- AES-256-GCM with stdlib HKDF column keys and previous_keys fallback - Fail-loud LoadAppKey, redacting marshal paths, key:generate via crypto/rand - Standalone DecryptLaravelPayload unwired from Scan/Value
27 lines
643 B
Go
27 lines
643 B
Go
package lagoon
|
|
|
|
import (
|
|
"context"
|
|
"crypto/rand"
|
|
"encoding/base64"
|
|
|
|
"git.golem15.com/golem15/summercms/bonfire"
|
|
)
|
|
|
|
// KeyGenerateCommand prints a fresh 32-byte base64 app.key and performs no
|
|
// other side effect (D-11).
|
|
func KeyGenerateCommand() bonfire.Command {
|
|
return bonfire.Command{
|
|
Name: "key:generate",
|
|
Description: "Print a fresh 32-byte base64 app.key",
|
|
Run: func(ctx context.Context, in bonfire.Input, out bonfire.Output) error {
|
|
key := make([]byte, encryptedKeySize)
|
|
if _, err := rand.Read(key); err != nil {
|
|
return err
|
|
}
|
|
out.Success(base64.StdEncoding.EncodeToString(key))
|
|
return nil
|
|
},
|
|
}
|
|
}
|