mirror of
https://github.com/taylanbakircioglu/haproxy-openmanager.git
synced 2026-10-02 15:08:13 +00:00
Compare commits
29 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| eee0a4716a | |||
| 3c8832330a | |||
| 81ab674072 | |||
| 6bf6d016f5 | |||
| 0a0226c758 | |||
| 8e534ef170 | |||
| 71786200dd | |||
| 33e3e8ef9d | |||
| 69e12f7459 | |||
| af07d72514 | |||
| a6166d11b9 | |||
| 882d25bb68 | |||
| 0ebf6583ea | |||
| 6be19f0bb5 | |||
| 9e5185c458 | |||
| 520b69a1c6 | |||
| 56107fa86f | |||
| f86a4331e8 | |||
| 1c47e246ec | |||
| d914f2398b | |||
| 9c1f3c811b | |||
| c79391cd13 | |||
| 9e2ea04777 | |||
| 60f4fa71ed | |||
| 97b2452bd2 | |||
| 23257b02cf | |||
| c8d144ca9d | |||
| 64d42663cd | |||
| 27fbe48c4b |
+35
-3
@@ -17,11 +17,34 @@ REDIS_URL=redis://redis:6379
|
||||
# Change this to a strong random string in production
|
||||
SECRET_KEY=your-secret-key-change-this-in-production
|
||||
|
||||
# Optional: dedicated Fernet key for encrypting VRRP secrets of HA/VIP (Issue #27).
|
||||
# If unset, it is derived from SECRET_KEY (HKDF), exactly like MFA. Set an explicit
|
||||
# key (urlsafe-base64, 32 bytes) in production if you want independent key rotation.
|
||||
# ----------------------------------------------------------------------------
|
||||
# Optional per-purpose encryption keys.
|
||||
#
|
||||
# Every secret the application stores is encrypted at rest with Fernet. Each class
|
||||
# derives its own key, so rotating one never affects another. If a variable below is
|
||||
# unset, that class's key is derived from SECRET_KEY via HKDF — which works, but means
|
||||
# rotating SECRET_KEY makes the existing values of that class UNDECRYPTABLE. Set an
|
||||
# explicit key (urlsafe-base64, 32 bytes) in production if you want independent
|
||||
# rotation. Generate one with:
|
||||
# python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
# VRRP secrets for HA/VIP (Issue #27).
|
||||
# VIP_ENCRYPTION_KEY=
|
||||
|
||||
# TOTP secrets for multi-factor authentication (Issue #18).
|
||||
# MFA_ENCRYPTION_KEY=
|
||||
|
||||
# Per-account DNS provider credentials for ACME DNS-01 (Issue #35).
|
||||
# Rotating this without re-entering credentials makes DNS-01 renewals fail until the
|
||||
# affected accounts' credentials are re-saved in ACME Automation.
|
||||
# DNS_PROVIDER_ENCRYPTION_KEY=
|
||||
|
||||
# Private keys of PENDING CSRs, held only until the signed certificate is imported
|
||||
# (Issue #53). Rotating this while CSRs are out for signature makes those CSRs
|
||||
# unusable — they must be deleted and re-created.
|
||||
# CSR_ENCRYPTION_KEY=
|
||||
|
||||
# ============================================================================
|
||||
# PUBLIC URL CONFIGURATION
|
||||
# ============================================================================
|
||||
@@ -59,6 +82,15 @@ AGENT_HEARTBEAT_TIMEOUT_SECONDS=15
|
||||
# Config sync interval in seconds
|
||||
AGENT_CONFIG_SYNC_INTERVAL_SECONDS=30
|
||||
|
||||
# ============================================================================
|
||||
# BACKEND PERFORMANCE
|
||||
# ============================================================================
|
||||
# Number of uvicorn worker processes for the backend API (default: 1).
|
||||
# On multi-core hosts, setting this to the core count (e.g. 2) lets the API
|
||||
# use all cores. Safe to increase: background tasks are multi-replica safe
|
||||
# (the k8s deployment already runs 2+ replicas via HPA).
|
||||
UVICORN_WORKERS=1
|
||||
|
||||
# ============================================================================
|
||||
# CORS CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
@@ -21,27 +21,17 @@ jobs:
|
||||
- name: read product version
|
||||
id: prodversion
|
||||
run: |
|
||||
VERSION=$(jq -r .version version.json)
|
||||
VERSION=$(jq -r .version backend/version.json)
|
||||
if [ -z "$VERSION" ] || [ "$VERSION" = "null" ]; then
|
||||
echo "Failed to read product version from version.json" >&2
|
||||
echo "Failed to read product version from backend/version.json" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "VERSION=$VERSION" >> $GITHUB_OUTPUT
|
||||
|
||||
# The backend image is built with `context: ./backend`, so the
|
||||
# repo-root version.json is OUTSIDE the build context and never
|
||||
# reaches the container. Backend `main.py` falls back to a
|
||||
# compile-time constant when /app/version.json is missing, which
|
||||
# caused a real production drift: a redeploy of the v1.5.2 tree
|
||||
# silently still reported "v1.5.0" in `/api/version` because the
|
||||
# constant in main.py had been bumped but the file was not
|
||||
# available to read. Stage version.json into the backend
|
||||
# context here so the canonical file IS shipped and the
|
||||
# constant only serves as a defensive fallback. The staged file
|
||||
# is gitignored to keep `git status` clean for developers.
|
||||
- name: stage version.json into backend build context
|
||||
run: cp version.json backend/version.json
|
||||
|
||||
# version.json now lives at backend/version.json (inside the ./backend build
|
||||
# context), so `COPY . .` bakes it into the image directly — no staging step
|
||||
# is needed and the backend reports the correct version in every deployment,
|
||||
# not just this workflow's builds.
|
||||
- name: set up qemu
|
||||
uses: docker/setup-qemu-action@v3
|
||||
|
||||
@@ -91,7 +81,7 @@ jobs:
|
||||
run: |
|
||||
VERSION="${{ steps.prodversion.outputs.VERSION }}"
|
||||
TAG="v${VERSION}"
|
||||
RELEASE_NAME=$(jq -r '.releaseName // empty' version.json)
|
||||
RELEASE_NAME=$(jq -r '.releaseName // empty' backend/version.json)
|
||||
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
|
||||
echo "Release $TAG already exists, skipping."
|
||||
else
|
||||
|
||||
@@ -39,11 +39,6 @@ venv.bak/
|
||||
*.sqlite
|
||||
*.sqlite3
|
||||
|
||||
# Build-time staged version.json (CI `cp version.json backend/`).
|
||||
# The canonical file lives at repo root; this path is a transient
|
||||
# copy for the backend Docker build context.
|
||||
backend/version.json
|
||||
|
||||
# IDE
|
||||
.vscode/
|
||||
.idea/
|
||||
|
||||
@@ -105,8 +105,9 @@ This architecture provides better security (no inbound connections to HAProxy se
|
||||
✅ **Version Control & Rollback** - Every change versioned with one-click restore capability
|
||||
✅ **Real-Time Monitoring** - Live stats, health checks, and performance dashboards
|
||||
✅ **SSL Certificate Management** - Centralized SSL with expiration tracking
|
||||
✅ **CSR Creation** *(v1.9.0)* - Generate a private key + CSR in-app (RSA 2048/4096, ECDSA P-256/P-384, full subject + SANs), have it signed by any external CA, then import the signed certificate — the key never leaves the server
|
||||
✅ **ACME Auto SSL (Let's Encrypt)** - Automated certificate issuance, renewal, and deployment via ACME protocol
|
||||
✅ **ACME DNS-01 Challenge** *(v1.8.0)* - TXT-record validation for internal/isolated clusters (no public port 80) and wildcard certificates; pluggable DNS providers (Manual + Cloudflare), opt-in, HTTP-01 unchanged
|
||||
✅ **ACME DNS-01 Challenge** *(v1.8.0)* - TXT-record validation for internal/isolated clusters (no public port 80) and wildcard certificates; pluggable DNS providers (Manual + Cloudflare + GoDaddy *(v1.10.0)*), opt-in, HTTP-01 unchanged
|
||||
✅ **ACME Certificate Diagnostic Panel** - Automated preflight that checks agent readiness, DNS resolution, port 80 reachability, and ACME challenge ACL before issuing certificates
|
||||
✅ **WAF Rules** - Web Application Firewall management and deployment
|
||||
✅ **Agent Script Versioning** - Update agents via UI (Monaco editor) with auto-upgrade
|
||||
@@ -255,7 +256,7 @@ This architecture provides better security (no inbound connections to HAProxy se
|
||||
- **Stuck Order Detection** *(v1.4.0)*: Setup wizard surfaces orders that the CA has validated but not yet downloaded, with one-click `Complete` action and automatic 60-second retry
|
||||
- **Multi-Provider Support**: Configurable ACME directory URL supports Let's Encrypt, ZeroSSL, Google Trust Services, Buypass, and custom CAs
|
||||
- **HTTP-01 Challenge**: Built-in challenge responder with automatic HAProxy routing injection; reserved backend name `_acme_challenge_backend` is auto-managed and protected from manual edits / agent sync collisions
|
||||
- **DNS-01 Challenge** *(v1.8.0 — Issue #35)*: Validate via a DNS TXT record instead of HTTP on port 80, for **internal/isolated clusters with no public ingress** and for **wildcard** certificates (`*.example.com`). Pluggable per-account DNS provider (Manual + Cloudflare to start; credentials encrypted at rest and verified on save), same PENDING → APPLIED pipeline, bounded automatic retry on propagation lag, and a DNS-01 event timeline. Opt-in via a global setting; HTTP-01 behaviour is unchanged. (See the *DNS-01 Challenge* subsection under ACME Auto SSL below.)
|
||||
- **DNS-01 Challenge** *(v1.8.0 — Issue #35)*: Validate via a DNS TXT record instead of HTTP on port 80, for **internal/isolated clusters with no public ingress** and for **wildcard** certificates (`*.example.com`). Pluggable per-account DNS provider (Manual + Cloudflare + GoDaddy *(v1.10.0)*; credentials encrypted at rest and verified on save), same PENDING → APPLIED pipeline, bounded automatic retry on propagation lag, and a DNS-01 event timeline. Opt-in via a global setting; HTTP-01 behaviour is unchanged. (See the *DNS-01 Challenge* subsection under ACME Auto SSL below.)
|
||||
- **ACME Account Management**: Register, view, and deactivate ACME accounts from the UI
|
||||
- **Staging Mode**: Test certificate issuance with Let's Encrypt staging environment before production
|
||||
- **Custom Staging Endpoint** *(v1.4.0)*: Optional `staging_url_override` setting lets you point staging mode at a private ACME test CA (e.g. Pebble) without touching the production directory URL
|
||||
@@ -778,6 +779,15 @@ User Updates SSL in UI → All Agents Poll Backend (30s)
|
||||
→ Validate Config → Reload HAProxy (zero downtime)
|
||||
```
|
||||
|
||||
#### CSR Workflow (external / corporate CAs) — v1.9.0
|
||||
|
||||
For certificates signed by an external or corporate CA, the **CSR tab** on the SSL Certificates page covers the whole flow without the private key ever leaving the server:
|
||||
|
||||
1. **Create CSR**: pick a name (becomes the certificate name / on-agent file path), Common Name, optional SANs and subject fields (O/OU/L/ST/C/email), and a key algorithm (RSA 2048/4096 or ECDSA P-256/P-384). The backend generates the key + CSR; only the CSR PEM is shown (copy or download as `.csr`).
|
||||
2. **Get it signed**: submit the CSR to your Certificate Authority.
|
||||
3. **Import**: paste the signed certificate (+ optional chain), choose Global or cluster-specific scope and usage type. The backend verifies the certificate matches the stored key, rejects expired certs, warns on SAN drift, and creates a normal SSL certificate entry (source: `CSR`).
|
||||
4. **Deploy**: the imported certificate goes through the standard **PENDING → Apply Management → agent pull** pipeline like any other certificate.
|
||||
|
||||
#### Key Features
|
||||
- **Certificate Upload**: PEM format certificate and private key upload
|
||||
- **ACME Automation**: Automatic certificate issuance and renewal via Let's Encrypt / ACME protocol (see [ACME Auto SSL](#acme-auto-ssl---automated-certificate-management))
|
||||
@@ -979,9 +989,9 @@ DNS-01 is **opt-in** and fully backward compatible: it is disabled until an admi
|
||||
|
||||
- **Enable it**: Settings → ACME / SSL Automation → **DNS-01 Challenge (advanced)** → turn on *Enable DNS-01 Challenge* and Save. While off, DNS-01 options are hidden and no DNS-01 orders can be created.
|
||||
- **Per-account provider**: in ACME Automation, create (or reconfigure) an ACME account with **Challenge Method = DNS-01** and a **DNS Provider**. Provider credentials are **verified before saving** and **encrypted at rest** (Fernet, mirroring the VRRP/MFA secret pattern); they are never returned by the API or written to logs.
|
||||
- **Supported providers**: **Manual** (publish the TXT record yourself in any DNS — including fully internal DNS — then click *Verify*; works everywhere but cannot auto-renew unattended) and **Cloudflare** (API token with `Zone:DNS:Edit` + `Zone:Read`; the TXT record is created and cleaned up automatically and renews unattended). The provider interface is pluggable — more providers can be added without changing the issuance flow.
|
||||
- **Supported providers**: **Manual** (publish the TXT record yourself in any DNS — including fully internal DNS — then click *Verify*; works everywhere but cannot auto-renew unattended), **Cloudflare** (API token with `Zone:DNS:Edit` + `Zone:Read`; the TXT record is created and cleaned up automatically and renews unattended), and **GoDaddy** *(v1.10.0)* (a **Production** API Key + Secret pair from `developer.godaddy.com/keys` — the first key that dashboard issues is an OTE/test key and is rejected; the zone must be in the same GoDaddy account, which needs at least one registered domain before GoDaddy allows DNS API access at all. A **Personal Access Token** works too: paste it as the API Key and leave the Secret blank — that is the forward path as GoDaddy retires the `sso-key` scheme. TXT records are created and cleaned up automatically and renew unattended). The provider interface is pluggable — more providers can be added without changing the issuance flow.
|
||||
- **Same pipeline**: after validation the certificate follows the normal PENDING → APPLIED flow (assign to clusters / Apply Management) and the agent serves it — identical to HTTP-01 from finalize onward, with **zero agent or rendered-config changes** for DNS-01.
|
||||
- **Manual flow**: the order detail shows the exact `_acme-challenge.<domain>` record name + TXT value (copyable); publish it and click *I've added the records — Verify*. For Cloudflare it is automatic.
|
||||
- **Manual flow**: the order detail shows the exact `_acme-challenge.<domain>` record name + TXT value (copyable); publish it and click *I've added the records — Verify*. For Cloudflare and GoDaddy it is automatic.
|
||||
- **Resilience**: a propagation-lag failure is recovered by a **bounded fresh-order retry chain** (1 original + 3 retries with increasing backoff, kept under Let's Encrypt's rate limits); any orphaned TXT record is cleaned up by a reconcile sweep. The order detail shows a DNS-01 event timeline (publish → validation → cleanup).
|
||||
- **Wildcards**: `*.example.com` is validated at `_acme-challenge.example.com`; it does **not** cover the apex — add `example.com` as a separate name if you need both (the providers handle the two coexisting TXT values automatically).
|
||||
- **Scope (this release)**: the Site Wizard remains HTTP-01-only; issue DNS-01 / wildcard certificates from **ACME Automation**.
|
||||
@@ -1738,6 +1748,19 @@ Add new HAProxy clusters through the web interface or directly via API:
|
||||
}
|
||||
```
|
||||
|
||||
### Performance Tuning *(v1.8.6)*
|
||||
|
||||
The backend API defaults to a **single uvicorn worker process**, which uses one CPU core. Agents poll the API every 30 seconds (heartbeat, config, pending-requests, upgrade checks), so larger fleets add a constant baseline load. Two ways to scale:
|
||||
|
||||
- **Docker Compose — worker processes**: set `UVICORN_WORKERS` in your `.env` (default `1`). On a multi-core host, matching the core count (e.g. `UVICORN_WORKERS=2` on a 2-core machine) lets the API use all cores:
|
||||
```bash
|
||||
echo "UVICORN_WORKERS=2" >> .env && docker-compose up -d backend
|
||||
```
|
||||
- **Kubernetes/OpenShift — replicas**: the shipped manifests already include an HPA for the backend (2→10 replicas, `k8s/manifests/13-hpa.yaml`); raise `minReplicas`/`maxReplicas` as needed.
|
||||
|
||||
Both are safe: all background tasks (ACME completion, renewals, agent monitoring) are multi-replica safe by design (atomic claims via `FOR UPDATE SKIP LOCKED`, PostgreSQL advisory locks).
|
||||
|
||||
**Diagnosing slow requests**: every API response carries an `X-Response-Time` header, and the backend logs `Slow request detected` (WARNING) for any request taking longer than 1 second — check those log lines to pinpoint slow endpoints before tuning anything else.
|
||||
|
||||
## API Reference
|
||||
|
||||
@@ -1843,6 +1866,42 @@ GET /api/backends?cluster_id=1
|
||||
GET /api/frontends?cluster_id=1
|
||||
```
|
||||
|
||||
### SSL CSR API (v1.9.0)
|
||||
```bash
|
||||
# Create a CSR (generates the private key server-side; response contains the
|
||||
# CSR PEM — the private key is never returned by any endpoint)
|
||||
POST /api/ssl/csrs
|
||||
Authorization: Bearer <token>
|
||||
{
|
||||
"name": "www-example-com",
|
||||
"common_name": "www.example.com",
|
||||
"sans": ["api.example.com"],
|
||||
"key_algorithm": "rsa-2048", # rsa-2048 | rsa-4096 | ecdsa-p256 | ecdsa-p384
|
||||
"organization": "Example Corp",
|
||||
"country": "TR"
|
||||
}
|
||||
|
||||
# List CSRs (metadata only, no PEM)
|
||||
GET /api/ssl/csrs
|
||||
|
||||
# CSR detail (includes the CSR PEM)
|
||||
GET /api/ssl/csrs/{csr_id}
|
||||
|
||||
# Import the CA-signed certificate for a pending CSR
|
||||
POST /api/ssl/csrs/{csr_id}/import
|
||||
{
|
||||
"certificate_content": "-----BEGIN CERTIFICATE-----...",
|
||||
"chain_content": "-----BEGIN CERTIFICATE-----...", # optional
|
||||
"usage_type": "frontend", # frontend | server
|
||||
"is_global": false,
|
||||
"cluster_ids": [1, 2]
|
||||
}
|
||||
|
||||
# Delete a CSR (pending: permanently destroys the private key;
|
||||
# completed: removes history only — the imported certificate is unaffected)
|
||||
DELETE /api/ssl/csrs/{csr_id}
|
||||
```
|
||||
|
||||
### ACME / Let's Encrypt API
|
||||
```bash
|
||||
# List ACME accounts
|
||||
@@ -2069,7 +2128,7 @@ haproxy-openmanager/
|
||||
├── docker-compose.yml # Docker Compose configuration
|
||||
├── docker-compose.localtest.yml # Local development/testing overrides
|
||||
├── docker-compose.test.yml # Test environment
|
||||
├── version.json # Application version metadata
|
||||
├── backend/version.json # Application version metadata (single source of truth)
|
||||
├── build-images.sh # Build Docker images
|
||||
├── pytest.ini # Pytest configuration
|
||||
├── README.md # This file
|
||||
@@ -2415,6 +2474,17 @@ Developed with ❤️ for the HAProxy community
|
||||
|
||||
## Release Notes
|
||||
|
||||
- **v1.10.1** (2026-08-08) — **CSR private key encrypted at rest** (Issue #53): the private key of a **pending** CSR is now Fernet-encrypted in the database instead of stored as PEM. It is the one key in the system worth protecting this way — it sits idle for the entire signing window (days to weeks), is never transmitted to an agent, and is destroyed the moment the signed certificate is imported; `ssl_certificates.private_key_content` and the ACME order keys are unchanged, because agents must receive those in plaintext on every poll. The token replaces the PEM in the **same column**, so there is **no schema change and no `SCHEMA_VERSION` bump** (and therefore no re-seed of the built-in roles). CSRs created before this release keep a raw PEM and are still read transparently, so anything already out for signature imports normally with no data migration. The key derives from `SECRET_KEY` via HKDF with its own info string, independent of the VIP/MFA/DNS keys, and an optional `CSR_ENCRYPTION_KEY` enables independent rotation — rotating `SECRET_KEY` without it makes pending CSR keys unrecoverable, which now fails with an explicit "delete and re-create this CSR" error rather than a misleading key-mismatch. `.env.template` now documents all four per-purpose encryption keys. No API, UI or agent change.
|
||||
- **v1.10.0** (2026-08-07) — **GoDaddy DNS provider for DNS-01** (Issue #35 follow-up): DNS-01 challenges can now be published and cleaned up automatically through **GoDaddy**, alongside the existing Manual and Cloudflare providers, so wildcard and internal-cluster certificates on GoDaddy-hosted zones **renew unattended**. Credentials are a **Production API Key + Secret** pair from `developer.godaddy.com/keys` (a **Personal Access Token** also works — paste it as the Key and leave the Secret blank, which is the forward path as GoDaddy retires `sso-key`); they are **verified against the GoDaddy API before being saved** and **encrypted at rest** (Fernet, the same path as Cloudflare), and are never returned by the API, logged, or written to an order event. GoDaddy's v1 API has **no per-value TXT write** — `PUT` replaces an entire RRset — so add/remove are read-modify-write with sibling values merged back, empty-`data` tombstones filtered out, and `DELETE` used for the last value (`PUT []` is rejected); this is what keeps the **apex + wildcard** case (two TXT values at one `_acme-challenge` name) working, and the record path is hard-gated so it can never collapse onto the zone-wide endpoint that would wipe SPF/DKIM/DMARC. Zone lookup probes the records API rather than the domain listing, so **delegated sub-zones** resolve and small accounts are not falsely rejected. Registry-only addition: one new provider module plus one registry line — no frontend change (the credential form is schema-driven). No schema, API-shape, agent, or rendered-config changes; Manual, Cloudflare and HTTP-01 are unaffected.
|
||||
- **v1.9.0** (2026-08-04) — **CSR creation** (in-app key + CSR generation and signed-certificate import): a new **CSR tab** on the SSL Certificates page generates a private key and Certificate Signing Request server-side (RSA 2048/4096 or ECDSA P-256/P-384; full subject — O/OU/L/ST/C/email — plus DNS SANs with wildcard support), for certificates signed by an **external or corporate CA**. The operator downloads/copies the CSR PEM, has it signed, then imports the signed certificate (+ optional chain): the backend verifies the certificate against the stored key (hard gate), rejects expired certs, warns on SAN drift, and creates a normal SSL certificate entry (source `CSR`) that flows through the standard **PENDING → Apply Management → agent pull** pipeline. The private key **never leaves the server** — no CSR endpoint returns it, and after import the CSR row's key copy is destroyed (the key then lives only on the certificate, like every other key). Additive schema change: one new table `ssl_csrs` (SCHEMA_VERSION 9 → 10, auto-migrated, no existing table altered); key generation runs off the event loop and is rate-limited per user; existing `ssl.*` permissions govern all new endpoints. No agent or rendered-config changes.
|
||||
- **v1.8.10** (2026-07-20) — **Security hardening** (GHSA-7rhv-c5pc-69r8, GHSA-3p5c-m5m4-mjpx, GHSA-3vh4): three advisory classes remediated, backend-only, no agent changes. (1) **RCE**: the agent script-template read/write endpoints now require the `agents.version` permission on top of authentication — a poisoned template is executed as root on every HAProxy node, so authentication alone was insufficient. (2) **Missing authentication**: operator/UI endpoints that were served without a JWT (dashboard stats, pool/cluster listings, agent inventory, WAF rules, config validate/optimize, SSL config-versions, health deep/agents/clusters) are now gated by a `require_authenticated_user` dependency, and agent data-plane endpoints that treated the `X-API-Key` header as *optional* (heartbeat, config, ssl-certificates, upgrade-status, pending-requests) now hard-reject a missing key. In every case the auth check was moved **ahead of** the handler's `try:` block so a 401 can no longer be rewritten into a 500 by the generic exception handler. (3) **SSRF**: a new `utils/ssrf_guard.py` (https-only, IPv4-pinned connector, all resolved addresses must be public, no redirects) protects the ACME directory fetch, the signed-request target and the ACME connection test, which accept operator- or DB-supplied URLs; the connection test also stopped reflecting arbitrary upstream JSON. Frontend dependency advisories patched in the same release. No schema, API-shape or rendered-config changes.
|
||||
- **v1.8.9** (2026-07-13) — **ACL `-f` pattern-file support** (Issue #38 follow-up): ACL definitions that reference a host-side pattern file (`acl … -f /etc/haproxy/lists/blocked.lst`) are accepted on import and edit instead of being rejected. The referenced file lives on the HAProxy node and cannot be validated from the manager, so the manager emits an **advisory warning** rather than a hard rejection and lets the agent's `haproxy -c` check be the fail-safe gate (a broken reference fails validation on the node and the previous config is restored). Consistent with the SPOE handling introduced in v1.8.8.
|
||||
- **v1.8.8** (2026-07-10) — **SPOE filter and frontend `log-format` preserved on import/edit** (Issue #38): importing an existing `haproxy.cfg` or editing a frontend silently dropped `filter spoe …` directives and custom `log-format` lines, so the next Apply pushed a config that had lost them. Both are now round-tripped through import and edit. As with `-f` pattern files, the SPOE engine config is a host-side file the manager cannot read, so it is preserved verbatim and reported as an advisory rather than validated centrally.
|
||||
- **v1.8.7** (2026-07-09) — **Version reporting single-source fix**: the version shown in the UI (backend-sourced via `/api/version`) could lag behind the real release. The canonical version lived in the repo-root `version.json`, but the backend image is built from the `./backend` context, so that file did not reach the container in every pipeline; the backend then fell back to a hardcoded constant in `main.py` that had to be bumped by hand and had drifted (it reported 1.8.4 after 1.8.5/1.8.6 shipped). The version now lives in a single file, `backend/version.json`, baked into every image automatically, and `main.py` no longer carries a real version literal (its fallback is a neutral "unknown"). A new test enforces that the version stays single-source and cannot drift. No functional or API change.
|
||||
- **v1.8.6** (2026-07-06) — **Performance: opt-in API workers + heartbeat micro-optimization** (Issue #35 follow-up): the backend container can now run multiple uvicorn worker processes via the new `UVICORN_WORKERS` environment variable (default **1** — behavior unchanged unless you opt in), letting the API use all cores on multi-core hosts; background tasks were already multi-replica safe, as exercised by the Kubernetes HPA deployment. The agent heartbeat handler now reads the agent's `status`/`version`/`upgrade_status` in one query instead of three (one round-trip per heartbeat, per agent, every 30s). Added a *Performance Tuning* section to the README (worker/replica scaling and how to use the `X-Response-Time` header and `Slow request detected` logs to pinpoint slow endpoints). Zero-risk release: no schema, API, or agent changes; defaults preserve existing behavior exactly.
|
||||
- **v1.8.5** (2026-07-03) — **ACME completion-task SQL fix** (Issue #35 follow-up): the background order-completion task (`complete_pending_acme_orders`, runs every 60s) died on **every cycle** with `syntax error at or near ")"` — an extra closing parenthesis introduced in v1.8.0's bounded DNS-01 retry claim query. Because that query is the task's first database call, **no background ACME work ran at all from v1.8.0 through v1.8.4**: orders were never claimed for finalize/download, the DNS-01 TXT record was never published (so DNS-01 with an automated provider such as Cloudflare could never validate), Site Wizard staged orders never left `wizard_staged`, and DNS-01 retry/TXT-cleanup never executed. The stray parenthesis is removed and a regression test now scans all ACME modules' SQL for unbalanced parentheses (the unit suite mocks the database, which is why a raw-SQL syntax error could slip through). One-line backend query fix; no schema, API, or agent changes — fully backward compatible.
|
||||
- **v1.8.4** (2026-06-27) — **Agent installer self-kill fix** (Issue #31): the Linux/macOS agent installer could abort during "pre-installation cleanup" (terminal showed `Killing processes matching: haproxy-agent` then `Killed`) when the install script's own filename contained "haproxy-agent". The cleanup killed processes by matching the bare string "haproxy-agent" against full command lines, which also matched the running installer (and a `sudo`/PAM ancestor the self-exclusion did not cover), so the installer terminated itself. Cleanup now targets only the installed agent (the `$INSTALL_DIR/haproxy-agent` binary and the agent service), never the bare string, and the UI now names the downloaded scripts `install-agent-<platform>.sh` / `uninstall-agent-<platform>.sh`. Installer-only change; the running agent and its privilege model (it runs as root for HAProxy reload, config writes, keepalived, and self-upgrade) are unchanged.
|
||||
- **v1.8.3** (2026-06-25) — **Agent heartbeat JSON fix** (Issue #31): a self-hosted agent could fail every heartbeat with `HTTP 400 Invalid JSON: Expecting property name enclosed in double quotes` when the system-info block it collects came back empty on an unusual host, leaving a stray comma in the hand-built heartbeat JSON. The agent script now substitutes a valid placeholder when that block is empty so it can no longer emit a stray comma, and the backend heartbeat endpoint now parses valid payloads as-is and, only when a body fails to parse, tolerates that specific malformed pattern (a leading or doubled comma) so an already-deployed agent recovers on its next heartbeat after this build is deployed. Backend + agent-script only; healthy agents of every version are byte-for-byte unaffected.
|
||||
- **v1.8.2** (2026-06-25) — **ACME nonce fix** (Issue #35 follow-up): the ACME client now scopes the anti-replay nonce **per certificate authority** so a nonce issued by one CA is never sent to another. This fixes ZeroSSL/Google account registration failing with `malformed: The Replay Nonce could not be base64url-decoded` (the client previously shared one nonce across CAs and only auto-retried on `badNonce`). Account registration now always uses a fresh nonce from the target CA, and the retry covers this case too. Backend-only; HTTP-01 and Let's Encrypt are unaffected.
|
||||
- **v1.8.1** (2026-06-24) — **ACME DNS-01 fixes** (Issue #35 follow-up): Cloudflare API tokens are now sanitized so a pasted token with quotes/spaces no longer fails with "Invalid request headers"; ZeroSSL/Google **External Account Binding (EAB)** can be entered per-account in the register dialog and EAB-required failures show a clear message; and **Apply Management** now categorizes cluster ACME enable/disable changes under their own "ACME Challenge Routing" section and **Apply/Reject All** correctly process them (previously "Rejected 0 HA/VIP change(s)"), consistent with every other entity. Fully backward compatible.
|
||||
- **v1.8.0** (2026-06-23) — **ACME DNS-01 challenge support** (Issue #35): Auto SSL can now validate via a **DNS TXT record** (`_acme-challenge.<domain>`) instead of HTTP-01 on port 80, enabling certificates for **internal/isolated clusters with no public ingress** and **wildcard** certificates (`*.example.com`). Pluggable **per-account DNS provider** (Manual + Cloudflare to start; credentials verified on save and **encrypted at rest**, never returned by the API or logged), the same **PENDING → APPLIED** pipeline, a **bounded automatic retry** on propagation lag, and a **DNS-01 event timeline** in the order detail. **Opt-in** via Settings → ACME (global switch, default off); **HTTP-01 is byte-for-byte unchanged**, with **zero agent or rendered-config changes**. Manual DNS-01 certificates cannot auto-renew unattended; the UI states this and disables auto-renew for them.
|
||||
|
||||
@@ -1,3 +1,123 @@
|
||||
# Upgrade Notes — v1.10.1 (CSR private key encrypted at rest)
|
||||
|
||||
**Backward compatible.** Nothing to do on upgrade, and nothing changes for existing clusters,
|
||||
agents or certificates:
|
||||
|
||||
- **Schema:** **no `SCHEMA_VERSION` bump and no migration.** The Fernet token replaces the PEM
|
||||
inside the *existing* `ssl_csrs.private_key_pem` TEXT column. As in v1.10.0, this means the
|
||||
four built-in roles are **not** re-seeded, so any customization of `super_admin` / `operator` /
|
||||
`security_admin` / `viewer` survives.
|
||||
- **Existing pending CSRs keep working.** Rows written before this release hold a raw PEM and are
|
||||
still read transparently, so a CSR that is already out for signature can be imported normally
|
||||
after the upgrade. There is no data migration and no downtime step. Those rows stay plaintext
|
||||
until they are imported (which NULLs the key) — if you want everything encrypted immediately,
|
||||
delete and re-create any long-pending CSRs.
|
||||
- **Scope:** this covers the PENDING CSR key only. It is the one key in the system that sits idle
|
||||
for the whole signing window and is never transmitted. `ssl_certificates.private_key_content`
|
||||
and the ACME order keys are unchanged, because agents must receive those in plaintext on every
|
||||
poll.
|
||||
- **Optional env:** `CSR_ENCRYPTION_KEY` (see `.env.template`). If unset, the key is derived from
|
||||
`SECRET_KEY` via HKDF with its own info string, so it is independent of the VIP, MFA and DNS
|
||||
provider keys.
|
||||
- **⚠️ Rotating `SECRET_KEY` while `CSR_ENCRYPTION_KEY` is unset makes pending CSR keys
|
||||
unrecoverable.** Import then fails with an explicit "delete this CSR and create a new one"
|
||||
error rather than a misleading key-mismatch. Set an explicit `CSR_ENCRYPTION_KEY` if you
|
||||
rotate `SECRET_KEY`. Certificates already imported are unaffected — their key lives on the
|
||||
certificate row.
|
||||
- **API / UI / agents:** unchanged. No CSR endpoint ever returned the private key before or now,
|
||||
and nothing about the CSR tab changes.
|
||||
- **Rollback:** the application downgrades cleanly — 1.10.0 starts normally against the same
|
||||
database and every other feature is unaffected. The one casualty is a CSR **created on 1.10.1
|
||||
and still pending**: 1.10.0 has no decrypt step, so it hands the Fernet token straight to the
|
||||
key-pairing check. Measured on a real downgrade, the import then fails with
|
||||
`HTTP 500 — Could not verify the certificate/key pair: key parse failed (encrypted?)`; it does
|
||||
**not** silently pair the wrong key, and it does not corrupt anything. Import or delete CSRs
|
||||
created on 1.10.1 before downgrading. Certificates already imported are unaffected, since their
|
||||
key lives on the certificate row, and CSRs created before 1.10.1 are plaintext and still work.
|
||||
|
||||
---
|
||||
|
||||
# Upgrade Notes — v1.10.0 (GoDaddy DNS-01 provider)
|
||||
|
||||
**Backward compatible & additive.** Nothing changes unless you select **GoDaddy** as an ACME
|
||||
account's DNS provider:
|
||||
|
||||
- **Schema:** **no `SCHEMA_VERSION` bump.** The GoDaddy credentials (API Key + Secret) are stored
|
||||
as two keys inside the *existing* encrypted
|
||||
`letsencrypt_account_dns_credentials.credentials_encrypted` blob — no new table, no new column,
|
||||
no migration.
|
||||
- **✅ Built-in roles are NOT re-seeded.** The re-seed warning in the v1.9.0 notes below is
|
||||
triggered by a `SCHEMA_VERSION` bump. This release does not bump it, so any customization you
|
||||
made to `super_admin` / `operator` / `security_admin` / `viewer` survives untouched.
|
||||
- **Permissions / API shape:** unchanged. `GET /api/letsencrypt/dns-providers` simply returns one
|
||||
extra entry in its `providers` array; every request and response shape is identical, and the
|
||||
credential form is rendered from that schema, so there is no frontend behaviour change either.
|
||||
- **Environment:** no new variable. GoDaddy credentials use the same Fernet-at-rest path as
|
||||
Cloudflare (`DNS_PROVIDER_ENCRYPTION_KEY`, falling back to a key derived from `SECRET_KEY`).
|
||||
- **Agents:** zero agent changes. DNS-01 is invisible to agents; an issued certificate follows the
|
||||
normal PENDING → Apply Management → agent pull pipeline exactly as before.
|
||||
- **Using it:** the API Key must be a **Production** key from `developer.godaddy.com/keys` (the
|
||||
first key that dashboard issues is an OTE/test key and is rejected), the zone must be in the same
|
||||
GoDaddy account, and that account needs at least one registered domain before GoDaddy permits DNS
|
||||
API access. A Personal Access Token also works — paste it as the Key and leave the Secret blank.
|
||||
Credentials are checked against the GoDaddy API before they are stored, so an invalid, OTE or
|
||||
ineligible key fails at save time. Note the check is a **read**: a Personal Access Token that has
|
||||
`domains.domain:read` but not `domains.dns:update` saves successfully and only fails at the first
|
||||
publish, with a 403 in the order timeline.
|
||||
- **Rollback:** don't select GoDaddy. Existing Manual and Cloudflare accounts and all HTTP-01
|
||||
issuance are untouched. **Downgrading after adopting GoDaddy is not a no-op**: on 1.9.0
|
||||
`godaddy` is not a known provider, so any account still set to it degrades to the manual-confirm
|
||||
path (in-flight DNS-01 orders wait for a confirmation nobody can give and expire after 48h, and
|
||||
renewals stop), and the cleanup sweep marks published TXT records cleaned without removing them.
|
||||
Before downgrading, switch affected accounts back to Manual or Cloudflare and let the reconcile
|
||||
sweep remove outstanding `_acme-challenge` records first. The stored credential row itself is
|
||||
inert — an encrypted blob for an unknown provider.
|
||||
|
||||
---
|
||||
|
||||
# Upgrade Notes — v1.9.0 (CSR creation)
|
||||
|
||||
**Backward compatible & additive.** Upgrading to v1.9.0 changes nothing for existing
|
||||
clusters/agents until you create a CSR:
|
||||
|
||||
- **Schema:** `SCHEMA_VERSION` bumps to `10`, so on first start the (idempotent)
|
||||
migration sequence re-runs once and adds **one new table** (`ssl_csrs`) plus its
|
||||
indexes. **No existing table is altered**, existing rows are untouched, and the
|
||||
**admin password is not reset** (the default-user seeding is guarded by an
|
||||
existence check, not an upsert). No new permission strings are introduced — all
|
||||
CSR endpoints are governed by the existing `ssl.create` / `ssl.read` /
|
||||
`ssl.delete` permissions.
|
||||
- **⚠️ Built-in roles are re-seeded to their defaults (pre-existing behaviour of
|
||||
every `SCHEMA_VERSION` bump — verified in a v1.8.10 → v1.9.0 upgrade drill).**
|
||||
Because the version gate re-runs the whole sequence, `update_system_roles_to_enterprise_rbac()`
|
||||
issues an unconditional `UPDATE roles SET … permissions = <defaults> WHERE name = …`
|
||||
for the four **built-in** roles (`super_admin`, `operator`, `security_admin`,
|
||||
`viewer`). **Any customization you made to a built-in role is reverted.** In the
|
||||
drill, an `operator` role that had been narrowed by removing `apply.execute` and
|
||||
`config.bulk_import` came back with both restored (57 → 59 permissions).
|
||||
- **Roles you created yourself are NOT affected** — the re-seed matches on the four
|
||||
built-in names only.
|
||||
- This is not new in v1.9.0: it happens on every release that bumps
|
||||
`SCHEMA_VERSION` (v1.7.0, v1.8.0, v1.8.8 …). It is documented as intentional at
|
||||
`backend/database/migrations.py` (the "BUMP THIS … OR seeded/role data" note) —
|
||||
the migration is treated as the authority on built-in-role contents.
|
||||
- **If you have hardened a built-in role, do this:** export it before upgrading
|
||||
(`GET /api/roles`), then re-apply your changes after the first start
|
||||
(`PUT /api/roles/{id}`) — or, preferably, move your customization into a
|
||||
purpose-made custom role, which survives every upgrade.
|
||||
- **Key storage:** CSR private keys are stored in the database like every other key
|
||||
in the system (`ssl_certificates.private_key_content` and the ACME order keys).
|
||||
The key is never returned by any CSR API endpoint, and after a successful import
|
||||
the CSR row's key copy is set to NULL (the key then lives only on the certificate
|
||||
row).
|
||||
- **Agents:** zero agent changes. Agents never read the new table; a CSR becomes
|
||||
visible to agents only after its signed certificate is imported **and** applied via
|
||||
Apply Management (the standard PENDING pipeline).
|
||||
- **Rollback:** simply don't use the CSR tab. The `ssl_csrs` table is inert when
|
||||
empty; downgrading the application leaves it as an ignored extra table.
|
||||
|
||||
---
|
||||
|
||||
# Upgrade Notes — v1.7.0 (HA / VIP Keepalived management, Issue #27)
|
||||
|
||||
**Backward compatible & opt-in.** Upgrading to v1.7.0 changes nothing for existing
|
||||
|
||||
+10
-2
@@ -37,5 +37,13 @@ USER appuser
|
||||
# Expose port
|
||||
EXPOSE 8000
|
||||
|
||||
# Run the application in production mode (without --reload)
|
||||
CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]
|
||||
# Run the application in production mode (without --reload).
|
||||
# UVICORN_WORKERS (default 1) opts into multiple worker processes on multi-core
|
||||
# hosts; with 1 worker uvicorn runs in-process, identical to the flagless CMD
|
||||
# this replaces. Falls back to WEB_CONCURRENCY when UVICORN_WORKERS is unset
|
||||
# because flagless uvicorn honored WEB_CONCURRENCY (uvicorn config.py) — this
|
||||
# keeps any deployment that relied on it byte-for-byte compatible. Background
|
||||
# tasks are multi-replica safe (FOR UPDATE SKIP LOCKED / advisory locks), as
|
||||
# already exercised by the k8s HPA deployment. `exec` keeps uvicorn as PID 1
|
||||
# so signal handling is unchanged.
|
||||
CMD ["sh", "-c", "exec uvicorn main:app --host 0.0.0.0 --port 8000 --workers ${UVICORN_WORKERS:-${WEB_CONCURRENCY:-1}}"]
|
||||
@@ -1,4 +1,4 @@
|
||||
from fastapi import HTTPException, status
|
||||
from fastapi import HTTPException, status, Header
|
||||
from typing import Optional, Dict, Any
|
||||
from jose import jwt
|
||||
import logging
|
||||
@@ -92,6 +92,18 @@ async def get_current_user_from_token(authorization: Optional[str] = None) -> Op
|
||||
detail="Authentication failed"
|
||||
)
|
||||
|
||||
async def require_authenticated_user(authorization: Optional[str] = Header(None)) -> Dict[str, Any]:
|
||||
"""FastAPI dependency: require a valid operator JWT, else 401.
|
||||
|
||||
Reads the Authorization header itself, so it can be attached at router or
|
||||
route level to gate operator/UI endpoints that must not be public:
|
||||
APIRouter(..., dependencies=[Depends(require_authenticated_user)])
|
||||
@router.get(..., dependencies=[Depends(require_authenticated_user)])
|
||||
Any authenticated user passes (no fine-grained RBAC here) — this restores the
|
||||
pre-existing "logged-in users only" expectation without changing role access.
|
||||
"""
|
||||
return await get_current_user_from_token(authorization)
|
||||
|
||||
async def get_current_user_from_token_no_exception(authorization: Optional[str] = None) -> Optional[Dict[str, Any]]:
|
||||
"""
|
||||
Get current user from JWT token without raising HTTPException.
|
||||
|
||||
@@ -194,7 +194,14 @@ async def ensure_agents_table():
|
||||
'use_backend_rules': "ALTER TABLE frontends ADD COLUMN use_backend_rules JSONB DEFAULT '[]'::jsonb;",
|
||||
'request_headers': "ALTER TABLE frontends ADD COLUMN request_headers TEXT;",
|
||||
'response_headers': "ALTER TABLE frontends ADD COLUMN response_headers TEXT;",
|
||||
'maxconn': "ALTER TABLE frontends ADD COLUMN maxconn INTEGER;"
|
||||
'maxconn': "ALTER TABLE frontends ADD COLUMN maxconn INTEGER;",
|
||||
# Issue #38: SPOE filter directives (e.g. Coraza WAF) and frontend
|
||||
# log-format were silently dropped on bulk-import / manual edit
|
||||
# because the parser recognised only a fixed set of directives.
|
||||
# These nullable TEXT columns persist them verbatim (multi-line for
|
||||
# `filters`), mirroring the request_headers/options passthrough.
|
||||
'log_format': "ALTER TABLE frontends ADD COLUMN log_format TEXT;",
|
||||
'filters': "ALTER TABLE frontends ADD COLUMN filters TEXT;"
|
||||
}
|
||||
|
||||
for col, query in frontend_columns.items():
|
||||
@@ -1741,7 +1748,17 @@ async def ensure_agent_activity_logs_table():
|
||||
# columns on letsencrypt_accounts/letsencrypt_orders/acme_challenges and the brand-new
|
||||
# letsencrypt_account_dns_credentials table (ensure_letsencrypt_dns_credentials step).
|
||||
# All additive + idempotent; default challenge_type 'http-01' keeps existing flows byte-identical.
|
||||
SCHEMA_VERSION = 8
|
||||
# v1.8.8 (Issue #38 — SPOE filter + frontend log-format): bumped 8 -> 9 for the additive
|
||||
# `log_format` + `filters` TEXT columns on `frontends` (frontend_columns loop). Without this
|
||||
# bump, already-deployed databases (version >= 8) skip the whole migration run and never gain
|
||||
# the columns, so the frontends SELECT/INSERT would fail. Additive + idempotent + nullable;
|
||||
# existing rows stay NULL and render byte-identical.
|
||||
# v1.9.0 (CSR creation): bumped 9 -> 10 for the brand-new `ssl_csrs` table
|
||||
# (ensure_ssl_csrs_table step). Holds a locally generated private key + CSR PEM
|
||||
# until the operator imports the CA-signed certificate; the import creates a
|
||||
# normal ssl_certificates row and NULLs the key copy here. Additive + idempotent;
|
||||
# no existing table is altered, agents never read this table.
|
||||
SCHEMA_VERSION = 10
|
||||
|
||||
|
||||
async def run_all_migrations():
|
||||
@@ -1878,12 +1895,84 @@ async def _run_all_migrations_inner():
|
||||
await ensure_mfa_columns()
|
||||
|
||||
# Issue #27 — HA/VIP Keepalived management (v1.7.0): two brand-new tables.
|
||||
# MUST stay last: FK-references haproxy_cluster_pools/agents/users, all created above.
|
||||
# MUST run after its FK targets (haproxy_cluster_pools/agents/users), all created above.
|
||||
await ensure_vip_tables()
|
||||
|
||||
# v1.9.0 — CSR creation: brand-new ssl_csrs table. FK-references
|
||||
# ssl_certificates/users, both created above.
|
||||
await ensure_ssl_csrs_table()
|
||||
|
||||
logger.info("Database migrations completed successfully.")
|
||||
|
||||
|
||||
async def ensure_ssl_csrs_table():
|
||||
"""v1.9.0 — CSR (Certificate Signing Request) creation. Additive only:
|
||||
one brand-new table (ssl_csrs) + indexes. No ALTER of any existing table,
|
||||
so the entire current fleet is byte-identical. Fully idempotent
|
||||
(CREATE TABLE/INDEX IF NOT EXISTS). FK targets (ssl_certificates, users)
|
||||
are created earlier in the sequence.
|
||||
|
||||
A CSR row holds a locally generated private key + CSR PEM until the
|
||||
operator imports the CA-signed certificate. The import creates a normal
|
||||
ssl_certificates row (source='csr', last_config_status='PENDING') and
|
||||
NULLs the private_key_pem copy here — the key then lives only on the
|
||||
certificate row, like every other key in the system. Agents never read
|
||||
this table: the agent SSL delivery endpoint selects from
|
||||
ssl_certificates only, so a pending CSR can never leak to an agent.
