Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MOTOR-689: Add async wrapper for pymongo.encryption.ClientEncryption #103

Merged
merged 44 commits into from
Mar 31, 2021
Merged
Show file tree
Hide file tree
Changes from 6 commits
Commits
Show all changes
44 commits
Select commit Hold shift + click to select a range
ee7b490
added wrapper for Asyncio explicit encryption
guanlinzhou Mar 25, 2021
e252b38
add docs
guanlinzhou Mar 25, 2021
8fed6c1
syntax mistake
guanlinzhou Mar 25, 2021
1ef5c2a
add docstring
guanlinzhou Mar 25, 2021
3e11eb7
add tornado support
guanlinzhou Mar 25, 2021
dea8025
shorten docstring
guanlinzhou Mar 25, 2021
9a60728
expose close api
guanlinzhou Mar 26, 2021
75d2fdc
checkout
guanlinzhou Mar 29, 2021
9a58140
checkout
guanlinzhou Mar 29, 2021
a3575c0
get tests working
guanlinzhou Mar 29, 2021
bf05409
remove .eggs
guanlinzhou Mar 29, 2021
13f4cdb
newline
guanlinzhou Mar 29, 2021
4254aae
eof
guanlinzhou Mar 29, 2021
efddbe8
eof
guanlinzhou Mar 29, 2021
d3a73ab
cleanup calls back
guanlinzhou Mar 29, 2021
0c0e70b
cleanup calls back
guanlinzhou Mar 29, 2021
c6c7edd
updated travis config for installing pymongocrypt
guanlinzhou Mar 29, 2021
7f9b84a
add setup
guanlinzhou Mar 29, 2021
aea3442
augment evergreen testing
guanlinzhou Mar 29, 2021
0b2ca3b
fix config
guanlinzhou Mar 29, 2021
05050b1
fix test script
guanlinzhou Mar 30, 2021
180509b
virtualenv eg
guanlinzhou Mar 30, 2021
68bc359
fix
guanlinzhou Mar 30, 2021
b4849e0
fix python binary
guanlinzhou Mar 30, 2021
f2615ed
replace with pip install
guanlinzhou Mar 30, 2021
bb4cbe8
test if extra commands are needed
guanlinzhou Mar 30, 2021
310ff1c
test fix
guanlinzhou Mar 30, 2021
bcff10c
use createvenv
guanlinzhou Mar 30, 2021
29b0880
fix
guanlinzhou Mar 30, 2021
e0337ca
add testing lines
guanlinzhou Mar 30, 2021
d569bd0
install through tox
guanlinzhou Mar 30, 2021
ef043bb
restore dsi files
guanlinzhou Mar 30, 2021
e093948
replace config.yml
guanlinzhou Mar 30, 2021
64f68d7
remove extra newline
guanlinzhou Mar 30, 2021
a9b976b
nits
guanlinzhou Mar 30, 2021
7011887
Merge branch 'master' of github.com:mongodb/motor into PYTHON-689
guanlinzhou Mar 30, 2021
c4e81a3
update installation info
guanlinzhou Mar 30, 2021
9a03574
link to pymongocrypt
guanlinzhou Mar 30, 2021
171becc
single source python dependency
guanlinzhou Mar 31, 2021
26cf82f
extra
guanlinzhou Mar 31, 2021
81f87cd
revert changes
guanlinzhou Mar 31, 2021
3f5f880
fix failure with setUp
guanlinzhou Mar 31, 2021
87e711f
fix failure with setUp
guanlinzhou Mar 31, 2021
8f6026e
update older pip version
guanlinzhou Mar 31, 2021
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
7 changes: 7 additions & 0 deletions doc/api-asyncio/asyncio_motor_client_encryption.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
:class:`~motor.motor_asyncio.AsyncIOMotorClientEncryption`
==========================================================

.. currentmodule:: motor.motor_asyncio

.. autoclass:: AsyncIOMotorClientEncryption
:members:
1 change: 1 addition & 0 deletions doc/api-asyncio/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ Motor asyncio API
asyncio_motor_database
asyncio_motor_collection
asyncio_motor_change_stream
asyncio_motor_client_encryption
cursors
asyncio_gridfs
aiohttp
Expand Down
1 change: 1 addition & 0 deletions doc/api-tornado/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ Motor Tornado API
motor_database
motor_collection
motor_change_stream
motor_client_encryption
cursors
gridfs
web
Expand Down
7 changes: 7 additions & 0 deletions doc/api-tornado/motor_client_encryption.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
:class:`~motor.motor_tornado.MotorClientEncryption`
===================================================

.. currentmodule:: motor.motor_tornado

.. autoclass:: MotorClientEncryption
:members:
39 changes: 39 additions & 0 deletions motor/core.py
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@
from pymongo.cursor import Cursor, RawBatchCursor, _QUERY_OPTIONS
from pymongo.database import Database
from pymongo.driver_info import DriverInfo
from pymongo.encryption import ClientEncryption

from . import version as motor_version
from .metaprogramming import (AsyncCommand,
Expand Down Expand Up @@ -1795,3 +1796,41 @@ def __enter__(self):

def __exit__(self, exc_type, exc_val, exc_tb):
pass

class AgnosticClientEncryption(AgnosticBase):
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
__motor_class_name__ = 'MotorClientEncryption'
__delegate_class__ = ClientEncryption

create_data_key = AsyncCommand(doc=create_data_key_doc)
encrypt = AsyncCommand()
decrypt = AsyncCommand()

_close = AsyncCommand(attr_name='close')
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved

def __init__(self, kms_providers, key_vault_namespace, key_vault_client, codec_options, io_loop=None):
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
"""Explicit client-side field level encryption.

