Support MetadataKeyTypeUserKey, Rework Metadata Validation

This commit is contained in:
Samuel Lorch 2025-05-12 20:01:47 +02:00
parent 6a72f6987c
commit 5369030d50

View file

@ -7,11 +7,22 @@ import (
"fmt"
"strings"
"github.com/ProtonMail/gopenpgp/v3/crypto"
"github.com/passbolt/go-passbolt/api"
"github.com/santhosh-tekuri/jsonschema"
)
func GetResourceMetadata(ctx context.Context, c *api.Client, resource api.Resource, rType api.ResourceType) (string, error) {
var metadatakey *crypto.Key
if resource.MetadataKeyType == api.MetadataKeyTypeUserKey {
key, err := c.GetUserPrivateKeyCopy()
if err != nil {
return "", fmt.Errorf("Get User Private Key Copy: %W", err)
}
metadatakey = key
} else {
// Must be a shared key
keys, err := c.GetMetadataKeys(ctx, &api.GetMetadataKeysOptions{
ContainMetadataPrivateKeys: true,
})
@ -53,38 +64,51 @@ func GetResourceMetadata(ctx context.Context, c *api.Client, resource api.Resour
return "", fmt.Errorf("Get Metadata Private Key: %w", err)
}
decMetadata, err := c.DecryptMetadata(metadataPrivateKeyObj, resource.Metadata)
metadatakey = metadataPrivateKeyObj
}
decMetadata, err := c.DecryptMetadata(metadatakey, resource.Metadata)
if err != nil {
return "", fmt.Errorf("Decrypt Metadata: %w", err)
}
err = validateMetadata(&rType, string(decMetadata))
if err != nil {
return "", fmt.Errorf("Validate Metadata: %w", err)
}
return decMetadata, nil
}
func validateMetadata(rType *api.ResourceType, metadata string) error {
var schemaDefinition api.ResourceTypeSchema
err = json.Unmarshal([]byte(rType.Definition), &schemaDefinition)
definition := rType.Definition
// Fallback schema
if string(definition) == "[]" || string(definition) == "\"[]\"" {
tmp, ok := api.ResourceSchemas[rType.Slug]
if !ok {
return fmt.Errorf("Server Does not have the Required json Schema and there is no fallback available for type: %v", rType.Slug)
}
definition = tmp
}
err := json.Unmarshal([]byte(definition), &schemaDefinition)
if err != nil {
// Workaround for inconsistant API Responses where sometime the Schema is embedded directly and sometimes it's escaped as a string
if err.Error() == "json: cannot unmarshal string into Go value of type api.ResourceTypeSchema" {
var tmp string
err = json.Unmarshal([]byte(rType.Definition), &tmp)
err = json.Unmarshal([]byte(definition), &tmp)
if err != nil {
return "", fmt.Errorf("Workaround Unmarshal Json Schema String: %w", err)
}
if tmp == "[]" {
// Use The Builtin Fallback Schemas in this Case
schema, ok := api.ResourceSchemas[rType.Slug]
if !ok {
return "", fmt.Errorf("Server Does not have the Required json Schema and there is no fallback available for type: %v", rType.Slug)
}
tmp = string(schema)
return fmt.Errorf("Workaround Unmarshal Json Schema String: %w", err)
}
err = json.Unmarshal([]byte(tmp), &schemaDefinition)
if err != nil {
return "", fmt.Errorf("Workaround Unmarshal Json Schema: %w", err)
return fmt.Errorf("Workaround Unmarshal Json Schema: %w", err)
}
} else {
return "", fmt.Errorf("Unmarshal Json Schema: %w", err)
return fmt.Errorf("Unmarshal Json Schema: %w", err)
}
}
@ -92,18 +116,17 @@ func GetResourceMetadata(ctx context.Context, c *api.Client, resource api.Resour
err = comp.AddResource("metadata.json", bytes.NewReader(schemaDefinition.Resource))
if err != nil {
return "", fmt.Errorf("Adding Json Schema: %w", err)
return fmt.Errorf("Adding Json Schema: %w", err)
}
schema, err := comp.Compile("metadata.json")
if err != nil {
return "", fmt.Errorf("Compiling Json Schema: %w", err)
return fmt.Errorf("Compiling Json Schema: %w", err)
}
err = schema.Validate(strings.NewReader(decMetadata))
err = schema.Validate(strings.NewReader(metadata))
if err != nil {
return "", fmt.Errorf("Validating Secret Data: %w", err)
return fmt.Errorf("Validating Secret Data: %w", err)
}
return decMetadata, nil
return nil
}