|
||||
"""
|
||||
conn = None
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
await conn.execute("""
|
||||
CREATE TABLE IF NOT EXISTS ssl_csrs (
|
||||
id SERIAL PRIMARY KEY,
|
||||
name VARCHAR(100) NOT NULL,
|
||||
common_name VARCHAR(253) NOT NULL,
|
||||
subject JSONB NOT NULL DEFAULT '{}'::jsonb,
|
||||
sans JSONB NOT NULL DEFAULT '[]'::jsonb,
|
||||
key_algorithm VARCHAR(20) NOT NULL DEFAULT 'rsa-2048',
|
||||
csr_pem TEXT NOT NULL,
|
||||
private_key_pem TEXT,
|
||||
status VARCHAR(20) NOT NULL DEFAULT 'pending',
|
||||
ssl_certificate_id INTEGER REFERENCES ssl_certificates(id) ON DELETE SET NULL,
|
||||
completed_at TIMESTAMP,
|
||||
created_by INTEGER REFERENCES users(id) ON DELETE SET NULL,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
CONSTRAINT ssl_csrs_status_check CHECK (status IN ('pending', 'completed'))
|
||||
);
|
||||
""")
|
||||
|
||||
# Only PENDING CSRs reserve their name: the name becomes the
|
||||
# ssl_certificates.name (and thus /etc/ssl/haproxy/{name}.pem on every
|
||||
# agent) at import time, so two open CSRs must not target the same
|
||||
# cert name. Completed CSRs are history and may share a name across
|
||||
# reissues — mirrors the uq_vip_name_active partial-index rationale.
|
||||
await conn.execute(
|
||||
"CREATE UNIQUE INDEX IF NOT EXISTS uq_ssl_csrs_name_pending ON ssl_csrs(name) WHERE status = 'pending';"
|
||||
)
|
||||
await conn.execute(
|
||||
"CREATE INDEX IF NOT EXISTS idx_ssl_csrs_status ON ssl_csrs(status);"
|
||||
)
|
||||
await conn.execute(
|
||||
"CREATE INDEX IF NOT EXISTS idx_ssl_csrs_cert ON ssl_csrs(ssl_certificate_id);"
|
||||
)
|
||||
|
||||
logger.info("ssl_csrs table ensured (v1.9.0 CSR creation)")
|
||||
except Exception as e:
|
||||
logger.error(f"Error ensuring ssl_csrs table: {e}")
|
||||
# Re-raise (ensure_ssl_cluster_junction_table precedent): this step is
|
||||
# part of the SCHEMA_VERSION=10 bump, and run_all_migrations() records
|
||||
# the marker only after the inner sequence completes cleanly. Swallowing
|
||||
# a failure here would stamp version 10 with no ssl_csrs table, and the
|
||||
# version gate would then skip every future retry — permanently.
|
||||
raise
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
|
||||
|
||||
async def ensure_mfa_columns():
|
||||
"""Issue #18 — TOTP MFA (v1.6.0): additive columns on users + 3 new tables.
|
||||
|
||||
|
||||
+9
-4
@@ -8,9 +8,13 @@ import redis
|
||||
import asyncio
|
||||
from datetime import datetime, timedelta
|
||||
|
||||
# Build/deploy marker for the v1.8.x (Issue #35, DNS-01) rollout — ensures the pipeline ships this commit's image.
|
||||
_version_info = {"version": "1.8.2", "releaseName": "ACME nonce fix (ZeroSSL registration)", "releaseDate": "2026-06-25"}
|
||||
for _vpath in ["/app/version.json", os.path.join(os.path.dirname(__file__), "..", "version.json")]:
|
||||
# Single source of truth: backend/version.json, which sits next to this module and is baked into
|
||||
# every image by `COPY . .` (build context ./backend) — no pipeline staging needed. The literal
|
||||
# below is only a last-resort "file missing" marker; it is deliberately NOT a real version so it can
|
||||
# never silently drift out of sync (this exact drift showed a stale version after v1.8.5/v1.8.6).
|
||||
# Keep the canonical version ONLY in backend/version.json — test_version_consistency.py enforces it.
|
||||
_version_info = {"version": "unknown", "releaseName": "unknown", "releaseDate": ""}
|
||||
for _vpath in [os.path.join(os.path.dirname(__file__), "version.json"), "/app/version.json"]:
|
||||
try:
|
||||
with open(_vpath) as _vf:
|
||||
_version_info = json.load(_vf)
|
||||
@@ -43,6 +47,7 @@ from routers.acme_diagnostics import router as acme_diagnostics_router
|
||||
from routers.site_wizard import router as site_wizard_router
|
||||
from routers.mfa import router as mfa_router
|
||||
from routers.vip import router as vip_router # Issue #27 — HA/VIP (Keepalived) management
|
||||
from routers.csr import router as csr_router # v1.9.0 — CSR creation (in-app key+CSR generation, signed-cert import)
|
||||
|
||||
# Production logging configuration
|
||||
from utils.logging_config import setup_production_logging
|
||||
@@ -318,7 +323,6 @@ async def complete_pending_acme_orders():
|
||||
OR dns01_last_attempt_at < NOW() - (
|
||||
(CASE COALESCE(dns01_attempts, 0) WHEN 0 THEN 15 WHEN 1 THEN 30 ELSE 60 END)
|
||||
|| ' minutes')::INTERVAL
|
||||
)
|
||||
)
|
||||
)
|
||||
)
|
||||
@@ -889,6 +893,7 @@ app.include_router(dashboard_stats_router) # HAProxy stats dashboard
|
||||
app.include_router(agent_router)
|
||||
app.include_router(waf_router)
|
||||
app.include_router(ssl_router)
|
||||
app.include_router(csr_router) # v1.9.0: CSR creation (in-app key+CSR generation, signed-cert import)
|
||||
app.include_router(security_router)
|
||||
app.include_router(configuration_router)
|
||||
app.include_router(settings_router)
|
||||
|
||||
@@ -0,0 +1,251 @@
|
||||
"""
|
||||
Pydantic models for the CSR (Certificate Signing Request) feature (v1.9.0).
|
||||
|
||||
A CSR row is the precursor of an ssl_certificates row: the backend generates
|
||||
the private key + CSR locally, the operator has the CSR signed by an external
|
||||
CA and then imports the signed certificate. The CSR `name` therefore obeys the
|
||||
exact same path-traversal contract as the SSL certificate name (Bulgu #21) —
|
||||
at import time it becomes /etc/ssl/haproxy/{name}.pem on every agent and is
|
||||
shell-processed by the agent script as root.
|
||||
|
||||
The import model deliberately has NO private key field: the key never leaves
|
||||
the server. It is stored on the ssl_csrs row at generation time and paired
|
||||
with the signed certificate server-side.
|
||||
"""
|
||||
|
||||
import re
|
||||
from typing import List, Optional
|
||||
|
||||
from pydantic import BaseModel, field_validator, model_validator
|
||||
|
||||
KEY_ALGORITHMS = ('rsa-2048', 'rsa-4096', 'ecdsa-p256', 'ecdsa-p384')
|
||||
|
||||
# RFC 1035 LDH hostname, lowercase, optional single leftmost wildcard label.
|
||||
# Single-label names are allowed (internal CAs routinely sign bare hostnames).
|
||||
_DNS_NAME_PATTERN = re.compile(
|
||||
r'^(\*\.)?[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?'
|
||||
r'(\.[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?)*$'
|
||||
)
|
||||
|
||||
# Reject control characters in free-text subject fields: they would be
|
||||
# persisted, echoed into the UI / issuer column, and printed into agent logs
|
||||
# via `openssl -subject` output.
|
||||
_CONTROL_CHARS_PATTERN = re.compile(r'[\x00-\x1f\x7f]')
|
||||
|
||||
_MAX_SANS = 100
|
||||
_MAX_CERT_PEM_BYTES = 64 * 1024 # a leaf certificate is ~2 KB; 64 KB is generous
|
||||
_MAX_CHAIN_PEM_BYTES = 256 * 1024 # agents re-download all cert content every poll
|
||||
|
||||
|
||||
def _validate_dns_name(value: str, field_label: str) -> str:
|
||||
v = (value or '').strip().lower()
|
||||
if not v:
|
||||
raise ValueError(f'{field_label} must not be empty')
|
||||
if len(v) > 253:
|
||||
raise ValueError(f'{field_label} must be 253 characters or fewer')
|
||||
if not _DNS_NAME_PATTERN.match(v):
|
||||
raise ValueError(
|
||||
f'{field_label} {value!r} is not a valid DNS name — lowercase '
|
||||
'letters, digits, hyphens and dots only; a wildcard is allowed '
|
||||
'only as the leftmost label (e.g. *.example.com).'
|
||||
)
|
||||
return v
|
||||
|
||||
|
||||
def _validate_subject_text(value: Optional[str], field_label: str, max_len: int = 64) -> Optional[str]:
|
||||
if value is None:
|
||||
return None
|
||||
v = value.strip()
|
||||
if not v:
|
||||
return None
|
||||
if len(v) > max_len:
|
||||
raise ValueError(f'{field_label} must be {max_len} characters or fewer')
|
||||
if _CONTROL_CHARS_PATTERN.search(v):
|
||||
raise ValueError(f'{field_label} must not contain control characters')
|
||||
return v
|
||||
|
||||
|
||||
def _validate_csr_name(v: str) -> str:
|
||||
"""Mirror of SSLCertificateCreate.validate_name_no_path_traversal (Bulgu #21)
|
||||
with one deliberate tightening: max length 100, matching the
|
||||
ssl_certificates.name VARCHAR(100) column (the historical 200-char limit
|
||||
overflows the column and 500s — not replicated here)."""
|
||||
if v is None:
|
||||
raise ValueError('CSR name is required')
|
||||
stripped = v.strip()
|
||||
if not stripped:
|
||||
raise ValueError('CSR name must not be empty')
|
||||
if stripped != v:
|
||||
raise ValueError('CSR name must not contain leading/trailing whitespace')
|
||||
if len(stripped) > 100:
|
||||
raise ValueError('CSR name must be 100 characters or fewer')
|
||||
if not re.match(r'^[A-Za-z0-9_.-]+$', stripped):
|
||||
raise ValueError(
|
||||
f'CSR name={v!r} contains forbidden characters — only letters, '
|
||||
'digits, underscore, hyphen, and dot are allowed (the name becomes '
|
||||
'a filename component under /etc/ssl/haproxy/ at import).'
|
||||
)
|
||||
if '..' in stripped:
|
||||
raise ValueError(f'CSR name={v!r} must not contain ".." (path traversal)')
|
||||
if stripped.startswith('.'):
|
||||
raise ValueError(f'CSR name={v!r} must not start with "." (hidden filename)')
|
||||
if stripped.startswith('-'):
|
||||
raise ValueError(f'CSR name={v!r} must not start with "-" (CLI flag confusion)')
|
||||
return stripped
|
||||
|
||||
|
||||
class SSLCSRCreate(BaseModel):
|
||||
name: str # becomes the certificate name at import
|
||||
common_name: str
|
||||
organization: Optional[str] = None # O
|
||||
organizational_unit: Optional[str] = None # OU
|
||||
locality: Optional[str] = None # L
|
||||
state: Optional[str] = None # ST
|
||||
country: Optional[str] = None # C — exactly 2 letters
|
||||
email: Optional[str] = None # emailAddress
|
||||
sans: List[str] = [] # DNS names; CN is auto-added server-side
|
||||
key_algorithm: str = 'rsa-2048'
|
||||
|
||||
@field_validator('name')
|
||||
@classmethod
|
||||
def validate_name(cls, v):
|
||||
return _validate_csr_name(v)
|
||||
|
||||
@field_validator('common_name')
|
||||
@classmethod
|
||||
def validate_common_name(cls, v):
|
||||
v = _validate_dns_name(v, 'Common Name')
|
||||
# RFC 5280 ub-common-name — many CAs reject CNs longer than 64 chars.
|
||||
if len(v) > 64:
|
||||
raise ValueError(
|
||||
'Common Name must be 64 characters or fewer (RFC 5280 upper '
|
||||
'bound) — put longer names in the SAN list instead.'
|
||||
)
|
||||
return v
|
||||
|
||||
@field_validator('sans')
|
||||
@classmethod
|
||||
def validate_sans(cls, v):
|
||||
if not v:
|
||||
return []
|
||||
if len(v) > _MAX_SANS:
|
||||
raise ValueError(f'At most {_MAX_SANS} SAN entries are allowed')
|
||||
seen = set()
|
||||
result = []
|
||||
for entry in v:
|
||||
normalised = _validate_dns_name(entry, 'SAN entry')
|
||||
if normalised not in seen:
|
||||
seen.add(normalised)
|
||||
result.append(normalised)
|
||||
return result
|
||||
|
||||
@field_validator('organization')
|
||||
@classmethod
|
||||
def validate_organization(cls, v):
|
||||
return _validate_subject_text(v, 'Organization (O)')
|
||||
|
||||
@field_validator('organizational_unit')
|
||||
@classmethod
|
||||
def validate_organizational_unit(cls, v):
|
||||
return _validate_subject_text(v, 'Organizational Unit (OU)')
|
||||
|
||||
@field_validator('locality')
|
||||
@classmethod
|
||||
def validate_locality(cls, v):
|
||||
return _validate_subject_text(v, 'Locality (L)')
|
||||
|
||||
@field_validator('state')
|
||||
@classmethod
|
||||
def validate_state(cls, v):
|
||||
return _validate_subject_text(v, 'State/Province (ST)')
|
||||
|
||||
@field_validator('country')
|
||||
@classmethod
|
||||
def validate_country(cls, v):
|
||||
# cryptography raises a bare ValueError for a non-2-char COUNTRY_NAME;
|
||||
# pre-validate so the operator gets a friendly 422 instead of a 500.
|
||||
if v is None:
|
||||
return None
|
||||
v = v.strip()
|
||||
if not v:
|
||||
return None
|
||||
if not re.match(r'^[A-Za-z]{2}$', v):
|
||||
raise ValueError('Country (C) must be exactly 2 letters (ISO 3166-1 alpha-2, e.g. TR, US)')
|
||||
return v.upper()
|
||||
|
||||
@field_validator('email')
|
||||
@classmethod
|
||||
def validate_email(cls, v):
|
||||
v = _validate_subject_text(v, 'Email', max_len=254)
|
||||
if v is not None and ('@' not in v or v.startswith('@') or v.endswith('@')):
|
||||
raise ValueError('Email must be a valid address (missing or misplaced "@")')
|
||||
return v
|
||||
|
||||
@field_validator('key_algorithm')
|
||||
@classmethod
|
||||
def validate_key_algorithm(cls, v):
|
||||
if v not in KEY_ALGORITHMS:
|
||||
raise ValueError(
|
||||
f'key_algorithm must be one of: {", ".join(KEY_ALGORITHMS)}'
|
||||
)
|
||||
return v
|
||||
|
||||
|
||||
class SSLCSRImport(BaseModel):
|
||||
"""Import the CA-signed certificate for a pending CSR. The private key is
|
||||
NOT part of the request — it is already stored on the CSR row."""
|
||||
certificate_content: str # PEM
|
||||
chain_content: Optional[str] = None # PEM, optional
|
||||
usage_type: str = 'frontend' # "frontend" or "server"
|
||||
is_global: bool = False
|
||||
cluster_ids: Optional[List[int]] = None
|
||||
# Escape hatch for name collisions that appeared AFTER the CSR was
|
||||
# created: overrides the CSR's reserved name for the certificate row.
|
||||
name: Optional[str] = None
|
||||
|
||||
@field_validator('certificate_content')
|
||||
@classmethod
|
||||
def validate_certificate(cls, v):
|
||||
if not v or not v.strip():
|
||||
raise ValueError('Certificate content is required')
|
||||
v = v.strip()
|
||||
if len(v.encode('utf-8', errors='ignore')) > _MAX_CERT_PEM_BYTES:
|
||||
raise ValueError('Certificate content exceeds the 64 KB limit')
|
||||
if '-----BEGIN CERTIFICATE-----' not in v or '-----END CERTIFICATE-----' not in v:
|
||||
raise ValueError('Certificate must be in PEM format')
|
||||
return v
|
||||
|
||||
@field_validator('chain_content')
|
||||
@classmethod
|
||||
def validate_chain(cls, v):
|
||||
if v and v.strip():
|
||||
v = v.strip()
|
||||
if len(v.encode('utf-8', errors='ignore')) > _MAX_CHAIN_PEM_BYTES:
|
||||
raise ValueError('Certificate chain exceeds the 256 KB limit')
|
||||
if '-----BEGIN CERTIFICATE-----' not in v or '-----END CERTIFICATE-----' not in v:
|
||||
raise ValueError('Certificate chain must be in PEM format')
|
||||
return v
|
||||
return None
|
||||
|
||||
@field_validator('usage_type')
|
||||
@classmethod
|
||||
def validate_usage_type(cls, v):
|
||||
if v not in ['frontend', 'server']:
|
||||
raise ValueError('usage_type must be either "frontend" or "server"')
|
||||
return v
|
||||
|
||||
@field_validator('name')
|
||||
@classmethod
|
||||
def validate_name(cls, v):
|
||||
if v is None or not str(v).strip():
|
||||
return None
|
||||
return _validate_csr_name(v)
|
||||
|
||||
@model_validator(mode='after')
|
||||
def validate_cluster_selection(self):
|
||||
if not self.is_global and not self.cluster_ids:
|
||||
raise ValueError(
|
||||
'cluster_ids is required when is_global is false — pick at '
|
||||
'least one cluster or import the certificate as global.'
|
||||
)
|
||||
return self
|
||||
+28
-45
@@ -85,6 +85,11 @@ class FrontendConfig(BaseModel):
|
||||
response_headers: Optional[str] = None
|
||||
options: Optional[str] = None
|
||||
tcp_request_rules: Optional[str] = None
|
||||
# Issue #38: SPOE filter directives (Coraza WAF etc.) + frontend log-format.
|
||||
# Passthrough TEXT (no validator) — SPOE `filter ... config <path>` legitimately
|
||||
# references an operator-managed file, so the ACL `-f` guard must NOT apply here.
|
||||
log_format: Optional[str] = None
|
||||
filters: Optional[str] = None
|
||||
timeout_client: Optional[int] = None
|
||||
timeout_http_request: Optional[int] = None
|
||||
rate_limit: Optional[int] = None
|
||||
@@ -451,26 +456,17 @@ class FrontendConfig(BaseModel):
|
||||
if any(dangerous in rule.lower() for dangerous in ['$(', '`']):
|
||||
raise ValueError(f'ACL rule contains potentially dangerous content: "{rule}"')
|
||||
|
||||
# Phase K Phase D follow-up (Bulgu #12 round 3) — reject
|
||||
# the HAProxy `-f <file>` pattern-file flag here too so the
|
||||
# manual Frontend API mirrors the wizard's parity rule.
|
||||
# HAProxy OpenManager does not provision pattern files
|
||||
# onto the HAProxy node filesystem, so any `-f /path/...`
|
||||
# reference will fail HAProxy's `-c` parse at apply time
|
||||
# with "failed to open pattern file". Reject up-front so
|
||||
# operators get the same actionable error from both the
|
||||
# manual page and the wizard.
|
||||
if re.search(r"(^|\s)-f(\s|$)", rule):
|
||||
raise ValueError(
|
||||
f'ACL rule "{rule}" uses the HAProxy `-f <file>` '
|
||||
"pattern-file flag, which is not supported in "
|
||||
"HAProxy OpenManager: the product does not "
|
||||
"provision pattern files onto the HAProxy node "
|
||||
"filesystem, so the reference would fail at "
|
||||
"reload time. Use inline values instead "
|
||||
"(e.g. `src 10.0.0.0/24` rather than "
|
||||
"`src -f /etc/haproxy/admins.lst`)."
|
||||
)
|
||||
# Issue #38 follow-up — the `-f <file>` pattern-file flag
|
||||
# is ACCEPTED here (the Bulgu #12 hard reject was removed).
|
||||
# Pattern files are operator-managed host files, exactly
|
||||
# like the SPOE `filter ... config <path>` reference this
|
||||
# release started preserving: bulk import always accepted
|
||||
# `-f`, the free-form fields (request_headers,
|
||||
# tcp_request_rules) always accepted it, and the agent
|
||||
# runs `haproxy -c` before every reload so a missing file
|
||||
# fails safely (previous config keeps running). The route
|
||||
# handlers surface a non-blocking warning listing the
|
||||
# referenced pattern files instead.
|
||||
|
||||
validated_rules.append(rule)
|
||||
|
||||
@@ -510,20 +506,12 @@ class FrontendConfig(BaseModel):
|
||||
if not any(rule.startswith(redirect_type) for redirect_type in valid_redirects):
|
||||
raise ValueError(f'Invalid redirect rule: "{rule}". Must start with: location, prefix, or scheme.')
|
||||
|
||||
# Phase K Phase D follow-up (Bulgu #12 round 3) —
|
||||
# mirror the wizard's `-f <file>` guard here. The
|
||||
# `X !X` contradiction check used to live alongside
|
||||
# this guard, but Bulgu #62 (round-22 audit) moved
|
||||
# it into the route handler so updates can grandfather
|
||||
# legacy rules created before the contradiction guard
|
||||
# landed. See `routers/frontend.py::_collect_routing_rule_contradictions`.
|
||||
if re.search(r"(^|\s)-f(\s|$)", rule):
|
||||
raise ValueError(
|
||||
f'Redirect rule "{rule}" uses the HAProxy `-f <file>` '
|
||||
"pattern-file flag, which is not supported in "
|
||||
"HAProxy OpenManager: the product does not provision "
|
||||
"pattern files onto the HAProxy node filesystem."
|
||||
)
|
||||
# Issue #38 follow-up — `-f <file>` pattern-file references
|
||||
# are ACCEPTED (Bulgu #12 hard reject removed; see
|
||||
# validate_acl_rules for the full rationale). The `X !X`
|
||||
# contradiction check lives in the route handler
|
||||
# (`routers/frontend.py::_collect_routing_rule_contradictions`,
|
||||
# Bulgu #62) and is unchanged.
|
||||
|
||||
validated_rules.append(rule)
|
||||
|
||||
@@ -531,9 +519,12 @@ class FrontendConfig(BaseModel):
|
||||
|
||||
@validator('use_backend_rules')
|
||||
def validate_use_backend_rules_syntax(cls, v):
|
||||
"""Phase K Phase D follow-up (Bulgu #12 round 3) — manual
|
||||
Frontend API parity guard: reject `-f <file>` references
|
||||
and dangerous shell patterns.
|
||||
"""Manual Frontend API guard for dangerous shell patterns.
|
||||
|
||||
Issue #38 follow-up — the Bulgu #12 `-f <file>` hard reject
|
||||
was removed (see validate_acl_rules for the rationale);
|
||||
pattern-file references are operator-managed host files and
|
||||
are surfaced as non-blocking warnings by the route handlers.
|
||||
|
||||
Bulgu #62 (round-22 audit) — the `X !X` contradiction check
|
||||
previously lived here but moved into the route handler so
|
||||
@@ -563,13 +554,5 @@ class FrontendConfig(BaseModel):
|
||||
f'use_backend rule contains potentially dangerous '
|
||||
f'content: "{rule}"'
|
||||
)
|
||||
if re.search(r"(^|\s)-f(\s|$)", rule):
|
||||
raise ValueError(
|
||||
f'use_backend rule "{rule}" uses the HAProxy '
|
||||
"`-f <file>` pattern-file flag, which is not "
|
||||
"supported in HAProxy OpenManager: the product "
|
||||
"does not provision pattern files onto the HAProxy "
|
||||
"node filesystem."
|
||||
)
|
||||
validated_rules.append(rule)
|
||||
return validated_rules
|
||||
@@ -179,35 +179,17 @@ _MAX_RULE_STRING_LEN = 4096
|
||||
# attempts.
|
||||
_DANGEROUS_RULE_PATTERNS = ("$(", "`")
|
||||
|
||||
# Phase K Phase D follow-up (Bulgu #12 round 3) — the HAProxy `-f
|
||||
# <file>` ACL/condition flag instructs HAProxy to load match patterns
|
||||
# from a server-side file at parse time. HAProxy OpenManager is a
|
||||
# fully-managed product: we do NOT provision pattern files onto the
|
||||
# HAProxy node's filesystem, and operators have no UI to upload one.
|
||||
# A `-f /some/path` reference therefore ALWAYS resolves to
|
||||
# "file not found" when HAProxy's real `-c` parse runs at apply
|
||||
# time, producing exactly the operator-reported failure mode:
|
||||
# [ALERT] parsing ACL 'acl1' : failed to open pattern file </path>.
|
||||
# [ALERT] parsing switching rule : no such ACL : 'acl1'.
|
||||
#
|
||||
# Surface this BEFORE persist by rejecting `-f` in any rule string
|
||||
# that comes through the wizard / manual frontend API. Reject ALL
|
||||
# variants (` -f `, leading `-f `, trailing `... -f`) defensively so
|
||||
# operators cannot slip the flag through with creative spacing.
|
||||
# The check is anchored to ACL/condition rule strings only; raw
|
||||
# HAProxy snippet fields (tcp_request_rules, request_headers, ...)
|
||||
# are NOT touched because those are inherently free-form and
|
||||
# advanced operators may legitimately reference pre-provisioned
|
||||
# pattern files there.
|
||||
_ACL_FILE_FLAG_PATTERN = re.compile(r"(^|\s)-f(\s|$)")
|
||||
_ACL_FILE_FLAG_MESSAGE = (
|
||||
"pattern-file references with '-f <file>' are not supported in ACL / "
|
||||
"use_backend / redirect rules: HAProxy OpenManager does not provision "
|
||||
"pattern files onto the HAProxy node's filesystem, so the reference "
|
||||
"would always fail at HAProxy reload time. Use inline values "
|
||||
"instead (e.g. `acl is_admin src 10.0.0.0/24` rather than "
|
||||
"`acl is_admin src -f /etc/haproxy/admins.lst`)."
|
||||
)
|
||||
# Issue #38 follow-up — the HAProxy `-f <file>` ACL/condition flag
|
||||
# loads match patterns from a file on the HAProxy host. The Bulgu #12
|
||||
# hard reject (`_ACL_FILE_FLAG_PATTERN`/`_ACL_FILE_FLAG_MESSAGE`) was
|
||||
# removed: pattern files are operator-managed host files (exactly like
|
||||
# the SPOE `filter ... config <path>` reference preserved since
|
||||
# v1.8.8), bulk import and the free-form fields (tcp_request_rules,
|
||||
# request_headers) always accepted them, and the agent runs
|
||||
# `haproxy -c` before every reload so a missing file fails safely
|
||||
# (the previous config keeps running). The manual frontend route
|
||||
# handlers emit a non-blocking warning listing referenced pattern
|
||||
# files (`routers/frontend.py::_pattern_file_warnings`).
|
||||
|
||||
# Phase K Phase D follow-up (Bulgu #13) — detect a routing /
|
||||
# redirect rule whose condition references the SAME ACL in both
|
||||
@@ -305,13 +287,10 @@ def _validate_haproxy_directive_string(
|
||||
f"{field_label} entry contains potentially dangerous content: "
|
||||
f"{pattern!r}"
|
||||
)
|
||||
# Phase K Phase D follow-up (Bulgu #12 round 3) — reject the
|
||||
# HAProxy `-f <file>` pattern-file flag because OpenManager does
|
||||
# not manage the HAProxy node filesystem. See the module-level
|
||||
# `_ACL_FILE_FLAG_PATTERN` docstring for the full operator-
|
||||
# reported failure mode this guards against.
|
||||
if _ACL_FILE_FLAG_PATTERN.search(stripped):
|
||||
raise ValueError(f"{field_label}: {_ACL_FILE_FLAG_MESSAGE}")
|
||||
# Issue #38 follow-up — `-f <file>` pattern-file references are
|
||||
# ACCEPTED (Bulgu #12 hard reject removed; see the module-level
|
||||
# `_ACL_FILE_FLAG_PATTERN` comment). The route handlers surface
|
||||
# a non-blocking pattern-file warning instead.
|
||||
# Phase K Phase D follow-up (Bulgu #13) — for routing /
|
||||
# redirect rules (not ACL definitions themselves), reject a
|
||||
# condition that contains the same ACL in both positive and
|
||||
@@ -1083,21 +1062,12 @@ class FrontendStep(BaseModel):
|
||||
normalised: List[Union[str, dict]] = []
|
||||
for el in v:
|
||||
if isinstance(el, dict):
|
||||
# Phase K Phase D follow-up (Bulgu #12 round 3
|
||||
# extension) — dict-shaped redirect rules emit their
|
||||
# `condition` / `target` fields VERBATIM into the
|
||||
# rendered HAProxy directive. A dict with
|
||||
# `condition: "if { src -f /etc/haproxy/x.lst }"`
|
||||
# would slip past the string-only validator above
|
||||
# and trigger the same operator-reported "failed to
|
||||
# open pattern file" rejection at apply time. Reject
|
||||
# `-f` in any string-shaped value the dict carries.
|
||||
for field_name in ("condition", "target", "type"):
|
||||
val = el.get(field_name)
|
||||
if isinstance(val, str) and _ACL_FILE_FLAG_PATTERN.search(val):
|
||||
raise ValueError(
|
||||
f"redirect_rules.{field_name}: {_ACL_FILE_FLAG_MESSAGE}"
|
||||
)
|
||||
# Issue #38 follow-up — dict-shaped redirect rules may
|
||||
# carry `-f <file>` pattern-file references in their
|
||||
# `condition`/`target` values; these are ACCEPTED now
|
||||
# (Bulgu #12 hard reject removed — operator-managed
|
||||
# host files, fail-safe apply; see module-level
|
||||
# `_ACL_FILE_FLAG_PATTERN` comment).
|
||||
# Bulgu #13 extension — same contradiction guard
|
||||
# for dict-shaped redirect conditions.
|
||||
cond_val = el.get("condition")
|
||||
|
||||
+206
-125
@@ -29,6 +29,40 @@ AGENT_VERSIONS = {
|
||||
"linux": "2.0.0"
|
||||
}
|
||||
|
||||
|
||||
def _sanitize_agent_json(body_str: str):
|
||||
"""Repair the common malformed-JSON patterns a hand-built agent heartbeat can emit.
|
||||
|
||||
Agents assemble their heartbeat JSON as text in bash, so an empty interpolated value can leave
|
||||
a structurally-invalid comma (issue #31). Returns (possibly_repaired_str, was_changed). The
|
||||
repairs are conservative and target only structural artifacts an agent produces; they never
|
||||
alter this endpoint's legitimate string values (the agent emits no string containing ',,' —
|
||||
haproxy_stats_csv is base64/comma-free and the rest are constrained os/kernel/ip/version text).
|
||||
"""
|
||||
import re
|
||||
sanitized = False
|
||||
# Fix 1: empty value before a comma ("server_statuses": ,)
|
||||
if re.search(r':\s*,', body_str):
|
||||
body_str = re.sub(r':\s*,', ': null,', body_str); sanitized = True
|
||||
# Fix 2: empty value before a closing brace ("field":})
|
||||
if re.search(r':\s*}', body_str):
|
||||
body_str = re.sub(r':\s*}', ': null}', body_str); sanitized = True
|
||||
# Fix 3: trailing comma before } or ]
|
||||
if re.search(r',(\s*[}\]])', body_str):
|
||||
body_str = re.sub(r',(\s*[}\]])', r'\1', body_str); sanitized = True
|
||||
# Fix 4: leading comma run right after an opening brace/bracket (issue #31): an empty
|
||||
# $system_info as the first member collapses to '{ , "name": ...'. The ': ,' fix above cannot
|
||||
# catch this because there is no key/colon before the comma.
|
||||
if re.search(r'([{\[])(\s*,)+', body_str):
|
||||
body_str = re.sub(r'([{\[])(\s*,)+', r'\1', body_str); sanitized = True
|
||||
# Fix 5: a run of commas between members (issue #31): an empty $system_info between two fields
|
||||
# produces '"version": "x",\n ,\n "haproxy_status": ...'. Runs after Fix 1/3 so only
|
||||
# structural commas remain; collapse any comma run to a single comma.
|
||||
if re.search(r',(\s*,)+', body_str):
|
||||
body_str = re.sub(r',(\s*,)+', ',', body_str); sanitized = True
|
||||
return body_str, sanitized
|
||||
|
||||
|
||||
def get_platform_key(agent_platform: str) -> str:
|
||||
"""Convert agent platform to standardized platform key - fixed empty platform fallback"""
|
||||
platform = agent_platform.lower() if agent_platform else 'unknown'
|
||||
@@ -217,7 +251,7 @@ def calculate_agent_health(status, last_seen):
|
||||
return "offline"
|
||||
|
||||
@router.get("", summary="Get All Agents", response_description="List of all agents")
|
||||
async def get_agents(pool_id: Optional[int] = None, authorization: str = Header(None)):
|
||||
async def get_agents(pool_id: Optional[int] = None, authorization: str = Header(None), x_api_key: Optional[str] = Header(None)):
|
||||
"""
|
||||
# Get All Agents
|
||||
|
||||
@@ -269,9 +303,22 @@ async def get_agents(pool_id: Optional[int] = None, authorization: str = Header(
|
||||
- **haproxy_status**: Status of HAProxy service on agent's server
|
||||
- **last_seen**: Last heartbeat timestamp
|
||||
"""
|
||||
# SECURITY (GHSA-3p5c-m5m4-mjpx): the agent inventory (names, hostnames, IPs,
|
||||
# pools, OS) is operator data and was previously served unauthenticated — it is
|
||||
# also the read-back channel used in the RCE exfil PoC. Require EITHER a valid
|
||||
# operator JWT OR a valid agent X-API-Key: deployed agents poll this endpoint
|
||||
# (with their key, not a JWT) to read their own applied_config_version and avoid
|
||||
# re-applying config on restart, so a JWT-only gate would break them. Checked
|
||||
# before the try so the 401 is not swallowed by the generic handler.
|
||||
if authorization:
|
||||
current_user = await get_current_user_from_token(authorization) # raises 401 on invalid JWT
|
||||
else:
|
||||
from auth_middleware import validate_agent_api_key
|
||||
if not await validate_agent_api_key(x_api_key):
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
|
||||
try:
|
||||
if pool_id:
|
||||
agents = await conn.fetch("""
|
||||
@@ -729,6 +776,14 @@ async def generate_uninstall_script(platform: str, authorization: str = Header(N
|
||||
sudo ./uninstall-agent.sh
|
||||
```
|
||||
"""
|
||||
# SECURITY (GHSA-3p5c-m5m4-mjpx): require authentication (operator JWT or agent
|
||||
# key), consistent with generate-install-script. The uninstall script itself is
|
||||
# generic (no secrets/topology), but an agent-management endpoint should not be
|
||||
# anonymously reachable. Checked before the try so the 401 is not swallowed.
|
||||
if authorization:
|
||||
await get_current_user_from_token(authorization)
|
||||
elif not await validate_agent_api_key(x_api_key):
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
# Normalize platform to a canonical key (always 'linux' or 'macos').
|
||||
# macOS agents register with platform 'darwin' (from `uname -s`), so the
|
||||
@@ -924,14 +979,24 @@ def _extract_agent_ip(heartbeat_data: AgentHeartbeat) -> Optional[str]:
|
||||
return None
|
||||
|
||||
@router.post("/{agent_id}/heartbeat")
|
||||
async def agent_heartbeat(agent_id: int, heartbeat_data: AgentHeartbeat):
|
||||
async def agent_heartbeat(agent_id: int, heartbeat_data: AgentHeartbeat, x_api_key: Optional[str] = Header(None)):
|
||||
"""Receive agent heartbeat and update status."""
|
||||
# Agent authentication is MANDATORY (GHSA-3p5c-m5m4-mjpx). This legacy by-ID
|
||||
# heartbeat previously had NO auth, allowing unauthenticated state spoofing of
|
||||
# any agent row. Deployed agents use the by-name heartbeat; a valid global
|
||||
# agent token is now required here too. NOTE: raised BEFORE the try below so
|
||||
# the 401 is not swallowed by the generic `except Exception` handler.
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key on by-id heartbeat for agent ID {agent_id}")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
|
||||
await conn.execute("""
|
||||
UPDATE agents
|
||||
SET status = 'online',
|
||||
UPDATE agents
|
||||
SET status = 'online',
|
||||
last_seen = CURRENT_TIMESTAMP,
|
||||
hostname = COALESCE($2, hostname),
|
||||
haproxy_status = COALESCE($3, haproxy_status),
|
||||
@@ -1054,6 +1119,8 @@ async def agent_config_applied_notification(agent_name: str, notification_data:
|
||||
await close_database_connection(conn)
|
||||
return {"status": "ok", "message": "Config applied notification received"}
|
||||
|
||||
except HTTPException:
|
||||
raise # let auth 401/403 propagate (do not turn it into a 200 error body)
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to process config applied notification from agent '{agent_name}': {e}")
|
||||
return {"status": "error", "message": str(e)}
|
||||
@@ -1149,6 +1216,8 @@ async def agent_config_validation_failed(agent_name: str, notification_data: dic
|
||||
|
||||
return {"status": "ok", "message": "Validation error notification received"}
|
||||
|
||||
except HTTPException:
|
||||
raise # let auth 401/403 propagate (do not turn it into a 200 error body)
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to process validation error notification from agent '{agent_name}': {e}")
|
||||
return {"status": "error", "message": str(e)}
|
||||
@@ -1438,6 +1507,8 @@ async def agent_config_sync(agent_name: str, sync_data: dict, x_api_key: Optiona
|
||||
logger.info(f"CONFIG SYNC: Agent '{agent_name}' synced {len(active_backends)} backends, {len(active_frontends)} frontends, {len(active_servers)} servers with database")
|
||||
return {"status": "ok", "message": f"Config synced - {len(active_backends)} backends, {len(active_frontends)} frontends, {len(active_servers)} servers processed"}
|
||||
|
||||
except HTTPException:
|
||||
raise # let auth 401/403 propagate (do not turn it into a 200 error body)
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to process config sync from agent '{agent_name}': {e}")
|
||||
return {"status": "error", "message": str(e)}
|
||||
@@ -1455,47 +1526,33 @@ async def agent_heartbeat_by_name(
|
||||
import json
|
||||
from pydantic import ValidationError
|
||||
|
||||
# Read raw body and sanitize common JSON errors from agents
|
||||
# Read raw body. Parse VALID JSON as-is (the normal case for every agent version) and only
|
||||
# fall back to the malformed-JSON repair when the body does not parse. This guarantees a healthy
|
||||
# heartbeat from any agent version is byte-for-byte untouched — the repair regexes can never run
|
||||
# against a well-formed payload (issue #31; strictly safer than repairing unconditionally).
|
||||
try:
|
||||
raw_body = await request.body()
|
||||
body_str = raw_body.decode('utf-8')
|
||||
|
||||
# Sanitize common malformed JSON patterns from agents
|
||||
original_body = body_str
|
||||
sanitized = False
|
||||
|
||||
# Fix 1: Empty values before comma (most common: "server_statuses": ,)
|
||||
if re.search(r':\s*,', body_str):
|
||||
body_str = re.sub(r':\s*,', ': null,', body_str)
|
||||
sanitized = True
|
||||
|
||||
# Fix 2: Empty values before closing brace
|
||||
if re.search(r':\s*}', body_str):
|
||||
body_str = re.sub(r':\s*}', ': null}', body_str)
|
||||
sanitized = True
|
||||
|
||||
# Fix 3: Trailing commas
|
||||
if re.search(r',(\s*[}\]])', body_str):
|
||||
body_str = re.sub(r',(\s*[}\]])', r'\1', body_str)
|
||||
sanitized = True
|
||||
|
||||
if sanitized:
|
||||
# Extract agent name for logging
|
||||
agent_name = "unknown"
|
||||
try:
|
||||
name_match = re.search(r'"name"\s*:\s*"([^"]+)"', body_str)
|
||||
if name_match:
|
||||
agent_name = name_match.group(1)
|
||||
except:
|
||||
pass
|
||||
|
||||
logger.info(f"Sanitized malformed JSON from agent '{agent_name}' - fixed empty values and trailing commas")
|
||||
logger.debug(f"Original JSON (preview): {original_body[:300]}")
|
||||
logger.debug(f"Sanitized JSON (preview): {body_str[:300]}")
|
||||
|
||||
# Parse sanitized JSON into Pydantic model
|
||||
heartbeat_dict = json.loads(body_str)
|
||||
|
||||
|
||||
try:
|
||||
heartbeat_dict = json.loads(body_str)
|
||||
except json.JSONDecodeError:
|
||||
# Malformed body (would otherwise be a hard 400). Attempt a conservative repair of the
|
||||
# comma artifacts a hand-built agent heartbeat can emit, then re-parse.
|
||||
repaired, changed = _sanitize_agent_json(body_str)
|
||||
if changed:
|
||||
agent_name = "unknown"
|
||||
try:
|
||||
name_match = re.search(r'"name"\s*:\s*"([^"]+)"', repaired)
|
||||
if name_match:
|
||||
agent_name = name_match.group(1)
|
||||
except Exception:
|
||||
pass
|
||||
logger.info(f"Repaired malformed JSON from agent '{agent_name}' before parsing")
|
||||
logger.debug(f"Original JSON (preview): {body_str[:300]}")
|
||||
logger.debug(f"Repaired JSON (preview): {repaired[:300]}")
|
||||
heartbeat_dict = json.loads(repaired) # may still raise -> handled as 400 below
|
||||
|
||||
# DEBUG: Log cluster_id for auto-register troubleshooting
|
||||
if heartbeat_dict.get('name'):
|
||||
logger.info(f"HEARTBEAT DEBUG: agent={heartbeat_dict.get('name')}, cluster_id={heartbeat_dict.get('cluster_id')}, has_cluster_id={bool(heartbeat_dict.get('cluster_id'))}")
|
||||
@@ -1512,21 +1569,25 @@ async def agent_heartbeat_by_name(
|
||||
logger.error(f"Unexpected error processing heartbeat: {e}")
|
||||
raise HTTPException(status_code=500, detail="Internal server error")
|
||||
|
||||
# Agent authentication is MANDATORY (GHSA-3p5c-m5m4-mjpx). A valid global agent
|
||||
# token is required to heartbeat OR auto-register. Deployed agents always send
|
||||
# X-API-Key; an absent/invalid key is an unauthenticated caller. This is done
|
||||
# OUTSIDE the processing try below (whose generic `except Exception` would
|
||||
# otherwise convert the 401 into a 500), and before opening a DB connection
|
||||
# (validate_agent_api_key(None) needs no DB). Closes keyless heartbeat spoofing
|
||||
# and keyless rogue-agent auto-registration (the `elif not agent` keyless path
|
||||
# below is now unreachable, since agent_auth is guaranteed truthy past here).
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key on heartbeat for agent '{heartbeat_data.name}'")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
|
||||
# Continue with normal heartbeat processing
|
||||
try:
|
||||
# Validate agent API key for security
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
|
||||
conn = await get_database_connection()
|
||||
agent_name = heartbeat_data.name
|
||||
|
||||
# If API key provided, validate it exists but allow placeholder agent updates
|
||||
if x_api_key and not agent_auth:
|
||||
await close_database_connection(conn)
|
||||
logger.warning(f"Invalid API key provided by agent '{agent_name}'")
|
||||
raise HTTPException(status_code=401, detail="Invalid API key")
|
||||
|
||||
agent = await conn.fetchrow("SELECT id, pool_id, api_key FROM agents WHERE name = $1", agent_name)
|
||||
|
||||
# If agent exists and is using a different API key, update the token association
|
||||
@@ -1675,9 +1736,13 @@ async def agent_heartbeat_by_name(
|
||||
""", x_api_key)
|
||||
|
||||
# Check if agent was in upgrading status and version has changed
|
||||
current_agent_status = await conn.fetchval("SELECT status FROM agents WHERE id = $1", agent_id)
|
||||
current_agent_version = await conn.fetchval("SELECT version FROM agents WHERE id = $1", agent_id)
|
||||
current_upgrade_status = await conn.fetchval("SELECT upgrade_status FROM agents WHERE id = $1", agent_id)
|
||||
# (v1.8.6: one round-trip instead of three; row is None exactly when the
|
||||
# per-column fetchvals would each have returned None)
|
||||
current_agent_row = await conn.fetchrow(
|
||||
"SELECT status, version, upgrade_status FROM agents WHERE id = $1", agent_id)
|
||||
current_agent_status = current_agent_row['status'] if current_agent_row else None
|
||||
current_agent_version = current_agent_row['version'] if current_agent_row else None
|
||||
current_upgrade_status = current_agent_row['upgrade_status'] if current_agent_row else None
|
||||
|
||||
# Determine new status - preserve upgrading status unless version actually changed
|
||||
new_status = current_agent_status or 'online'
|
||||
@@ -1931,9 +1996,19 @@ async def agent_heartbeat_by_name(
|
||||
@router.get("/{agent_name}/config")
|
||||
async def get_agent_config(agent_name: str, x_api_key: Optional[str] = Header(None)):
|
||||
"""Get HAProxy configuration for specific agent"""
|
||||
# Validate agent API key — MANDATORY (GHSA-3p5c-m5m4-mjpx). Checked BEFORE any
|
||||
# DB work and before the existence check, so an unauthenticated caller learns
|
||||
# neither the full haproxy.cfg nor whether the agent exists. Raised before the
|
||||
# try so it is not swallowed by the generic handler; validate_agent_api_key(None)
|
||||
# returns None without touching the DB.
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key for agent '{agent_name}' config fetch")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
|
||||
# Get agent info first to check pool
|
||||
# CRITICAL: Include cluster's haproxy_bin_path, haproxy_config_path, stats_socket_path
|
||||
# These are needed for dynamic validation - cluster admin can change paths without reinstalling agent
|
||||
@@ -1945,30 +2020,19 @@ async def get_agent_config(agent_name: str, x_api_key: Optional[str] = Header(No
|
||||
LEFT JOIN haproxy_clusters hc ON hc.pool_id = a.pool_id
|
||||
WHERE a.name = $1
|
||||
""", agent_name)
|
||||
|
||||
|
||||
if not agent_info:
|
||||
await close_database_connection(conn)
|
||||
raise HTTPException(status_code=404, detail=f"Agent '{agent_name}' not found")
|
||||
|
||||
# Validate agent API key
|
||||
# API key is global - can be used for multiple agents
|
||||
if x_api_key:
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
|
||||
if not agent_auth:
|
||||
await close_database_connection(conn)
|
||||
logger.warning(f"Invalid API key provided for agent '{agent_name}' config fetch")
|
||||
raise HTTPException(status_code=401, detail="Invalid API key")
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.info(f"Agent '{agent_name}' fetching config using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' fetching config using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"Config fetch authorized for agent '{agent_name}'")
|
||||
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.info(f"Agent '{agent_name}' fetching config using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' fetching config using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"Config fetch authorized for agent '{agent_name}'")
|
||||
|
||||
if not agent_info['enabled']:
|
||||
await close_database_connection(conn)
|
||||
return {
|
||||
@@ -2059,9 +2123,18 @@ async def get_agent_config(agent_name: str, x_api_key: Optional[str] = Header(No
|
||||
@router.get("/{agent_name}/ssl-certificates")
|
||||
async def get_agent_ssl_certificates(agent_name: str, since: Optional[str] = None, x_api_key: Optional[str] = Header(None)):
|
||||
"""Get SSL certificates for specific agent's cluster"""
|
||||
# Validate agent API key — MANDATORY (GHSA-3p5c-m5m4-mjpx). This response
|
||||
# returns SSL private_key_content, so authentication is checked BEFORE any DB
|
||||
# work and before the existence check. Raised before the try so the 401 is not
|
||||
# swallowed; validate_agent_api_key(None) returns None without a DB hit.
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key for agent '{agent_name}' SSL certificates")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
|
||||
# Get agent and cluster info first
|
||||
agent_info = await conn.fetchrow("""
|
||||
SELECT a.id, a.name, a.pool_id, hc.id as cluster_id, hc.name as cluster_name,
|
||||
@@ -2070,29 +2143,18 @@ async def get_agent_ssl_certificates(agent_name: str, since: Optional[str] = Non
|
||||
LEFT JOIN haproxy_clusters hc ON hc.pool_id = a.pool_id
|
||||
WHERE a.name = $1
|
||||
""", agent_name)
|
||||
|
||||
|
||||
if not agent_info:
|
||||
await close_database_connection(conn)
|
||||
raise HTTPException(status_code=404, detail=f"Agent '{agent_name}' not found")
|
||||
|
||||
# Validate agent API key
|
||||
# API key is global - can be used for multiple agents
|
||||
if x_api_key:
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
|
||||
if not agent_auth:
|
||||
await close_database_connection(conn)
|
||||
logger.warning(f"Invalid API key provided for agent '{agent_name}' SSL certificates")
|
||||
raise HTTPException(status_code=401, detail="Invalid API key")
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.info(f"Agent '{agent_name}' fetching SSL certificates using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' fetching SSL certificates using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"SSL fetch authorized for agent '{agent_name}'")
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.info(f"Agent '{agent_name}' fetching SSL certificates using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' fetching SSL certificates using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"SSL fetch authorized for agent '{agent_name}'")
|
||||
|
||||
if not agent_info['enabled']:
|
||||
await close_database_connection(conn)
|
||||
@@ -2416,16 +2478,24 @@ async def get_latest_script_version(platform: str = "macos"):
|
||||
@router.get("/{agent_name}/upgrade-status")
|
||||
async def get_agent_upgrade_status(agent_name: str, x_api_key: Optional[str] = Header(None)):
|
||||
"""Get agent upgrade status - used by agents to check if they should upgrade"""
