Solved conundrum about Server separation of Subscribe and SendCommand streams
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
use actix::prelude::*;
|
||||
use std::collections::HashMap;
|
||||
use std::sync::Arc;
|
||||
use libbonknet::{load_cert, load_prkey, FromServerMessage, RequiredReplyValues, FromGuestServerMessage, ToGuestServerMessage};
|
||||
use libbonknet::*;
|
||||
use rustls::{RootCertStore, ServerConfig};
|
||||
use rustls::server::WebPkiClientVerifier;
|
||||
use actix_tls::accept::rustls_0_22::{Acceptor as RustlsAcceptor, TlsStream};
|
||||
@@ -14,6 +14,8 @@ use tokio_util::codec::{Framed, LengthDelimitedCodec};
|
||||
use tracing::{info, error};
|
||||
use rcgen::{Certificate, CertificateParams, DnType, KeyPair};
|
||||
|
||||
type TransportStream = Framed<TlsStream<TcpStream>, LengthDelimitedCodec>;
|
||||
|
||||
struct ServerCert {
|
||||
cert: Vec<u8>,
|
||||
prkey: Vec<u8>,
|
||||
@@ -21,7 +23,7 @@ struct ServerCert {
|
||||
|
||||
fn generate_server_cert(root_cert: &Certificate, name: &str) -> ServerCert {
|
||||
let mut params = CertificateParams::new(vec!["entity.other.host".into(), format!("bonk.server.{name}")]);
|
||||
params.distinguished_name.push(DnType::CommonName, format!("{name}"));
|
||||
params.distinguished_name.push(DnType::CommonName, name);
|
||||
params.use_authority_key_identifier_extension = true;
|
||||
params.key_usages.push(rcgen::KeyUsagePurpose::DigitalSignature);
|
||||
params
|
||||
@@ -54,6 +56,12 @@ struct RegisterServer {
|
||||
name: String,
|
||||
}
|
||||
|
||||
#[derive(Message)]
|
||||
#[rtype(result = "Option<String>")]
|
||||
struct FetchName {
|
||||
cert: Vec<u8>,
|
||||
}
|
||||
|
||||
// TODO: Move into Sqlite DB with unique check on col1 and col2!!!! Right now name is not unique
|
||||
struct ServerCertDB {
|
||||
db: HashMap<Vec<u8>, String>, // Cert to Name
|
||||
@@ -87,32 +95,14 @@ impl Handler<IsNameRegistered> for ServerCertDB {
|
||||
}
|
||||
}
|
||||
|
||||
struct GuestServerConnection {
|
||||
stream: TlsStream<TcpStream>,
|
||||
}
|
||||
impl Handler<FetchName> for ServerCertDB {
|
||||
type Result = Option<String>;
|
||||
|
||||
impl Actor for GuestServerConnection {
|
||||
type Context = Context<Self>;
|
||||
}
|
||||
|
||||
struct ServerConnection<T: 'static> {
|
||||
stream: Framed<TlsStream<TcpStream>, T>,
|
||||
name: String
|
||||
}
|
||||
|
||||
impl<T> ServerConnection<T> {
|
||||
fn new(stream: TlsStream<TcpStream>, codec: T) -> Self {
|
||||
let stream = Framed::new(stream, codec);
|
||||
ServerConnection {
|
||||
stream,
|
||||
name: "Polnareffland1".into(),
|
||||
}
|
||||
fn handle(&mut self, msg: FetchName, _ctx: &mut Self::Context) -> Self::Result {
|
||||
self.db.get(&msg.cert).map(|s| s.to_owned())
|
||||
}
|
||||
}
|
||||
|
||||
impl<T> Actor for ServerConnection<T> {
|
||||
type Context = Context<Self>;
|
||||
}
|
||||
|
||||
#[actix_rt::main]
|
||||
async fn main() {
|
||||
@@ -149,7 +139,7 @@ async fn main() {
|
||||
let client_root_cert_der = Arc::new(client_root_cert_der);
|
||||
let guestserver_root_cert_der = Arc::new(guestserver_root_cert_der);
|
||||
let server_root_cert = Arc::new(Certificate::from_params(CertificateParams::from_ca_cert_der(
|
||||
&*server_root_cert_der,
|
||||
&server_root_cert_der,
|
||||
server_root_prkey
|
||||
).unwrap()).unwrap());
|
||||
|
||||
@@ -176,87 +166,46 @@ async fn main() {
|
||||
let server_root_cert = Arc::clone(&server_root_cert);
|
||||
let server_db_addr = server_db_addr.clone();
|
||||
async move {
|
||||
let peer_cert_der = stream.get_ref().1.peer_certificates().unwrap().last().unwrap().clone();
|
||||
if peer_cert_der == *server_root_cert_der {
|
||||
let peer_certs = stream.get_ref().1.peer_certificates().unwrap();
|
||||
let peer_cert_bytes = peer_certs.first().unwrap().to_vec();
|
||||
let peer_root_cert_der = peer_certs.last().unwrap().clone();
|
||||
if peer_root_cert_der == *server_root_cert_der {
|
||||
info!("Server connection");
|
||||
let framed = Framed::new(stream, LengthDelimitedCodec::new());
|
||||
framed.for_each(|item| async move {
|
||||
match item {
|
||||
let mut transport = Framed::new(stream, LengthDelimitedCodec::new());
|
||||
match transport.next().await {
|
||||
None => {
|
||||
info!("Connection closed by peer");
|
||||
}
|
||||
Some(item) => match item {
|
||||
Ok(buf) => {
|
||||
use FromServerMessage::*;
|
||||
let msg: FromServerMessage = rmp_serde::from_slice(&buf).unwrap();
|
||||
use FromServerConnTypeMessage::*;
|
||||
let msg: FromServerConnTypeMessage = rmp_serde::from_slice(&buf).unwrap();
|
||||
info!("{:?}", msg);
|
||||
match msg {
|
||||
RequiredReply(v) => match v {
|
||||
RequiredReplyValues::Ok => {
|
||||
info!("Required Reply OK")
|
||||
}
|
||||
RequiredReplyValues::GenericFailure { .. } => {
|
||||
info!("Required Reply Generic Failure")
|
||||
}
|
||||
SendCommand => {
|
||||
info!("SendCommand Stream");
|
||||
let reply = ToServerConnTypeReply::OkSendCommand;
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
server_command_handler(transport, peer_cert_bytes, &server_db_addr).await;
|
||||
}
|
||||
ChangeName { name } => {
|
||||
info!("Requested Change Name to Name {}", name);
|
||||
}
|
||||
WhoAmI => {
|
||||
info!("Requested WhoAmI");
|
||||
Subscribe => {
|
||||
info!("Subscribe Stream")
|
||||
}
|
||||
}
|
||||
},
|
||||
}
|
||||
Err(e) => {
|
||||
info!("Disconnection: {:?}", e);
|
||||
}
|
||||
}
|
||||
}).await;
|
||||
info!("Disconnection!");
|
||||
} else if peer_cert_der == *guestserver_root_cert_der {
|
||||
}
|
||||
info!("Server Task terminated!");
|
||||
} else if peer_root_cert_der == *guestserver_root_cert_der {
|
||||
info!("GuestServer connection");
|
||||
let server_root_cert = Arc::clone(&server_root_cert);
|
||||
let codec = LengthDelimitedCodec::new();
|
||||
let mut transport = Framed::new(stream, codec);
|
||||
loop {
|
||||
match transport.next().await {
|
||||
None => {
|
||||
info!("Transport returned None");
|
||||
}
|
||||
Some(item) => {
|
||||
match item {
|
||||
Ok(buf) => {
|
||||
use FromGuestServerMessage::*;
|
||||
let msg: FromGuestServerMessage = rmp_serde::from_slice(&buf).unwrap();
|
||||
info!("{:?}", msg);
|
||||
match msg {
|
||||
Announce { name } => {
|
||||
info!("Announced with name {}", name);
|
||||
if server_db_addr.send(IsNameRegistered { name: name.clone() }).await.unwrap() {
|
||||
info!("Name {} already registered!", name);
|
||||
let reply = ToGuestServerMessage::FailedNameAlreadyOccupied;
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
break; // Stop reading
|
||||
} else {
|
||||
let cert = generate_server_cert(&server_root_cert, name.as_str());
|
||||
server_db_addr.send(RegisterServer {
|
||||
cert: cert.cert.clone(),
|
||||
name,
|
||||
}).await.unwrap().unwrap();
