mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #2001 from akhilmhdh/fix/handover-enc-v1
feat: resolved generate srp failing for user enc v1 users
This commit is contained in:
@@ -101,33 +101,51 @@ export const getUserPrivateKey = async (
|
|||||||
password: string,
|
password: string,
|
||||||
user: Pick<
|
user: Pick<
|
||||||
TUserEncryptionKeys,
|
TUserEncryptionKeys,
|
||||||
"protectedKeyTag" | "protectedKey" | "protectedKeyIV" | "encryptedPrivateKey" | "iv" | "salt" | "tag"
|
| "protectedKeyTag"
|
||||||
|
| "protectedKey"
|
||||||
|
| "protectedKeyIV"
|
||||||
|
| "encryptedPrivateKey"
|
||||||
|
| "iv"
|
||||||
|
| "salt"
|
||||||
|
| "tag"
|
||||||
|
| "encryptionVersion"
|
||||||
>
|
>
|
||||||
) => {
|
) => {
|
||||||
const derivedKey = await argon2.hash(password, {
|
if (user.encryptionVersion === 1) {
|
||||||
salt: Buffer.from(user.salt),
|
return decryptSymmetric128BitHexKeyUTF8({
|
||||||
memoryCost: 65536,
|
ciphertext: user.encryptedPrivateKey,
|
||||||
timeCost: 3,
|
iv: user.iv,
|
||||||
parallelism: 1,
|
tag: user.tag,
|
||||||
hashLength: 32,
|
key: password.slice(0, 32).padStart(32 + (password.slice(0, 32).length - new Blob([password]).size), "0")
|
||||||
type: argon2.argon2id,
|
});
|
||||||
raw: true
|
}
|
||||||
});
|
if (user.encryptionVersion === 2 && user.protectedKey && user.protectedKeyIV && user.protectedKeyTag) {
|
||||||
if (!derivedKey) throw new Error("Failed to derive key from password");
|
const derivedKey = await argon2.hash(password, {
|
||||||
const key = decryptSymmetric128BitHexKeyUTF8({
|
salt: Buffer.from(user.salt),
|
||||||
ciphertext: user.protectedKey as string,
|
memoryCost: 65536,
|
||||||
iv: user.protectedKeyIV as string,
|
timeCost: 3,
|
||||||
tag: user.protectedKeyTag as string,
|
parallelism: 1,
|
||||||
key: derivedKey
|
hashLength: 32,
|
||||||
});
|
type: argon2.argon2id,
|
||||||
|
raw: true
|
||||||
|
});
|
||||||
|
if (!derivedKey) throw new Error("Failed to derive key from password");
|
||||||
|
const key = decryptSymmetric128BitHexKeyUTF8({
|
||||||
|
ciphertext: user.protectedKey,
|
||||||
|
iv: user.protectedKeyIV,
|
||||||
|
tag: user.protectedKeyTag,
|
||||||
|
key: derivedKey
|
||||||
|
});
|
||||||
|
|
||||||
const privateKey = decryptSymmetric128BitHexKeyUTF8({
|
const privateKey = decryptSymmetric128BitHexKeyUTF8({
|
||||||
ciphertext: user.encryptedPrivateKey,
|
ciphertext: user.encryptedPrivateKey,
|
||||||
iv: user.iv,
|
iv: user.iv,
|
||||||
tag: user.tag,
|
tag: user.tag,
|
||||||
key: Buffer.from(key, "hex")
|
key: Buffer.from(key, "hex")
|
||||||
});
|
});
|
||||||
return privateKey;
|
return privateKey;
|
||||||
|
}
|
||||||
|
throw new Error(`GetUserPrivateKey: Encryption version not found`);
|
||||||
};
|
};
|
||||||
|
|
||||||
export const buildUserProjectKey = async (privateKey: string, publickey: string) => {
|
export const buildUserProjectKey = async (privateKey: string, publickey: string) => {
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import { generateSrpServerKey, srpCheckClientProof } from "@app/lib/crypto";
|
|||||||
import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
import { infisicalSymmetricEncypt } from "@app/lib/crypto/encryption";
|
||||||
import { getUserPrivateKey } from "@app/lib/crypto/srp";
