feat: backward compatiable enc key

This commit is contained in:
Akhil Mohan
2023-11-01 22:21:31 +05:30
parent bc68a00265
commit 2de898fdbd
2 changed files with 58 additions and 20 deletions
+25 -9
View File
@@ -5,7 +5,7 @@ import { customAlphabet } from "nanoid";
import { Client as PgClient } from "pg"; import { Client as PgClient } from "pg";
import mysql from "mysql"; import mysql from "mysql";
import { client, getRootEncryptionKey } from "../../config"; import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
import { BotService, EventService, TelemetryService } from "../../services"; import { BotService, EventService, TelemetryService } from "../../services";
import { SecretRotation } from "./models"; import { SecretRotation } from "./models";
import { rotationTemplates } from "./templates"; import { rotationTemplates } from "./templates";
@@ -21,9 +21,12 @@ import {
TProviderFunction, TProviderFunction,
TProviderFunctionTypes TProviderFunctionTypes
} from "./types"; } from "./types";
import { encryptSymmetric128BitHexKeyUTF8 } from "../../utils/crypto"; import {
decryptSymmetric128BitHexKeyUTF8,
encryptSymmetric128BitHexKeyUTF8
} from "../../utils/crypto";
import { ISecret, Secret } from "../../models"; import { ISecret, Secret } from "../../models";
import { SECRET_SHARED } from "../../variables"; import { ENCODING_SCHEME_BASE64, ENCODING_SCHEME_UTF8, SECRET_SHARED } from "../../variables";
import { EESecretService } from "../services"; import { EESecretService } from "../services";
import { SecretVersion } from "../models"; import { SecretVersion } from "../models";
import { eventPushSecrets } from "../../events"; import { eventPushSecrets } from "../../events";
@@ -215,13 +218,26 @@ secretRotationQueue.process(async (job: Job) => {
) as ISecretRotationProviderTemplate; ) as ISecretRotationProviderTemplate;
// decrypt user provided inputs for secret rotation // decrypt user provided inputs for secret rotation
const encryptionKey = await getEncryptionKey();
const rootEncryptionKey = await getRootEncryptionKey(); const rootEncryptionKey = await getRootEncryptionKey();
const decryptedData = client.decryptSymmetric( let decryptedData = "";
secretRotation.encryptedData, if (rootEncryptionKey && secretRotation.keyEncoding === ENCODING_SCHEME_BASE64) {
rootEncryptionKey, // case: encoding scheme is base64
secretRotation.encryptedDataIV, decryptedData = client.decryptSymmetric(
secretRotation.encryptedDataTag secretRotation.encryptedData,
); rootEncryptionKey,
secretRotation.encryptedDataIV,
secretRotation.encryptedDataTag
);
} else if (encryptionKey && secretRotation.keyEncoding === ENCODING_SCHEME_UTF8) {
// case: encoding scheme is utf8
decryptedData = decryptSymmetric128BitHexKeyUTF8({
ciphertext: secretRotation.encryptedData,
iv: secretRotation.encryptedDataIV,
tag: secretRotation.encryptedDataTag,
key: encryptionKey
});
}
const variables = JSON.parse(decryptedData) as ISecretRotationEncData; const variables = JSON.parse(decryptedData) as ISecretRotationEncData;
+33 -11
View File
@@ -1,10 +1,16 @@
import { ISecretRotationEncData, TCreateSecretRotation, TGetProviderTemplates } from "./types"; import { ISecretRotationEncData, TCreateSecretRotation, TGetProviderTemplates } from "./types";
import { rotationTemplates } from "./templates"; import { rotationTemplates } from "./templates";
import { SecretRotation } from "./models"; import { SecretRotation } from "./models";
import { client, getRootEncryptionKey } from "../../config"; import { client, getEncryptionKey, getRootEncryptionKey } from "../../config";
import { BadRequestError } from "../../utils/errors"; import { BadRequestError } from "../../utils/errors";
import Ajv from "ajv"; import Ajv from "ajv";
import { removeSecretRotationQueue, startSecretRotationQueue } from "./queue"; import { removeSecretRotationQueue, startSecretRotationQueue } from "./queue";
import {
ALGORITHM_AES_256_GCM,
ENCODING_SCHEME_BASE64,
ENCODING_SCHEME_UTF8
} from "../../variables";
import { encryptSymmetric128BitHexKeyUTF8 } from "../../utils/crypto";
const ajv = new Ajv(); const ajv = new Ajv();
@@ -51,24 +57,40 @@ export const createSecretRotation = async ({
creds: [] creds: []
}; };
const rootEncryptionKey = await getRootEncryptionKey();
const { ciphertext, iv, tag } = client.encryptSymmetric(
JSON.stringify(encData),
rootEncryptionKey
);
const secretRotation = new SecretRotation({ const secretRotation = new SecretRotation({
workspace: workspaceId, workspace: workspaceId,
provider, provider,
environment, environment,
secretPath, secretPath,
interval, interval,
outputs: Object.entries(outputs).map(([key, secret]) => ({ key, secret })), outputs: Object.entries(outputs).map(([key, secret]) => ({ key, secret }))
encryptedData: ciphertext,
encryptedDataIV: iv,
encryptedDataTag: tag
}); });
const encryptionKey = await getEncryptionKey();
const rootEncryptionKey = await getRootEncryptionKey();
if (rootEncryptionKey) {
const { ciphertext, iv, tag } = client.encryptSymmetric(
JSON.stringify(encData),
rootEncryptionKey
);
secretRotation.encryptedDataIV = iv;
secretRotation.encryptedDataTag = tag;
secretRotation.encryptedData = ciphertext;
secretRotation.algorithm = ALGORITHM_AES_256_GCM;
secretRotation.keyEncoding = ENCODING_SCHEME_BASE64;
} else if (encryptionKey) {
const { ciphertext, iv, tag } = encryptSymmetric128BitHexKeyUTF8({
plaintext: JSON.stringify(encData),
key: encryptionKey
});
secretRotation.encryptedDataIV = iv;
secretRotation.encryptedDataTag = tag;
secretRotation.encryptedData = ciphertext;
secretRotation.algorithm = ALGORITHM_AES_256_GCM;
secretRotation.keyEncoding = ENCODING_SCHEME_UTF8;
}
await secretRotation.save(); await secretRotation.save();
await startSecretRotationQueue(secretRotation._id.toString(), interval); await startSecretRotationQueue(secretRotation._id.toString(), interval);