mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-26 16:28:15 +00:00
fix(crypto): reject plaintext fallback without crypto (#4391)
* fix(crypto): reject plaintext fallback without crypto * test(crypto): gate no-feature regression under cfg
This commit is contained in:
@@ -35,7 +35,7 @@ chacha20poly1305 = { workspace = true, optional = true }
|
||||
jsonwebtoken = { workspace = true }
|
||||
base64-simd = { workspace = true }
|
||||
pbkdf2 = { workspace = true, optional = true }
|
||||
rand = { workspace = true, optional = true }
|
||||
rand = { workspace = true }
|
||||
rsa = { workspace = true, features = ["sha2"] }
|
||||
serde = { workspace = true, features = ["derive"] }
|
||||
sha2 = { workspace = true, optional = true }
|
||||
@@ -55,7 +55,6 @@ crypto = [
|
||||
"dep:argon2",
|
||||
"dep:chacha20poly1305",
|
||||
"dep:pbkdf2",
|
||||
"dep:rand",
|
||||
"dep:sha2",
|
||||
]
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
#[cfg(not(feature = "fips"))]
|
||||
#[cfg(all(any(test, feature = "crypto"), not(feature = "fips")))]
|
||||
mod aes;
|
||||
|
||||
#[cfg(any(test, feature = "crypto"))]
|
||||
|
||||
@@ -53,6 +53,6 @@ fn decrypt<T: aes_gcm::aead::Aead>(stream: T, nonce: &[u8], data: &[u8]) -> Resu
|
||||
}
|
||||
|
||||
#[cfg(not(any(test, feature = "crypto")))]
|
||||
pub fn decrypt_data(_password: &[u8], data: &[u8]) -> Result<Vec<u8>, crate::Error> {
|
||||
Ok(data.to_vec())
|
||||
pub fn decrypt_data(_password: &[u8], _data: &[u8]) -> Result<Vec<u8>, crate::Error> {
|
||||
Err(crate::Error::ErrCryptoDisabled)
|
||||
}
|
||||
|
||||
@@ -75,6 +75,6 @@ fn encrypt<T: aes_gcm::aead::Aead>(
|
||||
}
|
||||
|
||||
#[cfg(not(any(test, feature = "crypto")))]
|
||||
pub fn encrypt_data(_password: &[u8], data: &[u8]) -> Result<Vec<u8>, crate::Error> {
|
||||
Ok(data.to_vec())
|
||||
pub fn encrypt_data(_password: &[u8], _data: &[u8]) -> Result<Vec<u8>, crate::Error> {
|
||||
Err(crate::Error::ErrCryptoDisabled)
|
||||
}
|
||||
|
||||
@@ -26,6 +26,9 @@ pub enum Error {
|
||||
#[error("invalid key length")]
|
||||
ErrInvalidKeyLength,
|
||||
|
||||
#[error("crypto feature is disabled")]
|
||||
ErrCryptoDisabled,
|
||||
|
||||
#[cfg(any(test, feature = "crypto"))]
|
||||
#[error("{0}")]
|
||||
ErrInvalidLength(#[from] sha2::digest::InvalidLength),
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
#![cfg(not(feature = "crypto"))]
|
||||
|
||||
use rustfs_crypto::{Error, decrypt_data, encrypt_data};
|
||||
|
||||
#[test]
|
||||
fn encrypt_data_returns_error_without_crypto_feature() {
|
||||
let plain = b"must not be returned as ciphertext";
|
||||
|
||||
let result = encrypt_data(b"password", plain);
|
||||
|
||||
assert!(matches!(result, Err(Error::ErrCryptoDisabled)));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn decrypt_data_returns_error_without_crypto_feature() {
|
||||
let ciphertext = b"must not be returned as plaintext";
|
||||
|
||||
let result = decrypt_data(b"password", ciphertext);
|
||||
|
||||
assert!(matches!(result, Err(Error::ErrCryptoDisabled)));
|
||||
}
|
||||
Reference in New Issue
Block a user