feat(twenty-server): migrate remaining at-rest encryption sites to versioned envelope (#20550)
## Summary Second PR in the encryption key rotation series. The previous PR (#20528) introduced `ENCRYPTION_KEY` + the versioned `enc:v2:<keyId>:<base64>` envelope inside `SecretEncryptionService` and migrated `ConnectedAccountTokenEncryptionService` as the first consumer. This PR routes every remaining at-rest encryption site through the versioned envelope so that `ENCRYPTION_KEY` (and the future `FALLBACK_ENCRYPTION_KEY`) actually covers them. The legacy unprefixed CTR ciphertext remains readable as a fallback during the rollout window — every migrated read site uses `decryptVersioned`, which transparently delegates to the legacy CTR decrypt when it sees an unprefixed payload. ### Service migrations - **`ApplicationVariableEntityService` (#8)** — workspace-scoped. HKDF info is bound to each row's `workspaceId`. A new `decryptAndMaskVersioned` helper lands on `SecretEncryptionService` for the resolver display path. - **`ApplicationRegistrationVariableService` (#7)** + consumers — **instance-scoped**. Registration variables are server-level config readable by every workspace that installs the application, so HKDF info is `instance`. Updated consumers: - `LogicFunctionExecutorService.buildServerVariableEnvMap` - `ConnectionProviderService.getClientCredentials` - **`LogicFunctionExecutorService.buildEnvVar` (#9)** — workspace-scoped. Each variable's `workspaceId` is threaded into `decryptVersioned`, so per-workspace HKDF contexts are honoured at execution time. - **`UpdateApplicationVariableActionHandlerService`** (workspace-migration runner) — threads `workspaceId` through the secret/non-secret toggle. - **`JwtKeyManagerService` (#3)** — instance-scoped. Signing keys are shared across the JWKS. - **`ConfigStorageService` (#6)** — instance-scoped sensitive STRING config variables. ### Slow instance commands (2.5.0) Each migrated site has a paired backfill that re-encrypts existing rows into the v2 envelope before the column is constrained: | timestamp | command | scope | CHECK constraint | |---|---|---|---| | `1798000005000` | encrypt-application-variable | workspaceId | `"isSecret" = false OR value = '' OR value LIKE 'enc:v2:%'` | | `1798000006000` | encrypt-application-registration-variable | instance | `"encryptedValue" = '' OR value LIKE 'enc:v2:%'` | | `1798000007000` | encrypt-signing-key-private-keys | instance | `"privateKey" IS NULL OR value LIKE 'enc:v2:%'` | | `1798000008000` | encrypt-sensitive-config-storage | instance | _none_ — heterogeneous jsonb column | All backfills are idempotent (the SELECT filter skips rows already in v2 form) and run before their respective `up()` adds the CHECK constraint. Every `down()` deliberately stops at dropping the CHECK constraint — they intentionally do not re-introduce plaintext on rollback. ### Tests - Unit specs for each new slow command cover the v2 upgrade path, the idempotency invariant, and the instance vs workspace HKDF scope. - New `JwtKeyManagerService` spec asserts `decryptVersioned`/`encryptVersioned` are called without `workspaceId` (instance scope). - Updated existing specs for `ApplicationVariableEntityService`, `ConfigStorageService`, and `buildEnvVar` to assert the versioned API and the workspace HKDF context plumbing. - New `SecretEncryptionService.decryptAndMaskVersioned` cases in the service spec. - Updated the `applicationRegistrationVariable` integration spec to assert the column now stores `enc:v2:<keyId>:<base64>` instead of raw legacy CTR. ### Out of scope (future PRs) - `PostgresCredentialsService` — bespoke `jwtWrapperService.generateAppSecret`–derived key + `encryptText`/`decryptText` from `auth.util.ts`; deserves its own migration. - `SimpleSecretEncryptionUtil` (TOTP) — entirely different `aes-256-cbc` `iv:enc` format; deserves its own migration. ## Test plan - [x] `npx nx typecheck twenty-server` - [x] `npx nx lint:diff-with-main twenty-server` (oxlint + prettier) - [x] Local jest run for `secret-encryption | connected-account-token | application-variable | application-registration-variable | build-env-var | jwt-key-manager | config-storage | encrypt-application-variable | encrypt-application-registration-variable | encrypt-signing-key | encrypt-sensitive-config-storage` — 17 suites, 106 tests pass. - [x] Local jest run for `upgrade | instance-command` — 12 suites, 86 tests pass. - [ ] CI green - [ ] Manual review of CHECK constraint shapes by a server reviewer (each one matches `enc:v2:%` rather than `enc:v_:%` since none of the migrated columns can legitimately hold `enc:v1:` ciphertext).
This commit is contained in:
+8
@@ -2,6 +2,7 @@ import { Field, ObjectType } from '@nestjs/graphql';
|
||||
|
||||
import { IDField } from '@ptc-org/nestjs-query-graphql';
|
||||
import {
|
||||
Check,
|
||||
Column,
|
||||
CreateDateColumn,
|
||||
Entity,
|
||||
@@ -24,6 +25,13 @@ import { ApplicationRegistrationEntity } from 'src/engine/core-modules/applicati
|
||||
'applicationRegistrationId',
|
||||
])
|
||||
@Index('IDX_APP_REG_VAR_APP_REGISTRATION_ID', ['applicationRegistrationId'])
|
||||
// Constrains `encryptedValue` to the unfilled default ('') or to the
|
||||
// versioned envelope. Registration variables are instance-scoped so the
|
||||
// envelope's HKDF info does not include a workspaceId.
|
||||
@Check(
|
||||
'CHK_applicationRegistrationVariable_encryptedValue_encrypted',
|
||||
`"encryptedValue" = '' OR "encryptedValue" LIKE 'enc:v2:%'`,
|
||||
)
|
||||
export class ApplicationRegistrationVariableEntity {
|
||||
@IDField(() => UUIDScalarType)
|
||||
@PrimaryGeneratedColumn('uuid')
|
||||
|
||||
+5
-3
@@ -46,7 +46,7 @@ export class ApplicationRegistrationVariableService {
|
||||
value: variable.isFilled
|
||||
? variable.isSecret
|
||||
? '•••••••••••••'
|
||||
: this.encryptionService.decrypt(variable.encryptedValue)
|
||||
: this.encryptionService.decryptVersioned(variable.encryptedValue)
|
||||
: null,
|
||||
}));
|
||||
}
|
||||
@@ -60,7 +60,7 @@ export class ApplicationRegistrationVariableService {
|
||||
workspaceId,
|
||||
);
|
||||
|
||||
const encryptedValue = this.encryptionService.encrypt(input.value);
|
||||
const encryptedValue = this.encryptionService.encryptVersioned(input.value);
|
||||
|
||||
const variable = this.variableRepository.create({
|
||||
applicationRegistrationId: input.applicationRegistrationId,
|
||||
@@ -98,7 +98,9 @@ export class ApplicationRegistrationVariableService {
|
||||
const updateData: Record<string, unknown> = {};
|
||||
|
||||
if (isDefined(update.value)) {
|
||||
updateData.encryptedValue = this.encryptionService.encrypt(update.value);
|
||||
updateData.encryptedValue = this.encryptionService.encryptVersioned(
|
||||
update.value,
|
||||
);
|
||||
}
|
||||
|
||||
if (isDefined(update.resetValue) && update.resetValue) {
|
||||
|
||||
+27
-13
@@ -39,17 +39,23 @@ describe('ApplicationVariableEntityService', () => {
|
||||
{
|
||||
provide: SecretEncryptionService,
|
||||
useValue: {
|
||||
encrypt: jest.fn((value: string) => `encrypted_${value}`),
|
||||
decrypt: jest.fn((value: string) =>
|
||||
value.replace('encrypted_', ''),
|
||||
encryptVersioned: jest.fn(
|
||||
(value: string, opts?: { workspaceId?: string }) =>
|
||||
`enc:v2:deadbeef:${value}|${opts?.workspaceId ?? 'instance'}`,
|
||||
),
|
||||
decryptAndMask: jest.fn(
|
||||
decryptVersioned: jest.fn(
|
||||
(value: string, _opts?: { workspaceId?: string }) =>
|
||||
value.replace(/^enc:v2:[0-9a-f]+:/, '').replace(/\|.*$/, ''),
|
||||
),
|
||||
decryptAndMaskVersioned: jest.fn(
|
||||
({
|
||||
value: _value,
|
||||
mask: _mask,
|
||||
workspaceId: _workspaceId,
|
||||
}: {
|
||||
value: string;
|
||||
mask: string;
|
||||
workspaceId?: string;
|
||||
}) => '********',
|
||||
),
|
||||
},
|
||||
@@ -76,7 +82,7 @@ describe('ApplicationVariableEntityService', () => {
|
||||
});
|
||||
|
||||
describe('update', () => {
|
||||
it('should encrypt value when variable is secret', async () => {
|
||||
it('should encrypt value with workspaceId-scoped envelope when variable is secret', async () => {
|
||||
const existingVariable = {
|
||||
id: '1',
|
||||
key: 'API_KEY',
|
||||
@@ -95,12 +101,13 @@ describe('ApplicationVariableEntityService', () => {
|
||||
workspaceId: mockWorkspaceId,
|
||||
});
|
||||
|
||||
expect(secretEncryptionService.encrypt).toHaveBeenCalledWith(
|
||||
expect(secretEncryptionService.encryptVersioned).toHaveBeenCalledWith(
|
||||
'new-secret-value',
|
||||
{ workspaceId: mockWorkspaceId },
|
||||
);
|
||||
expect(repository.update).toHaveBeenCalledWith(
|
||||
{ key: 'API_KEY', applicationId: mockApplicationId },
|
||||
{ value: 'encrypted_new-secret-value' },
|
||||
{ value: `enc:v2:deadbeef:new-secret-value|${mockWorkspaceId}` },
|
||||
);
|
||||
