feat(server): enhance secret management and logging functionality
- Added SCRUNNER_SECRETS_KEY to README as a required variable for production. - Implemented redaction of sensitive information in logs across various components. - Enhanced script execution functions to include an owner parameter for better secret management. - Introduced a secrets API in the script sandbox for retrieving and managing secrets. - Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from "node:crypto";
|
||||
|
||||
const DEV_DEFAULT = "scrunner-dev-secrets-key";
|
||||
const SCRYPT_SALT = Buffer.from("scrunner-secrets-v1");
|
||||
const KEY_LEN = 32;
|
||||
const IV_LEN = 12;
|
||||
const AUTH_TAG_LEN = 16;
|
||||
|
||||
/**
|
||||
* @returns {string}
|
||||
*/
|
||||
export function resolveSecretsKeyMaterial() {
|
||||
const raw =
|
||||
process.env.SCRUNNER_SECRETS_KEY ??
|
||||
(process.env.NODE_ENV === "production" ? "" : DEV_DEFAULT);
|
||||
if (!raw) {
|
||||
throw new Error("SCRUNNER_SECRETS_KEY is required in production");
|
||||
}
|
||||
return raw;
|
||||
}
|
||||
|
||||
/** @type {Buffer | null} */
|
||||
let cachedKey = null;
|
||||
|
||||
/**
|
||||
* @returns {Buffer}
|
||||
*/
|
||||
export function getMasterKey() {
|
||||
if (cachedKey) return cachedKey;
|
||||
const raw = resolveSecretsKeyMaterial();
|
||||
cachedKey = /^[0-9a-fA-F]{64}$/.test(raw)
|
||||
? Buffer.from(raw, "hex")
|
||||
: scryptSync(raw, SCRYPT_SALT, KEY_LEN);
|
||||
return cachedKey;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} plaintext
|
||||
* @returns {{ ciphertext: string, iv: string, authTag: string }}
|
||||
*/
|
||||
export function encryptSecret(plaintext) {
|
||||
const iv = randomBytes(IV_LEN);
|
||||
const cipher = createCipheriv("aes-256-gcm", getMasterKey(), iv, {
|
||||
authTagLength: AUTH_TAG_LEN,
|
||||
});
|
||||
const encrypted = Buffer.concat([
|
||||
cipher.update(plaintext, "utf8"),
|
||||
cipher.final(),
|
||||
]);
|
||||
return {
|
||||
ciphertext: encrypted.toString("base64"),
|
||||
iv: iv.toString("base64"),
|
||||
authTag: cipher.getAuthTag().toString("base64"),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {{ ciphertext: string, iv: string, authTag: string }} row
|
||||
* @returns {string}
|
||||
*/
|
||||
export function decryptSecret(row) {
|
||||
const decipher = createDecipheriv(
|
||||
"aes-256-gcm",
|
||||
getMasterKey(),
|
||||
Buffer.from(row.iv, "base64"),
|
||||
{ authTagLength: AUTH_TAG_LEN },
|
||||
);
|
||||
decipher.setAuthTag(Buffer.from(row.authTag, "base64"));
|
||||
return Buffer.concat([
|
||||
decipher.update(Buffer.from(row.ciphertext, "base64")),
|
||||
decipher.final(),
|
||||
]).toString("utf8");
|
||||
}
|
||||
Reference in New Issue
Block a user