1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
use openssl::symm::Cipher;
use url::Url;
use super::hkdf::{derive_auth_key, derive_file_key, derive_meta_key};
use super::{b64, rand_bytes};
use crate::api::url::UrlBuilder;
use crate::file::remote_file::RemoteFile;
const KEY_IV_LEN: usize = 12;
pub struct KeySet {
secret: Vec<u8>,
iv: [u8; KEY_IV_LEN],
file_key: Option<Vec<u8>>,
auth_key: Option<Vec<u8>>,
meta_key: Option<Vec<u8>>,
}
impl KeySet {
pub fn new(secret: Vec<u8>, iv: [u8; 12]) -> Self {
Self {
secret,
iv,
file_key: None,
auth_key: None,
meta_key: None,
}
}
pub fn from(file: &RemoteFile, password: Option<&String>) -> Self {
let mut set = Self::new(file.secret_raw().clone(), [0; 12]);
set.derive();
if let Some(password) = password {
set.derive_auth_password(password, &UrlBuilder::download(&file, true));
}
set
}
pub fn generate(derive: bool) -> Self {
let mut secret = vec![0u8; 16];
let mut iv = [0u8; 12];
rand_bytes(&mut secret).expect("failed to generate crypto secure random secret");
rand_bytes(&mut iv).expect("failed to generate crypto secure random input vector");
let mut key = Self::new(secret, iv);
if derive {
key.derive();
}
key
}
pub fn derive(&mut self) {
self.file_key = Some(derive_file_key(&self.secret));
self.auth_key = Some(derive_auth_key(&self.secret, None, None));
self.meta_key = Some(derive_meta_key(&self.secret));
}
pub fn derive_auth_password(&mut self, pass: &str, url: &Url) {
self.auth_key = Some(derive_auth_key(&self.secret, Some(pass), Some(url)));
}
pub fn secret(&self) -> &[u8] {
&self.secret
}
pub fn secret_encoded(&self) -> String {
b64::encode(self.secret())
}
pub fn iv(&self) -> &[u8] {
&self.iv
}
pub fn set_iv(&mut self, iv: [u8; KEY_IV_LEN]) {
self.iv = iv;
}
pub fn file_key(&self) -> Option<&Vec<u8>> {
self.file_key.as_ref()
}
pub fn auth_key(&self) -> Option<&Vec<u8>> {
self.auth_key.as_ref()
}
pub fn auth_key_encoded(&self) -> Option<String> {
self.auth_key().map(|key| b64::encode(key))
}
pub fn meta_key(&self) -> Option<&Vec<u8>> {
self.meta_key.as_ref()
}
pub fn cipher() -> Cipher {
Cipher::aes_128_gcm()
}
}