mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 06:28:50 +00:00
fix: remove md5 support in fips
This commit is contained in:
Generated
-15
@@ -69,7 +69,6 @@
|
|||||||
"cassandra-driver": "^4.7.2",
|
"cassandra-driver": "^4.7.2",
|
||||||
"connect-redis": "^7.1.1",
|
"connect-redis": "^7.1.1",
|
||||||
"cron": "^3.1.7",
|
"cron": "^3.1.7",
|
||||||
"crypto-js": "4.2.0",
|
|
||||||
"dd-trace": "^5.40.0",
|
"dd-trace": "^5.40.0",
|
||||||
"dotenv": "^16.4.1",
|
"dotenv": "^16.4.1",
|
||||||
"fastify": "^4.28.1",
|
"fastify": "^4.28.1",
|
||||||
@@ -140,7 +139,6 @@
|
|||||||
"@babel/preset-react": "^7.24.7",
|
"@babel/preset-react": "^7.24.7",
|
||||||
"@smithy/types": "^4.3.1",
|
"@smithy/types": "^4.3.1",
|
||||||
"@types/bcrypt": "^5.0.2",
|
"@types/bcrypt": "^5.0.2",
|
||||||
"@types/crypto-js": "4.2.2",
|
|
||||||
"@types/jmespath": "^0.15.2",
|
"@types/jmespath": "^0.15.2",
|
||||||
"@types/jsonwebtoken": "^9.0.5",
|
"@types/jsonwebtoken": "^9.0.5",
|
||||||
"@types/jsrp": "^0.2.6",
|
"@types/jsrp": "^0.2.6",
|
||||||
@@ -13335,13 +13333,6 @@
|
|||||||
"@types/node": "*"
|
"@types/node": "*"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@types/crypto-js": {
|
|
||||||
"version": "4.2.2",
|
|
||||||
"resolved": "https://registry.npmjs.org/@types/crypto-js/-/crypto-js-4.2.2.tgz",
|
|
||||||
"integrity": "sha512-sDOLlVbHhXpAUAL0YHDUUwDZf3iN4Bwi4W6a0W0b+QcAezUbRtH4FVb+9J4h+XFPW7l/gQ9F8qC7P+Ec4k8QVQ==",
|
|
||||||
"dev": true,
|
|
||||||
"license": "MIT"
|
|
||||||
},
|
|
||||||
"node_modules/@types/debug": {
|
"node_modules/@types/debug": {
|
||||||
"version": "4.1.12",
|
"version": "4.1.12",
|
||||||
"resolved": "https://registry.npmjs.org/@types/debug/-/debug-4.1.12.tgz",
|
"resolved": "https://registry.npmjs.org/@types/debug/-/debug-4.1.12.tgz",
|
||||||
@@ -16622,12 +16613,6 @@
|
|||||||
"node": ">= 8"
|
"node": ">= 8"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/crypto-js": {
|
|
||||||
"version": "4.2.0",
|
|
||||||
"resolved": "https://registry.npmjs.org/crypto-js/-/crypto-js-4.2.0.tgz",
|
|
||||||
"integrity": "sha512-KALDyEYgpY+Rlob/iriUtjV6d5Eq+Y191A5g4UqLAi8CyGP9N1+FdVbkc1SxKc2r4YAYqG8JzO2KGL+AizD70Q==",
|
|
||||||
"license": "MIT"
|
|
||||||
},
|
|
||||||
"node_modules/crypto-randomuuid": {
|
"node_modules/crypto-randomuuid": {
|
||||||
"version": "1.0.0",
|
"version": "1.0.0",
|
||||||
"resolved": "https://registry.npmjs.org/crypto-randomuuid/-/crypto-randomuuid-1.0.0.tgz",
|
"resolved": "https://registry.npmjs.org/crypto-randomuuid/-/crypto-randomuuid-1.0.0.tgz",
|
||||||
|
|||||||
@@ -86,7 +86,6 @@
|
|||||||
"@babel/preset-react": "^7.24.7",
|
"@babel/preset-react": "^7.24.7",
|
||||||
"@smithy/types": "^4.3.1",
|
"@smithy/types": "^4.3.1",
|
||||||
"@types/bcrypt": "^5.0.2",
|
"@types/bcrypt": "^5.0.2",
|
||||||
"@types/crypto-js": "4.2.2",
|
|
||||||
"@types/jmespath": "^0.15.2",
|
"@types/jmespath": "^0.15.2",
|
||||||
"@types/jsonwebtoken": "^9.0.5",
|
"@types/jsonwebtoken": "^9.0.5",
|
||||||
"@types/jsrp": "^0.2.6",
|
"@types/jsrp": "^0.2.6",
|
||||||
@@ -190,7 +189,6 @@
|
|||||||
"cassandra-driver": "^4.7.2",
|
"cassandra-driver": "^4.7.2",
|
||||||
"connect-redis": "^7.1.1",
|
"connect-redis": "^7.1.1",
|
||||||
"cron": "^3.1.7",
|
"cron": "^3.1.7",
|
||||||
"crypto-js": "4.2.0",
|
|
||||||
"dd-trace": "^5.40.0",
|
"dd-trace": "^5.40.0",
|
||||||
"dotenv": "^16.4.1",
|
"dotenv": "^16.4.1",
|
||||||
"fastify": "^4.28.1",
|
"fastify": "^4.28.1",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import {
|
|||||||
ProjectPermissionDynamicSecretActions,
|
ProjectPermissionDynamicSecretActions,
|
||||||
ProjectPermissionSub
|
ProjectPermissionSub
|
||||||
} from "@app/ee/services/permission/project-permission";
|
} from "@app/ee/services/permission/project-permission";
|
||||||
|
import { crypto } from "@app/lib/crypto";
|
||||||
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
import { BadRequestError, NotFoundError } from "@app/lib/errors";
|
||||||
import { OrderByDirection } from "@app/lib/types";
|
import { OrderByDirection } from "@app/lib/types";
|
||||||
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
import { TKmsServiceFactory } from "@app/services/kms/kms-service";
|
||||||
@@ -92,6 +93,12 @@ export const dynamicSecretServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (provider.type === DynamicSecretProviders.MongoAtlas && crypto.isFipsModeEnabled()) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "MongoDB Atlas dynamic secret is not supported in FIPS mode of operation"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
const folder = await folderDAL.findBySecretPath(projectId, environmentSlug, path);
|
const folder = await folderDAL.findBySecretPath(projectId, environmentSlug, path);
|
||||||
if (!folder) {
|
if (!folder) {
|
||||||
throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` });
|
throw new NotFoundError({ message: `Folder with path '${path}' in environment '${environmentSlug}' not found` });
|
||||||
|
|||||||
@@ -4,7 +4,6 @@
|
|||||||
import crypto, { subtle } from "node:crypto";
|
import crypto, { subtle } from "node:crypto";
|
||||||
|
|
||||||
import bcrypt from "bcrypt";
|
import bcrypt from "bcrypt";
|
||||||
import cryptoJs from "crypto-js";
|
|
||||||
import jwtDep from "jsonwebtoken";
|
import jwtDep from "jsonwebtoken";
|
||||||
import nacl from "tweetnacl";
|
import nacl from "tweetnacl";
|
||||||
import naclUtils from "tweetnacl-util";
|
import naclUtils from "tweetnacl-util";
|
||||||
@@ -74,24 +73,6 @@ export const generateAsymmetricKeyPair = () => {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
export const computeMd5 = (message: string, digest: DigestType = DigestType.Hex) => {
|
|
||||||
let encoder;
|
|
||||||
switch (digest) {
|
|
||||||
case DigestType.Hex:
|
|
||||||
encoder = cryptoJs.enc.Hex;
|
|
||||||
break;
|
|
||||||
case DigestType.Base64:
|
|
||||||
encoder = cryptoJs.enc.Base64;
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
throw new CryptographyError({
|
|
||||||
message: `Invalid digest type: ${digest as string}`
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return cryptoJs.MD5(message).toString(encoder);
|
|
||||||
};
|
|
||||||
|
|
||||||
const cryptographyFactory = () => {
|
const cryptographyFactory = () => {
|
||||||
let $fipsEnabled = false;
|
let $fipsEnabled = false;
|
||||||
let $isInitialized = false;
|
let $isInitialized = false;
|
||||||
@@ -354,15 +335,15 @@ const cryptographyFactory = () => {
|
|||||||
|
|
||||||
const hashing = () => {
|
const hashing = () => {
|
||||||
$checkIsInitialized();
|
$checkIsInitialized();
|
||||||
// mark this function as deprecated
|
|
||||||
/**
|
/**
|
||||||
* @deprecated Do not use MD5 unless you absolutely have to. It is considered an unsafe hashing algorithm, and should only be used if absolutely necessary.
|
* @deprecated Do not use MD5 unless you absolutely have to. It is considered an unsafe hashing algorithm, and should only be used if absolutely necessary.
|
||||||
*/
|
*/
|
||||||
const md5 = (message: string, digest: DigestType = DigestType.Hex) => {
|
const md5 = (message: string, digest: DigestType = DigestType.Hex) => {
|
||||||
// If FIPS is enabled and we need MD5, we use the crypto-js implementation.
|
// If FIPS is enabled, we block MD5 directly.
|
||||||
// Avoid this at all costs unless strictly necessary, like for mongo atlas digest auth.
|
|
||||||
if (isFipsModeEnabled()) {
|
if (isFipsModeEnabled()) {
|
||||||
return computeMd5(message, digest);
|
throw new CryptographyError({
|
||||||
|
message: "MD5 is not supported in FIPS mode of operation"
|
||||||
|
});
|
||||||
}
|
}
|
||||||
return crypto.createHash("md5").update(message).digest(digest);
|
return crypto.createHash("md5").update(message).digest(digest);
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user