casdoor/object/cert.go

234 lines
5.6 KiB
Go
Raw Normal View History

2022-02-13 23:39:27 +08:00
// Copyright 2021 The Casdoor Authors. All Rights Reserved.
2021-12-31 00:36:36 +08:00
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package object
import (
"fmt"
2022-01-20 14:11:46 +08:00
"github.com/casdoor/casdoor/util"
feat: app session control and db migrate (#1539) * feat: integrate application session management into Casdoor's session management (#774) && standardized the database migration process (#1533) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) * feat: integrate application session management into Casdoor's session management (#774) && standardized the database migration process * feat: integrate application session management into Casdoor's session management (#774) && standardized the database migration process * feat: integrate application session management into Casdoor's session management (#774) && standardized the database migration process --------- Co-authored-by: Zayn Xie <84443886+xiaoniuren99@users.noreply.github.com> * fix: migrate err * fix: migrate err * feat: app session control and db migrate * feat: app session control and db migrate * feat: app session control and db migrate --------- Co-authored-by: Zayn Xie <84443886+xiaoniuren99@users.noreply.github.com>
2023-02-12 09:33:24 +08:00
"github.com/xorm-io/core"
2021-12-31 00:36:36 +08:00
)
type Cert struct {
Owner string `xorm:"varchar(100) notnull pk" json:"owner"`
Name string `xorm:"varchar(100) notnull pk" json:"name"`
CreatedTime string `xorm:"varchar(100)" json:"createdTime"`
DisplayName string `xorm:"varchar(100)" json:"displayName"`
Scope string `xorm:"varchar(100)" json:"scope"`
Type string `xorm:"varchar(100)" json:"type"`
CryptoAlgorithm string `xorm:"varchar(100)" json:"cryptoAlgorithm"`
BitSize int `json:"bitSize"`
ExpireInYears int `json:"expireInYears"`
Certificate string `xorm:"mediumtext" json:"certificate"`
2022-03-06 22:46:02 +08:00
PrivateKey string `xorm:"mediumtext" json:"privateKey"`
AuthorityPublicKey string `xorm:"mediumtext" json:"authorityPublicKey"`
AuthorityRootPublicKey string `xorm:"mediumtext" json:"authorityRootPublicKey"`
2021-12-31 00:36:36 +08:00
}
func GetMaskedCert(cert *Cert) *Cert {
if cert == nil {
return nil
}
return cert
}
func GetMaskedCerts(certs []*Cert, err error) ([]*Cert, error) {
if err != nil {
return nil, err
}
2021-12-31 00:36:36 +08:00
for _, cert := range certs {
cert = GetMaskedCert(cert)
}
return certs, nil
2021-12-31 00:36:36 +08:00
}
func GetCertCount(owner, field, value string) (int64, error) {
session := GetSession("", -1, -1, field, value, "", "")
return session.Where("owner = ? or owner = ? ", "admin", owner).Count(&Cert{})
2021-12-31 00:36:36 +08:00
}
func GetCerts(owner string) ([]*Cert, error) {
2021-12-31 00:36:36 +08:00
certs := []*Cert{}
err := ormer.Engine.Where("owner = ? or owner = ? ", "admin", owner).Desc("created_time").Find(&certs, &Cert{})
2021-12-31 00:36:36 +08:00
if err != nil {
return certs, err
2021-12-31 00:36:36 +08:00
}
return certs, nil
2021-12-31 00:36:36 +08:00
}
func GetPaginationCerts(owner string, offset, limit int, field, value, sortField, sortOrder string) ([]*Cert, error) {
2021-12-31 00:36:36 +08:00
certs := []*Cert{}
session := GetSession("", offset, limit, field, value, sortField, sortOrder)
err := session.Where("owner = ? or owner = ? ", "admin", owner).Find(&certs)
if err != nil {
return certs, err
}
return certs, nil
}
func GetGlobalCertsCount(field, value string) (int64, error) {
session := GetSession("", -1, -1, field, value, "", "")
return session.Count(&Cert{})
}
func GetGlobleCerts() ([]*Cert, error) {
