aws / aws/aws-dynamodb-encryption-python

Upgrading "Do Nothing" model to one with a single action fails to decrypt old items

Abierto
#177 0 comentarios 0 reacciones 0 asignados Ver en GitHub
bug
Lenguaje dominante
Python
Estrellas
95
Forks
57
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### Problem:

According to our documentation it should always be possible to add new attributes to our model without issue: https://docs.aws.amazon.com/dynamodb-encryption-client/latest/devguide/data-model.html#add-attribute

However, if you start with data encrypted using
```
actions = AttributeActions(
default_action=CryptoAction.DO_NOTHING
)
```

And update to using
```
actions = AttributeActions(
default_action=CryptoAction.DO_NOTHING, attribute_actions={"someNewField": CryptoAction.ENCRYPT_AND_SIGN}
)
```

You run into issues. This is because data under the first model doesn't have a material description or signature written with it. Once the model is updated to include an action other than `DO_NOTHING`, it always expects there to be a material description and signature, *even if the record it's attempting to decrypt doesn't include `someNewField` yet*.

### Solution:

We should probably update the logic here to also pass through if the item under decrypt specifically doesn't have attributes where encryption or signing is needed, even if the attributeActions includes an encrypt or sign action for a non-present field.

https://github.com/aws/aws-dynamodb-encryption-python/blob/25c7c3d80bfbe0deb661b4beb86f61b8b2f8545e/src/dynamodb_encryption_sdk/encrypted/item.py#L176-L178

https://github.com/aws/aws-dynamodb-encryption-python/blob/25c7c3d80bfbe0deb661b4beb86f61b8b2f8545e/src/dynamodb_encryption_sdk/structures.py#L137-L148

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Empieza en src/dynamodb_encryption_sdk/encrypted/item.py alrededor de las líneas 176-178 y en src/dynamodb_encryption_sdk/structures.py alrededor de las líneas 137-148. Reproduce la transición de un modelo AttributeActions que solo usa DO_NOTHING a otro que añade ENCRYPT_AND_SIGN para someNewField, y luego sigue el descifrado de un elemento antiguo sin ese campo. La tarea está terminada cuando los elementos antiguos sin atributos que requieran cifrado o firma todavía puedan descifrarse con el modelo actualizado.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.