mirror of
https://github.com/Dokploy/dokploy.git
synced 2026-07-22 14:25:24 +02:00
feat: optionally include encryption key in web server backups
This commit is contained in:
@@ -4,9 +4,14 @@ import {
|
||||
createHmac,
|
||||
randomBytes,
|
||||
} from "node:crypto";
|
||||
import { readFileSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
import { paths } from "@dokploy/server/constants";
|
||||
import { betterAuthSecret } from "./auth-secret";
|
||||
import { encryptionSecret } from "./encryption-secret";
|
||||
|
||||
export const ENCRYPTION_KEY_BACKUP_FILE = "encryption.key";
|
||||
|
||||
const ENCRYPTION_PREFIX = "enc:v1:";
|
||||
const IV_LENGTH = 12;
|
||||
const AUTH_TAG_LENGTH = 16;
|
||||
@@ -23,6 +28,33 @@ const decryptionKeys = encryptionSecret
|
||||
? [primaryKey, deriveKey(betterAuthSecret)]
|
||||
: [primaryKey];
|
||||
|
||||
export const exportEncryptionKey = () => primaryKey.toString("hex");
|
||||
|
||||
let restoredKey: Buffer | undefined;
|
||||
|
||||
// A backup created with "include encryption key" places the original
|
||||
// server's key at BASE_PATH when restored; use it as a last-resort
|
||||
// decryption fallback so restored values keep working on the new server.
|
||||
const loadRestoredKey = (): Buffer | undefined => {
|
||||
if (restoredKey) {
|
||||
return restoredKey;
|
||||
}
|
||||
try {
|
||||
const { BASE_PATH } = paths();
|
||||
const hex = readFileSync(
|
||||
join(BASE_PATH, ENCRYPTION_KEY_BACKUP_FILE),
|
||||
"utf8",
|
||||
).trim();
|
||||
const key = Buffer.from(hex, "hex");
|
||||
if (key.length === 32 && !key.equals(primaryKey)) {
|
||||
restoredKey = key;
|
||||
}
|
||||
} catch {
|
||||
// No restored key file present.
|
||||
}
|
||||
return restoredKey;
|
||||
};
|
||||
|
||||
export const isEncrypted = (value: string) =>
|
||||
value.startsWith(ENCRYPTION_PREFIX);
|
||||
|
||||
@@ -47,7 +79,9 @@ export const decryptValue = (value: string): string => {
|
||||
const iv = payload.subarray(0, IV_LENGTH);
|
||||
const authTag = payload.subarray(IV_LENGTH, IV_LENGTH + AUTH_TAG_LENGTH);
|
||||
const encrypted = payload.subarray(IV_LENGTH + AUTH_TAG_LENGTH);
|
||||
for (const key of decryptionKeys) {
|
||||
const restored = loadRestoredKey();
|
||||
const keys = restored ? [...decryptionKeys, restored] : decryptionKeys;
|
||||
for (const key of keys) {
|
||||
try {
|
||||
const decipher = createDecipheriv("aes-256-gcm", key, iv);
|
||||
decipher.setAuthTag(authTag);
|
||||
|
||||
Reference in New Issue
Block a user