Send snapshots to server
This commit is contained in:
@@ -1,5 +1,4 @@
|
||||
use crate::server::HistorySegment;
|
||||
use std::convert::TryFrom;
|
||||
use std::io::Read;
|
||||
use tindercrypt::cryptors::RingCryptor;
|
||||
use uuid::Uuid;
|
||||
@@ -18,45 +17,31 @@ impl AsRef<[u8]> for Secret {
|
||||
}
|
||||
}
|
||||
|
||||
/// A cleartext payload containing a history segment.
|
||||
pub(super) struct HistoryCleartext {
|
||||
pub(super) parent_version_id: Uuid,
|
||||
pub(super) history_segment: HistorySegment,
|
||||
/// A cleartext payload with an attached version_id. The version_id is used to
|
||||
/// validate the context of the payload.
|
||||
pub(super) struct Cleartext {
|
||||
pub(super) version_id: Uuid,
|
||||
pub(super) payload: HistorySegment,
|
||||
}
|
||||
|
||||
impl HistoryCleartext {
|
||||
impl Cleartext {
|
||||
/// Seal the payload into its ciphertext
|
||||
pub(super) fn seal(self, secret: &Secret) -> anyhow::Result<HistoryCiphertext> {
|
||||
let cryptor = RingCryptor::new().with_aad(self.parent_version_id.as_bytes());
|
||||
let ciphertext = cryptor.seal_with_passphrase(secret.as_ref(), &self.history_segment)?;
|
||||
Ok(HistoryCiphertext(ciphertext))
|
||||
pub(super) fn seal(self, secret: &Secret) -> anyhow::Result<Ciphertext> {
|
||||
let cryptor = RingCryptor::new().with_aad(self.version_id.as_bytes());
|
||||
let ciphertext = cryptor.seal_with_passphrase(secret.as_ref(), &self.payload)?;
|
||||
Ok(Ciphertext(ciphertext))
|
||||
}
|
||||
}
|
||||
|
||||
/// An ecrypted payload containing a history segment
|
||||
pub(super) struct HistoryCiphertext(pub(super) Vec<u8>);
|
||||
/// An ecrypted payload
|
||||
pub(super) struct Ciphertext(pub(super) Vec<u8>);
|
||||
|
||||
impl HistoryCiphertext {
|
||||
pub(super) fn open(
|
||||
self,
|
||||
secret: &Secret,
|
||||
parent_version_id: Uuid,
|
||||
) -> anyhow::Result<HistoryCleartext> {
|
||||
let cryptor = RingCryptor::new().with_aad(parent_version_id.as_bytes());
|
||||
let plaintext = cryptor.open(secret.as_ref(), &self.0)?;
|
||||
|
||||
Ok(HistoryCleartext {
|
||||
parent_version_id,
|
||||
history_segment: plaintext,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
impl TryFrom<ureq::Response> for HistoryCiphertext {
|
||||
type Error = anyhow::Error;
|
||||
|
||||
fn try_from(resp: ureq::Response) -> Result<HistoryCiphertext, anyhow::Error> {
|
||||
if let Some("application/vnd.taskchampion.history-segment") = resp.header("Content-Type") {
|
||||
impl Ciphertext {
|
||||
pub(super) fn from_resp(
|
||||
resp: ureq::Response,
|
||||
content_type: &str,
|
||||
) -> Result<Ciphertext, anyhow::Error> {
|
||||
if resp.header("Content-Type") == Some(content_type) {
|
||||
let mut reader = resp.into_reader();
|
||||
let mut bytes = vec![];
|
||||
reader.read_to_end(&mut bytes)?;
|
||||
@@ -67,9 +52,19 @@ impl TryFrom<ureq::Response> for HistoryCiphertext {
|
||||
))
|
||||
}
|
||||
}
|
||||
|
||||
pub(super) fn open(self, secret: &Secret, version_id: Uuid) -> anyhow::Result<Cleartext> {
|
||||
let cryptor = RingCryptor::new().with_aad(version_id.as_bytes());
|
||||
let plaintext = cryptor.open(secret.as_ref(), &self.0)?;
|
||||
|
||||
Ok(Cleartext {
|
||||
version_id,
|
||||
payload: plaintext,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
