mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 02:26:40 +00:00
Patch support for ENCRYPTION_KEY and ROOT_ENCRYPTION_KEY in generateSecretBlindIndexHelper
This commit is contained in:
@@ -185,26 +185,56 @@ const generateSecretBlindIndexHelper = async ({
|
|||||||
workspaceId: Types.ObjectId;
|
workspaceId: Types.ObjectId;
|
||||||
}) => {
|
}) => {
|
||||||
// check if workspace blind index data exists
|
// check if workspace blind index data exists
|
||||||
|
const encryptionKey = await getEncryptionKey();
|
||||||
|
const rootEncryptionKey = await getRootEncryptionKey();
|
||||||
|
|
||||||
const secretBlindIndexData = await SecretBlindIndexData.findOne({
|
const secretBlindIndexData = await SecretBlindIndexData.findOne({
|
||||||
workspace: workspaceId,
|
workspace: workspaceId,
|
||||||
});
|
}).select('+algorithm +keyEncoding');
|
||||||
|
|
||||||
if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError();
|
if (!secretBlindIndexData) throw SecretBlindIndexDataNotFoundError();
|
||||||
|
|
||||||
// decrypt workspace salt
|
let salt;
|
||||||
const salt = decryptSymmetric128BitHexKeyUTF8({
|
if (
|
||||||
ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
|
rootEncryptionKey &&
|
||||||
iv: secretBlindIndexData.saltIV,
|
secretBlindIndexData.keyEncoding === ENCODING_SCHEME_BASE64
|
||||||
tag: secretBlindIndexData.saltTag,
|
) {
|
||||||
key: await getEncryptionKey(),
|
salt = client.decryptSymmetric(
|
||||||
});
|
secretBlindIndexData.encryptedSaltCiphertext,
|
||||||
|
rootEncryptionKey,
|
||||||
|
secretBlindIndexData.saltIV,
|
||||||
|
secretBlindIndexData.saltTag
|
||||||
|
);
|
||||||
|
|
||||||
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
||||||
secretName,
|
secretName,
|
||||||
salt,
|
salt,
|
||||||
});
|
});
|
||||||
|
|
||||||
return secretBlindIndex;
|
return secretBlindIndex;
|
||||||
|
} else if (
|
||||||
|
encryptionKey &&
|
||||||
|
secretBlindIndexData.keyEncoding === ENCODING_SCHEME_UTF8
|
||||||
|
) {
|
||||||
|
// decrypt workspace salt
|
||||||
|
salt = decryptSymmetric128BitHexKeyUTF8({
|
||||||
|
ciphertext: secretBlindIndexData.encryptedSaltCiphertext,
|
||||||
|
iv: secretBlindIndexData.saltIV,
|
||||||
|
tag: secretBlindIndexData.saltTag,
|
||||||
|
key: encryptionKey,
|
||||||
|
});
|
||||||
|
|
||||||
|
const secretBlindIndex = await generateSecretBlindIndexWithSaltHelper({
|
||||||
|
secretName,
|
||||||
|
salt,
|
||||||
|
});
|
||||||
|
|
||||||
|
return secretBlindIndex;
|
||||||
|
}
|
||||||
|
|
||||||
|
throw InternalServerError({
|
||||||
|
message: 'Failed to generate secret blind index'
|
||||||
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -51,7 +51,6 @@ export const validateClientForWorkspace = async ({
|
|||||||
requiredPermissions?: string[];
|
requiredPermissions?: string[];
|
||||||
requireBlindIndicesEnabled: boolean;
|
requireBlindIndicesEnabled: boolean;
|
||||||
}) => {
|
}) => {
|
||||||
|
|
||||||
const workspace = await Workspace.findById(workspaceId);
|
const workspace = await Workspace.findById(workspaceId);
|
||||||
|
|
||||||
if (!workspace) throw WorkspaceNotFoundError({
|
if (!workspace) throw WorkspaceNotFoundError({
|
||||||
|
|||||||
Reference in New Issue
Block a user