mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 10:28:00 +00:00
feat: backward compatiable enc key
This commit is contained in:
@@ -5,7 +5,7 @@ import { customAlphabet } from "nanoid";
|
|||||||
import { Client as PgClient } from "pg";
|
import { Client as PgClient } from "pg";
|
||||||
import mysql from "mysql";
|
import mysql from "mysql";
|
||||||
|
|
||||||
import { client, getRootEncryptionKey } from "../../config";
|
import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
|
||||||
import { BotService, EventService, TelemetryService } from "../../services";
|
import { BotService, EventService, TelemetryService } from "../../services";
|
||||||
import { SecretRotation } from "./models";
|
import { SecretRotation } from "./models";
|
||||||
import { rotationTemplates } from "./templates";
|
import { rotationTemplates } from "./templates";
|
||||||
@@ -21,9 +21,12 @@ import {
|
|||||||
TProviderFunction,
|
TProviderFunction,
|
||||||
TProviderFunctionTypes
|
TProviderFunctionTypes
|
||||||
} from "./types";
|
} from "./types";
|
||||||
import { encryptSymmetric128BitHexKeyUTF8 } from "../../utils/crypto";
|
import {
|
||||||
|
decryptSymmetric128BitHexKeyUTF8,
|
||||||
|
encryptSymmetric128BitHexKeyUTF8
|
||||||
|
} from "../../utils/crypto";
|
||||||
import { ISecret, Secret } from "../../models";
|
import { ISecret, Secret } from "../../models";
|
||||||
import { SECRET_SHARED } from "../../variables";
|
import { ENCODING_SCHEME_BASE64, ENCODING_SCHEME_UTF8, SECRET_SHARED } from "../../variables";
|
||||||
import { EESecretService } from "../services";
|
import { EESecretService } from "../services";
|
||||||
import { SecretVersion } from "../models";
|
import { SecretVersion } from "../models";
|
||||||
import { eventPushSecrets } from "../../events";
|
import { eventPushSecrets } from "../../events";
|
||||||
@@ -215,13 +218,26 @@ secretRotationQueue.process(async (job: Job) => {
|
|||||||
) as ISecretRotationProviderTemplate;
|
) as ISecretRotationProviderTemplate;
|
||||||
|
|
||||||
// decrypt user provided inputs for secret rotation
|
// decrypt user provided inputs for secret rotation
|
||||||
|
const encryptionKey = await getEncryptionKey();
|
||||||
const rootEncryptionKey = await getRootEncryptionKey();
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
const decryptedData = client.decryptSymmetric(
|
let decryptedData = "";
|
||||||
secretRotation.encryptedData,
|
if (rootEncryptionKey && secretRotation.keyEncoding === ENCODING_SCHEME_BASE64) {
|
||||||
rootEncryptionKey,
|
// case: encoding scheme is base64
|
||||||
secretRotation.encryptedDataIV,
|
decryptedData = client.decryptSymmetric(
|
||||||
secretRotation.encryptedDataTag
|
secretRotation.encryptedData,
|
||||||
);
|
rootEncryptionKey,
|
||||||
|
secretRotation.encryptedDataIV,
|
||||||
|
secretRotation.encryptedDataTag
|
||||||
|
);
|
||||||
|
} else if (encryptionKey && secretRotation.keyEncoding === ENCODING_SCHEME_UTF8) {
|
||||||
|
// case: encoding scheme is utf8
|
||||||
|
decryptedData = decryptSymmetric128BitHexKeyUTF8({
|
||||||
|
ciphertext: secretRotation.encryptedData,
|
||||||
|
iv: secretRotation.encryptedDataIV,
|
||||||
|
tag: secretRotation.encryptedDataTag,
|
||||||
|
key: encryptionKey
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const variables = JSON.parse(decryptedData) as ISecretRotationEncData;
|
const variables = JSON.parse(decryptedData) as ISecretRotationEncData;
|
||||||
|
|
||||||
|
|||||||
@@ -1,10 +1,16 @@
|
|||||||
