A new D8 version of the dbee module not depending on the AES module is planned. It will be the v8.x-2.0 release.
Because the AES module is not supported anymore.
It will depends on the Encrypt module instead.
The D8 current status of the encrypt module is 8.x-3.0-alpha3.
I am going to wait for a encrypt module stable release before starting to work on the dbee v8.x-2.0 release.

CommentFileSizeAuthor
#13 dbee_encrypt_diagram.jpg61.64 KBthedut

Comments

thedut created an issue. See original summary.

bramdriesen’s picture

Issue summary: View changes
Ivo.Radulovski’s picture

Hello Bram,

Is there any progress here? Encrypt may take some time until stable. Is there any other solution you'd suggest for D8 to encrypt emails?

Considering to support the D8 v8.x-2.0 version as a co-maintainer.

Best,
Ivo

bramdriesen’s picture

I think development effort for this can be made, but taking into account the Encrypt module is still in Alpha, the D8 v8.x-2.0 of this module should thus also be released as an Alpha version until encrypt is stable or at least in beta.

shaxa’s picture

Hi guys, i have started working on the Alpha a couple of days ago, so if you are interested I can share my code till now and we can continue work together. Please if so open 8.x-2.0 dev branch so i can push whatever i have till now.

bramdriesen’s picture

@thedut Can you do this? :)

Ivo.Radulovski’s picture

@BramDriesen

just wrote an email to @thedut. We'll be working on the module implementing an Alpha version with Mihail (ShaxA)

I'd be good to know if there are any other ongoing development efforts here, not to duplicate / to support each other.

thedut’s picture

Hello Ivor, Bram and Shahov,

Sorry for the delay.
Thanks for your help on the dbee module v8.x-2.x !
I have just created this new git branch and now Ivor is set as co-maintener.
I think we should use code from both v.7.x-3.x and v.8.x-1.x dbee version in order to prepare the v8.x-2.x version (v7.x-3.x has a better documentation).
I will look at your commits,
Best regards

Julien

thedut’s picture

And I have just added Shahov as a co-mantener to !

shaxa’s picture

Hello guys,

I have just pushed the first draft of 8.x-2.x module. It is using the Encrypt module. Dbee is now an entity. Things which I didn't have time to finish are:
- To encrypt also the 'init' field in the user table.
- Uninstall will not work since dbee is now an entity and you must delete all entities before uninstall. We will need to think about a solution here.
- Queries with the user don't work, because now the field used by Drupal is actually 'uid' and not as before 'mail' and 'init'. Tested this on the admin view when searching for a user mail.
- Tests are not up to date.
- Also, the tab for the batch rebuild is not in place.

I think this sums up the current state. Hope that I will have some time soon again to continue work on it.

Best regards,
Mihail

thedut’s picture

Hello ShaxA,

Thanks a lot for your contribution.
I will test your code.
As a first approch, I'm not sure creating a entity is the way I would choose, because dbee module replace some values, it does not add datas to the user entity. I need to think about it.
About all queries on Mail or Init values : they will be handled by adapting the dbee_query_alter() (hook_query_alter) function.

shaxa’s picture

Hi @thedut,

I personally think entities are more reliable and then easier to integrate with everything in D8, since everything is an entity. But of course, it's good to have a discussion and maybe some pros and cons.

The bigger problem is that I spent almost the whole day trying to figure out the query alter stuff and it's not because of the _alter itself. It's because the RealAES module which is I guess one of the best now for Drupal uses Defuse crypto Library. And after spending some time on it i found that the same string will get a different encrypted value each time so the thing we were doing as to encrypt the string and try to match it won't work any more.

The guys which contribute the Crypto library are pointing to this article as a step to do our thing.
https://paragonie.com/blog/2017/05/building-searchable-encrypted-databas...