|
import { getUserPrivateKey } from "@app/lib/crypto/srp";
|
||||||
import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/errors";
|
import { BadRequestError, DatabaseError, UnauthorizedError } from "@app/lib/errors";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
import { getServerCfg } from "@app/services/super-admin/super-admin-service";
|
||||||
|
|
||||||
import { TTokenDALFactory } from "../auth-token/auth-token-dal";
|
import { TTokenDALFactory } from "../auth-token/auth-token-dal";
|
||||||
@@ -258,7 +259,13 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
// from password decrypt the private key
|
// from password decrypt the private key
|
||||||
if (password) {
|
if (password) {
|
||||||
const privateKey = await getUserPrivateKey(password, userEnc);
|
const privateKey = await getUserPrivateKey(password, userEnc).catch((err) => {
|
||||||
|
logger.error(
|
||||||
|
err,
|
||||||
|
`loginExchangeClientProof: private key generation failed for [userId=${user.id}] and [email=${user.email}] `
|
||||||
|
);
|
||||||
|
return "";
|
||||||
|
});
|
||||||
const hashedPassword = await bcrypt.hash(password, cfg.BCRYPT_SALT_ROUND);
|
const hashedPassword = await bcrypt.hash(password, cfg.BCRYPT_SALT_ROUND);
|
||||||
const { iv, tag, ciphertext, encoding } = infisicalSymmetricEncypt(privateKey);
|
const { iv, tag, ciphertext, encoding } = infisicalSymmetricEncypt(privateKey);
|
||||||
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
|
await userDAL.updateUserEncryptionByUserId(userEnc.userId, {
|
||||||
|
|||||||
@@ -165,7 +165,8 @@ export const authSignupServiceFactory = ({
|
|||||||
protectedKeyTag,
|
protectedKeyTag,
|
||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag
|
tag: encryptedPrivateKeyTag,
|
||||||
|
encryptionVersion: 2
|
||||||
});
|
});
|
||||||
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
||||||
const updateduser = await authDAL.transaction(async (tx) => {
|
const updateduser = await authDAL.transaction(async (tx) => {
|
||||||
@@ -325,7 +326,8 @@ export const authSignupServiceFactory = ({
|
|||||||
protectedKeyTag,
|
protectedKeyTag,
|
||||||
encryptedPrivateKey,
|
encryptedPrivateKey,
|
||||||
iv: encryptedPrivateKeyIV,
|
iv: encryptedPrivateKeyIV,
|
||||||
tag: encryptedPrivateKeyTag
|
tag: encryptedPrivateKeyTag,
|
||||||
|
encryptionVersion: 2
|
||||||
});
|
});
|
||||||
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
const { tag, encoding, ciphertext, iv } = infisicalSymmetricEncypt(privateKey);
|
||||||
const updateduser = await authDAL.transaction(async (tx) => {
|
const updateduser = await authDAL.transaction(async (tx) => {
|
||||||
|
|||||||
@@ -98,6 +98,7 @@ export const superAdminServiceFactory = ({
|
|||||||
if (existingUser) throw new BadRequestError({ name: "Admin sign up", message: "User already exist" });
|
if (existingUser) throw new BadRequestError({ name: "Admin sign up", message: "User already exist" });
|
||||||
|
|
||||||
const privateKey = await getUserPrivateKey(password, {
|
const privateKey = await getUserPrivateKey(password, {
|
||||||
|
encryptionVersion: 2,
|
||||||
salt,
|
salt,
|
||||||
protectedKey,
|
protectedKey,
|
||||||
protectedKeyIV,
|
protectedKeyIV,
|
||||||
|
|||||||
Reference in New Issue
Block a user