refactor: untangle lnd's macaroon encryption with AESCipher class (#3152)
This commit is contained in:
+10
-17
@@ -12,7 +12,7 @@ import lnbits.wallets.lnd_grpc_files.lightning_pb2_grpc as lnrpc
|
||||
import lnbits.wallets.lnd_grpc_files.router_pb2 as router
|
||||
import lnbits.wallets.lnd_grpc_files.router_pb2_grpc as routerrpc
|
||||
from lnbits.settings import settings
|
||||
from lnbits.utils.crypto import AESCipher, random_secret_and_hash
|
||||
from lnbits.utils.crypto import random_secret_and_hash
|
||||
|
||||
from .base import (
|
||||
InvoiceResponse,
|
||||
@@ -72,6 +72,11 @@ class LndWallet(Wallet):
|
||||
"cannot initialize LndWallet: missing lnd_grpc_cert or lnd_cert"
|
||||
)
|
||||
|
||||
self.endpoint = self.normalize_endpoint(
|
||||
settings.lnd_grpc_endpoint, add_proto=False
|
||||
)
|
||||
self.port = int(settings.lnd_grpc_port)
|
||||
|
||||
macaroon = (
|
||||
settings.lnd_grpc_macaroon
|
||||
or settings.lnd_grpc_admin_macaroon
|
||||
@@ -80,23 +85,11 @@ class LndWallet(Wallet):
|
||||
or settings.lnd_invoice_macaroon
|
||||
)
|
||||
encrypted_macaroon = settings.lnd_grpc_macaroon_encrypted
|
||||
if encrypted_macaroon:
|
||||
macaroon = AESCipher(description="macaroon decryption").decrypt(
|
||||
encrypted_macaroon
|
||||
)
|
||||
if not macaroon:
|
||||
raise ValueError(
|
||||
"cannot initialize LndWallet: "
|
||||
"missing lnd_grpc_macaroon or lnd_grpc_admin_macaroon or "
|
||||
"lnd_admin_macaroon or lnd_grpc_invoice_macaroon or "
|
||||
"lnd_invoice_macaroon or lnd_grpc_macaroon_encrypted"
|
||||
)
|
||||
try:
|
||||
self.macaroon = load_macaroon(macaroon, encrypted_macaroon)
|
||||
except ValueError as exc:
|
||||
raise ValueError(f"cannot load macaroon for LndWallet: {exc!s}") from exc
|
||||
|
||||
self.endpoint = self.normalize_endpoint(
|
||||
settings.lnd_grpc_endpoint, add_proto=False
|
||||
)
|
||||
self.port = int(settings.lnd_grpc_port)
|
||||
self.macaroon = load_macaroon(macaroon)
|
||||
cert = open(cert_path, "rb").read()
|
||||
creds = grpc.ssl_channel_credentials(cert)
|
||||
auth_creds = grpc.metadata_call_credentials(self.metadata_callback)
|
||||
|
||||
+16
-22
@@ -9,7 +9,7 @@ from loguru import logger
|
||||
|
||||
from lnbits.nodes.lndrest import LndRestNode
|
||||
from lnbits.settings import settings
|
||||
from lnbits.utils.crypto import AESCipher, random_secret_and_hash
|
||||
from lnbits.utils.crypto import random_secret_and_hash
|
||||
|
||||
from .base import (
|
||||
InvoiceResponse,
|
||||
@@ -35,26 +35,6 @@ class LndRestWallet(Wallet):
|
||||
"cannot initialize LndRestWallet: missing lnd_rest_endpoint"
|
||||
)
|
||||
|
||||
macaroon = (
|
||||
settings.lnd_rest_macaroon
|
||||
or settings.lnd_admin_macaroon
|
||||
or settings.lnd_rest_admin_macaroon
|
||||
or settings.lnd_invoice_macaroon
|
||||
or settings.lnd_rest_invoice_macaroon
|
||||
)
|
||||
encrypted_macaroon = settings.lnd_rest_macaroon_encrypted
|
||||
if encrypted_macaroon:
|
||||
macaroon = AESCipher(description="macaroon decryption").decrypt(
|
||||
encrypted_macaroon
|
||||
)
|
||||
if not macaroon:
|
||||
raise ValueError(
|
||||
"cannot initialize LndRestWallet: "
|
||||
"missing lnd_rest_macaroon or lnd_admin_macaroon or "
|
||||
"lnd_rest_admin_macaroon or lnd_invoice_macaroon or "
|
||||
"lnd_rest_invoice_macaroon or lnd_rest_macaroon_encrypted"
|
||||
)
|
||||
|
||||
if not settings.lnd_rest_cert:
|
||||
logger.warning(
|
||||
"No certificate for LndRestWallet provided! "
