@ -216,7 +219,10 @@ export const auditLogQueueServiceFactory = async ({
const streamHeaders =
encryptedHeadersIV && encryptedHeadersCiphertext && encryptedHeadersTag
? (JSON.parse(
crypto.encryption().decryptWithRootEncryptionKey({
crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: encryptedHeadersKeyEncoding as SecretKeyEncoding,
iv: encryptedHeadersIV,
tag: encryptedHeadersTag,
+4 -1
View File
@@ -94,7 +94,10 @@ const addAcceptedUsersToGroup = async ({
});
}
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const botPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
iv: bot.iv,
tag: bot.tag,
@@ -820,7 +820,7 @@ export const secretApprovalRequestServiceFactory = ({
type: SecretType.Shared,
references: botKey
? getAllNestedSecretReferences(
crypto.encryption().decryptSymmetric({
crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -866,7 +866,7 @@ export const secretApprovalRequestServiceFactory = ({
]),
references: botKey
? getAllNestedSecretReferences(
crypto.encryption().decryptSymmetric({
crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -100,7 +100,7 @@ const getReplicationKeyLockPrefix = (projectId: string, environmentSlug: string,
export const getReplicationFolderName = (importId: string) => `${ReservedFolders.SecretReplication}${importId}`;
const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -108,7 +108,7 @@ const getDecryptedKeyValue = (key: string, secret: TSecrets) => {
keySize: SymmetricKeySize.Bits128
});
const secretValue = crypto.encryption().decryptSymmetric({
const secretValue = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -372,7 +372,10 @@ export const secretRotationQueueFactory = ({
const encryptedSecrets = rotationOutputs.map(({ key: outputKey, secretId }) => ({
secretId,
value: crypto.encryption().encryptSymmetric({
value: crypto
.encryption()
.symmetric()
.encrypt({
plaintext:
typeof newCredential.outputs[outputKey] === "object"
? JSON.stringify(newCredential.outputs[outputKey])
@@ -235,7 +235,7 @@ export const secretRotationServiceFactory = ({
secret: {
id: output.secret.id,
version: output.secret.version,
secretKey: crypto.encryption().decryptSymmetric({
secretKey: crypto.encryption().symmetric().decrypt({
ciphertext: output.secret.secretKeyCiphertext,
iv: output.secret.secretKeyIV,
tag: output.secret.secretKeyTag,
@@ -237,7 +237,7 @@ export const secretSnapshotServiceFactory = ({
snapshotDetails = {
...encryptedSnapshotDetails,
secretVersions: encryptedSnapshotDetails.secretVersions.map((el) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretKeyCiphertext,
iv: el.secretKeyIV,
tag: el.secretKeyTag,
@@ -259,7 +259,7 @@ export const secretSnapshotServiceFactory = ({
let secretValue = "";
if (canReadValue) {
secretValue = crypto.encryption().decryptSymmetric({
secretValue = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -277,7 +277,7 @@ export const secretSnapshotServiceFactory = ({
secretValue,
secretComment:
el.secretCommentTag && el.secretCommentIV && el.secretCommentCiphertext
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.secretCommentCiphertext,
iv: el.secretCommentIV,
tag: el.secretCommentTag,
+22 -10
View File
@@ -221,7 +221,8 @@ const cryptographyFactory = () => {
};
};
const decryptSymmetric = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
const symmetric = () => {
const decrypt = ({ ciphertext, iv, tag, key, keySize }: TDecryptSymmetricInput): string => {
let decipher;
if (keySize === SymmetricKeySize.Bits128) {
@@ -240,7 +241,7 @@ const cryptographyFactory = () => {
return cleartext;
};
const encryptSymmetric = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
const encrypt = ({ plaintext, key, keySize }: TEncryptSymmetricInput) => {
let iv;
let cipher;
@@ -268,7 +269,7 @@ const cryptographyFactory = () => {
const encryptionKey = appCfg.ENCRYPTION_KEY;
if (rootEncryptionKey) {
const { iv, tag, ciphertext } = encryptSymmetric({
const { iv, tag, ciphertext } = encrypt({
plaintext: data,
key: rootEncryptionKey,
keySize: SymmetricKeySize.Bits256
@@ -282,7 +283,7 @@ const cryptographyFactory = () => {
};
}
if (encryptionKey) {
const { iv, tag, ciphertext } = encryptSymmetric({
const { iv, tag, ciphertext } = encrypt({
plaintext: data,
key: encryptionKey,
keySize: SymmetricKeySize.Bits128
@@ -313,7 +314,7 @@ const cryptographyFactory = () => {
const rootEncryptionKey = appCfg?.ROOT_ENCRYPTION_KEY || process.env.ROOT_ENCRYPTION_KEY;
