DEK 버전을 프론트엔드에서 명시적으로 관리하도록 변경

This commit is contained in:
static
2025-01-06 15:38:50 +09:00
parent 71f12c942b
commit 47850e1421
16 changed files with 78 additions and 26 deletions

View File

@@ -23,6 +23,7 @@ export const generateDataKey = async () => {
true, true,
["encrypt", "decrypt"], ["encrypt", "decrypt"],
), ),
dataKeyVersion: new Date(),
}; };
}; };

View File

@@ -9,6 +9,7 @@ export interface NewDirectoryParams {
parentId: DirectoryId; parentId: DirectoryId;
mekVersion: number; mekVersion: number;
encDek: string; encDek: string;
dekVersion: Date;
encName: string; encName: string;
encNameIv: string; encNameIv: string;
} }
@@ -19,6 +20,7 @@ export interface NewFileParams {
userId: number; userId: number;
mekVersion: number; mekVersion: number;
encDek: string; encDek: string;
dekVersion: Date;
encContentIv: string; encContentIv: string;
encName: string; encName: string;
encNameIv: string; encNameIv: string;
@@ -41,7 +43,7 @@ export const registerNewDirectory = async (params: NewDirectoryParams) => {
userId: params.userId, userId: params.userId,
mekVersion: params.mekVersion, mekVersion: params.mekVersion,
encDek: params.encDek, encDek: params.encDek,
encryptedAt: now, dekVersion: params.dekVersion,
encName: { ciphertext: params.encName, iv: params.encNameIv }, encName: { ciphertext: params.encName, iv: params.encNameIv },
}); });
}); });
@@ -72,14 +74,22 @@ export const getDirectory = async (userId: number, directoryId: number) => {
export const setDirectoryEncName = async ( export const setDirectoryEncName = async (
userId: number, userId: number,
directoryId: number, directoryId: number,
dekVersion: Date,
encName: string, encName: string,
encNameIv: string, encNameIv: string,
) => { ) => {
await db const res = await db
.update(directory) .update(directory)
.set({ encName: { ciphertext: encName, iv: encNameIv } }) .set({ encName: { ciphertext: encName, iv: encNameIv } })
.where(and(eq(directory.userId, userId), eq(directory.id, directoryId))) .where(
and(
eq(directory.userId, userId),
eq(directory.id, directoryId),
eq(directory.dekVersion, dekVersion),
),
)
.execute(); .execute();
return res.changes > 0;
}; };
export const unregisterDirectory = async (userId: number, directoryId: number) => { export const unregisterDirectory = async (userId: number, directoryId: number) => {
@@ -128,7 +138,7 @@ export const registerNewFile = async (params: NewFileParams) => {
userId: params.userId, userId: params.userId,
mekVersion: params.mekVersion, mekVersion: params.mekVersion,
encDek: params.encDek, encDek: params.encDek,
encryptedAt: now, dekVersion: params.dekVersion,
encContentIv: params.encContentIv, encContentIv: params.encContentIv,
encName: { ciphertext: params.encName, iv: params.encNameIv }, encName: { ciphertext: params.encName, iv: params.encNameIv },
}); });
@@ -160,14 +170,16 @@ export const getFile = async (userId: number, fileId: number) => {
export const setFileEncName = async ( export const setFileEncName = async (
userId: number, userId: number,
fileId: number, fileId: number,
dekVersion: Date,
encName: string, encName: string,
encNameIv: string, encNameIv: string,
) => { ) => {
await db const res = await db
.update(file) .update(file)
.set({ encName: { ciphertext: encName, iv: encNameIv } }) .set({ encName: { ciphertext: encName, iv: encNameIv } })
.where(and(eq(file.userId, userId), eq(file.id, fileId))) .where(and(eq(file.userId, userId), eq(file.id, fileId), eq(file.dekVersion, dekVersion)))
.execute(); .execute();
return res.changes > 0;
}; };
export const unregisterFile = async (userId: number, fileId: number) => { export const unregisterFile = async (userId: number, fileId: number) => {

