mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 13:27:22 +00:00
Update hsm-service.ts
This commit is contained in:
@@ -301,7 +301,7 @@ export const hsmServiceFactory = ({ hsmModule: { isInitialized, pkcs11 } }: THsm
|
|||||||
pkcs11.C_VerifyFinal(sessionHandle, hmac);
|
pkcs11.C_VerifyFinal(sessionHandle, hmac);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
logger.error(error, "HSM: HMAC verification failed");
|
logger.error(error, "HSM: HMAC verification failed");
|
||||||
throw new Error("Decryption failed"); // Generic error for failed verification
|
throw new Error("HSM: Decryption failed"); // Generic error for failed verification
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only decrypt if verification passed
|
// Only decrypt if verification passed
|
||||||
@@ -318,8 +318,8 @@ export const hsmServiceFactory = ({ hsmModule: { isInitialized, pkcs11 } }: THsm
|
|||||||
// Create a new buffer from the decrypted data
|
// Create a new buffer from the decrypted data
|
||||||
return Buffer.from(decryptedData);
|
return Buffer.from(decryptedData);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
logger.error("Decryption error:", error);
|
logger.error(error, "HSM: Failed to perform decryption");
|
||||||
throw new Error(`Decryption failed: ${(error as Error)?.message}`);
|
throw new Error("HSM: Decryption failed"); // Generic error for failed decryption, to avoid leaking details about why it failed (such as padding related errors)
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user