|
||||
# Validate agent API key — MANDATORY (GHSA-3p5c-m5m4-mjpx). Checked before any
|
||||
# DB work; deployed agents always send X-API-Key. Raised before the try so the
|
||||
# 401 is not swallowed; validate_agent_api_key(None) returns None without a DB hit.
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key for agent '{agent_name}' upgrade status")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
|
||||
|
||||
# Check if agent has upgrade pending (include platform and pool for validation)
|
||||
agent = await conn.fetchrow("""
|
||||
SELECT status, version as current_version, platform, pool_id
|
||||
FROM agents
|
||||
FROM agents
|
||||
WHERE name = $1
|
||||
""", agent_name)
|
||||
|
||||
|
||||
if not agent:
|
||||
await close_database_connection(conn)
|
||||
return {
|
||||
@@ -2433,26 +2503,15 @@ async def get_agent_upgrade_status(agent_name: str, x_api_key: Optional[str] = H
|
||||
"target_version": "",
|
||||
"message": "Agent not found"
|
||||
}
|
||||
|
||||
# Validate agent API key
|
||||
# API key is global - can be used for multiple agents
|
||||
if x_api_key:
|
||||
from auth_middleware import validate_agent_api_key
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
|
||||
if not agent_auth:
|
||||
await close_database_connection(conn)
|
||||
logger.warning(f"Invalid API key provided for agent '{agent_name}' upgrade status")
|
||||
raise HTTPException(status_code=401, detail="Invalid API key")
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.debug(f"Agent '{agent_name}' checking upgrade status using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' checking upgrade status using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"Upgrade status check authorized for agent '{agent_name}'")
|
||||
|
||||
|
||||
# Log which agent's API key was used (for audit trail)
|
||||
if agent_auth['name'] == agent_name:
|
||||
logger.debug(f"Agent '{agent_name}' checking upgrade status using its own API key")
|
||||
else:
|
||||
logger.info(f"Agent '{agent_name}' checking upgrade status using API key from agent '{agent_auth['name']}'")
|
||||
|
||||
logger.debug(f"Upgrade status check authorized for agent '{agent_name}'")
|
||||
|
||||
await close_database_connection(conn)
|
||||
|
||||
# Agent should upgrade if status is 'upgrading'
|
||||
@@ -2886,7 +2945,17 @@ async def get_agent_script_template(platform: str, authorization: str = Header(N
|
||||
"""Get the latest script template for specified platform from database"""
|
||||
try:
|
||||
current_user = await get_current_user_from_token(authorization)
|
||||
|
||||
|
||||
# SECURITY (GHSA-7rhv-c5pc-69r8): the raw install/upgrade script is a
|
||||
# version-management surface. Gate reads with agents.version too, matching
|
||||
# the write path above (operator/security_admin/super_admin retain access).
|
||||
has_permission = await check_user_permission(current_user["id"], "agents", "version")
|
||||
if not has_permission:
|
||||
raise HTTPException(
|
||||
status_code=403,
|
||||
detail="Insufficient permissions: agents.version required"
|
||||
)
|
||||
|
||||
conn = await get_database_connection()
|
||||
|
||||
# Get latest script template for platform
|
||||
@@ -2937,7 +3006,19 @@ async def save_agent_script_template(platform: str, template_data: dict, authori
|
||||
"""Save updated script template to database using shared helper function"""
|
||||
try:
|
||||
current_user = await get_current_user_from_token(authorization)
|
||||
|
||||
|
||||
# SECURITY (GHSA-7rhv-c5pc-69r8): agent script templates become the
|
||||
# install/self-upgrade script executed as root on HAProxy nodes. A poisoned
|
||||
# template is RCE. Authentication alone is NOT enough — require the same
|
||||
# agents.version permission as POST /versions; otherwise any JWT holder
|
||||
# (including viewer) could overwrite the active script.
|
||||
has_permission = await check_user_permission(current_user["id"], "agents", "version")
|
||||
if not has_permission:
|
||||
raise HTTPException(
|
||||
status_code=403,
|
||||
detail="Insufficient permissions: agents.version required"
|
||||
)
|
||||
|
||||
script_content = template_data.get('script_content', '')
|
||||
version = template_data.get('version', '')
|
||||
|
||||
|
||||
@@ -3696,17 +3696,19 @@ async def confirm_restore_config_version(
|
||||
# UPDATE existing frontend (ALL 8 parsed fields)
|
||||
# CRITICAL FIX: Include maxconn and timeout_client so UI shows restored values
|
||||
await conn.execute("""
|
||||
UPDATE frontends
|
||||
SET bind_address = $1, bind_port = $2, default_backend = $3,
|
||||
UPDATE frontends
|
||||
SET bind_address = $1, bind_port = $2, default_backend = $3,
|
||||
mode = $4, ssl_enabled = $5, ssl_port = $6,
|
||||
maxconn = $7, timeout_client = $8,
|
||||
log_format = $11, filters = $12,
|
||||
updated_at = CURRENT_TIMESTAMP, last_config_status = 'PENDING'
|
||||
WHERE id = $9 AND cluster_id = $10
|
||||
""",
|
||||
""",
|
||||
parsed_fe.bind_address, parsed_fe.bind_port, parsed_fe.default_backend,
|
||||
parsed_fe.mode, parsed_fe.ssl_enabled, parsed_fe.ssl_port,
|
||||
parsed_fe.maxconn, parsed_fe.timeout_client,
|
||||
fe_id, cluster_id
|
||||
fe_id, cluster_id,
|
||||
parsed_fe.log_format, parsed_fe.filters # Issue #38
|
||||
)
|
||||
changes_summary["frontends_updated"] += 1
|
||||
logger.info(f"RESTORE: Updated frontend '{parsed_fe.name}' (SSL: {parsed_fe.ssl_enabled}, maxconn: {parsed_fe.maxconn})")
|
||||
@@ -3714,16 +3716,17 @@ async def confirm_restore_config_version(
|
||||
# CREATE new frontend (ALL 8 parsed fields)
|
||||
# CRITICAL FIX: Include maxconn and timeout_client so UI shows restored values
|
||||
await conn.execute("""
|
||||
INSERT INTO frontends
|
||||
INSERT INTO frontends
|
||||
(name, bind_address, bind_port, default_backend, mode, ssl_enabled, ssl_port,
|
||||
maxconn, timeout_client,
|
||||
cluster_id, is_active, last_config_status, created_at, updated_at)
|
||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, TRUE, 'PENDING', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP)
|
||||
""",
|
||||
cluster_id, log_format, filters, is_active, last_config_status, created_at, updated_at)
|
||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, TRUE, 'PENDING', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP)
|
||||
""",
|
||||
parsed_fe.name, parsed_fe.bind_address, parsed_fe.bind_port,
|
||||
parsed_fe.default_backend, parsed_fe.mode, parsed_fe.ssl_enabled, parsed_fe.ssl_port,
|
||||
parsed_fe.maxconn, parsed_fe.timeout_client,
|
||||
cluster_id
|
||||
cluster_id,
|
||||
parsed_fe.log_format, parsed_fe.filters # Issue #38
|
||||
)
|
||||
changes_summary["frontends_created"] += 1
|
||||
logger.info(f"RESTORE: Created frontend '{parsed_fe.name}' (SSL: {parsed_fe.ssl_enabled}, maxconn: {parsed_fe.maxconn})")
|
||||
|
||||
+101
-12
@@ -3,7 +3,7 @@ Configuration Management and Validation API
|
||||
Provides endpoints for HAProxy configuration validation, templates, and optimization
|
||||
"""
|
||||
|
||||
from fastapi import APIRouter, HTTPException, Header, Request
|
||||
from fastapi import APIRouter, HTTPException, Header, Request, Depends
|
||||
from pydantic import BaseModel
|
||||
from typing import Dict, List, Any, Optional
|
||||
import logging
|
||||
@@ -18,7 +18,7 @@ from utils.config_templates import (
|
||||
)
|
||||
from utils.haproxy_config_parser import parse_haproxy_config
|
||||
from utils.logging_config import log_with_correlation, PerformanceLogger
|
||||
from auth_middleware import get_current_user_from_token
|
||||
from auth_middleware import get_current_user_from_token, require_authenticated_user
|
||||
from database.connection import get_database_connection, close_database_connection
|
||||
|
||||
router = APIRouter(prefix="/api/config", tags=["Configuration Management"])
|
||||
@@ -62,7 +62,7 @@ class ConfigOptimizationRequest(BaseModel):
|
||||
optimization_level: str = "balanced" # conservative, balanced, aggressive
|
||||
target_environment: str = "production" # development, staging, production
|
||||
|
||||
@router.post("/validate")
|
||||
@router.post("/validate", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): was optional-auth; runs HAProxy validator on caller input
|
||||
async def validate_configuration(
|
||||
request: ConfigValidationRequest,
|
||||
current_user: dict = None,
|
||||
@@ -203,7 +203,7 @@ async def get_template_details(template_id: str):
|
||||
)
|
||||
raise HTTPException(status_code=500, detail=f"Failed to get template: {str(e)}")
|
||||
|
||||
@router.post("/templates/{template_id}/generate")
|
||||
@router.post("/templates/{template_id}/generate", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): was optional-auth
|
||||
async def generate_configuration(
|
||||
template_id: str,
|
||||
request: TemplateGenerationRequest,
|
||||
@@ -271,7 +271,7 @@ async def generate_configuration(
|
||||
detail=f"Configuration generation failed: {str(e)}"
|
||||
)
|
||||
|
||||
@router.post("/optimize")
|
||||
@router.post("/optimize", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): was optional-auth
|
||||
async def optimize_configuration(
|
||||
request: ConfigOptimizationRequest,
|
||||
current_user: dict = None,
|
||||
@@ -855,6 +855,9 @@ async def parse_bulk_config(
|
||||
"response_headers": frontend.response_headers,
|
||||
"options": frontend.options,
|
||||
"tcp_request_rules": frontend.tcp_request_rules,
|
||||
# Issue #38: SPOE filters + frontend log-format
|
||||
"log_format": frontend.log_format,
|
||||
"filters": frontend.filters,
|
||||
# CRITICAL: SSL Advanced Options (parsed from bind directive)
|
||||
"ssl_alpn": frontend.ssl_alpn,
|
||||
"ssl_npn": frontend.ssl_npn,
|
||||
@@ -1089,7 +1092,69 @@ async def parse_bulk_config(
|
||||
|
||||
# Add auto-assignment info at the beginning
|
||||
enhanced_warnings = ssl_auto_assign_info + enhanced_warnings
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────────
|
||||
# Issue #38: SPOE pre-flight advisories. Surface, at preview time, the
|
||||
# SPOE configurations that would FAIL HAProxy's `haproxy -c` at apply so
|
||||
# the operator sees them BEFORE importing. Cluster-aware: the referenced
|
||||
# SPOE engine config (e.g. coraza.cfg) is a sibling of the cluster's
|
||||
# haproxy_config_path, which HAProxy OpenManager does not provision.
|
||||
# ─────────────────────────────────────────────────────────────────
|
||||
try:
|
||||
_cfg_path = await conn.fetchval(
|
||||
"SELECT haproxy_config_path FROM haproxy_clusters WHERE id = $1",
|
||||
request.cluster_id,
|
||||
) or "/etc/haproxy/haproxy.cfg"
|
||||
_cfg_dir = _cfg_path.rsplit("/", 1)[0] or "/etc/haproxy"
|
||||
for _fe in frontends_data:
|
||||
_rh = _fe.get("request_headers") or ""
|
||||
_filters = _fe.get("filters") or ""
|
||||
# engines declared by `filter spoe engine <name> config <path>`
|
||||
_declared_engines = set(re.findall(
|
||||
r"filter\s+spoe\s+engine\s+(\S+)", _filters, re.IGNORECASE))
|
||||
# engines referenced by `... send-spoe-group <name> <group>`
|
||||
_used_engines = set(re.findall(
|
||||
r"send-spoe-group\s+(\S+)", _rh, re.IGNORECASE))
|
||||
_missing = _used_engines - _declared_engines
|
||||
if _missing:
|
||||
enhanced_warnings.append(
|
||||
f"⚠️ Frontend '{_fe['name']}': 'send-spoe-group' references SPOE "
|
||||
f"engine(s) {', '.join(sorted(_missing))} but no matching "
|
||||
f"'filter spoe engine <name> ...' line was found. HAProxy will "
|
||||
f"reject this at apply with \"unable to find SPOE engine\". Add the "
|
||||
f"filter line to this frontend."
|
||||
)
|
||||
for _path in re.findall(
|
||||
r"filter\s+spoe\s+engine\s+\S+\s+config\s+(\S+)",
|
||||
_filters, re.IGNORECASE):
|
||||
enhanced_warnings.append(
|
||||
f"ℹ️ Frontend '{_fe['name']}': SPOE engine config '{_path}' and its "
|
||||
f"SPOA backend must exist on the HAProxy host (cluster config dir: "
|
||||
f"{_cfg_dir}). HAProxy OpenManager preserves the filter directive but "
|
||||
f"does not provision these files; otherwise 'haproxy -c' fails at apply."
|
||||
)
|
||||
# Issue #38 follow-up: ACL `-f <file>` pattern-file advisory.
|
||||
# Scan only the structured rule fields (acl/use_backend) —
|
||||
# request_headers/tcp_request_rules were always free-form and
|
||||
# warning on them now would add new noise for existing users.
|
||||
_pattern_paths = []
|
||||
for _rule in (_fe.get("acl_rules") or []) + (_fe.get("use_backend_rules") or []):
|
||||
if isinstance(_rule, str):
|
||||
_pattern_paths.extend(
|
||||
re.findall(r"(?:^|\s)-f\s+(\S+)", _rule))
|
||||
if _pattern_paths:
|
||||
_uniq = sorted(set(_pattern_paths))
|
||||
enhanced_warnings.append(
|
||||
f"ℹ️ Frontend '{_fe['name']}': ACL/routing rules reference pattern "
|
||||
f"file(s) {', '.join(_uniq)}. Each file must exist at that exact path "
|
||||
f"on every HAProxy host in the cluster (cluster config dir: {_cfg_dir}) "
|
||||
f"— HAProxy OpenManager does not create or distribute pattern files. "
|
||||
f"A missing file fails safely at 'haproxy -c' (previous config keeps "
|
||||
f"running)."
|
||||
)
|
||||
except Exception as _spoe_adv_err:
|
||||
logger.warning(f"SPOE advisory generation skipped: {_spoe_adv_err}")
|
||||
|
||||
# BULK IMPORT MVP: Check existing entities for UPSERT detection
|
||||
# Mark each entity as new or update for UI display
|
||||
# CRITICAL: Only mark as UPDATE if there are actual field changes
|
||||
@@ -1150,7 +1215,17 @@ async def parse_bulk_config(
|
||||
if frontend.get("tcp_request_rules") and frontend["tcp_request_rules"] != existing["tcp_request_rules"]:
|
||||
has_changes = True
|
||||
changes["tcp_request_rules"] = {"old": existing["tcp_request_rules"], "new": frontend["tcp_request_rules"]}
|
||||
|
||||
# Issue #38: SPOE filters + log-format change detection. REQUIRED for
|
||||
# persistence (not just display): without it, an import that only adds
|
||||
# a `filter`/`log-format` to an existing frontend would be flagged
|
||||
# "no change" and the directive would never be written to the DB.
|
||||
if frontend.get("log_format") and frontend["log_format"] != existing.get("log_format"):
|
||||
has_changes = True
|
||||
changes["log_format"] = {"old": existing.get("log_format"), "new": frontend["log_format"]}
|
||||
if frontend.get("filters") and frontend["filters"] != existing.get("filters"):
|
||||
has_changes = True
|
||||
changes["filters"] = {"old": existing.get("filters"), "new": frontend["filters"]}
|
||||
|
||||
# CRITICAL: SSL Advanced Options change detection
|
||||
if frontend.get("ssl_alpn") is not None and frontend.get("ssl_alpn") != existing.get("ssl_alpn"):
|
||||
has_changes = True
|
||||
@@ -2094,7 +2169,18 @@ async def bulk_create_entities(
|
||||
update_fields.append(f"options = ${param_index}")
|
||||
update_values.append(frontend_data["options"])
|
||||
param_index += 1
|
||||
|
||||
|
||||
# Issue #38: SPOE filters + frontend log-format (merge strategy)
|
||||
if frontend_data.get("log_format") and frontend_data["log_format"] != existing_full.get("log_format"):
|
||||
update_fields.append(f"log_format = ${param_index}")
|
||||
update_values.append(frontend_data["log_format"])
|
||||
param_index += 1
|
||||
|
||||
if frontend_data.get("filters") and frontend_data["filters"] != existing_full.get("filters"):
|
||||
update_fields.append(f"filters = ${param_index}")
|
||||
update_values.append(frontend_data["filters"])
|
||||
param_index += 1
|
||||
|
||||
# CRITICAL FIX: Update SSL advanced options (alpn, npn, ciphers, etc.)
|
||||
# These are parsed from bind directive and should be preserved in database
|
||||
if "ssl_alpn" in frontend_data and frontend_data.get("ssl_alpn") != existing_full.get("ssl_alpn"):
|
||||
@@ -2214,9 +2300,10 @@ async def bulk_create_entities(
|
||||
timeout_client, timeout_http_request, maxconn,
|
||||
request_headers, response_headers, tcp_request_rules, options,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
cluster_id, acl_rules, use_backend_rules, redirect_rules, updated_at
|
||||
)
|
||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $20, $21, $22, $23, $24, $25, $26, $27, $28, $29, $30, $31, $32, $33, $34, CURRENT_TIMESTAMP)
|
||||
cluster_id, acl_rules, use_backend_rules, redirect_rules,
|
||||
log_format, filters, updated_at
|
||||
)
|
||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $20, $21, $22, $23, $24, $25, $26, $27, $28, $29, $30, $31, $32, $33, $34, $35, $36, CURRENT_TIMESTAMP)
|
||||
RETURNING id
|
||||
""",
|
||||
frontend_data["name"],
|
||||
@@ -2257,7 +2344,9 @@ async def bulk_create_entities(
|
||||
request.cluster_id,
|
||||
json.dumps(frontend_data.get("acl_rules", [])), # acl_rules
|
||||
json.dumps(frontend_data.get("use_backend_rules", [])), # use_backend_rules
|
||||
json.dumps([]) # redirect_rules
|
||||
json.dumps([]), # redirect_rules
|
||||
frontend_data.get("log_format"), # Issue #38
|
||||
frontend_data.get("filters") # Issue #38
|
||||
)
|
||||
|
||||
created_entities["frontends"].append({
|
||||
|
||||
@@ -201,13 +201,15 @@ async def get_pending_config_requests(agent_name: str, x_api_key: Optional[str]
|
||||
Called during heartbeat.
|
||||
"""
|
||||
try:
|
||||
# Validate agent API key
|
||||
# Validate agent API key — MANDATORY (GHSA-3p5c-m5m4-mjpx). Deployed agents
|
||||
# always send X-API-Key; an absent/invalid key is unauthenticated. This
|
||||
# endpoint also mutates state (marks requests 'processing'), so a keyless
|
||||
# caller could otherwise starve the real agent.
|
||||
agent_auth = await validate_agent_api_key(x_api_key)
|
||||
|
||||
if x_api_key and not agent_auth:
|
||||
logger.warning(f"Invalid API key provided by agent '{agent_name}' for pending requests")
|
||||
raise HTTPException(status_code=401, detail="Invalid API key")
|
||||
|
||||
if not agent_auth:
|
||||
logger.warning(f"Missing/invalid API key from '{agent_name}' for pending requests")
|
||||
raise HTTPException(status_code=401, detail="Authentication required")
|
||||
|
||||
conn = await get_database_connection()
|
||||
|
||||
# Get pending requests
|
||||
|
||||
@@ -0,0 +1,375 @@
|
||||
"""
|
||||
CSR (Certificate Signing Request) endpoints (v1.9.0).
|
||||
|
||||
Generate a private key + CSR in-app, download the CSR PEM, have it signed by
|
||||
an external CA, then import the signed certificate — which creates a normal
|
||||
ssl_certificates row that flows through the existing pipeline
|
||||
(config version → Apply Management → agent pull).
|
||||
|
||||
Security posture:
|
||||
- All endpoints enforce ssl.* permissions explicitly (including the read
|
||||
endpoints — deliberately stricter than the legacy cert detail route).
|
||||
- The private key is NEVER returned by any endpoint here; after import it is
|
||||
reachable only via the existing certificate detail route.
|
||||
- Key generation is offloaded to a thread (RSA-4096 takes seconds; the
|
||||
backend runs a single-worker event loop by default) and rate-limited
|
||||
per user via the user_activity_logs COUNT pattern (acme_diagnostics
|
||||
precedent — slowapi is not registered on the app).
|
||||
"""
|
||||
|
||||
import asyncio
|
||||
import logging
|
||||
from typing import Optional
|
||||
|
||||
from fastapi import APIRouter, HTTPException, Request, Header
|
||||
|
||||
from database.connection import get_database_connection, close_database_connection
|
||||
from auth_middleware import get_current_user_from_token, check_user_permission
|
||||
from models.csr import SSLCSRCreate, SSLCSRImport
|
||||
from services import csr_service, ssl_service
|
||||
from routers.ssl import _assert_safe_cert_name, validate_user_cluster_access
|
||||
from utils.activity_log import log_user_activity
|
||||
|
||||
router = APIRouter(prefix="/api/ssl/csrs", tags=["SSL CSRs"])
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
_RATE_LIMIT_CREATE_PER_MIN = 10
|
||||
|
||||
# Columns exposed to the API — private_key_pem is deliberately absent so a
|
||||
# future `SELECT *` refactor cannot silently start leaking it.
|
||||
_CSR_LIST_COLUMNS = """
|
||||
c.id, c.name, c.common_name, c.subject, c.sans, c.key_algorithm,
|
||||
c.status, c.ssl_certificate_id, c.completed_at, c.created_at, c.updated_at,
|
||||
s.name AS certificate_name, u.username AS created_by_username
|
||||
"""
|
||||
|
||||
_INT32_MAX = 2_147_483_647
|
||||
|
||||
|
||||
def _client_ip(request: Optional[Request]) -> Optional[str]:
|
||||
try:
|
||||
return str(request.client.host) if request and request.client else None
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
def _user_agent(request: Optional[Request]) -> Optional[str]:
|
||||
try:
|
||||
return request.headers.get("user-agent") if request else None
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
async def _require(authorization: Optional[str], action: str):
|
||||
"""Authenticate + enforce ssl.<action>; returns current_user or raises 401/403."""
|
||||
current_user = await get_current_user_from_token(authorization)
|
||||
ok = await check_user_permission(current_user["id"], "ssl", action, current_user=current_user)
|
||||
if not ok:
|
||||
raise HTTPException(status_code=403, detail=f"Insufficient permissions: ssl.{action} required")
|
||||
return current_user
|
||||
|
||||
|
||||
def _assert_int32_id(csr_id: int) -> None:
|
||||
"""ssl_csrs.id is int4 — an out-of-range path param would surface as an
|
||||
asyncpg DataError 500 (Bulgu #96 precedent); return a clean 404 instead."""
|
||||
if csr_id < 1 or csr_id > _INT32_MAX:
|
||||
raise HTTPException(status_code=404, detail="CSR not found")
|
||||
|
||||
|
||||
def _assert_valid_cluster_id(cluster_id: int) -> None:
|
||||
"""Same int4 guard for body-supplied cluster ids: haproxy_clusters.id is
|
||||
SERIAL/int4, so an out-of-range value would raise asyncpg DataError inside
|
||||
validate_user_cluster_access and surface as a 500 with the raw driver
|
||||
error. Fail with the same clean 404 the cluster lookup itself produces."""
|
||||
if not isinstance(cluster_id, int) or cluster_id < 1 or cluster_id > _INT32_MAX:
|
||||
raise HTTPException(status_code=404, detail="Cluster not found")
|
||||
|
||||
|
||||
async def _enforce_create_rate_limit(conn, user_id: int) -> None:
|
||||
"""Per-user per-minute limit on key generation, counted against the
|
||||
csr_create audit-log action (acme_diagnostics _enforce_rate_limit pattern,
|
||||
backed by the (user_id, action, created_at DESC) composite index)."""
|
||||
cnt = await conn.fetchval(
|
||||
"""
|
||||
SELECT COUNT(*)
|
||||
FROM user_activity_logs
|
||||
WHERE user_id = $1
|
||||
AND action = 'csr_create'
|
||||
AND created_at >= NOW() - INTERVAL '60 seconds'
|
||||
""",
|
||||
user_id,
|
||||
)
|
||||
if cnt is not None and cnt >= _RATE_LIMIT_CREATE_PER_MIN:
|
||||
raise HTTPException(
|
||||
status_code=429,
|
||||
detail=(
|
||||
f"Rate limit exceeded: at most {_RATE_LIMIT_CREATE_PER_MIN} "
|
||||
"CSRs may be created per minute"
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
@router.post("")
|
||||
async def create_csr(payload: SSLCSRCreate, request: Request, authorization: Optional[str] = Header(None)):
|
||||
"""Generate a private key + CSR. Returns the CSR PEM immediately (so the
|
||||
UI can show copy/download in one round trip) — never the private key."""
|
||||
current_user = await _require(authorization, "create")
|
||||
conn = None
|
||||
try:
|
||||
# Belt and braces on top of the model validator — same duplication
|
||||
# convention as the certificate create route.
|
||||
_assert_safe_cert_name(payload.name)
|
||||
|
||||
conn = await get_database_connection()
|
||||
await _enforce_create_rate_limit(conn, current_user["id"])
|
||||
|
||||
# Fail fast on a taken name BEFORE burning CPU on key generation;
|
||||
# insert_csr_row re-checks and the partial unique index closes the race.
|
||||
await csr_service.assert_csr_name_available(conn, payload.name)
|
||||
|
||||
bundle = await asyncio.to_thread(csr_service.generate_csr_bundle, payload)
|
||||
csr_id = await csr_service.insert_csr_row(conn, payload, bundle, current_user["id"])
|
||||
|
||||
row = await conn.fetchrow(
|
||||
f"""
|
||||
SELECT {_CSR_LIST_COLUMNS}, c.csr_pem
|
||||
FROM ssl_csrs c
|
||||
LEFT JOIN ssl_certificates s ON c.ssl_certificate_id = s.id
|
||||
LEFT JOIN users u ON c.created_by = u.id
|
||||
WHERE c.id = $1
|
||||
""",
|
||||
csr_id,
|
||||
)
|
||||
|
||||
await log_user_activity(
|
||||
user_id=current_user["id"],
|
||||
action='csr_create',
|
||||
resource_type='ssl_csr',
|
||||
resource_id=str(csr_id),
|
||||
details={
|
||||
'csr_name': payload.name,
|
||||
'common_name': payload.common_name,
|
||||
'sans': bundle['sans'],
|
||||
'key_algorithm': payload.key_algorithm,
|
||||
},
|
||||
ip_address=_client_ip(request),
|
||||
user_agent=_user_agent(request),
|
||||
)
|
||||
|
||||
return {
|
||||
"message": f"CSR '{payload.name}' created successfully",
|
||||
"csr": csr_service.csr_row_to_dict(row, include_pem=True),
|
||||
}
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
logger.error(f"Error creating CSR: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
|
||||
|
||||
@router.get("")
|
||||
async def list_csrs(authorization: Optional[str] = Header(None)):
|
||||
"""List CSRs (no PEM payloads — fetch the detail route for the CSR PEM).
|
||||
Cluster-agnostic: a CSR binds to clusters only at import time."""
|
||||
await _require(authorization, "read")
|
||||
conn = None
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
rows = await conn.fetch(
|
||||
f"""
|
||||
SELECT {_CSR_LIST_COLUMNS}
|
||||
FROM ssl_csrs c
|
||||
LEFT JOIN ssl_certificates s ON c.ssl_certificate_id = s.id
|
||||
LEFT JOIN users u ON c.created_by = u.id
|
||||
ORDER BY c.created_at DESC
|
||||
"""
|
||||
)
|
||||
return [csr_service.csr_row_to_dict(r) for r in rows]
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
logger.error(f"Error listing CSRs: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
|
||||
|
||||
@router.get("/{csr_id}")
|
||||
async def get_csr(csr_id: int, authorization: Optional[str] = Header(None)):
|
||||
"""CSR detail including the CSR PEM. The private key is never included."""
|
||||
await _require(authorization, "read")
|
||||
_assert_int32_id(csr_id)
|
||||
conn = None
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
row = await conn.fetchrow(
|
||||
f"""
|
||||
SELECT {_CSR_LIST_COLUMNS}, c.csr_pem
|
||||
FROM ssl_csrs c
|
||||
LEFT JOIN ssl_certificates s ON c.ssl_certificate_id = s.id
|
||||
LEFT JOIN users u ON c.created_by = u.id
|
||||
WHERE c.id = $1
|
||||
""",
|
||||
csr_id,
|
||||
)
|
||||
if not row:
|
||||
raise HTTPException(status_code=404, detail="CSR not found")
|
||||
return csr_service.csr_row_to_dict(row, include_pem=True)
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
logger.error(f"Error fetching CSR {csr_id}: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
|
||||
|
||||
@router.post("/{csr_id}/import")
|
||||
async def import_csr_certificate(
|
||||
csr_id: int,
|
||||
payload: SSLCSRImport,
|
||||
request: Request,
|
||||
authorization: Optional[str] = Header(None),
|
||||
):
|
||||
"""Import the CA-signed certificate for a pending CSR. Creates an
|
||||
ssl_certificates row (source='csr', PENDING) and stages one config
|
||||
version per affected cluster — the operator applies manually."""
|
||||
current_user = await _require(authorization, "create")
|
||||
_assert_int32_id(csr_id)
|
||||
conn = None
|
||||
try:
|
||||
if payload.name:
|
||||
_assert_safe_cert_name(payload.name)
|
||||
|
||||
conn = await get_database_connection()
|
||||
|
||||
if not payload.is_global:
|
||||
for cluster_id in payload.cluster_ids or []:
|
||||
_assert_valid_cluster_id(cluster_id)
|
||||
await validate_user_cluster_access(current_user["id"], cluster_id, conn)
|
||||
|
||||
result = await csr_service.import_signed_certificate(
|
||||
conn, csr_id, payload, current_user["id"]
|
||||
)
|
||||
cert_id = result["certificate_id"]
|
||||
|
||||
if payload.is_global:
|
||||
cluster_rows = await conn.fetch(
|
||||
"SELECT id FROM haproxy_clusters WHERE is_active = TRUE"
|
||||
)
|
||||
affected_clusters = [r['id'] for r in cluster_rows]
|
||||
else:
|
||||
affected_clusters = payload.cluster_ids or []
|
||||
|
||||
# Post-commit staging — a config-generation failure never rolls back
|
||||
# the certificate (same semantics as the manual create flow).
|
||||
sync_results = await ssl_service.stage_ssl_config_versions(
|
||||
conn, cert_id, affected_clusters, action='create',
|
||||
created_by=current_user["id"],
|
||||
)
|
||||
|
||||
await log_user_activity(
|
||||
user_id=current_user["id"],
|
||||
action='create',
|
||||
resource_type='ssl_certificate',
|
||||
resource_id=str(cert_id),
|
||||
details={
|
||||
'certificate_name': result['certificate_name'],
|
||||
'domain': result.get('primary_domain', 'unknown'),
|
||||
'via': 'csr',
|
||||
'csr_id': csr_id,
|
||||
'usage_type': payload.usage_type,
|
||||
'is_global': payload.is_global,
|
||||
'cluster_ids': payload.cluster_ids,
|
||||
'warnings': result['warnings'],
|
||||
},
|
||||
ip_address=_client_ip(request),
|
||||
user_agent=_user_agent(request),
|
||||
)
|
||||
await log_user_activity(
|
||||
user_id=current_user["id"],
|
||||
action='csr_import',
|
||||
resource_type='ssl_csr',
|
||||
resource_id=str(csr_id),
|
||||
details={
|
||||
'certificate_id': cert_id,
|
||||
'certificate_name': result['certificate_name'],
|
||||
},
|
||||
ip_address=_client_ip(request),
|
||||
user_agent=_user_agent(request),
|
||||
)
|
||||
|
||||
return {
|
||||
"message": (
|
||||
f"Certificate '{result['certificate_name']}' imported "
|
||||
"successfully. Go to Apply Management to deploy."
|
||||
),
|
||||
"certificate_id": cert_id,
|
||||
"warnings": result["warnings"],
|
||||
"sync_results": sync_results,
|
||||
}
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
logger.error(f"Error importing signed certificate for CSR {csr_id}: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
|
||||
|
||||
@router.delete("/{csr_id}")
|
||||
async def delete_csr(csr_id: int, request: Request, authorization: Optional[str] = Header(None)):
|
||||
"""Hard delete. For a pending CSR this permanently destroys the private
|
||||
key (any certificate later signed from that CSR becomes unusable); for a
|
||||
completed CSR it only removes history — the imported certificate is not
|
||||
affected (the FK points csr → cert)."""
|
||||
current_user = await _require(authorization, "delete")
|
||||
_assert_int32_id(csr_id)
|
||||
conn = None
|
||||
try:
|
||||
conn = await get_database_connection()
|
||||
async with conn.transaction():
|
||||
# FOR UPDATE serialises against an in-flight import of the same CSR.
|
||||
row = await conn.fetchrow(
|
||||
"SELECT id, name, status FROM ssl_csrs WHERE id = $1 FOR UPDATE",
|
||||
csr_id,
|
||||
)
|
||||
if not row:
|
||||
raise HTTPException(status_code=404, detail="CSR not found")
|
||||
await conn.execute("DELETE FROM ssl_csrs WHERE id = $1", csr_id)
|
||||
|
||||
await log_user_activity(
|
||||
user_id=current_user["id"],
|
||||
action='delete',
|
||||
resource_type='ssl_csr',
|
||||
resource_id=str(csr_id),
|
||||
details={'csr_name': row['name'], 'status': row['status']},
|
||||
ip_address=_client_ip(request),
|
||||
user_agent=_user_agent(request),
|
||||
)
|
||||
|
||||
if row['status'] == 'pending':
|
||||
message = (
|
||||
f"CSR '{row['name']}' deleted — its private key has been "
|
||||
"permanently destroyed."
|
||||
)
|
||||
else:
|
||||
message = (
|
||||
f"CSR '{row['name']}' deleted (history only) — the imported "
|
||||
"certificate is not affected."
|
||||
)
|
||||
return {"message": message}
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
logger.error(f"Error deleting CSR {csr_id}: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
finally:
|
||||
if conn:
|
||||
await close_database_connection(conn)
|
||||
@@ -1,4 +1,5 @@
|
||||
from fastapi import APIRouter, HTTPException, Header
|
||||
from fastapi import APIRouter, HTTPException, Header, Depends
|
||||
from auth_middleware import require_authenticated_user
|
||||
from typing import Optional
|
||||
from datetime import datetime
|
||||
import logging
|
||||
@@ -11,7 +12,7 @@ from agent_notifications import get_cluster_agents_status
|
||||
router = APIRouter(prefix="/api", tags=["dashboard", "pools"])
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
@router.get("/dashboard/overview")
|
||||
@router.get("/dashboard/overview", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): leaked cluster/pool/agent stats, names, health & alerts anonymously (auth was optional)
|
||||
async def get_dashboard_overview(cluster_id: Optional[int] = None, authorization: str = Header(None)):
|
||||
"""Get dashboard overview with comprehensive statistics, optionally filtered by cluster"""
|
||||
try:
|
||||
@@ -238,7 +239,7 @@ async def get_dashboard_overview(cluster_id: Optional[int] = None, authorization
|
||||
logger.error(f"Error fetching dashboard overview: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
|
||||
@router.get("/dashboard/stats")
|
||||
@router.get("/dashboard/stats", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): aggregate cluster/agent counts
|
||||
async def get_dashboard_stats():
|
||||
"""Get dashboard statistics"""
|
||||
try:
|
||||
@@ -279,7 +280,7 @@ async def get_dashboard_stats():
|
||||
except Exception as e:
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
|
||||
@router.get("/pools")
|
||||
@router.get("/pools", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): pool names/env/counts
|
||||
async def get_pools():
|
||||
"""Get all HAProxy cluster pools"""
|
||||
try:
|
||||
@@ -350,7 +351,7 @@ async def get_pools():
|
||||
logger.error(f"Error fetching pools: {e}")
|
||||
return {"pools": []}
|
||||
|
||||
@router.get("/haproxy-cluster-pools")
|
||||
@router.get("/haproxy-cluster-pools", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c)
|
||||
async def get_haproxy_cluster_pools():
|
||||
"""Get all HAProxy cluster pools (legacy endpoint)"""
|
||||
# Just call the main pools endpoint
|
||||
@@ -474,7 +475,7 @@ async def update_pool(pool_id: int, pool: PoolUpdate, authorization: str = Heade
|
||||
logger.error(f"Failed to update pool: {e}")
|
||||
raise HTTPException(status_code=500, detail=f"Failed to update pool: {str(e)}")
|
||||
|
||||
@router.get("/haproxy-cluster-pools/{pool_id}/agents")
|
||||
@router.get("/haproxy-cluster-pools/{pool_id}/agents", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): full agent inventory — same class as GET /api/agents
|
||||
async def get_pool_agents(pool_id: int):
|
||||
"""Get all agents for a specific pool"""
|
||||
try:
|
||||
@@ -561,7 +562,7 @@ async def get_pool_agents(pool_id: int):
|
||||
logger.error(f"Error fetching pool agents: {e}")
|
||||
raise HTTPException(status_code=500, detail=f"Failed to fetch pool agents: {str(e)}")
|
||||
|
||||
@router.get("/haproxy/stats")
|
||||
@router.get("/haproxy/stats", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c)
|
||||
async def get_haproxy_stats(cluster_id: Optional[int] = None):
|
||||
"""Get HAProxy statistics"""
|
||||
try:
|
||||
|
||||
@@ -3,13 +3,22 @@ Dashboard Stats Router
|
||||
API endpoints for HAProxy statistics dashboard
|
||||
"""
|
||||
|
||||
from fastapi import APIRouter, HTTPException, Query
|
||||
from fastapi import APIRouter, HTTPException, Query, Depends
|
||||
from typing import Optional, List
|
||||
import logging
|
||||
|
||||
from services.dashboard_stats_service import dashboard_stats_service
|
||||
from auth_middleware import require_authenticated_user
|
||||
|
||||
router = APIRouter(prefix="/api/dashboard-stats", tags=["dashboard-stats"])
|
||||
# SECURITY (GHSA-3p5c-m5m4-mjpx): this entire router (traffic metrics, backend
|
||||
# health, cluster topology, agent status) was mounted without authentication.
|
||||
# Require a valid JWT on every route. The frontend Dashboard already sends the
|
||||
# operator JWT on these calls, so this is transparent to the UI.
|
||||
router = APIRouter(
|
||||
prefix="/api/dashboard-stats",
|
||||
tags=["dashboard-stats"],
|
||||
dependencies=[Depends(require_authenticated_user)],
|
||||
)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
|
||||
+69
-12
@@ -117,6 +117,41 @@ def _rule_contradiction_text(rule: Any) -> Optional[str]:
|
||||
return None
|
||||
|
||||
|
||||
def _pattern_file_warnings(
|
||||
acl_rules: Optional[List[Any]] = None,
|
||||
use_backend_rules: Optional[List[Any]] = None,
|
||||
redirect_rules: Optional[List[Any]] = None,
|
||||
) -> List[str]:
|
||||
"""Issue #38 follow-up — non-blocking `-f <file>` pattern-file
|
||||
advisory for the manual frontend API.
|
||||
|
||||
The Bulgu #12 hard reject was removed from the Pydantic models:
|
||||
pattern files are operator-managed host files (same policy as the
|
||||
SPOE `filter ... config <path>` reference preserved since v1.8.8)
|
||||
and the agent's pre-reload `haproxy -c` makes a missing file fail
|
||||
safely. This helper returns one warning listing the unique file
|
||||
paths referenced across the rule fields, or [] when no rule uses
|
||||
`-f` — operators who don't use pattern files see no change.
|
||||
"""
|
||||
paths: List[str] = []
|
||||
for rules in (acl_rules, use_backend_rules, redirect_rules):
|
||||
for rule in rules or []:
|
||||
text = rule if isinstance(rule, str) else (
|
||||
rule.get("condition") if isinstance(rule, dict) else None)
|
||||
if isinstance(text, str):
|
||||
paths.extend(re.findall(r"(?:^|\s)-f\s+(\S+)", text))
|
||||
if not paths:
|
||||
return []
|
||||
uniq = sorted(set(paths))
|
||||
return [
|
||||
f"ACL/routing rules reference pattern file(s) {', '.join(uniq)}. "
|
||||
f"Each file must exist at that exact path on every HAProxy host "
|
||||
f"in the cluster — HAProxy OpenManager does not create or "
|
||||
f"distribute pattern files. A missing file fails safely at "
|
||||
f"'haproxy -c' (the previous config keeps running)."
|
||||
]
|
||||
|
||||
|
||||
def _collect_routing_rule_contradictions(
|
||||
rules: List[Any], origin_label: str,
|
||||
) -> List[Tuple[str, Any]]:
|
||||
@@ -408,6 +443,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -424,6 +460,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -453,6 +490,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -465,6 +503,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -480,6 +519,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -492,6 +532,7 @@ async def get_frontends(
|
||||
ssl_alpn, ssl_npn, ssl_ciphers, ssl_ciphersuites, ssl_min_ver, ssl_max_ver, ssl_strict_sni,
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules,
|
||||
log_format, filters,
|
||||
timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
maxconn, is_active, created_at, updated_at, cluster_id, last_config_status
|
||||
@@ -601,6 +642,8 @@ async def get_frontends(
|
||||
"response_headers": f.get("response_headers"),
|
||||
"options": f.get("options"),
|
||||
"tcp_request_rules": f.get("tcp_request_rules"),
|
||||
"log_format": f.get("log_format"), # Issue #38
|
||||
"filters": f.get("filters"), # Issue #38
|
||||
"timeout_client": f.get("timeout_client"),
|
||||
"timeout_http_request": f.get("timeout_http_request"),
|
||||
"rate_limit": f.get("rate_limit"),
|
||||
@@ -735,18 +778,18 @@ async def create_frontend(frontend: FrontendConfig, request: Request, authorizat
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules, timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
cluster_id, maxconn, updated_at
|
||||
) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $20, $21, $22, $23, $24, $25, $26, $27, $28, $29, $30, $31, $32, $33, $34, CURRENT_TIMESTAMP)
|
||||
cluster_id, maxconn, log_format, filters, updated_at
|
||||
) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12, $13, $14, $15, $16, $17, $18, $19, $20, $21, $22, $23, $24, $25, $26, $27, $28, $29, $30, $31, $32, $33, $34, $35, $36, CURRENT_TIMESTAMP)
|
||||
RETURNING id
|
||||
""", frontend.name, frontend.bind_address, frontend.bind_port,
|
||||
""", frontend.name, frontend.bind_address, frontend.bind_port,
|
||||
frontend.default_backend, frontend.mode, frontend.ssl_enabled,
|
||||
frontend.ssl_certificate_id, ssl_cert_ids_json, frontend.ssl_port, frontend.ssl_cert_path, frontend.ssl_cert, frontend.ssl_verify,
|
||||
frontend.ssl_alpn, frontend.ssl_npn, frontend.ssl_ciphers, frontend.ssl_ciphersuites,
|
||||
frontend.ssl_alpn, frontend.ssl_npn, frontend.ssl_ciphers, frontend.ssl_ciphersuites,
|
||||
frontend.ssl_min_ver, frontend.ssl_max_ver, frontend.ssl_strict_sni,
|
||||
json.dumps(frontend.acl_rules or []), json.dumps(frontend.redirect_rules or []), json.dumps(frontend.use_backend_rules or []),
|
||||
frontend.request_headers, frontend.response_headers, filtered_options, frontend.tcp_request_rules, frontend.timeout_client, frontend.timeout_http_request,
|
||||
frontend.rate_limit, frontend.compression, frontend.log_separate, frontend.monitor_uri,
|
||||
frontend.cluster_id, frontend.maxconn)
|
||||
frontend.cluster_id, frontend.maxconn, frontend.log_format, frontend.filters)
|
||||
|
||||
# If cluster_id provided, create new config version for agents
|
||||
sync_results = []
|
||||
@@ -825,12 +868,19 @@ async def create_frontend(frontend: FrontendConfig, request: Request, authorizat
|
||||
user_agent=request.headers.get('user-agent')
|
||||
)
|
||||
|
||||
return {
|
||||
response: dict = {
|
||||
"message": f"Frontend '{frontend.name}' created successfully",
|
||||
"id": frontend_id,
|
||||
"frontend": frontend.dict(),
|
||||
"sync_results": sync_results
|
||||
}
|
||||
# Issue #38 follow-up — non-blocking pattern-file advisory
|
||||
# (additive field; absent when no rule references `-f`).
|
||||
pattern_warnings = _pattern_file_warnings(
|
||||
frontend.acl_rules, frontend.use_backend_rules, frontend.redirect_rules)
|
||||
if pattern_warnings:
|
||||
response["warnings"] = pattern_warnings
|
||||
return response
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
@@ -1060,9 +1110,10 @@ async def update_frontend(frontend_id: int, frontend: FrontendConfig, request: R
|
||||
acl_rules = $20, redirect_rules = $21, use_backend_rules = $22,
|
||||
request_headers = $23, response_headers = $24, options = $25, tcp_request_rules = $26, timeout_client = $27, timeout_http_request = $28,
|
||||
rate_limit = $29, compression = $30, log_separate = $31, monitor_uri = $32,
|
||||
cluster_id = $33, maxconn = $34, updated_at = CURRENT_TIMESTAMP
|
||||
WHERE id = $35
|
||||
""", frontend.name, frontend.bind_address, frontend.bind_port,
|
||||
cluster_id = $33, maxconn = $34, log_format = $35, filters = $36,
|
||||
updated_at = CURRENT_TIMESTAMP
|
||||
WHERE id = $37
|
||||
""", frontend.name, frontend.bind_address, frontend.bind_port,
|
||||
frontend.default_backend, frontend.mode, ssl_enabled,
|
||||
ssl_certificate_id, ssl_cert_ids_json, ssl_port, ssl_cert_path, ssl_cert, ssl_verify,
|
||||
frontend.ssl_alpn, frontend.ssl_npn, frontend.ssl_ciphers, frontend.ssl_ciphersuites,
|
||||
@@ -1070,7 +1121,7 @@ async def update_frontend(frontend_id: int, frontend: FrontendConfig, request: R
|
||||
json.dumps(frontend.acl_rules or []), json.dumps(frontend.redirect_rules or []), json.dumps(frontend.use_backend_rules or []),
|
||||
frontend.request_headers, frontend.response_headers, filtered_options, frontend.tcp_request_rules, frontend.timeout_client, frontend.timeout_http_request,
|
||||
frontend.rate_limit, frontend.compression, frontend.log_separate, frontend.monitor_uri,
|
||||
frontend.cluster_id, frontend.maxconn, frontend_id)
|
||||
frontend.cluster_id, frontend.maxconn, frontend.log_format, frontend.filters, frontend_id)
|
||||
|
||||
# Debug: Check what was actually saved
|
||||
updated_frontend = await conn.fetchrow("""
|
||||
@@ -1124,6 +1175,8 @@ async def update_frontend(frontend_id: int, frontend: FrontendConfig, request: R
|
||||
"response_headers": frontend.response_headers,
|
||||
"options": filtered_options,
|
||||
"tcp_request_rules": frontend.tcp_request_rules,
|
||||
"log_format": frontend.log_format, # Issue #38
|
||||
"filters": frontend.filters, # Issue #38
|
||||
"timeout_client": frontend.timeout_client,
|
||||
"timeout_http_request": frontend.timeout_http_request,
|
||||
"rate_limit": frontend.rate_limit,
|
||||
@@ -1235,8 +1288,12 @@ async def update_frontend(frontend_id: int, frontend: FrontendConfig, request: R
|
||||
# yellow toast on the next refresh. The save SUCCEEDED; the
|
||||
# warnings only flag latent legacy data the operator may
|
||||
# want to clean up at their convenience.
|
||||
if contradiction_warnings:
|
||||
response["warnings"] = contradiction_warnings
|
||||
# Issue #38 follow-up — append the pattern-file advisory to
|
||||
# the same list (additive; empty when no rule uses `-f`).
|
||||
all_warnings = list(contradiction_warnings or []) + _pattern_file_warnings(
|
||||
frontend.acl_rules, frontend.use_backend_rules, frontend.redirect_rules)
|
||||
if all_warnings:
|
||||
response["warnings"] = all_warnings
|
||||
return response
|
||||
except HTTPException:
|
||||
raise
|
||||
|
||||
@@ -3,8 +3,9 @@ Production-Ready Health Check and Monitoring Endpoints
|
||||
Provides comprehensive system health monitoring for Kubernetes and production environments
|
||||
"""
|
||||
|
||||
from fastapi import APIRouter, HTTPException
|
||||
from fastapi import APIRouter, HTTPException, Depends
|
||||
from fastapi.responses import JSONResponse
|
||||
from auth_middleware import require_authenticated_user
|
||||
import logging
|
||||
import asyncio
|
||||
import time
|
||||
@@ -74,7 +75,7 @@ async def readiness_probe():
|
||||
logger.error(f"Readiness probe failed: {e}")
|
||||
raise HTTPException(status_code=503, detail=f"Not ready: {str(e)}")
|
||||
|
||||
@router.get("/deep")
|
||||
@router.get("/deep", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): leaks host CPU/mem/disk, DB/redis/python versions, PID
|
||||
async def deep_health_check():
|
||||
"""Comprehensive health check with detailed system information"""
|
||||
global _health_cache
|
||||
@@ -197,7 +198,7 @@ async def deep_health_check():
|
||||
|
||||
raise HTTPException(status_code=503, detail=error_response)
|
||||
|
||||
@router.get("/agents")
|
||||
@router.get("/agents", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): leaks agent names/hostnames
|
||||
async def agents_health():
|
||||
"""Monitor agent connectivity and health status"""
|
||||
try:
|
||||
@@ -261,7 +262,7 @@ async def agents_health():
|
||||
logger.error(f"Agent health check failed: {e}")
|
||||
raise HTTPException(status_code=500, detail=f"Agent health check failed: {str(e)}")
|
||||
|
||||
@router.get("/clusters")
|
||||
@router.get("/clusters", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): leaks cluster names, HAProxy versions, pending counts
|
||||
async def clusters_health():
|
||||
"""Monitor HAProxy cluster health and configuration status"""
|
||||
try:
|
||||
@@ -329,7 +330,7 @@ async def clusters_health():
|
||||
logger.error(f"Cluster health check failed: {e}")
|
||||
raise HTTPException(status_code=500, detail=f"Cluster health check failed: {str(e)}")
|
||||
|
||||
@router.get("/errors")
|
||||
@router.get("/errors", dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): app error metrics, sibling of /deep,/agents,/clusters
|
||||
async def error_statistics():
|
||||
"""Get application error statistics and metrics"""
|
||||
try:
|
||||
|
||||
@@ -87,6 +87,32 @@ class AccountCreate(BaseModel):
|
||||
raise ValueError("eab_hmac_key is not valid base64; copy it exactly from your CA account.")