const encryptionKey = appCfg?.ENCRYPTION_KEY || process.env.ENCRYPTION_KEY;
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
const data = decryptSymmetric({
const data = symmetric().decrypt({
key: rootEncryptionKey,
iv,
tag,
@@ -323,7 +324,13 @@ const cryptographyFactory = () => {
return data as T;
}
if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
const data = decryptSymmetric({ key: encryptionKey, iv, tag, ciphertext, keySize: SymmetricKeySize.Bits128 });
const data = symmetric().decrypt({
key: encryptionKey,
iv,
tag,
ciphertext,
keySize: SymmetricKeySize.Bits128
});
return data as T;
}
throw new CryptographyError({
@@ -332,11 +339,16 @@ const cryptographyFactory = () => {
};
return {
asymmetric,
decrypt,
encrypt,
encryptWithRootEncryptionKey,
decryptWithRootEncryptionKey,
encryptSymmetric,
decryptSymmetric
decryptWithRootEncryptionKey
};
};
return {
asymmetric,
symmetric
};
};
+4 -2
View File
@@ -32,11 +32,13 @@ export const buildSecretBlindIndexFromName = async ({
if (rootEncryptionKey && keyEncoding === SecretKeyEncoding.BASE64) {
salt = crypto
.encryption()
.decryptSymmetric({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
.symmetric()
.decrypt({ iv, ciphertext, key: rootEncryptionKey, tag, keySize: SymmetricKeySize.Bits256 });
} else if (encryptionKey && keyEncoding === SecretKeyEncoding.UTF8) {
salt = crypto
.encryption()
.decryptSymmetric({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
.symmetric()
.decrypt({ iv, ciphertext, key: encryptionKey, tag, keySize: SymmetricKeySize.Bits128 });
}
if (!salt) throw new Error("Missing secret blind index key");
+17 -5
View File
@@ -74,7 +74,10 @@ export const generateUserSrpKeys = async (
ciphertext: encryptedPrivateKey,
iv: encryptedPrivateKeyIV,
tag: encryptedPrivateKeyTag
} = crypto.encryption().encryptSymmetric({
} = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: privateKey,
key: key.toString("base64"),
keySize: SymmetricKeySize.Bits256
@@ -86,7 +89,10 @@ export const generateUserSrpKeys = async (
ciphertext: protectedKey,
iv: protectedKeyIV,
tag: protectedKeyTag
} = crypto.encryption().encryptSymmetric({
} = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: key.toString("hex"),
key: derivedKey.toString("base64"),
keySize: SymmetricKeySize.Bits256
@@ -121,7 +127,10 @@ export const getUserPrivateKey = async (
>
) => {
if (user.encryptionVersion === UserEncryption.V1) {
return crypto.encryption().decryptSymmetric({
return crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: user.encryptedPrivateKey,
iv: user.iv,
tag: user.tag,
@@ -145,7 +154,7 @@ export const getUserPrivateKey = async (
raw: true
});
if (!derivedKey) throw new Error("Failed to derive key from password");
const key = crypto.encryption().decryptSymmetric({
const key = crypto.encryption().symmetric().decrypt({
ciphertext: user.protectedKey,
iv: user.protectedKeyIV,
tag: user.protectedKeyTag,
@@ -153,7 +162,10 @@ export const getUserPrivateKey = async (
keySize: SymmetricKeySize.Bits128
});
const privateKey = crypto.encryption().decryptSymmetric({
const privateKey = crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: user.encryptedPrivateKey,
iv: user.iv,
tag: user.tag,
@@ -336,7 +336,10 @@ export const authLoginServiceFactory = ({
const hashedPassword = await crypto.hashing().createHash(password, cfg.SALT_ROUNDS);
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
const { iv, tag, ciphertext, encoding } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(privateKey);
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
serverPrivateKey: null,
@@ -222,7 +222,10 @@ export const authPaswordServiceFactory = ({
user.serverEncryptedPrivateKeyEncoding &&
user.encryptionVersion === UserEncryption.V2
) {
privateKey = crypto.encryption().decryptWithRootEncryptionKey({
privateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
iv: user.serverEncryptedPrivateKeyIV,
tag: user.serverEncryptedPrivateKeyTag,
ciphertext: user.serverEncryptedPrivateKey,
@@ -240,7 +243,7 @@ export const authPaswordServiceFactory = ({
privateKey
});
const { tag, iv, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
const { tag, iv, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
await userDAL.updateUserEncryptionByUserId(userId, {
hashedPassword: newHashedPassword,
@@ -201,7 +201,7 @@ export const authSignupServiceFactory = ({
tag: encryptedPrivateKeyTag,
encryptionVersion: UserEncryption.V2
});
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
