Encrypt connector sensitive data

Add database field level encryption level to sensitive data to reduce
the risk in term of data leak. I dedice to have only one key for now in
a near future I may move to one master key and one encryption key per
organization to make rotation easiest.

I don't use built-in pg_crypto function to have clear seperation and
avoid any encryption key leak.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2025-04-20 11:11:39 -07:00
parent 34de088ec7
commit 44a05be1af
9 changed files with 225 additions and 89 deletions

View File

@@ -42,27 +42,17 @@ const (
ProtocolOAuth2 ProtocolType = "oauth2" ProtocolOAuth2 ProtocolType = "oauth2"
) )
func UnmarshalConnection(data []byte) (Connection, error) { func UnmarshalConnection(prtcl ProtocolType, data []byte) (Connection, error) {
var typeContainer struct {
Type string `json:"type"`
}
if err := json.Unmarshal(data, &typeContainer); err != nil { switch prtcl {
return nil, fmt.Errorf("failed to unmarshal connection type: %w", err)
}
var conn Connection
switch ProtocolType(typeContainer.Type) {
case ProtocolOAuth2: case ProtocolOAuth2:
conn = &OAuth2Connection{} var conn OAuth2Connection
default: if err := json.Unmarshal(data, &conn); err != nil {
return nil, fmt.Errorf("unknown connection type: %s", typeContainer.Type) return nil, fmt.Errorf("cannot unmarshal oauth2 connection: %w", err)
}
return &conn, nil
} }
if err := conn.UnmarshalJSON(data); err != nil { return nil, fmt.Errorf("unknown connection type: %s", prtcl)
return nil, err
}
return conn, nil
} }

View File

@@ -21,6 +21,7 @@ import (
"time" "time"
"github.com/getprobo/probo/pkg/connector" "github.com/getprobo/probo/pkg/connector"
"github.com/getprobo/probo/pkg/crypto/cipher"
"github.com/getprobo/probo/pkg/gid" "github.com/getprobo/probo/pkg/gid"
"github.com/jackc/pgx/v5" "github.com/jackc/pgx/v5"
"go.gearno.de/kit/pg" "go.gearno.de/kit/pg"
@@ -28,14 +29,14 @@ import (
type ( type (
Connector struct { Connector struct {
ID gid.GID `db:"id"` ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"` OrganizationID gid.GID `db:"organization_id"`
Name string `db:"name"` Name string `db:"name"`
Type string `db:"type"` Type connector.ProtocolType `db:"type"`
Connection connector.Connection `db:"-"` Connection connector.Connection `db:"-"`
RawConfig json.RawMessage `db:"connection"` EncryptedConnection []byte `db:"encrypted_connection"`
CreatedAt time.Time `db:"created_at"` CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"` UpdatedAt time.Time `db:"updated_at"`
} }
) )
@@ -43,6 +44,7 @@ func (c *Connector) Upsert(
ctx context.Context, ctx context.Context,
conn pg.Conn, conn pg.Conn,
scope Scoper, scope Scoper,
encryptionKey cipher.EncryptionKey,
) error { ) error {
q := ` q := `
INSERT INTO INSERT INTO
@@ -52,7 +54,7 @@ INSERT INTO
organization_id, organization_id,
name, name,
type, type,
connection, encrypted_connection,
created_at, created_at,
updated_at updated_at
) )
@@ -62,37 +64,47 @@ VALUES (
@organization_id, @organization_id,
@name, @name,
@type, @type,
@connection, @encrypted_connection,
@created_at, @created_at,
@updated_at @updated_at
) )
ON CONFLICT (organization_id, name) DO UPDATE SET ON CONFLICT (organization_id, name) DO UPDATE SET
tenant_id = @tenant_id, tenant_id = @tenant_id,
organization_id = @organization_id, organization_id = @organization_id,
connection = @connection, encrypted_connection = @encrypted_connection,
updated_at = @updated_at updated_at = @updated_at
RETURNING RETURNING
id, id,
organization_id, organization_id,
name, name,
type, type,
connection, encrypted_connection,
created_at, created_at,
updated_at updated_at
` `
connection, err := json.Marshal(c.Connection)
if err != nil {
return fmt.Errorf("cannot marshal connection: %w", err)
}
encryptedConnection, err := cipher.Encrypt(connection, encryptionKey)
if err != nil {
return fmt.Errorf("cannot encrypt connection: %w", err)
}
rows, err := conn.Query( rows, err := conn.Query(
ctx, ctx,
q, q,
pgx.StrictNamedArgs{ pgx.StrictNamedArgs{
"id": c.ID, "id": c.ID,
"tenant_id": scope.GetTenantID(), "tenant_id": scope.GetTenantID(),
"organization_id": c.OrganizationID, "organization_id": c.OrganizationID,
"name": c.Name, "name": c.Name,
"type": c.Type, "type": c.Type,
"connection": c.Connection, "encrypted_connection": encryptedConnection,
"created_at": c.CreatedAt, "created_at": c.CreatedAt,
"updated_at": c.UpdatedAt, "updated_at": c.UpdatedAt,
}, },
) )
if err != nil { if err != nil {
@@ -105,6 +117,16 @@ RETURNING
return fmt.Errorf("cannot collect connectors: %w", err) return fmt.Errorf("cannot collect connectors: %w", err)
} }
decryptedConnection, err := cipher.Decrypt(cnnctr.EncryptedConnection, encryptionKey)
if err != nil {
return fmt.Errorf("cannot decrypt connection: %w", err)
}
cnnctr.Connection, err = connector.UnmarshalConnection(cnnctr.Type, decryptedConnection)
if err != nil {
return fmt.Errorf("cannot unmarshal connection: %w", err)
}
*c = cnnctr *c = cnnctr
return nil return nil

