2018-12-24 18:45:15 +01:00
|
|
|
/*
|
2022-11-11 05:49:16 +01:00
|
|
|
* Copyright © 2018-2019, 2021 Musing Studio LLC.
|
2018-12-24 18:45:15 +01:00
|
|
|
*
|
|
|
|
* This file is part of WriteFreely.
|
|
|
|
*
|
|
|
|
* WriteFreely is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License, included
|
|
|
|
* in the LICENSE file in this source code package.
|
|
|
|
*/
|
2018-12-31 07:05:26 +01:00
|
|
|
|
2018-10-15 20:44:15 +02:00
|
|
|
package writefreely
|
|
|
|
|
|
|
|
import (
|
2018-11-11 23:52:24 +01:00
|
|
|
"github.com/writeas/web-core/log"
|
2021-04-06 23:24:07 +02:00
|
|
|
"github.com/writefreely/writefreely/key"
|
2018-11-11 23:52:24 +01:00
|
|
|
"os"
|
2018-11-11 23:16:05 +01:00
|
|
|
"path/filepath"
|
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
|
|
|
keysDir = "keys"
|
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
emailKeyPath = filepath.Join(keysDir, "email.aes256")
|
|
|
|
cookieAuthKeyPath = filepath.Join(keysDir, "cookies_auth.aes256")
|
|
|
|
cookieKeyPath = filepath.Join(keysDir, "cookies_enc.aes256")
|
2021-04-22 18:41:54 +02:00
|
|
|
csrfKeyPath = filepath.Join(keysDir, "csrf.aes256")
|
2018-10-15 20:44:15 +02:00
|
|
|
)
|
|
|
|
|
2019-06-14 00:50:23 +02:00
|
|
|
// InitKeys loads encryption keys into memory via the given Apper interface
|
|
|
|
func InitKeys(apper Apper) error {
|
|
|
|
log.Info("Loading encryption keys...")
|
|
|
|
err := apper.LoadKeys()
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
2018-10-15 20:44:15 +02:00
|
|
|
|
2019-05-12 22:55:30 +02:00
|
|
|
func initKeyPaths(app *App) {
|
2019-01-20 20:18:09 +01:00
|
|
|
emailKeyPath = filepath.Join(app.cfg.Server.KeysParentDir, emailKeyPath)
|
|
|
|
cookieAuthKeyPath = filepath.Join(app.cfg.Server.KeysParentDir, cookieAuthKeyPath)
|
|
|
|
cookieKeyPath = filepath.Join(app.cfg.Server.KeysParentDir, cookieKeyPath)
|
2021-04-22 18:41:54 +02:00
|
|
|
csrfKeyPath = filepath.Join(app.cfg.Server.KeysParentDir, csrfKeyPath)
|
2019-01-20 20:18:09 +01:00
|
|
|
}
|
|
|
|
|
2018-11-11 23:52:24 +01:00
|
|
|
// generateKey generates a key at the given path used for the encryption of
|
|
|
|
// certain user data. Because user data becomes unrecoverable without these
|
|
|
|
// keys, this won't overwrite any existing key, and instead outputs a message.
|
|
|
|
func generateKey(path string) error {
|
|
|
|
// Check if key file exists
|
2019-01-20 19:43:06 +01:00
|
|
|
if _, err := os.Stat(path); err == nil {
|
2023-03-05 08:23:23 +01:00
|
|
|
log.Info("%s already exists. rm the file if you understand the consequences.", path)
|
2018-11-11 23:52:24 +01:00
|
|
|
return nil
|
2019-01-20 19:43:06 +01:00
|
|
|
} else if !os.IsNotExist(err) {
|
|
|
|
log.Error("%s", err)
|
|
|
|
return err
|
2018-11-11 23:52:24 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
log.Info("Generating %s.", path)
|
2019-06-13 16:14:35 +02:00
|
|
|
b, err := key.GenerateBytes(key.EncKeysBytes)
|
2018-11-11 23:52:24 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error("FAILED. %s. Run writefreely --gen-keys again.", err)
|
|
|
|
return err
|
|
|
|
}
|
2023-07-10 11:55:04 +02:00
|
|
|
err = os.WriteFile(path, b, 0600)
|
2018-11-11 23:52:24 +01:00
|
|
|
if err != nil {
|
|
|
|
log.Error("FAILED writing file: %s", err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
log.Info("Success.")
|
|
|
|
return nil
|
|
|
|
}
|