|
||||
return v
|
||||
|
||||
@field_validator('directory_url')
|
||||
@classmethod
|
||||
def _validate_directory_url(cls, v):
|
||||
# SECURITY (GHSA-3vh4-gvxx-wm2p): reject non-https URLs and literal
|
||||
# non-public IP hosts at the API boundary. The full DNS-based SSRF check
|
||||
# runs at fetch time (acme_service.get_directory -> ssrf_guard).
|
||||
if not v:
|
||||
return v
|
||||
from urllib.parse import urlparse
|
||||
import ipaddress
|
||||
from utils.ssrf_guard import is_public_ip
|
||||
parsed = urlparse(v.strip())
|
||||
if parsed.scheme.lower() != 'https':
|
||||
raise ValueError("directory_url must be an https URL")
|
||||
host = parsed.hostname
|
||||
if not host:
|
||||
raise ValueError("directory_url has no host")
|
||||
try:
|
||||
ipaddress.ip_address(host)
|
||||
is_ip_literal = True
|
||||
except ValueError:
|
||||
is_ip_literal = False
|
||||
if is_ip_literal and not is_public_ip(host):
|
||||
raise ValueError("directory_url must not point to a private/loopback IP address")
|
||||
return v
|
||||
|
||||
@model_validator(mode='after')
|
||||
def _require_provider_for_dns01(self):
|
||||
if self.challenge_type == 'dns-01' and not (self.dns_provider or '').strip():
|
||||
|
||||
@@ -104,16 +104,40 @@ async def test_acme_connection(authorization: str = Header(None), directory_url:
|
||||
finally:
|
||||
await close_database_connection(conn)
|
||||
|
||||
# SECURITY (GHSA-3vh4-gvxx-wm2p): validate the URL before any outbound request
|
||||
# (https-only; block loopback/RFC1918/link-local/cloud-metadata after DNS),
|
||||
# pin the connector to IPv4, and never follow redirects. Also do NOT reflect
|
||||
# arbitrary upstream JSON keys back to the caller — that was an information-
|
||||
# disclosure oracle. Only report presence of the FIXED, known ACME directory
|
||||
# field names (never attacker-controlled data).
|
||||
from utils.ssrf_guard import assert_public_url, safe_connector, SSRFValidationError
|
||||
|
||||
directory_url = str(directory_url)
|
||||
try:
|
||||
await assert_public_url(directory_url)
|
||||
except SSRFValidationError as e:
|
||||
return {"success": False, "error": f"Refused to fetch directory URL: {e}"}
|
||||
|
||||
_KNOWN_ACME_FIELDS = ["newNonce", "newAccount", "newOrder", "newAuthz", "revokeCert", "keyChange"]
|
||||
try:
|
||||
import aiohttp
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.get(str(directory_url), timeout=aiohttp.ClientTimeout(total=10)) as resp:
|
||||
async with aiohttp.ClientSession(connector=safe_connector()) as session:
|
||||
async with session.get(
|
||||
directory_url,
|
||||
timeout=aiohttp.ClientTimeout(total=10),
|
||||
allow_redirects=False,
|
||||
) as resp:
|
||||
if resp.status == 200:
|
||||
data = await resp.json()
|
||||
data = await resp.json(content_type=None)
|
||||
if not isinstance(data, dict):
|
||||
return {"success": False, "error": "Directory URL did not return a JSON object"}
|
||||
present = [k for k in _KNOWN_ACME_FIELDS if k in data]
|
||||
if not present:
|
||||
return {"success": False, "error": "Response is not a valid ACME directory"}
|
||||
return {
|
||||
"success": True,
|
||||
"directory": str(directory_url),
|
||||
"endpoints": list(data.keys()) if isinstance(data, dict) else []
|
||||
"directory": directory_url,
|
||||
"endpoints": present,
|
||||
}
|
||||
else:
|
||||
return {"success": False, "error": f"HTTP {resp.status} from directory URL"}
|
||||
|
||||
@@ -9,7 +9,7 @@ from datetime import datetime, timezone
|
||||
|
||||
# Import database and models
|
||||
from database.connection import get_database_connection, close_database_connection
|
||||
from auth_middleware import get_current_user_from_token
|
||||
from auth_middleware import get_current_user_from_token, require_authenticated_user
|
||||
from models.ssl import SSLCertificate, SSLCertificateCreate, SSLCertificateUpdate, SSLCertificateResponse
|
||||
from utils.ssl_parser import parse_ssl_certificate, validate_private_key, validate_certificate_chain, format_certificate_info
|
||||
from utils.activity_log import log_user_activity
|
||||
@@ -825,7 +825,8 @@ async def get_ssl_certificate(cert_id: int, authorization: str = Header(None)):
|
||||
logger.error(f"Error getting SSL certificate: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
|
||||
@router.get("/certificates/{cert_id}/config-versions")
|
||||
@router.get("/certificates/{cert_id}/config-versions",
|
||||
dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): was unauthenticated
|
||||
async def get_ssl_certificate_config_versions(cert_id: int):
|
||||
"""Get config version history for specific SSL certificate"""
|
||||
try:
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
from fastapi import APIRouter, HTTPException, Request, Header
|
||||
from fastapi import APIRouter, HTTPException, Request, Header, Depends
|
||||
from auth_middleware import require_authenticated_user
|
||||
from typing import Optional
|
||||
import logging
|
||||
import time
|
||||
@@ -182,7 +183,8 @@ async def get_waf_stats(cluster_id: Optional[int] = None, authorization: str = H
|
||||
logger.error(f"Error fetching WAF stats: {e}")
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
|
||||
@router.get("/rules", summary="Get WAF Rules", response_description="List of WAF rules")
|
||||
@router.get("/rules", summary="Get WAF Rules", response_description="List of WAF rules",
|
||||
dependencies=[Depends(require_authenticated_user)]) # SECURITY (GHSA-3p5c): WAF rule definitions aid bypass crafting
|
||||
async def get_waf_rules(cluster_id: Optional[int] = None):
|
||||
"""
|
||||
# Get WAF Rules
|
||||
|
||||
@@ -69,8 +69,14 @@ class ACMEService:
|
||||
if cached.get('_fetched_at', 0) > time.time() - 3600:
|
||||
return cached
|
||||
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.get(directory_url, timeout=aiohttp.ClientTimeout(total=15)) as resp:
|
||||
# SECURITY (GHSA-3vh4-gvxx-wm2p): directory_url can come from a stored
|
||||
# account row; validate it (https + public IP, no redirects) before the
|
||||
# server-side fetch so it cannot be pointed at internal/metadata targets.
|
||||
from utils.ssrf_guard import assert_public_url, safe_connector
|
||||
await assert_public_url(directory_url)
|
||||
|
||||
async with aiohttp.ClientSession(connector=safe_connector()) as session:
|
||||
async with session.get(directory_url, timeout=aiohttp.ClientTimeout(total=15), allow_redirects=False) as resp:
|
||||
if resp.status != 200:
|
||||
raise Exception(f"Failed to fetch ACME directory: HTTP {resp.status}")
|
||||
data = await resp.json()
|
||||
@@ -90,8 +96,16 @@ class ACMEService:
|
||||
cached = self._nonce_by_dir.pop(directory_url, None)
|
||||
if cached:
|
||||
return cached
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.head(directory['newNonce']) as resp:
|
||||
# SECURITY (GHSA-3vh4-gvxx-wm2p): newNonce is taken from the (attacker-
|
||||
# influenceable) directory JSON and is fetched here BEFORE the guarded
|
||||
# _signed_request POST, so it must be guarded too — otherwise a directory
|
||||
# that returns an internal newNonce (and omits Replay-Nonce) is a live SSRF.
|
||||
# https + public IP only, IPv4-pinned connector, no redirects, bounded timeout.
|
||||
from utils.ssrf_guard import assert_public_url, safe_connector
|
||||
nonce_url = directory['newNonce']
|
||||
await assert_public_url(nonce_url)
|
||||
async with aiohttp.ClientSession(connector=safe_connector()) as session:
|
||||
async with session.head(nonce_url, timeout=aiohttp.ClientTimeout(total=15), allow_redirects=False) as resp:
|
||||
return resp.headers['Replay-Nonce']
|
||||
|
||||
def _generate_account_key(self) -> Tuple[str, dict]:
|
||||
@@ -187,13 +201,21 @@ class ACMEService:
|
||||
|
||||
body = self._sign_jws(private_key, protected, payload)
|
||||
|
||||
async with aiohttp.ClientSession() as session:
|
||||
# SECURITY (GHSA-3vh4-gvxx-wm2p): `url` is taken from the CA directory /
|
||||
# order responses. The directory is already fetched from a validated
|
||||
# public CA, but guard the follow-up POST target too (defence in depth)
|
||||
# so a tampered/malicious directory cannot steer the request internally.
|
||||
from utils.ssrf_guard import assert_public_url, safe_connector
|
||||
await assert_public_url(url)
|
||||
|
||||
async with aiohttp.ClientSession(connector=safe_connector()) as session:
|
||||
for attempt in range(3):
|
||||
async with session.post(
|
||||
url,
|
||||
json=body,
|
||||
headers={"Content-Type": "application/jose+json"},
|
||||
timeout=aiohttp.ClientTimeout(total=30),
|
||||
allow_redirects=False,
|
||||
) as resp:
|
||||
if 'Replay-Nonce' in resp.headers:
|
||||
self._nonce_by_dir[directory_url] = resp.headers['Replay-Nonce']
|
||||
|
||||
@@ -0,0 +1,461 @@
|
||||
"""
|
||||
csr_service: CSR (Certificate Signing Request) generation + signed-certificate
|
||||
import (v1.9.0).
|
||||
|
||||
Flow:
|
||||
1. `generate_csr_bundle` builds a private key + CSR locally (pure crypto,
|
||||
no DB/IO — callers MUST run it via `asyncio.to_thread`: RSA-4096
|
||||
generation takes seconds and would stall the single-worker event loop).
|
||||
2. The bundle is persisted to `ssl_csrs` (`insert_csr_row`); the operator
|
||||
downloads the CSR PEM and has it signed by an external CA.
|
||||
3. `import_signed_certificate` pairs the CA response with the stored key,
|
||||
creates a normal `ssl_certificates` row (source='csr',
|
||||
last_config_status='PENDING' — agents never see it before Apply) and
|
||||
NULLs the key copy on the CSR row.
|
||||
|
||||
The CSR builder generalises the in-repo ACME reference
|
||||
(services/acme_service.py finalize_order): PEM output instead of DER, full
|
||||
subject instead of CN-only, ECDSA support, same PKCS8/NoEncryption key
|
||||
serialisation (the agent concatenates cert+key+chain into one PEM and HAProxy
|
||||
cannot read passphrase-protected keys).
|
||||
|
||||
Private keys are ENCRYPTED AT REST from v1.10.1 (Issue #53): the Fernet token
|
||||
replaces the PEM in the same `ssl_csrs.private_key_pem` column, so there is no
|
||||
schema change and no SCHEMA_VERSION bump. Rows written earlier hold a raw PEM
|
||||
and are still read transparently — see utils/csr_key_crypto.py for the format
|
||||
discriminator and the key-rotation caveat. The pending CSR key is the one key
|
||||
in the system worth encrypting: it sits idle for the whole signing window and
|
||||
is never transmitted, unlike ssl_certificates.private_key_content and the ACME
|
||||
order keys, which agents must receive in plaintext on every poll.
|
||||
The key is NEVER returned by any CSR API response — `csr_row_to_dict` strips
|
||||
it unconditionally.
|
||||
"""
|
||||
|
||||
import json
|
||||
import logging
|
||||
from typing import Any, Dict, List, Optional
|
||||
from types import SimpleNamespace
|
||||
|
||||
import asyncpg
|
||||
from fastapi import HTTPException
|
||||
|
||||
from cryptography import x509
|
||||
from cryptography.hazmat.primitives import hashes, serialization
|
||||
from cryptography.hazmat.primitives.asymmetric import ec, rsa
|
||||
from cryptography.x509.oid import NameOID
|
||||
|
||||
from services import ssl_service
|
||||
from utils.csr_key_crypto import decrypt_csr_private_key, encrypt_csr_private_key
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
_KEY_FACTORIES = {
|
||||
'rsa-2048': lambda: rsa.generate_private_key(public_exponent=65537, key_size=2048),
|
||||
'rsa-4096': lambda: rsa.generate_private_key(public_exponent=65537, key_size=4096),
|
||||
'ecdsa-p256': lambda: ec.generate_private_key(ec.SECP256R1()),
|
||||
'ecdsa-p384': lambda: ec.generate_private_key(ec.SECP384R1()),
|
||||
}
|
||||
|
||||
# (payload attribute, x509 OID, subject-JSON key)
|
||||
_SUBJECT_OID_MAP = [
|
||||
('organization', NameOID.ORGANIZATION_NAME, 'O'),
|
||||
('organizational_unit', NameOID.ORGANIZATIONAL_UNIT_NAME, 'OU'),
|
||||
('locality', NameOID.LOCALITY_NAME, 'L'),
|
||||
('state', NameOID.STATE_OR_PROVINCE_NAME, 'ST'),
|
||||
('country', NameOID.COUNTRY_NAME, 'C'),
|
||||
('email', NameOID.EMAIL_ADDRESS, 'emailAddress'),
|
||||
]
|
||||
|
||||
|
||||
def generate_csr_bundle(payload: Any) -> Dict[str, Any]:
|
||||
"""Generate a private key + CSR for a validated SSLCSRCreate payload.
|
||||
|
||||
Pure CPU-bound crypto — no DB, no network. Callers must offload via
|
||||
`asyncio.to_thread` (see module docstring).
|
||||
|
||||
Returns {'csr_pem', 'private_key_pem', 'sans', 'subject'}.
|
||||
"""
|
||||
key = _KEY_FACTORIES[payload.key_algorithm]()
|
||||
|
||||
attrs = [x509.NameAttribute(NameOID.COMMON_NAME, payload.common_name)]
|
||||
subject_json: Dict[str, str] = {}
|
||||
for attr_name, oid, json_key in _SUBJECT_OID_MAP:
|
||||
value = getattr(payload, attr_name, None)
|
||||
if value and str(value).strip():
|
||||
cleaned = str(value).strip()
|
||||
attrs.append(x509.NameAttribute(oid, cleaned))
|
||||
subject_json[json_key] = cleaned
|
||||
|
||||
# CN always first in the SAN list, then the extra names, deduped with
|
||||
# order preserved (mirrors the ACME flow where domains[0] is the CN).
|
||||
sans = list(dict.fromkeys([payload.common_name, *(payload.sans or [])]))
|
||||
|
||||
builder = (
|
||||
x509.CertificateSigningRequestBuilder()
|
||||
.subject_name(x509.Name(attrs))
|
||||
.add_extension(
|
||||
x509.SubjectAlternativeName([x509.DNSName(d) for d in sans]),
|
||||
critical=False,
|
||||
)
|
||||
)
|
||||
csr = builder.sign(key, hashes.SHA256())
|
||||
|
||||
return {
|
||||
'csr_pem': csr.public_bytes(serialization.Encoding.PEM).decode('utf-8'),
|
||||
'private_key_pem': key.private_bytes(
|
||||
serialization.Encoding.PEM,
|
||||
serialization.PrivateFormat.PKCS8,
|
||||
serialization.NoEncryption(),
|
||||
).decode('utf-8'),
|
||||
'sans': sans,
|
||||
'subject': subject_json,
|
||||
}
|
||||
|
||||
|
||||
def diff_domains(csr_sans: Optional[List[str]], cert_domains: Optional[List[str]]) -> List[str]:
|
||||
"""Human-readable warnings for SAN drift between the CSR and the signed
|
||||
certificate (case-insensitive set diff). CAs legitimately add/normalise
|
||||
SANs, so drift is WARN-only — the hard gate is the key match."""
|
||||
csr_set = {d.lower() for d in (csr_sans or []) if d}
|
||||
cert_set = {d.lower() for d in (cert_domains or []) if d}
|
||||
warnings: List[str] = []
|
||||
added = sorted(cert_set - csr_set)
|
||||
dropped = sorted(csr_set - cert_set)
|
||||
if added:
|
||||
warnings.append(
|
||||
f"The CA added domains that were not in the CSR: {', '.join(added)}"
|
||||
)
|
||||
if dropped:
|
||||
warnings.append(
|
||||
f"The CA dropped domains that were requested in the CSR: {', '.join(dropped)}"
|
||||
)
|
||||
return warnings
|
||||
|
||||
|
||||
def _maybe_json_list(value: Any) -> List[str]:
|
||||
"""asyncpg returns JSONB columns as str unless a codec is registered."""
|
||||
if isinstance(value, str):
|
||||
try:
|
||||
parsed = json.loads(value)
|
||||
return parsed if isinstance(parsed, list) else []
|
||||
except Exception:
|
||||
return []
|
||||
return list(value) if value else []
|
||||
|
||||
|
||||
def csr_row_to_dict(row: Any, include_pem: bool = False) -> Dict[str, Any]:
|
||||
"""Row → API dict. ALWAYS strips private_key_pem — the key never leaves
|
||||
the server via a CSR endpoint. csr_pem included only on demand
|
||||
(detail/create responses, not lists)."""
|
||||
d = dict(row)
|
||||
d.pop('private_key_pem', None)
|
||||
if not include_pem:
|
||||
d.pop('csr_pem', None)
|
||||
for key in ('subject', 'sans'):
|
||||
if key in d and isinstance(d[key], str):
|
||||
try:
|
||||
d[key] = json.loads(d[key])
|
||||
except Exception:
|
||||
pass
|
||||
return d
|
||||
|
||||
|
||||
async def assert_csr_name_available(conn, name: str) -> None:
|
||||
"""Reject a CSR name that is already taken by an ACTIVE certificate or
|
||||
another PENDING CSR. Called BEFORE key generation (cheap fail-fast) and
|
||||
re-run inside `insert_csr_row` (the unique index closes the race)."""
|
||||
existing_cert = await conn.fetchval(
|
||||
"SELECT id FROM ssl_certificates WHERE name = $1 AND is_active = TRUE",
|
||||
name,
|
||||
)
|
||||
if existing_cert:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=(
|
||||
f"An active SSL certificate named '{name}' already exists. "
|
||||
"The CSR name becomes the certificate name at import — choose "
|
||||
"a different name or remove the existing certificate first."
|
||||
),
|
||||
)
|
||||
existing_csr = await conn.fetchval(
|
||||
"SELECT id FROM ssl_csrs WHERE name = $1 AND status = 'pending'",
|
||||
name,
|
||||
)
|
||||
if existing_csr:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=(
|
||||
f"A pending CSR named '{name}' already exists (id={existing_csr}). "
|
||||
"Import or delete it first, or choose a different name."
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
async def insert_csr_row(conn, payload: Any, bundle: Dict[str, Any], user_id: Optional[int]) -> int:
|
||||
"""Persist a freshly generated CSR bundle. Returns the new csr id.
|
||||
|
||||
Issue #53 (v1.10.1): the private key is Fernet-encrypted before it is stored. The token goes
|
||||
into the SAME private_key_pem TEXT column — no schema change — and is only ever decrypted
|
||||
in-process by import_signed_certificate. No CSR endpoint returns the column either way.
|
||||
"""
|
||||
await assert_csr_name_available(conn, payload.name)
|
||||
stored_key = encrypt_csr_private_key(bundle['private_key_pem'])
|
||||
try:
|
||||
csr_id = await conn.fetchval(
|
||||
"""
|
||||
INSERT INTO ssl_csrs
|
||||
(name, common_name, subject, sans, key_algorithm, csr_pem,
|
||||
private_key_pem, status, created_by)
|
||||
VALUES ($1, $2, $3::jsonb, $4::jsonb, $5, $6, $7, 'pending', $8)
|
||||
RETURNING id
|
||||
""",
|
||||
payload.name,
|
||||
payload.common_name,
|
||||
json.dumps(bundle['subject']),
|
||||
json.dumps(bundle['sans']),
|
||||
payload.key_algorithm,
|
||||
bundle['csr_pem'],
|
||||
stored_key,
|
||||
user_id,
|
||||
)
|
||||
except asyncpg.exceptions.UniqueViolationError:
|
||||
# uq_ssl_csrs_name_pending — a concurrent request won the name.
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=(
|
||||
f"A pending CSR named '{payload.name}' was just created by a "
|
||||
"concurrent request — choose a different name."
|
||||
),
|
||||
)
|
||||
return csr_id
|
||||
|
||||
|
||||
async def import_signed_certificate(conn, csr_id: int, imp: Any, user_id: Optional[int]) -> Dict[str, Any]:
|
||||
"""Pair the CA-signed certificate with the stored CSR key and create the
|
||||
ssl_certificates row. Atomic: cert row + CSR state change commit together.
|
||||
|
||||
Returns {'certificate_id', 'certificate_name', 'primary_domain',
|
||||
'warnings', 'reactivated'}. Raises HTTPException on every failure
|
||||
(404 missing, 409 already completed, 400 validation).
|
||||
"""
|
||||
async with conn.transaction():
|
||||
# Row lock serialises concurrent imports AND a concurrent DELETE of
|
||||
# the same CSR; works across multiple uvicorn workers (DB-level lock).
|
||||
row = await conn.fetchrow(
|
||||
"SELECT * FROM ssl_csrs WHERE id = $1 FOR UPDATE", csr_id
|
||||
)
|
||||
if not row:
|
||||
raise HTTPException(status_code=404, detail="CSR not found")
|
||||
if row['status'] == 'completed':
|
||||
raise HTTPException(
|
||||
status_code=409,
|
||||
detail=(
|
||||
f"CSR '{row['name']}' is already completed — certificate "
|
||||
f"id {row['ssl_certificate_id']} was imported from it. "
|
||||
"Create a new CSR to reissue."
|
||||
),
|
||||
)
|
||||
if not row['private_key_pem']:
|
||||
raise HTTPException(
|
||||
status_code=500,
|
||||
detail=(
|
||||
"Stored CSR private key is missing — the CSR row is "
|
||||
"corrupt. Delete it and create a new CSR."
|
||||
),
|
||||
)
|
||||
# Issue #53: the column holds a Fernet token from v1.10.1 on, and a raw PEM for rows
|
||||
# written before it. decrypt_csr_private_key accepts both, so no data migration is
|
||||
# needed. A None here means the token cannot be decrypted — SECRET_KEY was rotated
|
||||
# without CSR_ENCRYPTION_KEY set. Fail loudly: the key is gone, so the CA's certificate
|
||||
# can never be paired with it, and silently falling through would surface as the far
|
||||
# more confusing "certificate does not match this CSR's private key".
|
||||
stored_key = decrypt_csr_private_key(row['private_key_pem'])
|
||||
if not stored_key:
|
||||
raise HTTPException(
|
||||
status_code=500,
|
||||
detail=(
|
||||
f"The stored private key for CSR '{row['name']}' cannot be decrypted. This "
|
||||
"happens when SECRET_KEY was rotated while CSR_ENCRYPTION_KEY was not set. "
|
||||
"The key is unrecoverable, so this CSR can no longer be completed — delete "
|
||||
"it and create a new one (then have the new CSR signed)."
|
||||
),
|
||||
)
|
||||
|
||||
effective_name = getattr(imp, 'name', None) or row['name']
|
||||
|
||||
# Parse the pasted certificate FIRST so a malformed/truncated CA
|
||||
# response gets the manual flow's 400, not a 500 from the key-match
|
||||
# step below (verify_certificate_key_match reports an unparseable
|
||||
# cert as match=None, which we treat as an integrity failure).
|
||||
from utils.ssl_parser import parse_ssl_certificate, verify_certificate_key_match
|
||||
precheck = parse_ssl_certificate(imp.certificate_content)
|
||||
if precheck.get('error'):
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=f"Invalid SSL certificate: {precheck['error']}",
|
||||
)
|
||||
|
||||
# THE defining check of this feature: the CA response must match the
|
||||
# key we generated. Deliberately stricter than create_cert_row's
|
||||
# lenient fallback — we generated this key ourselves, so an
|
||||
# unverifiable pair is an integrity failure, not operator input.
|
||||
match_result = verify_certificate_key_match(imp.certificate_content, stored_key)
|
||||
if match_result.get('match') is False:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=(
|
||||
"The signed certificate does not match this CSR's private "
|
||||
"key — the CA response likely belongs to a different "
|
||||
"CSR/key. Verify you pasted the certificate that was "
|
||||
"issued for this exact CSR."
|
||||
),
|
||||
)
|
||||
if match_result.get('match') is not True:
|
||||
raise HTTPException(
|
||||
status_code=500,
|
||||
detail=(
|
||||
"Could not verify the certificate/key pair: "
|
||||
f"{match_result.get('reason', 'unknown')}"
|
||||
),
|
||||
)
|
||||
|
||||
# Full parse/validation pipeline shared with the manual + wizard
|
||||
# flows: invalid PEM, bad chain and already-expired certs all 400.
|
||||
payload = SimpleNamespace(
|
||||
name=effective_name,
|
||||
certificate_content=imp.certificate_content,
|
||||
private_key_content=stored_key,
|
||||
chain_content=getattr(imp, 'chain_content', None),
|
||||
usage_type=getattr(imp, 'usage_type', 'frontend') or 'frontend',
|
||||
)
|
||||
fields = ssl_service._prepare_cert_fields(payload)
|
||||
|
||||
# Global name uniqueness (ssl_certificates.cluster_id is always NULL
|
||||
# under the R38 schema, so name is effectively a global namespace).
|
||||
existing = await conn.fetchrow(
|
||||
"SELECT id, is_active FROM ssl_certificates WHERE name = $1 LIMIT 1",
|
||||
effective_name,
|
||||
)
|
||||
if existing and existing['is_active']:
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=(
|
||||
f"An active SSL certificate named '{effective_name}' "
|
||||
"already exists (created after this CSR). Delete or "
|
||||
"rename it, or pass a different `name` in the import "
|
||||
"request — the CSR stays pending and can be re-imported."
|
||||
),
|
||||
)
|
||||
|
||||
reactivated = False
|
||||
if existing and not existing['is_active']:
|
||||
# Reactivate the soft-deleted row (mirrors create_cert_row):
|
||||
# preserves the row id so historical references keep working.
|
||||
await conn.execute(
|
||||
"DELETE FROM ssl_certificate_clusters WHERE ssl_certificate_id = $1",
|
||||
existing['id'],
|
||||
)
|
||||
await conn.execute(
|
||||
"""
|
||||
UPDATE ssl_certificates
|
||||
SET is_active = TRUE,
|
||||
last_config_status = 'PENDING',
|
||||
certificate_content = $2,
|
||||
private_key_content = $3,
|
||||
chain_content = $4,
|
||||
primary_domain = $5,
|
||||
all_domains = $6::jsonb,
|
||||
expiry_date = $7,
|
||||
usage_type = $8,
|
||||
issuer = $9,
|
||||
fingerprint = $10,
|
||||
status = $11,
|
||||
days_until_expiry = $12,
|
||||
source = 'csr',
|
||||
updated_at = CURRENT_TIMESTAMP
|
||||
WHERE id = $1
|
||||
""",
|
||||
existing['id'],
|
||||
fields['cert_content'],
|
||||
fields['private_key_content'],
|
||||
fields['chain_content'],
|
||||
fields['primary_domain'],
|
||||
json.dumps(fields['all_domains']),
|
||||
fields['expiry_date'],
|
||||
fields['usage_type'],
|
||||
fields['issuer'],
|
||||
fields['fingerprint'],
|
||||
fields['status'],
|
||||
fields['days_until_expiry'],
|
||||
)
|
||||
cert_id = existing['id']
|
||||
reactivated = True
|
||||
logger.info(
|
||||
f"csr_service.import_signed_certificate: reactivated "
|
||||
f"soft-deleted cert '{effective_name}' (id={cert_id}) for CSR {csr_id}"
|
||||
)
|
||||
else:
|
||||
cert_id = await conn.fetchval(
|
||||
"""
|
||||
INSERT INTO ssl_certificates (
|
||||
name, primary_domain, certificate_content, private_key_content,
|
||||
chain_content, expiry_date, issuer, fingerprint, status,
|
||||
days_until_expiry, all_domains, is_active, cluster_id,
|
||||
last_config_status, usage_type, source
|
||||
) VALUES (
|
||||
$1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11::jsonb,
|
||||
TRUE, NULL, 'PENDING', $12, 'csr'
|
||||
)
|
||||
RETURNING id
|
||||
""",
|
||||
effective_name,
|
||||
fields['primary_domain'],
|
||||
fields['cert_content'],
|
||||
fields['private_key_content'],
|
||||
fields['chain_content'],
|
||||
fields['expiry_date'],
|
||||
fields['issuer'],
|
||||
fields['fingerprint'],
|
||||
fields['status'],
|
||||
fields['days_until_expiry'],
|
||||
json.dumps(fields['all_domains']),
|
||||
fields['usage_type'],
|
||||
)
|
||||
|
||||
# Cluster bindings: global = zero junction rows (existing convention).
|
||||
if not getattr(imp, 'is_global', False):
|
||||
for cluster_id in (getattr(imp, 'cluster_ids', None) or []):
|
||||
await ssl_service.ensure_cluster_junction(conn, cert_id, cluster_id)
|
||||
|
||||
# Complete the CSR and destroy the key copy — the key now lives on
|
||||
# the certificate row only, like every other key in the system.
|
||||
await conn.execute(
|
||||
"""
|
||||
UPDATE ssl_csrs
|
||||
SET status = 'completed',
|
||||
ssl_certificate_id = $2,
|
||||
private_key_pem = NULL,
|
||||
completed_at = CURRENT_TIMESTAMP,
|
||||
updated_at = CURRENT_TIMESTAMP
|
||||
WHERE id = $1
|
||||
""",
|
||||
csr_id,
|
||||
cert_id,
|
||||
)
|
||||
|
||||
warnings = diff_domains(_maybe_json_list(row['sans']), fields['all_domains'])
|
||||
if reactivated:
|
||||
warnings.append(
|
||||
f"A soft-deleted certificate named '{effective_name}' was "
|
||||
f"reactivated (row id {cert_id}) — existing entities that still "
|
||||
"reference that id now serve the newly imported certificate."
|
||||
)
|
||||
|
||||
return {
|
||||
'certificate_id': cert_id,
|
||||
'certificate_name': effective_name,
|
||||
'primary_domain': fields['primary_domain'],
|
||||
'warnings': warnings,
|
||||
'reactivated': reactivated,
|
||||
}
|
||||
@@ -5,8 +5,8 @@ A small adapter layer so DNS-01 challenges can publish/clean up the
|
||||
additive at the RRset level (add/remove a single value by name+content, never
|
||||
overwrite-by-name) so multiple coexisting values at one name (wildcard + apex) work.
|
||||
|
||||
MVP providers: manual (user publishes the TXT themselves) and Cloudflare. New providers
|
||||
plug in via the registry without touching the orchestration.
|
||||
Providers: manual (user publishes the TXT themselves), Cloudflare, and GoDaddy (v1.10.0). New
|
||||
providers plug in via the registry without touching the orchestration.
|
||||
"""
|
||||
from .base import DnsProvider, DnsProviderError
|
||||
from .registry import get_provider, list_providers, is_supported
|
||||
|
||||
@@ -0,0 +1,512 @@
|
||||
"""GoDaddy DNS provider for ACME DNS-01 (Issue #35 follow-up, v1.10.0).
|
||||
|
||||
Uses the GoDaddy Domains API v1 over aiohttp (no new dependency). The base URL is a hardcoded
|
||||
constant and redirects are not followed (no user-controlled URL — only the already-validated
|
||||
domain name selects which zone is touched), which is the same reason cloudflare.py is exempt from
|
||||
utils/ssrf_guard.py. Every failure is wrapped in DnsProviderError with a SANITIZED message: the
|
||||
API Key and Secret are scrubbed out of any text that could reach a log, an order event, or
|
||||
letsencrypt_orders.error_detail.
|
||||
|
||||
Two GoDaddy-specific hazards drive the shape of this module — neither exists on Cloudflare:
|
||||
|
||||
1. NO PER-VALUE WRITE. `PUT /v1/domains/{d}/records/TXT/{name}` REPLACES the entire RRset at that
|
||||
type+name; it does not merge. A certificate for `example.com` + `*.example.com` publishes two
|
||||
DIFFERENT TXT values at the SAME name `_acme-challenge.example.com` (base.py's additive
|
||||
contract), so a naive single-value PUT would silently destroy the sibling and fail the wildcard
|
||||
authorization. Every mutation here is therefore read-modify-write: GET the current RRset, merge,
|
||||
PUT the whole list back. An EMPTY array is rejected (422 INVALID_BODY, "Records must be
|
||||
specified"), so removing the LAST value must use DELETE — never `PUT []`.
|
||||
|
||||
2. ZONE-DESTRUCTIVE SIBLING PATHS. `PUT /v1/domains/{d}/records/TXT` (three segments, no name)
|
||||
wipes EVERY TXT in the zone — SPF, DKIM, DMARC, Microsoft/Google verification — and
|
||||
`PUT /v1/domains/{d}/records` wipes the whole zone (this is dehydrated issue #430 verbatim).
|
||||
The record path is built only by _rrset_path(), which refuses an empty zone or relative name so
|
||||
a URL can never collapse onto one of those endpoints.
|
||||
|
||||
Concurrency: v1 has no ETag, no If-Match and no per-record id, so read-modify-write can lose an
|
||||
update if two mutations at one name overlap. Today they cannot: orders are advanced sequentially
|
||||
(`for oid in claimed_ids: await advance_dns01_order(oid)` in main.py) and an order's challenges are
|
||||
published sequentially (`for ch in challenges: await provider.add_txt_record(...)` in
|
||||
dns01_orchestrator.py), so the apex+wildcard pair is strictly ordered and the second publish sees
|
||||
the first. _rrset_lock() makes that safety structural rather than incidental. Across REPLICAS the
|
||||
window is real but narrow (two orders publishing at the same record name in overlapping cycles) and
|
||||
self-healing: a lost publish ends `invalid` and the bounded retry chain mints a fresh order, a lost
|
||||
cleanup is retried by the reconcile sweep, and an orphaned `_acme-challenge` TXT is inert. The real
|
||||
fix is the v3 API (POST + DELETE by recordId, natively per-value), which is PAT-only and a
|
||||
follow-up; it is deliberately not used here because v1 + sso-key is what operators can use today.
|
||||
|
||||
Credentials: an API Key + Secret pair from https://developer.godaddy.com/keys. It must be a
|
||||
PRODUCTION key — the first key the dashboard issues is an OTE (test) key and an OTE credential
|
||||
against api.godaddy.com returns 401. A Personal Access Token also works: paste it as the API Key
|
||||
and leave the Secret blank, and the Authorization header becomes `Bearer <token>`. That path is not
|
||||
cosmetic — GoDaddy marks sso-key "deprecated, supported through 2026" and the current v1 OpenAPI
|
||||
advertises only bearer auth, so the PAT is the migration target, not an alternative.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import asyncio
|
||||
import logging
|
||||
from typing import Any, Dict, List, Optional, Tuple
|
||||
from urllib.parse import quote
|
||||
|
||||
import aiohttp
|
||||
|
||||
from .base import DnsProvider, DnsProviderError
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
GODADDY_API_BASE = "https://api.godaddy.com/v1"
|
||||
_TIMEOUT = aiohttp.ClientTimeout(total=20)
|
||||
|
||||
# GoDaddy enforces a 600s (10 min) TTL floor at request time. The published v1 OpenAPI declares no
|
||||
# minimum, so a smaller value is not caught by the schema — it fails with
|
||||
# 422 {"code":"INVALID_BODY","fields":[{"message":"must have a minimum value of 600", ...}]}.
|
||||
# Pin the floor; DNS-01 has no reason to want anything longer.
|
||||
_TXT_TTL = 600
|
||||
|
||||
# Read-modify-write serialization, keyed by the RRset (record name), not the zone — the RRset is the
|
||||
# actual unit of contention, and keying on it avoids serializing unrelated subdomains of one zone.
|
||||
# The orchestrator is sequential today (see the module docstring), so this is defence in depth: it
|
||||
# is what stops a future `asyncio.gather()` over the publish loop from silently breaking every
|
||||
# wildcard+apex certificate. Bounded in practice by the certificate inventory of one process, so
|
||||
# there is no eviction; the entries are empty Lock objects.
|
||||
_RRSET_LOCKS: Dict[str, asyncio.Lock] = {}
|
||||
|
||||
|
||||
def _rrset_lock(record_name: str) -> asyncio.Lock:
|
||||
key = (record_name or "").rstrip(".").lower()
|
||||
lock = _RRSET_LOCKS.get(key)
|
||||
if lock is None:
|
||||
# Safe without a guard: a single event loop never preempts between the get and the assign.
|
||||
lock = _RRSET_LOCKS[key] = asyncio.Lock()
|
||||
return lock
|
||||
|
||||
|
||||
def _scrub(text: str, *secrets: str) -> str:
|
||||
"""Remove credential substrings from a message before it can reach a log or an order event.
|
||||
|
||||
GoDaddy error bodies do not echo the Authorization header, so this is belt-and-braces — but it
|
||||
makes base.py's "never leak a secret" invariant structural instead of a matter of care. Short
|
||||
strings are skipped so a 1-2 char credential fragment cannot blank out ordinary prose.
|
||||
"""
|
||||
out = text or ""
|
||||
for secret in secrets:
|
||||
if secret and len(secret) >= 4:
|
||||
out = out.replace(secret, "***")
|
||||
return out[:300]
|
||||
|
||||
|
||||
def _relative_name(fqdn: str, zone: str) -> str:
|
||||
"""Convert an absolute record name to the zone-relative form GoDaddy's API requires.
|
||||
|
||||
GoDaddy record names are RELATIVE to the zone with NO trailing dot, and the zone apex is the
|
||||
literal "@" — never an empty string (which would collapse the URL onto the zone-wide TXT
|
||||
endpoint) and never the domain name itself.
|
||||
|
||||
("_acme-challenge.example.com", "example.com") -> "_acme-challenge"
|
||||
("_acme-challenge.foo.bar.example.com", "example.com") -> "_acme-challenge.foo.bar"
|
||||
("example.com", "example.com") -> "@"
|
||||
"""
|
||||
f = (fqdn or "").rstrip(".").lower()
|
||||
z = (zone or "").rstrip(".").lower()
|
||||
if z and f == z:
|
||||
return "@"
|
||||
if z and f.endswith("." + z):
|
||||
return f[: -(len(z) + 1)]
|
||||
# Defensive: callers always pass a zone that _resolve_domain derived from this very name.
|
||||
return f or "@"
|
||||
|
||||
|
||||
def _rrset_path(zone: str, rel_name: str) -> str:
|
||||
"""Build the 4-segment record path `/domains/{zone}/records/TXT/{name}`.
|
||||
|
||||
SAFETY GATE: an empty rel_name would collapse the URL to `/domains/{zone}/records/TXT` — the
|
||||
endpoint that replaces EVERY TXT record in the zone (SPF, DKIM, DMARC, domain verifications).
|
||||
A "." or ".." segment does the same thing one step later: `quote()` leaves both untouched
|
||||
(they are unreserved) and yarl normalizes dot segments away when it builds the URL, so
|
||||
".../records/TXT/.." would resolve to ".../records" — the whole-zone endpoint. Refuse both
|
||||
rather than build them. `safe=''` percent-encodes the apex "@" as "%40" (accepted bare too,
|
||||
but safer through proxies); "_", "-" and "." are unreserved and pass through unchanged, so a
|
||||
multi-label relative name stays one readable path segment.
|
||||
"""
|
||||
if not zone or not rel_name:
|
||||
raise DnsProviderError("Internal error: refusing to build a zone-wide GoDaddy TXT record path.")
|
||||
if rel_name.strip(".") == "" or any(part in (".", "..") for part in rel_name.split("/")):
|
||||
raise DnsProviderError("Internal error: refusing to build a GoDaddy TXT path from a dot segment.")
|
||||
return f"/domains/{quote(zone, safe='')}/records/TXT/{quote(rel_name, safe='')}"
|
||||
|
||||
|
||||
def _live_values(records: List[Dict]) -> List[str]:
|
||||
"""The non-empty `data` values in an RRset read.
|
||||
|
||||
GoDaddy leaves tombstone rows with `"data": ""` behind at a name after some removals. Echoing
|
||||
one back in a PUT body is rejected with 422 INVALID_BODY, so every field implementation
|
||||
(lego, acme.sh, Posh-ACME) filters them independently — so do we.
|
||||
"""
|
||||
out: List[str] = []
|
||||
for rec in records or []:
|
||||
data = (rec or {}).get("data") or ""
|
||||
if data:
|
||||
out.append(data)
|
||||
return out
|
||||
|
||||
|
||||
def _merge_add(existing: List[Dict], value: str) -> Optional[List[Dict]]:
|
||||
"""PUT body that adds `value` while preserving every coexisting sibling value.
|
||||
|
||||
Returns None when `value` is already present — an idempotent no-op, which is where an ACME
|
||||
retry cycle lands.
|
||||
"""
|
||||
live = _live_values(existing)
|
||||
if value in live:
|
||||
return None
|
||||
return [{"data": d, "ttl": _TXT_TTL} for d in live] + [{"data": value, "ttl": _TXT_TTL}]
|
||||
|
||||
|
||||
def _merge_remove(existing: List[Dict], value: str) -> Optional[List[Dict]]:
|
||||
"""PUT body that removes ONLY `value`, keeping every sibling.
|
||||
|
||||
Three-state result, because GoDaddy needs three different calls:
|
||||
None -> `value` is not there; already gone, tolerate (base.py's remove contract).
|
||||
[] -> it was the last value; the caller must DELETE, since `PUT []` is rejected.
|
||||
list -> PUT this body.
|
||||
"""
|
||||
live = _live_values(existing)
|
||||
if value not in live:
|
||||
return None
|
||||
return [{"data": d, "ttl": _TXT_TTL} for d in live if d != value]
|
||||
|
||||
|
||||
def _require_rrset(body: Any) -> List[Dict]:
|
||||
"""The RRset read, or a refusal.
|
||||
|
||||
FAIL CLOSED. A read that did not come back as a JSON array must never be treated as "the RRset
|
||||
is empty" — the very next call is a full-RRset PUT, so coercing an unreadable read to [] would
|
||||
replace every coexisting sibling value with just ours. Failing instead is free: the orchestrator
|
||||
reverts the publish flag and retries next cycle, while a destructive PUT is unrecoverable.
|
||||
"""
|
||||
if not isinstance(body, list):
|
||||
raise DnsProviderError(
|
||||
"GoDaddy returned an unreadable TXT record list; refusing to replace the record set."
|
||||
)
|
||||
return body
|
||||
|
||||
|
||||
def _error_fields(body: Any) -> Tuple[str, str]:
|
||||
"""The whitelisted (code, message) pair from a GoDaddy error body.
|
||||
|
||||
Only these two string fields are ever read; the raw body is never interpolated into a
|
||||
user-facing message.
|
||||
"""
|
||||
if not isinstance(body, dict):
|
||||
return "", ""
|
||||
code = body.get("code")
|
||||
message = body.get("message")
|
||||
return (code if isinstance(code, str) else ""), (message if isinstance(message, str) else "")
|
||||
|
||||
|
||||
def _retry_after_seconds(headers, body: Any) -> int:
|
||||
"""Seconds to wait after a 429.
|
||||
|
||||
The current platform sends `Retry-After` and `ratelimit-reset` headers with no body, while the
|
||||
legacy v1 OpenAPI documents an `ErrorLimit` body carrying `retryAfterSec`. All three shapes are
|
||||
live in the wild — and so is none of them, hence the 60s default.
|
||||
"""
|
||||
for key in ("Retry-After", "ratelimit-reset"):
|
||||
raw = (headers or {}).get(key)
|
||||
if raw:
|
||||
try:
|
||||
return max(1, int(str(raw).strip()))
|
||||
except (TypeError, ValueError):
|
||||
pass
|
||||
if isinstance(body, dict):
|
||||
raw = body.get("retryAfterSec")
|
||||
if isinstance(raw, int) and raw > 0:
|
||||
return raw
|
||||
return 60
|
||||
|
||||
|
||||
class _GoDaddyHTTPError(DnsProviderError):
|
||||
"""A DnsProviderError that also carries the HTTP status and GoDaddy `code`.
|
||||
|
||||
Callers INSIDE this module branch on the status (tolerate a 404 read-back, fall through a
|
||||
zone probe), while everything outside — dns01_orchestrator, letsencrypt.py — still sees a
|
||||
plain sanitized DnsProviderError and needs no change.
|
||||
"""
|
||||
|
||||
def __init__(self, message: str, status: int, code: str = ""):
|
||||
super().__init__(message)
|
||||
self.status = status
|
||||
self.code = code
|
||||
|
||||
|
||||
class GoDaddyDNSProvider(DnsProvider):
|
||||
name = "godaddy"
|
||||
label = "GoDaddy"
|
||||
automated = True
|
||||
credential_fields: List[Dict] = [
|
||||
{
|
||||
"key": "api_key",
|
||||
"label": "API Key",
|
||||
"type": "password",
|
||||
"required": True,
|
||||
"max_length": 200,
|
||||
"help": ("Production API Key from developer.godaddy.com/keys — the first key the dashboard "
|
||||
"issues is an OTE (test) key and will be rejected. A Personal Access Token also "
|
||||
"works: paste it here and leave the Secret blank."),
|
||||
},
|
||||
{
|
||||
"key": "api_secret",
|
||||
"label": "API Secret",
|
||||
"type": "password",
|
||||
"required": False,
|
||||
"max_length": 200,
|
||||
"help": ("The Secret half of the same API Key pair. Leave blank ONLY if the field above "
|
||||
"holds a Personal Access Token. The account also needs at least one registered "
|
||||
"domain for GoDaddy to allow DNS API access at all."),
|
||||
},
|
||||
]
|
||||
|
||||
def __init__(self, credentials: Dict[str, str] | None = None):
|
||||
super().__init__(credentials)
|
||||
# Normalize, never validate: dns01_orchestrator.py calls get_provider() OUTSIDE any
|
||||
# DnsProviderError guard, so a constructor that raised on malformed credentials would escape
|
||||
# as an unhandled exception in the 60s background cycle. The UI drops blank fields before
|
||||
# submitting, so a left-blank field arrives as a MISSING key rather than "" — `.get() or ""`
|
||||
# covers both.
|
||||
self._api_key = (self.credentials.get("api_key") or "").strip()
|
||||
self._api_secret = (self.credentials.get("api_secret") or "").strip()
|
||||
# Per-INSTANCE zone cache. A module-level cache would leak one ACME account's zone visibility
|
||||
# into another's; an instance lives for exactly one orchestrator step, which is precisely the
|
||||
# scope where caching pays off (apex + wildcard resolve the same zone from the same name).
|
||||
self._zone_cache: Dict[str, str] = {}
|
||||
|
||||
def _auth_header(self) -> str:
|
||||
"""`sso-key <key>:<secret>` when a Secret is present, else `Bearer <token>` for a PAT.
