Selaa lähdekoodia

fix: editing a client certificate no longer encrypts nothing over the key

CredentialStore::update switched on the credential type and had no case for
ClientCertificate and no default, so an update carrying a data field fell
through with data_to_encrypt still null - and that null was encrypted straight
over the stored certificate and private key. The blob went from 3920 bytes to
44 and the API answered 200. Nothing failed until the next request that tried
to present the certificate.

A rename was safe, because the re-encrypt block only runs when the update
carries data. Changing the certificate destroyed it.

The default arm now refuses instead of falling through, so the next credential
type added to create without update is a clear error rather than silent data
loss.
fszontagh 1 kuukausi sitten
vanhempi
sitoutus
e37e7519ba
1 muutettua tiedostoa jossa 21 lisäystä ja 0 poistoa
  1. 21 0
      lib/credentials/credential_store.cpp

+ 21 - 0
lib/credentials/credential_store.cpp

@@ -376,6 +376,27 @@ Result<void> CredentialStore::update(const std::string& id, const UpdateCredenti
                 };
                 break;
             }
+            case CredentialType::ClientCertificate: {
+                // Without this case the switch fell through to nothing, leaving
+                // data_to_encrypt null - so saving any edit to an mTLS
+                // credential encrypted an empty blob over the certificate and
+                // its key, and the credential silently stopped authenticating.
+                auto data = ClientCertificateData::fromJson(request_data);
+                if (data.certificate_pem.empty() || data.private_key_pem.empty()) {
+                    return Error(ErrorCode::InvalidArgument,
+                                 "A client certificate needs both the certificate and its "
+                                 "private key");
+                }
+                data_to_encrypt = data.toJson();
+                public_data = {{"hasPrivateKey", true}};
+                break;
+            }
+            default:
+                // Every type this store knows how to create it must also know
+                // how to update. Anything else refuses loudly rather than
+                // encrypting nothing over the top of a working credential.
+                return Error(ErrorCode::InvalidArgument,
+                             "This credential type cannot be updated");
         }
 
         auto encrypt_result = encryptData(data_to_encrypt);