Checkpoint adding crypto metadata

This commit is contained in:
Tuan Dang
2023-05-04 20:35:06 +03:00
parent c766686670
commit 5eeda6272c
9 changed files with 40 additions and 37 deletions
@@ -6,7 +6,7 @@ import { CreateSecretRequestBody, ModifySecretRequestBody, SanitizedSecretForCre
const { ValidationError } = mongoose.Error; const { ValidationError } = mongoose.Error;
import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors'; import { BadRequestError, InternalServerError, UnauthorizedRequestError, ValidationError as RouteValidationError } from '../../utils/errors';
import { AnyBulkWriteOperation } from 'mongodb'; import { AnyBulkWriteOperation } from 'mongodb';
import { SECRET_PERSONAL, SECRET_SHARED } from "../../variables"; import { ALGORITHM_AES_256_GCM, ENCODING_SCHEME_UTF8, SECRET_PERSONAL, SECRET_SHARED } from "../../variables";
import { TelemetryService } from '../../services'; import { TelemetryService } from '../../services';
import { User } from "../../models"; import { User } from "../../models";
import { AccountNotFoundError } from '../../utils/errors'; import { AccountNotFoundError } from '../../utils/errors';
@@ -36,7 +36,9 @@ export const createSecret = async (req: Request, res: Response) => {
workspace: new Types.ObjectId(workspaceId), workspace: new Types.ObjectId(workspaceId),
environment, environment,
type: secretToCreate.type, type: secretToCreate.type,
user: new Types.ObjectId(req.user._id) user: new Types.ObjectId(req.user._id),
algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
} }
@@ -92,7 +94,9 @@ export const createSecrets = async (req: Request, res: Response) => {
workspace: new Types.ObjectId(workspaceId), workspace: new Types.ObjectId(workspaceId),
environment, environment,
type: rawSecret.type, type: rawSecret.type,
user: new Types.ObjectId(req.user._id) user: new Types.ObjectId(req.user._id),
algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
} }
sanitizedSecretesToCreate.push(safeUpdateFields) sanitizedSecretesToCreate.push(safeUpdateFields)
-6
View File
@@ -13,7 +13,6 @@ export interface IBackupPrivateKey {
tag: string; tag: string;
salt: string; salt: string;
algorithm: string; algorithm: string;
keySize: number;
keyEncoding: 'base64' | 'utf8'; keyEncoding: 'base64' | 'utf8';
verifier: string; verifier: string;
} }
@@ -45,11 +44,6 @@ const backupPrivateKeySchema = new Schema<IBackupPrivateKey>(
enum: [ALGORITHM_AES_256_GCM], enum: [ALGORITHM_AES_256_GCM],
required: true required: true
}, },
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: { keyEncoding: {
type: String, type: String,
enum: [ enum: [
-6
View File
@@ -16,7 +16,6 @@ export interface IBot {
iv: string; iv: string;
tag: string; tag: string;
algorithm: 'aes-256-gcm'; algorithm: 'aes-256-gcm';
keySize: 256;
keyEncoding: 'base64' | 'utf8'; keyEncoding: 'base64' | 'utf8';
} }
@@ -60,11 +59,6 @@ const botSchema = new Schema<IBot>(
enum: [ALGORITHM_AES_256_GCM], enum: [ALGORITHM_AES_256_GCM],
required: true required: true
}, },
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: { keyEncoding: {
type: String, type: String,
enum: [ enum: [
+1 -7
View File
@@ -35,8 +35,7 @@ export interface IIntegrationAuth extends Document {
accessIV?: string; accessIV?: string;
accessTag?: string; accessTag?: string;
algorithm?: 'aes-256-gcm'; algorithm?: 'aes-256-gcm';
keySize?: 256; keyEncoding?: 'utf8' | 'base64';
keyEncoding: 'utf8' | 'base64';
accessExpiresAt?: Date; accessExpiresAt?: Date;
} }
@@ -120,11 +119,6 @@ const integrationAuthSchema = new Schema<IIntegrationAuth>(
enum: [ALGORITHM_AES_256_GCM], enum: [ALGORITHM_AES_256_GCM],
required: true required: true
}, },
keySize: { // the size of the key used in the algorithm
type: Number,
enum: [256],
required: true
},
keyEncoding: { keyEncoding: {
type: String, type: String,
enum: [ enum: [
+18
View File
@@ -2,6 +2,9 @@ import { Schema, model, Types } from 'mongoose';
import { import {
SECRET_SHARED, SECRET_SHARED,
SECRET_PERSONAL, SECRET_PERSONAL,
ALGORITHM_AES_256_GCM,
ENCODING_SCHEME_UTF8,
ENCODING_SCHEME_BASE64
} from '../variables'; } from '../variables';
import { ROOT_FOLDER_PATH } from '../utils/folder'; import { ROOT_FOLDER_PATH } from '../utils/folder';
@@ -25,6 +28,8 @@ export interface ISecret {
secretCommentIV?: string; secretCommentIV?: string;
secretCommentTag?: string; secretCommentTag?: string;
secretCommentHash?: string; secretCommentHash?: string;