View File

@@ -0,0 +1,4 @@
DELETE FROM connectors;
ALTER TABLE connectors DROP COLUMN connection;
ALTER TABLE connectors ADD COLUMN encrypted_connection BYTEA NOT NULL;

116
pkg/crypto/cipher/cipher.go Normal file
View File

@@ -0,0 +1,116 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package cipher
import (
"crypto/aes"
"crypto/cipher"
"crypto/rand"
"encoding/base64"
"encoding/json"
"fmt"
"io"
)
type (
EncryptionKey [32]byte
)
func NewEncryptionKey(key string) (EncryptionKey, error) {
if len(key) != 32 {
return EncryptionKey{}, fmt.Errorf("key must be 32 bytes for AES-256")
}
var encryptionKey EncryptionKey
copy(encryptionKey[:], key)
return encryptionKey, nil
}
func (k EncryptionKey) Bytes() []byte {
return k[:]
}
func (k *EncryptionKey) UnmarshalJSON(data []byte) error {
var key string
if err := json.Unmarshal(data, &key); err != nil {
return err
}
return k.UnmarshalText([]byte(key))
}
func (k *EncryptionKey) UnmarshalText(text []byte) error {
decoded, err := base64.StdEncoding.DecodeString(string(text))
if err != nil {
return fmt.Errorf("cannot decode base64 key: %w", err)
}
if len(decoded) != 32 {
return fmt.Errorf("key must be 32 bytes for AES-256, got %d bytes after base64 decoding", len(decoded))
}
copy(k[:], decoded)
return nil
}
func (k EncryptionKey) MarshalJSON() ([]byte, error) {
return json.Marshal(base64.StdEncoding.EncodeToString(k[:]))
}
func Encrypt(data []byte, key EncryptionKey) ([]byte, error) {
block, err := aes.NewCipher(key.Bytes())
if err != nil {
return nil, err
}
nonce := make([]byte, 12)
if _, err := io.ReadFull(rand.Reader, nonce); err != nil {
return nil, err
}
aesgcm, err := cipher.NewGCM(block)
if err != nil {
return nil, err
}
ciphertext := aesgcm.Seal(nonce, nonce, data, nil)
return ciphertext, nil
}
func Decrypt(data []byte, key EncryptionKey) ([]byte, error) {
block, err := aes.NewCipher(key.Bytes())
if err != nil {
return nil, err
}
aesgcm, err := cipher.NewGCM(block)
if err != nil {
return nil, err
}
if len(data) < 12 {
return nil, fmt.Errorf("ciphertext too short")
}
nonce, ciphertext := data[:12], data[12:]
plaintext, err := aesgcm.Open(nil, nonce, ciphertext, nil)
if err != nil {
return nil, fmt.Errorf("cannot decrypt: %w", err)
}
return plaintext, nil
}

View File

@@ -33,7 +33,7 @@ type (
CreateOrUpdateConnectorRequest struct { CreateOrUpdateConnectorRequest struct {
OrganizationID gid.GID OrganizationID gid.GID
Name string Name string
Type string Type connector.ProtocolType
Connection connector.Connection Connection connector.Connection
} }
) )
@@ -75,7 +75,7 @@ func (s *ConnectorService) CreateOrUpdate(ctx context.Context, req CreateOrUpdat
err = s.svc.pg.WithConn( err = s.svc.pg.WithConn(
ctx, ctx,
func(conn pg.Conn) error { func(conn pg.Conn) error {
if err := connector.Upsert(ctx, conn, s.svc.scope); err != nil { if err := connector.Upsert(ctx, conn, s.svc.scope, s.svc.encryptionKey); err != nil {
return fmt.Errorf("cannot upsert connector: %w", err) return fmt.Errorf("cannot upsert connector: %w", err)
} }

