fix(crypto): reject plaintext fallback without crypto (#4391)

* fix(crypto): reject plaintext fallback without crypto

* test(crypto): gate no-feature regression under cfg
This commit is contained in:
Zhengchao An
2026-07-08 09:29:37 +08:00
committed by GitHub
parent 2b063b0c4a
commit f8ee0e7071
6 changed files with 30 additions and 7 deletions
+1 -2
View File
@@ -35,7 +35,7 @@ chacha20poly1305 = { workspace = true, optional = true }
jsonwebtoken = { workspace = true }
base64-simd = { workspace = true }
pbkdf2 = { workspace = true, optional = true }
rand = { workspace = true, optional = true }
rand = { workspace = true }
rsa = { workspace = true, features = ["sha2"] }
serde = { workspace = true, features = ["derive"] }
sha2 = { workspace = true, optional = true }
@@ -55,7 +55,6 @@ crypto = [
"dep:argon2",
"dep:chacha20poly1305",
"dep:pbkdf2",
"dep:rand",
"dep:sha2",
]
+1 -1
View File
@@ -12,7 +12,7 @@
// See the License for the specific language governing permissions and
// limitations under the License.
#[cfg(not(feature = "fips"))]
#[cfg(all(any(test, feature = "crypto"), not(feature = "fips")))]
mod aes;
#[cfg(any(test, feature = "crypto"))]
+2 -2
View File
@@ -53,6 +53,6 @@ fn decrypt<T: aes_gcm::aead::Aead>(stream: T, nonce: &[u8], data: &[u8]) -> Resu
}
#[cfg(not(any(test, feature = "crypto")))]
pub fn decrypt_data(_password: &[u8], data: &[u8]) -> Result<Vec<u8>, crate::Error> {
Ok(data.to_vec())
pub fn decrypt_data(_password: &[u8], _data: &[u8]) -> Result<Vec<u8>, crate::Error> {
Err(crate::Error::ErrCryptoDisabled)
}
+2 -2
View File
@@ -75,6 +75,6 @@ fn encrypt<T: aes_gcm::aead::Aead>(
}
#[cfg(not(any(test, feature = "crypto")))]
pub fn encrypt_data(_password: &[u8], data: &[u8]) -> Result<Vec<u8>, crate::Error> {
Ok(data.to_vec())
pub fn encrypt_data(_password: &[u8], _data: &[u8]) -> Result<Vec<u8>, crate::Error> {
Err(crate::Error::ErrCryptoDisabled)
}
+3
View File
@@ -26,6 +26,9 @@ pub enum Error {
#[error("invalid key length")]
ErrInvalidKeyLength,
#[error("crypto feature is disabled")]
ErrCryptoDisabled,
#[cfg(any(test, feature = "crypto"))]
#[error("{0}")]
ErrInvalidLength(#[from] sha2::digest::InvalidLength),
+21
View File
@@ -0,0 +1,21 @@
#![cfg(not(feature = "crypto"))]
use rustfs_crypto::{Error, decrypt_data, encrypt_data};
#[test]
fn encrypt_data_returns_error_without_crypto_feature() {
let plain = b"must not be returned as ciphertext";
let result = encrypt_data(b"password", plain);
assert!(matches!(result, Err(Error::ErrCryptoDisabled)));
}
#[test]
fn decrypt_data_returns_error_without_crypto_feature() {
let ciphertext = b"must not be returned as plaintext";
let result = decrypt_data(b"password", ciphertext);
assert!(matches!(result, Err(Error::ErrCryptoDisabled)));
}