|
||||
|
||||
Literal prefix, one space, a single colon — no base64, no URL-encoding, no quotes. Keeping
|
||||
this as one swappable string is what makes GoDaddy's sso-key sunset a credential change
|
||||
rather than a code change.
|
||||
"""
|
||||
if self._api_secret:
|
||||
return f"sso-key {self._api_key}:{self._api_secret}"
|
||||
return f"Bearer {self._api_key}"
|
||||
|
||||
def _headers(self) -> Dict[str, str]:
|
||||
# Accept is not optional: these endpoints content-negotiate application/xml and
|
||||
# text/javascript. Content-Type is required on every write or GoDaddy answers 400/415.
|
||||
return {
|
||||
"Authorization": self._auth_header(),
|
||||
"Accept": "application/json",
|
||||
"Content-Type": "application/json",
|
||||
}
|
||||
|
||||
def _http_error(self, status: int, code: str, message: str, retry_after: Optional[int]) -> _GoDaddyHTTPError:
|
||||
"""Map an HTTP status to a sanitized, operator-actionable DnsProviderError.
|
||||
|
||||
These strings land in acme_order_events and letsencrypt_orders.error_detail and are shown
|
||||
in the order timeline, so each one names what to fix. GoDaddy's own `code`/`message` is
|
||||
appended when present because the two 403 causes — account not eligible for the DNS API vs.
|
||||
a PAT missing `domains.dns:update` — are indistinguishable by status alone. Scrubbing
|
||||
happens HERE, at the single point where provider-supplied text enters a message, so a new
|
||||
caller cannot forget it.
|
||||
"""
|
||||
code = _scrub(code, self._api_key, self._api_secret)
|
||||
message = _scrub(message, self._api_key, self._api_secret)
|
||||
if status == 401:
|
||||
detail = ("GoDaddy rejected the API credentials. Check they are a PRODUCTION Key/Secret pair "
|
||||
"from developer.godaddy.com/keys — the first key the dashboard issues is an OTE "
|
||||
"(test) key and is not valid here.")
|
||||
elif status == 403:
|
||||
detail = ("GoDaddy denied access to the DNS API. The account needs at least one registered "
|
||||
"domain, and a Personal Access Token needs the domains.domain:read and "
|
||||
"domains.dns:update scopes.")
|
||||
elif status == 404:
|
||||
detail = ("GoDaddy has no zone for this domain (check it is registered in this account and "
|
||||
"uses GoDaddy nameservers).")
|
||||
elif status == 409:
|
||||
detail = "GoDaddy reports this domain is not eligible to have its DNS records changed."
|
||||
elif status == 422:
|
||||
detail = "GoDaddy rejected the record change as invalid (HTTP 422)."
|
||||
elif status == 429:
|
||||
detail = f"GoDaddy rate limit reached; retry in ~{retry_after or 60}s."
|
||||
else:
|
||||
detail = f"GoDaddy API error (HTTP {status})."
|
||||
if code or message:
|
||||
detail += f" (GoDaddy: {code}{': ' + message if message else ''})"
|
||||
return _GoDaddyHTTPError(detail, status=status, code=code)
|
||||
|
||||
async def _request(self, session: aiohttp.ClientSession, method: str, path: str, **kwargs) -> Any:
|
||||
"""One GoDaddy API call. Returns the parsed JSON body, or None for the empty-bodied writes.
|
||||
|
||||
Raises a SANITIZED _GoDaddyHTTPError / DnsProviderError — never the credentials, never the
|
||||
request, never a response body verbatim.
|
||||
"""
|
||||
url = f"{GODADDY_API_BASE}{path}"
|
||||
try:
|
||||
async with session.request(
|
||||
method, url, headers=self._headers(), allow_redirects=False, **kwargs
|
||||
) as resp:
|
||||
try:
|
||||
# content_type=None: every GoDaddy write answers 200/204 with an EMPTY body, and
|
||||
# aiohttp would otherwise raise on the missing/other content type before parsing.
|
||||
body = await resp.json(content_type=None)
|
||||
except ValueError:
|
||||
# ONLY a decode failure (JSONDecodeError subclasses ValueError) is swallowed —
|
||||
# an empty write body, or an HTML error page on a >=400. A transport failure
|
||||
# mid-read (ClientPayloadError, TimeoutError) must NOT land here: it would look
|
||||
# identical to "empty body", and a caller that reads an RRset would then see
|
||||
# None and could mistake it for an empty RRset. Those propagate to the handlers
|
||||
# below and become a real DnsProviderError.
|
||||
body = None
|
||||
# 2xx only. Redirects are deliberately not followed (aiohttp would forward the
|
||||
# Authorization header), so a 3xx is a failed call — treating `< 400` as success
|
||||
# would report a redirected write as a silent no-op.
|
||||
if 200 <= resp.status < 300:
|
||||
return body
|
||||
code, message = _error_fields(body)
|
||||
retry_after = _retry_after_seconds(resp.headers, body) if resp.status == 429 else None
|
||||
raise self._http_error(resp.status, code, message, retry_after)
|
||||
except DnsProviderError:
|
||||
raise
|
||||
except aiohttp.ClientError as exc:
|
||||
# Only the exception TYPE is interpolated: an aiohttp client error's str() can carry the
|
||||
# request URL, and the message is persisted to the order timeline.
|
||||
raise DnsProviderError(f"Could not reach the GoDaddy API ({type(exc).__name__}).")
|
||||
except Exception as exc: # noqa: BLE001
|
||||
raise DnsProviderError(f"Unexpected GoDaddy API failure ({type(exc).__name__}).")
|
||||
|
||||
async def verify_credentials(self) -> Dict:
|
||||
if not self._api_key:
|
||||
return {"ok": False, "detail": "No GoDaddy API Key provided."}
|
||||
try:
|
||||
async with aiohttp.ClientSession(timeout=_TIMEOUT) as session:
|
||||
# Cheapest read-only check: one request, no zone needed. Deliberately NOT
|
||||
# GET /v1/domains/{domain} — GoDaddy has rejected that details call for small
|
||||
# accounts since 2024-05 while record-level calls keep working, so verifying with it
|
||||
# produces false negatives on accounts where DNS-01 would succeed.
|
||||
body = await self._request(session, "GET", "/domains?limit=1")
|
||||
if not isinstance(body, list):
|
||||
return {"ok": False, "detail": "GoDaddy returned an unexpected response to the credential check."}
|
||||
if not body:
|
||||
# An empty list is NOT a failure: sub-zones delegated to GoDaddy nameservers are
|
||||
# manageable via the records API but never appear in the domain listing.
|
||||
return {"ok": True, "detail": ("GoDaddy credentials valid, but no domains are visible in this "
|
||||
"account — the domain you validate must be registered here, or "
|
||||
"be a zone delegated to GoDaddy nameservers.")}
|
||||
return {"ok": True, "detail": "GoDaddy credentials valid."}
|
||||
except DnsProviderError as exc:
|
||||
detail = str(exc)
|
||||
if not self._api_secret:
|
||||
# The Bearer path is silent otherwise, and a half-filled form is the likeliest cause.
|
||||
detail += (" Note: no API Secret was entered, so the API Key was sent as a Personal Access "
|
||||
"Token (Bearer). If you have a Key + Secret pair, enter both halves.")
|
||||
return {"ok": False, "detail": detail}
|
||||
except Exception: # noqa: BLE001 — never leak an internal/transport error verbatim
|
||||
return {"ok": False, "detail": "Could not verify the GoDaddy credentials."}
|
||||
|
||||
async def _resolve_domain(self, session: aiohttp.ClientSession, record_name: str) -> str:
|
||||
"""Find the most-specific (longest-suffix) GoDaddy-managed zone for an absolute record name.
|
||||
|
||||
GoDaddy has no `/zones?name=` equivalent, so this walks suffixes longest-to-shortest and
|
||||
probes `GET /v1/domains/{candidate}/records/NS`. That probe (rather than the domain listing
|
||||
or the domain-details call) is deliberate: it finds sub-zones delegated to GoDaddy
|
||||
nameservers, which never appear in `GET /v1/domains` at all, and it does not depend on the
|
||||
details endpoint that small accounts are rejected from.
|
||||
"""
|
||||
cached = self._zone_cache.get(record_name)
|
||||
if cached:
|
||||
return cached
|
||||
labels = record_name.rstrip(".").lower().split(".")
|
||||
for i in range(len(labels) - 1):
|
||||
candidate = ".".join(labels[i:])
|
||||
if candidate.count(".") < 1:
|
||||
break # a zone needs at least two labels
|
||||
try:
|
||||
body = await self._request(
|
||||
session, "GET", f"/domains/{quote(candidate, safe='')}/records/NS"
|
||||
)
|
||||
except _GoDaddyHTTPError as exc:
|
||||
if exc.status in (404, 422):
|
||||
continue # not a zone in this account — keep walking
|
||||
# 401/403/409/429/5xx are credential, eligibility or platform failures, not
|
||||
# "wrong zone". Continuing would burn the rate-limit budget re-failing on every
|
||||
# remaining suffix and would bury the real cause under "no managed domain".
|
||||
raise
|
||||
if isinstance(body, list) and body:
|
||||
self._zone_cache[record_name] = candidate
|
||||
return candidate
|
||||
raise DnsProviderError(f"No managed GoDaddy domain found for {record_name}.")
|
||||
|
||||
async def add_txt_record(self, name: str, value: str) -> None:
|
||||
async with _rrset_lock(name):
|
||||
async with aiohttp.ClientSession(timeout=_TIMEOUT) as session:
|
||||
zone = await self._resolve_domain(session, name)
|
||||
path = _rrset_path(zone, _relative_name(name, zone))
|
||||
try:
|
||||
existing = await self._request(session, "GET", path)
|
||||
except _GoDaddyHTTPError as exc:
|
||||
if exc.status != 404:
|
||||
raise
|
||||
# Some accounts 404 reading back a record set in a zone whose WRITES succeed
|
||||
# (acme.sh #6517). Reachable only when the NS probe resolved the zone but the
|
||||
# TXT read 404s — if the NS probe itself 404s we never get here and the caller
|
||||
# sees "No managed GoDaddy domain found", which is the honest answer. We cannot
|
||||
# merge what we cannot read, and a single-value PUT would destroy any coexisting
|
||||
# sibling, so PATCH is the only correct recovery: it is the one genuinely
|
||||
# ADDITIVE primitive in v1 ("Appends DNS records ... Existing records with the
|
||||
# same type and name are preserved"). It cannot dedupe, but a duplicate
|
||||
# identical TXT is harmless for validation and cleanup removes the whole RRset.
|
||||
await self._request(
|
||||
session, "PATCH", f"/domains/{quote(zone, safe='')}/records",
|
||||
json=[{"type": "TXT", "name": _relative_name(name, zone),
|
||||
"data": value, "ttl": _TXT_TTL}],
|
||||
)
|
||||
return
|
||||
body = _merge_add(_require_rrset(existing), value)
|
||||
if body is None:
|
||||
return # already published — idempotent, this is where ACME retries land
|
||||
await self._request(session, "PUT", path, json=body)
|
||||
|
||||
async def remove_txt_record(self, name: str, value: str) -> None:
|
||||
async with _rrset_lock(name):
|
||||
async with aiohttp.ClientSession(timeout=_TIMEOUT) as session:
|
||||
try:
|
||||
zone = await self._resolve_domain(session, name)
|
||||
except _GoDaddyHTTPError as exc:
|
||||
# Raise only what a later sweep could plausibly succeed at. reconcile_dns01_cleanup
|
||||
# swallows the error and leaves dns_record_cleaned FALSE, so the row is re-selected
|
||||
# every cycle — and its query takes a bare LIMIT 50, so rows that can NEVER succeed
|
||||
# (revoked key, account lost DNS-API eligibility) would monopolise the whole
|
||||
# cleanup budget and starve every other account. For those terminal statuses we
|
||||
# give up quietly: the orphaned `_acme-challenge` TXT is inert, and the same
|
||||
# credential failure is already loud on the publish path, where it is actionable.
|
||||
if exc.status == 429 or exc.status >= 500:
|
||||
raise
|
||||
return
|
||||
except DnsProviderError:
|
||||
return # zone genuinely not resolvable — nothing we could clean up
|
||||
path = _rrset_path(zone, _relative_name(name, zone))
|
||||
try:
|
||||
existing = await self._request(session, "GET", path)
|
||||
except _GoDaddyHTTPError as exc:
|
||||
if exc.status == 404:
|
||||
return # RRset (or the read) is gone — tolerate
|
||||
raise
|
||||
body = _merge_remove(_require_rrset(existing), value)
|
||||
if body is None:
|
||||
return # our value is not there — already gone, tolerate
|
||||
if not body:
|
||||
# The LAST value at this name. `PUT []` is rejected (422 INVALID_BODY, "Records
|
||||
# must be specified"), so emptying an RRset REQUIRES DELETE. This removes only
|
||||
# TXT at this exact name; other names and other record types are preserved.
|
||||
# Do NOT fall back to the "write an empty string to delete" folklore — that hack
|
||||
# is what creates the tombstone rows _live_values has to filter.
|
||||
try:
|
||||
await self._request(session, "DELETE", path)
|
||||
except _GoDaddyHTTPError as exc:
|
||||
if exc.status == 404:
|
||||
return # raced with another cleanup — tolerate
|
||||
raise
|
||||
return
|
||||
await self._request(session, "PUT", path, json=body)
|
||||
@@ -10,11 +10,13 @@ from typing import Dict, List, Type
|
||||
|
||||
from .base import DnsProvider
|
||||
from .cloudflare import CloudflareDNSProvider
|
||||
from .godaddy import GoDaddyDNSProvider
|
||||
from .manual import ManualDNSProvider
|
||||
|
||||
_PROVIDERS: Dict[str, Type[DnsProvider]] = {
|
||||
ManualDNSProvider.name: ManualDNSProvider,
|
||||
CloudflareDNSProvider.name: CloudflareDNSProvider,
|
||||
GoDaddyDNSProvider.name: GoDaddyDNSProvider,
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -56,14 +56,14 @@ async def create_frontend_row(
|
||||
acl_rules, redirect_rules, use_backend_rules,
|
||||
request_headers, response_headers, options, tcp_request_rules, timeout_client, timeout_http_request,
|
||||
rate_limit, compression, log_separate, monitor_uri,
|
||||
cluster_id, maxconn, updated_at
|
||||
cluster_id, maxconn, log_format, filters, updated_at
|
||||
) VALUES (
|
||||
$1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12,
|
||||
$13, $14, $15, $16, $17, $18, $19,
|
||||
$20, $21, $22,
|
||||
$23, $24, $25, $26, $27, $28,
|
||||
$29, $30, $31, $32,
|
||||
$33, $34, CURRENT_TIMESTAMP
|
||||
$33, $34, $35, $36, CURRENT_TIMESTAMP
|
||||
)
|
||||
RETURNING id
|
||||
""",
|
||||
@@ -101,6 +101,8 @@ async def create_frontend_row(
|
||||
getattr(payload, "monitor_uri", None),
|
||||
cluster_id,
|
||||
getattr(payload, "maxconn", None),
|
||||
getattr(payload, "log_format", None), # Issue #38
|
||||
getattr(payload, "filters", None), # Issue #38
|
||||
)
|
||||
|
||||
if mark_pending:
|
||||
|
||||
@@ -393,6 +393,12 @@ def _categorize_haproxy_directive(line: str) -> str:
|
||||
return "prelude"
|
||||
if s.startswith("acl "):
|
||||
return "acl"
|
||||
# Issue #38: SPOE (and other) `filter` directives must be declared BEFORE
|
||||
# the `http-request send-spoe-group` rules that use them, otherwise HAProxy
|
||||
# fails with "unable to find SPOE engine". Own bucket, flushed right after
|
||||
# `prelude` and before tcp_req/acl/http_req (see flush order below).
|
||||
if s.startswith("filter "):
|
||||
return "filter"
|
||||
if s.startswith("stick-table") or s.startswith("stick "):
|
||||
return "stick"
|
||||
if s.startswith("tcp-request"):
|
||||
@@ -414,6 +420,7 @@ def _categorize_haproxy_directive(line: str) -> str:
|
||||
or s.startswith("compression ")
|
||||
or s.startswith("monitor-uri")
|
||||
or s.startswith("log ")
|
||||
or s.startswith("log-format") # Issue #38: log-format / log-format-sd
|
||||
or s.startswith("description ")
|
||||
or s.startswith("disabled")
|
||||
or s.startswith("enabled")
|
||||
@@ -903,7 +910,7 @@ async def generate_haproxy_config_for_cluster(cluster_id: int, conn: Optional[An
|
||||
# "stick-table already declared").
|
||||
# ─────────────────────────────────────────────────────────────────
|
||||
_fe_buckets: Dict[str, List[str]] = {
|
||||
"prelude": [], "stick": [], "tcp_req": [],
|
||||
"prelude": [], "filter": [], "stick": [], "tcp_req": [],
|
||||
"acl": [], "http_req": [], "http_resp": [],
|
||||
"redirect": [], "use_be": [], "default_be": [],
|
||||
}
|
||||
@@ -996,6 +1003,17 @@ async def generate_haproxy_config_for_cluster(cluster_id: int, conn: Optional[An
|
||||
if line_stripped and line_stripped not in ('[]', '{}', 'null', 'None'):
|
||||
_emit_fe(f" {line_stripped}")
|
||||
|
||||
# Issue #38: emit frontend log-format and SPOE (etc.) filter directives.
|
||||
# `log_format` routes to the `prelude` bucket, `filters` to the `filter`
|
||||
# bucket (both via _emit_fe → _categorize_haproxy_directive), guaranteeing
|
||||
# `filter ...` is rendered before the `http-request send-spoe-group` rules.
|
||||
for _fld in ('log_format', 'filters'):
|
||||
if frontend.get(_fld):
|
||||
for line in frontend[_fld].split('\n'):
|
||||
line_stripped = line.strip()
|
||||
if line_stripped and line_stripped not in ('[]', '{}', 'null', 'None'):
|
||||
_emit_fe(f" {line_stripped}")
|
||||
|
||||
# CRITICAL: Validate frontend-backend mode compatibility
|
||||
if frontend.get('default_backend'):
|
||||
default_backend_name = frontend['default_backend'].strip() if frontend['default_backend'] else ''
|
||||
@@ -1223,6 +1241,7 @@ async def generate_haproxy_config_for_cluster(cluster_id: int, conn: Optional[An
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
for _bucket_key in (
|
||||
"prelude",
|
||||
"filter",
|
||||
"stick",
|
||||
"tcp_req",
|
||||
"acl",
|
||||
|
||||
+139
-13
@@ -40,10 +40,12 @@ flow.
|
||||
(callers translate to wizard step-jumpback toasts).
|
||||
"""
|
||||
|
||||
import hashlib
|
||||
import json
|
||||
import logging
|
||||
import time
|
||||
from datetime import datetime, timezone
|
||||
from typing import Any, Optional
|
||||
from typing import Any, List, Optional
|
||||
|
||||
from fastapi import HTTPException
|
||||
|
||||
@@ -106,23 +108,22 @@ def _recompute_status_from_expiry(
|
||||
return cert_info_status or "valid", cert_info_days or 0
|
||||
|
||||
|
||||
async def create_cert_row(
|
||||
conn,
|
||||
payload: Any,
|
||||
cluster_id: int,
|
||||
) -> int:
|
||||
"""Insert a row into ssl_certificates (always cluster_id=NULL) + junction
|
||||
binding to the given cluster_id. Returns new ssl_certificate_id.
|
||||
def _prepare_cert_fields(payload: Any) -> dict:
|
||||
"""Parse + validate the PEM material on `payload` and derive every
|
||||
ssl_certificates column value from it (v1.9.0 extraction — shared by
|
||||
`create_cert_row` and the CSR import flow in services/csr_service.py,
|
||||
byte-identical to the former inline body of `create_cert_row`).
|
||||
|
||||
payload is expected to expose:
|
||||
name, certificate_content, private_key_content, chain_content,
|
||||
usage_type (optional, default 'frontend').
|
||||
|
||||
All cert metadata (primary_domain, all_domains, expiry_date,
|
||||
issuer, fingerprint, status, days_until_expiry) is now parsed
|
||||
FROM the PEM content via `parse_ssl_certificate` — operator-
|
||||
supplied values on the payload are accepted as a graceful
|
||||
fallback only when parsing fails (which itself raises 400).
|
||||
Raises HTTPException(400) on any parse/validation failure (invalid PEM,
|
||||
bad private key, cert/key mismatch, bad chain, already-expired cert).
|
||||
|
||||
Returns a dict with keys: cert_content, private_key_content,
|
||||
chain_content, cert_info, primary_domain, all_domains, expiry_date,
|
||||
issuer, fingerprint, status, days_until_expiry, usage_type.
|
||||
"""
|
||||
cert_content = getattr(payload, "certificate_content", None) or ""
|
||||
if not cert_content.strip():
|
||||
@@ -213,6 +214,53 @@ async def create_cert_row(
|
||||
)
|
||||
usage_type = getattr(payload, "usage_type", "frontend") or "frontend"
|
||||
|
||||
return {
|
||||
"cert_content": cert_content,
|
||||
"private_key_content": private_key_content,
|
||||
"chain_content": chain_content,
|
||||
"cert_info": cert_info,
|
||||
"primary_domain": primary_domain,
|
||||
"all_domains": all_domains,
|
||||
"expiry_date": expiry_date,
|
||||
"issuer": issuer,
|
||||
"fingerprint": fingerprint,
|
||||
"status": status,
|
||||
"days_until_expiry": days_until_expiry,
|
||||
"usage_type": usage_type,
|
||||
}
|
||||
|
||||
|
||||
async def create_cert_row(
|
||||
conn,
|
||||
payload: Any,
|
||||
cluster_id: int,
|
||||
) -> int:
|
||||
"""Insert a row into ssl_certificates (always cluster_id=NULL) + junction
|
||||
binding to the given cluster_id. Returns new ssl_certificate_id.
|
||||
|
||||
payload is expected to expose:
|
||||
name, certificate_content, private_key_content, chain_content,
|
||||
usage_type (optional, default 'frontend').
|
||||
|
||||
All cert metadata (primary_domain, all_domains, expiry_date,
|
||||
issuer, fingerprint, status, days_until_expiry) is now parsed
|
||||
FROM the PEM content via `parse_ssl_certificate` — operator-
|
||||
supplied values on the payload are accepted as a graceful
|
||||
fallback only when parsing fails (which itself raises 400).
|
||||
"""
|
||||
fields = _prepare_cert_fields(payload)
|
||||
cert_content = fields["cert_content"]
|
||||
private_key_content = fields["private_key_content"]
|
||||
chain_content = fields["chain_content"]
|
||||
expiry_date = fields["expiry_date"]
|
||||
primary_domain = fields["primary_domain"]
|
||||
all_domains = fields["all_domains"]
|
||||
issuer = fields["issuer"]
|
||||
fingerprint = fields["fingerprint"]
|
||||
status = fields["status"]
|
||||
days_until_expiry = fields["days_until_expiry"]
|
||||
usage_type = fields["usage_type"]
|
||||
|
||||
existing = await conn.fetchrow(
|
||||
"""
|
||||
SELECT s.id, s.is_active
|
||||
@@ -408,3 +456,81 @@ async def validate_server_ca_bundle_eligibility(
|
||||
cluster_id,
|
||||
)
|
||||
return row is not None
|
||||
|
||||
|
||||
async def stage_ssl_config_versions(
|
||||
conn,
|
||||
cert_id: int,
|
||||
cluster_ids: List[int],
|
||||
action: str = "create",
|
||||
created_by: Optional[int] = None,
|
||||
) -> List[dict]:
|
||||
"""Stage one PENDING config version per affected cluster after an SSL
|
||||
certificate mutation (v1.9.0 — distilled from the routers/ssl.py POST
|
||||
/certificates staging loop; used by the CSR import flow).
|
||||
|
||||
Uses the EXACT `ssl-{cert_id}-{action}-{timestamp}` version-name scheme of
|
||||
the manual SSL flow so Apply Management, the `has_pending_config`
|
||||
LIKE-filter ('ssl-' || id || '-%'), and the agent delivery predicates
|
||||
treat CSR-imported certificates identically to manually uploaded ones.
|
||||
Agents are NOT notified here — the operator applies manually.
|
||||
|
||||
Per-cluster failures are caught and reported in the returned
|
||||
sync_results list (the DB save has already succeeded — same semantics as
|
||||
the manual flow, where a config-generation failure never rolls back the
|
||||
certificate row).
|
||||
"""
|
||||
# Local import: keeps services/haproxy_config free to import ssl helpers
|
||||
# without a module-level cycle.
|
||||
from services.haproxy_config import generate_haproxy_config_for_cluster
|
||||
|
||||
sync_results: List[dict] = []
|
||||
for cluster_id in cluster_ids:
|
||||
try:
|
||||
config_content = await generate_haproxy_config_for_cluster(cluster_id)
|
||||
config_hash = hashlib.sha256(config_content.encode()).hexdigest()
|
||||
version_name = f"ssl-{cert_id}-{action}-{int(time.time())}"
|
||||
|
||||
version_created_by = created_by
|
||||
if version_created_by is None:
|
||||
version_created_by = await conn.fetchval(
|
||||
"SELECT id FROM users WHERE username = 'admin' LIMIT 1"
|
||||
) or 1
|
||||
|
||||
await conn.fetchval(
|
||||
"""
|
||||
INSERT INTO config_versions
|
||||
(cluster_id, version_name, config_content, checksum, created_by, is_active, status)
|
||||
VALUES ($1, $2, $3, $4, $5, FALSE, 'PENDING')
|
||||
RETURNING id
|
||||
""",
|
||||
cluster_id,
|
||||
version_name,
|
||||
config_content,
|
||||
config_hash,
|
||||
version_created_by,
|
||||
)
|
||||
logger.info(
|
||||
f"APPLY WORKFLOW: Created PENDING config version {version_name} "
|
||||
f"for cluster {cluster_id} (ssl_service.stage_ssl_config_versions)"
|
||||
)
|
||||
sync_results.append({
|
||||
'node': 'pending',
|
||||
'success': True,
|
||||
'cluster_id': cluster_id,
|
||||
'version': version_name,
|
||||
'status': 'PENDING',
|
||||
'message': 'SSL certificate staged. Click Apply to activate.',
|
||||
})
|
||||
except Exception as e:
|
||||
logger.error(
|
||||
f"Cluster config staging failed for SSL certificate {cert_id} "
|
||||
f"on cluster {cluster_id}: {e}"
|
||||
)
|
||||
sync_results.append({
|
||||
'node': 'cluster',
|
||||
'success': False,
|
||||
'cluster_id': cluster_id,
|
||||
'error': str(e),
|
||||
})
|
||||
return sync_results
|
||||
|
||||
@@ -0,0 +1,190 @@
|
||||
"""Issue #38 follow-up — ACL `-f <file>` pattern-file support (v1.8.9).
|
||||
|
||||
The Bulgu #12 hard rejects were removed: pattern files are
|
||||
operator-managed host files (same policy as the SPOE
|
||||
`filter ... config <path>` reference preserved since v1.8.8), bulk
|
||||
import always accepted `-f`, and the agent runs `haproxy -c` before
|
||||
every reload so a missing file fails safely. These tests pin:
|
||||
|
||||
1. ACCEPT — the manual FrontendConfig model and the wizard models
|
||||
accept `-f` in every rule field (string + dict shapes).
|
||||
2. GUARDS KEPT — `$(`/backtick shell-substitution rejects and the
|
||||
`X !X` contradiction machinery are unchanged.
|
||||
3. WARNINGS — `_pattern_file_warnings` emits exactly one advisory
|
||||
listing the referenced files, and NOTHING for `-f`-free rules
|
||||
(zero-noise: existing users see no new output).
|
||||
4. ADVISORY — the bulk-import preview advisory block scans
|
||||
acl/use_backend rules (and only those fields).
|
||||
"""
|
||||
|
||||
import re
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parents[1]))
|
||||
|
||||
from models.frontend import FrontendConfig # noqa: E402
|
||||
from routers.frontend import _pattern_file_warnings # noqa: E402
|
||||
|
||||
|
||||
ACL_F = "blacklisted src -f /etc/haproxy/blacklist.lst"
|
||||
UB_F = "be-secure if { src -f /etc/haproxy/allowlist.lst }"
|
||||
REDIR_F = "location /blocked if { src -f /etc/haproxy/blacklist.lst }"
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# 1. ACCEPT — manual FrontendConfig model
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
def test_frontend_config_accepts_acl_file_flag():
|
||||
fe = FrontendConfig(name="fe1", bind_port=80, mode="http", acl_rules=[ACL_F])
|
||||
assert fe.acl_rules == [ACL_F]
|
||||
|
||||
|
||||
def test_frontend_config_accepts_use_backend_file_flag():
|
||||
fe = FrontendConfig(
|
||||
name="fe1", bind_port=80, mode="http", use_backend_rules=[UB_F])
|
||||
assert fe.use_backend_rules == [UB_F]
|
||||
|
||||
|
||||
def test_frontend_config_accepts_redirect_string_file_flag():
|
||||
fe = FrontendConfig(
|
||||
name="fe1", bind_port=80, mode="http", redirect_rules=[REDIR_F])
|
||||
assert fe.redirect_rules == [REDIR_F]
|
||||
|
||||
|
||||
def test_frontend_config_accepts_redirect_dict_file_flag():
|
||||
rule = {"type": "scheme", "scheme": "https",
|
||||
"condition": "if { src -f /etc/haproxy/blacklist.lst }"}
|
||||
fe = FrontendConfig(
|
||||
name="fe1", bind_port=80, mode="http", redirect_rules=[rule])
|
||||
assert fe.redirect_rules == [rule]
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# 2. GUARDS KEPT — dangerous-content rejects unchanged
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
@pytest.mark.parametrize("bad_rule", [
|
||||
"acl1 path $(rm -rf /)",
|
||||
"acl1 path `id`",
|
||||
])
|
||||
def test_acl_shell_substitution_still_rejected(bad_rule):
|
||||
from pydantic import ValidationError
|
||||
with pytest.raises(ValidationError):
|
||||
FrontendConfig(name="fe1", bind_port=80, mode="http", acl_rules=[bad_rule])
|
||||
|
||||
|
||||
@pytest.mark.parametrize("bad_rule", [
|
||||
"be1 if $(whoami)",
|
||||
"be1 if `id`",
|
||||
])
|
||||
def test_use_backend_shell_substitution_still_rejected(bad_rule):
|
||||
from pydantic import ValidationError
|
||||
with pytest.raises(ValidationError):
|
||||
FrontendConfig(
|
||||
name="fe1", bind_port=80, mode="http", use_backend_rules=[bad_rule])
|
||||
|
||||
|
||||
def test_contradiction_detection_still_works_on_file_flag_rules():
|
||||
"""Interaction guard: a `-f` rule with an `X !X` contradiction is
|
||||
still caught by the handler-level contradiction machinery — the
|
||||
`-f` relaxation must not weaken that gate."""
|
||||
from models.frontend import _frontend_has_acl_contradiction
|
||||
assert _frontend_has_acl_contradiction(
|
||||
"be1 if blacklisted !blacklisted") is True
|
||||
# And a normal -f rule is NOT a contradiction.
|
||||
assert _frontend_has_acl_contradiction(UB_F) is False
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# 3. WARNINGS — _pattern_file_warnings (zero-noise contract)
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
def test_pattern_file_warnings_lists_unique_paths():
|
||||
warnings = _pattern_file_warnings(
|
||||
acl_rules=[ACL_F, "other src -f /etc/haproxy/blacklist.lst"],
|
||||
use_backend_rules=[UB_F],
|
||||
redirect_rules=[{"condition": "if { src -f /etc/haproxy/geo.lst }"}],
|
||||
)
|
||||
assert len(warnings) == 1
|
||||
w = warnings[0]
|
||||
assert "/etc/haproxy/blacklist.lst" in w
|
||||
assert "/etc/haproxy/allowlist.lst" in w
|
||||
assert "/etc/haproxy/geo.lst" in w
|
||||
# Duplicate path listed once.
|
||||
assert w.count("/etc/haproxy/blacklist.lst") == 1
|
||||
# Non-blocking framing: mentions fail-safe haproxy -c.
|
||||
assert "haproxy -c" in w
|
||||
|
||||
|
||||
def test_pattern_file_warnings_empty_without_file_flag():
|
||||
"""Zero-noise: operators who don't use `-f` must see NO warning."""
|
||||
assert _pattern_file_warnings(
|
||||
acl_rules=["is_api path_beg /api", "is_admin src 10.0.0.0/24"],
|
||||
use_backend_rules=["be-api if is_api"],
|
||||
redirect_rules=[{"type": "scheme", "scheme": "https",
|
||||
"condition": "if !{ ssl_fc }"}],
|
||||
) == []
|
||||
assert _pattern_file_warnings() == []
|
||||
|
||||
|
||||
def test_pattern_file_warnings_ignores_dash_f_substrings():
|
||||
"""`-file`/`-foo` substrings must not trigger the advisory."""
|
||||
assert _pattern_file_warnings(
|
||||
acl_rules=["is_self path_beg /self-config-file",
|
||||
"is_foo path_beg /foo -m beg"],
|
||||
) == []
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# 4. Wizard models accept `-f` (string + dict) — parity
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
def test_wizard_models_accept_file_flag():
|
||||
from models.site_wizard import FrontendStep
|
||||
|
||||
fe = FrontendStep(
|
||||
name="fe1", mode="http", bind_address="*", bind_port=80,
|
||||
acl_rules=[ACL_F],
|
||||
use_backend_rules=["be-x if blacklisted"],
|
||||
redirect_rules=[{"type": "scheme", "target": "https",
|
||||
"condition": "if { src -f /etc/haproxy/x.lst }"}],
|
||||
)
|
||||
assert fe.acl_rules == [ACL_F]
|
||||
assert fe.redirect_rules[0]["condition"] == "if { src -f /etc/haproxy/x.lst }"
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# 5. Bulk-import preview advisory — source-level pin
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
def test_parse_bulk_advisory_scans_only_structured_rule_fields():
|
||||
"""The preview advisory scans acl_rules/use_backend_rules but NOT
|
||||
request_headers/tcp_request_rules (always-free-form fields —
|
||||
warning there would add new noise for existing users)."""
|
||||
src = Path(__file__).resolve().parents[1] / "routers" / "config.py"
|
||||
text = src.read_text()
|
||||
block_start = text.index("pattern-file advisory")
|
||||
block = text[block_start:block_start + 1200]
|
||||
assert 'acl_rules' in block
|
||||
assert 'use_backend_rules' in block
|
||||
assert 'request_headers' not in block.split("_pattern_paths")[1], (
|
||||
"advisory must not scan request_headers")
|
||||
|
||||
|
||||
def test_no_dash_f_reject_left_in_models():
|
||||
"""No model file may still hard-reject the `-f` flag."""
|
||||
for rel in ("models/frontend.py", "models/site_wizard.py"):
|
||||
text = (Path(__file__).resolve().parents[1] / rel).read_text()
|
||||
for m in re.finditer(r"-f\(\\s\|\$\)", text):
|
||||
ctx = text[max(0, m.start() - 400):m.start() + 400]
|
||||
assert "raise ValueError" not in ctx, (
|
||||
f"{rel}: a `-f` reject regex still sits next to a raise")
|
||||
@@ -0,0 +1,97 @@
|
||||
"""Issue #31 — agent heartbeat JSON sanitizer.
|
||||
|
||||
A self-hosted agent builds its heartbeat JSON as text in bash. When a collected value is empty,
|
||||
the payload can contain a structurally-invalid comma that broke the heartbeat with
|
||||
`HTTP 400 Invalid JSON: Expecting property name enclosed in double quotes`. The backend now
|
||||
repairs that pattern in `_sanitize_agent_json` so an already-deployed agent recovers without a
|
||||
re-install. These tests pin that behaviour and prove the repair never corrupts a healthy payload.
|
||||
"""
|
||||
import json
|
||||
|
||||
from routers.agent import _sanitize_agent_json
|
||||
|
||||
|
||||
def _assert_parses(raw: str) -> dict:
|
||||
out, _ = _sanitize_agent_json(raw)
|
||||
return json.loads(out) # raises if the repair did not produce valid JSON
|
||||
|
||||
|
||||
def test_reporter_empty_system_info_bare_comma():
|
||||
# The exact shape the reporter hit: an empty $system_info collapses ' $system_info,' to a
|
||||
# bare comma between two members -> '"version": "x",\n ,\n "haproxy_status": ...'.
|
||||
raw = (
|
||||
'{\n'
|
||||
' "name": "test",\n'
|
||||
' "hostname": "h",\n'
|
||||
' "status": "online",\n'
|
||||
' "version": "2.0.0",\n'
|
||||
' ,\n'
|
||||
' "haproxy_status": "running",\n'
|
||||
' "cluster_id": 1\n'
|
||||
'}'
|
||||
)
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["name"] == "test"
|
||||
assert parsed["status"] == "online"
|
||||
assert parsed["haproxy_status"] == "running"
|
||||
|
||||
|
||||
def test_empty_numeric_subfield_before_comma():
|
||||
# An empty unquoted numeric ("memory_total": ,) — covered by the pre-existing Fix 1.
|
||||
raw = '{ "name": "t", "cpu_count": , "memory_total": , "status": "online" }'
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["cpu_count"] is None and parsed["memory_total"] is None
|
||||
assert parsed["status"] == "online"
|
||||
|
||||
|
||||
def test_empty_value_before_closing_brace():
|
||||
raw = '{ "name": "t", "status": "online", "applied_config_version": }'
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["applied_config_version"] is None
|
||||
|
||||
|
||||
def test_leading_comma_first_member():
|
||||
# Empty $system_info as the FIRST member -> '{ , "name": ... }'.
|
||||
raw = '{\n ,\n "name": "t",\n "status": "online"\n}'
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["name"] == "t"
|
||||
|
||||
|
||||
def test_comma_run_two_empty_fields():
|
||||
# Two empties in a row (odd-length comma run) must still collapse to valid JSON.
|
||||
raw = '{ "a": 1,\n ,\n ,\n "b": 2 }'
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["a"] == 1 and parsed["b"] == 2
|
||||
|
||||
|
||||
def test_trailing_comma_regression():
|
||||
# Pre-existing Fix 3 must still hold after the new fixes were added.
|
||||
raw = '{ "name": "t", "status": "online", }'
|
||||
parsed = _assert_parses(raw)
|
||||
assert parsed["name"] == "t"
|
||||
|
||||
|
||||
def test_healthy_payload_is_untouched():
|
||||
# A well-formed agent payload must pass through unchanged (sanitized=False) and its values —
|
||||
# including the base64 stats CSV and the nested server_statuses — must be byte-identical.
|
||||
payload = {
|
||||
"name": "agent-1",
|
||||
"status": "online",
|
||||
"cluster_id": 1,
|
||||
"server_statuses": {"be_app": {"s1": "UP", "s2": "DOWN"}},
|
||||
"network_interfaces": ["eth0", "eth1"],
|
||||
"haproxy_stats_csv": "IyBwdmJjLGJhY2tlbmQsZnJvbnRlbmQs", # base64: contains commas only inside a quoted string is impossible (base64 has none)
|
||||
"applied_config_version": "cluster-1-v42",
|
||||
}
|
||||
raw = json.dumps(payload)
|
||||
out, changed = _sanitize_agent_json(raw)
|
||||
assert changed is False
|
||||
assert out == raw # byte-identical
|
||||
assert json.loads(out) == payload
|
||||
|
||||
|
||||
def test_idempotent_on_already_clean_minimal():
|
||||
raw = '{"name": "t", "status": "online"}'
|
||||
out, changed = _sanitize_agent_json(raw)
|
||||
assert changed is False
|
||||
assert out == raw
|
||||
@@ -0,0 +1,61 @@
|
||||
"""Issue #31 — agent-script hardening guard (static).
|
||||
|
||||
The agent install scripts hand-build the heartbeat JSON, so if `collect_system_info` ever yields
|
||||
nothing the `$system_info,` line collapses to a bare comma and the whole heartbeat is invalid JSON
|
||||
(HTTP 400). The fix adds a guard at every fragment-form call site that substitutes a single valid
|
||||
key when system_info is empty. This static check enforces that the guard is present AND kept in
|
||||
sync across BOTH platform scripts — the project requires the two agent-script copies to stay in
|
||||
lockstep. (Empty numeric subfields like "memory_total": , are a separate, milder case already
|
||||
repaired by the backend sanitizer, so they are intentionally NOT guarded in the script — guarding
|
||||
them with a strict integer test would wrongly reject the scientific-notation that mawk emits for
|
||||
multi-GB sizes on Debian/Ubuntu.)
|
||||
"""
|
||||
import os
|
||||
|
||||
_SCRIPT_DIR = os.path.join(
|
||||
os.path.dirname(os.path.dirname(os.path.abspath(__file__))), # backend/
|
||||
"utils", "agent_scripts",
|
||||
)
|
||||
|
||||
|
||||
def _read(name: str) -> str:
|
||||
with open(os.path.join(_SCRIPT_DIR, name), "r") as f:
|
||||
return f.read()
|
||||
|
||||
|
||||
LINUX = _read("linux_install.sh")
|
||||
MACOS = _read("macos_install.sh")
|
||||
|
||||
# The empty-system_info guard — present at BOTH fragment call sites (register_agent + send_heartbeat).
|
||||
_B2_GUARD = '[[ "$system_info" != *\'"\'* ]] && system_info=\'"operating_system": "unknown"\''
|
||||
|
||||
|
||||
def test_b2_guard_present_and_in_sync():
|
||||
# Two fragment-form call sites per script (register_agent + send_heartbeat), identical wording.
|
||||
assert LINUX.count(_B2_GUARD) == 2, "linux_install.sh missing/duplicated empty-system_info guard"
|
||||
assert MACOS.count(_B2_GUARD) == 2, "macos_install.sh missing/duplicated empty-system_info guard"
|
||||
|
||||
|
||||
def test_b2_guard_precedes_every_fragment_system_info_use():
|
||||
# Every ' $system_info,' fragment line (the one that breaks on an empty value) must be in a
|
||||
# function whose system_info was guarded. We assert the count of guards matches the count of
|
||||
# fragment-form interpolations' call sites: each script has exactly one register + one
|
||||
# send_heartbeat fragment builder feeding those lines, both guarded above.
|
||||
for name, script in (("linux", LINUX), ("macos", MACOS)):
|
||||
assert script.count(" $system_info,") >= 1, f"{name}: fragment heartbeat form unexpectedly gone"
|
||||
assert script.count(_B2_GUARD) == 2, f"{name}: each fragment call site must carry the guard"
|
||||
|
||||
|
||||
def test_cleanup_does_not_self_kill_via_bare_haproxy_agent_pattern():
|
||||
# Issue #31 (v1.8.4): the pre-installation cleanup kills processes by pgrep -f "$pattern". A bare
|
||||
# "haproxy-agent" pattern also matches the installer's OWN path (install-haproxy-agent-*.sh) and a
|
||||
# sudo/PAM ancestor, so the installer killed itself. The kill loop must target ONLY the installed
|
||||
# agent (binary path + service/label), never the bare string.
|
||||
for name, script in (("linux", LINUX), ("macos", MACOS)):
|
||||
assert 'for pattern in "haproxy-agent"' not in script, (
|
||||
f"{name}: pre-install cleanup uses the bare 'haproxy-agent' kill pattern -> self-kill (issue #31)"
|
||||
)
|
||||
# The narrowed, installer-safe pattern must be present (binary path via $INSTALL_DIR).
|
||||
assert 'for pattern in "$INSTALL_DIR/haproxy-agent"' in script, (
|
||||
f"{name}: cleanup must match the installed binary path, not a bare substring"
|
||||
)
|
||||
@@ -0,0 +1,469 @@
|
||||
"""
|
||||
v1.9.0 CSR creation — unit tests for the signed-certificate import flow and
|
||||
config-version staging (pattern: test_ssl_service_extraction.py, AsyncMock conn).
|
||||
|
||||
Pins the security-relevant invariants:
|
||||
- key match is a HARD gate: match=False → 400 before any INSERT, and
|
||||
match=None (unverifiable) → 500, never a lenient pass (we generated the
|
||||
key ourselves — deliberate divergence from create_cert_row's fallback).
|
||||
- the new cert row is cluster_id=NULL / last_config_status='PENDING' /
|
||||
source='csr' (PENDING keeps it invisible to agents until Apply).
|
||||
- completing the CSR NULLs the private key copy.
|
||||
- staging reuses the exact `ssl-{id}-create-{ts}` version-name scheme.
|
||||
"""
|
||||
import json
|
||||
from contextlib import contextmanager
|
||||
from datetime import datetime, timezone
|
||||
from types import SimpleNamespace
|
||||
from unittest.mock import AsyncMock, MagicMock, patch
|
||||
|
||||
import pytest
|
||||
from fastapi import HTTPException
|
||||
|
||||
from models.csr import SSLCSRImport
|
||||
from services.csr_service import (
|
||||
assert_csr_name_available,
|
||||
import_signed_certificate,
|
||||
insert_csr_row,
|
||||
)
|
||||
from services.ssl_service import stage_ssl_config_versions
|
||||
|
||||
|
||||
_VALID_PARSE = {
|
||||
"primary_domain": "www.example.com",
|
||||
"all_domains": ["www.example.com"],
|
||||
"expiry_date": datetime(2099, 1, 1, tzinfo=timezone.utc),
|
||||
"issuer": "CN=Test CA",
|
||||
"fingerprint": "AA:BB:CC",
|
||||
"status": "valid",
|
||||
"days_until_expiry": 365,
|
||||
}
|
||||
|
||||
_FAKE_CERT = "-----BEGIN CERTIFICATE-----\nX\n-----END CERTIFICATE-----"
|
||||
_FAKE_KEY = "-----BEGIN PRIVATE KEY-----\nY\n-----END PRIVATE KEY-----"
|
||||
|
||||
|
||||
def _csr_row(**overrides):
|
||||
row = {
|
||||
"id": 5,
|
||||
"name": "csr-www",
|
||||
"common_name": "www.example.com",
|
||||
"subject": "{}",
|
||||
"sans": json.dumps(["www.example.com"]),
|
||||
"key_algorithm": "rsa-2048",
|
||||
"csr_pem": "-----BEGIN CERTIFICATE REQUEST-----\nZ\n-----END CERTIFICATE REQUEST-----",
|
||||
"private_key_pem": _FAKE_KEY,
|
||||
"status": "pending",
|
||||
"ssl_certificate_id": None,
|
||||
}
|
||||
row.update(overrides)
|
||||
return row
|
||||
|
||||
|
||||
def _mk_conn():
|
||||
conn = AsyncMock()
|
||||
# asyncpg's conn.transaction() is a SYNC call returning an async CM.
|
||||
conn.transaction = MagicMock()
|
||||
return conn
|
||||
|
||||
|
||||
def _import_payload(**overrides):
|
||||
base = dict(
|
||||
certificate_content=_FAKE_CERT,
|
||||
chain_content=None,
|
||||
usage_type="frontend",
|
||||
is_global=False,
|
||||
cluster_ids=[1, 2],
|
||||
name=None,
|
||||
)
|
||||
base.update(overrides)
|
||||
return SSLCSRImport(**base)
|
||||
|
||||
|
||||
@contextmanager
|
||||
def _patched(match=None, parse=None):
|
||||
"""Patch every parser touchpoint of the import path: the function-local
|
||||
imports in csr_service (utils.ssl_parser.*) and the module-level imports
|
||||
in ssl_service._prepare_cert_fields (services.ssl_service.*)."""
|
||||
match_result = match if match is not None else {"match": True}
|
||||
parse_result = dict(parse or _VALID_PARSE)
|
||||
with patch("utils.ssl_parser.verify_certificate_key_match", return_value=match_result), \
|
||||
patch("utils.ssl_parser.parse_ssl_certificate", return_value=dict(parse_result)), \
|
||||
patch("services.ssl_service.parse_ssl_certificate", return_value=dict(parse_result)), \
|
||||
patch("services.ssl_service.validate_private_key", return_value=True), \
|
||||
patch("services.ssl_service.validate_certificate_chain", return_value=True):
|
||||
yield
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# import_signed_certificate
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_happy_path_inserts_pending_csr_sourced_cert():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(), None] # FOR UPDATE row, no name clash
|
||||
conn.fetchval.return_value = 42 # INSERT ... RETURNING id
|
||||
|
||||
with _patched():
|
||||
result = await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert result["certificate_id"] == 42
|
||||
assert result["reactivated"] is False
|
||||
|
||||
# Concurrency invariants: everything runs inside a transaction and the
|
||||
# CSR row is locked FOR UPDATE (serialises double-import and delete-races).
|
||||
assert conn.transaction.call_count == 1
|
||||
lock_sql = conn.fetchrow.call_args_list[0].args[0]
|
||||
assert "FOR UPDATE" in lock_sql
|
||||
|
||||
insert_sql, *insert_args = conn.fetchval.call_args.args
|
||||
assert "INSERT INTO ssl_certificates" in insert_sql
|
||||
assert "NULL, 'PENDING'" in insert_sql, "cert must stay invisible to agents until Apply"
|
||||
assert "'csr'" in insert_sql, "source column must record the CSR origin"
|
||||
# The stored CSR key — not any request-supplied key — must be persisted.
|
||||
assert _FAKE_KEY in insert_args
|
||||
|
||||
# One junction row per requested cluster.
|
||||
junction_calls = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "ssl_certificate_clusters" in c.args[0] and "INSERT" in c.args[0]
|
||||
]
|
||||
assert len(junction_calls) == 2
|
||||
assert {c.args[2] for c in junction_calls} == {1, 2}
|
||||
|
||||
# CSR completion must destroy the key copy.
|
||||
completion_calls = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "UPDATE ssl_csrs" in c.args[0]
|
||||
]
|
||||
assert len(completion_calls) == 1
|
||||
assert "private_key_pem = NULL" in completion_calls[0].args[0]
|
||||
assert "status = 'completed'" in completion_calls[0].args[0]
|
||||
assert completion_calls[0].args[1] == 5 # csr_id
|
||||
assert completion_calls[0].args[2] == 42 # cert_id
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_global_creates_zero_junction_rows():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(), None]
|
||||
conn.fetchval.return_value = 42
|
||||
|
||||
with _patched():
|
||||
await import_signed_certificate(
|
||||
conn, 5, _import_payload(is_global=True, cluster_ids=None), user_id=7
|
||||
)
|
||||
|
||||
junction_calls = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "ssl_certificate_clusters" in c.args[0] and "INSERT" in c.args[0]
|
||||
]
|
||||
assert junction_calls == [], "global cert = zero junction rows (existing convention)"
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_key_mismatch_rejected_400_before_any_write():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row()]
|
||||
|
||||
with _patched(match={"match": False, "reason": "public key mismatch"}):
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "does not match" in exc_info.value.detail
|
||||
assert not conn.fetchval.await_count, "nothing must be inserted on mismatch"
|
||||
assert not conn.execute.await_count
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_unverifiable_key_match_is_hard_error_not_lenient():
|
||||
"""match=None means OUR stored key is unreadable — integrity failure,
|
||||
never the lenient pass create_cert_row historically allows."""
