feat(05-03): implement lagoon.Encrypted, key:generate, Laravel decrypt helper
- AES-256-GCM with stdlib HKDF column keys and previous_keys fallback - Fail-loud LoadAppKey, redacting marshal paths, key:generate via crypto/rand - Standalone DecryptLaravelPayload unwired from Scan/Value
This commit is contained in:
26
lagoon/keygen.go
Normal file
26
lagoon/keygen.go
Normal file
@@ -0,0 +1,26 @@
|
||||
package lagoon
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
|
||||
"git.golem15.com/golem15/summercms/bonfire"
|
||||
)
|
||||
|
||||
// KeyGenerateCommand prints a fresh 32-byte base64 app.key and performs no
|
||||
// other side effect (D-11).
|
||||
func KeyGenerateCommand() bonfire.Command {
|
||||
return bonfire.Command{
|
||||
Name: "key:generate",
|
||||
Description: "Print a fresh 32-byte base64 app.key",
|
||||
Run: func(ctx context.Context, in bonfire.Input, out bonfire.Output) error {
|
||||
key := make([]byte, encryptedKeySize)
|
||||
if _, err := rand.Read(key); err != nil {
|
||||
return err
|
||||
}
|
||||
out.Success(base64.StdEncoding.EncodeToString(key))
|
||||
return nil
|
||||
},
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user