certs := []*Cert{}
err := ormer.Engine.Desc("created_time").Find(&certs)
if err != nil {
return certs, err
}
return certs, nil
}
func GetPaginationGlobalCerts(offset, limit int, field, value, sortField, sortOrder string) ([]*Cert, error) {
certs := []*Cert{}
session := GetSession("", offset, limit, field, value, sortField, sortOrder)
2021-12-31 00:36:36 +08:00
err := session.Find(&certs)
if err != nil {
return certs, err
2021-12-31 00:36:36 +08:00
}
return certs, nil
2021-12-31 00:36:36 +08:00
}
func getCert(owner string, name string) (*Cert, error) {
2021-12-31 00:36:36 +08:00
if owner == "" || name == "" {
return nil, nil
2021-12-31 00:36:36 +08:00
}
cert := Cert{Owner: owner, Name: name}
existed, err := ormer.Engine.Get(&cert)
2021-12-31 00:36:36 +08:00
if err != nil {
return &cert, err
2021-12-31 00:36:36 +08:00
}
if existed {
return &cert, nil
2021-12-31 00:36:36 +08:00
} else {
return nil, nil
2021-12-31 00:36:36 +08:00
}
}
func getCertByName(name string) (*Cert, error) {
2023-05-18 16:32:43 +08:00
if name == "" {
return nil, nil
2023-05-18 16:32:43 +08:00
}
cert := Cert{Name: name}
existed, err := ormer.Engine.Get(&cert)
2023-05-18 16:32:43 +08:00
if err != nil {
return &cert, nil
2023-05-18 16:32:43 +08:00
}
if existed {
return &cert, nil
2023-05-18 16:32:43 +08:00
} else {
return nil, nil
2023-05-18 16:32:43 +08:00
}
}
func GetCert(id string) (*Cert, error) {
2021-12-31 00:36:36 +08:00
owner, name := util.GetOwnerAndNameFromId(id)
return getCert(owner, name)
}
func UpdateCert(id string, cert *Cert) (bool, error) {
2021-12-31 00:36:36 +08:00
owner, name := util.GetOwnerAndNameFromId(id)
if c, err := getCert(owner, name); err != nil {
return false, err
} else if c == nil {
return false, nil
2021-12-31 00:36:36 +08:00
}
if name != cert.Name {
err := certChangeTrigger(name, cert.Name)
if err != nil {
return false, nil
}
}
affected, err := ormer.Engine.ID(core.PK{owner, name}).AllCols().Update(cert)
2021-12-31 00:36:36 +08:00
if err != nil {
return false, err
2021-12-31 00:36:36 +08:00
}
return affected != 0, nil
2021-12-31 00:36:36 +08:00
}
func AddCert(cert *Cert) (bool, error) {
if cert.Certificate == "" || cert.PrivateKey == "" {
certificate, privateKey := generateRsaKeys(cert.BitSize, cert.ExpireInYears, cert.Name, cert.Owner)
cert.Certificate = certificate
2021-12-31 09:36:48 +08:00
cert.PrivateKey = privateKey
}
affected, err := ormer.Engine.Insert(cert)
2021-12-31 00:36:36 +08:00
if err != nil {
return false, err
2021-12-31 00:36:36 +08:00
}
return affected != 0, nil
2021-12-31 00:36:36 +08:00
}
func DeleteCert(cert *Cert) (bool, error) {
affected, err := ormer.Engine.ID(core.PK{cert.Owner, cert.Name}).Delete(&Cert{})
2021-12-31 00:36:36 +08:00
if err != nil {
return false, err
2021-12-31 00:36:36 +08:00
}
return affected != 0, nil
2021-12-31 00:36:36 +08:00
}
func (p *Cert) GetId() string {
return fmt.Sprintf("%s/%s", p.Owner, p.Name)
}
2021-12-31 09:36:48 +08:00
func getCertByApplication(application *Application) (*Cert, error) {
2021-12-31 09:36:48 +08:00
if application.Cert != "" {
2023-05-18 16:32:43 +08:00
return getCertByName(application.Cert)
2021-12-31 09:36:48 +08:00
} else {
return GetDefaultCert()
}
}
func GetDefaultCert() (*Cert, error) {
2021-12-31 09:36:48 +08:00
return getCert("admin", "cert-built-in")
}
func certChangeTrigger(oldName string, newName string) error {
session := ormer.Engine.NewSession()
defer session.Close()
err := session.Begin()
if err != nil {
return err
}
application := new(Application)
application.Cert = newName
_, err = session.Where("cert=?", oldName).Update(application)
if err != nil {
return err
}
return session.Commit()
}