From 5eeda6272c3a983e51ca9421ea82c52d558851a7 Mon Sep 17 00:00:00 2001 From: Tuan Dang Date: Thu, 4 May 2023 20:35:06 +0300 Subject: [PATCH] Checkpoint adding crypto metadata --- backend/src/controllers/v2/secretController.ts | 10 +++++++--- backend/src/models/backupPrivateKey.ts | 6 ------ backend/src/models/bot.ts | 6 ------ backend/src/models/integrationAuth.ts | 8 +------- backend/src/models/secret.ts | 18 ++++++++++++++++++ backend/src/models/secretBlindIndexData.ts | 6 ------ backend/src/utils/crypto/index.ts | 6 +++--- backend/src/utils/setup/backfill.ts | 15 ++++++++++----- backend/src/variables/crypto.ts | 2 +- 9 files changed, 40 insertions(+), 37 deletions(-) diff --git a/backend/src/controllers/v2/secretController.ts b/backend/src/controllers/v2/secretController.ts index 75eff3127..fecba43d6 100644 --- a/backend/src/controllers/v2/secretController.ts +++ b/backend/src/controllers/v2/secretController.ts @@ -6,7 +6,7 @@ import { CreateSecretRequestBody, ModifySecretRequestBody, SanitizedSecretForCre const { ValidationError } = mongoose.Error; import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors'; import { AnyBulkWriteOperation } from 'mongodb'; -import { SECRET_PERSONAL, SECRET_SHARED } from "../../variables"; +import { ALGORITHM_AES_256_GCM, ENCODING_SCHEME_UTF8, SECRET_PERSONAL, SECRET_SHARED } from "../../variables"; import { TelemetryService } from '../../services'; import { User } from "../../models"; import { AccountNotFoundError } from '../../utils/errors'; @@ -36,7 +36,9 @@ export const createSecret = async (req: Request, res: Response) => { workspace: new Types.ObjectId(workspaceId), environment, type: secretToCreate.type, - user: new Types.ObjectId(req.user._id) + user: new Types.ObjectId(req.user._id), + algorithm: ALGORITHM_AES_256_GCM, + keyEncoding: ENCODING_SCHEME_UTF8 } @@ -92,7 +94,9 @@ export const createSecrets = async (req: Request, res: Response) => { workspace: new Types.ObjectId(workspaceId), environment, type: rawSecret.type, - user: new Types.ObjectId(req.user._id) + user: new Types.ObjectId(req.user._id), + algorithm: ALGORITHM_AES_256_GCM, + keyEncoding: ENCODING_SCHEME_UTF8 } sanitizedSecretesToCreate.push(safeUpdateFields) diff --git a/backend/src/models/backupPrivateKey.ts b/backend/src/models/backupPrivateKey.ts index 580b0ab38..09bcbb588 100644 --- a/backend/src/models/backupPrivateKey.ts +++ b/backend/src/models/backupPrivateKey.ts @@ -13,7 +13,6 @@ export interface IBackupPrivateKey { tag: string; salt: string; algorithm: string; - keySize: number; keyEncoding: 'base64' | 'utf8'; verifier: string; } @@ -45,11 +44,6 @@ const backupPrivateKeySchema = new Schema( enum: [ALGORITHM_AES_256_GCM], required: true }, - keySize: { // the size of the key used in the algorithm - type: Number, - enum: [256], - required: true - }, keyEncoding: { type: String, enum: [ diff --git a/backend/src/models/bot.ts b/backend/src/models/bot.ts index 85b1c0adb..3dd90fb07 100644 --- a/backend/src/models/bot.ts +++ b/backend/src/models/bot.ts @@ -16,7 +16,6 @@ export interface IBot { iv: string; tag: string; algorithm: 'aes-256-gcm'; - keySize: 256; keyEncoding: 'base64' | 'utf8'; } @@ -60,11 +59,6 @@ const botSchema = new Schema( enum: [ALGORITHM_AES_256_GCM], required: true }, - keySize: { // the size of the key used in the algorithm - type: Number, - enum: [256], - required: true - }, keyEncoding: { type: String, enum: [ diff --git a/backend/src/models/integrationAuth.ts b/backend/src/models/integrationAuth.ts index b55aa9b2f..affe811df 100644 --- a/backend/src/models/integrationAuth.ts +++ b/backend/src/models/integrationAuth.ts @@ -35,8 +35,7 @@ export interface IIntegrationAuth extends Document { accessIV?: string; accessTag?: string; algorithm?: 'aes-256-gcm'; - keySize?: 256; - keyEncoding: 'utf8' | 'base64'; + keyEncoding?: 'utf8' | 'base64'; accessExpiresAt?: Date; } @@ -120,11 +119,6 @@ const integrationAuthSchema = new Schema( enum: [ALGORITHM_AES_256_GCM], required: true }, - keySize: { // the size of the key used in the algorithm - type: Number, - enum: [256], - required: true - }, keyEncoding: { type: String, enum: [ diff --git a/backend/src/models/secret.ts b/backend/src/models/secret.ts index 7670124bf..39e362bf7 100644 --- a/backend/src/models/secret.ts +++ b/backend/src/models/secret.ts @@ -2,6 +2,9 @@ import { Schema, model, Types } from 'mongoose'; import { SECRET_SHARED, SECRET_PERSONAL, + ALGORITHM_AES_256_GCM, + ENCODING_SCHEME_UTF8, + ENCODING_SCHEME_BASE64 } from '../variables'; import { ROOT_FOLDER_PATH } from '../utils/folder'; @@ -25,6 +28,8 @@ export interface ISecret { secretCommentIV?: string; secretCommentTag?: string; secretCommentHash?: string; + algorithm: 'aes-256-gcm'; + keyEncoding: 'utf8' | 'base64'; tags?: string[]; path?: string; folder?: Types.ObjectId; @@ -111,6 +116,19 @@ const secretSchema = new Schema( type: String, required: false }, + algorithm: { // the encryption algorithm used + type: String, + enum: [ALGORITHM_AES_256_GCM], + required: true + }, + keyEncoding: { + type: String, + enum: [ + ENCODING_SCHEME_UTF8, + ENCODING_SCHEME_BASE64 + ], + required: true + }, // the full path to the secret in relation to folders path: { type: String, diff --git a/backend/src/models/secretBlindIndexData.ts b/backend/src/models/secretBlindIndexData.ts index 47e82c053..fc9896618 100644 --- a/backend/src/models/secretBlindIndexData.ts +++ b/backend/src/models/secretBlindIndexData.ts @@ -12,7 +12,6 @@ export interface ISecretBlindIndexData extends Document { saltIV: string; saltTag: string; algorithm: 'aes-256-gcm'; - keySize: 256; keyEncoding: 'base64' | 'utf8' } @@ -40,11 +39,6 @@ const secretBlindIndexDataSchema = new Schema( enum: [ALGORITHM_AES_256_GCM], required: true }, - keySize: { - type: Number, - enum: [256], - required: true - }, keyEncoding: { type: String, enum: [ diff --git a/backend/src/utils/crypto/index.ts b/backend/src/utils/crypto/index.ts index bfe9df85a..0e7fb24b3 100644 --- a/backend/src/utils/crypto/index.ts +++ b/backend/src/utils/crypto/index.ts @@ -16,7 +16,7 @@ import { } from '../errors'; import { ALGORITHM_AES_256_GCM, - BLOCK_SIZE_BYTES_32, + NONCE_BYTES_SIZE, BLOCK_SIZE_BYTES_16 } from '../../variables'; import { validateEncryptionKey } from '../../validation'; @@ -112,7 +112,7 @@ const encryptSymmetric = ({ }: IEncryptSymmetricInput): IEncryptSymmetricOutput => { validateEncryptionKey(key); - const iv = crypto.randomBytes(BLOCK_SIZE_BYTES_32); + const iv = crypto.randomBytes(NONCE_BYTES_SIZE); const secretKey = crypto.createSecretKey(key, 'base64'); const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv); @@ -169,7 +169,7 @@ const decryptSymmetric = ({ * * @param {Object} obj * @param {String} obj.plaintext - (utf8) plaintext to encrypt - * @param {String} obj.key - (base64) 256-bit key + * @param {String} obj.key - (hex) 128-bit key * @returns {Object} obj * @returns {String} obj.ciphertext (base64) ciphertext * @returns {String} obj.iv (base64) iv diff --git a/backend/src/utils/setup/backfill.ts b/backend/src/utils/setup/backfill.ts index 4a06fe9ee..8a964dfd7 100644 --- a/backend/src/utils/setup/backfill.ts +++ b/backend/src/utils/setup/backfill.ts @@ -114,7 +114,6 @@ export const backfillEncryptionMetadata = async () => { { $set: { algorithm: ALGORITHM_AES_256_GCM, - keySize: 256, keyEncoding: ENCODING_SCHEME_UTF8 } } @@ -136,7 +135,6 @@ export const backfillEncryptionMetadata = async () => { { $set: { algorithm: ALGORITHM_AES_256_GCM, - keySize: 256, keyEncoding: ENCODING_SCHEME_UTF8 } } @@ -158,7 +156,6 @@ export const backfillEncryptionMetadata = async () => { { $set: { algorithm: ALGORITHM_AES_256_GCM, - keySize: 256, keyEncoding: ENCODING_SCHEME_UTF8 } } @@ -167,12 +164,20 @@ export const backfillEncryptionMetadata = async () => { // backfill integration auth encryption metadata await IntegrationAuth.updateMany( { - + algorithm: { + $exists: false + }, + keySize: { + $exists: false + }, + keyEncoding: { + $exists: false + } }, { $set: { algorithm: ALGORITHM_AES_256_GCM, - + keyEncoding: ENCODING_SCHEME_UTF8 } } ); diff --git a/backend/src/variables/crypto.ts b/backend/src/variables/crypto.ts index 3b8c7820d..bd2ae110c 100644 --- a/backend/src/variables/crypto.ts +++ b/backend/src/variables/crypto.ts @@ -1,5 +1,5 @@ export const ALGORITHM_AES_256_GCM = 'aes-256-gcm'; -export const BLOCK_SIZE_BYTES_32 = 32; +export const NONCE_BYTES_SIZE = 12; export const BLOCK_SIZE_BYTES_16 = 16; export const ENCODING_SCHEME_UTF8 = 'utf8';