enrollmentkey.go 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221
  1. package logic
  2. import (
  3. b64 "encoding/base64"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "time"
  8. "github.com/gravitl/netmaker/database"
  9. "github.com/gravitl/netmaker/models"
  10. "github.com/gravitl/netmaker/netclient/ncutils"
  11. )
  12. // EnrollmentErrors - struct for holding EnrollmentKey error messages
  13. var EnrollmentErrors = struct {
  14. InvalidCreate error
  15. NoKeyFound error
  16. InvalidKey error
  17. NoUsesRemaining error
  18. FailedToTokenize error
  19. FailedToDeTokenize error
  20. }{
  21. InvalidCreate: fmt.Errorf("invalid enrollment key created"),
  22. NoKeyFound: fmt.Errorf("no enrollmentkey found"),
  23. InvalidKey: fmt.Errorf("invalid key provided"),
  24. NoUsesRemaining: fmt.Errorf("no uses remaining"),
  25. FailedToTokenize: fmt.Errorf("failed to tokenize"),
  26. FailedToDeTokenize: fmt.Errorf("failed to detokenize"),
  27. }
  28. // CreateEnrollmentKey - creates a new enrollment key in db
  29. func CreateEnrollmentKey(uses int, expiration time.Time, networks, tags []string, unlimited bool) (k *models.EnrollmentKey, err error) {
  30. newKeyID, err := getUniqueEnrollmentID()
  31. if err != nil {
  32. return nil, err
  33. }
  34. k = &models.EnrollmentKey{
  35. Value: newKeyID,
  36. Expiration: time.Time{},
  37. UsesRemaining: 0,
  38. Unlimited: unlimited,
  39. Networks: []string{},
  40. Tags: []string{},
  41. }
  42. if uses > 0 {
  43. k.UsesRemaining = uses
  44. }
  45. if !expiration.IsZero() {
  46. k.Expiration = expiration
  47. }
  48. if len(networks) > 0 {
  49. k.Networks = networks
  50. }
  51. if len(tags) > 0 {
  52. k.Tags = tags
  53. }
  54. if ok := k.Validate(); !ok {
  55. return nil, EnrollmentErrors.InvalidCreate
  56. }
  57. if err = upsertEnrollmentKey(k); err != nil {
  58. return nil, err
  59. }
  60. return
  61. }
  62. // GetAllEnrollmentKeys - fetches all enrollment keys from DB
  63. func GetAllEnrollmentKeys() ([]*models.EnrollmentKey, error) {
  64. currentKeys, err := getEnrollmentKeysMap()
  65. if err != nil {
  66. return nil, err
  67. }
  68. var currentKeysList = []*models.EnrollmentKey{}
  69. for k := range currentKeys {
  70. currentKeysList = append(currentKeysList, currentKeys[k])
  71. }
  72. return currentKeysList, nil
  73. }
  74. // GetEnrollmentKey - fetches a single enrollment key
  75. // returns nil and error if not found
  76. func GetEnrollmentKey(value string) (*models.EnrollmentKey, error) {
  77. currentKeys, err := getEnrollmentKeysMap()
  78. if err != nil {
  79. return nil, err
  80. }
  81. if key, ok := currentKeys[value]; ok {
  82. return key, nil
  83. }
  84. return nil, EnrollmentErrors.NoKeyFound
  85. }
  86. // DeleteEnrollmentKey - delete's a given enrollment key by value
  87. func DeleteEnrollmentKey(value string) error {
  88. _, err := GetEnrollmentKey(value)
  89. if err != nil {
  90. return err
  91. }
  92. return database.DeleteRecord(database.ENROLLMENT_KEYS_TABLE_NAME, value)
  93. }
  94. // TryToUseEnrollmentKey - checks first if key can be decremented
  95. // returns true if it is decremented or isvalid
  96. func TryToUseEnrollmentKey(k *models.EnrollmentKey) bool {
  97. key, err := decrementEnrollmentKey(k.Value)
  98. if err != nil {
  99. if errors.Is(err, EnrollmentErrors.NoUsesRemaining) {
