mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 16:28:11 +00:00
Checkpoint adding crypto metadata
This commit is contained in:
@@ -6,7 +6,7 @@ import { CreateSecretRequestBody, ModifySecretRequestBody, SanitizedSecretForCre
|
|||||||
const { ValidationError } = mongoose.Error;
|
const { ValidationError } = mongoose.Error;
|
||||||
import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors';
|
import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors';
|
||||||
import { AnyBulkWriteOperation } from 'mongodb';
|
import { AnyBulkWriteOperation } from 'mongodb';
|
||||||
import { SECRET_PERSONAL, SECRET_SHARED } from "../../variables";
|
import { ALGORITHM_AES_256_GCM, ENCODING_SCHEME_UTF8, SECRET_PERSONAL, SECRET_SHARED } from "../../variables";
|
||||||
import { TelemetryService } from '../../services';
|
import { TelemetryService } from '../../services';
|
||||||
import { User } from "../../models";
|
import { User } from "../../models";
|
||||||
import { AccountNotFoundError } from '../../utils/errors';
|
import { AccountNotFoundError } from '../../utils/errors';
|
||||||
@@ -36,7 +36,9 @@ export const createSecret = async (req: Request, res: Response) => {
|
|||||||
workspace: new Types.ObjectId(workspaceId),
|
workspace: new Types.ObjectId(workspaceId),
|
||||||
environment,
|
environment,
|
||||||
type: secretToCreate.type,
|
type: secretToCreate.type,
|
||||||
user: new Types.ObjectId(req.user._id)
|
user: new Types.ObjectId(req.user._id),
|
||||||
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -92,7 +94,9 @@ export const createSecrets = async (req: Request, res: Response) => {
|
|||||||
workspace: new Types.ObjectId(workspaceId),
|
workspace: new Types.ObjectId(workspaceId),
|
||||||
environment,
|
environment,
|
||||||
type: rawSecret.type,
|
type: rawSecret.type,
|
||||||
user: new Types.ObjectId(req.user._id)
|
user: new Types.ObjectId(req.user._id),
|
||||||
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
|
|
||||||
sanitizedSecretesToCreate.push(safeUpdateFields)
|
sanitizedSecretesToCreate.push(safeUpdateFields)
|
||||||
|
|||||||
@@ -13,7 +13,6 @@ export interface IBackupPrivateKey {
|
|||||||
tag: string;
|
tag: string;
|
||||||
salt: string;
|
salt: string;
|
||||||
algorithm: string;
|
algorithm: string;
|
||||||
keySize: number;
|
|
||||||
keyEncoding: 'base64' | 'utf8';
|
keyEncoding: 'base64' | 'utf8';
|
||||||
verifier: string;
|
verifier: string;
|
||||||
}
|
}
|
||||||
@@ -45,11 +44,6 @@ const backupPrivateKeySchema = new Schema<IBackupPrivateKey>(
|
|||||||
enum: [ALGORITHM_AES_256_GCM],
|
enum: [ALGORITHM_AES_256_GCM],
|
||||||
required: true
|
required: true
|
||||||
},
|
},
|
||||||
keySize: { // the size of the key used in the algorithm
|
|
||||||
type: Number,
|
|
||||||
enum: [256],
|
|
||||||
required: true
|
|
||||||
},
|
|
||||||
keyEncoding: {
|
keyEncoding: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: [
|
enum: [
|
||||||
|
|||||||
@@ -16,7 +16,6 @@ export interface IBot {
|
|||||||
iv: string;
|
iv: string;
|
||||||
tag: string;
|
tag: string;
|
||||||
algorithm: 'aes-256-gcm';
|
algorithm: 'aes-256-gcm';
|
||||||
keySize: 256;
|
|
||||||
keyEncoding: 'base64' | 'utf8';
|
keyEncoding: 'base64' | 'utf8';
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -60,11 +59,6 @@ const botSchema = new Schema<IBot>(
|
|||||||
enum: [ALGORITHM_AES_256_GCM],
|
enum: [ALGORITHM_AES_256_GCM],
|
||||||
required: true
|
required: true
|
||||||
},
|
},
|
||||||
keySize: { // the size of the key used in the algorithm
|
|
||||||
type: Number,
|
|
||||||
enum: [256],
|
|
||||||
required: true
|
|
||||||
},
|
|
||||||
keyEncoding: {
|
keyEncoding: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: [
