util.go 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106
  1. package mq
  2. import (
  3. "errors"
  4. "fmt"
  5. "strings"
  6. "time"
  7. "github.com/gravitl/netmaker/logic"
  8. "github.com/gravitl/netmaker/models"
  9. "github.com/gravitl/netmaker/netclient/ncutils"
  10. )
  11. func decryptMsgWithHost(host *models.Host, msg []byte) ([]byte, error) {
  12. if host.OS == models.OS_Types.IoT { // just pass along IoT messages
  13. return msg, nil
  14. }
  15. trafficKey, trafficErr := logic.RetrievePrivateTrafficKey() // get server private key
  16. if trafficErr != nil {
  17. return nil, trafficErr
  18. }
  19. serverPrivTKey, err := ncutils.ConvertBytesToKey(trafficKey)
  20. if err != nil {
  21. return nil, err
  22. }
  23. nodePubTKey, err := ncutils.ConvertBytesToKey(host.TrafficKeyPublic)
  24. if err != nil {
  25. return nil, err
  26. }
  27. return ncutils.DeChunk(msg, nodePubTKey, serverPrivTKey)
  28. }
  29. func DecryptMsg(node *models.Node, msg []byte) ([]byte, error) {
  30. if len(msg) <= 24 { // make sure message is of appropriate length
  31. return nil, fmt.Errorf("received invalid message from broker %v", msg)
  32. }
  33. host, err := logic.GetHost(node.HostID.String())
  34. if err != nil {
  35. return nil, err
  36. }
  37. return decryptMsgWithHost(host, msg)
  38. }
  39. func encryptMsg(host *models.Host, msg []byte) ([]byte, error) {
  40. if host.OS == models.OS_Types.IoT {
  41. return msg, nil
  42. }
  43. // fetch server public key to be certain hasn't changed in transit
  44. trafficKey, trafficErr := logic.RetrievePrivateTrafficKey()
  45. if trafficErr != nil {
  46. return nil, trafficErr
  47. }
  48. serverPrivKey, err := ncutils.ConvertBytesToKey(trafficKey)
  49. if err != nil {
  50. return nil, err
  51. }
  52. nodePubKey, err := ncutils.ConvertBytesToKey(host.TrafficKeyPublic)
  53. if err != nil {
  54. return nil, err
  55. }
  56. if strings.Contains(host.Version, "0.10.0") {
  57. return ncutils.BoxEncrypt(msg, nodePubKey, serverPrivKey)
  58. }
  59. return ncutils.Chunk(msg, nodePubKey, serverPrivKey)
  60. }
  61. func publish(host *models.Host, dest string, msg []byte) error {
  62. encrypted, encryptErr := encryptMsg(host, msg)
  63. if encryptErr != nil {
  64. return encryptErr
  65. }
  66. if mqclient == nil || !mqclient.IsConnectionOpen() {
  67. return errors.New("cannot publish ... mqclient not connected")
  68. }
  69. if token := mqclient.Publish(dest, 0, true, encrypted); !token.WaitTimeout(MQ_TIMEOUT*time.Second) || token.Error() != nil {
  70. var err error
  71. if token.Error() == nil {
  72. err = errors.New("connection timeout")
  73. } else {
  74. err = token.Error()
  75. }
  76. return err
  77. }
  78. return nil
  79. }
  80. // decodes a message queue topic and returns the embedded node.ID
  81. func GetID(topic string) (string, error) {
  82. parts := strings.Split(topic, "/")
  83. count := len(parts)
  84. if count == 1 {
  85. return "", fmt.Errorf("invalid topic")
  86. }
  87. //the last part of the topic will be the node.ID
  88. return parts[count-1], nil
  89. }