This commit is contained in:
Daniel Hougaard
2024-02-22 05:00:25 +01:00
parent b0356ba941
commit f7e6a96a02
+20 -67
View File
@@ -2,9 +2,9 @@ import crypto from "crypto";
import { z } from "zod"; import { z } from "zod";
import { TProjectKeys } from "@app/db/schemas"; import { TProjectKeys } from "@app/db/schemas";
import { logger } from "@app/lib/logger";
import { decryptAsymmetric } from "../crypto"; import { decryptAsymmetric } from "../crypto";
// import { decryptSymmetric128BitHexKeyUTF8, TDecryptSymmetricInput } from "../crypto/encryption";
export enum SecretDocType { export enum SecretDocType {
Secret = "secret", Secret = "secret",
@@ -12,24 +12,23 @@ export enum SecretDocType {
ApprovalSecret = "approvalSecret" ApprovalSecret = "approvalSecret"
} }
const PartialSecretSchema = z.object({ export interface TPartialSecret {
id: z.string(), id: string;
secretKeyCiphertext: z.string(), secretKeyCiphertext: string;
secretKeyIV: z.string(), secretKeyIV: string;
secretKeyTag: z.string(), secretKeyTag: string;
secretValueCiphertext: z.string(), secretValueCiphertext: string;
secretValueIV: z.string(), secretValueIV: string;
secretValueTag: z.string(), secretValueTag: string;
secretCommentCiphertext: z.string().nullish(), secretCommentCiphertext?: string | null;
secretCommentIV: z.string().nullish(), secretCommentIV?: string | null;
secretCommentTag: z.string().nullish(), secretCommentTag?: string | null;
docType: z.nativeEnum(SecretDocType), docType: SecretDocType;
keyEncoding: string;
keyEncoding: z.string() }
});
const PartialDecryptedSecretSchema = z.object({ const PartialDecryptedSecretSchema = z.object({
id: z.string(), id: z.string(),
@@ -39,46 +38,8 @@ const PartialDecryptedSecretSchema = z.object({
docType: z.nativeEnum(SecretDocType) docType: z.nativeEnum(SecretDocType)
}); });
export type TPartialSecret = z.infer<typeof PartialSecretSchema>;
export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>; export type TPartialDecryptedSecret = z.infer<typeof PartialDecryptedSecretSchema>;
// const symmetricDecrypt = ({
// keyEncoding,
// ciphertext,
// tag,
// iv,
// key,
// isApprovalSecret
// }: TDecryptSymmetricInput & { keyEncoding: SecretKeyEncoding; isApprovalSecret: boolean }) => {
// try {
// if (keyEncoding === SecretKeyEncoding.UTF8 || isApprovalSecret) {
// const data = decryptSymmetric128BitHexKeyUTF8({ key, iv, tag, ciphertext });
// return data;
// }
// if (keyEncoding === SecretKeyEncoding.BASE64) {
// const data = decryptSymmetric({ key, iv, tag, ciphertext });
// return data;
// }
// throw new Error("BAD_ENCODING");
// } catch (err) {
// if (err instanceof Error && err.message === "BAD_ENCODING") {
// throw new Error("Invalid key encoding, cannot decrypt secret!");
// }
// // This is taken directly from our frontend secret decryption logic.
// const decipher = crypto.createDecipheriv("aes-256-gcm", key, Buffer.from(iv, "base64"));
// decipher.setAuthTag(Buffer.from(tag, "base64"));
// let data = decipher.update(ciphertext, "base64", "utf8");
// data += decipher.final("utf8");
// console.log(data);
// return data;
// }
// };
const decryptSecret = ({ const decryptSecret = ({
ciphertext, ciphertext,
iv, iv,
@@ -115,19 +76,15 @@ export const decryptSecrets = (
privateKey privateKey
}); });
const secrets: TPartialDecryptedSecret[] = []; const decryptedSecrets: TPartialDecryptedSecret[] = [];
encryptedSecrets.forEach((encSecret) => { encryptedSecrets.forEach((encSecret) => {
try { try {
console.log(encSecret.keyEncoding);
const secretKey = decryptSecret({ const secretKey = decryptSecret({
ciphertext: encSecret.secretKeyCiphertext, ciphertext: encSecret.secretKeyCiphertext,
iv: encSecret.secretKeyIV, iv: encSecret.secretKeyIV,
tag: encSecret.secretKeyTag, tag: encSecret.secretKeyTag,
key key
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
}); });
const secretValue = decryptSecret({ const secretValue = decryptSecret({
@@ -135,8 +92,6 @@ export const decryptSecrets = (
iv: encSecret.secretValueIV, iv: encSecret.secretValueIV,
tag: encSecret.secretValueTag, tag: encSecret.secretValueTag,
key key
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
}); });
const secretComment = const secretComment =
@@ -146,8 +101,6 @@ export const decryptSecrets = (
iv: encSecret.secretCommentIV, iv: encSecret.secretCommentIV,
tag: encSecret.secretCommentTag, tag: encSecret.secretCommentTag,
key key
// keyEncoding: encSecret.keyEncoding as SecretKeyEncoding,
// isApprovalSecret: encSecret.docType === SecretDocType.ApprovalSecret
}) })
: ""; : "";
@@ -159,12 +112,12 @@ export const decryptSecrets = (
docType: encSecret.docType docType: encSecret.docType
}; };
secrets.push(decryptedSecret); decryptedSecrets.push(PartialDecryptedSecretSchema.parse(decryptedSecret));
} catch (err) { } catch (err) {
// This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets array length. // This is ok, because we check that the decrypted secrets array length is the same as the encrypted secrets input array length.
console.log(`[${encSecret.id}] - failed to decrypt`, err); logger.error(`[${encSecret.id}] - failed to decrypt`, err);
} }
}); });
return secrets; return decryptedSecrets;
}; };