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row()]
|
||||
|
||||
with _patched(match={"match": None, "reason": "key could not be parsed"}):
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 500
|
||||
assert not conn.fetchval.await_count
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_expired_certificate_rejected_400():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row()]
|
||||
|
||||
expired = dict(_VALID_PARSE)
|
||||
expired["status"] = "expired"
|
||||
expired["days_until_expiry"] = -10
|
||||
with _patched(parse=expired):
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "expired" in exc_info.value.detail.lower()
|
||||
assert not conn.fetchval.await_count
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_malformed_certificate_rejected_400_not_500():
|
||||
"""A cert with PEM markers but unparseable content (truncated CA response)
|
||||
is OPERATOR INPUT — it must get the manual flow's 400, not the 500 that
|
||||
the strict key-match branch reserves for a corrupt STORED key."""
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row()]
|
||||
|
||||
with _patched(parse={"error": "Could not parse certificate"}):
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "Invalid SSL certificate" in exc_info.value.detail
|
||||
assert not conn.fetchval.await_count
|
||||
assert not conn.execute.await_count
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_completed_csr_conflicts_409():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(status="completed", ssl_certificate_id=42)]
|
||||
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 409
|
||||
assert "already completed" in exc_info.value.detail
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_missing_csr_404():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [None]
|
||||
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 999, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 404
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_active_name_collision_rejected_with_hint():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(), {"id": 9, "is_active": True}]
|
||||
|
||||
with _patched():
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "already exists" in exc_info.value.detail
|
||||
assert "name" in exc_info.value.detail # points at the override escape hatch
|
||||
assert not conn.fetchval.await_count
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_name_override_is_used_for_the_cert_row():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(), None]
|
||||
conn.fetchval.return_value = 42
|
||||
|
||||
with _patched():
|
||||
result = await import_signed_certificate(
|
||||
conn, 5, _import_payload(name="renamed-cert"), user_id=7
|
||||
)
|
||||
|
||||
assert result["certificate_name"] == "renamed-cert"
|
||||
_, *insert_args = conn.fetchval.call_args.args
|
||||
assert "renamed-cert" in insert_args
|
||||
# And the collision check must have run against the override, not csr.name.
|
||||
name_lookup = conn.fetchrow.call_args_list[1]
|
||||
assert name_lookup.args[1] == "renamed-cert"
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_reactivates_soft_deleted_name_and_warns():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [_csr_row(), {"id": 77, "is_active": False}]
|
||||
|
||||
with _patched():
|
||||
result = await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert result["certificate_id"] == 77
|
||||
assert result["reactivated"] is True
|
||||
assert any("reactivated" in w for w in result["warnings"])
|
||||
assert not conn.fetchval.await_count, "reactivation must UPDATE, not INSERT"
|
||||
update_calls = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "UPDATE ssl_certificates" in c.args[0]
|
||||
]
|
||||
assert len(update_calls) == 1
|
||||
update_sql = update_calls[0].args[0]
|
||||
assert "source = 'csr'" in update_sql
|
||||
# The reactivated row must come back to life invisible to agents until
|
||||
# Apply, with the row itself active again.
|
||||
assert "last_config_status = 'PENDING'" in update_sql
|
||||
assert "is_active = TRUE" in update_sql
|
||||
# Old cluster bindings must be wiped before re-binding to the new scope.
|
||||
junction_deletes = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "DELETE FROM ssl_certificate_clusters" in c.args[0]
|
||||
]
|
||||
assert len(junction_deletes) == 1
|
||||
assert junction_deletes[0].args[1] == 77
|
||||
# …and the importer's requested clusters re-bound via the junction.
|
||||
junction_inserts = [
|
||||
c for c in conn.execute.call_args_list
|
||||
if c.args and "INSERT INTO ssl_certificate_clusters" in c.args[0]
|
||||
]
|
||||
assert {c.args[2] for c in junction_inserts} == {1, 2}
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_import_san_drift_warns_but_succeeds():
|
||||
conn = _mk_conn()
|
||||
conn.fetchrow.side_effect = [
|
||||
_csr_row(sans=json.dumps(["www.example.com", "api.example.com"])),
|
||||
None,
|
||||
]
|
||||
conn.fetchval.return_value = 42
|
||||
|
||||
drifted = dict(_VALID_PARSE)
|
||||
drifted["all_domains"] = ["www.example.com", "cdn.example.com"]
|
||||
with _patched(parse=drifted):
|
||||
result = await import_signed_certificate(conn, 5, _import_payload(), user_id=7)
|
||||
|
||||
assert result["certificate_id"] == 42
|
||||
assert any("added" in w and "cdn.example.com" in w for w in result["warnings"])
|
||||
assert any("dropped" in w and "api.example.com" in w for w in result["warnings"])
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# insert_csr_row / assert_csr_name_available
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_csr_name_taken_by_active_cert_rejected():
|
||||
conn = _mk_conn()
|
||||
conn.fetchval.side_effect = [11] # active cert with the name exists
|
||||
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await assert_csr_name_available(conn, "taken")
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "certificate" in exc_info.value.detail.lower()
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_csr_name_taken_by_pending_csr_rejected():
|
||||
conn = _mk_conn()
|
||||
conn.fetchval.side_effect = [None, 12] # no cert, but a pending CSR
|
||||
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await assert_csr_name_available(conn, "taken")
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "pending CSR" in exc_info.value.detail
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_insert_csr_row_translates_unique_violation_to_400():
|
||||
"""The uq_ssl_csrs_name_pending partial index closes the create/create
|
||||
race — the loser must get a clean 400, not a 500."""
|
||||
import asyncpg as _asyncpg
|
||||
|
||||
conn = _mk_conn()
|
||||
# availability checks pass, INSERT hits the unique index
|
||||
conn.fetchval.side_effect = [
|
||||
None, None, _asyncpg.exceptions.UniqueViolationError("dup"),
|
||||
]
|
||||
payload = SimpleNamespace(
|
||||
name="raced", common_name="www.example.com", key_algorithm="rsa-2048"
|
||||
)
|
||||
bundle = {"subject": {}, "sans": ["www.example.com"], "csr_pem": "PEM", "private_key_pem": "KEY"}
|
||||
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
await insert_csr_row(conn, payload, bundle, user_id=1)
|
||||
assert exc_info.value.status_code == 400
|
||||
assert "concurrent" in exc_info.value.detail
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# router-level guards
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
def test_cluster_id_int32_guard_rejects_out_of_range_with_404():
|
||||
"""Body-supplied cluster ids must never reach asyncpg out of int4 range
|
||||
(DataError → raw 500) — same Bulgu #96 hygiene as the csr_id path param."""
|
||||
from routers.csr import _assert_valid_cluster_id
|
||||
|
||||
_assert_valid_cluster_id(1)
|
||||
_assert_valid_cluster_id(2_147_483_647)
|
||||
for bad in (0, -1, 2_147_483_648, 99_999_999_999):
|
||||
with pytest.raises(HTTPException) as exc_info:
|
||||
_assert_valid_cluster_id(bad)
|
||||
assert exc_info.value.status_code == 404
|
||||
assert "Cluster not found" in exc_info.value.detail
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# stage_ssl_config_versions
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_stage_creates_one_pending_version_per_cluster_with_ssl_naming():
|
||||
import re
|
||||
|
||||
conn = _mk_conn()
|
||||
conn.fetchval.return_value = 1001 # config_versions INSERT RETURNING id
|
||||
|
||||
with patch(
|
||||
"services.haproxy_config.generate_haproxy_config_for_cluster",
|
||||
new=AsyncMock(return_value="# cfg"),
|
||||
):
|
||||
results = await stage_ssl_config_versions(conn, 42, [1, 2], created_by=7)
|
||||
|
||||
assert len(results) == 2
|
||||
assert all(r["success"] for r in results)
|
||||
assert [r["cluster_id"] for r in results] == [1, 2]
|
||||
|
||||
insert_calls = [
|
||||
c for c in conn.fetchval.call_args_list
|
||||
if c.args and "INSERT INTO config_versions" in c.args[0]
|
||||
]
|
||||
assert len(insert_calls) == 2
|
||||
for call in insert_calls:
|
||||
sql = call.args[0]
|
||||
assert "FALSE, 'PENDING'" in sql, "staged versions must be inactive + PENDING"
|
||||
version_name = call.args[2]
|
||||
# EXACT manual-flow scheme: Apply Management + has_pending_config
|
||||
# LIKE-filters key off 'ssl-{id}-...'.
|
||||
assert re.match(r"^ssl-42-create-\d+$", version_name), version_name
|
||||
assert call.args[5] == 7 # created_by honours the importing user
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_stage_reports_per_cluster_failure_without_raising():
|
||||
conn = _mk_conn()
|
||||
conn.fetchval.return_value = 1001
|
||||
|
||||
async def _gen(cluster_id):
|
||||
if cluster_id == 2:
|
||||
raise RuntimeError("config generation exploded")
|
||||
return "# cfg"
|
||||
|
||||
with patch(
|
||||
"services.haproxy_config.generate_haproxy_config_for_cluster",
|
||||
new=AsyncMock(side_effect=_gen),
|
||||
):
|
||||
results = await stage_ssl_config_versions(conn, 42, [1, 2], created_by=7)
|
||||
|
||||
assert len(results) == 2
|
||||
assert results[0]["success"] is True
|
||||
assert results[1]["success"] is False
|
||||
assert "exploded" in results[1]["error"]
|
||||
@@ -0,0 +1,129 @@
|
||||
"""Issue #53 (v1.10.1) — at-rest encryption for the pending CSR private key.
|
||||
|
||||
Pure logic: no DB, no network. Covers the round-trip, the backward-compatible read of rows
|
||||
written before this release, the unrecoverable-key path after a key rotation, and a static
|
||||
assertion that the write path can no longer store a raw PEM.
|
||||
"""
|
||||
import os
|
||||
import re
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
os.environ.setdefault("SECRET_KEY", "test-secret-key-for-csr-encryption-unit-tests")
|
||||
|
||||
from cryptography.fernet import Fernet
|
||||
|
||||
from utils.csr_key_crypto import (
|
||||
decrypt_csr_private_key,
|
||||
encrypt_csr_private_key,
|
||||
is_encrypted,
|
||||
reset_fernet_for_tests,
|
||||
)
|
||||
|
||||
_SAMPLE_PEM = (
|
||||
"-----BEGIN PRIVATE KEY-----\n"
|
||||
"MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC7VJTUt9Us8cKj\n"
|
||||
"-----END PRIVATE KEY-----\n"
|
||||
)
|
||||
|
||||
|
||||
def test_roundtrip_and_ciphertext_does_not_contain_the_key():
|
||||
reset_fernet_for_tests()
|
||||
token = encrypt_csr_private_key(_SAMPLE_PEM)
|
||||
# The stored form must not be the PEM, and must not leak any recognisable fragment of it.
|
||||
assert token != _SAMPLE_PEM
|
||||
assert "-----BEGIN" not in token
|
||||
assert "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC7VJTUt9Us8cKj" not in token
|
||||
assert decrypt_csr_private_key(token) == _SAMPLE_PEM
|
||||
|
||||
|
||||
def test_is_encrypted_discriminates_token_from_legacy_pem():
|
||||
reset_fernet_for_tests()
|
||||
assert is_encrypted(encrypt_csr_private_key(_SAMPLE_PEM)) is True
|
||||
assert is_encrypted(_SAMPLE_PEM) is False
|
||||
assert is_encrypted("") is False
|
||||
assert is_encrypted(None) is False
|
||||
|
||||
|
||||
def test_legacy_plaintext_row_is_read_unchanged():
|
||||
# Rows written before v1.10.1 hold a raw PEM. They must keep working with NO data migration,
|
||||
# otherwise upgrading would strand every CSR that is out for signature.
|
||||
reset_fernet_for_tests()
|
||||
assert decrypt_csr_private_key(_SAMPLE_PEM) == _SAMPLE_PEM
|
||||
|
||||
|
||||
def test_empty_or_missing_value_returns_none():
|
||||
reset_fernet_for_tests()
|
||||
assert decrypt_csr_private_key(None) is None
|
||||
assert decrypt_csr_private_key("") is None
|
||||
|
||||
|
||||
def test_key_rotation_makes_the_stored_key_unrecoverable_rather_than_wrong():
|
||||
"""After a rotation the caller must get None, never a silently wrong key."""
|
||||
reset_fernet_for_tests()
|
||||
token = encrypt_csr_private_key(_SAMPLE_PEM)
|
||||
|
||||
# Rotate: an explicit, different CSR_ENCRYPTION_KEY takes precedence over the derived one.
|
||||
previous = os.environ.get("CSR_ENCRYPTION_KEY")
|
||||
os.environ["CSR_ENCRYPTION_KEY"] = Fernet.generate_key().decode()
|
||||
try:
|
||||
reset_fernet_for_tests()
|
||||
assert decrypt_csr_private_key(token) is None
|
||||
finally:
|
||||
if previous is None:
|
||||
os.environ.pop("CSR_ENCRYPTION_KEY", None)
|
||||
else:
|
||||
os.environ["CSR_ENCRYPTION_KEY"] = previous
|
||||
reset_fernet_for_tests()
|
||||
|
||||
|
||||
def test_explicit_env_key_is_used_and_survives_reset():
|
||||
previous = os.environ.get("CSR_ENCRYPTION_KEY")
|
||||
key = Fernet.generate_key().decode()
|
||||
os.environ["CSR_ENCRYPTION_KEY"] = key
|
||||
try:
|
||||
reset_fernet_for_tests()
|
||||
token = encrypt_csr_private_key(_SAMPLE_PEM)
|
||||
# Decryptable with the same explicit key from a fresh instance...
|
||||
reset_fernet_for_tests()
|
||||
assert decrypt_csr_private_key(token) == _SAMPLE_PEM
|
||||
# ...and independently verifiable with the raw Fernet key.
|
||||
assert Fernet(key.encode()).decrypt(token.encode()).decode() == _SAMPLE_PEM
|
||||
finally:
|
||||
if previous is None:
|
||||
os.environ.pop("CSR_ENCRYPTION_KEY", None)
|
||||
else:
|
||||
os.environ["CSR_ENCRYPTION_KEY"] = previous
|
||||
reset_fernet_for_tests()
|
||||
|
||||
|
||||
def test_derivation_uses_its_own_hkdf_info_string():
|
||||
"""Each secret class derives an independent key, so rotating one never affects another."""
|
||||
src = (Path(__file__).resolve().parent.parent / "utils" / "csr_key_crypto.py").read_text()
|
||||
assert b"csr-private-key-v1".decode() in src
|
||||
# Must NOT reuse another class's info string.
|
||||
for foreign in ("dns-provider-creds-v1", "vip-vrrp-secret-v1", "mfa-totp-secret-v1"):
|
||||
assert foreign not in src, f"CSR key derivation must not reuse the {foreign} info string"
|
||||
|
||||
|
||||
def test_write_path_stores_the_encrypted_form_not_the_pem():
|
||||
"""Static pin: insert_csr_row must encrypt before the INSERT.
|
||||
|
||||
A future refactor that passed bundle['private_key_pem'] straight through would silently
|
||||
reintroduce plaintext storage, and no unit test with a mocked connection would notice.
|
||||
"""
|
||||
src = (Path(__file__).resolve().parent.parent / "services" / "csr_service.py").read_text()
|
||||
insert_fn = src[src.index("async def insert_csr_row("):]
|
||||
insert_fn = insert_fn[: insert_fn.index("\nasync def ")]
|
||||
assert "encrypt_csr_private_key(bundle['private_key_pem'])" in insert_fn
|
||||
# The raw PEM must not be a bind parameter of the INSERT itself.
|
||||
assert not re.search(r"^\s*bundle\['private_key_pem'\],\s*$", insert_fn, re.M)
|
||||
|
||||
|
||||
def test_import_path_decrypts_and_fails_closed_on_unrecoverable_key():
|
||||
src = (Path(__file__).resolve().parent.parent / "services" / "csr_service.py").read_text()
|
||||
fn = src[src.index("async def import_signed_certificate("):]
|
||||
assert "decrypt_csr_private_key(row['private_key_pem'])" in fn
|
||||
# A None decrypt must raise rather than fall through to the key-match comparison.
|
||||
assert "cannot be decrypted" in fn
|
||||
@@ -0,0 +1,104 @@
|
||||
"""
|
||||
v1.9.0 CSR creation — static source assertions (pattern: test_vip_purge.py).
|
||||
|
||||
Guards the migration wiring that a unit test cannot exercise without a real
|
||||
database: the SCHEMA_VERSION bump (without it, deployed installs skip the
|
||||
whole migration run and the ssl_csrs table never appears), the migration
|
||||
registration, the security-relevant DDL, and the router registration.
|
||||
"""
|
||||
import os
|
||||
import re
|
||||
|
||||
_BACKEND_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
|
||||
|
||||
def _read(rel_path: str) -> str:
|
||||
with open(os.path.join(_BACKEND_DIR, rel_path), encoding="utf-8") as f:
|
||||
return f.read()
|
||||
|
||||
|
||||
def test_schema_version_bumped_to_10():
|
||||
src = _read(os.path.join("database", "migrations.py"))
|
||||
m = re.search(r"^SCHEMA_VERSION\s*=\s*(\d+)", src, re.MULTILINE)
|
||||
assert m, "SCHEMA_VERSION constant not found in migrations.py"
|
||||
assert int(m.group(1)) >= 10, (
|
||||
"SCHEMA_VERSION must be >= 10 for the v1.9.0 ssl_csrs table — "
|
||||
"without the bump, existing installs (version >= 9) skip the whole "
|
||||
"migration run and never gain the table."
|
||||
)
|
||||
|
||||
|
||||
def test_ssl_csrs_migration_defined_and_registered():
|
||||
src = _read(os.path.join("database", "migrations.py"))
|
||||
assert "async def ensure_ssl_csrs_table" in src
|
||||
|
||||
inner = src.split("async def _run_all_migrations_inner", 1)[1]
|
||||
inner = inner.split("\nasync def ", 1)[0] # body of the runner only
|
||||
assert "await ensure_ssl_csrs_table()" in inner, (
|
||||
"ensure_ssl_csrs_table must be invoked from _run_all_migrations_inner"
|
||||
)
|
||||
|
||||
|
||||
def test_ssl_csrs_ddl_essentials():
|
||||
src = _read(os.path.join("database", "migrations.py"))
|
||||
ddl_start = src.index("CREATE TABLE IF NOT EXISTS ssl_csrs")
|
||||
ddl = src[ddl_start:ddl_start + 2500]
|
||||
|
||||
assert "private_key_pem TEXT" in ddl
|
||||
assert "name VARCHAR(100) NOT NULL" in ddl, (
|
||||
"ssl_csrs.name must align with ssl_certificates.name VARCHAR(100)"
|
||||
)
|
||||
assert "ssl_certificate_id INTEGER REFERENCES ssl_certificates(id) ON DELETE SET NULL" in ddl, (
|
||||
"deleting the imported cert must not cascade into CSR history"
|
||||
)
|
||||
# Partial unique index: only PENDING CSRs reserve their target cert name.
|
||||
assert "uq_ssl_csrs_name_pending" in src
|
||||
assert re.search(
|
||||
r"uq_ssl_csrs_name_pending\s+ON\s+ssl_csrs\(name\)\s+WHERE\s+status\s*=\s*'pending'",
|
||||
src,
|
||||
), "name uniqueness must be scoped to pending CSRs (partial index)"
|
||||
|
||||
|
||||
def test_csr_router_registered_in_main():
|
||||
src = _read("main.py")
|
||||
assert "from routers.csr import router as csr_router" in src
|
||||
assert "app.include_router(csr_router)" in src
|
||||
|
||||
|
||||
def test_csr_endpoint_permission_mapping():
|
||||
"""Pin which ssl.<action> permission each endpoint enforces: a regression
|
||||
that dropped or weakened a _require() call would otherwise pass the
|
||||
auth-rejection tests (they only assert 401/403 for unauthenticated calls)."""
|
||||
src = _read(os.path.join("routers", "csr.py"))
|
||||
|
||||
def _handler_body(decorator):
|
||||
start = src.index(decorator)
|
||||
nxt = src.find("@router.", start + 1)
|
||||
return src[start:nxt if nxt != -1 else len(src)]
|
||||
|
||||
expectations = [
|
||||
('@router.post("")', '"create"'),
|
||||
('@router.get("")', '"read"'),
|
||||
('@router.get("/{csr_id}")', '"read"'),
|
||||
('@router.post("/{csr_id}/import")', '"create"'),
|
||||
('@router.delete("/{csr_id}")', '"delete"'),
|
||||
]
|
||||
for decorator, action in expectations:
|
||||
body = _handler_body(decorator)
|
||||
assert f"_require(authorization, {action})" in body, (
|
||||
f"endpoint {decorator} must enforce ssl.{action.strip(chr(34))}"
|
||||
)
|
||||
|
||||
|
||||
def test_csr_router_never_selects_private_key():
|
||||
"""The CSR endpoints must use the explicit column list — a bare
|
||||
`SELECT *` into an API response is how the key would leak. The one place
|
||||
SELECT * is allowed is the service-layer FOR UPDATE row (it needs the key
|
||||
to pair with the cert); the router itself must not touch the column."""
|
||||
src = _read(os.path.join("routers", "csr.py"))
|
||||
code_only = re.sub(r"#.*", "", src) # strip comments; the column name may
|
||||
# legitimately appear there as documentation
|
||||
assert "private_key_pem" not in code_only, (
|
||||
"routers/csr.py must never reference private_key_pem in code"
|
||||
)
|
||||
assert "SELECT *" not in code_only, "routers/csr.py must use explicit column lists"
|
||||
@@ -0,0 +1,172 @@
|
||||
"""
|
||||
v1.9.0 CSR creation — Pydantic model validation tests (models/csr.py).
|
||||
|
||||
The CSR name shares the SSL certificate name's path-traversal contract
|
||||
(Bulgu #21) with one deliberate tightening: max 100 chars, matching the
|
||||
ssl_certificates.name VARCHAR(100) column.
|
||||
"""
|
||||
import pytest
|
||||
from pydantic import ValidationError
|
||||
|
||||
from models.csr import SSLCSRCreate, SSLCSRImport
|
||||
|
||||
_CERT_PEM = "-----BEGIN CERTIFICATE-----\nX\n-----END CERTIFICATE-----"
|
||||
|
||||
|
||||
def _create(**overrides):
|
||||
base = dict(name="my-csr", common_name="www.example.com")
|
||||
base.update(overrides)
|
||||
return SSLCSRCreate(**base)
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# SSLCSRCreate
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
def test_minimal_valid_create():
|
||||
m = _create()
|
||||
assert m.name == "my-csr"
|
||||
assert m.common_name == "www.example.com"
|
||||
assert m.key_algorithm == "rsa-2048"
|
||||
assert m.sans == []
|
||||
|
||||
|
||||
@pytest.mark.parametrize("bad_name", [
|
||||
"../../etc/cron.d/evil", # path traversal
|
||||
"a..b", # embedded ..
|
||||
".hidden", # hidden filename
|
||||
"-flag", # CLI flag confusion
|
||||
"has space",
|
||||
"wild*card",
|
||||
"",
|
||||
"x" * 101, # VARCHAR(100) alignment — 200 is NOT allowed here
|
||||
])
|
||||
def test_name_rejects_unsafe_values(bad_name):
|
||||
with pytest.raises(ValidationError):
|
||||
_create(name=bad_name)
|
||||
|
||||
|
||||
def test_name_accepts_100_chars():
|
||||
assert _create(name="x" * 100).name == "x" * 100
|
||||
|
||||
|
||||
def test_common_name_wildcard_accepted_and_lowercased():
|
||||
m = _create(common_name="*.Example.COM")
|
||||
assert m.common_name == "*.example.com"
|
||||
|
||||
|
||||
@pytest.mark.parametrize("bad_cn", [
|
||||
"",
|
||||
"under_score.example.com", # _ is not LDH
|
||||
"*.*.example.com", # wildcard only as leftmost single label
|
||||
"-leading.example.com",
|
||||
"a" * 70 + ".example.com", # label > 63
|
||||
"cn-longer-than-64-chars-" + "x" * 45 + ".example.com", # CN > 64 total
|
||||
])
|
||||
def test_common_name_rejects_invalid(bad_cn):
|
||||
with pytest.raises(ValidationError):
|
||||
_create(common_name=bad_cn)
|
||||
|
||||
|
||||
def test_sans_normalised_deduped_and_capped():
|
||||
m = _create(sans=["API.example.com", "api.example.com", "cdn.example.com"])
|
||||
assert m.sans == ["api.example.com", "cdn.example.com"]
|
||||
|
||||
with pytest.raises(ValidationError):
|
||||
_create(sans=[f"h{i}.example.com" for i in range(101)])
|
||||
|
||||
|
||||
def test_country_normalised_or_rejected():
|
||||
assert _create(country="tr").country == "TR"
|
||||
assert _create(country=None).country is None
|
||||
for bad in ("TUR", "T", "1A"):
|
||||
with pytest.raises(ValidationError):
|
||||
_create(country=bad)
|
||||
|
||||
|
||||
def test_subject_fields_reject_control_characters():
|
||||
with pytest.raises(ValidationError):
|
||||
_create(organization="Evil\x00Corp")
|
||||
with pytest.raises(ValidationError):
|
||||
_create(locality="line\nbreak")
|
||||
|
||||
|
||||
def test_subject_fields_reject_overlength():
|
||||
with pytest.raises(ValidationError):
|
||||
_create(organization="x" * 65)
|
||||
|
||||
|
||||
def test_key_algorithm_strict_enum():
|
||||
for good in ("rsa-2048", "rsa-4096", "ecdsa-p256", "ecdsa-p384"):
|
||||
assert _create(key_algorithm=good).key_algorithm == good
|
||||
for bad in ("rsa-1024", "rsa-8192", "ed25519", "2048", ""):
|
||||
with pytest.raises(ValidationError):
|
||||
_create(key_algorithm=bad)
|
||||
|
||||
|
||||
def test_email_basic_validation():
|
||||
assert _create(email="ops@example.com").email == "ops@example.com"
|
||||
with pytest.raises(ValidationError):
|
||||
_create(email="not-an-email")
|
||||
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# SSLCSRImport
|
||||
# ----------------------------------------------------------------------------
|
||||
|
||||
|
||||
def test_import_minimal_global():
|
||||
m = SSLCSRImport(certificate_content=_CERT_PEM, is_global=True)
|
||||
assert m.usage_type == "frontend"
|
||||
assert m.name is None
|
||||
|
||||
|
||||
def test_import_requires_clusters_when_not_global():
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content=_CERT_PEM, is_global=False)
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content=_CERT_PEM, is_global=False, cluster_ids=[])
|
||||
m = SSLCSRImport(certificate_content=_CERT_PEM, is_global=False, cluster_ids=[1])
|
||||
assert m.cluster_ids == [1]
|
||||
|
||||
|
||||
def test_import_certificate_must_be_pem():
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content="not a pem", is_global=True)
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content="", is_global=True)
|
||||
|
||||
|
||||
def test_import_certificate_size_capped():
|
||||
huge = _CERT_PEM + "A" * (64 * 1024 + 1)
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content=huge, is_global=True)
|
||||
|
||||
|
||||
def test_import_chain_optional_but_validated():
|
||||
m = SSLCSRImport(certificate_content=_CERT_PEM, is_global=True, chain_content=" ")
|
||||
assert m.chain_content is None
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(
|
||||
certificate_content=_CERT_PEM, is_global=True, chain_content="garbage"
|
||||
)
|
||||
|
||||
|
||||
def test_import_name_override_shares_the_name_contract():
|
||||
m = SSLCSRImport(certificate_content=_CERT_PEM, is_global=True, name="renamed")
|
||||
assert m.name == "renamed"
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content=_CERT_PEM, is_global=True, name="../evil")
|
||||
# Empty override collapses to None (falls back to the CSR's own name).
|
||||
m2 = SSLCSRImport(certificate_content=_CERT_PEM, is_global=True, name=" ")
|
||||
assert m2.name is None
|
||||
|
||||
|
||||
def test_import_usage_type_enum():
|
||||
for good in ("frontend", "server"):
|
||||
assert SSLCSRImport(
|
||||
certificate_content=_CERT_PEM, is_global=True, usage_type=good
|
||||
).usage_type == good
|
||||
with pytest.raises(ValidationError):
|
||||
SSLCSRImport(certificate_content=_CERT_PEM, is_global=True, usage_type="both")
|
||||
@@ -0,0 +1,66 @@
|
||||
"""
|
||||
v1.9.0 CSR creation — behavioral auth tests for /api/ssl/csrs endpoints
|
||||
(pattern: test_ssl_list_endpoint_auth.py).
|
||||
|
||||
Every CSR endpoint must refuse unauthenticated / garbage-token requests.
|
||||
The CSR detail route additionally must never 200 without auth because it
|
||||
returns the CSR PEM; no endpoint ever returns the private key, but auth is
|
||||
the first line regardless.
|
||||
"""
|
||||
import pytest
|
||||
|
||||
_VALID_CREATE_BODY = {
|
||||
"name": "auth-test-csr",
|
||||
"common_name": "www.example.com",
|
||||
}
|
||||
|
||||
_VALID_IMPORT_BODY = {
|
||||
"certificate_content": (
|
||||
"-----BEGIN CERTIFICATE-----\nX\n-----END CERTIFICATE-----"
|
||||
),
|
||||
"is_global": True,
|
||||
}
|
||||
|
||||
_ENDPOINTS = [
|
||||
("get", "/api/ssl/csrs", None),
|
||||
("get", "/api/ssl/csrs/1", None),
|
||||
("post", "/api/ssl/csrs", _VALID_CREATE_BODY),
|
||||
("post", "/api/ssl/csrs/1/import", _VALID_IMPORT_BODY),
|
||||
("delete", "/api/ssl/csrs/1", None),
|
||||
]
|
||||
|
||||
|
||||
@pytest.mark.parametrize("method,path,body", _ENDPOINTS)
|
||||
def test_csr_endpoint_unauthenticated_rejected(client, method, path, body):
|
||||
"""No Authorization header → endpoint must refuse the request."""
|
||||
res = getattr(client, method)(path, json=body) if body is not None else getattr(client, method)(path)
|
||||
assert res.status_code in (401, 403, 422), (
|
||||
f"{method.upper()} {path} without Authorization returned "
|
||||
f"{res.status_code} — anonymous access to CSR data must not be "
|
||||
f"possible. Body: {res.text[:200]}"
|
||||
)
|
||||
if res.status_code == 200: # defensive, mirrors the R18 test style
|
||||
data = res.json()
|
||||
assert not data, "CSR endpoint returned data without auth"
|
||||
|
||||
|
||||
@pytest.mark.parametrize("method,path,body", _ENDPOINTS)
|
||||
def test_csr_endpoint_invalid_token_rejected(client, method, path, body):
|
||||
"""Garbage token → endpoint must refuse the request."""
|
||||
headers = {"Authorization": "Bearer not-a-valid-jwt"}
|
||||
if body is not None:
|
||||
res = getattr(client, method)(path, json=body, headers=headers)
|
||||
else:
|
||||
res = getattr(client, method)(path, headers=headers)
|
||||
assert res.status_code in (401, 403, 422), (
|
||||
f"{method.upper()} {path} with an invalid token returned {res.status_code}"
|
||||
)
|
||||
|
||||
|
||||
def test_csr_routes_are_registered(client):
|
||||
"""The router must actually be mounted — a 404 would make the auth tests
|
||||
above pass vacuously."""
|
||||
res = client.get("/api/ssl/csrs")
|
||||
assert res.status_code != 404, (
|
||||
"GET /api/ssl/csrs returned 404 — csr_router is not registered in main.py"
|
||||
)
|
||||
@@ -0,0 +1,171 @@
|
||||
"""
|
||||
v1.9.0 CSR creation — pure-crypto tests for services/csr_service.py.
|
||||
|
||||
No mocks: every algorithm's output must parse with `cryptography` and the
|
||||
CSR's public key must match the generated private key (the property the
|
||||
whole import flow depends on).
|
||||
"""
|
||||
from types import SimpleNamespace
|
||||
|
||||
import pytest
|
||||
|
||||
from cryptography import x509
|
||||
from cryptography.hazmat.primitives import serialization
|
||||
from cryptography.hazmat.primitives.asymmetric import ec, rsa
|
||||
from cryptography.x509.oid import ExtensionOID, NameOID
|
||||
|
||||
from services.csr_service import csr_row_to_dict, diff_domains, generate_csr_bundle
|
||||
|
||||
|
||||
def _payload(**overrides):
|
||||
base = dict(
|
||||
name="test-csr",
|
||||
common_name="www.example.com",
|
||||
organization=None,
|
||||
organizational_unit=None,
|
||||
locality=None,
|
||||
state=None,
|
||||
country=None,
|
||||
email=None,
|
||||
sans=[],
|
||||
key_algorithm="rsa-2048",
|
||||
)
|
||||
base.update(overrides)
|
||||
return SimpleNamespace(**base)
|
||||
|
||||
|
||||
def _spki(key):
|
||||
return key.public_key().public_bytes(
|
||||
serialization.Encoding.DER,
|
||||
serialization.PublicFormat.SubjectPublicKeyInfo,
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"algo,key_cls,key_check",
|
||||
[
|
||||
("rsa-2048", rsa.RSAPrivateKey, lambda k: k.key_size == 2048),
|
||||
("rsa-4096", rsa.RSAPrivateKey, lambda k: k.key_size == 4096),
|
||||
("ecdsa-p256", ec.EllipticCurvePrivateKey, lambda k: k.curve.name == "secp256r1"),
|
||||
("ecdsa-p384", ec.EllipticCurvePrivateKey, lambda k: k.curve.name == "secp384r1"),
|
||||
],
|
||||
)
|
||||
def test_generate_bundle_all_algorithms(algo, key_cls, key_check):
|
||||
bundle = generate_csr_bundle(_payload(key_algorithm=algo))
|
||||
|
||||
csr = x509.load_pem_x509_csr(bundle["csr_pem"].encode())
|
||||
key = serialization.load_pem_private_key(
|
||||
bundle["private_key_pem"].encode(), password=None
|
||||
)
|
||||
|
||||
assert isinstance(key, key_cls)
|
||||
assert key_check(key)
|
||||
# The CSR must be signed by exactly this key.
|
||||
csr_spki = csr.public_key().public_bytes(
|
||||
serialization.Encoding.DER,
|
||||
serialization.PublicFormat.SubjectPublicKeyInfo,
|
||||
)
|
||||
assert csr_spki == _spki(key)
|
||||
assert csr.is_signature_valid
|
||||
# PKCS8, unencrypted — the agent concatenates cert+key into one PEM and
|
||||
# HAProxy cannot read passphrase-protected keys.
|
||||
assert bundle["private_key_pem"].startswith("-----BEGIN PRIVATE KEY-----")
|
||||
|
||||
|
||||
def test_subject_contains_all_provided_fields():
|
||||
bundle = generate_csr_bundle(_payload(
|
||||
organization="Example Corp",
|
||||
organizational_unit="IT",
|
||||
locality="Istanbul",
|
||||
state="Marmara",
|
||||
country="TR",
|
||||
email="ops@example.com",
|
||||
))
|
||||
csr = x509.load_pem_x509_csr(bundle["csr_pem"].encode())
|
||||
|
||||
def _one(oid):
|
||||
attrs = csr.subject.get_attributes_for_oid(oid)
|
||||
return attrs[0].value if attrs else None
|
||||
|
||||
assert _one(NameOID.COMMON_NAME) == "www.example.com"
|
||||
assert _one(NameOID.ORGANIZATION_NAME) == "Example Corp"
|
||||
assert _one(NameOID.ORGANIZATIONAL_UNIT_NAME) == "IT"
|
||||
assert _one(NameOID.LOCALITY_NAME) == "Istanbul"
|
||||
assert _one(NameOID.STATE_OR_PROVINCE_NAME) == "Marmara"
|
||||
assert _one(NameOID.COUNTRY_NAME) == "TR"
|
||||
assert _one(NameOID.EMAIL_ADDRESS) == "ops@example.com"
|
||||
assert bundle["subject"] == {
|
||||
"O": "Example Corp", "OU": "IT", "L": "Istanbul",
|
||||
"ST": "Marmara", "C": "TR", "emailAddress": "ops@example.com",
|
||||
}
|
||||
|
||||
|
||||
def test_subject_omits_empty_fields():
|
||||
bundle = generate_csr_bundle(_payload())
|
||||
csr = x509.load_pem_x509_csr(bundle["csr_pem"].encode())
|
||||
assert not csr.subject.get_attributes_for_oid(NameOID.ORGANIZATION_NAME)
|
||||
assert bundle["subject"] == {}
|
||||
|
||||
|
||||
def test_sans_cn_first_and_deduped():
|
||||
bundle = generate_csr_bundle(_payload(
|
||||
common_name="www.example.com",
|
||||
sans=["api.example.com", "www.example.com", "api.example.com", "cdn.example.com"],
|
||||
))
|
||||
assert bundle["sans"] == ["www.example.com", "api.example.com", "cdn.example.com"]
|
||||
|
||||
csr = x509.load_pem_x509_csr(bundle["csr_pem"].encode())
|
||||
san_ext = csr.extensions.get_extension_for_oid(
|
||||
ExtensionOID.SUBJECT_ALTERNATIVE_NAME
|
||||
)
|
||||
dns_names = san_ext.value.get_values_for_type(x509.DNSName)
|
||||
assert dns_names == ["www.example.com", "api.example.com", "cdn.example.com"]
|
||||
|
||||
|
||||
def test_wildcard_common_name_flows_into_san():
|
||||
bundle = generate_csr_bundle(_payload(common_name="*.example.com"))
|
||||
csr = x509.load_pem_x509_csr(bundle["csr_pem"].encode())
|
||||
san_ext = csr.extensions.get_extension_for_oid(
|
||||
ExtensionOID.SUBJECT_ALTERNATIVE_NAME
|
||||
)
|
||||
assert san_ext.value.get_values_for_type(x509.DNSName) == ["*.example.com"]
|
||||
|
||||
|
||||
def test_diff_domains_reports_added_and_dropped():
|
||||
warnings = diff_domains(
|
||||
["www.example.com", "api.example.com"],
|
||||
["WWW.example.com", "cdn.example.com"],
|
||||
)
|
||||
assert len(warnings) == 2
|
||||
added = next(w for w in warnings if "added" in w)
|
||||
dropped = next(w for w in warnings if "dropped" in w)
|
||||
assert "cdn.example.com" in added
|
||||
assert "api.example.com" in dropped
|
||||
# Case-insensitive: www must NOT be reported in either direction.
|
||||
assert "www.example.com" not in added
|
||||
assert "www.example.com" not in dropped
|
||||
|
||||
|
||||
def test_diff_domains_identical_sets_yield_no_warnings():
|
||||
assert diff_domains(["a.example.com"], ["A.EXAMPLE.COM"]) == []
|
||||
assert diff_domains([], []) == []
|
||||
|
||||
|
||||
def test_csr_row_to_dict_never_exposes_private_key():
|
||||
row = {
|
||||
"id": 1,
|
||||
"name": "x",
|
||||
"private_key_pem": "-----BEGIN PRIVATE KEY-----\nSECRET\n-----END PRIVATE KEY-----",
|
||||
"csr_pem": "-----BEGIN CERTIFICATE REQUEST-----\nX\n-----END CERTIFICATE REQUEST-----",
|
||||
"subject": '{"O": "Example"}',
|
||||
"sans": '["a.example.com"]',
|
||||
}
|
||||
out = csr_row_to_dict(row)
|
||||
assert "private_key_pem" not in out
|
||||
assert "csr_pem" not in out # lists exclude the PEM
|
||||
assert out["subject"] == {"O": "Example"}
|
||||
assert out["sans"] == ["a.example.com"]
|
||||
|
||||
detail = csr_row_to_dict(row, include_pem=True)
|
||||
assert "private_key_pem" not in detail # NEVER, even on detail
|
||||
assert detail["csr_pem"].startswith("-----BEGIN CERTIFICATE REQUEST-----")
|
||||
+507
-4
@@ -2,7 +2,8 @@
|
||||
|
||||
Covers the TXT-value math (RFC 8555 §8.4 — raw SHA-256 digest, base64url, NOT hex),
|
||||
the _acme-challenge record-name derivation (wildcard stripping), credential encryption
|
||||
round-trip + tamper handling, and the DNS provider registry/allow-list.
|
||||
round-trip + tamper handling, the DNS provider registry/allow-list, and (v1.10.0) the
|
||||
GoDaddy provider's zone-relative name derivation and additive RRset merge math.
|
||||
"""
|
||||
import base64
|
||||
import hashlib
|
||||
@@ -53,9 +54,9 @@ def test_decrypt_invalid_token_returns_none():
|
||||
|
||||
def test_provider_registry_and_allow_list():
|
||||
names = {p["name"] for p in list_providers()}
|
||||
assert {"manual", "cloudflare"} <= names
|
||||
assert is_supported("manual") and is_supported("cloudflare")
|
||||
assert not is_supported("route53") # not in MVP allow-list
|
||||
assert {"manual", "cloudflare", "godaddy"} <= names
|
||||
assert is_supported("manual") and is_supported("cloudflare") and is_supported("godaddy")
|
||||
assert not is_supported("route53") # not in the allow-list
|
||||
|
||||
assert get_provider("manual").automated is False
|
||||
cf = get_provider("cloudflare", {"api_token": "x"})
|
||||
@@ -91,6 +92,400 @@ def test_cloudflare_token_sanitize():
|
||||
assert p._raw_token == '"my-token_123"'
|
||||
|
||||
|
||||
# --- v1.10.0: GoDaddy provider (pure logic only — no network, no DB) ---
|
||||
|
||||
|
||||
def test_godaddy_credential_fields_schema():
|
||||
# Re-assert DnsCredentialsUpsert's validator rules directly against the declared schema, so the
|
||||
# UI can never render a field whose submission the API would reject with a 422.
|
||||
import re
|
||||
from services.dns_providers.godaddy import GoDaddyDNSProvider
|
||||
|
||||
fields = GoDaddyDNSProvider.credential_fields
|
||||
assert [f["key"] for f in fields] == ["api_key", "api_secret"]
|
||||
for f in fields:
|
||||
assert re.match(r"^[a-zA-Z0-9_]{1,50}$", f["key"]) # DnsCredentialsUpsert key regex
|
||||
assert f["type"] == "password" # renders Input.Password, not Input
|
||||
assert isinstance(f["max_length"], int) and 0 < f["max_length"] <= 4000 # validator value cap
|
||||
assert f["help"] and isinstance(f["help"], str) # shown in the Form.Item `extra` slot
|
||||
# api_secret is optional on purpose: leaving it blank is how a Personal Access Token is used
|
||||
# (Bearer), which is the migration path off the sso-key scheme GoDaddy is retiring.
|
||||
assert fields[0]["required"] is True and fields[1]["required"] is False
|
||||
# Must not reuse Cloudflare's field name: the register modal's credential Form.Items are named
|
||||
# cred_<key> in a SHARED form and are not cleared when the provider dropdown changes.
|
||||
assert "api_token" not in {f["key"] for f in fields}
|
||||
|
||||
|
||||
def test_godaddy_provider_is_automated():
|
||||
p = get_provider("godaddy", {"api_key": "k", "api_secret": "s"})
|
||||
assert p.automated is True # else the orchestrator takes the manual-confirm branch
|
||||
assert p.name == "godaddy" and 1 <= len(p.name) <= 50 # dns_provider Field(min_length=1, max_length=50)
|
||||
assert p.label == "GoDaddy"
|
||||
|
||||
|
||||
def test_godaddy_missing_credentials_returns_not_ok():
|
||||
# verify_credentials must RETURN {"ok": False}, never raise: the router turns any non-
|
||||
# DnsProviderError into the information-free generic 422 and the user never sees the reason.
|
||||
import asyncio
|
||||
|
||||
for creds in ({}, {"api_secret": "s"}): # blank UI fields arrive as MISSING keys, not ""
|
||||
r = asyncio.run(get_provider("godaddy", creds).verify_credentials())
|
||||
assert r["ok"] is False and r["detail"]
|
||||
# Short-circuits before any request, so this touches no network.
|
||||
|
||||
|
||||
def test_godaddy_auth_header_formats_and_secret_never_leaks():
|
||||
from services.dns_providers.godaddy import GoDaddyDNSProvider, _scrub
|
||||
|
||||
sentinel = "SENTINEL-SECRET-DO-NOT-LEAK"
|
||||
p = GoDaddyDNSProvider({"api_key": "KEY123", "api_secret": sentinel})
|
||||
# Literal prefix, one space, a single colon — no base64, no quoting.
|
||||
assert p._auth_header() == f"sso-key KEY123:{sentinel}"
|
||||
# No secret -> Personal Access Token. This one branch is the whole sso-key-sunset migration.
|
||||
assert GoDaddyDNSProvider({"api_key": "PAT"})._auth_header() == "Bearer PAT"
|
||||
# _scrub removes credential substrings from anything bound for a log or an order event.
|
||||
assert sentinel not in _scrub(f"boom {sentinel} boom", "KEY123", sentinel)
|
||||
assert "KEY123" not in _scrub("boom KEY123", "KEY123", sentinel)
|
||||
assert _scrub("x" * 500, "KEY123") == "x" * 300 # bounded, so a huge body can't flood an event
|
||||
|
||||
# The channel that actually persists text: _http_error composes the message an order event and
|
||||
# letsencrypt_orders.error_detail will carry, so it must scrub its own inputs — a caller that
|
||||
# forgets to pre-scrub must not be able to leak. (Regression guard: scrubbing used to live at
|
||||
# the single call site in _request instead of here.)
|
||||
exc = p._http_error(403, f"DENIED_{sentinel}", f"token {sentinel} rejected", None)
|
||||
assert sentinel not in str(exc) and "***" in str(exc)
|
||||
|
||||
# This module must not log at all — logging is the one channel _scrub cannot reach, since the
|
||||
# arguments would be formatted by the logging framework rather than passed through it.
|
||||
import inspect
|
||||
import re as _re
|
||||
from services.dns_providers import godaddy as gd_mod
|
||||
|
||||
assert not _re.search(r"\blogger\.\w+\(", inspect.getsource(gd_mod)), \
|
||||
"godaddy.py must not log; surface everything through DnsProviderError so it is scrubbed"
|
||||
|
||||
|
||||
def test_godaddy_relative_record_name():
|
||||
# GoDaddy names are RELATIVE to the zone with no trailing dot; the apex is the literal "@".
|
||||
from services.dns_providers.godaddy import _relative_name
|
||||
|
||||
assert _relative_name("_acme-challenge.example.com", "example.com") == "_acme-challenge"
|
||||
assert _relative_name("_acme-challenge.foo.bar.example.com", "example.com") == "_acme-challenge.foo.bar"
|
||||
assert _relative_name("example.com", "example.com") == "@" # never "" — see _rrset_path
|
||||
assert _relative_name("_acme-challenge.example.com.", "example.com") == "_acme-challenge"
|
||||
assert _relative_name("_ACME-Challenge.Example.COM", "example.com") == "_acme-challenge"
|
||||
# Apex and wildcard produce the SAME relative name — which is exactly why the merge below
|
||||
# has to be additive.
|
||||
apex = ACMEService._challenge_dns_name("example.com")
|
||||
wild = ACMEService._challenge_dns_name("*.example.com")
|
||||
assert _relative_name(apex, "example.com") == _relative_name(wild, "example.com") == "_acme-challenge"
|
||||
|
||||
|
||||
def test_godaddy_rrset_merge_is_additive():
|
||||
# THE critical test: GoDaddy's PUT REPLACES an entire RRset, so the merge math is the only thing
|
||||
# keeping a wildcard+apex certificate's two coexisting TXT values alive.
|
||||
from services.dns_providers.godaddy import _live_values, _merge_add, _merge_remove
|
||||
|
||||
def vals(body):
|
||||
return sorted(r["data"] for r in body)
|
||||
|
||||
assert vals(_merge_add([{"data": "valueA", "ttl": 600}], "valueB")) == ["valueA", "valueB"]
|
||||
assert _merge_add([{"data": "valueA"}], "valueA") is None # idempotent; ACME retries land here
|
||||
# Total, not an all()-over-a-computed-list (which passes vacuously on an empty result): the
|
||||
# first publish at a fresh name must emit exactly one element, carrying the 600s TTL floor.
|
||||
assert _merge_add([], "v") == [{"data": "v", "ttl": 600}] # below 600 GoDaddy answers 422
|
||||
# Tombstone rows ({"data": ""}) must never be echoed back — GoDaddy answers 422 INVALID_BODY.
|
||||
assert _live_values([{"data": ""}, {"data": "x"}, {}]) == ["x"]
|
||||
assert vals(_merge_add([{"data": ""}, {"data": "valueA"}], "valueB")) == ["valueA", "valueB"]
|
||||
|
||||
assert vals(_merge_remove([{"data": "valueA"}, {"data": "valueB"}], "valueB")) == ["valueA"]
|
||||
assert _merge_remove([{"data": "valueA"}], "valueZ") is None # already gone — tolerate
|
||||
assert _merge_remove([], "valueZ") is None
|
||||
# [] means "use DELETE": PUT with an empty array is rejected (422, "Records must be specified").
|
||||
assert _merge_remove([{"data": "valueA"}], "valueA") == []
|
||||
assert _merge_remove([{"data": ""}, {"data": "valueA"}], "valueA") == []
|
||||
|
||||
|
||||
def test_godaddy_never_builds_a_zone_wide_txt_path():
|
||||
# A 3-segment path (.../records/TXT) is the endpoint that wipes EVERY TXT in the zone — SPF,
|
||||
# DKIM, DMARC, domain verifications. An empty relative name must never be able to produce it.
|
||||
from services.dns_providers.godaddy import _rrset_path
|
||||
|
||||
p = _rrset_path("example.com", "_acme-challenge")
|
||||
assert p == "/domains/example.com/records/TXT/_acme-challenge"
|
||||
assert p.count("/") == 5 and not p.endswith("/TXT")
|
||||
assert _rrset_path("example.com", "@").endswith("/%40") # apex percent-encoded for proxy safety
|
||||
# "." and ".." survive quote() and are then normalized away by yarl when the URL is built, so
|
||||
# ".../records/TXT/.." would resolve to the whole-zone endpoint. They must be refused too.
|
||||
for bad in [("example.com", ""), ("", "_acme-challenge"), ("example.com", "."),
|
||||
("example.com", ".."), ("example.com", "...")]:
|
||||
raised = False
|
||||
try:
|
||||
_rrset_path(*bad)
|
||||
except DnsProviderError:
|
||||
raised = True
|
||||
assert raised, f"_rrset_path{bad} must refuse to build a zone-wide TXT path"
|
||||
# And the only way to reach those inputs — a malformed domain — really does produce them.
|
||||
from services.dns_providers.godaddy import _relative_name as _rel
|
||||
assert _rel("..example.com", "example.com") == "."
