certificates/authority/admin/api/acme.go

207 lines
6.2 KiB
Go
Raw Normal View History

2021-07-23 13:41:24 +00:00
package api
import (
2021-09-16 21:09:24 +00:00
"context"
2021-07-23 13:41:24 +00:00
"net/http"
2021-08-27 12:10:00 +00:00
"github.com/go-chi/chi"
"github.com/smallstep/certificates/acme"
2021-07-23 13:41:24 +00:00
"github.com/smallstep/certificates/api"
"github.com/smallstep/certificates/authority/admin"
2021-09-16 21:09:24 +00:00
"github.com/smallstep/certificates/authority/provisioner"
"go.step.sm/linkedca"
2021-08-27 14:58:04 +00:00
"google.golang.org/protobuf/types/known/timestamppb"
2021-07-23 13:41:24 +00:00
)
// CreateExternalAccountKeyRequest is the type for POST /admin/acme/eab requests
type CreateExternalAccountKeyRequest struct {
2021-09-16 21:09:24 +00:00
Provisioner string `json:"provisioner"`
Reference string `json:"reference"`
2021-07-23 13:41:24 +00:00
}
2021-09-16 21:09:24 +00:00
// Validate validates a new ACME EAB Key request body.
func (r *CreateExternalAccountKeyRequest) Validate() error {
2021-09-16 21:09:24 +00:00
if r.Provisioner == "" {
return admin.NewError(admin.ErrorBadRequestType, "provisioner name cannot be empty")
}
return nil
2021-07-23 13:41:24 +00:00
}
// GetExternalAccountKeysResponse is the type for GET /admin/acme/eab responses
type GetExternalAccountKeysResponse struct {
EAKs []*linkedca.EABKey `json:"eaks"`
NextCursor string `json:"nextCursor"`
2021-07-23 13:41:24 +00:00
}
2021-09-16 21:09:24 +00:00
// provisionerHasEABEnabled determines if the "requireEAB" setting for an ACME
// provisioner is set to true and thus has EAB enabled.
// TODO: rewrite this into a middleware for the ACME handlers? This probably requires
// ensuring that all the ACME EAB APIs that need the middleware work the same in terms
// of specifying the provisioner; probably a bit of refactoring required.
func (h *Handler) provisionerHasEABEnabled(ctx context.Context, provisionerName string) (bool, error) {
var (
p provisioner.Interface
err error
)
if p, err = h.auth.LoadProvisionerByName(provisionerName); err != nil {
return false, admin.WrapErrorISE(err, "error loading provisioner %s", provisionerName)
}
prov, err := h.db.GetProvisioner(ctx, p.GetID())
if err != nil {
return false, admin.WrapErrorISE(err, "error getting provisioner with ID: %s", p.GetID())
}
details := prov.GetDetails()
if details == nil {
return false, admin.NewErrorISE("error getting details for provisioner with ID: %s", p.GetID())
}
acme := details.GetACME()
if acme == nil {
return false, admin.NewErrorISE("error getting ACME details for provisioner with ID: %s", p.GetID())
}
return acme.GetRequireEab(), nil
}
2021-07-23 13:41:24 +00:00
// CreateExternalAccountKey creates a new External Account Binding key
func (h *Handler) CreateExternalAccountKey(w http.ResponseWriter, r *http.Request) {
var body CreateExternalAccountKeyRequest
2021-08-27 14:58:04 +00:00
if err := api.ReadJSON(r.Body, &body); err != nil {
api.WriteError(w, admin.WrapError(admin.ErrorBadRequestType, err, "error reading request body"))
2021-07-23 13:41:24 +00:00
return
}
if err := body.Validate(); err != nil {
api.WriteError(w, err)
return
}
2021-07-23 13:41:24 +00:00
provisioner := body.Provisioner
reference := body.Reference
eabEnabled, err := h.provisionerHasEABEnabled(r.Context(), provisioner)
2021-09-16 21:09:24 +00:00
if err != nil {
api.WriteError(w, err)
return
}
if !eabEnabled {
api.WriteError(w, admin.NewError(admin.ErrorBadRequestType, "ACME EAB not enabled for provisioner %s", provisioner))
2021-09-16 21:09:24 +00:00
return
}
if reference != "" {
k, err := h.acmeDB.GetExternalAccountKeyByReference(r.Context(), provisioner, reference)
if err == nil || k != nil {
err := admin.NewError(admin.ErrorBadRequestType, "an ACME EAB key for provisioner %s with reference %s already exists", provisioner, reference)
err.Status = 409
api.WriteError(w, err)
return
}
}
eak, err := h.acmeDB.CreateExternalAccountKey(r.Context(), provisioner, reference)
2021-07-23 13:41:24 +00:00
if err != nil {
api.WriteError(w, admin.WrapErrorISE(err, "error creating ACME EAB key for provisioner %s and reference %s", provisioner, reference))
2021-07-23 13:41:24 +00:00
return
}
response := &linkedca.EABKey{
2021-09-16 21:09:24 +00:00
Id: eak.ID,
HmacKey: eak.KeyBytes,
Provisioner: eak.Provisioner,
Reference: eak.Reference,
2021-07-23 13:41:24 +00:00
}
api.ProtoJSONStatus(w, response, http.StatusCreated)
2021-07-23 13:41:24 +00:00
}
2021-08-27 12:10:00 +00:00
// DeleteExternalAccountKey deletes an ACME External Account Key.