View File

@@ -19,7 +19,7 @@ export const directory = sqliteTable(
.references(() => user.id), .references(() => user.id),
mekVersion: integer("master_encryption_key_version").notNull(), mekVersion: integer("master_encryption_key_version").notNull(),
encDek: text("encrypted_data_encryption_key").notNull().unique(), // Base64 encDek: text("encrypted_data_encryption_key").notNull().unique(), // Base64
encryptedAt: integer("encrypted_at", { mode: "timestamp_ms" }).notNull(), dekVersion: integer("data_encryption_key_version", { mode: "timestamp_ms" }).notNull(),
encName: ciphertext("encrypted_name").notNull(), encName: ciphertext("encrypted_name").notNull(),
}, },
(t) => ({ (t) => ({
@@ -46,7 +46,7 @@ export const file = sqliteTable(
.references(() => user.id), .references(() => user.id),
mekVersion: integer("master_encryption_key_version").notNull(), mekVersion: integer("master_encryption_key_version").notNull(),
encDek: text("encrypted_data_encryption_key").notNull().unique(), // Base64 encDek: text("encrypted_data_encryption_key").notNull().unique(), // Base64
encryptedAt: integer("encrypted_at", { mode: "timestamp_ms" }).notNull(), dekVersion: integer("data_encryption_key_version", { mode: "timestamp_ms" }).notNull(),
encContentIv: text("encrypted_content_iv").notNull(), // Base64 encContentIv: text("encrypted_content_iv").notNull(), // Base64
encName: ciphertext("encrypted_name").notNull(), encName: ciphertext("encrypted_name").notNull(),
}, },

View File

@@ -1,6 +1,7 @@
import { z } from "zod"; import { z } from "zod";
export const directoryRenameRequest = z.object({ export const directoryRenameRequest = z.object({
dekVersion: z.coerce.date(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),
}); });
@@ -12,6 +13,7 @@ export const directoryInfoResponse = z.object({
createdAt: z.date(), createdAt: z.date(),
mekVersion: z.number().int().positive(), mekVersion: z.number().int().positive(),
dek: z.string().base64().nonempty(), dek: z.string().base64().nonempty(),
dekVersion: z.date(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),
}) })
@@ -25,6 +27,7 @@ export const directoryCreateRequest = z.object({
parentId: z.union([z.enum(["root"]), z.number().int().positive()]), parentId: z.union([z.enum(["root"]), z.number().int().positive()]),
mekVersion: z.number().int().positive(), mekVersion: z.number().int().positive(),
dek: z.string().base64().nonempty(), dek: z.string().base64().nonempty(),
dekVersion: z.coerce.date(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),
}); });

View File

@@ -1,6 +1,7 @@
import { z } from "zod"; import { z } from "zod";
export const fileRenameRequest = z.object({ export const fileRenameRequest = z.object({
dekVersion: z.coerce.date(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),
}); });
@@ -10,6 +11,7 @@ export const fileInfoResponse = z.object({
createdAt: z.date(), createdAt: z.date(),
mekVersion: z.number().int().positive(), mekVersion: z.number().int().positive(),
dek: z.string().base64().nonempty(), dek: z.string().base64().nonempty(),
dekVersion: z.date(),
contentIv: z.string().base64().nonempty(), contentIv: z.string().base64().nonempty(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),
@@ -20,6 +22,7 @@ export const fileUploadRequest = z.object({
parentId: z.union([z.enum(["root"]), z.number().int().positive()]), parentId: z.union([z.enum(["root"]), z.number().int().positive()]),
mekVersion: z.number().int().positive(), mekVersion: z.number().int().positive(),
dek: z.string().base64().nonempty(), dek: z.string().base64().nonempty(),
dekVersion: z.coerce.date(),
contentIv: z.string().base64().nonempty(), contentIv: z.string().base64().nonempty(),
name: z.string().base64().nonempty(), name: z.string().base64().nonempty(),
nameIv: z.string().base64().nonempty(), nameIv: z.string().base64().nonempty(),

