feat: Encrypt file descriptions on E2EE rooms (#5599)

This commit is contained in:
Diego Mello 2024-04-19 17:19:30 -03:00 committed by GitHub
parent 197f13654f
commit 94845cbfd2
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
9 changed files with 97 additions and 21 deletions

View File

@ -95,16 +95,21 @@ export const RecordAudio = (): ReactElement | null => {
try { try {
if (!rid) return; if (!rid) return;
setRecordingAudio(false); setRecordingAudio(false);
const fileURI = recordingRef.current?.getURI(); const fileURI = recordingRef.current?.getURI() as string;
const fileData = await getInfoAsync(fileURI as string); const fileData = await getInfoAsync(fileURI);
const fileInfo = {
if (!fileData.exists) {
return;
}
const fileInfo: IUpload = {
rid,
name: `${Date.now()}${RECORDING_EXTENSION}`, name: `${Date.now()}${RECORDING_EXTENSION}`,
mime: 'audio/aac',
type: 'audio/aac', type: 'audio/aac',
store: 'Uploads', store: 'Uploads',
path: fileURI, path: fileURI,
size: fileData.exists ? fileData.size : null size: fileData.size
} as IUpload; };
if (fileInfo) { if (fileInfo) {
if (permissionToUpload) { if (permissionToUpload) {

View File

@ -55,14 +55,14 @@ const AttachedActions = ({ attachment, getCustomEmoji }: { attachment: IAttachme
const Attachments: React.FC<IMessageAttachments> = React.memo( const Attachments: React.FC<IMessageAttachments> = React.memo(
({ attachments, timeFormat, showAttachment, style, getCustomEmoji, isReply, author }: IMessageAttachments) => { ({ attachments, timeFormat, showAttachment, style, getCustomEmoji, isReply, author }: IMessageAttachments) => {
const { translateLanguage } = useContext(MessageContext); const { translateLanguage, isEncrypted } = useContext(MessageContext);
if (!attachments || attachments.length === 0) { if (!attachments || attachments.length === 0) {
return null; return null;
} }
const attachmentsElements = attachments.map((file: IAttachment, index: number) => { const attachmentsElements = attachments.map((file: IAttachment, index: number) => {
const msg = getMessageFromAttachment(file, translateLanguage); const msg = isEncrypted ? '' : getMessageFromAttachment(file, translateLanguage);
if (file && file.image_url) { if (file && file.image_url) {
return ( return (
<Image <Image

View File

@ -428,7 +428,8 @@ class MessageContainer extends React.Component<IMessageContainerProps, IMessageC
threadBadgeColor, threadBadgeColor,
toggleFollowThread, toggleFollowThread,
replies, replies,
translateLanguage: canTranslateMessage ? autoTranslateLanguage : undefined translateLanguage: canTranslateMessage ? autoTranslateLanguage : undefined,
isEncrypted: this.isEncrypted
}} }}
> >
{/* @ts-ignore*/} {/* @ts-ignore*/}

View File

@ -1,8 +1,10 @@
import Model from '@nozbe/watermelondb/Model'; import Model from '@nozbe/watermelondb/Model';
import { E2EType, MessageType } from './IMessage';
export interface IUpload { export interface IUpload {
id?: string; id?: string;
rid?: string; rid: string;
path: string; path: string;
name?: string; name?: string;
tmid?: string; tmid?: string;
@ -14,6 +16,8 @@ export interface IUpload {
error?: boolean; error?: boolean;
subscription?: { id: string }; subscription?: { id: string };
msg?: string; msg?: string;
t?: MessageType;
e2e?: E2EType;
} }
export type TUploadModel = IUpload & Model; export type TUploadModel = IUpload & Model;

