Files
wanderer/db/util/secrets.go
Tomaz Muraus 123470b81b Fix for double encryption of secrets (#216)
* Update db init code to verify that all the required environment
variables are set.

* Add a workaround for integration secret encryption code - make sure we
don't try to encrypt the secret twice.

This is needed due to the bug in the code which would encrypt secrets
even if they are already encrypted.

* fixes spelling & folder structure

---------

Co-authored-by: Christian Beutel <>
2025-03-28 19:54:43 +01:00

54 lines
1.1 KiB
Go

package util
import (
"crypto/aes"
"crypto/cipher"
"encoding/base64"
"os"
"github.com/pocketbase/pocketbase/tools/security"
)
// LooksLikeEncrypted checks if the given string looks like base64 encoded and AES encrypted data.
// This is format used by pocketbase encryption.
func LooksLikeEncrypted(s string) bool {
ciphertext, err := base64.StdEncoding.DecodeString(s)
if err != nil {
return false
}
// Use a dummy 32-byte key since we only want the nonce size
dummyKey := make([]byte, 32)
block, err := aes.NewCipher(dummyKey)
if err != nil {
return false
}
gcm, err := cipher.NewGCM(block)
if err != nil {
return false
}
nonceSize := gcm.NonceSize()
// At minimum: nonce + GCM auth tag (16 bytes)
return len(ciphertext) >= nonceSize+16
}
// Return true if the provided value can be decrypted using the secret key
func CanDecryptSecret(ciphertext string) bool {
encryptionKey := os.Getenv("POCKETBASE_ENCRYPTION_KEY")
if len(encryptionKey) == 0 {
return false
}
decryptedSecret, err := security.Decrypt(ciphertext, encryptionKey)
if len(decryptedSecret) > 0 && err == nil {
return true
}
return false
}