func (h *Handler) DeleteExternalAccountKey(w http.ResponseWriter, r *http.Request) {
provisioner := chi.URLParam(r, "prov")
keyID := chi.URLParam(r, "id")
2021-08-27 12:10:00 +00:00
eabEnabled, err := h.provisionerHasEABEnabled(r.Context(), provisioner)
if err != nil {
api.WriteError(w, err)
return
}
if !eabEnabled {
api.WriteError(w, admin.NewError(admin.ErrorBadRequestType, "ACME EAB not enabled for provisioner %s", provisioner))
return
}
2021-09-16 21:09:24 +00:00
if err := h.acmeDB.DeleteExternalAccountKey(r.Context(), provisioner, keyID); err != nil {
api.WriteError(w, admin.WrapErrorISE(err, "error deleting ACME EAB Key %s", keyID))
2021-08-27 12:10:00 +00:00
return
}
api.JSON(w, &DeleteResponse{Status: "ok"})
}
2021-07-23 13:41:24 +00:00
// GetExternalAccountKeys returns a segment of ACME EAB Keys.
func (h *Handler) GetExternalAccountKeys(w http.ResponseWriter, r *http.Request) {
2021-08-27 14:58:04 +00:00
prov := chi.URLParam(r, "prov")
reference := chi.URLParam(r, "ref")
2021-08-27 14:58:04 +00:00
2021-09-16 21:09:24 +00:00
eabEnabled, err := h.provisionerHasEABEnabled(r.Context(), prov)
if err != nil {
api.WriteError(w, err)
return
}
if !eabEnabled {
api.WriteError(w, admin.NewError(admin.ErrorBadRequestType, "ACME EAB not enabled for provisioner %s", prov))
return
}
2021-08-27 14:58:04 +00:00
// TODO: support paging properly? It'll probably leak to the DB layer, as we have to loop through all keys
2021-07-23 13:41:24 +00:00
// cursor, limit, err := api.ParseCursor(r)
// if err != nil {
// api.WriteError(w, admin.WrapError(admin.ErrorBadRequestType, err,
// "error parsing cursor and limit from query params"))
// return
// }
var (
key *acme.ExternalAccountKey
keys []*acme.ExternalAccountKey
)
if reference != "" {
key, err = h.acmeDB.GetExternalAccountKeyByReference(r.Context(), prov, reference)
if err != nil {
api.WriteError(w, admin.WrapErrorISE(err, "error getting external account key with reference %s", reference))
return
}
keys = []*acme.ExternalAccountKey{key}
} else {
keys, err = h.acmeDB.GetExternalAccountKeys(r.Context(), prov)
if err != nil {
api.WriteError(w, admin.WrapErrorISE(err, "error getting external account keys"))
return
}
2021-08-27 14:58:04 +00:00
}
eaks := make([]*linkedca.EABKey, len(keys))
for i, k := range keys {
eaks[i] = &linkedca.EABKey{
2021-09-16 21:09:24 +00:00
Id: k.ID,
HmacKey: []byte{},
Provisioner: k.Provisioner,
Reference: k.Reference,
Account: k.AccountID,
CreatedAt: timestamppb.New(k.CreatedAt),
BoundAt: timestamppb.New(k.BoundAt),
2021-08-27 14:58:04 +00:00
}
}
nextCursor := ""
api.JSON(w, &GetExternalAccountKeysResponse{
EAKs: eaks,
NextCursor: nextCursor,
})
2021-07-23 13:41:24 +00:00
}