mirror of
https://github.com/immich-app/immich.git
synced 2026-05-18 03:10:24 +03:00
4dcc049465
* feat: plugins * feat: table definition * feat: type and migration * feat: add repositories * feat: validate manifest with class-validator and load manifest info to database * feat: workflow/plugin controller/service layer * feat: implement workflow logic * feat: make trigger static * feat: dynamical instantiate plugin instances * fix: access control and helper script * feat: it works * chore: simplify * refactor: refactor and use queue for workflow execution * refactor: remove unsused property in plugin-schema * build wasm in prod * feat: plugin loader in transaction * fix: docker build arm64 * generated files * shell check * fix tests * fix: waiting for migration to finish before loading plugin * remove context reassignment * feat: use mise to manage extism tools (#23760) * pr feedback * refactor: create workflow now including create filters and actions * feat: workflow medium tests * fix: broken medium test * feat: medium tests * chore: unify workflow job * sign user id with jwt * chore: query plugin with filters and action * chore: read manifest in repository * chore: load manifest from server configs * merge main * feat: endpoint documentation * pr feedback * load plugin from absolute path * refactor:handle trigger * throw error and return early * pr feedback * unify plugin services * fix: plugins code * clean up * remove triggerConfig * clean up * displayName and methodName --------- Co-authored-by: Jason Rasmussen <jason@rasm.me> Co-authored-by: bo0tzz <git@bo0tzz.me>
70 lines
2.1 KiB
TypeScript
70 lines
2.1 KiB
TypeScript
import { Injectable } from '@nestjs/common';
|
|
import { compareSync, hash } from 'bcrypt';
|
|
import jwt from 'jsonwebtoken';
|
|
import { createHash, createPublicKey, createVerify, randomBytes, randomUUID } from 'node:crypto';
|
|
import { createReadStream } from 'node:fs';
|
|
|
|
@Injectable()
|
|
export class CryptoRepository {
|
|
randomUUID(): string {
|
|
return randomUUID();
|
|
}
|
|
|
|
randomBytes(size: number) {
|
|
return randomBytes(size);
|
|
}
|
|
|
|
hashBcrypt(data: string | Buffer, saltOrRounds: string | number) {
|
|
return hash(data, saltOrRounds);
|
|
}
|
|
|
|
compareBcrypt(data: string | Buffer, encrypted: string) {
|
|
return compareSync(data, encrypted);
|
|
}
|
|
|
|
hashSha256(value: string) {
|
|
return createHash('sha256').update(value).digest('base64');
|
|
}
|
|
|
|
verifySha256(value: string, encryptedValue: string, publicKey: string) {
|
|
const publicKeyBuffer = Buffer.from(publicKey, 'base64');
|
|
const cryptoPublicKey = createPublicKey({
|
|
key: publicKeyBuffer,
|
|
type: 'spki',
|
|
format: 'pem',
|
|
});
|
|
|
|
const verifier = createVerify('SHA256');
|
|
verifier.update(value);
|
|
verifier.end();
|
|
const encryptedValueBuffer = Buffer.from(encryptedValue, 'base64');
|
|
return verifier.verify(cryptoPublicKey, encryptedValueBuffer);
|
|
}
|
|
|
|
hashSha1(value: string | Buffer): Buffer {
|
|
return createHash('sha1').update(value).digest();
|
|
}
|
|
|
|
hashFile(filepath: string | Buffer): Promise<Buffer> {
|
|
return new Promise<Buffer>((resolve, reject) => {
|
|
const hash = createHash('sha1');
|
|
const stream = createReadStream(filepath);
|
|
stream.on('error', (error) => reject(error));
|
|
stream.on('data', (chunk) => hash.update(chunk));
|
|
stream.on('end', () => resolve(hash.digest()));
|
|
});
|
|
}
|
|
|
|
randomBytesAsText(bytes: number) {
|
|
return randomBytes(bytes).toString('base64').replaceAll(/\W/g, '');
|
|
}
|
|
|
|
signJwt(payload: string | object | Buffer, secret: string, options?: jwt.SignOptions): string {
|
|
return jwt.sign(payload, secret, { algorithm: 'HS256', ...options });
|
|
}
|
|
|
|
verifyJwt<T = any>(token: string, secret: string): T {
|
|
return jwt.verify(token, secret, { algorithms: ['HS256'] }) as T;
|
|
}
|
|
}
|