Patch support for ENCRYPTION_KEY and ROOT_ENCRYPTION_KEY in generateSecretBlindIndexHelper

This commit is contained in:
Tuan Dang
2023-06-06 14:24:06 +01:00
parent 3a79a855cb
commit aaca66e5a4
2 changed files with 43 additions and 14 deletions
+43 -13
View File
@@ -185,26 +185,56 @@ const generateSecretBlindIndexHelper = async ({
workspaceId: Types.ObjectId; workspaceId: Types.ObjectId;
}) => { }) => {
// check if workspace blind index data exists // check if workspace blind index data exists
const encryptionKey = await getEncryptionKey();
const rootEncryptionKey = await getRootEncryptionKey();
const secretBlindIndexData = await SecretBlindIndexData.findOne({ const secretBlindIndexData = await SecretBlindIndexData.findOne({
workspace: workspaceId, workspace: workspaceId,
}); }).select('+algorithm +keyEncoding');
if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError(); if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError();
// decrypt workspace salt let salt;
const salt = decryptSymmetric128BitHexKeyUTF8({ if (
ciphertext: secretBlindIndexData.encryptedSaltCiphertext, rootEncryptionKey &&
iv: secretBlindIndexData.saltIV, secretBlindIndexData.keyEncoding === ENCODING_SCHEME_BASE64
tag: secretBlindIndexData.saltTag, ) {
key: await getEncryptionKey(), salt = client.decryptSymmetric(
}); secretBlindIndexData.encryptedSaltCiphertext,
rootEncryptionKey,
secretBlindIndexData.saltIV,
secretBlindIndexData.saltTag
);
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({ const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
secretName, secretName,
salt, salt,
}); });
return secretBlindIndex; return secretBlindIndex;
} else if (
encryptionKey &&
secretBlindIndexData.keyEncoding === ENCODING_SCHEME_UTF8
) {
// decrypt workspace salt
salt = decryptSymmetric128BitHexKeyUTF8({
ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
iv: secretBlindIndexData.saltIV,
tag: secretBlindIndexData.saltTag,
key: encryptionKey,
});
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
secretName,
salt,
});
return secretBlindIndex;
}
throw InternalServerError({
message: 'Failed to generate secret blind index'
});
}; };
/** /**
-1
View File
@@ -51,7 +51,6 @@ export const validateClientForWorkspace = async ({
requiredPermissions?: string[]; requiredPermissions?: string[];
requireBlindIndicesEnabled: boolean; requireBlindIndicesEnabled: boolean;
}) => { }) => {
const workspace = await Workspace.findById(workspaceId); const workspace = await Workspace.findById(workspaceId);
if (!workspace) throw WorkspaceNotFoundError({ if (!workspace) throw WorkspaceNotFoundError({