2011-10-21 19:02:11 +04:00
|
|
|
<?php
|
|
|
|
|
|
|
|
/**
|
|
|
|
* ownCloud
|
|
|
|
*
|
|
|
|
* @author Robin Appelman
|
|
|
|
* @copyright 2011 Robin Appelman icewind1991@gmail.com
|
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU AFFERO GENERAL PUBLIC LICENSE
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 3 of the License, or any later version.
|
|
|
|
*
|
|
|
|
* This library is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU AFFERO GENERAL PUBLIC LICENSE for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public
|
|
|
|
* License along with this library. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* transparent encryption
|
|
|
|
*/
|
|
|
|
|
|
|
|
class OC_FileProxy_Encryption extends OC_FileProxy{
|
2011-11-24 04:44:54 +04:00
|
|
|
private static $blackList=null; //mimetypes blacklisted from encryption
|
2012-04-18 18:02:35 +04:00
|
|
|
private static $enableEncryption=null;
|
2011-11-24 04:44:54 +04:00
|
|
|
|
|
|
|
/**
|
|
|
|
* check if a file should be encrypted during write
|
|
|
|
* @param string $path
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
private static function shouldEncrypt($path){
|
2012-04-19 18:36:07 +04:00
|
|
|
if(is_null(self::$enableEncryption)){
|
|
|
|
self::$enableEncryption=(OC_Appconfig::getValue('files_encryption','enable_encryption','true')=='true');
|
2012-04-18 18:02:35 +04:00
|
|
|
}
|
2012-04-19 18:36:07 +04:00
|
|
|
if(!self::$enableEncryption){
|
2012-04-18 18:02:35 +04:00
|
|
|
return false;
|
|
|
|
}
|
2011-11-24 04:44:54 +04:00
|
|
|
if(is_null(self::$blackList)){
|
|
|
|
self::$blackList=explode(',',OC_Appconfig::getValue('files_encryption','type_blacklist','jpg,png,jpeg,avi,mpg,mpeg,mkv,mp3,oga,ogv,ogg'));
|
|
|
|
}
|
2012-02-21 23:48:14 +04:00
|
|
|
if(self::isEncrypted($path)){
|
2011-11-24 04:44:54 +04:00
|
|
|
return true;
|
|
|
|
}
|
2012-04-15 15:32:45 +04:00
|
|
|
$extension=substr($path,strrpos($path,'.')+1);
|
|
|
|
if(array_search($extension,self::$blackList)===false){
|
2011-11-24 04:44:54 +04:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* check if a file is encrypted
|
|
|
|
* @param string $path
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
private static function isEncrypted($path){
|
2012-04-25 02:10:29 +04:00
|
|
|
$metadata=OC_FileCache::getCached($path);
|
|
|
|
return isset($metadata['encrypted']) and (bool)$metadata['encrypted'];
|
2011-11-24 04:44:54 +04:00
|
|
|
}
|
|
|
|
|
2011-10-21 19:02:11 +04:00
|
|
|
public function preFile_put_contents($path,&$data){
|
2011-11-24 04:44:54 +04:00
|
|
|
if(self::shouldEncrypt($path)){
|
2012-02-15 19:23:00 +04:00
|
|
|
if (!is_resource($data)) {//stream put contents should have been converter to fopen
|
2012-02-12 18:56:32 +04:00
|
|
|
$data=OC_Crypt::blockEncrypt($data);
|
2012-02-26 18:32:45 +04:00
|
|
|
OC_FileCache::put($path,array('encrypted'=>true));
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function postFile_get_contents($path,$data){
|
2011-11-24 04:44:54 +04:00
|
|
|
if(self::isEncrypted($path)){
|
|
|
|
$data=OC_Crypt::blockDecrypt($data);
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|
2011-11-24 04:44:54 +04:00
|
|
|
return $data;
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
public function postFopen($path,&$result){
|
2011-11-24 04:44:54 +04:00
|
|
|
if(!$result){
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
$meta=stream_get_meta_data($result);
|
|
|
|
if(self::isEncrypted($path)){
|
2011-10-21 19:02:11 +04:00
|
|
|
fclose($result);
|
2011-11-24 04:44:54 +04:00
|
|
|
$result=fopen('crypt://'.$path,$meta['mode']);
|
2012-02-26 18:32:45 +04:00
|
|
|
}elseif(self::shouldEncrypt($path) and $meta['mode']!='r' and $meta['mode']!='rb'){
|
2012-02-21 23:48:14 +04:00
|
|
|
if(OC_Filesystem::file_exists($path) and OC_Filesystem::filesize($path)>0){
|
2011-11-24 04:44:54 +04:00
|
|
|
//first encrypt the target file so we don't end up with a half encrypted file
|
2012-05-01 19:38:27 +04:00
|
|
|
OCP\Util::writeLog('files_encryption','Decrypting '.$path.' before writing',OCP\Util::DEBUG);
|
2012-02-21 23:48:14 +04:00
|
|
|
$tmp=fopen('php://temp');
|
2012-04-25 02:10:29 +04:00
|
|
|
OC_Helper::streamCopy($result,$tmp);
|
2012-02-21 23:48:14 +04:00
|
|
|
fclose($result);
|
|
|
|
OC_Filesystem::file_put_contents($path,$tmp);
|
|
|
|
fclose($tmp);
|
2011-11-24 04:44:54 +04:00
|
|
|
}
|
2011-10-22 16:11:15 +04:00
|
|
|
$result=fopen('crypt://'.$path,$meta['mode']);
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|
2011-11-24 04:44:54 +04:00
|
|
|
return $result;
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|
2012-02-16 00:44:58 +04:00
|
|
|
|
|
|
|
public function postGetMimeType($path,$mime){
|
2012-02-26 18:56:47 +04:00
|
|
|
if(self::isEncrypted($path)){
|
|
|
|
$mime=OC_Helper::getMimeType('crypt://'.$path,'w');
|
2012-02-21 23:48:14 +04:00
|
|
|
}
|
2012-02-26 18:56:47 +04:00
|
|
|
return $mime;
|
2012-02-16 00:44:58 +04:00
|
|
|
}
|
2011-10-21 19:02:11 +04:00
|
|
|
}
|