import { ISecretRotationEncData, TCreateSecretRotation, TGetProviderTemplates } from "./types";
|
import { ISecretRotationEncData, TCreateSecretRotation, TGetProviderTemplates } from "./types";
|
||||||
import { rotationTemplates } from "./templates";
|
import { rotationTemplates } from "./templates";
|
||||||
import { SecretRotation } from "./models";
|
import { SecretRotation } from "./models";
|
||||||
import { client, getRootEncryptionKey } from "../../config";
|
import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
|
||||||
import { BadRequestError } from "../../utils/errors";
|
import { BadRequestError } from "../../utils/errors";
|
||||||
import Ajv from "ajv";
|
import Ajv from "ajv";
|
||||||
import { removeSecretRotationQueue, startSecretRotationQueue } from "./queue";
|
import { removeSecretRotationQueue, startSecretRotationQueue } from "./queue";
|
||||||
|
import {
|
||||||
|
ALGORITHM_AES_256_GCM,
|
||||||
|
ENCODING_SCHEME_BASE64,
|
||||||
|
ENCODING_SCHEME_UTF8
|
||||||
|
} from "../../variables";
|
||||||
|
import { encryptSymmetric128BitHexKeyUTF8 } from "../../utils/crypto";
|
||||||
|
|
||||||
const ajv = new Ajv();
|
const ajv = new Ajv();
|
||||||
|
|
||||||
@@ -51,24 +57,40 @@ export const createSecretRotation = async ({
|
|||||||
creds: []
|
creds: []
|
||||||
};
|
};
|
||||||
|
|
||||||
const rootEncryptionKey = await getRootEncryptionKey();
|
|
||||||
const { ciphertext, iv, tag } = client.encryptSymmetric(
|
|
||||||
JSON.stringify(encData),
|
|
||||||
rootEncryptionKey
|
|
||||||
);
|
|
||||||
|
|
||||||
const secretRotation = new SecretRotation({
|
const secretRotation = new SecretRotation({
|
||||||
workspace: workspaceId,
|
workspace: workspaceId,
|
||||||
provider,
|
provider,
|
||||||
environment,
|
environment,
|
||||||
secretPath,
|
secretPath,
|
||||||
interval,
|
interval,
|
||||||
outputs: Object.entries(outputs).map(([key, secret]) => ({ key, secret })),
|
outputs: Object.entries(outputs).map(([key, secret]) => ({ key, secret }))
|
||||||
encryptedData: ciphertext,
|
|
||||||
encryptedDataIV: iv,
|
|
||||||
encryptedDataTag: tag
|
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const encryptionKey = await getEncryptionKey();
|
||||||
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
|
|
||||||
|
if (rootEncryptionKey) {
|
||||||
|
const { ciphertext, iv, tag } = client.encryptSymmetric(
|
||||||
|
JSON.stringify(encData),
|
||||||
|
rootEncryptionKey
|
||||||
|
);
|
||||||
|
secretRotation.encryptedDataIV = iv;
|
||||||
|
secretRotation.encryptedDataTag = tag;
|
||||||
|
secretRotation.encryptedData = ciphertext;
|
||||||
|
secretRotation.algorithm = ALGORITHM_AES_256_GCM;
|
||||||
|
secretRotation.keyEncoding = ENCODING_SCHEME_BASE64;
|
||||||
|
} else if (encryptionKey) {
|
||||||
|
const { ciphertext, iv, tag } = encryptSymmetric128BitHexKeyUTF8({
|
||||||
|
plaintext: JSON.stringify(encData),
|
||||||
|
key: encryptionKey
|
||||||
|
});
|
||||||
|
secretRotation.encryptedDataIV = iv;
|
||||||
|
secretRotation.encryptedDataTag = tag;
|
||||||
|
secretRotation.encryptedData = ciphertext;
|
||||||
|
secretRotation.algorithm = ALGORITHM_AES_256_GCM;
|
||||||
|
secretRotation.keyEncoding = ENCODING_SCHEME_UTF8;
|
||||||
|
}
|
||||||
|
|
||||||
await secretRotation.save();
|
await secretRotation.save();
|
||||||
await startSecretRotationQueue(secretRotation._id.toString(), interval);
|
await startSecretRotationQueue(secretRotation._id.toString(), interval);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user