mirror of
https://github.com/42wim/matterbridge.git
synced 2025-01-09 12:02:35 +01:00
106 lines
2.7 KiB
Go
106 lines
2.7 KiB
Go
|
// Package cipher is a package for common encrypt/decrypt of symmetric key messages.
|
||
|
package cipher
|
||
|
|
||
|
import (
|
||
|
"bytes"
|
||
|
"crypto/aes"
|
||
|
"crypto/cipher"
|
||
|
"errors"
|
||
|
)
|
||
|
|
||
|
// Decrypt will use the given key, iv, and ciphertext and return
|
||
|
// the plaintext bytes.
|
||
|
func Decrypt(iv, key, ciphertext []byte) ([]byte, error) {
|
||
|
block, err := aes.NewCipher(key)
|
||
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
if len(ciphertext) < aes.BlockSize {
|
||
|
return nil, errors.New("ciphertext too short")
|
||
|
}
|
||
|
cbc := cipher.NewCBCDecrypter(block, iv)
|
||
|
cbc.CryptBlocks(ciphertext, ciphertext)
|
||
|
|
||
|
unpaddedText, err := pkcs7Unpad(ciphertext, aes.BlockSize)
|
||
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
|
||
|
return unpaddedText, nil
|
||
|
}
|
||
|
|
||
|
// Encrypt will use the given iv, key, and plaintext bytes
|
||
|
// and return ciphertext bytes.
|
||
|
func Encrypt(iv, key, plaintext []byte) ([]byte, error) {
|
||
|
block, err := aes.NewCipher(key)
|
||
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
paddedText, err := pkcs7Pad(plaintext, block.BlockSize())
|
||
|
if err != nil {
|
||
|
return nil, err
|
||
|
}
|
||
|
ciphertext := make([]byte, len(paddedText))
|
||
|
mode := cipher.NewCBCEncrypter(block, iv)
|
||
|
mode.CryptBlocks(ciphertext, paddedText)
|
||
|
|
||
|
return ciphertext, nil
|
||
|
}
|
||
|
|
||
|
// PKCS7 padding.
|
||
|
|
||
|
// PKCS7 errors.
|
||
|
var (
|
||
|
// ErrInvalidBlockSize indicates hash blocksize <= 0.
|
||
|
ErrInvalidBlockSize = errors.New("invalid blocksize")
|
||
|
|
||
|
// ErrInvalidPKCS7Data indicates bad input to PKCS7 pad or unpad.
|
||
|
ErrInvalidPKCS7Data = errors.New("invalid PKCS7 data (empty or not padded)")
|
||
|
|
||
|
// ErrInvalidPKCS7Padding indicates PKCS7 unpad fails to bad input.
|
||
|
ErrInvalidPKCS7Padding = errors.New("invalid padding on input")
|
||
|
)
|
||
|
|
||
|
// pkcs7Pad right-pads the given byte slice with 1 to n bytes, where
|
||
|
// n is the block size. The size of the result is x times n, where x
|
||
|
// is at least 1.
|
||
|
func pkcs7Pad(b []byte, blocksize int) ([]byte, error) {
|
||
|
if blocksize <= 0 {
|
||
|
return nil, ErrInvalidBlockSize
|
||
|
}
|
||
|
if b == nil || len(b) == 0 {
|
||
|
return nil, ErrInvalidPKCS7Data
|
||
|
}
|
||
|
n := blocksize - (len(b) % blocksize)
|
||
|
pb := make([]byte, len(b)+n)
|
||
|
copy(pb, b)
|
||
|
copy(pb[len(b):], bytes.Repeat([]byte{byte(n)}, n))
|
||
|
return pb, nil
|
||
|
}
|
||
|
|
||
|
// pkcs7Unpad validates and unpads data from the given bytes slice.
|
||
|
// The returned value will be 1 to n bytes smaller depending on the
|
||
|
// amount of padding, where n is the block size.
|
||
|
func pkcs7Unpad(b []byte, blocksize int) ([]byte, error) {
|
||
|
if blocksize <= 0 {
|
||
|
return nil, ErrInvalidBlockSize
|
||
|
}
|
||
|
if b == nil || len(b) == 0 {
|
||
|
return nil, ErrInvalidPKCS7Data
|
||
|
}
|
||
|
if len(b)%blocksize != 0 {
|
||
|
return nil, ErrInvalidPKCS7Padding
|
||
|
}
|
||
|
c := b[len(b)-1]
|
||
|
n := int(c)
|
||
|
if n == 0 || n > len(b) {
|
||
|
return nil, ErrInvalidPKCS7Padding
|
||
|
}
|
||
|
for i := 0; i < n; i++ {
|
||
|
if b[len(b)-n+i] != c {
|
||
|
return nil, ErrInvalidPKCS7Padding
|
||
|
}
|
||
|
}
|
||
|
return b[:len(b)-n], nil
|
||
|
}
|