Skip to content

Commit 7c0e3b4

Browse files
authored
Merge pull request #62666 from nextcloud/fix/encryption-settings
fix(encryption): handle decryption exception with outdated passwords
2 parents fd68589 + 890ab98 commit 7c0e3b4

2 files changed

Lines changed: 31 additions & 1 deletion

File tree

‎apps/encryption/lib/Controller/SettingsController.php‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@
1717
use OCP\AppFramework\Http\Attribute\NoAdminRequired;
1818
use OCP\AppFramework\Http\Attribute\UseSession;
1919
use OCP\AppFramework\Http\DataResponse;
20+
use OCP\Encryption\Exceptions\GenericEncryptionException;
2021
use OCP\IL10N;
2122
use OCP\IRequest;
2223
use OCP\ISession;
@@ -76,7 +77,13 @@ public function updatePrivateKeyPassword($oldPassword, $newPassword) {
7677

7778
if ($passwordCorrect !== false) {
7879
$encryptedKey = $this->keyManager->getPrivateKey($uid);
79-
$decryptedKey = $this->crypt->decryptPrivateKey($encryptedKey, $oldPassword, $uid);
80+
try {
81+
$decryptedKey = $this->crypt->decryptPrivateKey($encryptedKey, $oldPassword, $uid);
82+
} catch (GenericEncryptionException) {
83+
// A wrong passphrase does not only make decrypting return false, it can
84+
// also fail the signature check or the decryption itself
85+
$decryptedKey = false;
86+
}
8087

8188
if ($decryptedKey) {
8289
$encryptedKey = $this->crypt->encryptPrivateKey($decryptedKey, $newPassword, $uid);

‎apps/encryption/tests/Controller/SettingsControllerTest.php‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010

1111
namespace OCA\Encryption\Tests\Controller;
1212

13+
use OC\Encryption\Exceptions\DecryptionFailedException;
1314
use OCA\Encryption\Controller\SettingsController;
1415
use OCA\Encryption\Crypto\Crypt;
1516
use OCA\Encryption\KeyManager;
@@ -147,6 +148,28 @@ public function testUpdatePrivateKeyPasswordWrongOldPassword(): void {
147148
$data['message']);
148149
}
149150

151+
/**
152+
* test updatePrivateKeyPassword() if decrypting the private key with the given
153+
* old password fails with an exception instead of returning false
154+
*/
155+
public function testUpdatePrivateKeyPasswordUndecryptableKey(): void {
156+
$this->userManagerMock
157+
->expects($this->once())
158+
->method('checkPassword')
159+
->willReturn(true);
160+
161+
$this->cryptMock
162+
->expects($this->once())
163+
->method('decryptPrivateKey')
164+
->willThrowException(new DecryptionFailedException('Decryption failed'));
165+
166+
$result = $this->controller->updatePrivateKeyPassword('old', 'new');
167+
168+
$this->assertSame(Http::STATUS_BAD_REQUEST, $result->getStatus());
169+
$this->assertSame('The old password was not correct, please try again.',
170+
$result->getData()['message']);
171+
}
172+
150173
/**
151174
* test updatePrivateKeyPassword() with the correct old and new password
152175
*/

0 commit comments

Comments
 (0)