-
Notifications
You must be signed in to change notification settings - Fork 367
Add error handling for invalid encryption keys with logging #4326
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
philippthun
merged 11 commits into
main
from
add-error-log-if-key-label-for-encryption-is-wrong
May 12, 2025
Merged
Add error handling for invalid encryption keys with logging #4326
philippthun
merged 11 commits into
main
from
add-error-log-if-key-label-for-encryption-is-wrong
May 12, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
- Wrapped pbkdf2_hmac in a begin-rescue block to catch encryption key errors. - Added detailed error logging for failed key derivation.
8d5472d to
f984d22
Compare
…redential_bindings/:binding_guid/details when encryption-key-label is invalid
e9932a6 to
ec88450
Compare
ad04ad7 to
047cf50
Compare
047cf50 to
3e15dbf
Compare
fbb9423 to
0613136
Compare
philippthun
reviewed
May 8, 2025
philippthun
previously approved these changes
May 9, 2025
philippthun
approved these changes
May 9, 2025
ari-wg-gitbot
added a commit
to cloudfoundry/capi-release
that referenced
this pull request
May 12, 2025
Changes in cloud_controller_ng:
- Add error handling for invalid encryption keys with logging
PR: cloudfoundry/cloud_controller_ng#4326
Author: Katharina Przybill <30441792+kathap@users.noreply.github.com>
Author: Philipp Thun <philipp.thun@sap.com>
- Fix typo in sample response JSON in API docs
PR: cloudfoundry/cloud_controller_ng#4353
Author: Rashid Rashidov <rrashidov@gmail.com>
Dependency updates in cloud_controller_ng:
- build(deps-dev): bump parallel_tests from 5.1.0 to 5.2.0
PR: cloudfoundry/cloud_controller_ng#4350
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
5 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR improves the Cloud Controller’s error handling when a key is present in the encryption_key_label database column but missing from the cloud_controller_ng.yml configuration file.
Previously, this scenario would raise a low-level Ruby error such as:
TypeError: no implicit conversion of nil into Stringwhich was unclear and did not help operators understand the root cause.
For that we introduce a global rescue for encryption and decryption failures at the controller level, ensuring that any OpenSSL::Cipher::CipherError raised during encryption or decryption is caught and turned into a
500 Internal Server Errorwith messageError while processing encrypted data.A short explanation of the proposed change:
Introduce global handling for encryption/decryption errors, converting low-level cipher failures into a clear 500 Internal Server Error response.
An explanation of the use cases your change solves
Helps operators diagnose missing or misconfigured encryption keys and gives API users a clear error response instead of an obscure Ruby exception.
Links to any other associated PRs
I have reviewed the contributing guide
I have viewed, signed, and submitted the Contributor License Agreement
I have made this pull request to the
mainbranchI have run all the unit tests using
bundle exec rakeI have run CF Acceptance Tests