const updateduser = await authDAL.transaction(async (tx) => {
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
if (!us) throw new Error("User not found");
@@ -222,7 +222,10 @@ export const authSignupServiceFactory = ({
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
) {
// get server generated password
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
const serverGeneratedPassword = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
@@ -444,7 +447,7 @@ export const authSignupServiceFactory = ({
tag: encryptedPrivateKeyTag,
encryptionVersion: 2
});
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
const updateduser = await authDAL.transaction(async (tx) => {
const us = await userDAL.updateById(user.id, { firstName, lastName, isAccepted: true }, tx);
if (!us) throw new Error("User not found");
@@ -461,7 +464,10 @@ export const authSignupServiceFactory = ({
systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyEncoding
) {
// get server generated password
const serverGeneratedPassword = crypto.encryption().decryptWithRootEncryptionKey({
const serverGeneratedPassword = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
iv: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyIV,
tag: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKeyTag,
ciphertext: systemGeneratedUserEncryptionKey.serverEncryptedPrivateKey,
@@ -98,7 +98,7 @@ export const externalMigrationQueueFactory = ({
template: SmtpTemplates.ExternalImportStarted
});
const decrypted = crypto.encryption().decryptWithRootEncryptionKey({
const decrypted = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
ciphertext: data.ciphertext,
iv: data.iv,
keyEncoding: data.encoding,
@@ -56,7 +56,7 @@ export const externalMigrationServiceFactory = ({
actorAuthMethod
});
const encrypted = crypto.encryption().encryptWithRootEncryptionKey(stringifiedJson);
const encrypted = crypto.encryption().symmetric().encryptWithRootEncryptionKey(stringifiedJson);
await externalMigrationQueue.startImport({
actorEmail: user.email!,
@@ -212,7 +212,10 @@ export const groupProjectServiceFactory = ({
});
}
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const botPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
iv: bot.iv,
tag: bot.tag,
@@ -218,7 +218,7 @@ export const integrationAuthServiceFactory = ({
} else {
if (!botKey) throw new NotFoundError({ message: `Project bot key for project with ID '${projectId}' not found` });
if (tokenExchange.refreshToken) {
const refreshEncToken = crypto.encryption().encryptSymmetric({
const refreshEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenExchange.refreshToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -229,7 +229,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
}
if (tokenExchange.accessToken) {
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenExchange.accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -355,7 +355,7 @@ export const integrationAuthServiceFactory = ({
url,
updateDoc.metadata as Record<string, string>
);
const refreshEncToken = crypto.encryption().encryptSymmetric({
const refreshEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.refreshToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -363,7 +363,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.refreshIV = refreshEncToken.iv;
updateDoc.refreshTag = refreshEncToken.tag;
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -377,7 +377,7 @@ export const integrationAuthServiceFactory = ({
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
if (accessToken) {
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -387,7 +387,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.accessCiphertext = accessEncToken.ciphertext;
}
if (accessId) {
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: accessId,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -397,7 +397,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
}
if (awsAssumeIamRoleArn) {
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
plaintext: awsAssumeIamRoleArn,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -516,7 +516,7 @@ export const integrationAuthServiceFactory = ({
url,
updateDoc.metadata as Record<string, string>
);
const refreshEncToken = crypto.encryption().encryptSymmetric({
const refreshEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.refreshToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -525,7 +525,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.refreshTag = refreshEncToken.tag;