algorithm: 'aes-256-gcm';
keyEncoding: 'utf8' | 'base64';
tags?: string[]; tags?: string[];
path?: string; path?: string;
folder?: Types.ObjectId; folder?: Types.ObjectId;
@@ -111,6 +116,19 @@ const secretSchema = new Schema<ISecret>(
type: String, type: String,
required: false required: false
}, },
algorithm: { // the encryption algorithm used
type: String,
enum: [ALGORITHM_AES_256_GCM],
required: true
},
keyEncoding: {
type: String,
enum: [
ENCODING_SCHEME_UTF8,
ENCODING_SCHEME_BASE64
],
required: true
},
// the full path to the secret in relation to folders // the full path to the secret in relation to folders
path: { path: {
type: String, type: String,
@@ -12,7 +12,6 @@ export interface ISecretBlindIndexData extends Document {
saltIV: string; saltIV: string;
saltTag: string; saltTag: string;
algorithm: 'aes-256-gcm'; algorithm: 'aes-256-gcm';
keySize: 256;
keyEncoding: 'base64' | 'utf8' keyEncoding: 'base64' | 'utf8'
} }
@@ -40,11 +39,6 @@ const secretBlindIndexDataSchema = new Schema<ISecretBlindIndexData>(
enum: [ALGORITHM_AES_256_GCM], enum: [ALGORITHM_AES_256_GCM],
required: true required: true
}, },
keySize: {
type: Number,
enum: [256],
required: true
},
keyEncoding: { keyEncoding: {
type: String, type: String,
enum: [ enum: [
+3 -3
View File
@@ -16,7 +16,7 @@ import {
} from '../errors'; } from '../errors';
import { import {
ALGORITHM_AES_256_GCM, ALGORITHM_AES_256_GCM,
BLOCK_SIZE_BYTES_32, NONCE_BYTES_SIZE,
BLOCK_SIZE_BYTES_16 BLOCK_SIZE_BYTES_16
} from '../../variables'; } from '../../variables';
import { validateEncryptionKey } from '../../validation'; import { validateEncryptionKey } from '../../validation';
@@ -112,7 +112,7 @@ const encryptSymmetric = ({
}: IEncryptSymmetricInput): IEncryptSymmetricOutput => { }: IEncryptSymmetricInput): IEncryptSymmetricOutput => {
validateEncryptionKey(key); validateEncryptionKey(key);
const iv = crypto.randomBytes(BLOCK_SIZE_BYTES_32); const iv = crypto.randomBytes(NONCE_BYTES_SIZE);
const secretKey = crypto.createSecretKey(key, 'base64'); const secretKey = crypto.createSecretKey(key, 'base64');
const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv); const cipher = crypto.createCipheriv(ALGORITHM_AES_256_GCM, secretKey, iv);
@@ -169,7 +169,7 @@ const decryptSymmetric = ({
* *
* @param {Object} obj * @param {Object} obj
* @param {String} obj.plaintext - (utf8) plaintext to encrypt * @param {String} obj.plaintext - (utf8) plaintext to encrypt
* @param {String} obj.key - (base64) 256-bit key * @param {String} obj.key - (hex) 128-bit key
* @returns {Object} obj * @returns {Object} obj
* @returns {String} obj.ciphertext (base64) ciphertext * @returns {String} obj.ciphertext (base64) ciphertext
* @returns {String} obj.iv (base64) iv * @returns {String} obj.iv (base64) iv
+10 -5
View File
@@ -114,7 +114,6 @@ export const backfillEncryptionMetadata = async () => {
{ {
$set: { $set: {
algorithm: ALGORITHM_AES_256_GCM, algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8 keyEncoding: ENCODING_SCHEME_UTF8
} }
} }
@@ -136,7 +135,6 @@ export const backfillEncryptionMetadata = async () => {
{ {
$set: { $set: {
algorithm: ALGORITHM_AES_256_GCM, algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8 keyEncoding: ENCODING_SCHEME_UTF8
} }
} }
@@ -158,7 +156,6 @@ export const backfillEncryptionMetadata = async () => {
{ {
$set: { $set: {
algorithm: ALGORITHM_AES_256_GCM, algorithm: ALGORITHM_AES_256_GCM,
keySize: 256,
keyEncoding: ENCODING_SCHEME_UTF8 keyEncoding: ENCODING_SCHEME_UTF8
} }
} }
@@ -167,12 +164,20 @@ export const backfillEncryptionMetadata = async () => {
// backfill integration auth encryption metadata // backfill integration auth encryption metadata
await IntegrationAuth.updateMany( await IntegrationAuth.updateMany(
{ {
algorithm: {
$exists: false
},
keySize: {
$exists: false
},
keyEncoding: {
$exists: false
}
}, },
{ {
$set: { $set: {
algorithm: ALGORITHM_AES_256_GCM, algorithm: ALGORITHM_AES_256_GCM,
keyEncoding: ENCODING_SCHEME_UTF8
} }
} }
); );
+1 -1
View File
@@ -1,5 +1,5 @@
export const ALGORITHM_AES_256_GCM = 'aes-256-gcm'; export const ALGORITHM_AES_256_GCM = 'aes-256-gcm';
export const BLOCK_SIZE_BYTES_32 = 32; export const NONCE_BYTES_SIZE = 12;
export const BLOCK_SIZE_BYTES_16 = 16; export const BLOCK_SIZE_BYTES_16 = 16;
export const ENCODING_SCHEME_UTF8 = 'utf8'; export const ENCODING_SCHEME_UTF8 = 'utf8';