PluginProbe
Media Cloud Sync / 1.2.10
Media Cloud Sync v1.2.10
1.4.2 1.4.1 1.4.0 1.3.12 1.3.11 1.3.10 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.2.0 1.2.10 1.2.11 1.2.12 1.2.13 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 All 36 releases
media-cloud-sync / includes / sdk / s3 / Aws / Crypto / DecryptionTrait.php

DecryptionTrait.php in Media Cloud Sync 1.2.10, at includes/sdk/s3/Aws/Crypto/DecryptionTrait.php

110 lines 5.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace Dudlewebs\WPMCS\s3\Aws\Crypto;
4
5 use Dudlewebs\WPMCS\s3\GuzzleHttp\Psr7;
6 use Dudlewebs\WPMCS\s3\GuzzleHttp\Psr7\LimitStream;
7 use Dudlewebs\WPMCS\s3\Psr\Http\Message\StreamInterface;
8 trait DecryptionTrait
9 {
10 /**
11 * Dependency to reverse lookup the openssl_* cipher name from the AESName
12 * in the MetadataEnvelope.
13 *
14 * @param $aesName
15 *
16 * @return string
17 *
18 * @internal
19 */
20 protected abstract function getCipherFromAesName($aesName);
21 /**
22 * Dependency to generate a CipherMethod from a set of inputs for loading
23 * in to an AesDecryptingStream.
24 *
25 * @param string $cipherName Name of the cipher to generate for decrypting.
26 * @param string $iv Base Initialization Vector for the cipher.
27 * @param int $keySize Size of the encryption key, in bits, that will be
28 * used.
29 *
30 * @return Cipher\CipherMethod
31 *
32 * @internal
33 */
34 protected abstract function buildCipherMethod($cipherName, $iv, $keySize);
35 /**
36 * Builds an AesStreamInterface using cipher options loaded from the
37 * MetadataEnvelope and MaterialsProvider. Can decrypt data from both the
38 * legacy and V2 encryption client workflows.
39 *
40 * @param string $cipherText Plain-text data to be encrypted using the
41 * materials, algorithm, and data provided.
42 * @param MaterialsProviderInterface $provider A provider to supply and encrypt
43 * materials used in encryption.
44 * @param MetadataEnvelope $envelope A storage envelope for encryption
45 * metadata to be read from.
46 * @param array $cipherOptions Additional verification options.
47 *
48 * @return AesStreamInterface
49 *
50 * @throws \InvalidArgumentException Thrown when a value in $cipherOptions
51 * is not valid.
52 *
53 * @internal
54 */
55 public function decrypt($cipherText, MaterialsProviderInterface $provider, MetadataEnvelope $envelope, array $cipherOptions = [])
56 {
57 $cipherOptions['Iv'] = \base64_decode($envelope[MetadataEnvelope::IV_HEADER]);
58 $cipherOptions['TagLength'] = $envelope[MetadataEnvelope::CRYPTO_TAG_LENGTH_HEADER] / 8;
59 $cek = $provider->decryptCek(\base64_decode($envelope[MetadataEnvelope::CONTENT_KEY_V2_HEADER]), \json_decode($envelope[MetadataEnvelope::MATERIALS_DESCRIPTION_HEADER], \true));
60 $cipherOptions['KeySize'] = \strlen($cek) * 8;
61 $cipherOptions['Cipher'] = $this->getCipherFromAesName($envelope[MetadataEnvelope::CONTENT_CRYPTO_SCHEME_HEADER]);
62 $decryptionStream = $this->getDecryptingStream($cipherText, $cek, $cipherOptions);
63 unset($cek);
64 return $decryptionStream;
65 }
66 private function getTagFromCiphertextStream(StreamInterface $cipherText, $tagLength)
67 {
68 $cipherTextSize = $cipherText->getSize();
69 if ($cipherTextSize == null || $cipherTextSize <= 0) {
70 throw new \RuntimeException('Cannot decrypt a stream of unknown' . ' size.');
71 }
72 return (string) new LimitStream($cipherText, $tagLength, $cipherTextSize - $tagLength);
73 }
74 private function getStrippedCiphertextStream(StreamInterface $cipherText, $tagLength)
75 {
76 $cipherTextSize = $cipherText->getSize();
77 if ($cipherTextSize == null || $cipherTextSize <= 0) {
78 throw new \RuntimeException('Cannot decrypt a stream of unknown' . ' size.');
79 }
80 return new LimitStream($cipherText, $cipherTextSize - $tagLength, 0);
81 }
82 /**
83 * Generates a stream that wraps the cipher text with the proper cipher and
84 * uses the content encryption key (CEK) to decrypt the data when read.
85 *
86 * @param string $cipherText Plain-text data to be encrypted using the
87 * materials, algorithm, and data provided.
88 * @param string $cek A content encryption key for use by the stream for
89 * encrypting the plaintext data.
90 * @param array $cipherOptions Options for use in determining the cipher to
91 * be used for encrypting data.
92 *
93 * @return AesStreamInterface
94 *
95 * @internal
96 */
97 protected function getDecryptingStream($cipherText, $cek, $cipherOptions)
98 {
99 $cipherTextStream = Psr7\Utils::streamFor($cipherText);
100 switch ($cipherOptions['Cipher']) {
101 case 'gcm':
102 $cipherOptions['Tag'] = $this->getTagFromCiphertextStream($cipherTextStream, $cipherOptions['TagLength']);
103 return new AesGcmDecryptingStream($this->getStrippedCiphertextStream($cipherTextStream, $cipherOptions['TagLength']), $cek, $cipherOptions['Iv'], $cipherOptions['Tag'], $cipherOptions['Aad'] = isset($cipherOptions['Aad']) ? $cipherOptions['Aad'] : null, $cipherOptions['TagLength'] ?: null, $cipherOptions['KeySize']);
104 default:
105 $cipherMethod = $this->buildCipherMethod($cipherOptions['Cipher'], $cipherOptions['Iv'], $cipherOptions['KeySize']);
106 return new AesDecryptingStream($cipherTextStream, $cek, $cipherMethod);
107 }
108 }
109 }
110