updateDoc.refreshCiphertext = refreshEncToken.ciphertext;
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -540,7 +540,7 @@ export const integrationAuthServiceFactory = ({
if (!refreshToken && (accessId || accessToken || awsAssumeIamRoleArn)) {
if (accessToken) {
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -550,7 +550,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.accessCiphertext = accessEncToken.ciphertext;
}
if (accessId) {
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: accessId,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -560,7 +560,7 @@ export const integrationAuthServiceFactory = ({
updateDoc.accessIdCiphertext = accessEncToken.ciphertext;
}
if (awsAssumeIamRoleArn) {
const awsAssumeIamRoleArnEnc = crypto.encryption().encryptSymmetric({
const awsAssumeIamRoleArnEnc = crypto.encryption().symmetric().encrypt({
plaintext: awsAssumeIamRoleArn,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -648,7 +648,7 @@ export const integrationAuthServiceFactory = ({
} else {
if (!botKey) throw new NotFoundError({ message: "Project bot key not found" });
if (integrationAuth.accessTag && integrationAuth.accessIV && integrationAuth.accessCiphertext) {
accessToken = crypto.encryption().decryptSymmetric({
accessToken = crypto.encryption().symmetric().decrypt({
ciphertext: integrationAuth.accessCiphertext,
iv: integrationAuth.accessIV,
tag: integrationAuth.accessTag,
@@ -658,7 +658,7 @@ export const integrationAuthServiceFactory = ({
}
if (integrationAuth.refreshCiphertext && integrationAuth.refreshIV && integrationAuth.refreshTag) {
const refreshToken = crypto.encryption().decryptSymmetric({
const refreshToken = crypto.encryption().symmetric().decrypt({
key: botKey,
ciphertext: integrationAuth.refreshCiphertext,
iv: integrationAuth.refreshIV,
@@ -675,13 +675,13 @@ export const integrationAuthServiceFactory = ({
integrationAuth.metadata as Record<string, string>
);
const refreshEncToken = crypto.encryption().encryptSymmetric({
const refreshEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.refreshToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const accessEncToken = crypto.encryption().encryptSymmetric({
const accessEncToken = crypto.encryption().symmetric().encrypt({
plaintext: tokenDetails.accessToken,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -701,7 +701,7 @@ export const integrationAuthServiceFactory = ({
if (!accessToken) throw new BadRequestError({ message: "Missing access token" });
if (integrationAuth.accessIdTag && integrationAuth.accessIdIV && integrationAuth.accessIdCiphertext) {
accessId = crypto.encryption().decryptSymmetric({
accessId = crypto.encryption().symmetric().decrypt({
key: botKey,
ciphertext: integrationAuth.accessIdCiphertext,
iv: integrationAuth.accessIdIV,
@@ -111,7 +111,7 @@ const getIntegrationSecretsV1 = async (
const secrets = await secretDAL.findByFolderId(dto.folderId);
secrets.forEach((secret) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -144,7 +144,10 @@ export const orgAdminServiceFactory = ({
});
}
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const botPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
iv: bot.iv,
tag: bot.tag,
+8 -3
View File
@@ -508,14 +508,14 @@ export const orgServiceFactory = ({
tag: privateKeyTag,
encoding: privateKeyKeyEncoding,
algorithm: privateKeyAlgorithm
} = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
const {
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
encoding: symmetricKeyKeyEncoding,
algorithm: symmetricKeyAlgorithm
} = crypto.encryption().encryptWithRootEncryptionKey(key);
} = crypto.encryption().symmetric().encryptWithRootEncryptionKey(key);
const customerId = await licenseService.generateOrgCustomerId(orgName, userEmail);
const organization = await orgDAL.transaction(async (tx) => {
@@ -879,6 +879,7 @@ export const orgServiceFactory = ({
const serverGeneratedPassword = crypto.randomBytes(32).toString("hex");
const { tag, encoding, ciphertext, iv } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(serverGeneratedPassword);
const encKeys = await generateUserSrpKeys(inviteeEmail, serverGeneratedPassword);
await userDAL.createUserEncryption(
@@ -1099,6 +1100,7 @@ export const orgServiceFactory = ({
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(newGhostUser.keys.plainPrivateKey);
if (autoGeneratedBot) {
await projectBotDAL.updateById(
