mirror of
https://github.com/netbirdio/netbird.git
synced 2024-12-13 10:21:10 +01:00
d4b6d7646c
Implement user deletion across all IDP-ss. Expires all user peers when the user is deleted. Users are permanently removed from a local store, but in IDP, we remove Netbird attributes for the user untilUserDeleteFromIDPEnabled setting is not enabled. To test, an admin user should remove any additional users. Until the UI incorporates this feature, use a curl DELETE request targeting the /users/<USER_ID> management endpoint. Note that this request only removes user attributes and doesn't trigger a delete from the IDP. To enable user removal from the IdP, set UserDeleteFromIDPEnabled to true in account settings. Until we have a UI for this, make this change directly in the store file. Store the deleted email addresses in encrypted in activity store.
82 lines
1.8 KiB
Go
82 lines
1.8 KiB
Go
package sqlite
|
|
|
|
import (
|
|
"bytes"
|
|
"crypto/aes"
|
|
"crypto/cipher"
|
|
"crypto/rand"
|
|
"encoding/base64"
|
|
"fmt"
|
|
)
|
|
|
|
var iv = []byte{10, 22, 13, 79, 05, 8, 52, 91, 87, 98, 88, 98, 35, 25, 13, 05}
|
|
|
|
type EmailEncrypt struct {
|
|
block cipher.Block
|
|
}
|
|
|
|
func GenerateKey() (string, error) {
|
|
key := make([]byte, 32)
|
|
_, err := rand.Read(key)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
readableKey := base64.StdEncoding.EncodeToString(key)
|
|
return readableKey, nil
|
|
}
|
|
|
|
func NewEmailEncrypt(key string) (*EmailEncrypt, error) {
|
|
binKey, err := base64.StdEncoding.DecodeString(key)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
block, err := aes.NewCipher(binKey)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
ec := &EmailEncrypt{
|
|
block: block,
|
|
}
|
|
|
|
return ec, nil
|
|
}
|
|
|
|
func (ec *EmailEncrypt) Encrypt(payload string) string {
|
|
plainText := pkcs5Padding([]byte(payload))
|
|
cipherText := make([]byte, len(plainText))
|
|
cbc := cipher.NewCBCEncrypter(ec.block, iv)
|
|
cbc.CryptBlocks(cipherText, plainText)
|
|
return base64.StdEncoding.EncodeToString(cipherText)
|
|
}
|
|
|
|
func (ec *EmailEncrypt) Decrypt(data string) (string, error) {
|
|
cipherText, err := base64.StdEncoding.DecodeString(data)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
cbc := cipher.NewCBCDecrypter(ec.block, iv)
|
|
cbc.CryptBlocks(cipherText, cipherText)
|
|
payload, err := pkcs5UnPadding(cipherText)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
return string(payload), nil
|
|
}
|
|
|
|
func pkcs5Padding(ciphertext []byte) []byte {
|
|
padding := aes.BlockSize - len(ciphertext)%aes.BlockSize
|
|
padText := bytes.Repeat([]byte{byte(padding)}, padding)
|
|
return append(ciphertext, padText...)
|
|
}
|
|
|
|
func pkcs5UnPadding(src []byte) ([]byte, error) {
|
|
srcLen := len(src)
|
|
paddingLen := int(src[srcLen-1])
|
|
if paddingLen >= srcLen || paddingLen > aes.BlockSize {
|
|
return nil, fmt.Errorf("padding size error")
|
|
}
|
|
return src[:srcLen-paddingLen], nil
|
|
}
|