Skip to content

Commit

Permalink
Implement cipher key encryption (#3990)
Browse files Browse the repository at this point in the history
  • Loading branch information
dani-garcia authored Oct 22, 2023
1 parent 6eaf131 commit cb4b683
Show file tree
Hide file tree
Showing 12 changed files with 29 additions and 1 deletion.
Empty file.
2 changes: 2 additions & 0 deletions migrations/mysql/2023-10-21-221242_add_cipher_key/up.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
ALTER TABLE ciphers
ADD COLUMN "key" TEXT;
Empty file.
2 changes: 2 additions & 0 deletions migrations/postgresql/2023-10-21-221242_add_cipher_key/up.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
ALTER TABLE ciphers
ADD COLUMN "key" TEXT;
Empty file.
2 changes: 2 additions & 0 deletions migrations/sqlite/2023-10-21-221242_add_cipher_key/up.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
ALTER TABLE ciphers
ADD COLUMN "key" TEXT;
3 changes: 3 additions & 0 deletions src/api/core/ciphers.rs
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,8 @@ pub struct CipherData {
// TODO: Some of these might appear all the time, no need for Option
OrganizationId: Option<String>,

Key: Option<String>,

/*
Login = 1,
SecureNote = 2,
Expand Down Expand Up @@ -483,6 +485,7 @@ pub async fn update_cipher_from_data(
None => err!("Data missing"),
};

cipher.key = data.Key;
cipher.name = data.Name;
cipher.notes = data.Notes;
cipher.fields = data.Fields.map(|f| _clean_cipher_data(f).to_string());
Expand Down
13 changes: 12 additions & 1 deletion src/api/core/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -194,7 +194,12 @@ fn version() -> Json<&'static str> {
fn config() -> Json<Value> {
let domain = crate::CONFIG.domain();
Json(json!({
"version": crate::VERSION,
// Note: The clients use this version to handle backwards compatibility concerns
// This means they expect a version that closely matches the Bitwarden server version
// We should make sure that we keep this updated when we support the new server features
// Version history:
// - Individual cipher key encryption: 2023.9.1
"version": "2023.9.1",
"gitHash": option_env!("GIT_REV"),
"server": {
"name": "Vaultwarden",
Expand All @@ -207,6 +212,12 @@ fn config() -> Json<Value> {
"notifications": format!("{domain}/notifications"),
"sso": "",
},
"featureStates": {
// Any feature flags that we want the clients to use
// Can check the enabled ones at:
// https://vault.bitwarden.com/api/config
"autofill-v2": true
},
"object": "config",
}))
}
Expand Down
5 changes: 5 additions & 0 deletions src/db/models/cipher.rs
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ db_object! {
pub user_uuid: Option<String>,
pub organization_uuid: Option<String>,

pub key: Option<String>,

/*
Login = 1,
SecureNote = 2,
Expand Down Expand Up @@ -62,6 +64,8 @@ impl Cipher {
user_uuid: None,
organization_uuid: None,

key: None,

atype,
name,

Expand Down Expand Up @@ -203,6 +207,7 @@ impl Cipher {
"DeletedDate": self.deleted_at.map_or(Value::Null, |d| Value::String(format_date(&d))),
"Reprompt": self.reprompt.unwrap_or(RepromptType::None as i32),
"OrganizationId": self.organization_uuid,
"Key": self.key,
"Attachments": attachments_json,
// We have UseTotp set to true by default within the Organization model.
// This variable together with UsersGetPremium is used to show or hide the TOTP counter.
Expand Down
1 change: 1 addition & 0 deletions src/db/schemas/mysql/schema.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ table! {
updated_at -> Datetime,
user_uuid -> Nullable<Text>,
organization_uuid -> Nullable<Text>,
key -> Nullable<Text>,
atype -> Integer,
name -> Text,
notes -> Nullable<Text>,
Expand Down
1 change: 1 addition & 0 deletions src/db/schemas/postgresql/schema.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ table! {
updated_at -> Timestamp,
user_uuid -> Nullable<Text>,
organization_uuid -> Nullable<Text>,
key -> Nullable<Text>,
atype -> Integer,
name -> Text,
notes -> Nullable<Text>,
Expand Down
1 change: 1 addition & 0 deletions src/db/schemas/sqlite/schema.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ table! {
updated_at -> Timestamp,
user_uuid -> Nullable<Text>,
organization_uuid -> Nullable<Text>,
key -> Nullable<Text>,
atype -> Integer,
name -> Text,
notes -> Nullable<Text>,
Expand Down

0 comments on commit cb4b683

Please sign in to comment.