mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 18:27:19 +00:00
More tests
This commit is contained in:
@@ -1,10 +1,10 @@
|
|||||||
import crypto from "crypto";
|
import crypto from "crypto";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { SecretKeyEncoding, TProjectKeys } from "@app/db/schemas";
|
import { TProjectKeys } from "@app/db/schemas";
|
||||||
|
|
||||||
import { decryptAsymmetric, decryptSymmetric } from "../crypto";
|
import { decryptAsymmetric } from "../crypto";
|
||||||
import { decryptSymmetric128BitHexKeyUTF8, TDecryptSymmetricInput } from "../crypto/encryption";
|
// import { decryptSymmetric128BitHexKeyUTF8, TDecryptSymmetricInput } from "../crypto/encryption";
|
||||||
|
|
||||||
export enum SecretDocType {
|
export enum SecretDocType {
|
||||||
Secret = "secret",
|
Secret = "secret",
|
||||||
@@ -43,38 +43,60 @@ const PartialDecryptedSecretSchema = z.object({
|
|||||||
export type TPartialSecret = z.infer<typeof PartialSecretSchema>;
|
export type TPartialSecret = z.infer<typeof PartialSecretSchema>;
|
||||||
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
|
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
|
||||||
|
|
||||||
const symmetricDecrypt = ({
|
// const symmetricDecrypt = ({
|
||||||
keyEncoding,
|
// keyEncoding,
|
||||||
|
// ciphertext,
|
||||||
|
// tag,
|
||||||
|
// iv,
|
||||||
|
// key,
|
||||||
|
// isApprovalSecret
|
||||||
|
// }: TDecryptSymmetricInput & { keyEncoding: SecretKeyEncoding; isApprovalSecret: boolean }) => {
|
||||||
|
// try {
|
||||||
|
// if (keyEncoding === SecretKeyEncoding.UTF8 || isApprovalSecret) {
|
||||||
|
// const data = decryptSymmetric128BitHexKeyUTF8({ key, iv, tag, ciphertext });
|
||||||
|
// return data;
|
||||||
|
// }
|
||||||
|
// if (keyEncoding === SecretKeyEncoding.BASE64) {
|
||||||
|
// const data = decryptSymmetric({ key, iv, tag, ciphertext });
|
||||||
|
// return data;
|
||||||
|
// }
|
||||||
|
// throw new Error("BAD_ENCODING");
|
||||||
|
// } catch (err) {
|
||||||
|
// if (err instanceof Error && err.message === "BAD_ENCODING") {
|
||||||
|
// throw new Error("Invalid key encoding, cannot decrypt secret!");
|
||||||
|
// }
|
||||||
|
|
||||||
|
// // This is taken directly from our frontend secret decryption logic.
|
||||||
|
// const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
|
||||||
|
// decipher.setAuthTag(Buffer.from(tag, "base64"));
|
||||||
|
|
||||||
|
// let data = decipher.update(ciphertext, "base64", "utf8");
|
||||||
|
// data += decipher.final("utf8");
|
||||||
|
|
||||||
|
// console.log(data);
|
||||||
|
|
||||||
|
// return data;
|
||||||
|
// }
|
||||||
|
// };
|
||||||
|
|
||||||
|
const decryptSecret = ({
|
||||||
ciphertext,
|
ciphertext,
|
||||||
tag,
|
|
||||||
iv,
|
iv,
|
||||||
key,
|
tag,
|
||||||
isApprovalSecret
|
key
|
||||||
}: TDecryptSymmetricInput & { keyEncoding: SecretKeyEncoding; isApprovalSecret: boolean }) => {
|
}: {
|
||||||
try {
|
ciphertext: string;
|
||||||
if (keyEncoding === SecretKeyEncoding.UTF8 || isApprovalSecret) {
|
iv: string;
|
||||||
const data = decryptSymmetric128BitHexKeyUTF8({ key, iv, tag, ciphertext });
|
tag: string;
|
||||||
return data;
|
key: string | Buffer;
|
||||||
}
|
}) => {
|
||||||
if (keyEncoding === SecretKeyEncoding.BASE64) {
|
const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
|
||||||
const data = decryptSymmetric({ key, iv, tag, ciphertext });
|
decipher.setAuthTag(Buffer.from(tag, "base64"));
|
||||||
return data;
|
|
||||||
}
|
|
||||||
throw new Error("BAD_ENCODING");
|
|
||||||
} catch (err) {
|
|
||||||
if (err instanceof Error && err.message === "BAD_ENCODING") {
|
|
||||||
throw new Error("Invalid key encoding, cannot decrypt secret!");
|
|
||||||
}
|
|
||||||
|
|
||||||
// This is taken directly from our frontend secret decryption logic.
