-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Expand file tree
/
Copy pathencryption.spec.ts
More file actions
99 lines (86 loc) · 3.05 KB
/
Copy pathencryption.spec.ts
File metadata and controls
99 lines (86 loc) · 3.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
import {
compare,
decrypt,
decryptFile,
encrypt,
encryptFile,
getSecret,
SecretOption,
} from "../encryption"
import env, { withEnv } from "../../environment"
import fsp from "fs/promises"
import { tmpdir } from "os"
import { join } from "path"
describe("encryption", () => {
it("uses the JWT secret as the default API encryption key", () => {
const jwt = getSecret(SecretOption.API)
expect(jwt).toBe(env.JWT_SECRET?.export().toString())
})
it("should throw an error if encryption key is not set", () => {
expect(() => getSecret(SecretOption.ENCRYPTION)).toThrow(
'Secret "ENCRYPTION_KEY" has not been set in environment.'
)
})
it("should encrypt and decrypt a string using API encryption key", () => {
withEnv({ API_ENCRYPTION_KEY: "api_secret" }, () => {
const plaintext = "budibase"
const apiEncrypted = encrypt(plaintext, SecretOption.API)
const decrypted = decrypt(apiEncrypted, SecretOption.API)
expect(decrypted).toEqual(plaintext)
})
})
it("should encrypt and decrypt a string using encryption key", () => {
withEnv({ ENCRYPTION_KEY: "normal_secret" }, () => {
const plaintext = "budibase"
const encryptionEncrypted = encrypt(plaintext, SecretOption.ENCRYPTION)
const decrypted = decrypt(encryptionEncrypted, SecretOption.ENCRYPTION)
expect(decrypted).toEqual(plaintext)
})
})
it("should compare plaintext against encrypted values", () => {
withEnv({ API_ENCRYPTION_KEY: "api_secret" }, () => {
const plaintext = "budibase"
const encrypted = encrypt(plaintext, SecretOption.API)
expect(compare(plaintext, encrypted, SecretOption.API)).toBe(true)
expect(compare("not-budibase", encrypted, SecretOption.API)).toBe(false)
})
})
})
describe("file decryption", () => {
let dir: string
const content = "a".repeat(128 * 1024)
const password = "example-password"
beforeEach(async () => {
dir = await fsp.mkdtemp(join(tmpdir(), "file-decryption-"))
await fsp.writeFile(join(dir, "source"), content)
await encryptFile({ dir, filename: "source" }, password)
})
afterEach(async () => {
await fsp.rm(dir, { recursive: true, force: true })
})
it.each([undefined, content.length])(
"decrypts a file within its output budget (%s)",
async maxOutputBytes => {
const output = join(dir, "output")
await decryptFile(join(dir, "source.enc"), output, password, {
maxOutputBytes,
})
expect(await fsp.readFile(output, "utf8")).toEqual(content)
}
)
it("stops decompression before writing beyond the output budget", async () => {
const output = join(dir, "output")
const maxOutputBytes = 32 * 1024
await expect(
decryptFile(join(dir, "source.enc"), output, password, {
maxOutputBytes,
})
).rejects.toThrow("Decrypted file exceeds the size limit")
const outputFile = await fsp.stat(output).catch(error => {
if (error.code !== "ENOENT") {
throw error
}
})
expect(outputFile?.size ?? 0).toBeLessThanOrEqual(maxOutputBytes)
})
})