feat(twenty-server): migrate remaining at-rest encryption sites to versioned envelope (#20550)
## Summary Second PR in the encryption key rotation series. The previous PR (#20528) introduced `ENCRYPTION_KEY` + the versioned `enc:v2:<keyId>:<base64>` envelope inside `SecretEncryptionService` and migrated `ConnectedAccountTokenEncryptionService` as the first consumer. This PR routes every remaining at-rest encryption site through the versioned envelope so that `ENCRYPTION_KEY` (and the future `FALLBACK_ENCRYPTION_KEY`) actually covers them. The legacy unprefixed CTR ciphertext remains readable as a fallback during the rollout window — every migrated read site uses `decryptVersioned`, which transparently delegates to the legacy CTR decrypt when it sees an unprefixed payload. ### Service migrations - **`ApplicationVariableEntityService` (#8)** — workspace-scoped. HKDF info is bound to each row's `workspaceId`. A new `decryptAndMaskVersioned` helper lands on `SecretEncryptionService` for the resolver display path. - **`ApplicationRegistrationVariableService` (#7)** + consumers — **instance-scoped**. Registration variables are server-level config readable by every workspace that installs the application, so HKDF info is `instance`. Updated consumers: - `LogicFunctionExecutorService.buildServerVariableEnvMap` - `ConnectionProviderService.getClientCredentials` - **`LogicFunctionExecutorService.buildEnvVar` (#9)** — workspace-scoped. Each variable's `workspaceId` is threaded into `decryptVersioned`, so per-workspace HKDF contexts are honoured at execution time. - **`UpdateApplicationVariableActionHandlerService`** (workspace-migration runner) — threads `workspaceId` through the secret/non-secret toggle. - **`JwtKeyManagerService` (#3)** — instance-scoped. Signing keys are shared across the JWKS. - **`ConfigStorageService` (#6)** — instance-scoped sensitive STRING config variables. ### Slow instance commands (2.5.0) Each migrated site has a paired backfill that re-encrypts existing rows into the v2 envelope before the column is constrained: | timestamp | command | scope | CHECK constraint | |---|---|---|---| | `1798000005000` | encrypt-application-variable | workspaceId | `"isSecret" = false OR value = '' OR value LIKE 'enc:v2:%'` | | `1798000006000` | encrypt-application-registration-variable | instance | `"encryptedValue" = '' OR value LIKE 'enc:v2:%'` | | `1798000007000` | encrypt-signing-key-private-keys | instance | `"privateKey" IS NULL OR value LIKE 'enc:v2:%'` | | `1798000008000` | encrypt-sensitive-config-storage | instance | _none_ — heterogeneous jsonb column | All backfills are idempotent (the SELECT filter skips rows already in v2 form) and run before their respective `up()` adds the CHECK constraint. Every `down()` deliberately stops at dropping the CHECK constraint — they intentionally do not re-introduce plaintext on rollback. ### Tests - Unit specs for each new slow command cover the v2 upgrade path, the idempotency invariant, and the instance vs workspace HKDF scope. - New `JwtKeyManagerService` spec asserts `decryptVersioned`/`encryptVersioned` are called without `workspaceId` (instance scope). - Updated existing specs for `ApplicationVariableEntityService`, `ConfigStorageService`, and `buildEnvVar` to assert the versioned API and the workspace HKDF context plumbing. - New `SecretEncryptionService.decryptAndMaskVersioned` cases in the service spec. - Updated the `applicationRegistrationVariable` integration spec to assert the column now stores `enc:v2:<keyId>:<base64>` instead of raw legacy CTR. ### Out of scope (future PRs) - `PostgresCredentialsService` — bespoke `jwtWrapperService.generateAppSecret`–derived key + `encryptText`/`decryptText` from `auth.util.ts`; deserves its own migration. - `SimpleSecretEncryptionUtil` (TOTP) — entirely different `aes-256-cbc` `iv:enc` format; deserves its own migration. ## Test plan - [x] `npx nx typecheck twenty-server` - [x] `npx nx lint:diff-with-main twenty-server` (oxlint + prettier) - [x] Local jest run for `secret-encryption | connected-account-token | application-variable | application-registration-variable | build-env-var | jwt-key-manager | config-storage | encrypt-application-variable | encrypt-application-registration-variable | encrypt-signing-key | encrypt-sensitive-config-storage` — 17 suites, 106 tests pass. - [x] Local jest run for `upgrade | instance-command` — 12 suites, 86 tests pass. - [ ] CI green - [ ] Manual review of CHECK constraint shapes by a server reviewer (each one matches `enc:v2:%` rather than `enc:v_:%` since none of the migrated columns can legitimately hold `enc:v1:` ciphertext).
This commit is contained in:
+6
-1
@@ -300,8 +300,13 @@ export class LogicFunctionExecutorService {
|
||||
// .updateVariable call encrypt unconditionally), independent of
|
||||
// `isSecret`. `isSecret` is display metadata — the storage contract is
|
||||
// not conditional, so decryption isn't either.
|
||||
//
|
||||
// Registration variables are server-level config — any installed
|
||||
// application across any workspace must be able to read them — so they
|
||||
// use the instance-scoped versioned envelope (no workspaceId in the HKDF
|
||||
// info).
|
||||
for (const variable of serverVariables) {
|
||||
envMap[variable.key] = this.secretEncryptionService.decrypt(
|
||||
envMap[variable.key] = this.secretEncryptionService.decryptVersioned(
|
||||
variable.encryptedValue,
|
||||
);
|
||||
}
|
||||
|
||||
+67
-13
@@ -3,9 +3,18 @@ import { type SecretEncryptionService } from 'src/engine/core-modules/secret-enc
|
||||
import { buildEnvVar } from 'src/engine/core-modules/logic-function/logic-function-executor/utils/build-env-var';
|
||||
|
||||
describe('buildEnvVar', () => {
|
||||
const workspaceA = 'aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa';
|
||||
const workspaceB = 'bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb';
|
||||
|
||||
const mockSecretEncryptionService = {
|
||||
encrypt: jest.fn((value: string) => `encrypted_${value}`),
|
||||
decrypt: jest.fn((value: string) => value.replace('encrypted_', '')),
|
||||
encryptVersioned: jest.fn(
|
||||
(value: string, opts?: { workspaceId?: string }) =>
|
||||
`enc:v2:deadbeef:${value}|${opts?.workspaceId ?? 'instance'}`,
|
||||
),
|
||||
decryptVersioned: jest.fn(
|
||||
(value: string, _opts?: { workspaceId?: string }) =>
|
||||
value.replace(/^enc:v2:[0-9a-f]+:/, '').replace(/\|.*$/, ''),
|
||||
),
|
||||
} as unknown as SecretEncryptionService;
|
||||
|
||||
beforeEach(() => {
|
||||
@@ -18,7 +27,7 @@ describe('buildEnvVar', () => {
|
||||
expect(result).toEqual({});
|
||||
});
|
||||
|
||||
it('should handle mixed secret and non-secret variables', () => {
|
||||
it('should decrypt secret variables with the row workspaceId bound to HKDF', () => {
|
||||
const flatVariables: FlatApplicationVariable[] = [
|
||||
{
|
||||
id: '1',
|
||||
@@ -27,7 +36,7 @@ describe('buildEnvVar', () => {
|
||||
description: 'Public URL',
|
||||
isSecret: false,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
@@ -36,11 +45,11 @@ describe('buildEnvVar', () => {
|
||||
{
|
||||
id: '2',
|
||||
key: 'API_SECRET',
|
||||
value: 'encrypted_secret-123',
|
||||
value: `enc:v2:deadbeef:secret-123|${workspaceA}`,
|
||||
description: 'API secret',
|
||||
isSecret: true,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
@@ -53,7 +62,7 @@ describe('buildEnvVar', () => {
|
||||
description: 'Debug flag',
|
||||
isSecret: false,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
@@ -68,9 +77,54 @@ describe('buildEnvVar', () => {
