Merge pull request #2001 from akhilmhdh/fix/handover-enc-v1

feat: resolved generate srp failing for user enc v1 users
This commit is contained in:
Maidul Islam
2024-06-20 14:05:52 -04:00
committed by GitHub
4 changed files with 55 additions and 27 deletions

View File

@@ -101,33 +101,51 @@ export const getUserPrivateKey = async (
password: string, password: string,
user: Pick< user: Pick<
TUserEncryptionKeys, TUserEncryptionKeys,
"protectedKeyTag" | "protectedKey" | "protectedKeyIV" | "encryptedPrivateKey" | "iv" | "salt" | "tag" | "protectedKeyTag"
| "protectedKey"
| "protectedKeyIV"
| "encryptedPrivateKey"
| "iv"
| "salt"
| "tag"
| "encryptionVersion"
> >
) => { ) => {
const derivedKey = await argon2.hash(password, { if (user.encryptionVersion === 1) {
salt: Buffer.from(user.salt), return decryptSymmetric128BitHexKeyUTF8({
memoryCost: 65536, ciphertext: user.encryptedPrivateKey,
timeCost: 3, iv: user.iv,
parallelism: 1, tag: user.tag,
hashLength: 32, key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0")
type: argon2.argon2id, });
raw: true }
}); if (user.encryptionVersion === 2 && user.protectedKey && user.protectedKeyIV && user.protectedKeyTag) {
if (!derivedKey) throw new Error("Failed to derive key from password"); const derivedKey = await argon2.hash(password, {
const key = decryptSymmetric128BitHexKeyUTF8({ salt: Buffer.from(user.salt),
ciphertext: user.protectedKey as string, memoryCost: 65536,
iv: user.protectedKeyIV as string, timeCost: 3,
tag: user.protectedKeyTag as string, parallelism: 1,
key: derivedKey hashLength: 32,
}); type: argon2.argon2id,
raw: true
});
if (!derivedKey) throw new Error("Failed to derive key from password");
const key = decryptSymmetric128BitHexKeyUTF8({
ciphertext: user.protectedKey,
iv: user.protectedKeyIV,
tag: user.protectedKeyTag,
key: derivedKey
});
const privateKey = decryptSymmetric128BitHexKeyUTF8({ const privateKey = decryptSymmetric128BitHexKeyUTF8({
ciphertext: user.encryptedPrivateKey, ciphertext: user.encryptedPrivateKey,
iv: user.iv, iv: user.iv,
tag: user.tag, tag: user.tag,
key: Buffer.from(key, "hex") key: Buffer.from(key, "hex")
}); });
return privateKey; return privateKey;
}
throw new Error(`GetUserPrivateKey: Encryption version not found`);
}; };
export const buildUserProjectKey = async (privateKey: string, publickey: string) => { export const buildUserProjectKey = async (privateKey: string, publickey: string) => {

View File

@@ -9,6 +9,7 @@ import { generateSrpServerKey, srpCheckClientProof } from "@app/lib/crypto";
import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
import { getUserPrivateKey } from "@app/lib/crypto/srp"; import { getUserPrivateKey } from "@app/lib/crypto/srp";
import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/errors"; import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/errors";
import { logger } from "@app/lib/logger";
import { getServerCfg } from "@app/services/super-admin/super-admin-service"; import { getServerCfg } from "@app/services/super-admin/super-admin-service";
import { TTokenDALFactory } from "../auth-token/auth-token-dal"; import { TTokenDALFactory } from "../auth-token/auth-token-dal";
@@ -258,7 +259,13 @@ export const authLoginServiceFactory = ({
}); });
// from password decrypt the private key // from password decrypt the private key
if (password) { if (password) {
const privateKey = await getUserPrivateKey(password, userEnc); const privateKey = await getUserPrivateKey(password, userEnc).catch((err) => {
logger.error(
err,
`loginExchangeClientProof: private key generation failed for [userId=${user.id}] and [email=${user.email}] `
);
return "";
});
const hashedPassword = await bcrypt.hash(password, cfg.BCRYPT_SALT_ROUND); const hashedPassword = await bcrypt.hash(password, cfg.BCRYPT_SALT_ROUND);
const { iv, tag, ciphertext, encoding } = infisicalSymmetricEncypt(privateKey); const { iv, tag, ciphertext, encoding } = infisicalSymmetricEncypt(privateKey);
await userDAL.updateUserEncryptionByUserId(userEnc.userId, { await userDAL.updateUserEncryptionByUserId(userEnc.userId, {

View File

@@ -165,7 +165,8 @@ export const authSignupServiceFactory = ({
protectedKeyTag, protectedKeyTag,
encryptedPrivateKey, encryptedPrivateKey,
iv: encryptedPrivateKeyIV, iv: encryptedPrivateKeyIV,
tag: encryptedPrivateKeyTag tag: encryptedPrivateKeyTag,
encryptionVersion: 2
}); });
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey); const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
const updateduser = await authDAL.transaction(async (tx) => { const updateduser = await authDAL.transaction(async (tx) => {
@@ -325,7 +326,8 @@ export const authSignupServiceFactory = ({
protectedKeyTag, protectedKeyTag,
encryptedPrivateKey, encryptedPrivateKey,
iv: encryptedPrivateKeyIV, iv: encryptedPrivateKeyIV,
tag: encryptedPrivateKeyTag tag: encryptedPrivateKeyTag,
encryptionVersion: 2
}); });
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey); const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
const updateduser = await authDAL.transaction(async (tx) => { const updateduser = await authDAL.transaction(async (tx) => {

View File

@@ -98,6 +98,7 @@ export const superAdminServiceFactory = ({
if (existingUser) throw new BadRequestError({ name: "Admin sign up", message: "User already exist" }); if (existingUser) throw new BadRequestError({ name: "Admin sign up", message: "User already exist" });
const privateKey = await getUserPrivateKey(password, { const privateKey = await getUserPrivateKey(password, {
encryptionVersion: 2,
salt, salt,
protectedKey, protectedKey,
protectedKeyIV, protectedKeyIV,