Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

+36 -27
View File
@@ -11,62 +11,71 @@
namespace IPS\Text;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use AesCtr;
use IPS\Settings;
use function defined;
use function function_exists;
use function in_array;
use function substr;
use const IPS\TEXT_ENCRYPTION_KEY;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* Encrypted
*/
class _Encrypt
class Encrypt
{
/**
* Get Key
*
* @return void
* @return string
*/
public static function key()
public static function key() : string
{
return \IPS\TEXT_ENCRYPTION_KEY ?: md5( \IPS\Settings::i()->sql_pass . \IPS\Settings::i()->sql_database );
return TEXT_ENCRYPTION_KEY ?: md5( Settings::i()->sql_pass . Settings::i()->sql_database );
}
/**
* @brief Cipher
*/
public $cipher;
public ?string $cipher = NULL;
/**
* @brief IV
*/
protected $iv = NULL;
protected ?string $iv = NULL;
/**
* @brief Tag
*/
protected $tag = NULL;
protected ?string $tag = NULL;
/**
* @brief Hash of cipher
*/
protected $hmac = NULL;
protected ?string $hmac = NULL;
/**
* From plaintext
*
* @param string $plaintext Plaintext
* @param string $plaintext Plaintext
* @return static
*/
public static function fromPlaintext( $plaintext )
public static function fromPlaintext( string $plaintext ): static
{
$obj = new static;
/* Try to use OpenSSL if it's available... */
if ( \function_exists( 'openssl_get_cipher_methods' ) )
if ( function_exists( 'openssl_get_cipher_methods' ) )
{
/* If GCM is available (PHP 7.1+), use that as if provides authenticated encryption natively */
if ( \in_array( 'aes-128-gcm', openssl_get_cipher_methods() ) )
if ( in_array( 'aes-128-gcm', openssl_get_cipher_methods() ) )
{
$obj->iv = openssl_random_pseudo_bytes( openssl_cipher_iv_length( 'aes-128-gcm' ) );
$obj->cipher = openssl_encrypt( $plaintext, 'aes-128-gcm', static::key(), 0, $obj->iv, $obj->tag );
@@ -74,7 +83,7 @@ class _Encrypt
}
/* Otherwise, use CBC and store the hash so we can do our own authentication when decrypting */
elseif ( \in_array( 'aes-128-cbc', openssl_get_cipher_methods() ) )
elseif ( in_array( 'aes-128-cbc', openssl_get_cipher_methods() ) )
{
$obj->iv = openssl_random_pseudo_bytes( openssl_cipher_iv_length( 'aes-128-cbc' ) );
$obj->cipher = openssl_encrypt( $plaintext, 'aes-128-cbc', static::key(), OPENSSL_RAW_DATA, $obj->iv );
@@ -85,20 +94,20 @@ class _Encrypt
/* If we're still here, fallback to the PHP library */
require_once \IPS\ROOT_PATH . '/system/3rd_party/AES/AES.php';
$obj->cipher = \AesCtr::encrypt( $plaintext, static::key(), 256 );
$obj->cipher = AesCtr::encrypt( $plaintext, static::key(), 256 );
return $obj;
}
/**
* From plaintext
*
* @param string $cipher Cipher
* @param string|null $iv The IV, or if null, will use the PHP library rather than built-in openssl_*() methods
* @param string|null $tag The tag if using AES-128-GCM
* @param string|null $hash The hash if using AES-128-CBC
* @param string $cipher Cipher
* @param string|null $iv The IV, or if null, will use the PHP library rather than built-in openssl_*() methods
* @param string|null $tag The tag if using AES-128-GCM
* @param string|null $hash The hash if using AES-128-CBC
* @return static
*/
public static function fromCipher( $cipher, $iv = NULL, $tag = NULL, $hash = NULL )
public static function fromCipher( string $cipher, string $iv = NULL, string $tag = NULL, string $hash = NULL ): static
{
$obj = new static;
$obj->cipher = $cipher;
@@ -111,10 +120,10 @@ class _Encrypt
/**
* From tag
*
* @param string $tag Tag
* @param string $tag Tag
* @return static
*/
public static function fromTag( $tag )
public static function fromTag( string $tag ): static
{
if ( preg_match( '/^\[\!AES128GCM\[(.+?)\]\[(.+?)\]\[(.+?)\]\]/', $tag, $matches ) )
{
@@ -125,7 +134,7 @@ class _Encrypt
$cipher = base64_decode( $matches[1] );
$ivLength = openssl_cipher_iv_length('aes-128-cbc');
return static::fromCipher( \substr( $cipher, $ivLength + 32 ), \substr( $cipher, 0, $ivLength ), NULL, \substr( $cipher, $ivLength, 32 ) );
return static::fromCipher( substr( $cipher, $ivLength + 32 ), substr( $cipher, 0, $ivLength ), NULL, substr( $cipher, $ivLength, 32 ) );
}
elseif ( preg_match( '/^\[\!AES\[(.+?)\]\]/', $tag, $matches ) )
{
@@ -142,7 +151,7 @@ class _Encrypt
*
* @return string
*/
public function tag()
public function tag(): string
{
if ( $this->tag )
{
@@ -157,7 +166,7 @@ class _Encrypt
return '[!AES[' . $this->cipher . ']]';
}
}
/**
* Decrypt
*
@@ -184,7 +193,7 @@ class _Encrypt
else
{
require_once \IPS\ROOT_PATH . '/system/3rd_party/AES/AES.php';
return \AesCtr::decrypt( $this->cipher, $keyToUse, 256 );
return AesCtr::decrypt( $this->cipher, $keyToUse, 256 );
}
}
}