|
||||
API_SECRET: 'secret-123',
|
||||
DEBUG: 'true',
|
||||
});
|
||||
expect(mockSecretEncryptionService.decrypt).toHaveBeenCalledTimes(1);
|
||||
expect(mockSecretEncryptionService.decrypt).toHaveBeenCalledWith(
|
||||
'encrypted_secret-123',
|
||||
expect(mockSecretEncryptionService.decryptVersioned).toHaveBeenCalledTimes(
|
||||
1,
|
||||
);
|
||||
expect(mockSecretEncryptionService.decryptVersioned).toHaveBeenCalledWith(
|
||||
`enc:v2:deadbeef:secret-123|${workspaceA}`,
|
||||
{ workspaceId: workspaceA },
|
||||
);
|
||||
});
|
||||
|
||||
it('routes each secret variable to its own workspace HKDF context', () => {
|
||||
const flatVariables: FlatApplicationVariable[] = [
|
||||
{
|
||||
id: '1',
|
||||
key: 'A_SECRET',
|
||||
value: `enc:v2:deadbeef:value-a|${workspaceA}`,
|
||||
description: '',
|
||||
isSecret: true,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
updatedAt: '2024-01-01T00:00:00.000Z',
|
||||
},
|
||||
{
|
||||
id: '2',
|
||||
key: 'B_SECRET',
|
||||
value: `enc:v2:deadbeef:value-b|${workspaceB}`,
|
||||
description: '',
|
||||
isSecret: true,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: workspaceB,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
updatedAt: '2024-01-01T00:00:00.000Z',
|
||||
},
|
||||
];
|
||||
|
||||
buildEnvVar(flatVariables, mockSecretEncryptionService);
|
||||
|
||||
expect(mockSecretEncryptionService.decryptVersioned).toHaveBeenCalledWith(
|
||||
`enc:v2:deadbeef:value-a|${workspaceA}`,
|
||||
{ workspaceId: workspaceA },
|
||||
);
|
||||
expect(mockSecretEncryptionService.decryptVersioned).toHaveBeenCalledWith(
|
||||
`enc:v2:deadbeef:value-b|${workspaceB}`,
|
||||
{ workspaceId: workspaceB },
|
||||
);
|
||||
});
|
||||
|
||||
@@ -83,7 +137,7 @@ describe('buildEnvVar', () => {
|
||||
description: '',
|
||||
isSecret: false,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
@@ -96,7 +150,7 @@ describe('buildEnvVar', () => {
|
||||
description: '',
|
||||
isSecret: false,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
@@ -121,7 +175,7 @@ describe('buildEnvVar', () => {
|
||||
description: '',
|
||||
isSecret: false,
|
||||
applicationId: 'app-1',
|
||||
workspaceId: '00000000-0000-0000-0000-000000000000',
|
||||
workspaceId: workspaceA,
|
||||
universalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
applicationUniversalIdentifier: '00000000-0000-0000-0000-000000000000',
|
||||
createdAt: '2024-01-01T00:00:00.000Z',
|
||||
|
||||
+3
-1
@@ -12,7 +12,9 @@ export const buildEnvVar = (
|
||||
|
||||
acc[flatApplicationVariable.key] =
|
||||
flatApplicationVariable.isSecret && isNonEmptyString(value)
|
||||
? secretEncryptionService.decrypt(value)
|
||||
? secretEncryptionService.decryptVersioned(value, {
|
||||
workspaceId: flatApplicationVariable.workspaceId,
|
||||
})
|
||||
: value;
|
||||
|
||||
return acc;
|
||||
|
||||
Reference in New Issue
Block a user