View File

@ -11,7 +11,15 @@ import log from '../methods/helpers/log';
import { store } from '../store/auxStore'; import { store } from '../store/auxStore';
import { joinVectorData, randomPassword, splitVectorData, toString, utf8ToBuffer } from './utils'; import { joinVectorData, randomPassword, splitVectorData, toString, utf8ToBuffer } from './utils';
import { EncryptionRoom } from './index'; import { EncryptionRoom } from './index';
import { IMessage, ISubscription, TMessageModel, TSubscriptionModel, TThreadMessageModel, TThreadModel } from '../../definitions'; import {
IMessage,
ISubscription,
IUpload,
TMessageModel,
TSubscriptionModel,
TThreadMessageModel,
TThreadModel
} from '../../definitions';
import { import {
E2E_BANNER_TYPE, E2E_BANNER_TYPE,
E2E_MESSAGE_TYPE, E2E_MESSAGE_TYPE,
@ -34,6 +42,7 @@ class Encryption {
handshake: Function; handshake: Function;
decrypt: Function; decrypt: Function;
encrypt: Function; encrypt: Function;
encryptUpload: Function;
importRoomKey: Function; importRoomKey: Function;
}; };
}; };
@ -275,7 +284,7 @@ class Encryption {
]; ];
toDecrypt = (await Promise.all( toDecrypt = (await Promise.all(
toDecrypt.map(async message => { toDecrypt.map(async message => {
const { t, msg, tmsg } = message; const { t, msg, tmsg, attachments } = message;
let newMessage: TMessageModel = {} as TMessageModel; let newMessage: TMessageModel = {} as TMessageModel;
if (message.subscription) { if (message.subscription) {
const { id: rid } = message.subscription; const { id: rid } = message.subscription;
@ -284,7 +293,8 @@ class Encryption {
t, t,
rid, rid,
msg: msg as string, msg: msg as string,
tmsg tmsg,
attachments
}); });
} }
@ -434,7 +444,7 @@ class Encryption {
}; };
// Encrypt a message // Encrypt a message
encryptMessage = async (message: IMessage) => { encryptMessage = async (message: IMessage | IUpload) => {
const { rid } = message; const { rid } = message;
const db = database.active; const db = database.active;
const subCollection = db.get('subscriptions'); const subCollection = db.get('subscriptions');
@ -456,6 +466,10 @@ class Encryption {
} }
const roomE2E = await this.getRoomInstance(rid); const roomE2E = await this.getRoomInstance(rid);
if ('path' in message) {
return roomE2E.encryptUpload(message);
}
return roomE2E.encrypt(message); return roomE2E.encrypt(message);
} catch { } catch {
// Subscription not found // Subscription not found
@ -467,7 +481,7 @@ class Encryption {
}; };
// Decrypt a message // Decrypt a message
decryptMessage = async (message: Pick<IMessage, 't' | 'e2e' | 'rid' | 'msg' | 'tmsg'>) => { decryptMessage = async (message: Pick<IMessage, 't' | 'e2e' | 'rid' | 'msg' | 'tmsg' | 'attachments'>) => {
const { t, e2e } = message; const { t, e2e } = message;
// Prevent create a new instance if this room was encrypted sometime ago // Prevent create a new instance if this room was encrypted sometime ago

View File

@ -5,7 +5,7 @@ import ByteBuffer from 'bytebuffer';
import parse from 'url-parse'; import parse from 'url-parse';
import getSingleMessage from '../methods/getSingleMessage'; import getSingleMessage from '../methods/getSingleMessage';
import { IMessage, IUser } from '../../definitions'; import { IMessage, IUpload, IUser } from '../../definitions';
import Deferred from './helpers/deferred'; import Deferred from './helpers/deferred';
import { debounce } from '../methods/helpers'; import { debounce } from '../methods/helpers';
import database from '../database'; import database from '../database';
@ -243,8 +243,38 @@ export default class EncryptionRoom {
return message; return message;
}; };
// Encrypt upload
encryptUpload = async (message: IUpload) => {
if (!this.ready) {
return message;
}
try {
let description = '';
if (message.description) {
description = await this.encryptText(EJSON.stringify({ text: message.description }));
}
return {
...message,
t: E2E_MESSAGE_TYPE,
e2e: E2E_STATUS.PENDING,
description
};
} catch {
// Do nothing
}
return message;
};
// Decrypt text // Decrypt text
decryptText = async (msg: string | ArrayBuffer) => { decryptText = async (msg: string | ArrayBuffer) => {
if (!msg) {
return null;
}
msg = b64ToBuffer(msg.slice(12) as string); msg = b64ToBuffer(msg.slice(12) as string);
const [vector, cipherText] = splitVectorData(msg); const [vector, cipherText] = splitVectorData(msg);
@ -275,6 +305,10 @@ export default class EncryptionRoom {
tmsg = await this.decryptText(tmsg); tmsg = await this.decryptText(tmsg);
} }
if (message.attachments?.length) {
message.attachments[0].description = await this.decryptText(message.attachments[0].description as string);
}
const decryptedMessage: IMessage = { const decryptedMessage: IMessage = {
...message, ...message,
tmsg, tmsg,

