Encrypt *plaintext_key* using the best available team key. Mirrors legacy ``share-folder``: prefer the team AES key when *prefer_aes* is set, otherwise try asymmetric keys first, then fall back to AES when no public key is available (common for enterprise teams).
(plaintext_key: bytes, team_keys,
prefer_aes: bool = False,
forbid_rsa: bool = False)
| 298 | |
| 299 | |
| 300 | def encrypt_for_team(plaintext_key: bytes, team_keys, |
| 301 | prefer_aes: bool = False, |
| 302 | forbid_rsa: bool = False) -> Tuple[bytes, int]: |
| 303 | """Encrypt *plaintext_key* using the best available team key. |
| 304 | |
| 305 | Mirrors legacy ``share-folder``: prefer the team AES key when |
| 306 | *prefer_aes* is set, otherwise try asymmetric keys first, then fall |
| 307 | back to AES when no public key is available (common for enterprise teams). |
| 308 | """ |
| 309 | aes = getattr(team_keys, 'aes', None) |
| 310 | ec_bytes = getattr(team_keys, 'ec', None) |
| 311 | rsa_bytes = getattr(team_keys, 'rsa', None) |
| 312 | |
| 313 | if prefer_aes and aes: |
| 314 | if forbid_rsa: |
| 315 | return (crypto.encrypt_aes_v2(plaintext_key, aes), |
| 316 | folder_pb2.encrypted_by_data_key_gcm) |
| 317 | return (crypto.encrypt_aes_v1(plaintext_key, aes), |
| 318 | folder_pb2.encrypted_by_data_key) |
| 319 | |
| 320 | if rsa_bytes and not forbid_rsa: |
| 321 | rsa_key = crypto.load_rsa_public_key(rsa_bytes) |
| 322 | return (crypto.encrypt_rsa(plaintext_key, rsa_key), |
| 323 | folder_pb2.encrypted_by_public_key) |
| 324 | |
| 325 | if ec_bytes: |
| 326 | ec_key = crypto.load_ec_public_key(ec_bytes) |
| 327 | return (crypto.encrypt_ec(plaintext_key, ec_key), |
| 328 | folder_pb2.encrypted_by_public_key_ecc) |
| 329 | |
| 330 | raise ValueError( |
| 331 | "No public key found for team; NSF folder sharing requires the " |
| 332 | "team's RSA or ECC public key (server requires key type 2)") |
| 333 | |
| 334 | |
| 335 | def resolve_uid_email(params, user_identifier: str) -> Tuple[Optional[bytes], str]: |
no outgoing calls