Closed (fixed)
Project:
DataBase Email Encryption
Version:
8.x-1.0
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Reporter:
Created:
4 May 2017 at 11:15 UTC
Updated:
27 Sep 2018 at 12:54 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
bramdriesenComment #3
Ivo.Radulovski commentedHello Bram,
Is there any progress here? Encrypt may take some time until stable. Is there any other solution you'd suggest for D8 to encrypt emails?
Considering to support the D8 v8.x-2.0 version as a co-maintainer.
Best,
Ivo
Comment #4
bramdriesenI think development effort for this can be made, but taking into account the Encrypt module is still in Alpha, the D8 v8.x-2.0 of this module should thus also be released as an Alpha version until encrypt is stable or at least in beta.
Comment #5
shaxa commentedHi guys, i have started working on the Alpha a couple of days ago, so if you are interested I can share my code till now and we can continue work together. Please if so open 8.x-2.0 dev branch so i can push whatever i have till now.
Comment #6
bramdriesen@thedut Can you do this? :)
Comment #7
Ivo.Radulovski commented@BramDriesen
just wrote an email to @thedut. We'll be working on the module implementing an Alpha version with Mihail (ShaxA)
I'd be good to know if there are any other ongoing development efforts here, not to duplicate / to support each other.
Comment #8
thedut commentedHello Ivor, Bram and Shahov,
Sorry for the delay.
Thanks for your help on the dbee module v8.x-2.x !
I have just created this new git branch and now Ivor is set as co-maintener.
I think we should use code from both v.7.x-3.x and v.8.x-1.x dbee version in order to prepare the v8.x-2.x version (v7.x-3.x has a better documentation).
I will look at your commits,
Best regards
Julien
Comment #9
thedut commentedAnd I have just added Shahov as a co-mantener to !
Comment #10
shaxa commentedHello guys,
I have just pushed the first draft of 8.x-2.x module. It is using the Encrypt module. Dbee is now an entity. Things which I didn't have time to finish are:
- To encrypt also the 'init' field in the user table.
- Uninstall will not work since dbee is now an entity and you must delete all entities before uninstall. We will need to think about a solution here.
- Queries with the user don't work, because now the field used by Drupal is actually 'uid' and not as before 'mail' and 'init'. Tested this on the admin view when searching for a user mail.
- Tests are not up to date.
- Also, the tab for the batch rebuild is not in place.
I think this sums up the current state. Hope that I will have some time soon again to continue work on it.
Best regards,
Mihail
Comment #11
thedut commentedHello ShaxA,
Thanks a lot for your contribution.
I will test your code.
As a first approch, I'm not sure creating a entity is the way I would choose, because dbee module replace some values, it does not add datas to the user entity. I need to think about it.
About all queries on Mail or Init values : they will be handled by adapting the dbee_query_alter() (hook_query_alter) function.
Comment #12
shaxa commentedHi @thedut,
I personally think entities are more reliable and then easier to integrate with everything in D8, since everything is an entity. But of course, it's good to have a discussion and maybe some pros and cons.
The bigger problem is that I spent almost the whole day trying to figure out the query alter stuff and it's not because of the _alter itself. It's because the RealAES module which is I guess one of the best now for Drupal uses Defuse crypto Library. And after spending some time on it i found that the same string will get a different encrypted value each time so the thing we were doing as to encrypt the string and try to match it won't work any more.
The guys which contribute the Crypto library are pointing to this article as a step to do our thing.
https://paragonie.com/blog/2017/05/building-searchable-encrypted-databas...
I am not sure yet, but i think this will need some extra work also on the RealAES module as well in order to make it work.
Comment #13
thedut commentedHello,
Yes the encrypted value may or may not be the same on each encryption for the same value to encrypt :
It was always the same in the depreciated aes module and in the encrypt module with the basic method
And encrypt value always change using the Encrypt module with default or real AES method.
The dbee module is able to manage both cases.
So I don't think we need some extra developpement on the real_aes module.
I made a quick diagram of the dbee workflow regarding a database query. The real workflow is more complex because it manages mail or init values, insensitive or sensitive case, partiel search (wildcards). But this diagram help to understand the main process.
I guess the code of the 8.x-2.x version should be mostly inspired by the one from dbee 7.x-3.x version, you may find interest looking at this code.
This diagram corresponds to the v7.x-3.x version dbee version. Of course, we will need some adpatations for the v8.x-2.x version.
Comment #14
thedut commentedI have just started testing encrypt module v8.x-3.x : It requires the key module and does not provide any default encryption method.
