mirror of
https://github.com/suitenumerique/meet.git
synced 2026-08-28 19:27:50 +00:00
wip encrypt and encode passphrase while storing it in cache
This commit is contained in:
@@ -18,6 +18,9 @@ import secrets
|
|||||||
import string
|
import string
|
||||||
|
|
||||||
from django.core.cache import cache
|
from django.core.cache import cache
|
||||||
|
from cryptography.fernet import Fernet
|
||||||
|
|
||||||
|
import base64
|
||||||
|
|
||||||
|
|
||||||
def generate_random_passphrase(length=26):
|
def generate_random_passphrase(length=26):
|
||||||
@@ -28,15 +31,21 @@ def generate_random_passphrase(length=26):
|
|||||||
def get_cached_passphrase(room_id):
|
def get_cached_passphrase(room_id):
|
||||||
"""Get or generate a cached passphrase for a room slug"""
|
"""Get or generate a cached passphrase for a room slug"""
|
||||||
|
|
||||||
|
cypher = Fernet(settings.PASSPHRASE_ENCRYPTION_KEY.encode())
|
||||||
|
|
||||||
# todo - discuss this hardcoded key prefix
|
# todo - discuss this hardcoded key prefix
|
||||||
passphrase = cache.get(f"room_passphrase:{room_id}")
|
encrypted_passphrase = cache.get(f"room_passphrase:{room_id}")
|
||||||
|
|
||||||
if passphrase is None:
|
if encrypted_passphrase is None:
|
||||||
passphrase = generate_random_passphrase()
|
passphrase = generate_random_passphrase()
|
||||||
# Store in cache with a timeout (e.g., 24 hours = 86400 seconds)
|
encrypted_passphrase = cypher.encrypt(passphrase.encode()).decode()
|
||||||
cache.set(f"room_passphrase:{room_id}", passphrase, timeout=86400)
|
|
||||||
|
|
||||||
return passphrase
|
# Store in cache with a timeout (e.g., 24 hours = 86400 seconds)
|
||||||
|
cache.set(f"room_passphrase:{room_id}", encrypted_passphrase, timeout=86400)
|
||||||
|
|
||||||
|
return passphrase
|
||||||
|
|
||||||
|
return cypher.decrypt(encrypted_passphrase.encode()).decode()
|
||||||
|
|
||||||
|
|
||||||
def generate_color(identity: str) -> str:
|
def generate_color(identity: str) -> str:
|
||||||
|
|||||||
@@ -483,6 +483,8 @@ class Base(Configuration):
|
|||||||
)
|
)
|
||||||
BREVO_API_CONTACT_ATTRIBUTES = values.DictValue({"VISIO_USER": True})
|
BREVO_API_CONTACT_ATTRIBUTES = values.DictValue({"VISIO_USER": True})
|
||||||
|
|
||||||
|
PASSPHRASE_ENCRYPTION_KEY = values.Value(environ_name="PASSPHRASE_ENCRYPTION_KEY", environ_prefix=None)
|
||||||
|
|
||||||
# pylint: disable=invalid-name
|
# pylint: disable=invalid-name
|
||||||
@property
|
@property
|
||||||
def ENVIRONMENT(self):
|
def ENVIRONMENT(self):
|
||||||
|
|||||||
@@ -61,6 +61,7 @@ backend:
|
|||||||
RECORDING_STORAGE_EVENT_TOKEN: password
|
RECORDING_STORAGE_EVENT_TOKEN: password
|
||||||
SUMMARY_SERVICE_ENDPOINT: http://meet-summary:80/api/v1/tasks/
|
SUMMARY_SERVICE_ENDPOINT: http://meet-summary:80/api/v1/tasks/
|
||||||
SUMMARY_SERVICE_API_TOKEN: password
|
SUMMARY_SERVICE_API_TOKEN: password
|
||||||
|
PASSPHRASE_ENCRYPTION_KEY: lT3cX5dzFhCe-9xNjXUiTCX00r2ZgHgGUJKO66x-QIo=
|
||||||
|
|
||||||
|
|
||||||
migrate:
|
migrate:
|
||||||
|
|||||||
Reference in New Issue
Block a user