1*e7b1675dSTing-Kang Chang// Copyright 2019 Google LLC 2*e7b1675dSTing-Kang Chang// 3*e7b1675dSTing-Kang Chang// Licensed under the Apache License, Version 2.0 (the "License"); 4*e7b1675dSTing-Kang Chang// you may not use this file except in compliance with the License. 5*e7b1675dSTing-Kang Chang// You may obtain a copy of the License at 6*e7b1675dSTing-Kang Chang// 7*e7b1675dSTing-Kang Chang// http://www.apache.org/licenses/LICENSE-2.0 8*e7b1675dSTing-Kang Chang// 9*e7b1675dSTing-Kang Chang// Unless required by applicable law or agreed to in writing, software 10*e7b1675dSTing-Kang Chang// distributed under the License is distributed on an "AS IS" BASIS, 11*e7b1675dSTing-Kang Chang// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12*e7b1675dSTing-Kang Chang// See the License for the specific language governing permissions and 13*e7b1675dSTing-Kang Chang// limitations under the License. 14*e7b1675dSTing-Kang Chang// 15*e7b1675dSTing-Kang Chang//////////////////////////////////////////////////////////////////////////////// 16*e7b1675dSTing-Kang Chang 17*e7b1675dSTing-Kang Chang// Package testkeyset provides for test code methods to read or write cleartext keyset material. 18*e7b1675dSTing-Kang Changpackage testkeyset 19*e7b1675dSTing-Kang Chang 20*e7b1675dSTing-Kang Changimport ( 21*e7b1675dSTing-Kang Chang "errors" 22*e7b1675dSTing-Kang Chang 23*e7b1675dSTing-Kang Chang "github.com/google/tink/go/internal" 24*e7b1675dSTing-Kang Chang "github.com/google/tink/go/keyset" 25*e7b1675dSTing-Kang Chang tinkpb "github.com/google/tink/go/proto/tink_go_proto" 26*e7b1675dSTing-Kang Chang) 27*e7b1675dSTing-Kang Chang 28*e7b1675dSTing-Kang Changvar ( 29*e7b1675dSTing-Kang Chang keysetHandle = internal.KeysetHandle.(func(*tinkpb.Keyset, ...keyset.Option) (*keyset.Handle, error)) 30*e7b1675dSTing-Kang Chang keysetMaterial = internal.KeysetMaterial.(func(*keyset.Handle) *tinkpb.Keyset) 31*e7b1675dSTing-Kang Chang 32*e7b1675dSTing-Kang Chang errInvalidKeyset = errors.New("cleartextkeyset: invalid keyset") 33*e7b1675dSTing-Kang Chang errInvalidHandle = errors.New("cleartextkeyset: invalid handle") 34*e7b1675dSTing-Kang Chang errInvalidReader = errors.New("cleartextkeyset: invalid reader") 35*e7b1675dSTing-Kang Chang errInvalidWriter = errors.New("cleartextkeyset: invalid writer") 36*e7b1675dSTing-Kang Chang) 37*e7b1675dSTing-Kang Chang 38*e7b1675dSTing-Kang Chang// NewHandle creates a new instance of Handle using the given keyset. 39*e7b1675dSTing-Kang Changfunc NewHandle(ks *tinkpb.Keyset) (*keyset.Handle, error) { 40*e7b1675dSTing-Kang Chang if ks == nil || len(ks.Key) == 0 { 41*e7b1675dSTing-Kang Chang return nil, errInvalidKeyset 42*e7b1675dSTing-Kang Chang } 43*e7b1675dSTing-Kang Chang return keysetHandle(ks) 44*e7b1675dSTing-Kang Chang} 45*e7b1675dSTing-Kang Chang 46*e7b1675dSTing-Kang Chang// Read creates a keyset.Handle from a cleartext keyset obtained via r. 47*e7b1675dSTing-Kang Changfunc Read(r keyset.Reader) (*keyset.Handle, error) { 48*e7b1675dSTing-Kang Chang if r == nil { 49*e7b1675dSTing-Kang Chang return nil, errInvalidReader 50*e7b1675dSTing-Kang Chang } 51*e7b1675dSTing-Kang Chang ks, err := r.Read() 52*e7b1675dSTing-Kang Chang if err != nil || ks == nil || len(ks.Key) == 0 { 53*e7b1675dSTing-Kang Chang return nil, errInvalidKeyset 54*e7b1675dSTing-Kang Chang } 55*e7b1675dSTing-Kang Chang return keysetHandle(ks) 56*e7b1675dSTing-Kang Chang} 57*e7b1675dSTing-Kang Chang 58*e7b1675dSTing-Kang Chang// Write exports the keyset from h to the given writer w without encrypting it. 59*e7b1675dSTing-Kang Chang// Storing secret key material in an unencrypted fashion is dangerous. If feasible, you should use 60*e7b1675dSTing-Kang Chang// [keyset.Handle.Write] instead. 61*e7b1675dSTing-Kang Changfunc Write(h *keyset.Handle, w keyset.Writer) error { 62*e7b1675dSTing-Kang Chang if h == nil { 63*e7b1675dSTing-Kang Chang return errInvalidHandle 64*e7b1675dSTing-Kang Chang } 65*e7b1675dSTing-Kang Chang if w == nil { 66*e7b1675dSTing-Kang Chang return errInvalidWriter 67*e7b1675dSTing-Kang Chang } 68*e7b1675dSTing-Kang Chang return w.Write(KeysetMaterial(h)) 69*e7b1675dSTing-Kang Chang} 70*e7b1675dSTing-Kang Chang 71*e7b1675dSTing-Kang Chang// KeysetMaterial returns the key material contained in a keyset.Handle. 72*e7b1675dSTing-Kang Changfunc KeysetMaterial(h *keyset.Handle) *tinkpb.Keyset { 73*e7b1675dSTing-Kang Chang return keysetMaterial(h) 74*e7b1675dSTing-Kang Chang} 75*e7b1675dSTing-Kang Chang 76*e7b1675dSTing-Kang Chang// KeysetHandle creates a keyset.Handle from cleartext key material. 77*e7b1675dSTing-Kang Chang// 78*e7b1675dSTing-Kang Chang// Callers should verify that the returned *keyset.Handle isn't nil. 79*e7b1675dSTing-Kang Chang// 80*e7b1675dSTing-Kang Chang// Deprecated: Use [NewHandle]. 81*e7b1675dSTing-Kang Changfunc KeysetHandle(ks *tinkpb.Keyset) *keyset.Handle { 82*e7b1675dSTing-Kang Chang kh, err := keysetHandle(ks) 83*e7b1675dSTing-Kang Chang if err != nil { 84*e7b1675dSTing-Kang Chang // This *keyset.Handle can only return errors when *keyset.Option arguments 85*e7b1675dSTing-Kang Chang // are provided. To maintain backwards compatibility and avoid panic, it returns 86*e7b1675dSTing-Kang Chang // a nil value if an error happens. 87*e7b1675dSTing-Kang Chang return nil 88*e7b1675dSTing-Kang Chang } 89*e7b1675dSTing-Kang Chang return kh 90*e7b1675dSTing-Kang Chang} 91