aws / aws/aws-dynamodb-encryption-python
Upgrading "Do Nothing" model to one with a single action fails to decrypt old items
- Lingua principale
- Python
- Stelle
- 95
- Fork
- 57
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### Problem:
According to our documentation it should always be possible to add new attributes to our model without issue: https://docs.aws.amazon.com/dynamodb-encryption-client/latest/devguide/data-model.html#add-attribute
However, if you start with data encrypted using
```
actions = AttributeActions(
default_action=CryptoAction.DO_NOTHING
)
```
And update to using
```
actions = AttributeActions(
default_action=CryptoAction.DO_NOTHING, attribute_actions={"someNewField": CryptoAction.ENCRYPT_AND_SIGN}
)
```
You run into issues. This is because data under the first model doesn't have a material description or signature written with it. Once the model is updated to include an action other than `DO_NOTHING`, it always expects there to be a material description and signature, *even if the record it's attempting to decrypt doesn't include `someNewField` yet*.
### Solution:
We should probably update the logic here to also pass through if the item under decrypt specifically doesn't have attributes where encryption or signing is needed, even if the attributeActions includes an encrypt or sign action for a non-present field.
https://github.com/aws/aws-dynamodb-encryption-python/blob/25c7c3d80bfbe0deb661b4beb86f61b8b2f8545e/src/dynamodb_encryption_sdk/encrypted/item.py#L176-L178
https://github.com/aws/aws-dynamodb-encryption-python/blob/25c7c3d80bfbe0deb661b4beb86f61b8b2f8545e/src/dynamodb_encryption_sdk/structures.py#L137-L148
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Inizia in src/dynamodb_encryption_sdk/encrypted/item.py intorno alle righe 176-178 e in src/dynamodb_encryption_sdk/structures.py intorno alle righe 137-148. Riproduci la transizione da un modello AttributeActions che usa solo DO_NOTHING a uno che aggiunge ENCRYPT_AND_SIGN per someNewField, quindi segui la decrittografia di un elemento precedente privo di quel campo. Il lavoro è completato quando gli elementi precedenti privi di attributi che richiedono la crittografia o la firma possono ancora essere decrittografati con il modello aggiornato.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- python
- Ambito
- security
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100