PluginProbe
Media Cloud Sync / 1.2.10
Media Cloud Sync v1.2.10
1.4.2 1.4.1 1.4.0 1.3.12 1.3.11 1.3.10 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.2.0 1.2.10 1.2.11 1.2.12 1.2.13 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 All 36 releases
media-cloud-sync / includes / sdk / s3 / Aws / Crypto / KmsMaterialsProviderV2.php

KmsMaterialsProviderV2.php in Media Cloud Sync 1.2.10, at includes/sdk/s3/Aws/Crypto/KmsMaterialsProviderV2.php

70 lines 3.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace Dudlewebs\WPMCS\s3\Aws\Crypto;
4
5 use Dudlewebs\WPMCS\s3\Aws\Exception\CryptoException;
6 use Dudlewebs\WPMCS\s3\Aws\Kms\KmsClient;
7 /**
8 * Uses KMS to supply materials for encrypting and decrypting data. This
9 * V2 implementation should be used with the V2 encryption clients (i.e.
10 * S3EncryptionClientV2).
11 */
12 class KmsMaterialsProviderV2 extends MaterialsProviderV2 implements MaterialsProviderInterfaceV2
13 {
14 const WRAP_ALGORITHM_NAME = 'kms+context';
15 private $kmsClient;
16 private $kmsKeyId;
17 /**
18 * @param KmsClient $kmsClient A KMS Client for use encrypting and
19 * decrypting keys.
20 * @param string $kmsKeyId The private KMS key id to be used for encrypting
21 * and decrypting keys.
22 */
23 public function __construct(KmsClient $kmsClient, $kmsKeyId = null)
24 {
25 $this->kmsClient = $kmsClient;
26 $this->kmsKeyId = $kmsKeyId;
27 }
28 /**
29 * @inheritDoc
30 */
31 public function getWrapAlgorithmName()
32 {
33 return self::WRAP_ALGORITHM_NAME;
34 }
35 /**
36 * @inheritDoc
37 */
38 public function decryptCek($encryptedCek, $materialDescription, $options)
39 {
40 $params = ['CiphertextBlob' => $encryptedCek, 'EncryptionContext' => $materialDescription];
41 if (empty($options['@KmsAllowDecryptWithAnyCmk'])) {
42 if (empty($this->kmsKeyId)) {
43 throw new CryptoException('KMS CMK ID was not specified and the' . ' operation is not opted-in to attempting to use any valid' . ' CMK it discovers. Please specify a CMK ID, or explicitly' . ' enable attempts to use any valid KMS CMK with the' . ' @KmsAllowDecryptWithAnyCmk option.');
44 }
45 $params['KeyId'] = $this->kmsKeyId;
46 }
47 $result = $this->kmsClient->decrypt($params);
48 return $result['Plaintext'];
49 }
50 /**
51 * @inheritDoc
52 */
53 public function generateCek($keySize, $context, $options)
54 {
55 if (empty($this->kmsKeyId)) {
56 throw new CryptoException('A KMS key id is required for encryption' . ' with KMS keywrap. Use a KmsMaterialsProviderV2 that has been' . ' instantiated with a KMS key id.');
57 }
58 $options = \array_change_key_case($options);
59 if (!isset($options['@kmsencryptioncontext']) || !\is_array($options['@kmsencryptioncontext'])) {
60 throw new CryptoException("'@KmsEncryptionContext' is a" . " required argument when using KmsMaterialsProviderV2, and" . " must be an associative array (or empty array).");
61 }
62 if (isset($options['@kmsencryptioncontext']['aws:x-amz-cek-alg'])) {
63 throw new CryptoException("Conflict in reserved @KmsEncryptionContext" . " key aws:x-amz-cek-alg. This value is reserved for the S3" . " Encryption Client and cannot be set by the user.");
64 }
65 $context = \array_merge($options['@kmsencryptioncontext'], $context);
66 $result = $this->kmsClient->generateDataKey(['KeyId' => $this->kmsKeyId, 'KeySpec' => "AES_{$keySize}", 'EncryptionContext' => $context]);
67 return ['Plaintext' => $result['Plaintext'], 'Ciphertext' => \base64_encode($result['CiphertextBlob']), 'UpdatedContext' => $context];
68 }
69 }
70