|
let cleartext = decipher.update(ciphertext, "base64", "utf8");
|
||||||
const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
|
cleartext += decipher.final("utf8");
|
||||||
decipher.setAuthTag(Buffer.from(tag, "base64"));
|
|
||||||
|
|
||||||
let data = decipher.update(ciphertext, "base64", "utf8");
|
return cleartext;
|
||||||
data += decipher.final("utf8");
|
|
||||||
|
|
||||||
return data;
|
|
||||||
}
|
|
||||||
};
|
};
|
||||||
|
|
||||||
export const decryptSecrets = (
|
export const decryptSecrets = (
|
||||||
@@ -96,45 +118,52 @@ export const decryptSecrets = (
|
|||||||
const secrets: TPartialDecryptedSecret[] = [];
|
const secrets: TPartialDecryptedSecret[] = [];
|
||||||
|
|
||||||
encryptedSecrets.forEach((encSecret) => {
|
encryptedSecrets.forEach((encSecret) => {
|
||||||
const secretKey = symmetricDecrypt({
|
try {
|
||||||
ciphertext: encSecret.secretKeyCiphertext,
|
console.log(encSecret.keyEncoding);
|
||||||
iv: encSecret.secretKeyIV,
|
|
||||||
tag: encSecret.secretKeyTag,
|
|
||||||
key,
|
|
||||||
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
|
||||||
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
|
||||||
});
|
|
||||||
|
|
||||||
const secretValue = symmetricDecrypt({
|
const secretKey = decryptSecret({
|
||||||
ciphertext: encSecret.secretValueCiphertext,
|
ciphertext: encSecret.secretKeyCiphertext,
|
||||||
iv: encSecret.secretValueIV,
|
iv: encSecret.secretKeyIV,
|
||||||
tag: encSecret.secretValueTag,
|
tag: encSecret.secretKeyTag,
|
||||||
key,
|
key
|
||||||
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
||||||
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
||||||
});
|
});
|
||||||
|
|
||||||
const secretComment =
|
const secretValue = decryptSecret({
|
||||||
encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag
|
ciphertext: encSecret.secretValueCiphertext,
|
||||||
? symmetricDecrypt({
|
iv: encSecret.secretValueIV,
|
||||||
ciphertext: encSecret.secretCommentCiphertext,
|
tag: encSecret.secretValueTag,
|
||||||
iv: encSecret.secretCommentIV,
|
key
|
||||||
tag: encSecret.secretCommentTag,
|
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
||||||
key,
|
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
||||||
keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
});
|
||||||
isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
|
||||||
})
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const decryptedSecret: TPartialDecryptedSecret = {
|
const secretComment =
|
||||||
id: encSecret.id,
|
encSecret.secretCommentCiphertext && encSecret.secretCommentIV && encSecret.secretCommentTag
|
||||||
secretKey,
|
? decryptSecret({
|
||||||
secretValue,
|
ciphertext: encSecret.secretCommentCiphertext,
|
||||||
secretComment,
|
iv: encSecret.secretCommentIV,
|
||||||
docType: encSecret.docType
|
tag: encSecret.secretCommentTag,
|
||||||
};
|
key
|
||||||
|
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
|
||||||
|
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
|
||||||
|
})
|
||||||
|
: "";
|
||||||
|
|
||||||
secrets.push(decryptedSecret);
|
const decryptedSecret: TPartialDecryptedSecret = {
|
||||||
|
id: encSecret.id,
|
||||||
|
secretKey,
|
||||||
|
secretValue,
|
||||||
|
secretComment,
|
||||||
|
docType: encSecret.docType
|
||||||
|
};
|
||||||
|
|
||||||
|
secrets.push(decryptedSecret);
|
||||||
|
} catch (err) {
|
||||||
|
// This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets array length.
|
||||||
|
console.log(`[${encSecret.id}] - failed to decrypt`, err);
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
return secrets;
|
return secrets;
|
||||||
|
|||||||
@@ -143,7 +143,12 @@ export const projectQueueFactory = ({
|
|||||||
secrets.push(...approvalSecrets.map((el) => ({ ...el, docType: SecretDocType.ApprovalSecret })));
|
secrets.push(...approvalSecrets.map((el) => ({ ...el, docType: SecretDocType.ApprovalSecret })));
|
||||||
}
|
}
|
||||||
|
|
||||||
const decryptedSecrets = decryptSecrets(secrets, userPrivateKey, oldProjectKey);
|
const decryptedSecrets = decryptSecrets(
|
||||||
|
// secrets.filter((s) => s.keyEncoding === "base64"),
|
||||||
|
secrets,
|
||||||
|
userPrivateKey,
|
||||||
|
oldProjectKey
|
||||||
|
);
|
||||||
|
|
||||||
console.log(
|
console.log(
|
||||||
decryptedSecrets
|
decryptedSecrets
|
||||||
|
|||||||
Reference in New Issue
Block a user