View File

@@ -24,15 +24,20 @@ export const deleteDirectory = async (userId: number, directoryId: number) => {
export const renameDirectory = async ( export const renameDirectory = async (
userId: number, userId: number,
directoryId: number, directoryId: number,
dekVersion: Date,
newEncName: string, newEncName: string,
newEncNameIv: string, newEncNameIv: string,
) => { ) => {
const directory = await getDirectory(userId, directoryId); const directory = await getDirectory(userId, directoryId);
if (!directory) { if (!directory) {
error(404, "Invalid directory id"); error(404, "Invalid directory id");
} else if (directory.dekVersion.getTime() !== dekVersion.getTime()) {
error(400, "Invalid DEK version");
} }
await setDirectoryEncName(userId, directoryId, newEncName, newEncNameIv); if (!(await setDirectoryEncName(userId, directoryId, dekVersion, newEncName, newEncNameIv))) {
error(500, "Invalid directory id or DEK version");
}
}; };
export const getDirectoryInformation = async (userId: number, directoryId: "root" | number) => { export const getDirectoryInformation = async (userId: number, directoryId: "root" | number) => {
@@ -49,6 +54,7 @@ export const getDirectoryInformation = async (userId: number, directoryId: "root
createdAt: directory.createdAt, createdAt: directory.createdAt,
mekVersion: directory.mekVersion, mekVersion: directory.mekVersion,
encDek: directory.encDek, encDek: directory.encDek,
dekVersion: directory.dekVersion,
encName: directory.encName, encName: directory.encName,
}, },
directories: directories.map(({ id }) => id), directories: directories.map(({ id }) => id),
@@ -64,5 +70,11 @@ export const createDirectory = async (params: NewDirectoryParams) => {
error(400, "Invalid MEK version"); error(400, "Invalid MEK version");
} }
const oneMinuteAgo = new Date(Date.now() - 60 * 1000);
const oneMinuteLater = new Date(Date.now() + 60 * 1000);
if (params.dekVersion <= oneMinuteAgo || params.dekVersion >= oneMinuteLater) {
error(400, "Invalid DEK version");
}
await registerNewDirectory(params); await registerNewDirectory(params);
}; };

View File

@@ -56,15 +56,20 @@ export const getFileStream = async (userId: number, fileId: number) => {
export const renameFile = async ( export const renameFile = async (
userId: number, userId: number,
fileId: number, fileId: number,
dekVersion: Date,
newEncName: string, newEncName: string,
newEncNameIv: string, newEncNameIv: string,
) => { ) => {
const file = await getFile(userId, fileId); const file = await getFile(userId, fileId);
if (!file) { if (!file) {
error(404, "Invalid file id"); error(404, "Invalid file id");
} else if (file.dekVersion.getTime() !== dekVersion.getTime()) {
error(400, "Invalid DEK version");
} }
await setFileEncName(userId, fileId, newEncName, newEncNameIv); if (!(await setFileEncName(userId, fileId, dekVersion, newEncName, newEncNameIv))) {
error(500, "Invalid file id or DEK version");
}
}; };
export const getFileInformation = async (userId: number, fileId: number) => { export const getFileInformation = async (userId: number, fileId: number) => {
@@ -77,6 +82,7 @@ export const getFileInformation = async (userId: number, fileId: number) => {
createdAt: file.createdAt, createdAt: file.createdAt,
mekVersion: file.mekVersion, mekVersion: file.mekVersion,
encDek: file.encDek, encDek: file.encDek,
dekVersion: file.dekVersion,
encContentIv: file.encContentIv, encContentIv: file.encContentIv,
encName: file.encName, encName: file.encName,
}; };
@@ -113,6 +119,12 @@ export const uploadFile = async (
error(400, "Invalid MEK version"); error(400, "Invalid MEK version");
} }
const oneMinuteAgo = new Date(Date.now() - 60 * 1000);
const oneMinuteLater = new Date(Date.now() + 60 * 1000);
if (params.dekVersion <= oneMinuteAgo || params.dekVersion >= oneMinuteLater) {
error(400, "Invalid DEK version");
}
const path = `${env.libraryPath}/${params.userId}/${uuidv4()}`; const path = `${env.libraryPath}/${params.userId}/${uuidv4()}`;
await mkdir(dirname(path), { recursive: true }); await mkdir(dirname(path), { recursive: true });