As a start, I suggest we focus of the install script : (dbee.install file).
add dependency to the encrypt module and the real_aes module,Done #19creating a key entity with name = 'dbee', provider = 'file' preferencially, or 'configuration' (db) if not available, key_type = 'encryption' and value = generating a 128bits key.Done #16 and #18Creating a encrypt profile entity, name = 'dbee', using the dbee key and the real_aes encryption method,Done #16 and #18refresh cache, if needed, to make sure those new entities are available,We need to increase the mail and init db storage size (because they will store the encrypted values), and fix the corresponding index.Something similar as the dbee v7.x3.x version.
We could talk after this step about the way to manage datas.
Comment #15
thedut commentedAbout the way to retreive encrypted datas from db :
This is an interesting article. We should implements this feature in the future. For now, we may focus on the general stuff and consider this article as an evolution of the dbee module.
Since there is no more symetric encryption ("Deprecated Encryption Methods" section on the encrypt module page) we can, for now, eliminate the part of the diagram that query the db without decrypting all emails. As a consequence, we don't need to store anymore 2 version of the encrypted value : sensitive case and lower case. That makes the dbee module more simple to write (and yes, it will consume more CPU to !). No need the {dbee} table from dbee v8.x-1.x anymore.
About the way to store data. We need to increase the mail and init database storage lenght, and use, as you did in your dbee v8.x-2.x draft, hook_entity_presave() for encryption on both mail and init values and hook_entity_storage_load() for decrypting values.
Al always in the dbee module, we should test the encryption/decryption success before modifying stored datas, in order to make sure to preserve the original datas.
Since this core issue is not fixed yet, we still need to implement the dbee.authentication.cookie service from v8.x-1.x
Comment #17
thedut commentedHello,
I did and commit some stuff : creating a dbee key entity and a dbee encryption profile entity generated during install script.
Comment #20
thedut commentedHello,
I have just uploaded a big commit : the adaptation for the encrypt module.
Still need some work bu it is globally fonctionnal.
Some simple tests just passed, some not !
Comment #21
thedut commentedOK, its better now : 9/10 tests are ok.
The failing test is for advanced stuff on hook_query_alter() : 12/14 tests are ok.
Still need to clean up, reformat...
Anyway this version is quite good for beta testing.
Comment #22
thedut commentedNew commit : all tests pass.
Still need to improve the module, some @TODO tag, prevent from changing key...
Comment #27
Ivo.Radulovski commentedThanks @thedut for the commits! @ShaxA please have a look and support where possible!
Comment #28
thedut commentedHello,
For your information I have made some improvements on the dbee v8.x-2.x version.
I still need to work on few things before stable version.
Comment #29
shaxa commented@thedut you can share what's left and I will try to help you out when possible.
Comment #31
thedut commentedHello ShaxA,
Thank you for proposing your help !
This is the TODO list before stable version :
Fixing uninstall : reseting the mail index (in dbee.users)Done on #36Fix automated test not fired on Drupal.org (not discovered, say there is no simpletest but they exists) : Help on this will be great !, Fixed in #2977112Test install/uninstall with Drush (Batch operations may not be fired)Done in #2974819 issueAdd link to the dbee parameter pageDone on #35(admin/config/system/encryption/profiles/manage/dbee) from the module page (/admin/modules)Stuff for upgrading from previous version to v8.x-2.x- hook_update_N saying to rollback to the previous version, uninstall the dbee module then install and enable the v8.x-2.x
- On automatic upgrade, prevent from uninstalling the AES module and related modules in order to not loose the old AES encryption key (so not loosing datas)
- Some actions may be inspired from the v7.x-3.x version
Done in #41drupal_set_message()(Done in #2981680) and db_or().Comment #38
volegerHere the followup issue #2977112: Tests refactoring
And the patch with the "green" tests #2977112-4: Tests refactoring
Comment #39
volegerAre there any updates? Is it possible to release first alpha of 2.x branch?
Comment #40
thedut commentedHello,
The dev version is fonctionnal. I just want to fix :
"Stuff for upgrading from previous version to v8.x-2.x" from #31 before the first release, in order to prevent loosing datas on upgrading.
Comment #42
thedut commentedHello,
Ok I have just commited a fix for "Stuff for upgrading from previous version to v8.x-2.x".
Module seems pretty ready for alpha release.
Just waiting to move forward on current other issues.
Comment #43
thedut commentedok, ready for beta1 !
Comment #44
volegerYay! Thanks @thedut for a huge work on that release!