Redesign backup system: AES-256-GCM encrypted .mdd format
- Replace plaintext JSON export with encrypted binary format (JDownloader 2 style) - Fixed app-internal key, works on any machine without password - Export now includes ALL credentials (no more ***-masking), session AND history - Add debridLinkApiKeys, linkSnappy credentials to sensitive keys list - Backward-compatible import: auto-detects legacy JSON backups - File extension changed from .json to .mdd - MDD1 magic bytes + random IV + GCM auth tag for integrity Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
ca534196b8
commit
0edd8f6be5
+39
-55
@@ -1,66 +1,50 @@
|
||||
import crypto from "node:crypto";
|
||||
|
||||
export const SENSITIVE_KEYS = [
|
||||
"token",
|
||||
"megaLogin",
|
||||
"megaPassword",
|
||||
"bestToken",
|
||||
"allDebridToken",
|
||||
"archivePasswordList"
|
||||
] as const;
|
||||
// Fixed app key — like JDownloader 2: deterministic, works on any machine.
|
||||
// Not meant to protect against reverse-engineering, just prevents casual
|
||||
// plaintext snooping when someone opens the backup file.
|
||||
const APP_KEY_MATERIAL = "MDD-v2-backup-aes256gcm-2026";
|
||||
const ALGORITHM = "aes-256-gcm";
|
||||
const IV_LENGTH = 12; // 96-bit IV for GCM
|
||||
const AUTH_TAG_LENGTH = 16;
|
||||
const MAGIC = Buffer.from("MDD1"); // file signature
|
||||
|
||||
export type SensitiveKey = (typeof SENSITIVE_KEYS)[number];
|
||||
|
||||
export interface EncryptedCredentials {
|
||||
salt: string;
|
||||
iv: string;
|
||||
tag: string;
|
||||
data: string;
|
||||
function deriveKey(): Buffer {
|
||||
return crypto.createHash("sha256").update(APP_KEY_MATERIAL).digest();
|
||||
}
|
||||
|
||||
const PBKDF2_ITERATIONS = 100_000;
|
||||
const KEY_LENGTH = 32; // 256 bit
|
||||
const IV_LENGTH = 12; // 96 bit for GCM
|
||||
const SALT_LENGTH = 16;
|
||||
|
||||
function deriveKey(username: string, salt: Buffer): Buffer {
|
||||
return crypto.pbkdf2Sync(username, salt, PBKDF2_ITERATIONS, KEY_LENGTH, "sha256");
|
||||
}
|
||||
|
||||
export function encryptCredentials(
|
||||
fields: Record<string, string>,
|
||||
username: string
|
||||
): EncryptedCredentials {
|
||||
const salt = crypto.randomBytes(SALT_LENGTH);
|
||||
/**
|
||||
* Encrypt a UTF-8 string into an MDD backup buffer.
|
||||
* Format: MAGIC(4) | IV(12) | AUTH_TAG(16) | CIPHERTEXT(…)
|
||||
*/
|
||||
export function encryptBackup(plaintext: string): Buffer {
|
||||
const key = deriveKey();
|
||||
const iv = crypto.randomBytes(IV_LENGTH);
|
||||
const key = deriveKey(username, salt);
|
||||
|
||||
const cipher = crypto.createCipheriv("aes-256-gcm", key, iv);
|
||||
const plaintext = JSON.stringify(fields);
|
||||
const cipher = crypto.createCipheriv(ALGORITHM, key, iv, { authTagLength: AUTH_TAG_LENGTH });
|
||||
const encrypted = Buffer.concat([cipher.update(plaintext, "utf8"), cipher.final()]);
|
||||
const tag = cipher.getAuthTag();
|
||||
|
||||
return {
|
||||
salt: salt.toString("hex"),
|
||||
iv: iv.toString("hex"),
|
||||
tag: tag.toString("hex"),
|
||||
data: encrypted.toString("hex")
|
||||
};
|
||||
const authTag = cipher.getAuthTag();
|
||||
return Buffer.concat([MAGIC, iv, authTag, encrypted]);
|
||||
}
|
||||
|
||||
export function decryptCredentials(
|
||||
encrypted: EncryptedCredentials,
|
||||
username: string
|
||||
): Record<string, string> {
|
||||
const salt = Buffer.from(encrypted.salt, "hex");
|
||||
const iv = Buffer.from(encrypted.iv, "hex");
|
||||
const tag = Buffer.from(encrypted.tag, "hex");
|
||||
const data = Buffer.from(encrypted.data, "hex");
|
||||
const key = deriveKey(username, salt);
|
||||
/**
|
||||
* Decrypt an MDD backup buffer back to a UTF-8 string.
|
||||
* Throws on invalid/corrupted data.
|
||||
*/
|
||||
export function decryptBackup(data: Buffer): string {
|
||||
if (data.length < MAGIC.length + IV_LENGTH + AUTH_TAG_LENGTH) {
|
||||
throw new Error("Backup-Datei zu kurz oder ungültig");
|
||||
}
|
||||
const magic = data.subarray(0, MAGIC.length);
|
||||
if (!magic.equals(MAGIC)) {
|
||||
throw new Error("Keine gültige MDD-Backup-Datei (falsche Signatur)");
|
||||
}
|
||||
const iv = data.subarray(MAGIC.length, MAGIC.length + IV_LENGTH);
|
||||
const authTag = data.subarray(MAGIC.length + IV_LENGTH, MAGIC.length + IV_LENGTH + AUTH_TAG_LENGTH);
|
||||
const ciphertext = data.subarray(MAGIC.length + IV_LENGTH + AUTH_TAG_LENGTH);
|
||||
|
||||
const decipher = crypto.createDecipheriv("aes-256-gcm", key, iv);
|
||||
decipher.setAuthTag(tag);
|
||||
const decrypted = Buffer.concat([decipher.update(data), decipher.final()]);
|
||||
|
||||
return JSON.parse(decrypted.toString("utf8")) as Record<string, string>;
|
||||
const key = deriveKey();
|
||||
const decipher = crypto.createDecipheriv(ALGORITHM, key, iv, { authTagLength: AUTH_TAG_LENGTH });
|
||||
decipher.setAuthTag(authTag);
|
||||
const decrypted = Buffer.concat([decipher.update(ciphertext), decipher.final()]);
|
||||
return decrypted.toString("utf8");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user