Checkpoint adding crypto metadata

This commit is contained in:
Tuan Dang
2023-05-04 20:35:06 +03:00
parent c766686670
commit 5eeda6272c
9 changed files with 40 additions and 37 deletions

View File

@@ -6,7 +6,7 @@ import { CreateSecretRequestBody, ModifySecretRequestBody, SanitizedSecretForCre
const { ValidationError } = mongoose.Error;
import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors';
import { AnyBulkWriteOperation } from 'mongodb';
import { SECRET_PERSONAL, SECRET_SHARED } from "../../variables";
import { ALGORITHM_AES_256_GCM, ENCODING_SCHEME_UTF8, SECRET_PERSONAL, SECRET_SHARED } from "../../variables";
import { TelemetryService } from '../../services';
import { User } from "../../models";
import { AccountNotFoundError } from '../../utils/errors';
@@ -36,7 +36,9 @@ export const createSecret = async (req: Request, res: Response) => {
workspace: new Types.ObjectId(workspaceId),
environment,
type: secretToCreate.type,
user: new Types.ObjectId(req.user._id)
user: new Types.ObjectId(req.user._id),
algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
}
@@ -92,7 +94,9 @@ export const createSecrets = async (req: Request, res: Response) => {
workspace: new Types.ObjectId(workspaceId),
environment,
type: rawSecret.type,
user: new Types.ObjectId(req.user._id)
user: new Types.ObjectId(req.user._id),
algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
}
sanitizedSecretesToCreate.push(safeUpdateFields)

View File

@@ -13,7 +13,6 @@ export interface IBackupPrivateKey {
tag: string;
salt: string;
algorithm: string;
keySize: number;
keyEncoding: 'base64' | 'utf8';
verifier: string;
}
@@ -45,11 +44,6 @@ const backupPrivateKeySchema = new Schema<IBackupPrivateKey>(
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: {
type: String,
enum: [

View File

@@ -16,7 +16,6 @@ export interface IBot {
iv: string;
tag: string;
algorithm: 'aes-256-gcm';
keySize: 256;
keyEncoding: 'base64' | 'utf8';
}
@@ -60,11 +59,6 @@ const botSchema = new Schema<IBot>(
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: {
type: String,
enum: [

View File

@@ -35,8 +35,7 @@ export interface IIntegrationAuth extends Document {
accessIV?: string;
accessTag?: string;
algorithm?: 'aes-256-gcm';
keySize?: 256;
keyEncoding: 'utf8' | 'base64';
keyEncoding?: 'utf8' | 'base64';
accessExpiresAt?: Date;
}
@@ -120,11 +119,6 @@ const integrationAuthSchema = new Schema<IIntegrationAuth>(
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: {
type: String,
enum: [

View File

@@ -2,6 +2,9 @@ import { Schema, model, Types } from 'mongoose';
import {
SECRET_SHARED,
SECRET_PERSONAL,
ALGORITHM_AES_256_GCM,
ENCODING_SCHEME_UTF8,
ENCODING_SCHEME_BASE64
} from '../variables';
import { ROOT_FOLDER_PATH } from '../utils/folder';
@@ -25,6 +28,8 @@ export interface ISecret {
secretCommentIV?: string;
secretCommentTag?: string;
secretCommentHash?: string;
algorithm: 'aes-256-gcm';
keyEncoding: 'utf8' | 'base64';
tags?: string[];
path?: string;
folder?: Types.ObjectId;
@@ -111,6 +116,19 @@ const secretSchema = new Schema<ISecret>(
type: String,
required: false
},
algorithm: { // the encryption algorithm used
type: String,
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keyEncoding: {
type: String,
enum: [
ENCODING_SCHEME_UTF8,
ENCODING_SCHEME_BASE64
],
required: true
},
// the full path to the secret in relation to folders
path: {
type: String,

View File

@@ -12,7 +12,6 @@ export interface ISecretBlindIndexData extends Document {
saltIV: string;
saltTag: string;
algorithm: 'aes-256-gcm';
keySize: 256;
keyEncoding: 'base64' | 'utf8'
}
@@ -40,11 +39,6 @@ const secretBlindIndexDataSchema = new Schema<ISecretBlindIndexData>(
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keySize: {
type: Number,
enum: [256],
required: true
},
keyEncoding: {
type: String,
enum: [

View File

@@ -16,7 +16,7 @@ import {
} from '../errors';
import {
ALGORITHM_AES_256_GCM,
BLOCK_SIZE_BYTES_32,
NONCE_BYTES_SIZE,
BLOCK_SIZE_BYTES_16
} from '../../variables';
import { validateEncryptionKey } from '../../validation';
@@ -112,7 +112,7 @@ const encryptSymmetric = ({
}: IEncryptSymmetricInput): IEncryptSymmetricOutput => {
validateEncryptionKey(key);
const iv = crypto.randomBytes(BLOCK_SIZE_BYTES_32);
const iv = crypto.randomBytes(NONCE_BYTES_SIZE);
const secretKey = crypto.createSecretKey(key, 'base64');
const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv);
@@ -169,7 +169,7 @@ const decryptSymmetric = ({
*
* @param {Object} obj
* @param {String} obj.plaintext - (utf8) plaintext to encrypt
* @param {String} obj.key - (base64) 256-bit key
* @param {String} obj.key - (hex) 128-bit key
* @returns {Object} obj
* @returns {String} obj.ciphertext (base64) ciphertext
* @returns {String} obj.iv (base64) iv

View File

@@ -114,7 +114,6 @@ export const backfillEncryptionMetadata = async () => {
{
$set: {
algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8
}
}
@@ -136,7 +135,6 @@ export const backfillEncryptionMetadata = async () => {
{
$set: {
algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8
}
}
@@ -158,7 +156,6 @@ export const backfillEncryptionMetadata = async () => {
{
$set: {
algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8
}
}
@@ -167,12 +164,20 @@ export const backfillEncryptionMetadata = async () => {
// backfill integration auth encryption metadata
await IntegrationAuth.updateMany(
{
algorithm: {
$exists: false
},
keySize: {
$exists: false
},
keyEncoding: {
$exists: false
}
},
{
$set: {
algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
}
}
);

View File

@@ -1,5 +1,5 @@
export const ALGORITHM_AES_256_GCM = 'aes-256-gcm';
export const BLOCK_SIZE_BYTES_32 = 32;
export const NONCE_BYTES_SIZE = 12;
export const BLOCK_SIZE_BYTES_16 = 16;
export const ENCODING_SCHEME_UTF8 = 'utf8';