im47cn commented on PR #6531:
URL: https://github.com/apache/shenyu/pull/6531#issuecomment-5201772672

   Thanks @Aias00 — your points on IV reuse and missing authentication were 
spot on. Rather than documenting the risk, this push closes it. All three items 
addressed:
   
   **1. CBC IV reuse (CWE-329) → resolved by switching to GCM.**
   AES and SM4 now use `AES/GCM/NoPadding` / `SM4/GCM/NoPadding` with a fresh 
96-bit `SecureRandom` nonce per message and a 128-bit tag. Output is 
`base64(nonce ‖ ciphertext ‖ tag)`, so the nonce is unique per message — no 
fixed IV to reuse. The `base64(secret):base64(iv)` key form is gone (GCM must 
never reuse a fixed IV); the key is now just `base64(secret)`, and the legacy 
`secret:iv` form is explicitly rejected with a clear error.
   
   **2. CBC malleability (CWE-1204) → resolved by GCM's authentication tag.**
   Any in-transit modification now fails decryption (`AEADBadTagException`) 
instead of silently producing corrupted plaintext. New tests assert both 
properties: `shouldEmitDifferentCiphertextForRepeatedEncrypts` (nonce 
freshness) and `shouldFailAuthenticationWhenCiphertextIsTampered` (integrity).
   
   **3. Base64 encoder/decoder asymmetry → fixed.** Unified to 
`getEncoder()`/`getDecoder()` throughout; `decrypt` now decodes UTF-8 
explicitly.
   
   **RSA — PKCS#1 v1.5 → OAEP, with a PKCS#1 fallback for your non-regression 
concern.**
   To address the padding-oracle weakness without breaking external peers that 
only speak PKCS#1 v1.5:
   - The default `rsa` strategy is now `RSA/ECB/OAEPWithSHA-256AndMGF1Padding`, 
with an explicit `OAEPParameterSpec` (MGF1 also SHA-256) so the transformation 
is identical across JDKs/providers.
   - A new **`rsa-pkcs1`** strategy keeps PKCS#1 v1.5 — any rule interoperating 
with a legacy/external PKCS#1 system can opt in by strategy name, with no code 
change and no surprise breakage.
   
   Shared RSA logic is factored into `AbstractRsaStrategy`; 
`AbstractCbcCryptorStrategy` is removed.
   
   **Note:** RSA test fixtures moved from 512-bit to 2048-bit — OAEP/SHA-256 
physically cannot encrypt any plaintext under a 512-bit key (`keyBytes − 2·32 − 
2 < 0`), so the old fixture is no longer usable. AES/SM4 round-trip tests cover 
CJK + JSON payloads.
   
   The full cryptor module suite (40 tests) is green locally (main project 
install + integrated-test test-compile both pass), including the SPI-wiring 
path you flagged earlier. Would appreciate another look when you have time.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to