feat(05-03): implement lagoon.Encrypted, key:generate, Laravel decrypt helper

- AES-256-GCM with stdlib HKDF column keys and previous_keys fallback
- Fail-loud LoadAppKey, redacting marshal paths, key:generate via crypto/rand
- Standalone DecryptLaravelPayload unwired from Scan/Value
This commit is contained in:
Jakub Zych
2026-09-18 19:35:24 +02:00
parent 06bad37c24
commit 8d9109a771
8 changed files with 503 additions and 9 deletions

View File

@@ -61,7 +61,7 @@ func TestRuntimeCommandsRegisterBareAndColonNames(t *testing.T) {
for _, c := range cmds {
names[c.Name] = true
}
for _, want := range []string{"migrate", "migrate:rollback", "migrate:status"} {
for _, want := range []string{"migrate", "migrate:rollback", "migrate:status", "key:generate"} {
if !names[want] {
t.Fatalf("missing %s", want)
}
@@ -131,11 +131,11 @@ type migPlugin struct {
migrations []*gormigrate.Migration
}
func (p migPlugin) ID() string { return p.id }
func (p migPlugin) Requires() []string { return nil }
func (p migPlugin) Register(*backpack.App) error { return nil }
func (p migPlugin) Boot(*backpack.App) error { return nil }
func (p migPlugin) Migrations() []*gormigrate.Migration { return p.migrations }
func (p migPlugin) ID() string { return p.id }
func (p migPlugin) Requires() []string { return nil }
func (p migPlugin) Register(*backpack.App) error { return nil }
func (p migPlugin) Boot(*backpack.App) error { return nil }
func (p migPlugin) Migrations() []*gormigrate.Migration { return p.migrations }
func TestTwoPluginMigrationSetsIsolated(t *testing.T) {
db, _ := dedicatedDB(t, "lagoon_mig_iso")