Files
OpenFlare/internal/apps/openflare/tls/sensitive.go
T
ryan 63cd906cfc refactor(repo): consolidate openflare-server to root and move subprojects to internal/apps
- Merge all files inside openflare-server to the repository root directory.
- Relocate agent, relay, and flared subprojects from internal/ to internal/apps/.
- Combine docker-compose files and update build context paths to root.
- Update GitHub workflows and Dockerfiles to refer to new directories and package names.
- Rewrite Go package imports across all files.
- Resolve database renew test race condition and clean up docs.
2026-06-19 14:23:29 +08:00

56 lines
1.3 KiB
Go

// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package tls
import (
"crypto/sha256"
"encoding/hex"
"errors"
"strings"
"github.com/Rain-kl/Wavelet/internal/config"
"github.com/Rain-kl/Wavelet/pkg/util"
)
const sensitiveValuePrefix = "enc:v1:"
func sensitiveEncryptionKey() string {
if config.Config == nil || strings.TrimSpace(config.Config.App.SessionSecret) == "" {
return ""
}
sum := sha256.Sum256([]byte(config.Config.App.SessionSecret))
return hex.EncodeToString(sum[:])
}
func sealSensitive(plaintext string) (string, error) {
plaintext = strings.TrimSpace(plaintext)
if plaintext == "" {
return "", nil
}
key := sensitiveEncryptionKey()
if key == "" {
return plaintext, nil
}
encrypted, err := util.Encrypt(key, plaintext)
if err != nil {
return "", err
}
return sensitiveValuePrefix + encrypted, nil
}
func openSensitive(stored string) (string, error) {
stored = strings.TrimSpace(stored)
if stored == "" {
return "", nil
}
if !strings.HasPrefix(stored, sensitiveValuePrefix) {
return stored, nil
}
key := sensitiveEncryptionKey()
if key == "" {
return "", errors.New("cannot decrypt sensitive field without session secret")
}
return util.Decrypt(key, strings.TrimPrefix(stored, sensitiveValuePrefix))
}