mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
Merge pull request #3416 from Infisical/daniel/make-idoment
fix: improve kms key migration
This commit is contained in:
@@ -5,15 +5,21 @@ import { KmsKeyUsage } from "@app/services/kms/kms-types";
|
|||||||
import { TableName } from "../schemas";
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
export async function up(knex: Knex): Promise<void> {
|
export async function up(knex: Knex): Promise<void> {
|
||||||
const hasTypeColumn = await knex.schema.hasColumn(TableName.KmsKey, "type");
|
const hasKeyUsageColumn = await knex.schema.hasColumn(TableName.KmsKey, "keyUsage");
|
||||||
|
|
||||||
await knex.schema.alterTable(TableName.KmsKey, (t) => {
|
if (!hasKeyUsageColumn) {
|
||||||
if (!hasTypeColumn) t.string("keyUsage").notNullable().defaultTo(KmsKeyUsage.ENCRYPT_DECRYPT);
|
await knex.schema.alterTable(TableName.KmsKey, (t) => {
|
||||||
});
|
t.string("keyUsage").notNullable().defaultTo(KmsKeyUsage.ENCRYPT_DECRYPT);
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export async function down(knex: Knex): Promise<void> {
|
export async function down(knex: Knex): Promise<void> {
|
||||||
await knex.schema.alterTable(TableName.KmsKey, (t) => {
|
const hasKeyUsageColumn = await knex.schema.hasColumn(TableName.KmsKey, "keyUsage");
|
||||||
t.dropColumn("keyUsage");
|
|
||||||
});
|
if (hasKeyUsageColumn) {
|
||||||
|
await knex.schema.alterTable(TableName.KmsKey, (t) => {
|
||||||
|
t.dropColumn("keyUsage");
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -288,11 +288,6 @@ export const kmsServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: `KMS with ID '${kmsId}' not found` });
|
throw new NotFoundError({ message: `KMS with ID '${kmsId}' not found` });
|
||||||
}
|
}
|
||||||
|
|
||||||
const encryptionAlgorithm = kmsDoc.internalKms?.encryptionAlgorithm as SymmetricKeyAlgorithm;
|
|
||||||
verifyKeyTypeAndAlgorithm(kmsDoc.keyUsage as KmsKeyUsage, encryptionAlgorithm, {
|
|
||||||
forceType: KmsKeyUsage.ENCRYPT_DECRYPT
|
|
||||||
});
|
|
||||||
|
|
||||||
if (kmsDoc.externalKms) {
|
if (kmsDoc.externalKms) {
|
||||||
let externalKms: TExternalKmsProviderFns;
|
let externalKms: TExternalKmsProviderFns;
|
||||||
|
|
||||||
@@ -353,6 +348,11 @@ export const kmsServiceFactory = ({
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const encryptionAlgorithm = kmsDoc.internalKms?.encryptionAlgorithm as SymmetricKeyAlgorithm;
|
||||||
|
verifyKeyTypeAndAlgorithm(kmsDoc.keyUsage as KmsKeyUsage, encryptionAlgorithm, {
|
||||||
|
forceType: KmsKeyUsage.ENCRYPT_DECRYPT
|
||||||
|
});
|
||||||
|
|
||||||
// internal KMS
|
// internal KMS
|
||||||
const keyCipher = symmetricCipherService(SymmetricKeyAlgorithm.AES_GCM_256);
|
const keyCipher = symmetricCipherService(SymmetricKeyAlgorithm.AES_GCM_256);
|
||||||
const dataCipher = symmetricCipherService(encryptionAlgorithm);
|
const dataCipher = symmetricCipherService(encryptionAlgorithm);
|
||||||
@@ -509,11 +509,6 @@ export const kmsServiceFactory = ({
|
|||||||
throw new NotFoundError({ message: `KMS with ID '${kmsId}' not found` });
|
throw new NotFoundError({ message: `KMS with ID '${kmsId}' not found` });
|
||||||
}
|
}
|
||||||
|
|
||||||
const encryptionAlgorithm = kmsDoc.internalKms?.encryptionAlgorithm as SymmetricKeyAlgorithm;
|
|
||||||
verifyKeyTypeAndAlgorithm(kmsDoc.keyUsage as KmsKeyUsage, encryptionAlgorithm, {
|
|
||||||
forceType: KmsKeyUsage.ENCRYPT_DECRYPT
|
|
||||||
});
|
|
||||||
|
|
||||||
if (kmsDoc.externalKms) {
|
if (kmsDoc.externalKms) {
|
||||||
let externalKms: TExternalKmsProviderFns;
|
let externalKms: TExternalKmsProviderFns;
|
||||||
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
if (!kmsDoc.orgKms.id || !kmsDoc.orgKms.encryptedDataKey) {
|
||||||
@@ -568,6 +563,11 @@ export const kmsServiceFactory = ({
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const encryptionAlgorithm = kmsDoc.internalKms?.encryptionAlgorithm as SymmetricKeyAlgorithm;
|
||||||
|
verifyKeyTypeAndAlgorithm(kmsDoc.keyUsage as KmsKeyUsage, encryptionAlgorithm, {
|
||||||
|
forceType: KmsKeyUsage.ENCRYPT_DECRYPT
|
||||||
|
});
|
||||||
|
|
||||||
// internal KMS
|
// internal KMS
|
||||||
const keyCipher = symmetricCipherService(SymmetricKeyAlgorithm.AES_GCM_256);
|
const keyCipher = symmetricCipherService(SymmetricKeyAlgorithm.AES_GCM_256);
|
||||||
const dataCipher = symmetricCipherService(encryptionAlgorithm);
|
const dataCipher = symmetricCipherService(encryptionAlgorithm);
|
||||||
|
|||||||
Reference in New Issue
Block a user