|
||||
let reply = ToGuestServerMessage::OkAnnounce {
|
||||
server_cert: cert.cert,
|
||||
server_prkey: cert.prkey
|
||||
};
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
info!("Disconnection: {:?}", e);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
} else if peer_cert_der == *client_root_cert_der {
|
||||
let transport = Framed::new(stream, codec);
|
||||
guestserver_handler(transport, &server_db_addr, &server_root_cert).await;
|
||||
} else if peer_root_cert_der == *client_root_cert_der {
|
||||
info!("Client connection");
|
||||
} else {
|
||||
error!("Unknown Root Certificate");
|
||||
@@ -270,3 +219,92 @@ async fn main() {
|
||||
.await
|
||||
.unwrap();
|
||||
}
|
||||
|
||||
async fn server_command_handler(mut transport: TransportStream, peer_cert_bytes: Vec<u8>, server_db_addr: &Addr<ServerCertDB>) {
|
||||
loop {
|
||||
match transport.next().await {
|
||||
None => {
|
||||
info!("Transport returned None");
|
||||
break;
|
||||
}
|
||||
Some(item) => match item {
|
||||
Ok(buf) => {
|
||||
use FromServerCommandMessage::*;
|
||||
let msg: FromServerCommandMessage = rmp_serde::from_slice(&buf).unwrap();
|
||||
info!("{:?}", msg);
|
||||
match msg {
|
||||
ChangeName { name } => {
|
||||
info!("Changing name to {}", name);
|
||||
// TODO
|
||||
}
|
||||
WhoAmI => {
|
||||
info!("Asked who I am");
|
||||
let reply = match server_db_addr.send(FetchName { cert: peer_cert_bytes.clone() }).await.unwrap() {
|
||||
None => {
|
||||
info!("I'm not registered anymore!? WTF");
|
||||
ToServerCommandReply::GenericFailure
|
||||
}
|
||||
Some(name) => {
|
||||
info!("I am {}", name);
|
||||
ToServerCommandReply::YouAre { name }
|
||||
}
|
||||
};
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
info!("Disconnection: {:?}", e);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TODO: Considera creare un context dove vengono contenute tutte le chiavi e gli address da dare a tutti gli handler
|
||||
async fn guestserver_handler(mut transport: TransportStream, server_db_addr: &Addr<ServerCertDB>, server_root_cert: &Arc<Certificate>) {
|
||||
loop {
|
||||
match transport.next().await {
|
||||
None => {
|
||||
info!("Transport returned None");
|
||||
break;
|
||||
}
|
||||
Some(item) => {
|
||||
match item {
|
||||
Ok(buf) => {
|
||||
use FromGuestServerMessage::*;
|
||||
let msg: FromGuestServerMessage = rmp_serde::from_slice(&buf).unwrap();
|
||||
info!("{:?}", msg);
|
||||
match msg {
|
||||
Announce { name } => {
|
||||
info!("Announced with name {}", name);
|
||||
if server_db_addr.send(IsNameRegistered { name: name.clone() }).await.unwrap() {
|
||||
info!("Name {} already registered!", name);
|
||||
let reply = ToGuestServerMessage::FailedNameAlreadyOccupied;
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
break; // Stop reading
|
||||
} else {
|
||||
let cert = generate_server_cert(server_root_cert, name.as_str());
|
||||
server_db_addr.send(RegisterServer {
|
||||
cert: cert.cert.clone(),
|
||||
name,
|
||||
}).await.unwrap().unwrap();
|
||||
let reply = ToGuestServerMessage::OkAnnounce {
|
||||
server_cert: cert.cert,
|
||||
server_prkey: cert.prkey
|
||||
};
|
||||
transport.send(rmp_serde::to_vec(&reply).unwrap().into()).await.unwrap();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
info!("Disconnection: {:?}", e);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user