|
||||
|
||||
|
||||
def test_godaddy_credential_encryption_roundtrip():
|
||||
# The two-field credential dict rides the same Fernet blob as Cloudflare's single token.
|
||||
reset_fernet_for_tests()
|
||||
creds = {"api_key": "gd-key-plaintext", "api_secret": "gd-secret-plaintext"}
|
||||
token = encrypt_dns_credentials(creds)
|
||||
assert "gd-key-plaintext" not in token and "gd-secret-plaintext" not in token # ciphertext
|
||||
assert decrypt_dns_credentials(token) == creds
|
||||
# This sorted key list is exactly what GET /dns-credentials exposes as credential_fields_present
|
||||
# — names only, never values.
|
||||
assert sorted(decrypt_dns_credentials(token).keys()) == ["api_key", "api_secret"]
|
||||
|
||||
|
||||
_GD_NS = "/domains/example.com/records/NS"
|
||||
_GD_TXT = "/domains/example.com/records/TXT/_acme-challenge"
|
||||
|
||||
|
||||
def _gd_provider(responses):
|
||||
"""A GoDaddy provider whose _request is replaced by a recorder.
|
||||
|
||||
The pure-merge tests above prove the MATH; this proves the WRITE PATH actually uses it. Without
|
||||
it, replacing the merge with a single-value PUT — the mutation that silently destroys the
|
||||
sibling value of every wildcard+apex certificate — leaves the whole suite green.
|
||||
|
||||
`responses` maps (method, path) -> value to return, or an Exception to raise. Unmapped calls
|
||||
return None, which is how the zone suffix-walk's failed probes are modelled.
|
||||
"""
|
||||
import types
|
||||
from services.dns_providers.godaddy import GoDaddyDNSProvider
|
||||
|
||||
calls = []
|
||||
|
||||
async def _fake_request(self, session, method, path, **kwargs):
|
||||
calls.append((method, path, kwargs.get("json")))
|
||||
result = responses.get((method, path))
|
||||
if isinstance(result, Exception):
|
||||
raise result
|
||||
return result
|
||||
|
||||
p = GoDaddyDNSProvider({"api_key": "k", "api_secret": "s"})
|
||||
p._request = types.MethodType(_fake_request, p)
|
||||
return p, calls
|
||||
|
||||
|
||||
def _assert_never_zone_wide(calls):
|
||||
# A write to .../records or .../records/TXT replaces every TXT (or every record) in the zone.
|
||||
for method, path, _json in calls:
|
||||
if method in ("PUT", "DELETE"):
|
||||
assert not path.endswith("/records"), f"zone-wide write: {method} {path}"
|
||||
assert not path.endswith("/records/TXT"), f"type-wide write: {method} {path}"
|
||||
|
||||
|
||||
def test_godaddy_add_write_path_merges_siblings():
|
||||
import asyncio
|
||||
|
||||
# An existing sibling value at the same name — the apex half of an apex+wildcard certificate.
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [{"data": "valueA", "ttl": 600}],
|
||||
})
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "valueB"))
|
||||
|
||||
writes = [c for c in calls if c[0] in ("PUT", "PATCH", "DELETE")]
|
||||
assert len(writes) == 1 and writes[0][0] == "PUT" and writes[0][1] == _GD_TXT
|
||||
# BOTH values must be in the body: GoDaddy's PUT replaces the whole RRset.
|
||||
assert sorted(r["data"] for r in writes[0][2]) == ["valueA", "valueB"]
|
||||
_assert_never_zone_wide(calls)
|
||||
|
||||
|
||||
def test_godaddy_add_write_path_is_idempotent_and_fails_closed():
|
||||
import asyncio
|
||||
|
||||
# Already published -> no write at all (this is where an ACME retry cycle lands).
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [{"data": "valueB", "ttl": 600}],
|
||||
})
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "valueB"))
|
||||
assert [c for c in calls if c[0] != "GET"] == []
|
||||
|
||||
# Unreadable RRset read (2xx whose body did not parse as a list) must FAIL, never be treated as
|
||||
# an empty RRset — the PUT that follows would replace the sibling values with only ours.
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): None,
|
||||
})
|
||||
raised = False
|
||||
try:
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "valueB"))
|
||||
except DnsProviderError:
|
||||
raised = True
|
||||
assert raised, "an unreadable RRset read must not be coerced into an empty RRset"
|
||||
assert [c for c in calls if c[0] != "GET"] == []
|
||||
|
||||
|
||||
def test_godaddy_remove_write_path_uses_delete_for_the_last_value():
|
||||
import asyncio
|
||||
|
||||
# Two values -> PUT back the survivor only.
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [{"data": "valueA"}, {"data": "valueB"}],
|
||||
})
|
||||
asyncio.run(p.remove_txt_record("_acme-challenge.example.com", "valueB"))
|
||||
writes = [c for c in calls if c[0] != "GET"]
|
||||
assert len(writes) == 1 and writes[0][0] == "PUT"
|
||||
assert [r["data"] for r in writes[0][2]] == ["valueA"]
|
||||
|
||||
# Last value -> DELETE. `PUT []` is rejected by GoDaddy (422 INVALID_BODY), so an empty PUT
|
||||
# body would make every cleanup fail forever.
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [{"data": "valueA"}],
|
||||
})
|
||||
asyncio.run(p.remove_txt_record("_acme-challenge.example.com", "valueA"))
|
||||
writes = [c for c in calls if c[0] != "GET"]
|
||||
assert len(writes) == 1 and writes[0] == ("DELETE", _GD_TXT, None)
|
||||
assert not any(c[0] == "PUT" and c[2] == [] for c in calls)
|
||||
|
||||
# Value already gone -> no write, no error.
|
||||
p, calls = _gd_provider({
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [{"data": "valueA"}],
|
||||
})
|
||||
asyncio.run(p.remove_txt_record("_acme-challenge.example.com", "valueZ"))
|
||||
assert [c for c in calls if c[0] != "GET"] == []
|
||||
_assert_never_zone_wide(calls)
|
||||
|
||||
|
||||
class _FakeGDResponse:
|
||||
"""Minimal stand-in for aiohttp's ClientResponse: status, headers, and json()."""
|
||||
|
||||
_NO_BODY = object()
|
||||
|
||||
def __init__(self, status, body=_NO_BODY, headers=None):
|
||||
self.status = status
|
||||
self._body = body
|
||||
self.headers = headers or {}
|
||||
|
||||
async def json(self, content_type=None):
|
||||
if self._body is _FakeGDResponse._NO_BODY:
|
||||
raise ValueError("no body to decode") # what an empty 204 does
|
||||
return self._body
|
||||
|
||||
|
||||
class _FakeGDSession:
|
||||
def __init__(self, response):
|
||||
self._response = response
|
||||
self.calls = []
|
||||
|
||||
def request(self, method, url, **kwargs):
|
||||
self.calls.append((method, url, kwargs))
|
||||
response = self._response
|
||||
|
||||
class _Ctx:
|
||||
async def __aenter__(self_inner):
|
||||
return response
|
||||
|
||||
async def __aexit__(self_inner, *exc):
|
||||
return False
|
||||
|
||||
return _Ctx()
|
||||
|
||||
|
||||
def test_godaddy_request_status_handling():
|
||||
import asyncio
|
||||
from services.dns_providers.godaddy import GoDaddyDNSProvider
|
||||
|
||||
p = GoDaddyDNSProvider({"api_key": "KEY123", "api_secret": "SEC456"})
|
||||
|
||||
def call(response):
|
||||
session = _FakeGDSession(response)
|
||||
try:
|
||||
return asyncio.run(p._request(session, "PUT", "/domains/example.com/records/TXT/x",
|
||||
json=[{"data": "v", "ttl": 600}])), None, session
|
||||
except DnsProviderError as exc:
|
||||
return None, str(exc), session
|
||||
|
||||
# 204 with an EMPTY body is the normal answer to every GoDaddy write — it must not raise.
|
||||
body, err, session = call(_FakeGDResponse(204))
|
||||
assert body is None and err is None
|
||||
# Redirects are deliberately not followed (aiohttp would forward the Authorization header), so
|
||||
# a 3xx is a FAILED call. Treating it as success would report a redirected write as a no-op.
|
||||
_kw = session.calls[0][2]
|
||||
assert _kw["allow_redirects"] is False
|
||||
assert _kw["headers"]["Authorization"] == "sso-key KEY123:SEC456"
|
||||
assert _kw["headers"]["Accept"] == "application/json"
|
||||
for status in (301, 302, 307):
|
||||
body, err, _ = call(_FakeGDResponse(status))
|
||||
assert body is None and err and str(status) in err, f"HTTP {status} must not read as success"
|
||||
|
||||
# 200 with a list is passed through verbatim.
|
||||
body, err, _ = call(_FakeGDResponse(200, [{"data": "v"}]))
|
||||
assert err is None and body == [{"data": "v"}]
|
||||
|
||||
# Error mapping: each message must name what the operator has to fix.
|
||||
_, err, _ = call(_FakeGDResponse(401, {"code": "UNABLE_TO_AUTHENTICATE", "message": "nope"}))
|
||||
assert "PRODUCTION" in err and "UNABLE_TO_AUTHENTICATE" in err
|
||||
_, err, _ = call(_FakeGDResponse(403, {"code": "ACCESS_DENIED", "message": "not allowed"}))
|
||||
assert "domains.dns:update" in err
|
||||
# 429: Retry-After wins; the legacy body field is the fallback; absent both -> 60s default.
|
||||
_, err, _ = call(_FakeGDResponse(429, None, {"Retry-After": "17"}))
|
||||
assert "~17s" in err
|
||||
_, err, _ = call(_FakeGDResponse(429, {"retryAfterSec": 42}))
|
||||
assert "~42s" in err
|
||||
_, err, _ = call(_FakeGDResponse(429, {"Retry-After": "not-a-number"}))
|
||||
assert "~60s" in err
|
||||
# A non-dict error body must not crash the error mapper.
|
||||
_, err, _ = call(_FakeGDResponse(500, "<html>gateway</html>"))
|
||||
assert "500" in err
|
||||
|
||||
# A transport failure MID-READ must not be mistaken for "empty body". Only a decode error may
|
||||
# be swallowed: a caller reading an RRset would otherwise see None and could take it for an
|
||||
# empty record set, and the full-RRset PUT that follows would destroy the sibling values.
|
||||
import aiohttp
|
||||
|
||||
class _TruncatedResponse(_FakeGDResponse):
|
||||
async def json(self, content_type=None):
|
||||
raise aiohttp.ClientPayloadError("connection closed mid-body")
|
||||
|
||||
body, err, _ = call(_TruncatedResponse(200))
|
||||
assert body is None and err and "GoDaddy" in err
|
||||
|
||||
|
||||
def test_godaddy_zone_resolution_walks_suffixes_and_caches():
|
||||
import asyncio
|
||||
from services.dns_providers.godaddy import _GoDaddyHTTPError
|
||||
|
||||
# The deepest candidate is not a zone (404 = "not this zone"); the walk must continue to the
|
||||
# registrable domain and then reuse it, so the second challenge at the same name costs no probe.
|
||||
p, calls = _gd_provider({
|
||||
("GET", "/domains/_acme-challenge.example.com/records/NS"):
|
||||
_GoDaddyHTTPError("nope", status=404, code="UNKNOWN_DOMAIN"),
|
||||
("GET", _GD_NS): [{"data": "ns1.domaincontrol.com"}],
|
||||
("GET", _GD_TXT): [],
|
||||
})
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "valueA"))
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "valueB"))
|
||||
probes = [c for c in calls if c[1].endswith("/records/NS")]
|
||||
assert len(probes) == 2, "the resolved zone must be cached for the life of the provider"
|
||||
# Relative name derived from the RESOLVED zone, never from the deepest candidate.
|
||||
assert all(c[1] == _GD_TXT for c in calls if "/records/TXT/" in c[1])
|
||||
|
||||
# A credential/eligibility failure during the walk must surface, not be swallowed as
|
||||
# "no managed domain" — otherwise the operator chases a DNS problem that is really a bad key.
|
||||
p, calls = _gd_provider({
|
||||
("GET", "/domains/_acme-challenge.example.com/records/NS"):
|
||||
_GoDaddyHTTPError("denied", status=403, code="ACCESS_DENIED"),
|
||||
})
|
||||
raised = ""
|
||||
try:
|
||||
asyncio.run(p.add_txt_record("_acme-challenge.example.com", "v"))
|
||||
except DnsProviderError as exc:
|
||||
raised = str(exc)
|
||||
assert "denied" in raised and "No managed GoDaddy domain" not in raised
|
||||
|
||||
|
||||
def test_b64url_decode_padding_roundtrip():
|
||||
# Issue #35 v1.8.2: _b64url_decode must round-trip for EVERY length, including base64url strings
|
||||
# whose length is a multiple of 4 (the case the old padding formula '=' * (4 - len%4) over-padded).
|
||||
@@ -110,3 +505,111 @@ def test_nonce_scoped_per_directory():
|
||||
assert got == "NONCE_A" # returns THIS CA's nonce
|
||||
assert svc._nonce_by_dir.get("https://a.example/dir") is None # consumed (single-use)
|
||||
assert svc._nonce_by_dir.get("https://b.example/dir") == "NONCE_B" # the other CA is untouched
|
||||
|
||||
|
||||
def _sql_paren_depth(sql: str):
|
||||
"""Parenthesis depth of a SQL string, counting only OUTSIDE '...' literals (with ''
|
||||
escapes), `--` line comments and /* */ block comments. Single-pass state machine so a
|
||||
`--` inside a literal or a `'` inside a comment cannot corrupt the count. Dollar-quoted
|
||||
strings are out of scope (not used in this codebase). Returns (final_depth, min_depth).
|
||||
"""
|
||||
depth = 0
|
||||
min_depth = 0
|
||||
state = "normal"
|
||||
i, n = 0, len(sql)
|
||||
while i < n:
|
||||
ch = sql[i]
|
||||
nxt = sql[i + 1] if i + 1 < n else ""
|
||||
if state == "normal":
|
||||
if ch == "'":
|
||||
state = "string"
|
||||
elif ch == "-" and nxt == "-":
|
||||
state = "line_comment"
|
||||
i += 1
|
||||
elif ch == "/" and nxt == "*":
|
||||
state = "block_comment"
|
||||
i += 1
|
||||
elif ch == "(":
|
||||
depth += 1
|
||||
elif ch == ")":
|
||||
depth -= 1
|
||||
min_depth = min(min_depth, depth)
|
||||
elif state == "string":
|
||||
if ch == "'":
|
||||
if nxt == "'":
|
||||
i += 1 # escaped '' stays inside the literal
|
||||
else:
|
||||
state = "normal"
|
||||
elif state == "line_comment":
|
||||
if ch == "\n":
|
||||
state = "normal"
|
||||
else: # block_comment
|
||||
if ch == "*" and nxt == "/":
|
||||
state = "normal"
|
||||
i += 1
|
||||
i += 1
|
||||
return depth, min_depth
|
||||
|
||||
|
||||
def test_acme_sql_parentheses_balanced():
|
||||
"""Issue #35 v1.8.5: the completion task's order-claim query shipped (v1.8.0-v1.8.4) with an
|
||||
extra closing parenthesis, so EVERY 60s cycle died with `syntax error at or near ")"` and no
|
||||
background ACME work (claim/finalize/download, DNS-01 publish, wizard-staged promotion,
|
||||
retry, TXT cleanup) ever ran. The suite never caught it because the DB layer is mocked and
|
||||
raw SQL never reaches a real parser. This guard scans the ACME modules' SQL string literals
|
||||
for unbalanced parentheses.
|
||||
|
||||
Guard scope is deliberately conservative to avoid false positives on production changes:
|
||||
keyword matching is case-sensitive (SQL is uppercase in this codebase; prose in docstrings
|
||||
is not) and f-string fragments are excluded (they split at `{`, so a fragment may be
|
||||
legitimately unbalanced).
|
||||
"""
|
||||
import ast
|
||||
import re
|
||||
|
||||
backend_dir = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
modules = [
|
||||
"main.py",
|
||||
os.path.join("services", "dns01_orchestrator.py"),
|
||||
os.path.join("services", "acme_service.py"),
|
||||
os.path.join("services", "letsencrypt_service.py"),
|
||||
os.path.join("routers", "letsencrypt.py"),
|
||||
os.path.join("routers", "acme_diagnostics.py"),
|
||||
]
|
||||
problems = []
|
||||
for rel in modules:
|
||||
with open(os.path.join(backend_dir, rel), encoding="utf-8") as fh:
|
||||
tree = ast.parse(fh.read())
|
||||
fstring_parts = {
|
||||
id(const)
|
||||
for joined in ast.walk(tree) if isinstance(joined, ast.JoinedStr)
|
||||
for const in ast.walk(joined) if isinstance(const, ast.Constant)
|
||||
}
|
||||
for node in ast.walk(tree):
|
||||
if not (isinstance(node, ast.Constant) and isinstance(node.value, str)):
|
||||
continue
|
||||
if id(node) in fstring_parts:
|
||||
continue
|
||||
sql = node.value
|
||||
if not re.search(r"\b(SELECT|INSERT|UPDATE|DELETE)\b", sql):
|
||||
continue
|
||||
if not re.search(r"\b(FROM|INTO|SET|WHERE)\b", sql):
|
||||
continue
|
||||
depth, min_depth = _sql_paren_depth(sql)
|
||||
if depth != 0 or min_depth < 0:
|
||||
problems.append(f"{rel}:{node.lineno} (paren depth {depth:+d}, min {min_depth})")
|
||||
assert not problems, f"Unbalanced parentheses in SQL literal(s): {problems}"
|
||||
|
||||
|
||||
def test_sql_paren_depth_scanner():
|
||||
# The guard's scanner itself: parens in literals/comments must not count; '' escapes and
|
||||
# block comments handled; an extra ')' is reported via min_depth even if a later '(' would
|
||||
# re-balance the total.
|
||||
assert _sql_paren_depth("SELECT (1)") == (0, 0)
|
||||
assert _sql_paren_depth("SELECT (1))") == (-1, -1) # the v1.8.0 bug shape
|
||||
assert _sql_paren_depth("SELECT ')' , '((' FROM t") == (0, 0) # literals ignored
|
||||
assert _sql_paren_depth("SELECT 'it''s ))' FROM t") == (0, 0) # '' escape stays inside
|
||||
assert _sql_paren_depth("SELECT 1 -- comment ) (\nFROM t") == (0, 0) # line comment ignored
|
||||
assert _sql_paren_depth("SELECT 1 /* ) */ FROM t") == (0, 0) # block comment ignored
|
||||
assert _sql_paren_depth("SELECT 'a--b' AND (x=1\n)") == (0, 0) # -- inside literal is data
|
||||
assert _sql_paren_depth("WHERE x) AND (y") == (0, -1) # net 0 but went negative
|
||||
|
||||
@@ -206,41 +206,38 @@ def test_module_level_validate_haproxy_config_forwards_partial_fragment():
|
||||
|
||||
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
# Wizard Pydantic gate: ACL `-f` flag must be REJECTED at submit.
|
||||
# Issue #38 follow-up: ACL `-f <file>` pattern-file references are
|
||||
# ACCEPTED (the Bulgu #12 hard reject was removed — pattern files are
|
||||
# operator-managed host files, the agent's pre-reload `haproxy -c`
|
||||
# makes a missing file fail safely, and bulk import always accepted
|
||||
# `-f`). These tests pin the ACCEPT behaviour.
|
||||
# ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
|
||||
def test_wizard_pydantic_rejects_acl_with_file_flag():
|
||||
"""Pre-fix the wizard's ACL string validator passed
|
||||
`acl name path -i -m reg -f /path` straight through. Apply-time
|
||||
HAProxy `-c` then failed with "failed to open pattern file".
|
||||
Pin that the validator now rejects `-f` at submit.
|
||||
def test_wizard_pydantic_accepts_acl_with_file_flag():
|
||||
"""Issue #38 follow-up — the wizard's ACL string validator must
|
||||
ACCEPT `-f <file>` pattern-file references (Bulgu #12 reject
|
||||
removed). Operators with large host-managed IP blacklists rely
|
||||
on this in production.
|
||||
"""
|
||||
from models.site_wizard import FrontendStep
|
||||
|
||||
# Minimal valid wizard frontend kwargs — only the offending
|
||||
# acl_rules entry should trigger the failure.
|
||||
fe_kwargs = dict(
|
||||
fe = FrontendStep(
|
||||
name="fe1",
|
||||
mode="http",
|
||||
bind_address="*",
|
||||
bind_port=80,
|
||||
acl_rules=["acl1 path -i -m reg -f /path"],
|
||||
)
|
||||
from pydantic import ValidationError
|
||||
with pytest.raises(ValidationError) as exc_info:
|
||||
FrontendStep(**fe_kwargs)
|
||||
msg = str(exc_info.value)
|
||||
assert "-f" in msg or "pattern-file" in msg.lower(), (
|
||||
f"Bulgu #12 regression: ACL -f flag must be rejected with a "
|
||||
f"clear pattern-file error. Got: {msg}"
|
||||
assert fe.acl_rules == ["acl1 path -i -m reg -f /path"], (
|
||||
"ACL `-f` rule must round-trip verbatim through the wizard model"
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"rule",
|
||||
[
|
||||
# Various spacing / position variants the regex must catch.
|
||||
# Various spacing / position variants must all be accepted.
|
||||
"acl1 path -f /etc/haproxy/list",
|
||||
"acl1 path -i -f /tmp/x.lst",
|
||||
"acl1 src -f /etc/haproxy/admins.lst",
|
||||
@@ -249,23 +246,19 @@ def test_wizard_pydantic_rejects_acl_with_file_flag():
|
||||
"acl1 path -f",
|
||||
],
|
||||
)
|
||||
def test_wizard_pydantic_rejects_acl_with_file_flag_variants(rule):
|
||||
"""Every spacing / position variant the operator might type must
|
||||
be rejected. Pinned defensively so the regex never accidentally
|
||||
relaxes to "only matches trailing -f".
|
||||
"""
|
||||
def test_wizard_pydantic_accepts_acl_with_file_flag_variants(rule):
|
||||
"""Every spacing / position variant must be accepted verbatim
|
||||
(Issue #38 follow-up — no `-f` shape may be rejected)."""
|
||||
from models.site_wizard import FrontendStep
|
||||
from pydantic import ValidationError
|
||||
|
||||
fe_kwargs = dict(
|
||||
fe = FrontendStep(
|
||||
name="fe1",
|
||||
mode="http",
|
||||
bind_address="*",
|
||||
bind_port=80,
|
||||
acl_rules=[rule],
|
||||
)
|
||||
with pytest.raises(ValidationError):
|
||||
FrontendStep(**fe_kwargs)
|
||||
assert fe.acl_rules == [rule]
|
||||
|
||||
|
||||
def test_wizard_pydantic_does_not_falsely_match_dash_f_inside_token():
|
||||
@@ -291,42 +284,29 @@ def test_wizard_pydantic_does_not_falsely_match_dash_f_inside_token():
|
||||
assert len(fe.acl_rules) == 3
|
||||
|
||||
|
||||
def test_manual_frontend_validator_rejects_acl_with_file_flag():
|
||||
"""Parity check: the manual Frontend API
|
||||
(`models/frontend.py::validate_acl_rules`) must apply the same
|
||||
`-f` rejection. Operators see consistent behaviour from both the
|
||||
wizard and the per-entity frontend page.
|
||||
def test_manual_frontend_validator_accepts_acl_with_file_flag():
|
||||
"""Parity check (Issue #38 follow-up): the manual Frontend API
|
||||
(`models/frontend.py::validate_acl_rules`) must ACCEPT `-f`
|
||||
pattern-file references, same as the wizard and bulk import.
|
||||
"""
|
||||
from models.frontend import FrontendConfig
|
||||
from pydantic import ValidationError
|
||||
|
||||
with pytest.raises(ValidationError) as exc_info:
|
||||
FrontendConfig(
|
||||
name="fe1",
|
||||
bind_port=80,
|
||||
mode="http",
|
||||
acl_rules=["acl1 path -i -m reg -f /path"],
|
||||
)
|
||||
msg = str(exc_info.value)
|
||||
assert "-f" in msg or "pattern-file" in msg.lower(), (
|
||||
f"Manual frontend API parity regression: ACL -f flag must be "
|
||||
f"rejected. Got: {msg}"
|
||||
fe = FrontendConfig(
|
||||
name="fe1",
|
||||
bind_port=80,
|
||||
mode="http",
|
||||
acl_rules=["acl1 path -i -m reg -f /path"],
|
||||
)
|
||||
assert fe.acl_rules == ["acl1 path -i -m reg -f /path"]
|
||||
|
||||
|
||||
def test_wizard_pydantic_rejects_structured_redirect_dict_with_file_flag():
|
||||
"""Round-3 audit extension — structured redirect dicts (the
|
||||
alternative shape that `models/site_wizard.py::_validate_redirect_rules`
|
||||
accepts alongside legacy strings) also flow through to
|
||||
`services/haproxy_config.py::_format_redirect_rule` and emit
|
||||
their `condition` / `target` verbatim into the rendered HAProxy
|
||||
directive. Without the dict-aware reject the visual builder's
|
||||
`-f` block could be bypassed by hand-crafting a dict payload
|
||||
against the API — recreating the same `failed to open pattern
|
||||
file` failure at apply time.
|
||||
def test_wizard_pydantic_accepts_structured_redirect_dict_with_file_flag():
|
||||
"""Issue #38 follow-up — structured redirect dicts carrying `-f`
|
||||
pattern-file references in `condition`/`target` are ACCEPTED
|
||||
(the Bulgu #12 dict-aware reject was removed together with the
|
||||
string-rule reject).
|
||||
"""
|
||||
from models.site_wizard import FrontendStep, BackendStep
|
||||
from pydantic import ValidationError
|
||||
from models.site_wizard import FrontendStep
|
||||
|
||||
fe_kwargs = dict(
|
||||
name="fe1",
|
||||
@@ -334,37 +314,32 @@ def test_wizard_pydantic_rejects_structured_redirect_dict_with_file_flag():
|
||||
mode="http",
|
||||
)
|
||||
|
||||
# `condition` carrying `-f` must be rejected.
|
||||
with pytest.raises(ValidationError) as exc_info:
|
||||
FrontendStep(
|
||||
**fe_kwargs,
|
||||
redirect_rules=[
|
||||
{
|
||||
"type": "scheme",
|
||||
"target": "https",
|
||||
"condition": "if { src -f /etc/haproxy/admins.lst }",
|
||||
}
|
||||
],
|
||||
)
|
||||
msg = str(exc_info.value)
|
||||
assert "pattern-file" in msg.lower() or "-f" in msg, msg
|
||||
# `condition` carrying `-f` is accepted.
|
||||
fe = FrontendStep(
|
||||
**fe_kwargs,
|
||||
redirect_rules=[
|
||||
{
|
||||
"type": "scheme",
|
||||
"target": "https",
|
||||
"condition": "if { src -f /etc/haproxy/admins.lst }",
|
||||
}
|
||||
],
|
||||
)
|
||||
assert fe.redirect_rules[0]["condition"] == "if { src -f /etc/haproxy/admins.lst }"
|
||||
|
||||
# `target` carrying `-f` must also be rejected (defence-in-depth
|
||||
# for hand-crafted payloads).
|
||||
with pytest.raises(ValidationError) as exc_info:
|
||||
FrontendStep(
|
||||
**fe_kwargs,
|
||||
redirect_rules=[
|
||||
{
|
||||
"type": "location",
|
||||
"target": "/foo -f /tmp/x.lst",
|
||||
}
|
||||
],
|
||||
)
|
||||
msg = str(exc_info.value)
|
||||
assert "pattern-file" in msg.lower() or "-f" in msg, msg
|
||||
# `target` carrying `-f` is accepted too.
|
||||
fe = FrontendStep(
|
||||
**fe_kwargs,
|
||||
redirect_rules=[
|
||||
{
|
||||
"type": "location",
|
||||
"target": "/foo -f /tmp/x.lst",
|
||||
}
|
||||
],
|
||||
)
|
||||
assert fe.redirect_rules[0]["target"] == "/foo -f /tmp/x.lst"
|
||||
|
||||
# Clean structured dict still passes — no false positive.
|
||||
# Clean structured dict still passes.
|
||||
FrontendStep(
|
||||
**fe_kwargs,
|
||||
redirect_rules=[
|
||||
@@ -667,8 +642,8 @@ def test_user_reported_wizard_config_emits_no_false_warnings():
|
||||
zero WARNINGs from the directives we expanded.
|
||||
"""
|
||||
# Distilled from the user's bulk-site-create snapshot, minus the
|
||||
# `-f` ACL (which the new Pydantic gate rejects before this
|
||||
# validator ever runs).
|
||||
# `-f` ACL (accepted since the Issue #38 follow-up, but irrelevant
|
||||
# to the directive-expansion warnings this test pins).
|
||||
config = """# ─── Wizard candidate fragment (dry-run preview) ───
|
||||
frontend fe-site1
|
||||
bind *:80
|
||||
|
||||
@@ -0,0 +1,223 @@
|
||||
"""Regression tests for the 2026-07 security advisories.
|
||||
|
||||
Covers:
|
||||
- GHSA-7rhv-c5pc-69r8 (CRITICAL RCE): agent script-template management must
|
||||
require the agents.version permission, not merely authentication.
|
||||
- GHSA-3p5c-m5m4-mjpx (missing auth): agent data-plane endpoints must require a
|
||||
valid X-API-Key, and operator/UI endpoints must require a JWT. An anonymous
|
||||
caller must never get a 200 with sensitive data.
|
||||
|
||||
These are behavioral assertions via FastAPI's TestClient. The auth checks were
|
||||
deliberately moved ahead of any DB access, so an unauthenticated request is
|
||||
rejected without needing a database — the same approach as the existing
|
||||
test_ssl_list_endpoint_auth.py. Accepted rejection statuses are 401/403/422
|
||||
(never 200-with-data).
|
||||
"""
|
||||
import re
|
||||
import os
|
||||
import pytest
|
||||
|
||||
REJECT = (401, 403, 422)
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-3p5c: agent data-plane endpoints must reject a missing X-API-Key
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
def test_agent_config_requires_api_key(client):
|
||||
"""GET /api/agents/{name}/config leaked the full haproxy.cfg without a key."""
|
||||
res = client.get("/api/agents/prod-haproxy-1/config")
|
||||
assert res.status_code in REJECT, (
|
||||
f"GHSA-3p5c regression: agent config served without X-API-Key ({res.status_code})"
|
||||
)
|
||||
|
||||
|
||||
def test_agent_ssl_certificates_requires_api_key(client):
|
||||
"""GET /api/agents/{name}/ssl-certificates leaked SSL private keys without a key."""
|
||||
res = client.get("/api/agents/prod-haproxy-1/ssl-certificates")
|
||||
assert res.status_code in REJECT, (
|
||||
f"GHSA-3p5c regression: SSL certs (private keys!) served without X-API-Key ({res.status_code})"
|
||||
)
|
||||
if res.status_code == 200:
|
||||
assert "private_key_content" not in res.text
|
||||
|
||||
|
||||
def test_agent_upgrade_status_requires_api_key(client):
|
||||
res = client.get("/api/agents/prod-haproxy-1/upgrade-status")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_agent_pending_requests_requires_api_key(client):
|
||||
res = client.get("/api/configuration/agents/prod-haproxy-1/pending-requests")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_agent_heartbeat_by_name_requires_api_key(client):
|
||||
res = client.post("/api/agents/heartbeat", json={"name": "rogue-poc"})
|
||||
assert res.status_code in REJECT, (
|
||||
f"GHSA-3p5c regression: keyless heartbeat/auto-register accepted ({res.status_code})"
|
||||
)
|
||||
|
||||
|
||||
def test_agent_heartbeat_by_id_requires_api_key(client):
|
||||
res = client.post("/api/agents/1/heartbeat", json={"name": "spoofed"})
|
||||
assert res.status_code in REJECT, (
|
||||
f"GHSA-3p5c regression: keyless by-id heartbeat state-spoof accepted ({res.status_code})"
|
||||
)
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-3p5c: operator/UI endpoints must reject a missing JWT
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
def test_agents_inventory_requires_jwt(client):
|
||||
"""GET /api/agents (RCE read-back channel) was served without a JWT."""
|
||||
res = client.get("/api/agents")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
@pytest.mark.parametrize("path", ["/api/health/deep", "/api/health/agents", "/api/health/clusters"])
|
||||
def test_detailed_health_requires_jwt(client, path):
|
||||
res = client.get(path)
|
||||
assert res.status_code in REJECT, f"{path} served without a JWT ({res.status_code})"
|
||||
|
||||
|
||||
def test_simple_health_stays_public(client):
|
||||
"""The liveness probe endpoint (/api/health) must remain UNAUTHENTICATED.
|
||||
|
||||
It reports 200 when healthy and 503 when the DB is unreachable (as in this
|
||||
no-DB test env); what matters for the k8s probe is that it is never gated
|
||||
behind auth (401/403). We only added auth to /api/health/{deep,agents,clusters}.
|
||||
"""
|
||||
res = client.get("/api/health")
|
||||
assert res.status_code not in (401, 403), (
|
||||
f"Regression: /api/health liveness probe now requires auth ({res.status_code}) — "
|
||||
f"this breaks k8s liveness/readiness"
|
||||
)
|
||||
|
||||
|
||||
def test_dashboard_stats_requires_jwt(client):
|
||||
res = client.get("/api/dashboard-stats/stats?cluster_id=1")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_ssl_config_versions_requires_jwt(client):
|
||||
res = client.get("/api/ssl/certificates/1/config-versions")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-7rhv (CRITICAL RCE): script-template management
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
def test_script_template_write_requires_auth(client):
|
||||
"""Anonymous POST must be rejected outright."""
|
||||
res = client.post("/api/agents/script-templates/linux",
|
||||
json={"script_content": "#!/bin/bash\nid", "version": "9.9.9"})
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_script_template_read_requires_auth(client):
|
||||
res = client.get("/api/agents/script-templates/linux")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-3p5c (round 2): sibling endpoints exposing the SAME class of data
|
||||
# (found during post-merge review — must also require a JWT)
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
@pytest.mark.parametrize("path", [
|
||||
"/api/haproxy-cluster-pools/1/agents", # full agent inventory — same class as GET /api/agents
|
||||
"/api/pools",
|
||||
"/api/haproxy-cluster-pools",
|
||||
"/api/dashboard/stats",
|
||||
"/api/dashboard/overview", # optional-auth pattern — leaked stats/names/alerts anonymously
|
||||
"/api/haproxy/stats",
|
||||
"/api/waf/rules",
|
||||
"/api/health/errors",
|
||||
])
|
||||
def test_sibling_inventory_endpoints_require_jwt(client, path):
|
||||
res = client.get(path)
|
||||
assert res.status_code in REJECT, (
|
||||
f"GHSA-3p5c (round 2) regression: {path} served without a JWT ({res.status_code}) — "
|
||||
f"anonymous access to inventory/topology/WAF/error data"
|
||||
)
|
||||
|
||||
|
||||
def test_pool_agents_no_anonymous_inventory_leak(client):
|
||||
"""The richest bypass: /api/haproxy-cluster-pools/{id}/agents must not leak inventory."""
|
||||
res = client.get("/api/haproxy-cluster-pools/1/agents")
|
||||
assert res.status_code in REJECT
|
||||
if res.status_code == 200:
|
||||
assert "ip_address" not in res.text and "hostname" not in res.text
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-3p5c (round 2): agent webhooks must return 401 (not a 200 error body)
|
||||
# for anonymous callers — the auth raise must propagate, not be swallowed.
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
@pytest.mark.parametrize("path", [
|
||||
"/api/agents/some-agent/config-applied",
|
||||
"/api/agents/some-agent/config-validation-failed",
|
||||
"/api/agents/some-agent/config-sync",
|
||||
])
|
||||
def test_agent_webhooks_reject_anonymous_with_401(client, path):
|
||||
res = client.post(path, json={})
|
||||
assert res.status_code in REJECT, (
|
||||
f"{path} returned {res.status_code} for an anonymous caller — the auth "
|
||||
f"rejection must be a 401/403, not a swallowed 200 error body"
|
||||
)
|
||||
# Specifically must NOT be a 200 "status: error" body.
|
||||
assert res.status_code != 200
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# GHSA-3p5c (round 2): GET /api/agents must accept EITHER a JWT OR an agent
|
||||
# X-API-Key. Anonymous (neither) is still rejected — agents send a key, so a
|
||||
# JWT-only gate would break them (verified end-to-end in the localtest smoke).
|
||||
# --------------------------------------------------------------------------
|
||||
|
||||
def test_agents_inventory_still_rejects_fully_anonymous(client):
|
||||
"""No JWT and no X-API-Key -> 401 (the agent-key accept path needs a valid key)."""
|
||||
res = client.get("/api/agents")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_generate_uninstall_script_requires_auth(client):
|
||||
"""Agent-management endpoint must not be anonymously reachable (JWT or agent key)."""
|
||||
res = client.get("/api/agents/generate-uninstall-script/linux")
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
@pytest.mark.parametrize("path", [
|
||||
"/api/config/validate",
|
||||
"/api/config/optimize",
|
||||
"/api/config/templates/default/generate",
|
||||
])
|
||||
def test_config_compute_endpoints_require_auth(client, path):
|
||||
"""Config compute endpoints (run a HAProxy validator on caller input) were
|
||||
optional-auth; now require a JWT. The dependency rejects before body parsing."""
|
||||
res = client.post(path, json={})
|
||||
assert res.status_code in REJECT
|
||||
|
||||
|
||||
def test_script_template_write_enforces_agents_version_permission():
|
||||
"""Static guarantee: the write handler checks agents.version (not just authN).
|
||||
|
||||
A behavioral 403-for-viewer test would need a seeded DB + a minted viewer JWT;
|
||||
instead we assert the permission gate is present in source, mirroring the
|
||||
existing audit-style source tests. This is the core RCE fix (GHSA-7rhv).
|
||||
"""
|
||||
src_path = os.path.join(os.path.dirname(__file__), "..", "routers", "agent.py")
|
||||
with open(src_path, "r") as f:
|
||||
src = f.read()
|
||||
# Isolate the save_agent_script_template handler body.
|
||||
m = re.search(r"async def save_agent_script_template\(.*?\n(.*?)\n@router\.", src, re.DOTALL)
|
||||
assert m, "save_agent_script_template handler not found"
|
||||
body = m.group(1)
|
||||
assert 'check_user_permission' in body and '"agents", "version"' in body, (
|
||||
"GHSA-7rhv regression: script-template WRITE no longer enforces the "
|
||||
"agents.version permission — any JWT holder could poison the root install script"
|
||||
)
|
||||
@@ -276,14 +276,16 @@ def test_categorize_routes_directives_correctly():
|
||||
|
||||
def test_emit_buckets_flushed_in_canonical_order():
|
||||
"""The flush block at end of frontend processing must list buckets
|
||||
in: prelude → stick → tcp_req → acl → http_req → http_resp →
|
||||
in: prelude → filter → stick → tcp_req → acl → http_req → http_resp →
|
||||
redirect → use_be → default_be. Pre-fix `http-request` rules
|
||||
interleaved with `use_backend` rules in source order, producing
|
||||
HAProxy parser warnings."""
|
||||
HAProxy parser warnings. (Issue #38 added the `filter` bucket, flushed
|
||||
right after `prelude` so SPOE `filter` lines precede `send-spoe-group`.)"""
|
||||
src = _gen_src()
|
||||
flush_match = re.search(
|
||||
r'for\s+_bucket_key\s+in\s+\(\s*'
|
||||
r'"prelude"\s*,\s*'
|
||||
r'"filter"\s*,\s*'
|
||||
r'"stick"\s*,\s*'
|
||||
r'"tcp_req"\s*,\s*'
|
||||
r'"acl"\s*,\s*'
|
||||
|
||||
@@ -0,0 +1,203 @@
|
||||
"""
|
||||
Issue #38 regression tests: HAProxy SPOE `filter` + frontend `log-format` support.
|
||||
|
||||
Bug: the bulk-config parser recognised only a fixed set of frontend directives,
|
||||
so `filter spoe engine coraza config ...` and `log-format ...` were silently
|
||||
dropped on import / manual edit. This regenerated a config missing the SPOE
|
||||
engine definition, so HAProxy failed with
|
||||
"unable to find SPOE engine 'coraza' used by the send-spoe-group 'coraza-req'".
|
||||
|
||||
These tests verify the end-to-end fix without requiring a database:
|
||||
1. parser captures `filter` + `log-format` into the new ParsedFrontend fields;
|
||||
2. `http-request send-spoe-group` is still preserved (regression guard);
|
||||
3. the generator's directive categoriser + bucket flush order emit `filter`
|
||||
BEFORE the `http-request send-spoe-group` rules and keep `log-format`;
|
||||
4. reject/rollback restores the new columns;
|
||||
5. a non-SPOE frontend is completely unaffected (zero-impact).
|
||||
"""
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.dirname(os.path.abspath(__file__))))
|
||||
|
||||
from utils.haproxy_config_parser import parse_haproxy_config, ParsedFrontend
|
||||
from services.haproxy_config import _categorize_haproxy_directive
|
||||
from models.frontend import FrontendConfig
|
||||
|
||||
|
||||
# The exact frontend/backend config reported in Issue #38 (Coraza-SPOA).
|
||||
ISSUE_38_CONFIG = r"""
|
||||
frontend web-frontend
|
||||
bind *:8073
|
||||
mode http
|
||||
log-format "%ci:%cp\ [%t]\ %ft\ %b/%s\ %ST\ %B\ %{+Q}r\ %[var(txn.coraza.id)]\ waf-hit:\ %[var(txn.coraza.fail)]"
|
||||
filter spoe engine coraza config /etc/haproxy/coraza.cfg
|
||||
http-request set-var(txn.coraza.app) str(haproxy_waf)
|
||||
http-request send-spoe-group coraza coraza-req
|
||||
http-request deny if { var(txn.coraza.fail) -m int eq 1 }
|
||||
default_backend web-backend
|
||||
|
||||
backend web-backend
|
||||
balance roundrobin
|
||||
mode http
|
||||
server server1 192.168.1.10:443 weight 100 ssl verify none
|
||||
|
||||
backend coraza-spoa
|
||||
mode tcp
|
||||
option spop-check
|
||||
server coraza_spoa 192.168.12.21:9000
|
||||
"""
|
||||
|
||||
|
||||
def _get_frontend(parse_result, name):
|
||||
for fe in parse_result.frontends:
|
||||
if fe.name == name:
|
||||
return fe
|
||||
return None
|
||||
|
||||
|
||||
class TestParserCapturesSpoe:
|
||||
def test_filter_and_log_format_captured(self):
|
||||
result = parse_haproxy_config(ISSUE_38_CONFIG)
|
||||
fe = _get_frontend(result, "web-frontend")
|
||||
assert fe is not None, "web-frontend should be parsed and kept"
|
||||
assert fe.filters is not None
|
||||
assert "filter spoe engine coraza config /etc/haproxy/coraza.cfg" in fe.filters
|
||||
assert fe.log_format is not None
|
||||
assert fe.log_format.startswith("log-format")
|
||||
# the escaped/quoted format string must be preserved verbatim
|
||||
assert "%[var(txn.coraza.fail)]" in fe.log_format
|
||||
|
||||
def test_send_spoe_group_still_preserved(self):
|
||||
# Regression guard: http-request rules (incl. send-spoe-group) must
|
||||
# still be collected into request_headers as before.
|
||||
result = parse_haproxy_config(ISSUE_38_CONFIG)
|
||||
fe = _get_frontend(result, "web-frontend")
|
||||
assert fe.request_headers is not None
|
||||
assert "send-spoe-group coraza coraza-req" in fe.request_headers
|
||||
|
||||
def test_multiple_filters_preserved_in_order(self):
|
||||
cfg = """
|
||||
frontend f1
|
||||
bind *:80
|
||||
mode http
|
||||
filter compression
|
||||
filter spoe engine coraza config /etc/haproxy/coraza.cfg
|
||||
default_backend b1
|
||||
|
||||
backend b1
|
||||
mode http
|
||||
server s1 10.0.0.1:80
|
||||
"""
|
||||
fe = _get_frontend(parse_haproxy_config(cfg), "f1")
|
||||
lines = fe.filters.split("\n")
|
||||
assert lines == [
|
||||
"filter compression",
|
||||
"filter spoe engine coraza config /etc/haproxy/coraza.cfg",
|
||||
]
|
||||
|
||||
def test_log_format_sd_variant_captured(self):
|
||||
cfg = """
|
||||
frontend f1
|
||||
bind *:80
|
||||
mode http
|
||||
log-format-sd "[exampleSDID@1234 field=value]"
|
||||
default_backend b1
|
||||
|
||||
backend b1
|
||||
mode http
|
||||
server s1 10.0.0.1:80
|
||||
"""
|
||||
fe = _get_frontend(parse_haproxy_config(cfg), "f1")
|
||||
assert fe.log_format is not None
|
||||
assert fe.log_format.startswith("log-format-sd")
|
||||
|
||||
|
||||
class TestGeneratorOrderingContract:
|
||||
"""The generator routes directives into ordered buckets. Verify SPOE
|
||||
correctness at the (pure) categoriser + documented flush-order level."""