View File

@@ -5,6 +5,7 @@ export const decryptFileMetadata = async (metadata: FileInfoResponse, masterKey:
const { dataKey } = await unwrapDataKey(metadata.dek, masterKey); const { dataKey } = await unwrapDataKey(metadata.dek, masterKey);
return { return {
dataKey, dataKey,
dataKeyVersion: metadata.dekVersion,
name: await decryptString(metadata.name, metadata.nameIv, dataKey), name: await decryptString(metadata.name, metadata.nameIv, dataKey),
}; };
}; };

View File

@@ -109,12 +109,12 @@
<div class="my-4 pb-[4.5rem]"> <div class="my-4 pb-[4.5rem]">
{#if subDirectories} {#if subDirectories}
{#await subDirectories then subDirectories} {#await subDirectories then subDirectories}
{#each subDirectories as { id, dataKey, name }} {#each subDirectories as { id, dataKey, dataKeyVersion, name }}
<DirectoryEntry <DirectoryEntry
{name} {name}
onclick={() => goto(`/directory/${id}`)} onclick={() => goto(`/directory/${id}`)}
onOpenMenuClick={() => { onOpenMenuClick={() => {
selectedEntry = { type: "directory", id, dataKey, name }; selectedEntry = { type: "directory", id, dataKey, dataKeyVersion, name };
isDirectoryEntryMenuBottomSheetOpen = true; isDirectoryEntryMenuBottomSheetOpen = true;
}} }}
type="directory" type="directory"
@@ -124,12 +124,12 @@
{/if} {/if}
{#if files} {#if files}
{#await files then files} {#await files then files}
{#each files as { id, dataKey, name }} {#each files as { id, dataKey, dataKeyVersion, name }}
<DirectoryEntry <DirectoryEntry
{name} {name}
onclick={() => goto(`/file/${id}`)} onclick={() => goto(`/file/${id}`)}
onOpenMenuClick={() => { onOpenMenuClick={() => {
selectedEntry = { type: "file", id, dataKey, name }; selectedEntry = { type: "file", id, dataKey, dataKeyVersion, name };
isDirectoryEntryMenuBottomSheetOpen = true; isDirectoryEntryMenuBottomSheetOpen = true;
}} }}
type="file" type="file"

