mirror of
https://github.com/grafana/grafana.git
synced 2026-08-18 17:15:08 -05:00
Encryption: Refactor securejsondata.SecureJsonData to stop relying on global functions (#38865)
* Encryption: Add support to encrypt/decrypt sjd * Add datasources.Service as a proxy to datasources db operations * Encrypt ds.SecureJsonData before calling SQLStore * Move ds cache code into ds service * Fix tlsmanager tests * Fix pluginproxy tests * Remove some securejsondata.GetEncryptedJsonData usages * Add pluginsettings.Service as a proxy for plugin settings db operations * Add AlertNotificationService as a proxy for alert notification db operations * Remove some securejsondata.GetEncryptedJsonData usages * Remove more securejsondata.GetEncryptedJsonData usages * Fix lint errors * Minor fixes * Remove encryption global functions usages from ngalert * Fix lint errors * Minor fixes * Minor fixes * Remove securejsondata.DecryptedValue usage * Refactor the refactor * Remove securejsondata.DecryptedValue usage * Move securejsondata to migrations package * Move securejsondata to migrations package * Minor fix * Fix integration test * Fix integration tests * Undo undesired changes * Fix tests * Add context.Context into encryption methods * Fix tests * Fix tests * Fix tests * Trigger CI * Fix test * Add names to params of encryption service interface * Remove bus from CacheServiceImpl * Add logging * Add keys to logger Co-authored-by: Emil Tullstedt <emil.tullstedt@grafana.com> * Add missing key to logger Co-authored-by: Emil Tullstedt <emil.tullstedt@grafana.com> * Undo changes in markdown files * Fix formatting * Add context to secrets service * Rename decryptSecureJsonData to decryptSecureJsonDataFn * Name args in GetDecryptedValueFn * Add template back to NewAlertmanagerNotifier * Copy GetDecryptedValueFn to ngalert * Add logging to pluginsettings * Fix pluginsettings test Co-authored-by: Tania B <yalyna.ts@gmail.com> Co-authored-by: Emil Tullstedt <emil.tullstedt@grafana.com>
This commit is contained in:
co-authored by
Emil Tullstedt
Tania B
parent
da813877fb
commit
722c414fef
@@ -1,6 +1,8 @@
|
||||
package secrets
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/encryption"
|
||||
"github.com/grafana/grafana/pkg/setting"
|
||||
)
|
||||
@@ -17,12 +19,12 @@ func newGrafanaProvider(settings setting.Provider, encryption encryption.Service
|
||||
}
|
||||
}
|
||||
|
||||
func (p grafanaProvider) Encrypt(blob []byte) ([]byte, error) {
|
||||
func (p grafanaProvider) Encrypt(ctx context.Context, blob []byte) ([]byte, error) {
|
||||
key := p.settings.KeyValue("security", "secret_key").Value()
|
||||
return p.encryption.Encrypt(blob, key)
|
||||
return p.encryption.Encrypt(ctx, blob, key)
|
||||
}
|
||||
|
||||
func (p grafanaProvider) Decrypt(blob []byte) ([]byte, error) {
|
||||
func (p grafanaProvider) Decrypt(ctx context.Context, blob []byte) ([]byte, error) {
|
||||
key := p.settings.KeyValue("security", "secret_key").Value()
|
||||
return p.encryption.Decrypt(blob, key)
|
||||
return p.encryption.Decrypt(ctx, blob, key)
|
||||
}
|
||||
|
||||
@@ -55,8 +55,8 @@ type dataKeyCacheItem struct {
|
||||
}
|
||||
|
||||
type Provider interface {
|
||||
Encrypt(blob []byte) ([]byte, error)
|
||||
Decrypt(blob []byte) ([]byte, error)
|
||||
Encrypt(ctx context.Context, blob []byte) ([]byte, error)
|
||||
Decrypt(ctx context.Context, blob []byte) ([]byte, error)
|
||||
}
|
||||
|
||||
var b64 = base64.RawStdEncoding
|
||||
@@ -95,7 +95,7 @@ func (s *SecretsService) Encrypt(ctx context.Context, payload []byte, opt Encryp
|
||||
}
|
||||
}
|
||||
|
||||
encrypted, err := s.enc.Encrypt(payload, string(dataKey))
|
||||
encrypted, err := s.enc.Encrypt(ctx, payload, string(dataKey))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -142,7 +142,7 @@ func (s *SecretsService) Decrypt(ctx context.Context, payload []byte) ([]byte, e
|
||||
}
|
||||
}
|
||||
|
||||
return s.enc.Decrypt(payload, string(dataKey))
|
||||
return s.enc.Decrypt(ctx, payload, string(dataKey))
|
||||
}
|
||||
|
||||
func (s *SecretsService) EncryptJsonData(ctx context.Context, kv map[string]string, opt EncryptionOptions) (map[string][]byte, error) {
|
||||
@@ -206,7 +206,7 @@ func (s *SecretsService) newDataKey(ctx context.Context, name string, scope stri
|
||||
}
|
||||
|
||||
// 2. Encrypt it
|
||||
encrypted, err := provider.Encrypt(dataKey)
|
||||
encrypted, err := provider.Encrypt(ctx, dataKey)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -254,7 +254,7 @@ func (s *SecretsService) dataKey(ctx context.Context, name string) ([]byte, erro
|
||||
return nil, fmt.Errorf("could not find encryption provider '%s'", dataKey.Provider)
|
||||
}
|
||||
|
||||
decrypted, err := provider.Decrypt(dataKey.EncryptedData)
|
||||
decrypted, err := provider.Decrypt(ctx, dataKey.EncryptedData)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
@@ -108,6 +108,7 @@ func TestSecretsService_DataKeys(t *testing.T) {
|
||||
Provider: "test",
|
||||
EncryptedData: []byte{0x62, 0xAF, 0xA1, 0x1A},
|
||||
}
|
||||
|
||||
err := svc.CreateDataKey(ctx, k)
|
||||
require.Error(t, err)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user