I am not sure yet, but i think this will need some extra work also on the RealAES module as well in order to make it work.

thedut’s picture

StatusFileSize
new61.64 KB

Hello,
Yes the encrypted value may or may not be the same on each encryption for the same value to encrypt :
It was always the same in the depreciated aes module and in the encrypt module with the basic method
And encrypt value always change using the Encrypt module with default or real AES method.
The dbee module is able to manage both cases.
So I don't think we need some extra developpement on the real_aes module.
I made a quick diagram of the dbee workflow regarding a database query. The real workflow is more complex because it manages mail or init values, insensitive or sensitive case, partiel search (wildcards). But this diagram help to understand the main process.
I guess the code of the 8.x-2.x version should be mostly inspired by the one from dbee 7.x-3.x version, you may find interest looking at this code.
This diagram corresponds to the v7.x-3.x version dbee version. Of course, we will need some adpatations for the v8.x-2.x version.

thedut’s picture

I have just started testing encrypt module v8.x-3.x : It requires the key module and does not provide any default encryption method.
As a start, I suggest we focus of the install script : (dbee.install file).

  1. add dependency to the encrypt module and the real_aes module, Done #19
  2. creating a key entity with name = 'dbee', provider = 'file' preferencially, or 'configuration' (db) if not available, key_type = 'encryption' and value = generating a 128bits key. Done #16 and #18
  3. Creating a encrypt profile entity, name = 'dbee', using the dbee key and the real_aes encryption method, Done #16 and #18
  4. refresh cache, if needed, to make sure those new entities are available,
  5. We need to increase the mail and init db storage size (because they will store the encrypted values), and fix the corresponding index.

Something similar as the dbee v7.x3.x version.
We could talk after this step about the way to manage datas.

thedut’s picture

About the way to retreive encrypted datas from db :

The guys which contribute the Crypto library are pointing to this article as a step to do our thing.
https://paragonie.com/blog/2017/05/building-searchable-encrypted-databas...

This is an interesting article. We should implements this feature in the future. For now, we may focus on the general stuff and consider this article as an evolution of the dbee module.
Since there is no more symetric encryption ("Deprecated Encryption Methods" section on the encrypt module page) we can, for now, eliminate the part of the diagram that query the db without decrypting all emails. As a consequence, we don't need to store anymore 2 version of the encrypted value : sensitive case and lower case. That makes the dbee module more simple to write (and yes, it will consume more CPU to !). No need the {dbee} table from dbee v8.x-1.x anymore.

About the way to store data. We need to increase the mail and init database storage lenght, and use, as you did in your dbee v8.x-2.x draft, hook_entity_presave() for encryption on both mail and init values and hook_entity_storage_load() for decrypting values.
Al always in the dbee module, we should test the encryption/decryption success before modifying stored datas, in order to make sure to preserve the original datas.
Since this core issue is not fixed yet, we still need to implement the dbee.authentication.cookie service from v8.x-1.x

  • thedut committed 9b4baf2 on 8.x-2.x
    Issue #2875664 prepare key and encrypt entities for dbee module
    
thedut’s picture

Hello,
I did and commit some stuff : creating a dbee key entity and a dbee encryption profile entity generated during install script.

  • thedut committed 3975632 on 8.x-2.x
    Issue #2875664 add namespaces
    

  • thedut committed 9b84405 on 8.x-2.x
    Issue #2875664 add real_aes dependency
    
thedut’s picture

Hello,
I have just uploaded a big commit : the adaptation for the encrypt module.
Still need some work bu it is globally fonctionnal.
Some simple tests just passed, some not !

thedut’s picture

OK, its better now : 9/10 tests are ok.
The failing test is for advanced stuff on hook_query_alter() : 12/14 tests are ok.
Still need to clean up, reformat...
Anyway this version is quite good for beta testing.

thedut’s picture

New commit : all tests pass.
Still need to improve the module, some @TODO tag, prevent from changing key...

