mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 17:26:36 +00:00
requested changes
This commit is contained in:
Generated
+1
-1
@@ -69,7 +69,7 @@
|
|||||||
"cassandra-driver": "^4.7.2",
|
"cassandra-driver": "^4.7.2",
|
||||||
"connect-redis": "^7.1.1",
|
"connect-redis": "^7.1.1",
|
||||||
"cron": "^3.1.7",
|
"cron": "^3.1.7",
|
||||||
"crypto-js": "^4.2.0",
|
"crypto-js": "4.2.0",
|
||||||
"dd-trace": "^5.40.0",
|
"dd-trace": "^5.40.0",
|
||||||
"dotenv": "^16.4.1",
|
"dotenv": "^16.4.1",
|
||||||
"fastify": "^4.28.1",
|
"fastify": "^4.28.1",
|
||||||
|
|||||||
@@ -190,7 +190,7 @@
|
|||||||
"cassandra-driver": "^4.7.2",
|
"cassandra-driver": "^4.7.2",
|
||||||
"connect-redis": "^7.1.1",
|
"connect-redis": "^7.1.1",
|
||||||
"cron": "^3.1.7",
|
"cron": "^3.1.7",
|
||||||
"crypto-js": "^4.2.0",
|
"crypto-js": "4.2.0",
|
||||||
"dd-trace": "^5.40.0",
|
"dd-trace": "^5.40.0",
|
||||||
"dotenv": "^16.4.1",
|
"dotenv": "^16.4.1",
|
||||||
"fastify": "^4.28.1",
|
"fastify": "^4.28.1",
|
||||||
|
|||||||
@@ -55,6 +55,11 @@ export const getMigrationEnvConfig = async (superAdminDAL: TSuperAdminDALFactory
|
|||||||
|
|
||||||
const fipsEnabled = await crypto.initialize(superAdminDAL);
|
const fipsEnabled = await crypto.initialize(superAdminDAL);
|
||||||
|
|
||||||
|
// Fix for 128-bit entropy encryption key expansion issue:
|
||||||
|
// In FIPS it is not ideal to expand a 128-bit key into 256-bit. We solved this issue in the past by creating the ROOT_ENCRYPTION_KEY.
|
||||||
|
// If FIPS mode is enabled, we set the value of ROOT_ENCRYPTION_KEY to the value of ENCRYPTION_KEY.
|
||||||
|
// ROOT_ENCRYPTION_KEY is expected to be a 256-bit base64-encoded key, unlike the 32-byte key of ENCRYPTION_KEY.
|
||||||
|
// When ROOT_ENCRYPTION_KEY is set, our cryptography will always use a 256-bit entropy encryption key. So for the sake of FIPS we should just roll over the value of ENCRYPTION_KEY to ROOT_ENCRYPTION_KEY.
|
||||||
if (fipsEnabled) {
|
if (fipsEnabled) {
|
||||||
const newEnvCfg = {
|
const newEnvCfg = {
|
||||||
...envCfg,
|
...envCfg,
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import crypto, { KeyObject } from "crypto";
|
import crypto, { KeyObject } from "node:crypto";
|
||||||
|
|
||||||
import { SecretEncryptionAlgo } from "@app/db/schemas";
|
import { SecretEncryptionAlgo } from "@app/db/schemas";
|
||||||
import { CryptographyError } from "@app/lib/errors";
|
import { CryptographyError } from "@app/lib/errors";
|
||||||
|
|||||||
Reference in New Issue
Block a user