View File

@@ -20,23 +20,25 @@ import (
"github.com/aws/aws-sdk-go-v2/service/s3" "github.com/aws/aws-sdk-go-v2/service/s3"
"github.com/getprobo/probo/pkg/coredata" "github.com/getprobo/probo/pkg/coredata"
"github.com/getprobo/probo/pkg/crypto/cipher"
"github.com/getprobo/probo/pkg/gid" "github.com/getprobo/probo/pkg/gid"
"go.gearno.de/kit/pg" "go.gearno.de/kit/pg"
) )
type ( type (
Service struct { Service struct {
pg *pg.Client pg *pg.Client
s3 *s3.Client s3 *s3.Client
bucket string bucket string
encryptionKey cipher.EncryptionKey
} }
TenantService struct { TenantService struct {
pg *pg.Client pg *pg.Client
s3 *s3.Client s3 *s3.Client
bucket string bucket string
encryptionKey cipher.EncryptionKey
scope coredata.Scoper scope coredata.Scoper
Frameworks *FrameworkService Frameworks *FrameworkService
Mesures *MesureService Mesures *MesureService
@@ -55,6 +57,7 @@ type (
func NewService( func NewService(
ctx context.Context, ctx context.Context,
encryptionKey cipher.EncryptionKey,
pgClient *pg.Client, pgClient *pg.Client,
s3Client *s3.Client, s3Client *s3.Client,
bucket string, bucket string,
@@ -64,9 +67,10 @@ func NewService(
} }
svc := &Service{ svc := &Service{
pg: pgClient, pg: pgClient,
s3: s3Client, s3: s3Client,
bucket: bucket, bucket: bucket,
encryptionKey: encryptionKey,
} }
return svc, nil return svc, nil
@@ -74,10 +78,11 @@ func NewService(
func (s *Service) WithTenant(tenantID gid.TenantID) *TenantService { func (s *Service) WithTenant(tenantID gid.TenantID) *TenantService {
tenantService := &TenantService{ tenantService := &TenantService{
pg: s.pg, pg: s.pg,
s3: s.s3, s3: s.s3,
bucket: s.bucket, bucket: s.bucket,
scope: coredata.NewScope(tenantID), encryptionKey: s.encryptionKey,
scope: coredata.NewScope(tenantID),
} }
tenantService.Frameworks = &FrameworkService{svc: tenantService} tenantService.Frameworks = &FrameworkService{svc: tenantService}

View File

@@ -23,26 +23,26 @@ import (
type ( type (
connectorConfig struct { connectorConfig struct {
Name string `json:"name"` Name string `json:"name"`
Type string `json:"type"` Type connector.ProtocolType `json:"type"`
Config connector.Connector `json:"-"` Config connector.Connector `json:"-"`
} }
connectorOAuth2Config struct { connectorConfigOAuth2 struct {
ClientID string `json:"client-id"` ClientID string `json:"client-id"`
ClientSecret string `json:"client-secret"` ClientSecret string `json:"client-secret"`
RedirectURI string `json:"redirect-uri"` RedirectURI string `json:"redirect-uri"`
Scopes []string `json:"scopes"`
AuthURL string `json:"auth-url"` AuthURL string `json:"auth-url"`
TokenURL string `json:"token-url"` TokenURL string `json:"token-url"`
Scopes []string `json:"scopes"`
} }
) )
func (c *connectorConfig) UnmarshalJSON(data []byte) error { func (c *connectorConfig) UnmarshalJSON(data []byte) error {
var tmp struct { var tmp struct {
Name string `json:"name"` Name string `json:"name"`
Type string `json:"type"` Type connector.ProtocolType `json:"type"`
RawConfig json.RawMessage `json:"config"` RawConfig json.RawMessage `json:"config"`
} }
if err := json.Unmarshal(data, &tmp); err != nil { if err := json.Unmarshal(data, &tmp); err != nil {
@@ -53,26 +53,24 @@ func (c *connectorConfig) UnmarshalJSON(data []byte) error {
c.Type = tmp.Type c.Type = tmp.Type
switch tmp.Type { switch tmp.Type {
case "oauth2": case connector.ProtocolOAuth2:
var cfg connectorOAuth2Config var config connectorConfigOAuth2
if err := json.Unmarshal(tmp.RawConfig, &cfg); err != nil { if err := json.Unmarshal(tmp.RawConfig, &config); err != nil {
return fmt.Errorf("cannot unmarshal oauth2 config: %w", err) return fmt.Errorf("cannot unmarshal oauth2 connector config: %w", err)
} }
if cfg.ClientID == "" || cfg.ClientSecret == "" || cfg.AuthURL == "" || cfg.TokenURL == "" || cfg.RedirectURI == "" { oauth2Connector := connector.OAuth2Connector{
return fmt.Errorf("oauth2 config: client-id, client-secret, auth-url, token-url and redirect-uri are required") ClientID: config.ClientID,
ClientSecret: config.ClientSecret,
RedirectURI: config.RedirectURI,
AuthURL: config.AuthURL,
TokenURL: config.TokenURL,
Scopes: config.Scopes,
} }
c.Config = &connector.OAuth2Connector{ c.Config = &oauth2Connector
ClientID: cfg.ClientID,
ClientSecret: cfg.ClientSecret,
RedirectURI: cfg.RedirectURI,
Scopes: cfg.Scopes,
AuthURL: cfg.AuthURL,
TokenURL: cfg.TokenURL,
}
default: default:
return fmt.Errorf("unknown %q connector type: %s", tmp.Name, tmp.Type) return fmt.Errorf("unknown connector type: %q", tmp.Type)
} }
return nil return nil