@@ -1137,7 +1139,10 @@ export const orgServiceFactory = ({
});
}
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const botPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
iv: bot.iv,
tag: bot.tag,
@@ -7,7 +7,10 @@ import { TProjectDALFactory } from "../project/project-dal";
import { TGetPrivateKeyDTO } from "./project-bot-types";
export const getBotPrivateKey = ({ bot }: TGetPrivateKeyDTO) => {
return crypto.encryption().decryptWithRootEncryptionKey({
return crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: bot.keyEncoding as SecretKeyEncoding,
iv: bot.iv,
tag: bot.tag,
@@ -46,7 +49,10 @@ export const getBotKeyFnFactory = (
projectV1Keys.serverEncryptedPrivateKeyTag &&
projectV1Keys.serverEncryptedPrivateKeyEncoding
) {
userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
userPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
iv: projectV1Keys.serverEncryptedPrivateKeyIV,
tag: projectV1Keys.serverEncryptedPrivateKeyTag,
ciphertext: projectV1Keys.serverEncryptedPrivateKey,
@@ -62,6 +68,7 @@ export const getBotKeyFnFactory = (
const botKey = await crypto.encryption().asymmetric().generateKeyPair();
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(botKey.privateKey);
const encryptedWorkspaceKey = crypto
.encryption()
@@ -58,6 +58,7 @@ export const projectBotServiceFactory = ({
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(keys.privateKey);
const project = await projectDAL.findById(projectId, tx);
+36 -14
View File
@@ -114,7 +114,7 @@ export const projectQueueFactory = ({
await projectDAL.setProjectUpgradeStatus(data.projectId, ProjectUpgradeStatus.InProgress); // Set the status to in progress. This is important to prevent multiple upgrades at the same time.
const userPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const userPrivateKey = crypto.encryption().symmetric().decryptWithRootEncryptionKey({
keyEncoding: data.encryptedPrivateKey.keyEncoding,
ciphertext: data.encryptedPrivateKey.encryptedKey,
iv: data.encryptedPrivateKey.encryptedKeyIv,
@@ -316,6 +316,7 @@ export const projectQueueFactory = ({
// Encrypt the bot private key (which is the same as the ghost user)
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
// 5. Create a bot for the project
@@ -337,7 +338,10 @@ export const projectQueueFactory = ({
tx
);
const botPrivateKey = crypto.encryption().decryptWithRootEncryptionKey({
const botPrivateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
keyEncoding: newBot.keyEncoding as SecretKeyEncoding,
iv: newBot.iv,
tag: newBot.tag,
@@ -356,19 +360,25 @@ export const projectQueueFactory = ({
const updatedSecretApprovals: TSecretApprovalRequestsSecrets[] = [];
const updatedIntegrationAuths: TIntegrationAuths[] = [];
for (const rawSecret of decryptedSecrets) {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: rawSecret.decrypted.secretKey,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecret.decrypted.secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecret.decrypted.secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -399,19 +409,25 @@ export const projectQueueFactory = ({
}
for (const rawSecretVersion of decryptedSecretVersions) {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: rawSecretVersion.decrypted.secretKey,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecretVersion.decrypted.secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecretVersion.decrypted.secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -442,17 +458,23 @@ export const projectQueueFactory = ({
}
for (const rawSecretApproval of decryptedApprovalSecrets) {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: rawSecretApproval.decrypted.secretKey,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecretApproval.decrypted.secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: rawSecretApproval.decrypted.secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -483,17 +505,17 @@ export const projectQueueFactory = ({
}
for (const integrationAuth of decryptedIntegrationAuths) {
const access = crypto.encryption().encryptSymmetric({
const access = crypto.encryption().symmetric().encrypt({
plaintext: integrationAuth.decrypted.access,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const accessId = crypto.encryption().encryptSymmetric({
const accessId = crypto.encryption().symmetric().encrypt({
plaintext: integrationAuth.decrypted.accessId,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const refresh = crypto.encryption().encryptSymmetric({
