| 1 | //! Secrets at rest, and the signatures put on what crosses between g1t |
| 2 | //! and outside systems. |
| 3 | //! |
| 4 | //! A secret is sealed with AES-256-GCM under its service's own key, with the |
| 5 | //! id of the row it belongs to as associated data, so a sealed value copied |
| 6 | //! onto another row does not open. |
| 7 | |
| 8 | use aes_gcm::aead::{Aead, KeyInit, Payload}; |
| 9 | use aes_gcm::{Aes256Gcm, Nonce}; |
| 10 | use base64::Engine; |
| 11 | use base64::engine::general_purpose::STANDARD; |
| 12 | use hmac::{Hmac, Mac}; |
| 13 | use sha2::{Digest, Sha256}; |
| 14 | |
| 15 | const VERSION: &str = "v1:"; |
| 16 | |
| 17 | pub struct Sealer { |
| 18 | cipher: Aes256Gcm, |
| 19 | } |
| 20 | |
| 21 | impl Sealer { |
| 22 | /// From the service's key: 64 hex characters. |
| 23 | pub fn new(key_hex: &str) -> Option<Sealer> { |
| 24 | let key = hex::decode(key_hex.trim()).ok()?; |
| 25 | (key.len() == 32).then(|| Sealer { |
| 26 | cipher: Aes256Gcm::new_from_slice(&key).expect("a 32-byte key"), |
| 27 | }) |
| 28 | } |
| 29 | |
| 30 | pub fn seal(&self, plaintext: &str, bound_to: &str) -> String { |
| 31 | let mut nonce = [0u8; 12]; |
| 32 | getrandom::getrandom(&mut nonce).expect("no source of randomness"); |
| 33 | let sealed = self |
| 34 | .cipher |
| 35 | .encrypt( |
| 36 | Nonce::from_slice(&nonce), |
| 37 | Payload { |
| 38 | msg: plaintext.as_bytes(), |
| 39 | aad: bound_to.as_bytes(), |
| 40 | }, |
| 41 | ) |
| 42 | .expect("encrypting cannot fail"); |
| 43 | let mut out = nonce.to_vec(); |
| 44 | out.extend(sealed); |
| 45 | format!("{VERSION}{}", STANDARD.encode(out)) |
| 46 | } |
| 47 | |
| 48 | /// `None` when it was sealed under another key or for another row. |
| 49 | pub fn open(&self, sealed: &str, bound_to: &str) -> Option<String> { |
| 50 | let bytes = STANDARD.decode(sealed.strip_prefix(VERSION)?).ok()?; |
| 51 | if bytes.len() < 12 { |
| 52 | return None; |
| 53 | } |
| 54 | let (nonce, ciphertext) = bytes.split_at(12); |
| 55 | let plain = self |
| 56 | .cipher |
| 57 | .decrypt( |
| 58 | Nonce::from_slice(nonce), |
| 59 | Payload { |
| 60 | msg: ciphertext, |
| 61 | aad: bound_to.as_bytes(), |
| 62 | }, |
| 63 | ) |
| 64 | .ok()?; |
| 65 | String::from_utf8(plain).ok() |
| 66 | } |
| 67 | } |
| 68 | |
| 69 | pub fn sha256_hex(value: &str) -> String { |
| 70 | hex::encode(Sha256::digest(value.as_bytes())) |
| 71 | } |
| 72 | |
| 73 | pub fn random_hex(bytes: usize) -> String { |
| 74 | let mut buffer = vec![0u8; bytes]; |
| 75 | getrandom::getrandom(&mut buffer).expect("no source of randomness"); |
| 76 | hex::encode(buffer) |
| 77 | } |
| 78 | |
| 79 | pub fn hmac_sha256_hex(secret: &str, body: &str) -> String { |
| 80 | let mut mac = <Hmac<Sha256> as Mac>::new_from_slice(secret.as_bytes()).expect("any key length"); |
| 81 | mac.update(body.as_bytes()); |
| 82 | hex::encode(mac.finalize().into_bytes()) |
| 83 | } |
| 84 | |
| 85 | /// Compares in time that does not depend on where they differ. |
| 86 | pub fn same(a: &str, b: &str) -> bool { |
| 87 | a.len() == b.len() && a.bytes().zip(b.bytes()).fold(0u8, |diff, (x, y)| diff | (x ^ y)) == 0 |
| 88 | } |
| 89 | |
| 90 | /// Whether `signature` is `body` signed with `secret`: hex HMAC-SHA256, |
| 91 | /// optionally written `sha256=<hex>`. |
| 92 | pub fn signed(secret: &str, body: &str, signature: &str) -> bool { |
| 93 | let given = signature.trim(); |
| 94 | let given = given.strip_prefix("sha256=").unwrap_or(given); |
| 95 | same(&hmac_sha256_hex(secret, body), &given.to_ascii_lowercase()) |
| 96 | } |
| 97 | |
| 98 | /// The last four characters, to tell keys apart without showing them. |
| 99 | pub fn hint(secret: &str) -> String { |
| 100 | let tail: String = secret.chars().rev().take(4).collect::<Vec<_>>().into_iter().rev().collect(); |
| 101 | format!("…{tail}") |
| 102 | } |
| 103 | |
| 104 | #[cfg(test)] |
| 105 | mod tests { |
| 106 | use super::*; |
| 107 | |
| 108 | const KEY: &str = "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f"; |
| 109 | |
| 110 | #[test] |
| 111 | fn a_sealed_secret_opens_only_for_its_own_row() { |
| 112 | let sealer = Sealer::new(KEY).unwrap(); |
| 113 | let sealed = sealer.seal("sk-ant-secret", "con_1"); |
| 114 | assert!(!sealed.contains("sk-ant")); |
| 115 | assert_eq!(sealer.open(&sealed, "con_1").as_deref(), Some("sk-ant-secret")); |
| 116 | assert_eq!(sealer.open(&sealed, "con_2"), None); |
| 117 | } |
| 118 | |
| 119 | #[test] |
| 120 | fn a_key_of_the_wrong_length_is_refused() { |
| 121 | assert!(Sealer::new("abcd").is_none()); |
| 122 | } |
| 123 | |
| 124 | #[test] |
| 125 | fn signatures_are_checked_in_either_form() { |
| 126 | let signature = hmac_sha256_hex("shh", "{\"a\":1}"); |
| 127 | assert!(signed("shh", "{\"a\":1}", &signature)); |
| 128 | assert!(signed("shh", "{\"a\":1}", &format!("sha256={signature}"))); |
| 129 | assert!(!signed("shh", "{\"a\":2}", &signature)); |
| 130 | assert!(!signed("other", "{\"a\":1}", &signature)); |
| 131 | } |
| 132 | |
| 133 | #[test] |
| 134 | fn a_hint_shows_only_the_end() { |
| 135 | assert_eq!(hint("sk-ant-api03-abcdef"), "…cdef"); |
| 136 | } |
| 137 | } |