From 5d606bba66af245ff4e2b20e99c680ec9f6c2a59 Mon Sep 17 00:00:00 2001 From: Hubert Chathi Date: Mon, 13 Apr 2020 16:54:02 -0400 Subject: [PATCH] add test for passthrough on backups --- spec/unit/crypto/secrets.spec.js | 138 +++++++++++++++++++++++++++++++ 1 file changed, 138 insertions(+) diff --git a/spec/unit/crypto/secrets.spec.js b/spec/unit/crypto/secrets.spec.js index a40ceb137..0e3318de4 100644 --- a/spec/unit/crypto/secrets.spec.js +++ b/spec/unit/crypto/secrets.spec.js @@ -578,6 +578,144 @@ describe("Secrets", function() { expect(await alice.getSecret("m.megolm_backup.v1")) .toEqual(olmlib.encodeBase64(backupKey)); }); + it("converts asymmetric SSSS with passthrough to symmetric SSSS", async function() { + let crossSigningKeys = {}; + const secretStorageKeys = { + "old_key_id": SSSSKey, + "new_key_id": SSSSKey, + }; + const alice = await makeTestClient( + {userId: "@alice:example.com", deviceId: "Osborne2"}, + { + cryptoCallbacks: { + getCrossSigningKey: t => crossSigningKeys[t], + saveCrossSigningKeys: k => crossSigningKeys = k, + getSecretStorageKey: ({keys}, name) => { + for (const keyId of Object.keys(keys)) { + if (secretStorageKeys[keyId]) { + return [keyId, secretStorageKeys[keyId]]; + } + } + }, + }, + }, + ); + const encryption = new global.Olm.PkEncryption(); + encryption.set_recipient_key(SSSSPubKey); + alice.store.storeAccountDataEvents([ + new MatrixEvent({ + type: "m.secret_storage.default_key", + content: { + key: "old_key_id", + }, + }), + new MatrixEvent({ + type: "m.secret_storage.key.old_key_id", + content: sign({ + algorithm: "m.secret_storage.v1.curve25519-aes-sha2", + passphrase: { + algorithm: "m.pbkdf2", + iterations: 500000, + salt: "GbkvwKHVMveo1zGVSb2GMMdCinG2npJK", + }, + pubkey: "v3A8HTypbccUm6jaRCRw5l+7lSdzQUACeY9xpQ5BVmE", + }, XSK, "@alice:example.com"), + }), + new MatrixEvent({ + type: "m.cross_signing.master", + content: { + encrypted: { + old_key_id: encryption.encrypt(olmlib.encodeBase64(XSK)), + }, + }, + }), + new MatrixEvent({ + type: "m.cross_signing.self_signing", + content: { + encrypted: { + old_key_id: encryption.encrypt(olmlib.encodeBase64(SSK)), + }, + }, + }), + new MatrixEvent({ + type: "m.cross_signing.user_signing", + content: { + encrypted: { + old_key_id: encryption.encrypt(olmlib.encodeBase64(USK)), + }, + }, + }), + new MatrixEvent({ + type: "m.megolm_backup.v1", + content: { + encrypted: { + old_key_id: { + passthrough: true, + }, + }, + }, + }), + ]); + encryption.free(); + alice._crypto._deviceList.storeCrossSigningForUser("@alice:example.com", { + keys: { + master: { + user_id: "@alice:example.com", + usage: ["master"], + keys: { + [`ed25519:${XSPubKey}`]: XSPubKey, + }, + }, + self_signing: sign({ + user_id: "@alice:example.com", + usage: ["self_signing"], + keys: { + [`ed25519:${SSPubKey}`]: SSPubKey, + }, + }, XSK, "@alice:example.com"), + user_signing: sign({ + user_id: "@alice:example.com", + usage: ["user_signing"], + keys: { + [`ed25519:${USPubKey}`]: USPubKey, + }, + }, XSK, "@alice:example.com"), + }, + }); + alice.getKeyBackupVersion = async () => { + return { + version: "1", + algorithm: "m.megolm_backup.v1.curve25519-aes-sha2", + auth_data: sign({ + public_key: "v3A8HTypbccUm6jaRCRw5l+7lSdzQUACeY9xpQ5BVmE", + }, XSK, "@alice:example.com"), + }; + }; + const origAddSecretStorageKey = alice._crypto.addSecretStorageKey; + alice._crypto.addSecretStorageKey = async function(algorithm, opts, keyId) { + return await origAddSecretStorageKey.call( + alice._crypto, algorithm, opts, keyId || "new_key_id", + ); + }; + alice.setAccountData = async function(name, data) { + const event = new MatrixEvent({ + type: name, + content: data, + }); + alice.store.storeAccountDataEvents([event]); + this.emit("accountData", event); + }; + + await alice.bootstrapSecretStorage(); + + // the new backup key should be the encoded SSSS key + const backupKeyInfo = alice.getAccountData("m.megolm_backup.v1") + .getContent(); + expect(backupKeyInfo.encrypted).toHaveProperty("new_key_id"); + expect(backupKeyInfo.encrypted).not.toHaveProperty("old_key_id"); + expect(await alice.getSecret("m.megolm_backup.v1")) + .toEqual(olmlib.encodeBase64(SSSSKey)); + }); it("adds passphrase checking if it's lacking", async function() { let crossSigningKeys = { master: XSK,