remove encryptionKey validation check

This commit is contained in:
Maidul Islam
2023-06-06 09:43:11 -07:00
parent aaca66e5a4
commit 4bf2407d13
+17 -17
View File
@@ -21,39 +21,39 @@ import {
export const validateEncryptionKeysConfig = async () => { export const validateEncryptionKeysConfig = async () => {
const encryptionKey = await getEncryptionKey(); const encryptionKey = await getEncryptionKey();
const rootEncryptionKey = await getRootEncryptionKey(); const rootEncryptionKey = await getRootEncryptionKey();
if ( if (
(encryptionKey === undefined || encryptionKey === "") && (encryptionKey === undefined || encryptionKey === "") &&
(rootEncryptionKey === undefined || rootEncryptionKey === "") (rootEncryptionKey === undefined || rootEncryptionKey === "")
) throw InternalServerError({ ) throw InternalServerError({
message: "Failed to find required root encryption key environment variable. Please make sure that you're passing in a ROOT_ENCRYPTION_KEY environment variable." message: "Failed to find required root encryption key environment variable. Please make sure that you're passing in a ROOT_ENCRYPTION_KEY environment variable."
}); });
if (encryptionKey && encryptionKey !== '') {
// validate [encryptionKey]
const keyBuffer = Buffer.from(encryptionKey, 'hex');
const decoded = keyBuffer.toString('hex');
if (decoded !== encryptionKey) throw InternalServerError({ // if (encryptionKey && encryptionKey !== '') {
message: 'Failed to validate that the encryption key is correctly encoded in hex.' // // validate [encryptionKey]
});
// const keyBuffer = Buffer.from(encryptionKey, 'hex');
if (keyBuffer.length !== 16) throw InternalServerError({ // const decoded = keyBuffer.toString('hex');
message: 'Failed to validate that the encryption key is a 128-bit hex string.'
}); // if (decoded !== encryptionKey) throw InternalServerError({
} // message: 'Failed to validate that the encryption key is correctly encoded in hex.'
// });
// if (keyBuffer.length !== 16) throw InternalServerError({
// message: 'Failed to validate that the encryption key is a 128-bit hex string.'
// });
// }
if (rootEncryptionKey && rootEncryptionKey !== '') { if (rootEncryptionKey && rootEncryptionKey !== '') {
// validate [rootEncryptionKey] // validate [rootEncryptionKey]
const keyBuffer = Buffer.from(rootEncryptionKey, 'base64') const keyBuffer = Buffer.from(rootEncryptionKey, 'base64')
const decoded = keyBuffer.toString('base64'); const decoded = keyBuffer.toString('base64');
if (decoded !== rootEncryptionKey) throw InternalServerError({ if (decoded !== rootEncryptionKey) throw InternalServerError({
message: 'Failed to validate that the root encryption key is correctly encoded in base64' message: 'Failed to validate that the root encryption key is correctly encoded in base64'
}); });
if (keyBuffer.length !== 32) throw InternalServerError({ if (keyBuffer.length !== 32) throw InternalServerError({
message: 'Failed to validate that the encryption key is a 256-bit base64 string' message: 'Failed to validate that the encryption key is a 256-bit base64 string'
}); });