  100. return k.IsValid()
  101. }
  102. } else {
  103. k.UsesRemaining = key.UsesRemaining
  104. return true
  105. }
  106. return false
  107. }
  108. // Tokenize - tokenizes an enrollment key to be used via registration
  109. // and attaches it to the Token field on the struct
  110. func Tokenize(k *models.EnrollmentKey, serverAddr string) error {
  111. if len(serverAddr) == 0 || k == nil {
  112. return EnrollmentErrors.FailedToTokenize
  113. }
  114. newToken := models.EnrollmentToken{
  115. Server: serverAddr,
  116. Value: k.Value,
  117. }
  118. data, err := json.Marshal(&newToken)
  119. if err != nil {
  120. return err
  121. }
  122. k.Token = b64.StdEncoding.EncodeToString(data)
  123. return nil
  124. }
  125. // DeTokenize - detokenizes a base64 encoded string
  126. // and finds the associated enrollment key
  127. func DeTokenize(b64Token string) (*models.EnrollmentKey, error) {
  128. if len(b64Token) == 0 {
  129. return nil, EnrollmentErrors.FailedToDeTokenize
  130. }
  131. tokenData, err := b64.StdEncoding.DecodeString(b64Token)
  132. if err != nil {
  133. return nil, err
  134. }
  135. var newToken models.EnrollmentToken
  136. err = json.Unmarshal(tokenData, &newToken)
  137. if err != nil {
  138. return nil, err
  139. }
  140. k, err := GetEnrollmentKey(newToken.Value)
  141. if err != nil {
  142. return nil, err
  143. }
  144. return k, nil
  145. }
  146. // == private ==
  147. // decrementEnrollmentKey - decrements the uses on a key if above 0 remaining
  148. func decrementEnrollmentKey(value string) (*models.EnrollmentKey, error) {
  149. k, err := GetEnrollmentKey(value)
  150. if err != nil {
  151. return nil, err
  152. }
  153. if k.UsesRemaining == 0 {
  154. return nil, EnrollmentErrors.NoUsesRemaining
  155. }
  156. k.UsesRemaining = k.UsesRemaining - 1
  157. if err = upsertEnrollmentKey(k); err != nil {
  158. return nil, err
  159. }
  160. return k, nil
  161. }
  162. func upsertEnrollmentKey(k *models.EnrollmentKey) error {
  163. if k == nil {
  164. return EnrollmentErrors.InvalidKey
  165. }
  166. data, err := json.Marshal(k)
  167. if err != nil {
  168. return err
  169. }
  170. return database.Insert(k.Value, string(data), database.ENROLLMENT_KEYS_TABLE_NAME)
  171. }
  172. func getUniqueEnrollmentID() (string, error) {
  173. currentKeys, err := getEnrollmentKeysMap()
  174. if err != nil {
  175. return "", err
  176. }
  177. newID := ncutils.MakeRandomString(models.EnrollmentKeyLength)
  178. for _, ok := currentKeys[newID]; ok; {
  179. newID = ncutils.MakeRandomString(models.EnrollmentKeyLength)
  180. }
  181. return newID, nil
  182. }
  183. func getEnrollmentKeysMap() (map[string]*models.EnrollmentKey, error) {
  184. records, err := database.FetchRecords(database.ENROLLMENT_KEYS_TABLE_NAME)
  185. if err != nil {
  186. if !database.IsEmptyRecord(err) {
  187. return nil, err
  188. }
  189. }
  190. if records == nil {
  191. records = make(map[string]string)
  192. }
  193. currentKeys := make(map[string]*models.EnrollmentKey, 0)
  194. if len(records) > 0 {
  195. for k := range records {
  196. var currentKey models.EnrollmentKey
  197. if err = json.Unmarshal([]byte(records[k]), &currentKey); err != nil {
  198. continue
  199. }
  200. currentKeys[k] = &currentKey
  201. }
  202. }
  203. return currentKeys, nil
  204. }