|
1 | | -// Copyright Amazon.com Inc. or its affiliates. All Rights Reserved. |
2 | | -// SPDX-License-Identifier: Apache-2.0 |
3 | 1 | package software.amazon.encryption.s3.internal; |
4 | 2 |
|
| 3 | +import software.amazon.awssdk.protocols.jsoncore.JsonWriter; |
5 | 4 | import software.amazon.awssdk.services.s3.model.CreateMultipartUploadRequest; |
6 | 5 | import software.amazon.awssdk.services.s3.model.PutObjectRequest; |
| 6 | +import software.amazon.encryption.s3.S3EncryptionClientException; |
| 7 | +import software.amazon.encryption.s3.materials.EncryptedDataKey; |
7 | 8 | import software.amazon.encryption.s3.materials.EncryptionMaterials; |
8 | 9 |
|
9 | | -public interface ContentMetadataEncodingStrategy { |
| 10 | +import java.nio.charset.StandardCharsets; |
| 11 | +import java.util.Base64; |
| 12 | +import java.util.HashMap; |
| 13 | +import java.util.Map; |
10 | 14 |
|
11 | | - PutObjectRequest encodeMetadata(EncryptionMaterials materials, byte[] iv, PutObjectRequest putObjectRequest); |
12 | | - CreateMultipartUploadRequest encodeMetadata(EncryptionMaterials materials, byte[] iv, CreateMultipartUploadRequest createMultipartUploadRequest); |
| 15 | +public class ContentMetadataEncodingStrategy { |
13 | 16 |
|
| 17 | + private static final Base64.Encoder ENCODER = Base64.getEncoder(); |
| 18 | + private final InstructionFileConfig _instructionFileConfig; |
| 19 | + |
| 20 | + public ContentMetadataEncodingStrategy(InstructionFileConfig instructionFileConfig) { |
| 21 | + _instructionFileConfig = instructionFileConfig; |
| 22 | + } |
| 23 | + |
| 24 | + public PutObjectRequest encodeMetadata(EncryptionMaterials materials, byte[] iv, PutObjectRequest putObjectRequest) { |
| 25 | + if (_instructionFileConfig.isInstructionFilePutEnabled()) { |
| 26 | + // TODO: serialize inst file as string |
| 27 | + final String metadataString = metadataToString(materials, iv); |
| 28 | + _instructionFileConfig.putInstructionFile(putObjectRequest, ""); |
| 29 | + // the original object is returned as-is |
| 30 | + return putObjectRequest; |
| 31 | + } else { |
| 32 | + Map<String, String> newMetadata = addMetadataToMap(putObjectRequest.metadata(), materials, iv); |
| 33 | + return putObjectRequest.toBuilder() |
| 34 | + .metadata(newMetadata) |
| 35 | + .build(); |
| 36 | + } |
| 37 | + } |
| 38 | + |
| 39 | + public CreateMultipartUploadRequest encodeMetadata(EncryptionMaterials materials, byte[] iv, CreateMultipartUploadRequest createMultipartUploadRequest) { |
| 40 | + Map<String, String> newMetadata = addMetadataToMap(createMultipartUploadRequest.metadata(), materials, iv); |
| 41 | + return createMultipartUploadRequest.toBuilder() |
| 42 | + .metadata(newMetadata) |
| 43 | + .build(); |
| 44 | + } |
| 45 | + |
| 46 | + private String metadataToString(EncryptionMaterials materials, byte[] iv) { |
| 47 | + // this is just the metadata map serialized as JSON |
| 48 | + return ""; |
| 49 | + } |
| 50 | + |
| 51 | + private Map<String, String> addMetadataToMap(Map<String, String> map, EncryptionMaterials materials, byte[] iv) { |
| 52 | + Map<String, String> metadata = new HashMap<>(map); |
| 53 | + EncryptedDataKey edk = materials.encryptedDataKeys().get(0); |
| 54 | + metadata.put(MetadataKeyConstants.ENCRYPTED_DATA_KEY_V2, ENCODER.encodeToString(edk.encryptedDatakey())); |
| 55 | + metadata.put(MetadataKeyConstants.CONTENT_IV, ENCODER.encodeToString(iv)); |
| 56 | + metadata.put(MetadataKeyConstants.CONTENT_CIPHER, materials.algorithmSuite().cipherName()); |
| 57 | + metadata.put(MetadataKeyConstants.CONTENT_CIPHER_TAG_LENGTH, Integer.toString(materials.algorithmSuite().cipherTagLengthBits())); |
| 58 | + metadata.put(MetadataKeyConstants.ENCRYPTED_DATA_KEY_ALGORITHM, new String(edk.keyProviderInfo(), StandardCharsets.UTF_8)); |
| 59 | + |
| 60 | + try (JsonWriter jsonWriter = JsonWriter.create()) { |
| 61 | + jsonWriter.writeStartObject(); |
| 62 | + for (Map.Entry<String, String> entry : materials.encryptionContext().entrySet()) { |
| 63 | + jsonWriter.writeFieldName(entry.getKey()).writeValue(entry.getValue()); |
| 64 | + } |
| 65 | + jsonWriter.writeEndObject(); |
| 66 | + |
| 67 | + String jsonEncryptionContext = new String(jsonWriter.getBytes(), StandardCharsets.UTF_8); |
| 68 | + metadata.put(MetadataKeyConstants.ENCRYPTED_DATA_KEY_CONTEXT, jsonEncryptionContext); |
| 69 | + } catch (JsonWriter.JsonGenerationException e) { |
| 70 | + throw new S3EncryptionClientException("Cannot serialize encryption context to JSON.", e); |
| 71 | + } |
| 72 | + return metadata; |
| 73 | + } |
14 | 74 | } |
0 commit comments