Green: unseal shared collection keys with the account keypair
decryptCollection now takes the full key material {masterKey,
publicKey, secretKey} and dispatches on keyDecryptionNonce: present
means an owned collection (secretbox under the master key), absent
means a shared collection (sealed box to our public key). Client
already held the keypair for unsealing the auth token, so it just
passes it through.
This commit is contained in:
+24
-7
@@ -1,10 +1,16 @@
|
||||
import { decryptBlob, decryptBox, fromBase64 } from "../crypto/index.js";
|
||||
import {
|
||||
decryptBlob,
|
||||
decryptBox,
|
||||
decryptSealed,
|
||||
fromBase64,
|
||||
} from "../crypto/index.js";
|
||||
import type {
|
||||
Collection,
|
||||
CollectionType,
|
||||
EnteFile,
|
||||
FileMetadata,
|
||||
FileType,
|
||||
KeyMaterial,
|
||||
RawCollection,
|
||||
RawEnteFile,
|
||||
RawMagicMetadata,
|
||||
@@ -30,14 +36,25 @@ const parseFileType = (n: number): FileType => FILE_TYPE_MAP[n] ?? "unknown";
|
||||
|
||||
export const decryptCollection = (
|
||||
raw: RawCollection,
|
||||
masterKey: Uint8Array,
|
||||
keys: KeyMaterial,
|
||||
currentUserID?: number,
|
||||
): Collection => {
|
||||
const key = decryptBox(
|
||||
fromBase64(raw.encryptedKey),
|
||||
fromBase64(raw.keyDecryptionNonce),
|
||||
masterKey,
|
||||
);
|
||||
// Owned collections carry their key as a secretbox under our master
|
||||
// key, with the nonce in keyDecryptionNonce. Collections shared with
|
||||
// us carry it as an anonymous sealed box to our public key and have
|
||||
// no keyDecryptionNonce at all (sealed boxes embed an ephemeral
|
||||
// public key instead).
|
||||
const key = raw.keyDecryptionNonce
|
||||
? decryptBox(
|
||||
fromBase64(raw.encryptedKey),
|
||||
fromBase64(raw.keyDecryptionNonce),
|
||||
keys.masterKey,
|
||||
)
|
||||
: decryptSealed(
|
||||
fromBase64(raw.encryptedKey),
|
||||
keys.publicKey,
|
||||
keys.secretKey,
|
||||
);
|
||||
|
||||
let name = "";
|
||||
if (raw.encryptedName && raw.nameDecryptionNonce) {
|
||||
|
||||
Reference in New Issue
Block a user