  • thedut committed b2b2054 on 8.x-2.x
    Issue #2875664 : adaptation for encrypt, dbee way
    

  • thedut committed 5fb9cf1 on 8.x-2.x
    Issue #2875664 fix batch, hook_query_alter, tests.
    

  • thedut committed 4a14029 on 8.x-2.x
    Issue #2875664 : fix dbee_query_user
    

  • thedut committed 85fc6a9 on 8.x-2.x
    Issue #2875664 : improve tests, add dbee_disabled query tag
    
Ivo.Radulovski’s picture

Thanks @thedut for the commits! @ShaxA please have a look and support where possible!

thedut’s picture

Hello,

For your information I have made some improvements on the dbee v8.x-2.x version.
I still need to work on few things before stable version.

shaxa’s picture

@thedut you can share what's left and I will try to help you out when possible.

  • thedut committed b4e99d2 on 8.x-2.x
    Issue #2875664 by thedut : fixing Drupal coding standard.
    
thedut’s picture

Hello ShaxA,

Thank you for proposing your help !
This is the TODO list before stable version :

  • Fixing uninstall : reseting the mail index (in dbee.users) Done on #36
  • Force the encryption parameter on the dbee encryption profile edit page (admin/config/system/encryption/profiles/manage/dbee), probably using hook_form_FORM_ID_alter and an extra validate() function.
  • Fix automated test not fired on Drupal.org (not discovered, say there is no simpletest but they exists) : Help on this will be great !, Fixed in #2977112
  • Test install/uninstall with Drush (Batch operations may not be fired) Done in #2974819 issue
  • Add link to the dbee parameter page Done on #35(admin/config/system/encryption/profiles/manage/dbee) from the module page (/admin/modules)
  • Fixing documentation
  • Stuff for upgrading from previous version to v8.x-2.x
    • hook_update_N saying to rollback to the previous version, uninstall the dbee module then install and enable the v8.x-2.x
    • On automatic upgrade, prevent from uninstalling the AES module and related modules in order to not loose the old AES encryption key (so not loosing datas)
    • Some actions may be inspired from the v7.x-3.x version

    Done in #41
  • Add simpletest on changing encryption parameters (key and encrypt profile).
  • Replace depreciated functions drupal_set_message() (Done in #2981680) and db_or().

  • thedut committed ed782e4 on 8.x-2.x
    Issue #2875664 by thedut : fixing Drupal coding standard.
    

  • thedut committed 023a457 on 8.x-2.x
    Issue #2875664 by thedut : fixing Drupal coding standard.
    

  • thedut committed f4164f1 on 8.x-2.x
    Issue #2875664 by thedut : fix discover of simpletests by drupal.org
    

  • thedut committed cabb306 on 8.x-2.x
    Issue #2875664 by thedut : add configure page link on module page
    

  • thedut committed 181146c on 8.x-2.x
    Issue #2875664 by thedut : recreate mail index on unintall
    

  • thedut committed 272e059 on 8.x-2.x
    Issue #2875664 by thedut : fix discover of simpletests by drupal.org
    
voleger’s picture

Here the followup issue #2977112: Tests refactoring
And the patch with the "green" tests #2977112-4: Tests refactoring

voleger’s picture

Are there any updates? Is it possible to release first alpha of 2.x branch?

thedut’s picture

Hello,

The dev version is fonctionnal. I just want to fix :
"Stuff for upgrading from previous version to v8.x-2.x" from #31 before the first release, in order to prevent loosing datas on upgrading.

  • thedut committed 3fdcf83 on 8.x-2.x
    Issue #2875664 by thedut: prevent loosing datas from upgrading from...
thedut’s picture

Hello,
Ok I have just commited a fix for "Stuff for upgrading from previous version to v8.x-2.x".
Module seems pretty ready for alpha release.
Just waiting to move forward on current other issues.

thedut’s picture

Status: Active » Fixed
voleger’s picture

Yay! Thanks @thedut for a huge work on that release!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.