|
||||
@@ -68,7 +48,21 @@ class LndRestWallet(Wallet):
|
||||
# even on startup
|
||||
cert = settings.lnd_rest_cert or True
|
||||
|
||||
macaroon = load_macaroon(macaroon)
|
||||
macaroon = (
|
||||
settings.lnd_rest_macaroon
|
||||
or settings.lnd_admin_macaroon
|
||||
or settings.lnd_rest_admin_macaroon
|
||||
or settings.lnd_invoice_macaroon
|
||||
or settings.lnd_rest_invoice_macaroon
|
||||
)
|
||||
encrypted_macaroon = settings.lnd_rest_macaroon_encrypted
|
||||
try:
|
||||
macaroon = load_macaroon(macaroon, encrypted_macaroon)
|
||||
except ValueError as exc:
|
||||
raise ValueError(
|
||||
f"cannot load macaroon for LndRestWallet: {exc!s}"
|
||||
) from exc
|
||||
|
||||
headers = {
|
||||
"Grpc-Metadata-macaroon": macaroon,
|
||||
"User-Agent": settings.user_agent,
|
||||
|
||||
@@ -1,45 +1,45 @@
|
||||
import base64
|
||||
|
||||
from loguru import logger
|
||||
from getpass import getpass
|
||||
from typing import Optional
|
||||
|
||||
from lnbits.utils.crypto import AESCipher
|
||||
|
||||
|
||||
def load_macaroon(macaroon: str) -> str:
|
||||
"""Returns hex version of a macaroon encoded in base64 or the file path.
|
||||
def load_macaroon(
|
||||
macaroon: Optional[str] = None,
|
||||
encrypted_macaroon: Optional[str] = None,
|
||||
) -> str:
|
||||
"""Returns hex version of a macaroon encoded in base64 or the file path."""
|
||||
|
||||
:param macaroon: Macaroon encoded in base64 or file path.
|
||||
:type macaroon: str
|
||||
:return: Hex version of macaroon.
|
||||
:rtype: str
|
||||
"""
|
||||
if macaroon is None and encrypted_macaroon is None:
|
||||
raise ValueError("Either macaroon or encrypted_macaroon must be provided.")
|
||||
|
||||
if encrypted_macaroon:
|
||||
# if the macaroon is encrypted, decrypt it and return the hex version
|
||||
key = getpass("Enter the macaroon decryption key: ")
|
||||
aes = AESCipher(key.encode())
|
||||
return aes.decrypt(encrypted_macaroon)
|
||||
|
||||
assert macaroon, "macaroon must be set here"
|
||||
|
||||
# if the macaroon is a file path, load it and return hex version
|
||||
if macaroon.split(".")[-1] == "macaroon":
|
||||
with open(macaroon, "rb") as f:
|
||||
macaroon_bytes = f.read()
|
||||
return macaroon_bytes.hex()
|
||||
else:
|
||||
# if macaroon is a provided string
|
||||
# check if it is hex, if so, return
|
||||
try:
|
||||
bytes.fromhex(macaroon)
|
||||
return macaroon
|
||||
except ValueError:
|
||||
pass
|
||||
# convert the bas64 macaroon to hex
|
||||
try:
|
||||
macaroon = base64.b64decode(macaroon).hex()
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
# if macaroon is a provided string check if it is hex, if so, return
|
||||
try:
|
||||
bytes.fromhex(macaroon)
|
||||
return macaroon
|
||||
except ValueError:
|
||||
pass
|
||||
|
||||
# convert the base64 macaroon to hex
|
||||
try:
|
||||
macaroon = base64.b64decode(macaroon).hex()
|
||||
return macaroon
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
return macaroon
|
||||
|
||||
|
||||
# todo: move to its own (crypto.py) file
|
||||
# if this file is executed directly, ask for a macaroon and encrypt it
|
||||
if __name__ == "__main__":
|
||||
macaroon = input("Enter macaroon: ")
|
||||
macaroon = load_macaroon(macaroon)
|
||||
macaroon = AESCipher(description="encryption").encrypt(macaroon.encode())
|
||||
logger.info("Encrypted macaroon:")
|
||||
logger.info(macaroon)
|
||||
|
||||
Reference in New Issue
Block a user