feat(05-03): implement lagoon.Encrypted, key:generate, Laravel decrypt helper

- AES-256-GCM with stdlib HKDF column keys and previous_keys fallback
- Fail-loud LoadAppKey, redacting marshal paths, key:generate via crypto/rand
- Standalone DecryptLaravelPayload unwired from Scan/Value
This commit is contained in:
Jakub Zych
2026-09-18 19:35:24 +02:00
parent 06bad37c24
commit 8d9109a771
8 changed files with 503 additions and 9 deletions

View File

@@ -1,7 +1,9 @@
package lagoon
import (
"bytes"
"database/sql"
"encoding/base64"
"os"
"path/filepath"
"strings"
@@ -139,6 +141,7 @@ func TestOpenFromAppReadsDSN(t *testing.T) {
Environ: []string{
"SUMMER_ENV=development",
"SUMMER_DATABASE__DSN=" + dsn,
"SUMMER_APP__KEY=" + base64.StdEncoding.EncodeToString(bytes.Repeat([]byte("T"), 32)),
},
})
if err != nil {