add missing transactions

This commit is contained in:
Maidul Islam
2025-02-10 21:07:41 -05:00
parent 6845ac0f5e
commit b644829bb9
7 changed files with 78 additions and 79 deletions
@@ -31,8 +31,7 @@ export async function up(knex: Knex): Promise<void> {
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const projectEncryptionRingBuffer = const projectEncryptionRingBuffer =
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const webhooks = await knex(TableName.Webhook)
const webhooks = await knex(TableName.Webhook)
.where({}) .where({})
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`) .join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`)
.select( .select(
@@ -57,7 +56,7 @@ export async function up(knex: Knex): Promise<void> {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
projectId: el.projectId projectId: el.projectId
}); }, knex);
projectEncryptionRingBuffer.push(el.projectId, projectKmsService); projectEncryptionRingBuffer.push(el.projectId, projectKmsService);
} }
@@ -49,7 +49,7 @@ export async function up(knex: Knex): Promise<void> {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
projectId projectId
}); }, knex);
projectEncryptionRingBuffer.push(projectId, projectKmsService); projectEncryptionRingBuffer.push(projectId, projectKmsService);
} }
@@ -42,7 +42,7 @@ export async function up(knex: Knex): Promise<void> {
projectKmsService = await kmsService.createCipherPairWithDataKey({ projectKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
projectId projectId
}); }, knex);
projectEncryptionRingBuffer.push(projectId, projectKmsService); projectEncryptionRingBuffer.push(projectId, projectKmsService);
} }
@@ -59,7 +59,6 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth) const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
.join( .join(
TableName.IdentityOrgMembership, TableName.IdentityOrgMembership,
@@ -77,76 +76,76 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
) )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId"); .orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedIdentityKubernetesConfigs = await Promise.all( const updatedIdentityKubernetesConfigs = [];
identityKubernetesConfigs.map(
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el }) => {
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
if (!orgKmsService) {
orgKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization,
orgId
});
orgEncryptionRingBuffer.push(orgId, orgKmsService);
}
const key = infisicalSymmetricDecrypt({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
});
const decryptedTokenReviewerJwt = for (const { encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el } of identityKubernetesConfigs) {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag if (!orgKmsService) {
? decryptSymmetric({ orgKmsService = await kmsService.createCipherPairWithDataKey({
key, type: KmsDataKey.Organization,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment orgId
// @ts-ignore This will be removed in next cycle so ignore the ts missing error }, knex);
iv: el.tokenReviewerJwtIV, orgEncryptionRingBuffer.push(orgId, orgKmsService);
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.tokenReviewerJwtTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedTokenReviewerJwt
})
: "";
const decryptedCertificate =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.caCertIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.caCertTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedCaCert
})
: "";
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
plainText: Buffer.from(decryptedTokenReviewerJwt)
}).cipherTextBlob;
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
plainText: Buffer.from(decryptedCertificate)
}).cipherTextBlob;
return {
...el,
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
encryptedKubernetesCaCertificate,
encryptedKubernetesTokenReviewerJwt
};
} }
)
); const key = infisicalSymmetricDecrypt({
ciphertext: encryptedSymmetricKey,
iv: symmetricKeyIV,
tag: symmetricKeyTag,
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
});
const decryptedTokenReviewerJwt =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.tokenReviewerJwtIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.tokenReviewerJwtTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedTokenReviewerJwt
})
: "";
const decryptedCertificate =
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
el.encryptedCaCert && el.caCertIV && el.caCertTag
? decryptSymmetric({
key,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
iv: el.caCertIV,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
tag: el.caCertTag,
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
ciphertext: el.encryptedCaCert
})
: "";
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
plainText: Buffer.from(decryptedTokenReviewerJwt)
}).cipherTextBlob;
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
plainText: Buffer.from(decryptedCertificate)
}).cipherTextBlob;
updatedIdentityKubernetesConfigs.push({
...el,
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
encryptedKubernetesCaCertificate,
encryptedKubernetesTokenReviewerJwt
});
}
for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) { for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) {
// eslint-disable-next-line no-await-in-loop // eslint-disable-next-line no-await-in-loop
@@ -65,7 +65,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId orgId
}); }, knex);
orgEncryptionRingBuffer.push(orgId, orgKmsService); orgEncryptionRingBuffer.push(orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -52,7 +52,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId: el.orgId orgId: el.orgId
}); }, knex);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -207,7 +207,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId: el.orgId orgId: el.orgId
}); }, knex);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
@@ -356,7 +356,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
orgKmsService = await kmsService.createCipherPairWithDataKey({ orgKmsService = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId: el.orgId orgId: el.orgId
}); }, knex);
orgEncryptionRingBuffer.push(el.orgId, orgKmsService); orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
} }
const key = infisicalSymmetricDecrypt({ const key = infisicalSymmetricDecrypt({
+2 -1
View File
@@ -472,7 +472,8 @@ export const kmsServiceFactory = ({
} }
const kmsDecryptor = await decryptWithKmsKey({ const kmsDecryptor = await decryptWithKmsKey({
kmsId: kmsKeyId kmsId: kmsKeyId,
tx: trx
}); });
return kmsDecryptor({ return kmsDecryptor({