mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-08-14 06:47:28 +00:00
Two additions to Credential Sharing. `logicsrc credentials rotate` (alias `logicsrc secrets rotate`) re-keys a team vault: fresh DEK, re-sealed to the members who keep access, every secret re-encrypted under it. Values do not change, so nothing that consumes them breaks; what changes is that every wrapped key issued before the rotation is dead. --active (the default) keeps only active members and revokes the rest -- the "someone left" rotation. --all keeps everyone who holds access, for plain hygiene. Dry run by default, like `sync`. The DEK is recoverable ONLY through the grants, so a half-applied rotation makes a vault permanently unreadable by everyone. The whole next state therefore goes to the server in one request and commits in one transaction (new db.batch helper). The server also requires every submitted fingerprint to equal the stored one: it cannot see values, but it can prove a re-key did not swap any. Rotations that would leave the caller ungranted, grant nobody, or cover the wrong secret count are rejected before anything is written. GET /vaults/:id/grants now returns publicKey and status so a client can re-seal in one pass instead of N+1 user lookups, and revocation finally deletes the grant row rather than leaving one that reports access it no longer confers. The sh1pt adapter is the fifth provider. It is the only one driven through a CLI rather than HTTP, because sh1pt publishes `sh1pt secret set|get|list|rm` as the interface to its vault and documents no REST endpoint. Values go over the child's stdin, never argv -- a secret in argv is readable by any user on the host via ps. Since `sh1pt secret get` needs interactive confirmation it cannot be scripted, so the adapter is write-only for values like github-secrets: a sync target, never a source, no value-restoring rollback. Tests drive a real fake sh1pt binary rather than a mocked execFile, which is how the hang surfaced: with nothing to pipe, stdin was left open and any subcommand that reads it would wait forever. It is now always closed. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
155 lines
6.3 KiB
TypeScript
155 lines
6.3 KiB
TypeScript
/**
|
|
* Vault re-keying (rotation) for LogicSRC team vaults.
|
|
*
|
|
* Re-keying replaces a vault's data-encryption key. Every secret is decrypted
|
|
* with the old DEK and re-encrypted under a new one, and the new DEK is sealed
|
|
* afresh to each member who should keep access. Secret VALUES never change --
|
|
* that is the whole point. Nothing downstream breaks; what changes is that
|
|
* every previously-issued wrapped DEK becomes useless, so anyone dropped from
|
|
* the grant list can no longer read the vault even if they kept a copy of their
|
|
* old grant.
|
|
*
|
|
* This module is deliberately pure: it takes the current sealed state plus the
|
|
* caller's identity and returns the complete next state. All of it runs on the
|
|
* member's machine -- the server receives ciphertext and sealed keys only, and
|
|
* never sees either DEK.
|
|
*
|
|
* Ordering matters and is NOT this module's problem: a half-applied rotation
|
|
* (new grants, old ciphertext, or the reverse) locks everyone out permanently,
|
|
* because the DEK is recoverable only through the grants. The server applies
|
|
* the result of `planVaultRekey` in a single transaction; see the
|
|
* /vaults/:id/rekey endpoint.
|
|
*/
|
|
import { decryptValue, encryptValue, generateVaultKey, unwrapVaultKey, wrapVaultKey, type IdentityKeyPair } from "./crypto.js";
|
|
import { fingerprintValue, fingerprintsEqual } from "./fingerprint.js";
|
|
|
|
/** A secret as the server stores it. */
|
|
export interface SealedSecret {
|
|
name: string;
|
|
nonce: string;
|
|
ciphertext: string;
|
|
fingerprint: string;
|
|
}
|
|
|
|
/** A member who is a candidate to receive the new DEK. */
|
|
export interface RekeyMember {
|
|
email: string;
|
|
/** X25519 public key, or null if they have never uploaded one. */
|
|
publicKey: string | null;
|
|
/** Team membership status. Only "active" members are kept by default. */
|
|
status: "active" | "invited";
|
|
/** Whether they hold a grant on this vault today. */
|
|
hasAccess: boolean;
|
|
}
|
|
|
|
export interface RekeyPlanInput {
|
|
/** The caller's own wrapped DEK, which bootstraps the whole operation. */
|
|
myWrappedDek: string;
|
|
/** The caller's identity keypair. */
|
|
identity: IdentityKeyPair;
|
|
/** Every secret currently in the vault. */
|
|
secrets: SealedSecret[];
|
|
/** Every team member, with their current access. */
|
|
members: RekeyMember[];
|
|
/**
|
|
* Who keeps access.
|
|
* - "active" (default): only members whose team status is "active" AND who
|
|
* hold a grant today. This is the "someone left the team" rotation.