const refresh = crypto.encryption().symmetric().encrypt({
plaintext: integrationAuth.decrypted.refresh,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -379,6 +379,7 @@ export const projectServiceFactory = ({
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
// 5. Create & a bot for the project
@@ -822,7 +823,7 @@ export const projectServiceFactory = ({
});
}
const encryptedPrivateKey = crypto.encryption().encryptWithRootEncryptionKey(userPrivateKey);
const encryptedPrivateKey = crypto.encryption().symmetric().encryptWithRootEncryptionKey(userPrivateKey);
await projectQueue.upgradeProject({
projectId,
+26 -14
View File
@@ -234,14 +234,14 @@ export const interpolateSecrets = ({ projectId, secretEncKey, secretDAL, folderD
const secrets = await secretDAL.findByFolderId(folder.id);
const decryptedSec = secrets.reduce<Record<string, string>>((prev, secret) => {
const decryptedSecretKey = crypto.encryption().decryptSymmetric({
const decryptedSecretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
key: secretEncKey,
keySize: SymmetricKeySize.Bits128
});
const decryptedSecretValue = crypto.encryption().decryptSymmetric({
const decryptedSecretValue = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -363,7 +363,7 @@ export const decryptSecretRaw = (
},
key: string
) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -372,7 +372,7 @@ export const decryptSecretRaw = (
});
const secretValue = !secret.secretValueHidden
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -384,7 +384,7 @@ export const decryptSecretRaw = (
let secretComment = "";
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
secretComment = crypto.encryption().decryptSymmetric({
secretComment = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretCommentCiphertext,
iv: secret.secretCommentIV,
tag: secret.secretCommentTag,
@@ -879,18 +879,24 @@ export const createManySecretsRawFnFactory = ({
});
const inputSecrets = secrets.map((secret) => {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: secret.secretName,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secret.secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secret.secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -1078,18 +1084,24 @@ export const updateManySecretsRawFnFactory = ({
throw new BadRequestError({ message: "New secret name cannot be empty" });
}
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: secret.secretName,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secret.secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretReferences = getAllNestedSecretReferences(secret.secretValue || "");
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secret.secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -1176,7 +1188,7 @@ export const decryptSecretWithBot = (
>,
key: string
) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -1184,7 +1196,7 @@ export const decryptSecretWithBot = (
keySize: SymmetricKeySize.Bits128
});
const secretValue = crypto.encryption().decryptSymmetric({
const secretValue = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -1195,7 +1207,7 @@ export const decryptSecretWithBot = (
let secretComment = "";
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
secretComment = crypto.encryption().decryptSymmetric({
secretComment = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretCommentCiphertext,
iv: secret.secretCommentIV,
tag: secret.secretCommentTag,
+21 -17
View File
@@ -503,7 +503,7 @@ export const secretQueueFactory = ({
const secrets = await secretDAL.findByFolderId(dto.folderId);
await Promise.allSettled(
secrets.map(async (secret) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -511,7 +511,7 @@ export const secretQueueFactory = ({
keySize: SymmetricKeySize.Bits128
});
const secretValue = crypto.encryption().decryptSymmetric({
const secretValue = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -528,7 +528,7 @@ export const secretQueueFactory = ({
content[secretKey] = { value: expandedSecretValue || "" };
if (secret.secretCommentCiphertext && secret.secretCommentIV && secret.secretCommentTag) {
const commentValue = crypto.encryption().decryptSymmetric({
const commentValue = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretCommentCiphertext,
iv: secret.secretCommentIV,
tag: secret.secretCommentTag,
@@ -954,7 +954,10 @@ export const secretQueueFactory = ({
integrationAuth.awsAssumeIamRoleArnIV &&