expect(workspaceCacheService.invalidateAndRecompute).toHaveBeenCalledWith(
|
||||
mockWorkspaceId,
|
||||
@@ -127,7 +134,7 @@ describe('ApplicationVariableEntityService', () => {
|
||||
workspaceId: mockWorkspaceId,
|
||||
});
|
||||
|
||||
expect(secretEncryptionService.encrypt).not.toHaveBeenCalled();
|
||||
expect(secretEncryptionService.encryptVersioned).not.toHaveBeenCalled();
|
||||
expect(repository.update).toHaveBeenCalledWith(
|
||||
{ key: 'PUBLIC_URL', applicationId: mockApplicationId },
|
||||
{ value: 'https://new-url.com' },
|
||||
@@ -167,28 +174,35 @@ describe('ApplicationVariableEntityService', () => {
|
||||
value: 'https://example.com',
|
||||
isSecret: false,
|
||||
applicationId: mockApplicationId,
|
||||
workspaceId: mockWorkspaceId,
|
||||
} as ApplicationVariableEntity;
|
||||
|
||||
const result = service.getDisplayValue(variable);
|
||||
|
||||
expect(result).toBe('https://example.com');
|
||||
expect(secretEncryptionService.decryptAndMask).not.toHaveBeenCalled();
|
||||
expect(
|
||||
secretEncryptionService.decryptAndMaskVersioned,
|
||||
).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it('should call decryptAndMask for secret variables', () => {
|
||||
it('should call decryptAndMaskVersioned with the row workspaceId for secret variables', () => {
|
||||
const variable = {
|
||||
id: '1',
|
||||
key: 'SECRET_KEY',
|
||||
value: 'encrypted_value',
|
||||
value: 'enc:v2:deadbeef:secret|workspace-123',
|
||||
isSecret: true,
|
||||
applicationId: mockApplicationId,
|
||||
workspaceId: mockWorkspaceId,
|
||||
} as ApplicationVariableEntity;
|
||||
|
||||
service.getDisplayValue(variable);
|
||||
|
||||
expect(secretEncryptionService.decryptAndMask).toHaveBeenCalledWith({
|
||||
value: 'encrypted_value',
|
||||
expect(
|
||||
secretEncryptionService.decryptAndMaskVersioned,
|
||||
).toHaveBeenCalledWith({
|
||||
value: 'enc:v2:deadbeef:secret|workspace-123',
|
||||
mask: SECRET_APPLICATION_VARIABLE_MASK,
|
||||
workspaceId: mockWorkspaceId,
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
+9
@@ -2,6 +2,7 @@ import { ObjectType } from '@nestjs/graphql';
|
||||
|
||||
import { IDField } from '@ptc-org/nestjs-query-graphql';
|
||||
import {
|
||||
Check,
|
||||
Column,
|
||||
CreateDateColumn,
|
||||
Entity,
|
||||
@@ -17,6 +18,14 @@ import { SyncableEntity } from 'src/engine/workspace-manager/types/syncable-enti
|
||||
schema: 'core',
|
||||
})
|
||||
@ObjectType('ApplicationVariable')
|
||||
// Constrains `value` for secret rows to the versioned envelope, while
|
||||
// leaving plaintext non-secret values untouched. The keyId portion is
|
||||
// not constrained so future ENCRYPTION_KEY rotations do not need a DDL
|
||||
// migration.
|
||||
@Check(
|
||||
'CHK_applicationVariable_value_encrypted',
|
||||
`"isSecret" = false OR "value" = '' OR "value" LIKE 'enc:v2:%'`,
|
||||
)
|
||||
export class ApplicationVariableEntity extends SyncableEntity {
|
||||
@IDField(() => UUIDScalarType)
|
||||
@PrimaryGeneratedColumn('uuid')
|
||||
|
||||
+5
-2
@@ -32,9 +32,10 @@ export class ApplicationVariableEntityService {
|
||||
return '';
|
||||
}
|
||||
|
||||
return this.secretEncryptionService.decryptAndMask({
|
||||
return this.secretEncryptionService.decryptAndMaskVersioned({
|
||||
value: applicationVariable.value,
|
||||
mask: SECRET_APPLICATION_VARIABLE_MASK,
|
||||
workspaceId: applicationVariable.workspaceId,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -60,7 +61,9 @@ export class ApplicationVariableEntityService {
|
||||
}
|
||||
|
||||
const encryptedValue = existingVariable.isSecret
|
||||
? this.secretEncryptionService.encrypt(plainTextValue)
|
||||
? this.secretEncryptionService.encryptVersioned(plainTextValue, {
|
||||
workspaceId,
|
||||
})
|
||||
: plainTextValue;
|
||||
|
||||
await this.applicationVariableRepository.update(
|
||||
|
||||
+1
-1
@@ -53,7 +53,7 @@ export class ConnectionProviderService {
|
||||
variables.map((v) => [
|
||||
v.key,
|
||||
v.encryptedValue
|
||||
? this.secretEncryptionService.decrypt(v.encryptedValue)
|
||||
? this.secretEncryptionService.decryptVersioned(v.encryptedValue)
|
||||
: '',
|
||||
]),
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user