signal-desktop/ts/textsecure/ProvisioningCipher.ts

131 lines
3.7 KiB
TypeScript
Raw Normal View History

2020-10-30 20:34:04 +00:00
// Copyright 2020 Signal Messenger, LLC
// SPDX-License-Identifier: AGPL-3.0-only
/* eslint-disable more/no-then */
/* eslint-disable max-classes-per-file */
import { KeyPairType } from './Types.d';
import {
decryptAes256CbcPkcsPadding,
deriveSecrets,
bytesFromString,
verifyHmacSha256,
2021-07-02 19:21:24 +00:00
typedArrayToArrayBuffer,
} from '../Crypto';
import { calculateAgreement, createKeyPair, generateKeyPair } from '../Curve';
2021-07-02 19:21:24 +00:00
import { SignalService as Proto } from '../protobuf';
2021-07-09 19:36:10 +00:00
import { strictAssert } from '../util/assert';
import { normalizeUuid } from '../util/normalizeUuid';
2021-07-02 19:21:24 +00:00
// TODO: remove once we move away from ArrayBuffers
const FIXMEU8 = Uint8Array;
type ProvisionDecryptResult = {
identityKeyPair: KeyPairType;
number?: string;
uuid?: string;
provisioningCode?: string;
userAgent?: string;
readReceipts?: boolean;
profileKey?: ArrayBuffer;
};
class ProvisioningCipherInner {
keyPair?: KeyPairType;
async decrypt(
2021-07-02 19:21:24 +00:00
provisionEnvelope: Proto.ProvisionEnvelope
): Promise<ProvisionDecryptResult> {
2021-07-09 19:36:10 +00:00
strictAssert(
2021-07-02 19:21:24 +00:00
provisionEnvelope.publicKey && provisionEnvelope.body,
'Missing required fields in ProvisionEnvelope'
);
const masterEphemeral = provisionEnvelope.publicKey;
const message = provisionEnvelope.body;
if (new Uint8Array(message)[0] !== 1) {
throw new Error('Bad version number on ProvisioningMessage');
}
const iv = message.slice(1, 16 + 1);
const mac = message.slice(message.byteLength - 32, message.byteLength);
const ivAndCiphertext = message.slice(0, message.byteLength - 32);
const ciphertext = message.slice(16 + 1, message.byteLength - 32);
if (!this.keyPair) {
throw new Error('ProvisioningCipher.decrypt: No keypair!');
}
2021-07-02 19:21:24 +00:00
const ecRes = calculateAgreement(
typedArrayToArrayBuffer(masterEphemeral),
this.keyPair.privKey
);
const keys = deriveSecrets(
ecRes,
new ArrayBuffer(32),
bytesFromString('TextSecure Provisioning Message')
);
2021-07-02 19:21:24 +00:00
await verifyHmacSha256(
typedArrayToArrayBuffer(ivAndCiphertext),
keys[1],
typedArrayToArrayBuffer(mac),
32
);
const plaintext = await decryptAes256CbcPkcsPadding(
keys[0],
2021-07-02 19:21:24 +00:00
typedArrayToArrayBuffer(ciphertext),
typedArrayToArrayBuffer(iv)
);
2021-07-02 19:21:24 +00:00
const provisionMessage = Proto.ProvisionMessage.decode(
new FIXMEU8(plaintext)
);
2021-07-02 19:21:24 +00:00
const privKey = provisionMessage.identityKeyPrivate;
2021-07-09 19:36:10 +00:00
strictAssert(privKey, 'Missing identityKeyPrivate in ProvisionMessage');
2021-07-02 19:21:24 +00:00
const keyPair = createKeyPair(typedArrayToArrayBuffer(privKey));
2021-07-09 19:36:10 +00:00
const { uuid } = provisionMessage;
strictAssert(uuid, 'Missing uuid in provisioning message');
const ret: ProvisionDecryptResult = {
identityKeyPair: keyPair,
number: provisionMessage.number,
2021-07-09 19:36:10 +00:00
uuid: normalizeUuid(uuid, 'ProvisionMessage.uuid'),
provisioningCode: provisionMessage.provisioningCode,
userAgent: provisionMessage.userAgent,
readReceipts: provisionMessage.readReceipts,
};
if (provisionMessage.profileKey) {
2021-07-02 19:21:24 +00:00
ret.profileKey = typedArrayToArrayBuffer(provisionMessage.profileKey);
}
return ret;
}
async getPublicKey(): Promise<ArrayBuffer> {
if (!this.keyPair) {
this.keyPair = generateKeyPair();
}
if (!this.keyPair) {
throw new Error('ProvisioningCipher.decrypt: No keypair!');
}
return this.keyPair.pubKey;
}
}
export default class ProvisioningCipher {
constructor() {
const inner = new ProvisioningCipherInner();
this.decrypt = inner.decrypt.bind(inner);
this.getPublicKey = inner.getPublicKey.bind(inner);
}
decrypt: (
2021-07-02 19:21:24 +00:00
provisionEnvelope: Proto.ProvisionEnvelope
) => Promise<ProvisionDecryptResult>;
getPublicKey: () => Promise<ArrayBuffer>;
}