|
enum: [
|
||||||
|
|||||||
@@ -35,8 +35,7 @@ export interface IIntegrationAuth extends Document {
|
|||||||
accessIV?: string;
|
accessIV?: string;
|
||||||
accessTag?: string;
|
accessTag?: string;
|
||||||
algorithm?: 'aes-256-gcm';
|
algorithm?: 'aes-256-gcm';
|
||||||
keySize?: 256;
|
keyEncoding?: 'utf8' | 'base64';
|
||||||
keyEncoding: 'utf8' | 'base64';
|
|
||||||
accessExpiresAt?: Date;
|
accessExpiresAt?: Date;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -120,11 +119,6 @@ const integrationAuthSchema = new Schema<IIntegrationAuth>(
|
|||||||
enum: [ALGORITHM_AES_256_GCM],
|
enum: [ALGORITHM_AES_256_GCM],
|
||||||
required: true
|
required: true
|
||||||
},
|
},
|
||||||
keySize: { // the size of the key used in the algorithm
|
|
||||||
type: Number,
|
|
||||||
enum: [256],
|
|
||||||
required: true
|
|
||||||
},
|
|
||||||
keyEncoding: {
|
keyEncoding: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: [
|
enum: [
|
||||||
|
|||||||
@@ -2,6 +2,9 @@ import { Schema, model, Types } from 'mongoose';
|
|||||||
import {
|
import {
|
||||||
SECRET_SHARED,
|
SECRET_SHARED,
|
||||||
SECRET_PERSONAL,
|
SECRET_PERSONAL,
|
||||||
|
ALGORITHM_AES_256_GCM,
|
||||||
|
ENCODING_SCHEME_UTF8,
|
||||||
|
ENCODING_SCHEME_BASE64
|
||||||
} from '../variables';
|
} from '../variables';
|
||||||
import { ROOT_FOLDER_PATH } from '../utils/folder';
|
import { ROOT_FOLDER_PATH } from '../utils/folder';
|
||||||
|
|
||||||
@@ -25,6 +28,8 @@ export interface ISecret {
|
|||||||
secretCommentIV?: string;
|
secretCommentIV?: string;
|
||||||
secretCommentTag?: string;
|
secretCommentTag?: string;
|
||||||
secretCommentHash?: string;
|
secretCommentHash?: string;
|
||||||
|
algorithm: 'aes-256-gcm';
|
||||||
|
keyEncoding: 'utf8' | 'base64';
|
||||||
tags?: string[];
|
tags?: string[];
|
||||||
path?: string;
|
path?: string;
|
||||||
folder?: Types.ObjectId;
|
folder?: Types.ObjectId;
|
||||||
@@ -111,6 +116,19 @@ const secretSchema = new Schema<ISecret>(
|
|||||||
type: String,
|
type: String,
|
||||||
required: false
|
required: false
|
||||||
},
|
},
|
||||||
|
algorithm: { // the encryption algorithm used
|
||||||
|
type: String,
|
||||||
|
enum: [ALGORITHM_AES_256_GCM],
|
||||||
|
required: true
|
||||||
|
},
|
||||||
|
keyEncoding: {
|
||||||
|
type: String,
|
||||||
|
enum: [
|
||||||
|
ENCODING_SCHEME_UTF8,
|
||||||
|
ENCODING_SCHEME_BASE64
|
||||||
|
],
|
||||||
|
required: true
|
||||||
|
},
|
||||||
// the full path to the secret in relation to folders
|
// the full path to the secret in relation to folders
|
||||||
path: {
|
path: {
|
||||||
type: String,
|
type: String,
|
||||||
|
|||||||
@@ -12,7 +12,6 @@ export interface ISecretBlindIndexData extends Document {
|
|||||||
saltIV: string;
|
saltIV: string;
|
||||||
saltTag: string;
|
saltTag: string;
|
||||||
algorithm: 'aes-256-gcm';
|
algorithm: 'aes-256-gcm';
|
||||||
keySize: 256;
|
|
||||||
keyEncoding: 'base64' | 'utf8'
|
keyEncoding: 'base64' | 'utf8'
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -40,11 +39,6 @@ const secretBlindIndexDataSchema = new Schema<ISecretBlindIndexData>(
|
|||||||
enum: [ALGORITHM_AES_256_GCM],
|
enum: [ALGORITHM_AES_256_GCM],
|
||||||
required: true
|
required: true
|
||||||
},
|
},
|
||||||
keySize: {
|
|
||||||
type: Number,
|
|
||||||
enum: [256],
|
|
||||||
required: true
|
|
||||||
},
|
|
||||||
keyEncoding: {
|
keyEncoding: {
|
||||||
type: String,
|
type: String,
|
||||||
enum: [
|
enum: [
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ import {
|
|||||||
} from '../errors';
|
} from '../errors';
|
||||||
import {
|
import {
|
||||||
ALGORITHM_AES_256_GCM,
|
ALGORITHM_AES_256_GCM,
|
||||||
BLOCK_SIZE_BYTES_32,