View File

@ -4,12 +4,14 @@ import isEmpty from 'lodash/isEmpty';
import { FetchBlobResponse, StatefulPromise } from 'rn-fetch-blob'; import { FetchBlobResponse, StatefulPromise } from 'rn-fetch-blob';
import { Alert } from 'react-native'; import { Alert } from 'react-native';
import { Encryption } from '../encryption';
import { IUpload, IUser, TUploadModel } from '../../definitions'; import { IUpload, IUser, TUploadModel } from '../../definitions';
import i18n from '../../i18n'; import i18n from '../../i18n';
import database from '../database'; import database from '../database';
import FileUpload from './helpers/fileUpload'; import FileUpload from './helpers/fileUpload';
import { IFileUpload } from './helpers/fileUpload/interfaces'; import { IFileUpload } from './helpers/fileUpload/interfaces';
import log from './helpers/log'; import log from './helpers/log';
import { E2E_MESSAGE_TYPE } from '../constants';
const uploadQueue: { [index: string]: StatefulPromise<FetchBlobResponse> } = {}; const uploadQueue: { [index: string]: StatefulPromise<FetchBlobResponse> } = {};
@ -85,6 +87,8 @@ export function sendFileMessage(
} }
} }
const encryptedFileInfo = await Encryption.encryptMessage(fileInfo);
const formData: IFileUpload[] = []; const formData: IFileUpload[] = [];
formData.push({ formData.push({
name: 'file', name: 'file',
@ -96,7 +100,7 @@ export function sendFileMessage(
if (fileInfo.description) { if (fileInfo.description) {
formData.push({ formData.push({
name: 'description', name: 'description',
data: fileInfo.description data: encryptedFileInfo.description
}); });
} }
@ -114,6 +118,17 @@ export function sendFileMessage(
}); });
} }
if (encryptedFileInfo.t === E2E_MESSAGE_TYPE) {
formData.push({
name: 't',
data: encryptedFileInfo.t
});
formData.push({
name: 'e2e',
data: encryptedFileInfo.e2e
});
}
const headers = { const headers = {
...RocketChatSettings.customHeaders, ...RocketChatSettings.customHeaders,
'Content-Type': 'multipart/form-data', 'Content-Type': 'multipart/form-data',

View File

@ -126,7 +126,9 @@ class ShareView extends Component<IShareViewProps, IShareViewState> {
// if is share extension show default back button // if is share extension show default back button
if (!this.isShareExtension) { if (!this.isShareExtension) {
options.headerLeft = () => <HeaderButton.CloseModal navigation={navigation} color={themes[theme].surfaceTint} testID='share-view-close' />; options.headerLeft = () => (
<HeaderButton.CloseModal navigation={navigation} color={themes[theme].surfaceTint} testID='share-view-close' />
);
} }
if (!attachments.length && !readOnly) { if (!attachments.length && !readOnly) {
@ -255,6 +257,7 @@ class ShareView extends Component<IShareViewProps, IShareViewState> {
return sendFileMessage( return sendFileMessage(
room.rid, room.rid,
{ {
rid: room.rid,
name, name,
description, description,
size, size,