|
|
* - "all": everyone holding a grant today, whatever their status. Pure
|
|
* crypto hygiene -- re-key without revoking anyone.
|
|
*/
|
|
scope?: "active" | "all";
|
|
}
|
|
|
|
export interface RekeyPlan {
|
|
/** Re-encrypted secrets, ready to write. Values are identical to the input. */
|
|
secrets: SealedSecret[];
|
|
/** New sealed DEKs, one per retained member. */
|
|
grants: Array<{ email: string; wrappedDek: string }>;
|
|
/** Members whose access this rotation removes. */
|
|
revoked: string[];
|
|
/** Members skipped because they have no public key to seal to. */
|
|
skipped: Array<{ email: string; reason: string }>;
|
|
}
|
|
|
|
/** Members who have no key yet cannot be sealed to, whatever the scope. */
|
|
function sealable(member: RekeyMember): boolean {
|
|
return typeof member.publicKey === "string" && member.publicKey.length > 0;
|
|
}
|
|
|
|
/**
|
|
* Build the complete next state of a vault under a fresh DEK.
|
|
*
|
|
* Throws rather than returning a partial plan: a rotation that silently dropped
|
|
* a secret it could not decrypt would destroy it on write.
|
|
*/
|
|
export async function planVaultRekey(input: RekeyPlanInput): Promise<RekeyPlan> {
|
|
const scope = input.scope ?? "active";
|
|
|
|
const oldDek = await unwrapVaultKey(input.myWrappedDek, input.identity);
|
|
const newDek = await generateVaultKey();
|
|
|
|
// Decrypt everything BEFORE encrypting anything. If one secret fails to open
|
|
// we abort with the vault untouched, rather than writing a half-rotated set.
|
|
const plaintext = new Map<string, string>();
|
|
for (const secret of input.secrets) {
|
|
let value: string;
|
|
try {
|
|
value = await decryptValue({ nonce: secret.nonce, ciphertext: secret.ciphertext }, oldDek);
|
|
} catch {
|
|
throw new Error(
|
|
`Cannot rotate: "${secret.name}" did not decrypt with your vault key. The vault may already be mid-rotation, or your grant is stale — re-run after a member with access re-grants you.`
|
|
);
|
|
}
|
|
// The fingerprint is a deterministic hash of the value, so a mismatch here
|
|
// means the stored row was already inconsistent. Refuse to propagate it.
|
|
if (!fingerprintsEqual(secret.fingerprint, fingerprintValue(value))) {
|
|
throw new Error(
|
|
`Cannot rotate: "${secret.name}" has a fingerprint that does not match its ciphertext. Refusing to re-encrypt a record that is already inconsistent.`
|
|
);
|
|
}
|
|
plaintext.set(secret.name, value);
|
|
}
|
|
|
|
const secrets: SealedSecret[] = [];
|
|
for (const secret of input.secrets) {
|
|
const value = plaintext.get(secret.name) as string;
|
|
const sealed = await encryptValue(value, newDek);
|
|
secrets.push({
|
|
name: secret.name,
|
|
nonce: sealed.nonce,
|
|
ciphertext: sealed.ciphertext,
|
|
// Unchanged by construction -- the value did not change. Recomputed
|
|
// rather than copied so a bug here surfaces as a server-side rejection.
|
|
fingerprint: fingerprintValue(value)
|
|
});
|
|
}
|
|
|
|
const grants: Array<{ email: string; wrappedDek: string }> = [];
|
|
const revoked: string[] = [];
|
|
const skipped: Array<{ email: string; reason: string }> = [];
|
|
|
|
for (const member of input.members) {
|
|
const keep = member.hasAccess && (scope === "all" || member.status === "active");
|
|
if (!keep) {
|
|
if (member.hasAccess) revoked.push(member.email);
|
|
continue;
|
|
}
|
|
if (!sealable(member)) {
|
|
// Holds access today but has no key to re-seal to. Rotating would cut
|
|
// them off silently, so surface it instead of burying it.
|
|
skipped.push({ email: member.email, reason: "no public key on file" });
|
|
revoked.push(member.email);
|
|
continue;
|
|
}
|
|
grants.push({ email: member.email, wrappedDek: await wrapVaultKey(newDek, member.publicKey as string) });
|
|
}
|
|
|
|
if (grants.length === 0) {
|
|
throw new Error(
|
|
"Cannot rotate: no member would keep access, which would make the vault permanently unreadable. Grant at least one active member with a registered key first."
|
|
);
|
|
}
|
|
|
|
return { secrets, grants, revoked, skipped };
|
|
}
|