admin api: Fix reencryption of private_key in signing_key table, introduce test for reencryption (#105010)
* Add integration test for reencrypting secrets. Rotate keys before reencryption. Test for setting table from enterprise repo.
This commit is contained in:
@@ -14,7 +14,9 @@ import (
|
||||
)
|
||||
|
||||
type SecretsRotator interface {
|
||||
// ReEncrypt returns true on success, false on any failure.
|
||||
ReEncrypt(context.Context, *manager.SecretsService, db.DB) bool
|
||||
// Rollback returns true on success, false on any failure.
|
||||
Rollback(context.Context, *manager.SecretsService, encryption.Internal, db.DB, string) bool
|
||||
}
|
||||
|
||||
@@ -43,7 +45,7 @@ func ProvideSecretsMigrator(
|
||||
b64Secret{simpleSecret: simpleSecret{tableName: "secrets", columnName: "value"}, hasUpdatedColumn: true, encoding: base64.RawStdEncoding},
|
||||
jsonSecret{tableName: "data_source"},
|
||||
jsonSecret{tableName: "plugin_setting"},
|
||||
b64Secret{simpleSecret: simpleSecret{tableName: "signing_key", columnName: "private_key"}, encoding: base64.StdEncoding},
|
||||
b64Secret{simpleSecret: simpleSecret{tableName: "signing_key", columnName: "private_key"}, encoding: base64.RawStdEncoding},
|
||||
alertingSecret{},
|
||||
ssoSettingsSecret{},
|
||||
b64Secret{simpleSecret: simpleSecret{tableName: "user_external_session", columnName: "access_token"}, encoding: base64.StdEncoding},
|
||||
@@ -94,12 +96,12 @@ func (m *SecretsMigrator) RollBackSecrets(ctx context.Context) (bool, error) {
|
||||
var anyFailure bool
|
||||
|
||||
for _, r := range m.rotators {
|
||||
if failed := r.Rollback(ctx,
|
||||
if success := r.Rollback(ctx,
|
||||
m.secretsSrv,
|
||||
m.encryptionSrv,
|
||||
m.sqlStore,
|
||||
m.settings.KeyValue("security", "secret_key").Value(),
|
||||
); failed {
|
||||
); !success {
|
||||
anyFailure = true
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user