impl AsRef<[u8]> for HistoryCiphertext {
|
||||
impl AsRef<[u8]> for Ciphertext {
|
||||
fn as_ref(&self) -> &[u8] {
|
||||
self.0.as_ref()
|
||||
}
|
||||
@@ -82,52 +77,50 @@ mod test {
|
||||
|
||||
#[test]
|
||||
fn round_trip() {
|
||||
let parent_version_id = Uuid::new_v4();
|
||||
let history_segment = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
let version_id = Uuid::new_v4();
|
||||
let payload = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
let secret = Secret(b"SEKRIT".to_vec());
|
||||
|
||||
let history_cleartext = HistoryCleartext {
|
||||
parent_version_id,
|
||||
history_segment: history_segment.clone(),
|
||||
let cleartext = Cleartext {
|
||||
version_id,
|
||||
payload: payload.clone(),
|
||||
};
|
||||
let history_ciphertext = history_cleartext.seal(&secret).unwrap();
|
||||
let history_cleartext = history_ciphertext.open(&secret, parent_version_id).unwrap();
|
||||
let ciphertext = cleartext.seal(&secret).unwrap();
|
||||
let cleartext = ciphertext.open(&secret, version_id).unwrap();
|
||||
|
||||
assert_eq!(history_cleartext.history_segment, history_segment);
|
||||
assert_eq!(history_cleartext.parent_version_id, parent_version_id);
|
||||
assert_eq!(cleartext.payload, payload);
|
||||
assert_eq!(cleartext.version_id, version_id);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn round_trip_bad_key() {
|
||||
let parent_version_id = Uuid::new_v4();
|
||||
let history_segment = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
let version_id = Uuid::new_v4();
|
||||
let payload = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
let secret = Secret(b"SEKRIT".to_vec());
|
||||
|
||||
let history_cleartext = HistoryCleartext {
|
||||
parent_version_id,
|
||||
history_segment: history_segment.clone(),
|
||||
let cleartext = Cleartext {
|
||||
version_id,
|
||||
payload: payload.clone(),
|
||||
};
|
||||
let history_ciphertext = history_cleartext.seal(&secret).unwrap();
|
||||
let ciphertext = cleartext.seal(&secret).unwrap();
|
||||
|
||||
let secret = Secret(b"BADSEKRIT".to_vec());
|
||||
assert!(history_ciphertext.open(&secret, parent_version_id).is_err());
|
||||
assert!(ciphertext.open(&secret, version_id).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn round_trip_bad_pvid() {
|
||||
let parent_version_id = Uuid::new_v4();
|
||||
let history_segment = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
fn round_trip_bad_version() {
|
||||
let version_id = Uuid::new_v4();
|
||||
let payload = b"HISTORY REPEATS ITSELF".to_vec();
|
||||
let secret = Secret(b"SEKRIT".to_vec());
|
||||
|
||||
let history_cleartext = HistoryCleartext {
|
||||
parent_version_id,
|
||||
history_segment: history_segment.clone(),
|
||||
let cleartext = Cleartext {
|
||||
version_id,
|
||||
payload: payload.clone(),
|
||||
};
|
||||
let history_ciphertext = history_cleartext.seal(&secret).unwrap();
|
||||
let ciphertext = cleartext.seal(&secret).unwrap();
|
||||
|
||||
let bad_parent_version_id = Uuid::new_v4();
|
||||
assert!(history_ciphertext
|
||||
.open(&secret, bad_parent_version_id)
|
||||
.is_err());
|
||||
let bad_version_id = Uuid::new_v4();
|
||||
assert!(ciphertext.open(&secret, bad_version_id).is_err());
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user