Browse Source

Used IStringEncryptionService to encrypt data

pull/4826/head
liangshiwei 6 years ago
parent
commit
1aaabc7e90
  1. 2
      framework/src/Volo.Abp.BlobStoring.Aws/Volo.Abp.BlobStoring.Aws.csproj
  2. 4
      framework/src/Volo.Abp.BlobStoring.Aws/Volo/Abp/BlobStoring/Aws/AbpBlobStoringAwsModule.cs
  3. 29
      framework/src/Volo.Abp.BlobStoring.Aws/Volo/Abp/BlobStoring/Aws/DefaultAmazonS3ClientFactory.cs

2
framework/src/Volo.Abp.BlobStoring.Aws/Volo.Abp.BlobStoring.Aws.csproj

@ -19,8 +19,6 @@
<ItemGroup>
<PackageReference Include="AWSSDK.S3" Version="3.3.111.27" />
<PackageReference Include="AWSSDK.SecurityToken" Version="3.3.105.30" />
<PackageReference Include="Microsoft.AspNetCore.DataProtection.Abstractions" Version="3.1.5" />
<PackageReference Include="Microsoft.AspNetCore.DataProtection.Extensions" Version="3.1.5" />
</ItemGroup>
</Project>

4
framework/src/Volo.Abp.BlobStoring.Aws/Volo/Abp/BlobStoring/Aws/AbpBlobStoringAwsModule.cs

@ -1,5 +1,4 @@
using Microsoft.Extensions.DependencyInjection;
using Volo.Abp.Caching;
using Volo.Abp.Caching;
using Volo.Abp.Modularity;
namespace Volo.Abp.BlobStoring.Aws
@ -10,7 +9,6 @@ namespace Volo.Abp.BlobStoring.Aws
{
public override void ConfigureServices(ServiceConfigurationContext context)
{
context.Services.AddDataProtection();
}
}
}

29
framework/src/Volo.Abp.BlobStoring.Aws/Volo/Abp/BlobStoring/Aws/DefaultAmazonS3ClientFactory.cs

@ -6,10 +6,10 @@ using Amazon.Runtime.CredentialManagement;
using Amazon.S3;
using Amazon.SecurityToken;
using Amazon.SecurityToken.Model;
using Microsoft.AspNetCore.DataProtection;
using Microsoft.Extensions.Caching.Distributed;
using Volo.Abp.Caching;
using Volo.Abp.DependencyInjection;
using Volo.Abp.Security.Encryption;
namespace Volo.Abp.BlobStoring.Aws
{
@ -17,13 +17,14 @@ namespace Volo.Abp.BlobStoring.Aws
{
protected IDistributedCache<AwsTemporaryCredentialsCacheItem> Cache { get; }
protected IDataProtector DataProtector { get; }
protected IStringEncryptionService StringEncryptionService { get; }
public DefaultAmazonS3ClientFactory(IDistributedCache<AwsTemporaryCredentialsCacheItem> cache,
IDataProtectionProvider dataProtectionProvider)
public DefaultAmazonS3ClientFactory(
IDistributedCache<AwsTemporaryCredentialsCacheItem> cache,
IStringEncryptionService stringEncryptionService)
{
Cache = cache;
DataProtector = dataProtectionProvider.CreateProtector(nameof(AwsTemporaryCredentialsCacheItem));
StringEncryptionService = stringEncryptionService;
}
public virtual async Task<AmazonS3Client> GetAmazonS3Client(
@ -114,9 +115,9 @@ namespace Volo.Abp.BlobStoring.Aws
}
var sessionCredentials = new SessionAWSCredentials(
DataProtector.Unprotect(temporaryCredentialsCache.AccessKeyId),
DataProtector.Unprotect(temporaryCredentialsCache.SecretAccessKey),
DataProtector.Unprotect(temporaryCredentialsCache.SessionToken));
StringEncryptionService.Decrypt(temporaryCredentialsCache.AccessKeyId),
StringEncryptionService.Decrypt(temporaryCredentialsCache.SecretAccessKey),
StringEncryptionService.Decrypt(temporaryCredentialsCache.SessionToken));
return sessionCredentials;
}
@ -165,9 +166,9 @@ namespace Volo.Abp.BlobStoring.Aws
}
var sessionCredentials = new SessionAWSCredentials(
DataProtector.Unprotect(temporaryCredentialsCache.AccessKeyId),
DataProtector.Unprotect(temporaryCredentialsCache.SecretAccessKey),
DataProtector.Unprotect(temporaryCredentialsCache.SessionToken));
StringEncryptionService.Decrypt(temporaryCredentialsCache.AccessKeyId),
StringEncryptionService.Decrypt(temporaryCredentialsCache.SecretAccessKey),
StringEncryptionService.Decrypt(temporaryCredentialsCache.SessionToken));
return sessionCredentials;
}
@ -176,9 +177,9 @@ namespace Volo.Abp.BlobStoring.Aws
Credentials credentials)
{
var temporaryCredentialsCache = new AwsTemporaryCredentialsCacheItem(
DataProtector.Protect(credentials.AccessKeyId),
DataProtector.Protect(credentials.SecretAccessKey),
DataProtector.Protect(credentials.SessionToken));
StringEncryptionService.Encrypt(credentials.AccessKeyId),
StringEncryptionService.Encrypt(credentials.SecretAccessKey),
StringEncryptionService.Encrypt(credentials.SessionToken));
await Cache.SetAsync(configuration.TemporaryCredentialsCacheKey, temporaryCredentialsCache,
new DistributedCacheEntryOptions

Loading…
Cancel
Save