View File

@@ -23,6 +23,7 @@ export interface SelectedDirectoryEntry {
type: "directory" | "file"; type: "directory" | "file";
id: number; id: number;
dataKey: CryptoKey; dataKey: CryptoKey;
dataKeyVersion: Date;
name: string; name: string;
} }
@@ -33,6 +34,7 @@ export const decryptDirectoryMetadata = async (
const { dataKey } = await unwrapDataKey(metadata.dek, masterKey); const { dataKey } = await unwrapDataKey(metadata.dek, masterKey);
return { return {
dataKey, dataKey,
dataKeyVersion: metadata.dekVersion,
name: await decryptString(metadata.name, metadata.nameIv, dataKey), name: await decryptString(metadata.name, metadata.nameIv, dataKey),
}; };
}; };
@@ -42,12 +44,13 @@ export const requestDirectoryCreation = async (
parentId: "root" | number, parentId: "root" | number,
masterKey: MasterKey, masterKey: MasterKey,
) => { ) => {
const { dataKey } = await generateDataKey(); const { dataKey, dataKeyVersion } = await generateDataKey();
const nameEncrypted = await encryptData(new TextEncoder().encode(name), dataKey); const nameEncrypted = await encryptData(new TextEncoder().encode(name), dataKey);
return await callPostApi<DirectoryCreateRequest>("/api/directory/create", { return await callPostApi<DirectoryCreateRequest>("/api/directory/create", {
parentId, parentId,
mekVersion: masterKey.version, mekVersion: masterKey.version,
dek: await wrapDataKey(dataKey, masterKey.key), dek: await wrapDataKey(dataKey, masterKey.key),
dekVersion: dataKeyVersion,
name: encodeToBase64(nameEncrypted.ciphertext), name: encodeToBase64(nameEncrypted.ciphertext),
nameIv: nameEncrypted.iv, nameIv: nameEncrypted.iv,
}); });
@@ -58,7 +61,7 @@ export const requestFileUpload = async (
parentId: "root" | number, parentId: "root" | number,
masterKey: MasterKey, masterKey: MasterKey,
) => { ) => {
const { dataKey } = await generateDataKey(); const { dataKey, dataKeyVersion } = await generateDataKey();
const fileEncrypted = await encryptData(await file.arrayBuffer(), dataKey); const fileEncrypted = await encryptData(await file.arrayBuffer(), dataKey);
const nameEncrypted = await encryptString(file.name, dataKey); const nameEncrypted = await encryptString(file.name, dataKey);
@@ -69,6 +72,7 @@ export const requestFileUpload = async (
parentId, parentId,
mekVersion: masterKey.version, mekVersion: masterKey.version,
dek: await wrapDataKey(dataKey, masterKey.key), dek: await wrapDataKey(dataKey, masterKey.key),
dekVersion: dataKeyVersion,
contentIv: fileEncrypted.iv, contentIv: fileEncrypted.iv,
name: nameEncrypted.ciphertext, name: nameEncrypted.ciphertext,
nameIv: nameEncrypted.iv, nameIv: nameEncrypted.iv,
@@ -90,11 +94,13 @@ export const requestDirectoryEntryRename = async (
if (entry.type === "directory") { if (entry.type === "directory") {
await callPostApi<DirectoryRenameRequest>(`/api/directory/${entry.id}/rename`, { await callPostApi<DirectoryRenameRequest>(`/api/directory/${entry.id}/rename`, {
dekVersion: entry.dataKeyVersion,
name: newNameEncrypted.ciphertext, name: newNameEncrypted.ciphertext,
nameIv: newNameEncrypted.iv, nameIv: newNameEncrypted.iv,
}); });
} else { } else {
await callPostApi<FileRenameRequest>(`/api/file/${entry.id}/rename`, { await callPostApi<FileRenameRequest>(`/api/file/${entry.id}/rename`, {
dekVersion: entry.dataKeyVersion,
name: newNameEncrypted.ciphertext, name: newNameEncrypted.ciphertext,
nameIv: newNameEncrypted.iv, nameIv: newNameEncrypted.iv,
}); });

View File

@@ -23,6 +23,7 @@ export const GET: RequestHandler = async ({ cookies, params }) => {
createdAt: metadata.createdAt, createdAt: metadata.createdAt,
mekVersion: metadata.mekVersion, mekVersion: metadata.mekVersion,
dek: metadata.encDek, dek: metadata.encDek,
dekVersion: metadata.dekVersion,
name: metadata.encName.ciphertext, name: metadata.encName.ciphertext,
nameIv: metadata.encName.iv, nameIv: metadata.encName.iv,
}, },