View File

@@ -27,6 +27,7 @@ import (
"github.com/getprobo/probo/pkg/awsconfig" "github.com/getprobo/probo/pkg/awsconfig"
"github.com/getprobo/probo/pkg/connector" "github.com/getprobo/probo/pkg/connector"
"github.com/getprobo/probo/pkg/coredata" "github.com/getprobo/probo/pkg/coredata"
"github.com/getprobo/probo/pkg/crypto/cipher"
"github.com/getprobo/probo/pkg/crypto/passwdhash" "github.com/getprobo/probo/pkg/crypto/passwdhash"
"github.com/getprobo/probo/pkg/mailer" "github.com/getprobo/probo/pkg/mailer"
"github.com/getprobo/probo/pkg/probo" "github.com/getprobo/probo/pkg/probo"
@@ -49,13 +50,14 @@ type (
} }
config struct { config struct {
Hostname string `json:"hostname"` Hostname string `json:"hostname"`
Pg pgConfig `json:"pg"` EncryptionKey cipher.EncryptionKey `json:"encryption-key"`
Api apiConfig `json:"api"` Pg pgConfig `json:"pg"`
Auth authConfig `json:"auth"` Api apiConfig `json:"api"`
AWS awsConfig `json:"aws"` Auth authConfig `json:"auth"`
Mailer mailerConfig `json:"mailer"` AWS awsConfig `json:"aws"`
Connectors []connectorConfig `json:"connectors"` Mailer mailerConfig `json:"mailer"`
Connectors []connectorConfig `json:"connectors"`
} }
) )
@@ -142,7 +144,6 @@ func (impl *Implm) Run(
return fmt.Errorf("cannot get pepper bytes: %w", err) return fmt.Errorf("cannot get pepper bytes: %w", err)
} }
// Validate cookie secret
_, err = impl.cfg.Auth.GetCookieSecretBytes() _, err = impl.cfg.Auth.GetCookieSecretBytes()
if err != nil { if err != nil {
rootSpan.RecordError(err) rootSpan.RecordError(err)
@@ -195,7 +196,7 @@ func (impl *Implm) Run(
return fmt.Errorf("cannot create usrmgr service: %w", err) return fmt.Errorf("cannot create usrmgr service: %w", err)
} }
proboService, err := probo.NewService(ctx, pgClient, s3Client, impl.cfg.AWS.Bucket) proboService, err := probo.NewService(ctx, impl.cfg.EncryptionKey, pgClient, s3Client, impl.cfg.AWS.Bucket)
if err != nil { if err != nil {
return fmt.Errorf("cannot create probo service: %w", err) return fmt.Errorf("cannot create probo service: %w", err)
} }

View File

@@ -129,7 +129,7 @@ func NewMux(proboSvc *probo.Service, usrmgrSvc *usrmgr.Service, authCfg AuthConf
probo.CreateOrUpdateConnectorRequest{ probo.CreateOrUpdateConnectorRequest{
OrganizationID: organizationID, OrganizationID: organizationID,
Name: connectorID, Name: connectorID,
Type: string(connection.Type()), Type: connector.ProtocolType(connection.Type()),
Connection: connection, Connection: connection,
}, },
) )