integrationAuth.awsAssumeIamRoleArnCipherText
) {
awsAssumeRoleArn = crypto.encryption().decryptSymmetric({
awsAssumeRoleArn = crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: integrationAuth.awsAssumeIamRoleArnCipherText,
iv: integrationAuth.awsAssumeIamRoleArnIV,
tag: integrationAuth.awsAssumeIamRoleArnTag,
@@ -1241,6 +1244,7 @@ export const secretQueueFactory = ({
);
const { iv, tag, ciphertext, encoding, algorithm } = crypto
.encryption()
.symmetric()
.encryptWithRootEncryptionKey(ghostUser.keys.plainPrivateKey);
await projectBotDAL.updateById(
bot.id,
@@ -1275,14 +1279,14 @@ export const secretQueueFactory = ({
await secretV2BridgeDAL.batchInsert(
projectV1Secrets.map((el) => {
const key = crypto.encryption().decryptSymmetric({
const key = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretKeyCiphertext,
iv: el.secretKeyIV,
tag: el.secretKeyTag,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const value = crypto.encryption().decryptSymmetric({
const value = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -1291,7 +1295,7 @@ export const secretQueueFactory = ({
});
const comment =
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.secretCommentCiphertext,
iv: el.secretCommentIV,
tag: el.secretCommentTag,
@@ -1346,14 +1350,14 @@ export const secretQueueFactory = ({
});
if (projectV3SecretVersionsGroupById[el.id]) return;
const key = crypto.encryption().decryptSymmetric({
const key = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretKeyCiphertext,
iv: el.secretKeyIV,
tag: el.secretKeyTag,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const value = crypto.encryption().decryptSymmetric({
const value = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -1362,7 +1366,7 @@ export const secretQueueFactory = ({
});
const comment =
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.secretCommentCiphertext,
iv: el.secretCommentIV,
tag: el.secretCommentTag,
@@ -1408,14 +1412,14 @@ export const secretQueueFactory = ({
);
Object.values(latestSecretVersionByFolder).forEach((el) => {
if (projectV3SecretVersionsGroupById[el.id]) return;
const key = crypto.encryption().decryptSymmetric({
const key = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretKeyCiphertext,
iv: el.secretKeyIV,
tag: el.secretKeyTag,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const value = crypto.encryption().decryptSymmetric({
const value = crypto.encryption().symmetric().decrypt({
ciphertext: el.secretValueCiphertext,
iv: el.secretValueIV,
tag: el.secretValueTag,
@@ -1424,7 +1428,7 @@ export const secretQueueFactory = ({
});
const comment =
el.secretCommentCiphertext && el.secretCommentTag && el.secretCommentIV
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.secretCommentCiphertext,
iv: el.secretCommentIV,
tag: el.secretCommentTag,
@@ -1496,7 +1500,7 @@ export const secretQueueFactory = ({
projectV1IntegrationAuths.map((el) => {
const accessToken =
el.accessIV && el.accessTag && el.accessCiphertext
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.accessCiphertext,
iv: el.accessIV,
tag: el.accessTag,
@@ -1506,7 +1510,7 @@ export const secretQueueFactory = ({
: undefined;
const accessId =
el.accessIdIV && el.accessIdTag && el.accessIdCiphertext
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.accessIdCiphertext,
iv: el.accessIdIV,
tag: el.accessIdTag,
@@ -1516,7 +1520,7 @@ export const secretQueueFactory = ({
: undefined;
const refreshToken =
el.refreshIV && el.refreshTag && el.refreshCiphertext
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.refreshCiphertext,
iv: el.refreshIV,
tag: el.refreshTag,
@@ -1526,7 +1530,7 @@ export const secretQueueFactory = ({
: undefined;
const awsAssumeRoleArn =
el.awsAssumeIamRoleArnCipherText && el.awsAssumeIamRoleArnIV && el.awsAssumeIamRoleArnTag
? crypto.encryption().decryptSymmetric({
? crypto.encryption().symmetric().decrypt({
ciphertext: el.awsAssumeIamRoleArnCipherText,
iv: el.awsAssumeIamRoleArnIV,
tag: el.awsAssumeIamRoleArnTag,
+52 -19
View File
@@ -158,7 +158,10 @@ export const secretServiceFactory = ({
return (el: { ciphertext?: string; iv: string; tag: string }) =>
projectBot?.botKey
? getAllNestedSecretReferences(
crypto.encryption().decryptSymmetric({
crypto
.encryption()
.symmetric()
.decrypt({
ciphertext: el.ciphertext || "",
iv: el.iv,
tag: el.tag,
@@ -1695,17 +1698,23 @@ export const secretServiceFactory = ({
name: "bot_not_found_error"
});