|
NONCE_BYTES_SIZE,
|
||||||
BLOCK_SIZE_BYTES_16
|
BLOCK_SIZE_BYTES_16
|
||||||
} from '../../variables';
|
} from '../../variables';
|
||||||
import { validateEncryptionKey } from '../../validation';
|
import { validateEncryptionKey } from '../../validation';
|
||||||
@@ -112,7 +112,7 @@ const encryptSymmetric = ({
|
|||||||
}: IEncryptSymmetricInput): IEncryptSymmetricOutput => {
|
}: IEncryptSymmetricInput): IEncryptSymmetricOutput => {
|
||||||
validateEncryptionKey(key);
|
validateEncryptionKey(key);
|
||||||
|
|
||||||
const iv = crypto.randomBytes(BLOCK_SIZE_BYTES_32);
|
const iv = crypto.randomBytes(NONCE_BYTES_SIZE);
|
||||||
const secretKey = crypto.createSecretKey(key, 'base64');
|
const secretKey = crypto.createSecretKey(key, 'base64');
|
||||||
const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv);
|
const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv);
|
||||||
|
|
||||||
@@ -169,7 +169,7 @@ const decryptSymmetric = ({
|
|||||||
*
|
*
|
||||||
* @param {Object} obj
|
* @param {Object} obj
|
||||||
* @param {String} obj.plaintext - (utf8) plaintext to encrypt
|
* @param {String} obj.plaintext - (utf8) plaintext to encrypt
|
||||||
* @param {String} obj.key - (base64) 256-bit key
|
* @param {String} obj.key - (hex) 128-bit key
|
||||||
* @returns {Object} obj
|
* @returns {Object} obj
|
||||||
* @returns {String} obj.ciphertext (base64) ciphertext
|
* @returns {String} obj.ciphertext (base64) ciphertext
|
||||||
* @returns {String} obj.iv (base64) iv
|
* @returns {String} obj.iv (base64) iv
|
||||||
|
|||||||
@@ -114,7 +114,6 @@ export const backfillEncryptionMetadata = async () => {
|
|||||||
{
|
{
|
||||||
$set: {
|
$set: {
|
||||||
algorithm: ALGORITHM_AES_256_GCM,
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
keySize: 256,
|
|
||||||
keyEncoding: ENCODING_SCHEME_UTF8
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -136,7 +135,6 @@ export const backfillEncryptionMetadata = async () => {
|
|||||||
{
|
{
|
||||||
$set: {
|
$set: {
|
||||||
algorithm: ALGORITHM_AES_256_GCM,
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
keySize: 256,
|
|
||||||
keyEncoding: ENCODING_SCHEME_UTF8
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -158,7 +156,6 @@ export const backfillEncryptionMetadata = async () => {
|
|||||||
{
|
{
|
||||||
$set: {
|
$set: {
|
||||||
algorithm: ALGORITHM_AES_256_GCM,
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
keySize: 256,
|
|
||||||
keyEncoding: ENCODING_SCHEME_UTF8
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -167,12 +164,20 @@ export const backfillEncryptionMetadata = async () => {
|
|||||||
// backfill integration auth encryption metadata
|
// backfill integration auth encryption metadata
|
||||||
await IntegrationAuth.updateMany(
|
await IntegrationAuth.updateMany(
|
||||||
{
|
{
|
||||||
|
algorithm: {
|
||||||
|
$exists: false
|
||||||
|
},
|
||||||
|
keySize: {
|
||||||
|
$exists: false
|
||||||
|
},
|
||||||
|
keyEncoding: {
|
||||||
|
$exists: false
|
||||||
|
}
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
$set: {
|
$set: {
|
||||||
algorithm: ALGORITHM_AES_256_GCM,
|
algorithm: ALGORITHM_AES_256_GCM,
|
||||||
|
keyEncoding: ENCODING_SCHEME_UTF8
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
export const ALGORITHM_AES_256_GCM = 'aes-256-gcm';
|
export const ALGORITHM_AES_256_GCM = 'aes-256-gcm';
|
||||||
export const BLOCK_SIZE_BYTES_32 = 32;
|
export const NONCE_BYTES_SIZE = 12;
|
||||||
export const BLOCK_SIZE_BYTES_16 = 16;
|
export const BLOCK_SIZE_BYTES_16 = 16;
|
||||||
|
|
||||||
export const ENCODING_SCHEME_UTF8 = 'utf8';
|
export const ENCODING_SCHEME_UTF8 = 'utf8';
|
||||||
|
|||||||
Reference in New Issue
Block a user