feat(security): field encryption AES-256-GCM + random IV (at-rest)
- common/crypto/crypto.util.ts: encrypt/decrypt (GCM, random 96-bit IV), format v1:base64(iv|tag|ct) - EncryptedTransformer applied to users.name + drivers.vehicle_plate (auto, no service change) - blindIndex (HMAC) helper for future searchable-field encryption (phone) - tolerant decrypt for legacy plaintext → no migration needed (varchar holds base64) - ENCRYPTION_KEY env + boot warning if unset; docs/16-encryption.md - fixes Siro's documented CBC+fixed-IV flaw Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -24,6 +24,11 @@ QUEUE_PREFIX=tripz_
|
||||
|
||||
# ---- Auth ----
|
||||
JWT_SECRET=change_me_jwt_secret
|
||||
|
||||
# ---- تشفير الحقول الحساسة at-rest (AES-256-GCM) ----
|
||||
# 32 بايت بصيغة hex (64 محرف). ولّده: openssl rand -hex 32
|
||||
# إلزامي للإنتاج — بدونه يُستخدم مفتاح تطوير غير آمن
|
||||
ENCRYPTION_KEY=
|
||||
JWT_EXPIRES=15m
|
||||
JWT_REFRESH_EXPIRES=30d
|
||||
|
||||
|
||||
Reference in New Issue
Block a user