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: secretName,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -1875,18 +1884,27 @@ export const secretServiceFactory = ({
name: "bot_not_found_error"
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: newSecretName || secretName,
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -2137,17 +2155,23 @@ export const secretServiceFactory = ({
const sanitizedSecrets = inputSecrets.map(
({ secretComment, secretKey, metadata, tagIds, secretValue, skipMultilineEncoding }) => {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto.encryption().symmetric().encrypt({
plaintext: secretKey,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -2303,17 +2327,26 @@ export const secretServiceFactory = ({
secretReminderNote,
secretReminderRepeatDays
}) => {
const secretKeyEncrypted = crypto.encryption().encryptSymmetric({
const secretKeyEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: newSecretName || secretKey,
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretValueEncrypted = crypto.encryption().encryptSymmetric({
const secretValueEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretValue || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
});
const secretCommentEncrypted = crypto.encryption().encryptSymmetric({
const secretCommentEncrypted = crypto
.encryption()
.symmetric()
.encrypt({
plaintext: secretComment || "",
key: botKey,
keySize: SymmetricKeySize.Bits128
@@ -2528,7 +2561,7 @@ export const secretServiceFactory = ({
});
return secretVersions.map((el) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -2850,7 +2883,7 @@ export const secretServiceFactory = ({
secrets.map(({ id, secretValueCiphertext, secretValueIV, secretValueTag }) => ({
secretId: id,
references: getAllNestedSecretReferences(
crypto.encryption().decryptSymmetric({
crypto.encryption().symmetric().decrypt({
ciphertext: secretValueCiphertext,
iv: secretValueIV,
tag: secretValueTag,
@@ -2955,7 +2988,7 @@ export const secretServiceFactory = ({
const destinationActions = [ProjectPermissionSecretActions.Create, ProjectPermissionSecretActions.Edit] as const;
const decryptedSourceSecrets = sourceSecrets.map((secret) => {
const secretKey = crypto.encryption().decryptSymmetric({
const secretKey = crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
@@ -2996,7 +3029,7 @@ export const secretServiceFactory = ({
return {
...secret,
secretKey,
secretValue: crypto.encryption().decryptSymmetric({
secretValue: crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -3022,14 +3055,14 @@ export const secretServiceFactory = ({
const decryptedDestinationSecrets = destinationSecretsFromDB.map((secret) => {
return {
...secret,
secretKey: crypto.encryption().decryptSymmetric({
secretKey: crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretKeyCiphertext,
iv: secret.secretKeyIV,
tag: secret.secretKeyTag,
key: botKey,
keySize: SymmetricKeySize.Bits128
}),
secretValue: crypto.encryption().decryptSymmetric({
secretValue: crypto.encryption().symmetric().decrypt({
ciphertext: secret.secretValueCiphertext,
iv: secret.secretValueIV,
tag: secret.secretValueTag,
@@ -501,7 +501,7 @@ export const superAdminServiceFactory = ({
const hashedPassword = await crypto.hashing().createHash(password, appCfg.SALT_ROUNDS);
const { iv, tag, ciphertext, encoding } = crypto.encryption().encryptWithRootEncryptionKey(privateKey);
const { iv, tag, ciphertext, encoding } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(privateKey);
const userInfo = await userDAL.transaction(async (tx) => {
const newUser = await userDAL.create(
{
@@ -587,7 +587,7 @@ export const superAdminServiceFactory = ({
},
tx
);
const { tag, encoding, ciphertext, iv } = crypto.encryption().encryptWithRootEncryptionKey(password);
const { tag, encoding, ciphertext, iv } = crypto.encryption().symmetric().encryptWithRootEncryptionKey(password);
const encKeys = await generateUserSrpKeys(sanitizedEmail, password);
const userEnc = await userDAL.createUserEncryption(
+4 -1
View File
@@ -218,7 +218,10 @@ export const userServiceFactory = ({
throw new NotFoundError({ message: `Private key for user with ID '${userId}' not found` });
}
const privateKey = crypto.encryption().decryptWithRootEncryptionKey({
const privateKey = crypto
.encryption()
.symmetric()
.decryptWithRootEncryptionKey({
ciphertext: user.serverEncryptedPrivateKey,
tag: user.serverEncryptedPrivateKeyTag,
iv: user.serverEncryptedPrivateKeyIV,