More tests

This commit is contained in:
Daniel Hougaard
2024-02-22 05:00:25 +01:00
parent 7ea5323a37
commit b0356ba941
2 changed files with 101 additions and 67 deletions
+95 -66
View File
@@ -1,10 +1,10 @@
import crypto from "crypto"; import crypto from "crypto";
import { z } from "zod"; import { z } from "zod";
import { SecretKeyEncoding, TProjectKeys } from "@app/db/schemas"; import { TProjectKeys } from "@app/db/schemas";
import { decryptAsymmetric, decryptSymmetric } from "../crypto"; import { decryptAsymmetric } from "../crypto";
import { decryptSymmetric128BitHexKeyUTF8, TDecryptSymmetricInput } from "../crypto/encryption"; // import { decryptSymmetric128BitHexKeyUTF8, TDecryptSymmetricInput } from "../crypto/encryption";
export enum SecretDocType { export enum SecretDocType {
Secret = "secret", Secret = "secret",
@@ -43,38 +43,60 @@ const PartialDecryptedSecretSchema = z.object({
export type TPartialSecret = z.infer<typeof PartialSecretSchema>; export type TPartialSecret = z.infer<typeof PartialSecretSchema>;
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>; export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
const symmetricDecrypt = ({ // const symmetricDecrypt = ({
keyEncoding, // keyEncoding,
// ciphertext,
// tag,
// iv,
// key,
// isApprovalSecret
// }: TDecryptSymmetricInput & { keyEncoding: SecretKeyEncoding; isApprovalSecret: boolean }) => {
// try {
// if (keyEncoding === SecretKeyEncoding.UTF8 || isApprovalSecret) {
// const data = decryptSymmetric128BitHexKeyUTF8({ key, iv, tag, ciphertext });
// return data;
// }
// if (keyEncoding === SecretKeyEncoding.BASE64) {
// const data = decryptSymmetric({ key, iv, tag, ciphertext });
// return data;
// }
// throw new Error("BAD_ENCODING");
// } catch (err) {
// if (err instanceof Error && err.message === "BAD_ENCODING") {
// throw new Error("Invalid key encoding, cannot decrypt secret!");
// }
// // This is taken directly from our frontend secret decryption logic.
// const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
// decipher.setAuthTag(Buffer.from(tag, "base64"));
// let data = decipher.update(ciphertext, "base64", "utf8");
// data += decipher.final("utf8");
// console.log(data);
// return data;
// }
// };
const decryptSecret = ({
ciphertext, ciphertext,
tag,
iv, iv,
key, tag,
isApprovalSecret key
}: TDecryptSymmetricInput & { keyEncoding: SecretKeyEncoding; isApprovalSecret: boolean }) => { }: {
try { ciphertext: string;
if (keyEncoding === SecretKeyEncoding.UTF8 || isApprovalSecret) { iv: string;
const data = decryptSymmetric128BitHexKeyUTF8({ key, iv, tag, ciphertext }); tag: string;
return data; key: string | Buffer;
} }) => {
if (keyEncoding === SecretKeyEncoding.BASE64) { const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
const data = decryptSymmetric({ key, iv, tag, ciphertext }); decipher.setAuthTag(Buffer.from(tag, "base64"));
return data;
}
throw new Error("BAD_ENCODING");
} catch (err) {
if (err instanceof Error && err.message === "BAD_ENCODING") {
throw new Error("Invalid key encoding, cannot decrypt secret!");
}
// This is taken directly from our frontend secret decryption logic. let cleartext = decipher.update(ciphertext, "base64", "utf8");
const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64")); cleartext += decipher.final("utf8");
decipher.setAuthTag(Buffer.from(tag, "base64"));
let data = decipher.update(ciphertext, "base64", "utf8"); return cleartext;
data += decipher.final("utf8");
return data;
}
}; };
export const decryptSecrets = ( export const decryptSecrets = (
@@ -96,45 +118,52 @@ export const decryptSecrets = (
const secrets: TPartialDecryptedSecret[] = []; const secrets: TPartialDecryptedSecret[] = [];
encryptedSecrets.forEach((encSecret) => { encryptedSecrets.forEach((encSecret) => {
const secretKey = symmetricDecrypt({ try {
ciphertext: encSecret.secretKeyCiphertext, console.log(encSecret.keyEncoding);
iv: encSecret.secretKeyIV,
tag: encSecret.secretKeyTag,
key,
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
});
const secretValue = symmetricDecrypt({ const secretKey = decryptSecret({
ciphertext: encSecret.secretValueCiphertext, ciphertext: encSecret.secretKeyCiphertext,
iv: encSecret.secretValueIV, iv: encSecret.secretKeyIV,
tag: encSecret.secretValueTag, tag: encSecret.secretKeyTag,
key, key
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding, // keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret // isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
}); });
const secretComment = const secretValue = decryptSecret({
encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag ciphertext: encSecret.secretValueCiphertext,
? symmetricDecrypt({ iv: encSecret.secretValueIV,
ciphertext: encSecret.secretCommentCiphertext, tag: encSecret.secretValueTag,
iv: encSecret.secretCommentIV, key
tag: encSecret.secretCommentTag, // keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
key, // isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding, });
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
})
: "";
const decryptedSecret: TPartialDecryptedSecret = { const secretComment =
id: encSecret.id, encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag
secretKey, ? decryptSecret({
secretValue, ciphertext: encSecret.secretCommentCiphertext,
secretComment, iv: encSecret.secretCommentIV,
docType: encSecret.docType tag: encSecret.secretCommentTag,
}; key
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
})
: "";
secrets.push(decryptedSecret); const decryptedSecret: TPartialDecryptedSecret = {
id: encSecret.id,
secretKey,
secretValue,
secretComment,
docType: encSecret.docType
};
secrets.push(decryptedSecret);
} catch (err) {
// This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets array length.
console.log(`[${encSecret.id}] - failed to decrypt`, err);
}
}); });
return secrets; return secrets;
@@ -143,7 +143,12 @@ export const projectQueueFactory = ({
secrets.push(...approvalSecrets.map((el) => ({ ...el, docType: SecretDocType.ApprovalSecret }))); secrets.push(...approvalSecrets.map((el) => ({ ...el, docType: SecretDocType.ApprovalSecret })));
} }
const decryptedSecrets = decryptSecrets(secrets, userPrivateKey, oldProjectKey); const decryptedSecrets = decryptSecrets(
// secrets.filter((s) => s.keyEncoding === "base64"),
secrets,
userPrivateKey,
oldProjectKey
);
console.log( console.log(
decryptedSecrets decryptedSecrets