mirror of
https://github.com/the-djmaze/snappymail.git
synced 2026-08-27 19:19:21 +03:00
Improve security of SensitiveString
This commit is contained in:
parent
b7b266defc
commit
95ec5e6bb0
1 changed files with 26 additions and 21 deletions
|
|
@ -2,23 +2,10 @@
|
|||
|
||||
namespace SnappyMail;
|
||||
|
||||
function xorIt(
|
||||
#[\SensitiveParameter]
|
||||
string $value
|
||||
) : string
|
||||
{
|
||||
$key = APP_SALT;
|
||||
$kl = \strlen($key);
|
||||
$i = \strlen($value);
|
||||
while ($i--) {
|
||||
$value[$i] = $value[$i] ^ $key[$i % $kl];
|
||||
}
|
||||
return $value;
|
||||
}
|
||||
|
||||
class SensitiveString /* extends SensitiveParameterValue | SensitiveParameter */ implements \Stringable
|
||||
{
|
||||
private string $value, $nonce;
|
||||
private static ?string $key = null;
|
||||
|
||||
public function __construct(
|
||||
#[\SensitiveParameter]
|
||||
|
|
@ -31,9 +18,9 @@ class SensitiveString /* extends SensitiveParameterValue | SensitiveParameter */
|
|||
public function getValue(): string
|
||||
{
|
||||
if (\is_callable('sodium_crypto_secretbox')) {
|
||||
return \sodium_crypto_secretbox_open($this->value, $this->nonce, APP_SALT);
|
||||
return \sodium_crypto_secretbox_open($this->value, $this->nonce, static::$key);
|
||||
}
|
||||
return xorIt($this->value);
|
||||
return static::xorIt($this->value);
|
||||
}
|
||||
|
||||
public function setValue(
|
||||
|
|
@ -43,13 +30,31 @@ class SensitiveString /* extends SensitiveParameterValue | SensitiveParameter */
|
|||
{
|
||||
if (\is_callable('sodium_crypto_secretbox')) {
|
||||
$this->nonce = \random_bytes(\SODIUM_CRYPTO_SECRETBOX_NONCEBYTES);
|
||||
// $this->key = \sodium_crypto_secretbox_keygen();
|
||||
$this->value = \sodium_crypto_secretbox($value, $this->nonce, APP_SALT);
|
||||
if (!static::$key) {
|
||||
static::$key = \sodium_crypto_secretbox_keygen();
|
||||
}
|
||||
$this->value = \sodium_crypto_secretbox($value, $this->nonce, static::$key);
|
||||
} else {
|
||||
$this->value = xorIt($value);
|
||||
$this->value = static::xorIt($value);
|
||||
}
|
||||
}
|
||||
|
||||
private static function xorIt(
|
||||
#[\SensitiveParameter]
|
||||
string $value
|
||||
) : string
|
||||
{
|
||||
if (!static::$key) {
|
||||
static::$key = \random_bytes(32);
|
||||
}
|
||||
$kl = \strlen(static::$key);
|
||||
$i = \strlen($value);
|
||||
while ($i--) {
|
||||
$value[$i] = $value[$i] ^ static::$key[$i % $kl];
|
||||
}
|
||||
return $value;
|
||||
}
|
||||
|
||||
public function __toString(): string
|
||||
{
|
||||
return $this->getValue();
|
||||
|
|
@ -62,11 +67,11 @@ class SensitiveString /* extends SensitiveParameterValue | SensitiveParameter */
|
|||
|
||||
public function __serialize(): array
|
||||
{
|
||||
throw new \Exception("Serialization of 'SensitiveString' is not allowed");
|
||||
throw new \Exception("Serialization of 'SnappyMail\\SensitiveString' is not allowed");
|
||||
}
|
||||
|
||||
public function __unserialize(array $data): void
|
||||
{
|
||||
throw new \Exception("Unserialization of 'SensitiveString' is not allowed");
|
||||
throw new \Exception("Unserialization of 'SnappyMail\\SensitiveString' is not allowed");
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue