2022-03-15 14:51:45 +00:00
|
|
|
package nosql
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"encoding/json"
|
2022-04-18 19:14:30 +00:00
|
|
|
"fmt"
|
2022-03-15 14:51:45 +00:00
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
"go.step.sm/linkedca"
|
2022-03-15 14:51:45 +00:00
|
|
|
|
|
|
|
"github.com/smallstep/certificates/authority/admin"
|
|
|
|
"github.com/smallstep/nosql"
|
|
|
|
)
|
|
|
|
|
|
|
|
type dbAuthorityPolicy struct {
|
|
|
|
ID string `json:"id"`
|
|
|
|
AuthorityID string `json:"authorityID"`
|
|
|
|
Policy *linkedca.Policy `json:"policy"`
|
|
|
|
}
|
|
|
|
|
|
|
|
func (dbap *dbAuthorityPolicy) convert() *linkedca.Policy {
|
2022-04-18 19:14:30 +00:00
|
|
|
if dbap == nil {
|
|
|
|
return nil
|
|
|
|
}
|
2022-03-15 14:51:45 +00:00
|
|
|
return dbap.Policy
|
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) getDBAuthorityPolicyBytes(ctx context.Context, authorityID string) ([]byte, error) {
|
|
|
|
data, err := db.db.Get(authorityPoliciesTable, []byte(authorityID))
|
|
|
|
if nosql.IsErrNotFound(err) {
|
2022-04-18 19:14:30 +00:00
|
|
|
return nil, admin.NewError(admin.ErrorNotFoundType, "authority policy not found")
|
2022-03-15 14:51:45 +00:00
|
|
|
} else if err != nil {
|
2022-04-18 19:14:30 +00:00
|
|
|
return nil, fmt.Errorf("error loading authority policy: %w", err)
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|
|
|
|
return data, nil
|
|
|
|
}
|
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
func (db *DB) unmarshalDBAuthorityPolicy(data []byte) (*dbAuthorityPolicy, error) {
|
|
|
|
if len(data) == 0 {
|
|
|
|
return nil, nil
|
|
|
|
}
|
2022-03-15 14:51:45 +00:00
|
|
|
var dba = new(dbAuthorityPolicy)
|
|
|
|
if err := json.Unmarshal(data, dba); err != nil {
|
2022-04-18 19:14:30 +00:00
|
|
|
return nil, fmt.Errorf("error unmarshaling policy bytes into dbAuthorityPolicy: %w", err)
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|
|
|
|
return dba, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) getDBAuthorityPolicy(ctx context.Context, authorityID string) (*dbAuthorityPolicy, error) {
|
|
|
|
data, err := db.getDBAuthorityPolicyBytes(ctx, authorityID)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2022-04-18 19:14:30 +00:00
|
|
|
dbap, err := db.unmarshalDBAuthorityPolicy(data)
|
2022-03-15 14:51:45 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2022-04-18 19:14:30 +00:00
|
|
|
if dbap == nil {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
if dbap.AuthorityID != authorityID {
|
|
|
|
return nil, admin.NewError(admin.ErrorAuthorityMismatchType,
|
|
|
|
"authority policy is not owned by authority %s", authorityID)
|
|
|
|
}
|
2022-03-15 14:51:45 +00:00
|
|
|
return dbap, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) CreateAuthorityPolicy(ctx context.Context, policy *linkedca.Policy) error {
|
|
|
|
|
|
|
|
dbap := &dbAuthorityPolicy{
|
|
|
|
ID: db.authorityID,
|
|
|
|
AuthorityID: db.authorityID,
|
|
|
|
Policy: policy,
|
|
|
|
}
|
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
if err := db.save(ctx, dbap.ID, dbap, nil, "authority_policy", authorityPoliciesTable); err != nil {
|
|
|
|
return admin.WrapErrorISE(err, "error creating authority policy")
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
return nil
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) GetAuthorityPolicy(ctx context.Context) (*linkedca.Policy, error) {
|
|
|
|
dbap, err := db.getDBAuthorityPolicy(ctx, db.authorityID)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return dbap.convert(), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) UpdateAuthorityPolicy(ctx context.Context, policy *linkedca.Policy) error {
|
|
|
|
old, err := db.getDBAuthorityPolicy(ctx, db.authorityID)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
dbap := &dbAuthorityPolicy{
|
|
|
|
ID: db.authorityID,
|
|
|
|
AuthorityID: db.authorityID,
|
|
|
|
Policy: policy,
|
|
|
|
}
|
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
if err := db.save(ctx, dbap.ID, dbap, old, "authority_policy", authorityPoliciesTable); err != nil {
|
|
|
|
return admin.WrapErrorISE(err, "error updating authority policy")
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (db *DB) DeleteAuthorityPolicy(ctx context.Context) error {
|
2022-04-18 19:14:30 +00:00
|
|
|
old, err := db.getDBAuthorityPolicy(ctx, db.authorityID)
|
2022-03-15 14:51:45 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2022-04-18 19:14:30 +00:00
|
|
|
if err := db.save(ctx, old.ID, nil, old, "authority_policy", authorityPoliciesTable); err != nil {
|
|
|
|
return admin.WrapErrorISE(err, "error deleting authority policy")
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
2022-03-15 14:51:45 +00:00
|
|
|
}
|