Takes the same constructor arguments as
:class:`pymongo.encryption.ClientEncryption`, as well as:

:Parameters:
- `io_loop` (optional): Special event loop
instance to use instead of default
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
"""
if io_loop:
self._framework.check_event_loop(io_loop)
else:
io_loop = self._framework.get_event_loop()
delegate = self.__delegate_class__(kms_providers, key_vault_namespace, key_vault_client, codec_options)
super().__init__(delegate)
self.io_loop = io_loop

def get_io_loop(self):
return self.io_loop

async def __aenter__(self):
return self

async def __aexit__(self, exc_type, exc_val, exc_tb):
if self.delegate:
await self._close()
56 changes: 56 additions & 0 deletions motor/docstrings.py
Original file line number Diff line number Diff line change
Expand Up @@ -1268,3 +1268,59 @@ async def coro():
.. _$expr: https://docs.mongodb.com/manual/reference/operator/query/expr/
.. _$where: https://docs.mongodb.com/manual/reference/operator/query/where/
"""

create_data_key_doc = """Create and insert a new data key into the key vault collection.

:Parameters:
- `kms_provider`: The KMS provider to use. Supported values are
"aws" and "local".
- `master_key`: Identifies a KMS-specific key used to encrypt the
new data key. If the kmsProvider is "local" the `master_key` is
not applicable and may be omitted.

If the `kms_provider` is "aws" it is required and has the
following fields::

- `region` (string): Required. The AWS region, e.g. "us-east-1".
- `key` (string): Required. The Amazon Resource Name (ARN) to
the AWS customer.
- `endpoint` (string): Optional. An alternate host to send KMS
requests to. May include port number, e.g.
"kms.us-east-1.amazonaws.com:443".

If the `kms_provider` is "azure" it is required and has the
following fields::

- `keyVaultEndpoint` (string): Required. Host with optional
port, e.g. "example.vault.azure.net".
- `keyName` (string): Required. Key name in the key vault.
- `keyVersion` (string): Optional. Version of the key to use.

If the `kms_provider` is "gcp" it is required and has the
following fields::

- `projectId` (string): Required. The Google cloud project ID.
- `location` (string): Required. The GCP location, e.g. "us-east1".
- `keyRing` (string): Required. Name of the key ring that contains
the key to use.
- `keyName` (string): Required. Name of the key to use.
- `keyVersion` (string): Optional. Version of the key to use.
- `endpoint` (string): Optional. Host with optional port.
Defaults to "cloudkms.googleapis.com".

- `key_alt_names` (optional): An optional list of string alternate
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
names used to reference a key. If a key is created with alternate
names, then encryption may refer to the key by the unique alternate
name instead of by ``key_id``. The following example shows creating
and referring to a data key by alternate name::

await client_encryption.create_data_key("local", keyAltNames=["name1"])
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
# reference the key with the alternate name
await client_encryption.encrypt("457-55-5462", keyAltName="name1",
algorithm=Algorithm.Random)
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved

:Returns:
The ``_id`` of the created data key document as a
:class:`~bson.binary.Binary` with subtype
:data:`~bson.binary.UUID_SUBTYPE`.
"""
6 changes: 5 additions & 1 deletion motor/motor_asyncio.py
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
from .frameworks import asyncio as asyncio_framework
guanlinzhou marked this conversation as resolved.
Show resolved Hide resolved
from .metaprogramming import create_class_with_framework

__all__ = ['AsyncIOMotorClient']
__all__ = ['AsyncIOMotorClient','AsyncIOMotorClientEncryption']


def create_asyncio_class(cls):
Expand Down Expand Up @@ -70,3 +70,7 @@ def create_asyncio_class(cls):

AsyncIOMotorGridOutCursor = create_asyncio_class(
motor_gridfs.AgnosticGridOutCursor)


AsyncIOMotorClientEncryption = create_asyncio_class(
core.AgnosticClientEncryption)
5 changes: 4 additions & 1 deletion motor/motor_tornado.py
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
from .frameworks import tornado as tornado_framework
from .metaprogramming import create_class_with_framework

__all__ = ['MotorClient']
__all__ = ['MotorClient', 'MotorClientEncryption']


def create_motor_class(cls):
Expand Down Expand Up @@ -60,3 +60,6 @@ def create_motor_class(cls):


MotorGridOutCursor = create_motor_class(motor_gridfs.AgnosticGridOutCursor)


MotorClientEncryption = create_motor_class(core.AgnosticClientEncryption)