| 1 |
<?php |
| 2 |
|
| 3 |
namespace Dudlewebs\WPMCS\s3\Aws\Crypto; |
| 4 |
|
| 5 |
use Dudlewebs\WPMCS\s3\Aws\Exception\CryptoException; |
| 6 |
use Dudlewebs\WPMCS\s3\Aws\Kms\KmsClient; |
| 7 |
/** |
| 8 |
* Uses KMS to supply materials for encrypting and decrypting data. This |
| 9 |
* V2 implementation should be used with the V2 encryption clients (i.e. |
| 10 |
* S3EncryptionClientV2). |
| 11 |
*/ |
| 12 |
class KmsMaterialsProviderV2 extends MaterialsProviderV2 implements MaterialsProviderInterfaceV2 |
| 13 |
{ |
| 14 |
const WRAP_ALGORITHM_NAME = 'kms+context'; |
| 15 |
private $kmsClient; |
| 16 |
private $kmsKeyId; |
| 17 |
/** |
| 18 |
* @param KmsClient $kmsClient A KMS Client for use encrypting and |
| 19 |
* decrypting keys. |
| 20 |
* @param string $kmsKeyId The private KMS key id to be used for encrypting |
| 21 |
* and decrypting keys. |
| 22 |
*/ |
| 23 |
public function __construct(KmsClient $kmsClient, $kmsKeyId = null) |
| 24 |
{ |
| 25 |
$this->kmsClient = $kmsClient; |
| 26 |
$this->kmsKeyId = $kmsKeyId; |
| 27 |
} |
| 28 |
/** |
| 29 |
* @inheritDoc |
| 30 |
*/ |
| 31 |
public function getWrapAlgorithmName() |
| 32 |
{ |
| 33 |
return self::WRAP_ALGORITHM_NAME; |
| 34 |
} |
| 35 |
/** |
| 36 |
* @inheritDoc |
| 37 |
*/ |
| 38 |
public function decryptCek($encryptedCek, $materialDescription, $options) |
| 39 |
{ |
| 40 |
$params = ['CiphertextBlob' => $encryptedCek, 'EncryptionContext' => $materialDescription]; |
| 41 |
if (empty($options['@KmsAllowDecryptWithAnyCmk'])) { |
| 42 |
if (empty($this->kmsKeyId)) { |
| 43 |
throw new CryptoException('KMS CMK ID was not specified and the' . ' operation is not opted-in to attempting to use any valid' . ' CMK it discovers. Please specify a CMK ID, or explicitly' . ' enable attempts to use any valid KMS CMK with the' . ' @KmsAllowDecryptWithAnyCmk option.'); |
| 44 |
} |
| 45 |
$params['KeyId'] = $this->kmsKeyId; |
| 46 |
} |
| 47 |
$result = $this->kmsClient->decrypt($params); |
| 48 |
return $result['Plaintext']; |
| 49 |
} |
| 50 |
/** |
| 51 |
* @inheritDoc |
| 52 |
*/ |
| 53 |
public function generateCek($keySize, $context, $options) |
| 54 |
{ |
| 55 |
if (empty($this->kmsKeyId)) { |
| 56 |
throw new CryptoException('A KMS key id is required for encryption' . ' with KMS keywrap. Use a KmsMaterialsProviderV2 that has been' . ' instantiated with a KMS key id.'); |
| 57 |
} |
| 58 |
$options = \array_change_key_case($options); |
| 59 |
if (!isset($options['@kmsencryptioncontext']) || !\is_array($options['@kmsencryptioncontext'])) { |
| 60 |
throw new CryptoException("'@KmsEncryptionContext' is a" . " required argument when using KmsMaterialsProviderV2, and" . " must be an associative array (or empty array)."); |
| 61 |
} |
| 62 |
if (isset($options['@kmsencryptioncontext']['aws:x-amz-cek-alg'])) { |
| 63 |
throw new CryptoException("Conflict in reserved @KmsEncryptionContext" . " key aws:x-amz-cek-alg. This value is reserved for the S3" . " Encryption Client and cannot be set by the user."); |
| 64 |
} |
| 65 |
$context = \array_merge($options['@kmsencryptioncontext'], $context); |
| 66 |
$result = $this->kmsClient->generateDataKey(['KeyId' => $this->kmsKeyId, 'KeySpec' => "AES_{$keySize}", 'EncryptionContext' => $context]); |
| 67 |
return ['Plaintext' => $result['Plaintext'], 'Ciphertext' => \base64_encode($result['CiphertextBlob']), 'UpdatedContext' => $context]; |
| 68 |
} |
| 69 |
} |
| 70 |
|