Fix cache keys and eviction of the cipher key store decorators - #207
Merged
Merged
Conversation
The cache keys used a colon, which is a reserved character in PSR-6 and PSR-16, so the decorators failed with any compliant cache like symfony/cache. Ids and subject ids are now hashed, and a cache hit is only accepted if the cached key really belongs to the requested id or subject. Removing keys also left entries behind: removeWithSubjectId() kept the cached keys by id and remove() kept the cached key by subject, so deleted personal data could still be decrypted until the cache expired. The decorators now remember the cached key ids per subject and evict all of them.
|
Hello 👋 here is the most recent benchmark result:
This comment gets update everytime a new commit comes in! |
DanielBadura
approved these changes
Sep 23, 2026
Covers the exact cache key format and removeWithSubjectId() after store(), which were not caught by the existing tests. Also drops the rememberKeyId() call in currentKeyFor(), it only caches the entry by subject, which is evicted directly anyway.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
Psr6CacheStoreDecoratorandPsr16CacheStoreDecoratorused cache keys likesubjectId:...andid:.... The colon is reserved in PSR-6 and PSR-16, so both decorators threw anInvalidArgumentExceptionwith symfony/cache. The keys are now hashed, which also avoids problems with reserved characters or long ids. A cache hit is only accepted if the cached key matches the requested id or subject, so hash collisions can't return a wrong key.Removal was incomplete as well.
removeWithSubjectId()only evicted the subject entry, but decryption goes throughget($id), so the removed keys stayed usable until the cache expired, which defeats crypto shredding.remove()had the same problem the other way around. The decorators now keep a list of cached key ids per subject and evict all related entries.The tests now run against a real symfony/cache adapter, which is added as a dev dependency.