View File

@@ -18,8 +18,8 @@ export const POST: RequestHandler = async ({ request, cookies, params }) => {
const bodyZodRes = directoryRenameRequest.safeParse(await request.json()); const bodyZodRes = directoryRenameRequest.safeParse(await request.json());
if (!bodyZodRes.success) error(400, "Invalid request body"); if (!bodyZodRes.success) error(400, "Invalid request body");
const { name, nameIv } = bodyZodRes.data; const { dekVersion, name, nameIv } = bodyZodRes.data;
await renameDirectory(userId, id, name, nameIv); await renameDirectory(userId, id, dekVersion, name, nameIv);
return text("Directory renamed", { headers: { "Content-Type": "text/plain" } }); return text("Directory renamed", { headers: { "Content-Type": "text/plain" } });
}; };

View File

@@ -9,13 +9,14 @@ export const POST: RequestHandler = async ({ request, cookies }) => {
const zodRes = directoryCreateRequest.safeParse(await request.json()); const zodRes = directoryCreateRequest.safeParse(await request.json());
if (!zodRes.success) error(400, "Invalid request body"); if (!zodRes.success) error(400, "Invalid request body");
const { parentId, mekVersion, dek, name, nameIv } = zodRes.data; const { parentId, mekVersion, dek, dekVersion, name, nameIv } = zodRes.data;
await createDirectory({ await createDirectory({
userId, userId,
parentId, parentId,
mekVersion, mekVersion,
encDek: dek, encDek: dek,
dekVersion,
encName: name, encName: name,
encNameIv: nameIv, encNameIv: nameIv,
}); });

View File

@@ -16,15 +16,14 @@ export const GET: RequestHandler = async ({ cookies, params }) => {
if (!zodRes.success) error(400, "Invalid path parameters"); if (!zodRes.success) error(400, "Invalid path parameters");
const { id } = zodRes.data; const { id } = zodRes.data;
const { createdAt, mekVersion, encDek, encContentIv, encName } = await getFileInformation( const { createdAt, mekVersion, encDek, dekVersion, encContentIv, encName } =
userId, await getFileInformation(userId, id);
id,
);
return json( return json(
fileInfoResponse.parse({ fileInfoResponse.parse({
createdAt, createdAt,
mekVersion, mekVersion,
dek: encDek, dek: encDek,
dekVersion,
contentIv: encContentIv, contentIv: encContentIv,
name: encName.ciphertext, name: encName.ciphertext,
nameIv: encName.iv, nameIv: encName.iv,

View File

@@ -18,8 +18,8 @@ export const POST: RequestHandler = async ({ request, cookies, params }) => {
const bodyZodRes = fileRenameRequest.safeParse(await request.json()); const bodyZodRes = fileRenameRequest.safeParse(await request.json());
if (!bodyZodRes.success) error(400, "Invalid request body"); if (!bodyZodRes.success) error(400, "Invalid request body");
const { name, nameIv } = bodyZodRes.data; const { dekVersion, name, nameIv } = bodyZodRes.data;
await renameFile(userId, id, name, nameIv); await renameFile(userId, id, dekVersion, name, nameIv);
return text("File renamed", { headers: { "Content-Type": "text/plain" } }); return text("File renamed", { headers: { "Content-Type": "text/plain" } });
}; };

View File

@@ -16,7 +16,7 @@ export const POST: RequestHandler = async ({ request, cookies }) => {
const zodRes = fileUploadRequest.safeParse(JSON.parse(metadata)); const zodRes = fileUploadRequest.safeParse(JSON.parse(metadata));
if (!zodRes.success) error(400, "Invalid request body"); if (!zodRes.success) error(400, "Invalid request body");
const { parentId, mekVersion, dek, contentIv, name, nameIv } = zodRes.data; const { parentId, mekVersion, dek, dekVersion, contentIv, name, nameIv } = zodRes.data;
await uploadFile( await uploadFile(
{ {
@@ -24,6 +24,7 @@ export const POST: RequestHandler = async ({ request, cookies }) => {
parentId, parentId,
mekVersion, mekVersion,
encDek: dek, encDek: dek,
dekVersion,
encContentIv: contentIv, encContentIv: contentIv,
encName: name, encName: name,
encNameIv: nameIv, encNameIv: nameIv,