|
||||
|
||||
def test_filter_routes_to_filter_bucket(self):
|
||||
assert _categorize_haproxy_directive(" filter spoe engine coraza config /x.cfg") == "filter"
|
||||
|
||||
def test_send_spoe_group_routes_to_http_req(self):
|
||||
assert _categorize_haproxy_directive(" http-request send-spoe-group coraza coraza-req") == "http_req"
|
||||
|
||||
def test_log_format_routes_to_prelude(self):
|
||||
assert _categorize_haproxy_directive(' log-format "%ci:%cp"') == "prelude"
|
||||
assert _categorize_haproxy_directive(' log-format-sd "[x]"') == "prelude"
|
||||
|
||||
def test_flush_order_places_filter_before_http_req(self):
|
||||
# The bucket flush order is the single source of truth for emission
|
||||
# ordering. Assert `filter` is flushed before `http_req` (and after
|
||||
# `prelude`), guaranteeing `filter ...` renders before
|
||||
# `http-request send-spoe-group ...`.
|
||||
src = _read_source("services/haproxy_config.py")
|
||||
m = re.search(r"for _bucket_key in \((.*?)\):", src, re.DOTALL)
|
||||
assert m, "bucket flush loop not found"
|
||||
order = re.findall(r'"(\w+)"', m.group(1))
|
||||
assert "filter" in order, "new 'filter' bucket missing from flush order"
|
||||
assert order.index("prelude") < order.index("filter") < order.index("http_req")
|
||||
|
||||
|
||||
class TestModelAndRollback:
|
||||
def test_model_has_passthrough_fields(self):
|
||||
fc = FrontendConfig(
|
||||
name="f", bind_port=80,
|
||||
filters="filter spoe engine coraza config /etc/haproxy/coraza.cfg",
|
||||
log_format='log-format "%ci"',
|
||||
)
|
||||
assert fc.filters.startswith("filter spoe")
|
||||
assert fc.log_format.startswith("log-format")
|
||||
|
||||
def test_dataclass_defaults_none(self):
|
||||
fe = ParsedFrontend(name="f")
|
||||
assert fe.filters is None
|
||||
assert fe.log_format is None
|
||||
|
||||
def test_rollback_restores_new_columns(self):
|
||||
# Reject/rollback of a frontend UPDATE must restore the new columns,
|
||||
# otherwise the rejected (new) filters/log_format would persist.
|
||||
src = _read_source("utils/entity_snapshot.py")
|
||||
assert "log_format = $" in src
|
||||
assert "filters = $" in src
|
||||
assert "old_values.get('log_format')" in src
|
||||
assert "old_values.get('filters')" in src
|
||||
|
||||
|
||||
class TestZeroImpact:
|
||||
def test_non_spoe_frontend_unaffected(self):
|
||||
cfg = """
|
||||
frontend plain
|
||||
bind *:80
|
||||
mode http
|
||||
option httplog
|
||||
default_backend b1
|
||||
|
||||
backend b1
|
||||
mode http
|
||||
server s1 10.0.0.1:80
|
||||
"""
|
||||
fe = _get_frontend(parse_haproxy_config(cfg), "plain")
|
||||
# No filter / log-format present → new fields stay None (no behaviour change)
|
||||
assert fe.filters is None
|
||||
assert fe.log_format is None
|
||||
|
||||
def test_spop_check_backend_roundtrips_without_warning(self):
|
||||
result = parse_haproxy_config(ISSUE_38_CONFIG)
|
||||
be = next((b for b in result.backends if b.name == "coraza-spoa"), None)
|
||||
assert be is not None, "coraza-spoa backend should import"
|
||||
assert be.mode == "tcp"
|
||||
assert be.options and "option spop-check" in be.options
|
||||
# spop-check is now a known option → no spurious 'unknown option' warning
|
||||
assert not any(
|
||||
"coraza-spoa" in w and "spop-check" in w and "Unknown" in w
|
||||
for w in result.warnings
|
||||
)
|
||||
|
||||
|
||||
def _read_source(relpath):
|
||||
base = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
with open(os.path.join(base, relpath), "r", encoding="utf-8") as fh:
|
||||
return fh.read()
|
||||
@@ -0,0 +1,68 @@
|
||||
"""Unit tests for the SSRF guard (GHSA-3vh4-gvxx-wm2p).
|
||||
|
||||
The guard protects server-side fetches of ACME `directory_url` values. This
|
||||
project uses only public ACME CAs, so every non-public IP must be rejected.
|
||||
Tests avoid real network/DNS by using IP literals and scheme checks.
|
||||
"""
|
||||
import asyncio
|
||||
import pytest
|
||||
|
||||
from utils.ssrf_guard import is_public_ip, assert_public_url, SSRFValidationError
|
||||
|
||||
|
||||
# ---- is_public_ip -----------------------------------------------------------
|
||||
|
||||
@pytest.mark.parametrize("ip", [
|
||||
"8.8.8.8", "1.1.1.1", "93.184.216.34", # public
|
||||
])
|
||||
def test_public_ips_allowed(ip):
|
||||
assert is_public_ip(ip) is True
|
||||
|
||||
|
||||
@pytest.mark.parametrize("ip", [
|
||||
"127.0.0.1", # loopback
|
||||
"10.0.0.5", # RFC1918
|
||||
"172.19.0.1", # RFC1918 (the SSRF PoC docker gateway)
|
||||
"192.168.1.1", # RFC1918
|
||||
"169.254.169.254", # link-local / cloud metadata
|
||||
"0.0.0.0", # unspecified
|
||||
"::1", # IPv6 loopback
|
||||
"fe80::1", # IPv6 link-local
|
||||
"::ffff:127.0.0.1", # IPv4-mapped IPv6 loopback (R18c bypass)
|
||||
"::ffff:169.254.169.254", # IPv4-mapped metadata
|
||||
"not-an-ip", # garbage
|
||||
])
|
||||
def test_non_public_ips_rejected(ip):
|
||||
assert is_public_ip(ip) is False
|
||||
|
||||
|
||||
# ---- assert_public_url ------------------------------------------------------
|
||||
|
||||
def _raises(url):
|
||||
with pytest.raises(SSRFValidationError):
|
||||
asyncio.run(assert_public_url(url))
|
||||
|
||||
|
||||
def test_rejects_non_https_scheme():
|
||||
# The SSRF PoC used http:// against an internal listener.
|
||||
_raises("http://172.19.0.1:2121/internal-secret")
|
||||
_raises("http://8.8.8.8/") # even a public IP over http is refused
|
||||
_raises("file:///etc/passwd")
|
||||
_raises("gopher://8.8.8.8/")
|
||||
|
||||
|
||||
def test_rejects_private_ip_literals():
|
||||
_raises("https://127.0.0.1/")
|
||||
_raises("https://10.0.0.5/")
|
||||
_raises("https://169.254.169.254/latest/meta-data/")
|
||||
_raises("https://[::1]/")
|
||||
|
||||
|
||||
def test_rejects_empty_or_hostless():
|
||||
_raises("")
|
||||
_raises("https://")
|
||||
|
||||
|
||||
def test_allows_public_ip_literal_https():
|
||||
# A public IP literal over https must pass (no DNS needed).
|
||||
asyncio.run(assert_public_url("https://8.8.8.8/directory"))
|
||||
@@ -0,0 +1,71 @@
|
||||
"""v1.8.7: app version is single-source and cannot silently drift.
|
||||
|
||||
The UI shows the version via GET /api/version, which returns main.py's `_version_info`. That MUST be
|
||||
sourced from the one canonical file backend/version.json (co-located with main.py so `COPY . .`
|
||||
bakes it into every image, regardless of pipeline). main.py's in-code fallback must NOT be a real
|
||||
version, otherwise it drifts when version.json is bumped but the constant is forgotten — exactly
|
||||
what left the UI reporting 1.8.4 after 1.8.5/1.8.6 shipped. These checks fail loudly on regression.
|
||||
"""
|
||||
import ast
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
|
||||
import pytest
|
||||
|
||||
_BACKEND = os.path.dirname(os.path.dirname(os.path.abspath(__file__))) # backend/
|
||||
_VERSION_JSON = os.path.join(_BACKEND, "version.json")
|
||||
_MAIN = os.path.join(_BACKEND, "main.py")
|
||||
_SEMVER = re.compile(r"^\d+\.\d+\.\d+$")
|
||||
|
||||
|
||||
def test_canonical_version_file_exists_and_valid():
|
||||
assert os.path.exists(_VERSION_JSON), "backend/version.json (single source of truth) is missing"
|
||||
with open(_VERSION_JSON) as f:
|
||||
data = json.load(f)
|
||||
assert _SEMVER.match(data.get("version", "")), \
|
||||
f"backend/version.json version is not semver: {data.get('version')!r}"
|
||||
assert data.get("releaseName"), "backend/version.json must have a releaseName"
|
||||
|
||||
|
||||
def _main_fallback_version_info():
|
||||
"""The literal dict assigned to _version_info in main.py (the in-code fallback)."""
|
||||
with open(_MAIN) as f:
|
||||
tree = ast.parse(f.read())
|
||||
for node in ast.walk(tree):
|
||||
if isinstance(node, ast.Assign) and isinstance(node.value, ast.Dict):
|
||||
for t in node.targets:
|
||||
if isinstance(t, ast.Name) and t.id == "_version_info":
|
||||
return ast.literal_eval(node.value)
|
||||
return None
|
||||
|
||||
|
||||
def test_main_has_no_hardcoded_real_version():
|
||||
fb = _main_fallback_version_info()
|
||||
assert fb is not None, "could not find the _version_info fallback literal in main.py"
|
||||
# Must be a neutral marker, never a real version that can drift out of sync.
|
||||
assert not _SEMVER.match(str(fb.get("version", ""))), (
|
||||
f"main.py hardcodes a real version {fb.get('version')!r}; it must be a neutral marker "
|
||||
f"(e.g. 'unknown') so the version stays single-source in backend/version.json"
|
||||
)
|
||||
|
||||
|
||||
def test_main_loads_the_canonical_file_first():
|
||||
# The first candidate path main.py reads must resolve to the co-located backend/version.json,
|
||||
# so the correct version is available in every image (not dependent on CI staging).
|
||||
with open(_MAIN) as f:
|
||||
src = f.read()
|
||||
assert 'os.path.dirname(__file__), "version.json"' in src, \
|
||||
"main.py must read version.json co-located with the module (backend/version.json)"
|
||||
|
||||
|
||||
def test_frontend_package_json_matches_when_present():
|
||||
# Only meaningful in a full-repo checkout; the backend image build context (./backend) has no frontend/.
|
||||
pkg = os.path.join(os.path.dirname(_BACKEND), "frontend", "package.json")
|
||||
if not os.path.exists(pkg):
|
||||
pytest.skip("frontend/package.json not in this context (e.g. backend-only image build)")
|
||||
with open(_VERSION_JSON) as f:
|
||||
canonical = json.load(f)["version"]
|
||||
with open(pkg) as f:
|
||||
fe = json.load(f)["version"]
|
||||
assert fe == canonical, f"frontend/package.json {fe!r} != backend/version.json {canonical!r}"
|
||||
@@ -470,7 +470,12 @@ safe_remove() {
|
||||
[[ "$QUIET_MODE" != "true" ]] && echo "Terminating existing HAProxy Agent processes..."
|
||||
KILLED_COUNT=0
|
||||
INSTALLER_PID=$$
|
||||
for pattern in "haproxy-agent" "/usr/local/bin/haproxy-agent" "haproxy-agent.service"; do
|
||||
# issue #31: match ONLY the installed agent (binary path + service), never the bare string
|
||||
# "haproxy-agent". With pgrep -f, that bare string can also match the installer's OWN command line
|
||||
# or a sudo/PAM ancestor (which the $$/$PPID guard does not fully cover), making the cleanup kill
|
||||
# the installer itself ("Killed", install aborts). The systemd service is also stopped below; the
|
||||
# "$INSTALL_DIR/haproxy-agent" path still catches any running daemon.
|
||||
for pattern in "$INSTALL_DIR/haproxy-agent" "haproxy-agent.service"; do
|
||||
PIDS=$(pgrep -f "$pattern" 2>/dev/null || true)
|
||||
if [[ -n "$PIDS" ]]; then
|
||||
FILTERED=""
|
||||
@@ -1055,7 +1060,12 @@ register_agent() {
|
||||
local arch=$(uname -m)
|
||||
platform=$(uname -s | tr '[:upper:]' '[:lower:]') # Remove local to make it global
|
||||
local system_info=$(collect_system_info)
|
||||
|
||||
# issue #31: if collect_system_info produced no JSON content (empty on an unusual host), the
|
||||
# '$system_info,' line below would collapse to a bare comma and break the heartbeat JSON. A
|
||||
# valid fragment always contains a quoted key; if none is present, fall back to one. The glob
|
||||
# '*"*' is the most portable bash test (no POSIX class / pattern-substitution), safe on bash 3.x+.
|
||||
[[ "$system_info" != *'"'* ]] && system_info='"operating_system": "unknown"'
|
||||
|
||||
local json_payload=$(cat <<SIMPLE_EOF
|
||||
{
|
||||
"name": "$AGENT_NAME",
|
||||
@@ -1357,7 +1367,12 @@ send_heartbeat() {
|
||||
local server_statuses=$(get_server_statuses)
|
||||
local haproxy_stats_csv=$(get_haproxy_stats_csv)
|
||||
local system_info=$(collect_system_info)
|
||||
|
||||
# issue #31: if collect_system_info produced no JSON content (empty on an unusual host), the
|
||||
# '$system_info,' line below would collapse to a bare comma and break the heartbeat JSON. A
|
||||
# valid fragment always contains a quoted key; if none is present, fall back to one. The glob
|
||||
# '*"*' is the most portable bash test (no POSIX class / pattern-substitution), safe on bash 3.x+.
|
||||
[[ "$system_info" != *'"'* ]] && system_info='"operating_system": "unknown"'
|
||||
|
||||
# Get HAProxy version for heartbeat (safe extraction, fallback to "unknown")
|
||||
local haproxy_version="unknown"
|
||||
if command -v haproxy &> /dev/null; then
|
||||
|
||||
@@ -318,7 +318,11 @@ safe_remove() {
|
||||
[[ "$QUIET_MODE" != "true" ]] && echo "Terminating existing HAProxy Agent processes..."
|
||||
KILLED_COUNT=0
|
||||
INSTALLER_PID=$$
|
||||
for pattern in "haproxy-agent" "/usr/local/bin/haproxy-agent" "com.haproxy.agent"; do
|
||||
# issue #31: match ONLY the installed agent (binary path + LaunchDaemon label), never the bare
|
||||
# string "haproxy-agent". With pgrep -f, that bare string can also match the installer's OWN command
|
||||
# line or a sudo ancestor (which the $$/$PPID guard does not fully cover), making the cleanup kill
|
||||
# the installer itself. The "$INSTALL_DIR/haproxy-agent" path still catches any running daemon.
|
||||
for pattern in "$INSTALL_DIR/haproxy-agent" "com.haproxy.agent"; do
|
||||
PIDS=$(pgrep -f "$pattern" 2>/dev/null || true)
|
||||
if [[ -n "$PIDS" ]]; then
|
||||
FILTERED=""
|
||||
@@ -920,7 +924,12 @@ register_agent() {
|
||||
local arch=$(uname -m)
|
||||
platform=$(uname -s | tr '[:upper:]' '[:lower:]') # Remove local to make it global
|
||||
local system_info=$(collect_system_info)
|
||||
|
||||
# issue #31: if collect_system_info produced no JSON content (empty on an unusual host), the
|
||||
# '$system_info,' line below would collapse to a bare comma and break the heartbeat JSON. A
|
||||
# valid fragment always contains a quoted key; if none is present, fall back to one. The glob
|
||||
# '*"*' is the most portable bash test (no POSIX class / pattern-substitution), safe on bash 3.x+.
|
||||
[[ "$system_info" != *'"'* ]] && system_info='"operating_system": "unknown"'
|
||||
|
||||
local json_payload=$(cat <<SIMPLE_EOF
|
||||
{
|
||||
"name": "$AGENT_NAME",
|
||||
@@ -1191,7 +1200,12 @@ send_heartbeat() {
|
||||
local server_statuses=$(get_server_statuses)
|
||||
local haproxy_stats_csv=$(get_haproxy_stats_csv)
|
||||
local system_info=$(collect_system_info)
|
||||
|
||||
# issue #31: if collect_system_info produced no JSON content (empty on an unusual host), the
|
||||
# '$system_info,' line below would collapse to a bare comma and break the heartbeat JSON. A
|
||||
# valid fragment always contains a quoted key; if none is present, fall back to one. The glob
|
||||
# '*"*' is the most portable bash test (no POSIX class / pattern-substitution), safe on bash 3.x+.
|
||||
[[ "$system_info" != *'"'* ]] && system_info='"operating_system": "unknown"'
|
||||
|
||||
# Get HAProxy version for heartbeat (safe extraction, fallback to "unknown")
|
||||
local haproxy_version="unknown"
|
||||
if command -v haproxy &> /dev/null; then
|
||||
|
||||
@@ -0,0 +1,120 @@
|
||||
"""Issue #53 — at-rest encryption for the pending CSR private key (v1.10.1).
|
||||
|
||||
Mirrors the established Fernet + HKDF(SECRET_KEY) pattern already used for the VRRP secret
|
||||
(services/keepalived_config.py), TOTP secrets (services/mfa_service.py) and DNS provider
|
||||
credentials (utils/dns_credentials.py): prefer an explicit CSR_ENCRYPTION_KEY env var (enables
|
||||
key rotation), else derive a stable key from SECRET_KEY via HKDF with its own versioned info
|
||||
string, so a rotation of one secret class never affects another.
|
||||
|
||||
WHY this key and not every key in the system: the CSR private key is the one key that sits IDLE.
|
||||
It is generated at CSR creation, waits for an external CA to sign the request (days to weeks),
|
||||
and is destroyed the moment the signed certificate is imported — it is never transmitted to an
|
||||
agent and never leaves the server. `ssl_certificates.private_key_content` and the ACME order keys
|
||||
are different: agents must receive them in plaintext on every poll, so encrypting them at rest
|
||||
buys nothing without an end-to-end redesign.
|
||||
|
||||
STORAGE: the Fernet token replaces the PEM in the SAME `ssl_csrs.private_key_pem` TEXT column.
|
||||
No new column, no new table, and deliberately NO `SCHEMA_VERSION` bump — a bump would re-run the
|
||||
migration sequence and re-seed the four built-in roles to their defaults (see UPGRADE_GUIDE.md),
|
||||
which is a needless side effect for a storage-format change.
|
||||
|
||||
BACKWARD COMPATIBILITY: rows written before this release hold a raw PEM. `decrypt_csr_private_key`
|
||||
detects those by their `-----BEGIN` header and returns them unchanged. The discriminator is exact,
|
||||
not a heuristic: a Fernet token is base64url text and can never contain "-----". Legacy rows drain
|
||||
naturally, since a CSR's key copy is NULLed on import.
|
||||
|
||||
KEY ROTATION: if SECRET_KEY rotates while CSR_ENCRYPTION_KEY is unset, previously stored keys
|
||||
become undecryptable and `decrypt_csr_private_key` returns None. Callers MUST surface a clear
|
||||
"delete this CSR and create a new one" error — the CSR is unusable at that point, because the
|
||||
signed certificate can no longer be paired with its key.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import base64
|
||||
import logging
|
||||
import os
|
||||
from typing import Optional
|
||||
|
||||
from cryptography.fernet import Fernet, InvalidToken
|
||||
from cryptography.hazmat.primitives import hashes
|
||||
from cryptography.hazmat.primitives.kdf.hkdf import HKDF
|
||||
|
||||
from config import SECRET_KEY
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# A PEM private key always carries this header; a Fernet token is base64url and never can.
|
||||
_PEM_MARKER = "-----BEGIN"
|
||||
|
||||
_fernet_instance: Optional[Fernet] = None
|
||||
|
||||
|
||||
def _resolve_fernet_key() -> bytes:
|
||||
"""Prefer an explicit CSR_ENCRYPTION_KEY; else derive from SECRET_KEY via HKDF with a
|
||||
versioned info string (so stored keys survive restarts)."""
|
||||
explicit = os.getenv("CSR_ENCRYPTION_KEY", "").strip()
|
||||
if explicit:
|
||||
try:
|
||||
Fernet(explicit.encode())
|
||||
return explicit.encode()
|
||||
except Exception as exc: # noqa: BLE001
|
||||
logger.error("CSR_ENCRYPTION_KEY env var present but invalid: %s", exc)
|
||||
logger.warning(
|
||||
"CSR_ENCRYPTION_KEY not set; deriving the CSR private-key encryption key from SECRET_KEY. "
|
||||
"Set CSR_ENCRYPTION_KEY to a Fernet key to enable key rotation."
|
||||
)
|
||||
hkdf = HKDF(algorithm=hashes.SHA256(), length=32, salt=None, info=b"csr-private-key-v1")
|
||||
derived = hkdf.derive(SECRET_KEY.encode("utf-8"))
|
||||
return base64.urlsafe_b64encode(derived)
|
||||
|
||||
|
||||
def _get_fernet() -> Fernet:
|
||||
global _fernet_instance
|
||||
if _fernet_instance is None:
|
||||
_fernet_instance = Fernet(_resolve_fernet_key())
|
||||
return _fernet_instance
|
||||
|
||||
|
||||
def reset_fernet_for_tests() -> None:
|
||||
"""Test-only hook to force re-resolution after env mutation."""
|
||||
global _fernet_instance
|
||||
_fernet_instance = None
|
||||
|
||||
|
||||
def is_encrypted(stored: Optional[str]) -> bool:
|
||||
"""True when the stored value is a Fernet token rather than a legacy raw PEM.
|
||||
|
||||
Single source of the format discriminator: `decrypt_csr_private_key` branches on this, so
|
||||
the "what does a stored value look like" rule is stated exactly once.
|
||||
"""
|
||||
return bool(stored) and _PEM_MARKER not in stored
|
||||
|
||||
|
||||
def encrypt_csr_private_key(pem: str) -> str:
|
||||
"""Fernet-encrypt a PEM private key to a storable token string."""
|
||||
return _get_fernet().encrypt(pem.encode("utf-8")).decode("utf-8")
|
||||
|
||||
|
||||
def decrypt_csr_private_key(stored: Optional[str]) -> Optional[str]:
|
||||
"""Return the PEM private key for a stored value.
|
||||
|
||||
Accepts BOTH shapes so an upgrade needs no data migration:
|
||||
- a raw PEM written before v1.10.1 -> returned unchanged
|
||||
- a Fernet token -> decrypted
|
||||
|
||||
Returns None when the value is empty or cannot be decrypted (e.g. SECRET_KEY rotated without
|
||||
CSR_ENCRYPTION_KEY). Callers MUST treat None as "this CSR's key is unrecoverable" and tell the
|
||||
operator to delete it and create a new one; never fall through to a pairing attempt.
|
||||
"""
|
||||
if not stored:
|
||||
return None
|
||||
if not is_encrypted(stored):
|
||||
return stored # legacy plaintext row, pre-v1.10.1
|
||||
try:
|
||||
return _get_fernet().decrypt(stored.encode("utf-8")).decode("utf-8")
|
||||
except InvalidToken:
|
||||
logger.warning("Failed to decrypt a stored CSR private key (invalid Fernet token)")
|
||||
return None
|
||||
except Exception as exc: # noqa: BLE001
|
||||
logger.error("Unexpected error decrypting a stored CSR private key: %s", exc)
|
||||
return None
|
||||
@@ -329,9 +329,10 @@ async def _rollback_update(
|
||||
tcp_request_rules = $26, timeout_client = $27, timeout_http_request = $28,
|
||||
rate_limit = $29, compression = $30, log_separate = $31,
|
||||
monitor_uri = $32, maxconn = $33,
|
||||
cluster_id = $34, is_active = $35, last_config_status = $36,
|
||||
cluster_id = $34, is_active = $35, last_config_status = $36,
|
||||
log_format = $37, filters = $38,
|
||||
updated_at = CURRENT_TIMESTAMP
|
||||
WHERE id = $37
|
||||
WHERE id = $39
|
||||
""",
|
||||
old_values.get('name'),
|
||||
old_values.get('bind_address'),
|
||||
@@ -369,6 +370,8 @@ async def _rollback_update(
|
||||
old_values.get('cluster_id'),
|
||||
old_values.get('is_active'),
|
||||
old_values.get('last_config_status'),
|
||||
old_values.get('log_format'), # Issue #38
|
||||
old_values.get('filters'), # Issue #38
|
||||
entity_id
|
||||
)
|
||||
|
||||
|
||||
@@ -105,6 +105,11 @@ class ParsedFrontend:
|
||||
response_headers: Optional[str] = None
|
||||
options: Optional[str] = None # HAProxy frontend options (option httplog, option forwardfor, etc.)
|
||||
tcp_request_rules: Optional[str] = None # TCP request directives (for TCP mode)
|
||||
# Issue #38: SPOE (and other) filter directives + frontend log-format.
|
||||
# Stored as full directive lines; `filters` is newline-joined to preserve
|
||||
# ordering when multiple `filter ...` lines exist.
|
||||
log_format: Optional[str] = None # `log-format` / `log-format-sd` line(s)
|
||||
filters: Optional[str] = None # `filter ...` line(s), e.g. `filter spoe engine coraza config ...`
|
||||
|
||||
|
||||
@dataclass
|
||||
@@ -256,8 +261,23 @@ class HAProxyConfigParser:
|
||||
acl_rules_list = []
|
||||
use_backend_rules_list = []
|
||||
tcp_request_rules_list = []
|
||||
filters_list = []
|
||||
log_format_list = []
|
||||
|
||||
for line in lines:
|
||||
# Issue #38: capture `filter ...` (SPOE/Coraza etc.) and
|
||||
# `log-format`/`log-format-sd` directives. Pre-fix these matched
|
||||
# no branch below and were silently dropped, so an imported SPOE
|
||||
# config lost `filter spoe engine coraza ...` (→ HAProxy fatal
|
||||
# "unable to find SPOE engine") and the frontend log-format.
|
||||
# `continue` isolates them from the header/option handling below.
|
||||
if line.startswith('filter '):
|
||||
filters_list.append(line.strip())
|
||||
continue
|
||||
if re.match(r'^log-format(-sd)?\s', line, re.IGNORECASE):
|
||||
log_format_list.append(line.strip())
|
||||
continue
|
||||
|
||||
# Parse bind directive
|
||||
# IMPORTANT: Handle multiple bind lines correctly
|
||||
# Example: bind *:1002 (HTTP) and bind *:443 ssl (HTTPS)
|
||||
@@ -540,6 +560,13 @@ class HAProxyConfigParser:
|
||||
if tcp_request_rules_list:
|
||||
frontend.tcp_request_rules = '\n'.join(tcp_request_rules_list)
|
||||
|
||||
# Issue #38: assign captured SPOE filters + log-format
|
||||
if filters_list:
|
||||
frontend.filters = '\n'.join(filters_list)
|
||||
|
||||
if log_format_list:
|
||||
frontend.log_format = '\n'.join(log_format_list)
|
||||
|
||||
self.frontends.append(frontend)
|
||||
logger.info(f"Parsed frontend: {name} -> {frontend.default_backend}")
|
||||
|
||||
@@ -666,9 +693,14 @@ class HAProxyConfigParser:
|
||||
'transparent', 'abortonclose', 'allbackups', 'checkcache', 'clitcpka',
|
||||
'srvtcpka', 'http-no-delay', 'socket-stats', 'tcp-smart-accept',
|
||||
'tcp-smart-connect', 'independant-streams', 'log-separate-errors',
|
||||
'log-health-checks', 'accept-invalid-http-request', 'accept-invalid-http-response'
|
||||
'log-health-checks', 'accept-invalid-http-request', 'accept-invalid-http-response',
|
||||
# Issue #38: SPOP health check for SPOE agent backends
|
||||
# (e.g. coraza-spoa). Already collected below regardless, but
|
||||
# listing it suppresses the spurious "unknown option" warning
|
||||
# for the exact SPOE use-case.
|
||||
'spop-check'
|
||||
]
|
||||
|
||||
|
||||
if option_name not in valid_options:
|
||||
# Unknown/invalid option - add warning but still collect it
|
||||
self.warnings.append(
|
||||
|
||||
@@ -0,0 +1,116 @@
|
||||
"""
|
||||
SSRF guard for outbound HTTP fetches to user/DB-controlled URLs.
|
||||
|
||||
GHSA-3vh4-gvxx-wm2p: the ACME `directory_url` was fetched server-side with no
|
||||
validation, turning the backend into a request-forwarding primitive against
|
||||
loopback / RFC1918 / link-local / cloud-metadata IP space (and reflecting the
|
||||
upstream JSON keys back to the caller).
|
||||
|
||||
The classification logic mirrors the hardened ACME diagnostics probe
|
||||
(services/acme_diagnostics.py, R18b/R18c audits): unwrap IPv4-mapped IPv6, reject
|
||||
loopback/link-local/private/multicast/reserved/unspecified, resolve DNS off the
|
||||
event loop, and pin the aiohttp connector to IPv4 so the family the guard
|
||||
classifies equals the family the connector dials (no dual-stack AAAA bypass).
|
||||
|
||||
Deployment note: this project uses ONLY public ACME CAs (e.g. Let's Encrypt), so
|
||||
every non-public IP is rejected — there is no internal/private-IP CA to allow.
|
||||
Residual: DNS rebinding between validate-time and fetch-time is not fully closed
|
||||
(fetching by hostname keeps TLS cert validation working); the IPv4 pin +
|
||||
https-only + admin-gating + internal-only exposure keep this residual low.
|
||||
"""
|
||||
import asyncio
|
||||
import ipaddress
|
||||
import socket
|
||||
from typing import List
|
||||
from urllib.parse import urlparse
|
||||
|
||||
import aiohttp
|
||||
|
||||
# Only https is legitimate for a public ACME directory URL.
|
||||
_ALLOWED_SCHEMES = {"https"}
|
||||
|
||||
|
||||
class SSRFValidationError(ValueError):
|
||||
"""Raised when a URL fails SSRF validation (bad scheme or non-public host)."""
|
||||
|
||||
|
||||
def is_public_ip(ip_str: str) -> bool:
|
||||
"""Return True only for globally-routable IPv4/IPv6 addresses.
|
||||
|
||||
Unwraps IPv4-mapped IPv6 (``::ffff:127.0.0.1``) before classification so an
|
||||
attacker-controlled AAAA record cannot smuggle loopback/metadata through the
|
||||
IPv6 checks.
|
||||
"""
|
||||
try:
|
||||
ip = ipaddress.ip_address(ip_str)
|
||||
except (ValueError, TypeError):
|
||||
return False
|
||||
if isinstance(ip, ipaddress.IPv6Address) and ip.ipv4_mapped is not None:
|
||||
ip = ip.ipv4_mapped
|
||||
if ip.is_loopback or ip.is_link_local or ip.is_private:
|
||||
return False
|
||||
if ip.is_multicast or ip.is_reserved or ip.is_unspecified:
|
||||
return False
|
||||
return True
|
||||
|
||||
|
||||
async def _resolve_ips(host: str, *, timeout: float = 5.0) -> List[str]:
|
||||
"""Resolve `host` to IPv4 addresses without blocking the event loop."""
|
||||
loop = asyncio.get_running_loop()
|
||||
_, _, ips = await asyncio.wait_for(
|
||||
loop.run_in_executor(None, socket.gethostbyname_ex, host),
|
||||
timeout=timeout,
|
||||
)
|
||||
return ips or []
|
||||
|
||||
|
||||
async def assert_public_url(url: str, *, timeout: float = 5.0) -> None:
|
||||
"""Validate that `url` is safe to fetch server-side.
|
||||
|
||||
Requirements: https scheme, and a host that either is a public IP literal or
|
||||
resolves entirely to public IPv4 addresses. Raises ``SSRFValidationError``
|
||||
otherwise. Intended to be called immediately before the outbound request,
|
||||
which MUST use ``safe_connector()`` and ``allow_redirects=False``.
|
||||
"""
|
||||
if not url or not isinstance(url, str):
|
||||
raise SSRFValidationError("A URL is required")
|
||||
parsed = urlparse(url.strip())
|
||||
if parsed.scheme.lower() not in _ALLOWED_SCHEMES:
|
||||
raise SSRFValidationError(f"URL scheme must be https (got '{parsed.scheme or 'none'}')")
|
||||
host = parsed.hostname
|
||||
if not host:
|
||||
raise SSRFValidationError("URL has no host")
|
||||
|
||||
# Literal IP host: classify directly, no DNS needed.
|
||||
try:
|
||||
ipaddress.ip_address(host)
|
||||
if not is_public_ip(host):
|
||||
raise SSRFValidationError(f"URL host {host} is not a public IP address")
|
||||
return
|
||||
except ValueError:
|
||||
pass # hostname, not an IP literal -> resolve below
|
||||
|
||||
try:
|
||||
ips = await _resolve_ips(host, timeout=timeout)
|
||||
except asyncio.TimeoutError:
|
||||
raise SSRFValidationError(f"DNS resolution timed out for {host}")
|
||||
except Exception as e: # socket.gaierror etc.
|
||||
raise SSRFValidationError(f"DNS resolution failed for {host}: {e}")
|
||||
|
||||
if not ips:
|
||||
raise SSRFValidationError(f"{host} did not resolve to any address")
|
||||
if not all(is_public_ip(ip) for ip in ips):
|
||||
raise SSRFValidationError(
|
||||
f"{host} resolves to a non-public IP {ips} — refusing to fetch (SSRF guard)"
|
||||
)
|
||||
|
||||
|
||||
def safe_connector() -> aiohttp.TCPConnector:
|
||||
"""IPv4-pinned aiohttp connector.
|
||||
|
||||
Forces the connect family to match what :func:`assert_public_url` classified
|
||||
(closes the dual-stack AAAA bypass). TLS verification stays ON (default), so
|
||||
the request must target the validated hostname. Always combine with
|
||||
``allow_redirects=False`` at the request call site.
|
||||
"""
|
||||
return aiohttp.TCPConnector(family=socket.AF_INET)
|
||||
@@ -0,0 +1,5 @@
|
||||
{
|
||||
"version": "1.10.1",
|
||||
"releaseName": "CSR private key encrypted at rest",
|
||||
"releaseDate": "2026-08-08"
|
||||
}
|
||||
@@ -10,7 +10,6 @@ services:
|
||||
dockerfile: Dockerfile
|
||||
volumes:
|
||||
- haproxy_configs:/etc/haproxy
|
||||
- ./version.json:/app/version.json:ro
|
||||
|
||||
frontend:
|
||||
image: haproxy-openmanager-frontend:localtest
|
||||
|
||||
+4
-1
@@ -22,7 +22,7 @@ services:
|
||||
|
||||
# Redis Cache
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
image: redis:8.8.0-alpine
|
||||
container_name: haproxy-openmanager-redis
|
||||
command: redis-server --maxmemory 2gb --maxmemory-policy volatile-lru --save ""
|
||||
ports:
|
||||
@@ -51,6 +51,9 @@ services:
|
||||
- LOG_LEVEL=INFO
|
||||
- PUBLIC_URL=http://localhost:8080
|
||||
- MANAGEMENT_BASE_URL=http://localhost:8080
|
||||
# Empty when unset on the host: the image CMD then falls back to
|
||||
# WEB_CONCURRENCY (uvicorn's native env) and finally to 1.
|
||||
- UVICORN_WORKERS=${UVICORN_WORKERS:-}
|
||||
volumes:
|
||||
- haproxy_configs:/etc/haproxy
|
||||
expose:
|
||||
|
||||
Generated
+181
-145
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"name": "haproxy-openmanager-frontend",
|
||||
"version": "1.7.8",
|
||||
"version": "1.9.0",
|
||||
"lockfileVersion": 3,
|
||||
"requires": true,
|
||||
"packages": {
|
||||
"": {
|
||||
"name": "haproxy-openmanager-frontend",
|
||||
"version": "1.7.8",
|
||||
"version": "1.9.0",
|
||||
"license": "AGPL-3.0-or-later",
|
||||
"dependencies": {
|
||||
"@ant-design/icons": "^5.0.0",
|
||||
@@ -20,7 +20,7 @@
|
||||
"react": "^18.2.0",
|
||||
"react-ace": "^10.1.0",
|
||||
"react-dom": "^18.2.0",
|
||||
"react-router-dom": "^6.8.0",
|
||||
"react-router-dom": "^6.30.4",
|
||||
"react-window": "^1.8.10",
|
||||
"react18-json-view": "^0.2.9",
|
||||
"recharts": "^2.5.0"
|
||||
@@ -179,18 +179,18 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/core": {
|
||||
"version": "7.29.0",
|
||||
"resolved": "https://registry.npmjs.org/@babel/core/-/core-7.29.0.tgz",
|
||||
"integrity": "sha512-CGOfOJqWjg2qW/Mb6zNsDm+u5vFQ8DxXfbM09z69p5Z6+mE1ikP2jUXw+j42Pf1XTYED2Rni5f95npYeuwMDQA==",
|
||||
"version": "7.29.6",
|
||||
"resolved": "https://registry.npmjs.org/@babel/core/-/core-7.29.6.tgz",
|
||||
"integrity": "sha512-QdxmAo/ikZqqRGA8s43ww8lcql6naWRvEz0FFrl6MIlc7Gi6TroXnSdWa5U/kq6fzcpqpHesicQxFZIieZbyIA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@babel/code-frame": "^7.29.0",
|
||||
"@babel/generator": "^7.29.0",
|
||||
"@babel/generator": "^7.29.6",
|
||||
"@babel/helper-compilation-targets": "^7.28.6",
|
||||
"@babel/helper-module-transforms": "^7.28.6",
|
||||
"@babel/helpers": "^7.28.6",
|
||||
"@babel/parser": "^7.29.0",
|
||||
"@babel/helpers": "^7.29.2",
|
||||
"@babel/parser": "^7.29.3",
|
||||
"@babel/template": "^7.28.6",
|
||||
"@babel/traverse": "^7.29.0",
|
||||
"@babel/types": "^7.29.0",
|
||||
@@ -239,14 +239,14 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/generator": {
|
||||
"version": "7.29.1",
|
||||
"resolved": "https://registry.npmjs.org/@babel/generator/-/generator-7.29.1.tgz",
|
||||
"integrity": "sha512-qsaF+9Qcm2Qv8SRIMMscAvG4O3lJ0F1GuMo5HR/Bp02LopNgnZBC/EkbevHFeGs4ls/oPz9v+Bsmzbkbe+0dUw==",
|
||||
"version": "7.29.7",
|
||||
"resolved": "https://registry.npmjs.org/@babel/generator/-/generator-7.29.7.tgz",
|
||||
"integrity": "sha512-DkXD5OJQaAQIdZ1bt3UZdEnHAn9Imd3IVBdX03UFe+ony9Ojw5pzr9YVKGDY1jt+Gcn/FnGkNf8r+Vj5NOJWtQ==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@babel/parser": "^7.29.0",
|
||||
"@babel/types": "^7.29.0",
|
||||
"@babel/parser": "^7.29.7",
|
||||
"@babel/types": "^7.29.7",
|
||||
"@jridgewell/gen-mapping": "^0.3.12",
|
||||
"@jridgewell/trace-mapping": "^0.3.28",
|
||||
"jsesc": "^3.0.2"
|
||||
@@ -472,9 +472,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/helper-string-parser": {
|
||||
"version": "7.27.1",
|
||||
"resolved": "https://registry.npmjs.org/@babel/helper-string-parser/-/helper-string-parser-7.27.1.tgz",
|
||||
"integrity": "sha512-qMlSxKbpRlAridDExk92nSobyDdpPijUq2DW6oDnUqd0iOGxmQjyqhMIihI9+zv4LPyZdRje2cavWPbCbWm3eA==",
|
||||
"version": "7.29.7",
|
||||
"resolved": "https://registry.npmjs.org/@babel/helper-string-parser/-/helper-string-parser-7.29.7.tgz",
|
||||
"integrity": "sha512-Pb5ijPrZ89GDH8223L4UP8i6QApWxs04RbPQJTeWDV0/keR2E36MeKnyr6LYmUUvqRRI+Iv87SuF1W6ErINzYw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
@@ -482,9 +482,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/helper-validator-identifier": {
|
||||
"version": "7.28.5",
|
||||
"resolved": "https://registry.npmjs.org/@babel/helper-validator-identifier/-/helper-validator-identifier-7.28.5.tgz",
|
||||
"integrity": "sha512-qSs4ifwzKJSV39ucNjsvc6WVHs6b7S03sOh2OcHF9UHfVPqWWALUsNUVzhSBiItjRZoLHx7nIarVjqKVusUZ1Q==",
|
||||
"version": "7.29.7",
|
||||
"resolved": "https://registry.npmjs.org/@babel/helper-validator-identifier/-/helper-validator-identifier-7.29.7.tgz",
|
||||
"integrity": "sha512-qehxGkRj55h/ff8EMaJ+cYhyaKlHIxqYDn682wQD7RNp9UujOQsHog2uS0r2vzr4pW+sXf90NeeayjcNaX3fFg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
@@ -531,13 +531,13 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/parser": {
|
||||
"version": "7.29.2",
|
||||
"resolved": "https://registry.npmjs.org/@babel/parser/-/parser-7.29.2.tgz",
|
||||
"integrity": "sha512-4GgRzy/+fsBa72/RZVJmGKPmZu9Byn8o4MoLpmNe1m8ZfYnz5emHLQz3U4gLud6Zwl0RZIcgiLD7Uq7ySFuDLA==",
|
||||
"version": "7.29.7",
|
||||
"resolved": "https://registry.npmjs.org/@babel/parser/-/parser-7.29.7.tgz",
|
||||
"integrity": "sha512-hnORnjP/1P/zFEndoeX+n+t1RwWRJiJpM/jO7FW32Kn9r5+sJB2JWOdYo4L6k78j15eCwY3Gm/7364B1EMwtNg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@babel/types": "^7.29.0"
|
||||
"@babel/types": "^7.29.7"
|
||||
},
|
||||
"bin": {
|
||||
"parser": "bin/babel-parser.js"
|
||||
@@ -2274,14 +2274,14 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@babel/types": {
|
||||
"version": "7.29.0",
|
||||
"resolved": "https://registry.npmjs.org/@babel/types/-/types-7.29.0.tgz",
|
||||
"integrity": "sha512-LwdZHpScM4Qz8Xw2iKSzS+cfglZzJGvofQICy7W7v4caru4EaAmyUuO6BGrbyQ2mYV11W0U8j5mBhd14dd3B0A==",
|
||||
"version": "7.29.7",
|
||||
"resolved": "https://registry.npmjs.org/@babel/types/-/types-7.29.7.tgz",
|
||||
"integrity": "sha512-4zBIxpPzowiZpusoFkyGVwakdRJUyuH5PxQ/PrqghfdFWWasvnCdPfQXHrenDai+gyLARulZjZowCOj6fjT4pA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@babel/helper-string-parser": "^7.27.1",
|
||||
"@babel/helper-validator-identifier": "^7.28.5"
|
||||
"@babel/helper-string-parser": "^7.29.7",
|
||||
"@babel/helper-validator-identifier": "^7.29.7"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=6.9.0"
|
||||
@@ -2669,10 +2669,20 @@
|
||||
"license": "Python-2.0"
|
||||
},
|
||||
"node_modules/@eslint/eslintrc/node_modules/js-yaml": {
|
||||
"version": "4.1.1",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz",
|
||||
"integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==",
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/nodeca"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1"
|
||||
@@ -2756,6 +2766,20 @@
|
||||
"node": ">=6"
|
||||
}
|
||||
},
|
||||
"node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml": {
|
||||
"version": "3.15.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.0.tgz",
|
||||
"integrity": "sha512-ttBQIIQPDeLjpPOohtUdXuXUVoA2uIB6fEH9HyJ7234s5mBJ5wTx20njxplLZQgLaOfpmPQA7X2t5AX6tIPbog==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^1.0.7",
|
||||
"esprima": "^4.0.0"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
}
|
||||
},
|
||||
"node_modules/@istanbuljs/schema": {
|
||||
"version": "0.1.3",
|
||||
"resolved": "https://registry.npmjs.org/@istanbuljs/schema/-/schema-0.1.3.tgz",
|
||||
@@ -4260,9 +4284,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@remix-run/router": {
|
||||
"version": "1.23.2",
|
||||
"resolved": "https://registry.npmjs.org/@remix-run/router/-/router-1.23.2.tgz",
|
||||
"integrity": "sha512-Ic6m2U/rMjTkhERIa/0ZtXJP17QUi2CbWE7cqx4J58M8aA3QTfW+2UlQ4psvTX9IO1RfNVhK3pcpdjej7L+t2w==",
|
||||
"version": "1.23.3",
|
||||
"resolved": "https://registry.npmjs.org/@remix-run/router/-/router-1.23.3.tgz",
|
||||
"integrity": "sha512-4An71tdz9X8+3sI4Qqqd2LWd9vS39J7sqd9EU4Scw7TJE/qB10Flv/UuqbPVgfQV9XoK8Np6jNquZitnZq5i+Q==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=14.0.0"
|
||||
@@ -4654,6 +4678,27 @@
|
||||
"url": "https://github.com/sponsors/gregberge"
|
||||
}
|
||||
},
|
||||
"node_modules/@testing-library/dom": {
|
||||
"version": "10.4.1",
|
||||
"resolved": "https://registry.npmjs.org/@testing-library/dom/-/dom-10.4.1.tgz",
|
||||
"integrity": "sha512-o4PXJQidqJl82ckFaXUeoAW+XysPLauYI43Abki5hABd853iMhitooc6znOnczgbTYmEP6U6/y1ZyKAIsvMKGg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"peer": true,
|
||||
"dependencies": {
|
||||
"@babel/code-frame": "^7.10.4",
|
||||
"@babel/runtime": "^7.12.5",
|
||||
"@types/aria-query": "^5.0.1",
|
||||
"aria-query": "5.3.0",
|
||||
"dom-accessibility-api": "^0.5.9",
|
||||
"lz-string": "^1.5.0",
|
||||
"picocolors": "1.1.1",
|
||||
"pretty-format": "^27.0.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18"
|
||||
}
|
||||
},
|
||||
"node_modules/@testing-library/jest-dom": {
|
||||
"version": "5.17.0",
|
||||
"resolved": "https://registry.npmjs.org/@testing-library/jest-dom/-/jest-dom-5.17.0.tgz",
|
||||
@@ -6534,6 +6579,22 @@
|
||||
"proxy-from-env": "^2.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/axios/node_modules/form-data": {
|
||||
"version": "4.0.6",
|
||||
"resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.6.tgz",
|
||||
"integrity": "sha512-vKatAh4SlVfgbv+YtmhiRjhEMJsYpsG1Y2rMQtR+SVSbytsSD1YGzDIcrAJmdFec88u/+VoGmxnl+80gL1tRCQ==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"asynckit": "^0.4.0",
|
||||
"combined-stream": "^1.0.8",
|
||||
"es-set-tostringtag": "^2.1.0",
|
||||
"hasown": "^2.0.4",
|
||||
"mime-types": "^2.1.35"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 6"
|
||||
}
|
||||
},
|
||||
"node_modules/axobject-query": {
|
||||
"version": "4.1.0",
|
||||
"resolved": "https://registry.npmjs.org/axobject-query/-/axobject-query-4.1.0.tgz",
|
||||
@@ -9779,10 +9840,20 @@
|
||||
}
|
||||
},
|
||||
"node_modules/eslint/node_modules/js-yaml": {
|
||||
"version": "4.1.1",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz",
|
||||
"integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==",
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/nodeca"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1"
|
||||
@@ -10560,22 +10631,6 @@
|
||||
"node": ">=6"
|
||||
}
|
||||
},
|
||||
"node_modules/form-data": {
|
||||
"version": "4.0.5",
|
||||
"resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.5.tgz",
|
||||
"integrity": "sha512-8RipRLol37bNs2bhoV67fiTEvdTrbMUYcFTiy3+wuuOnUog2QBHCZWXDRijWQfAkhBj2Uf5UnVaiWwA5vdd82w==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"asynckit": "^0.4.0",
|
||||
"combined-stream": "^1.0.8",
|
||||
"es-set-tostringtag": "^2.1.0",
|
||||
"hasown": "^2.0.2",
|
||||
"mime-types": "^2.1.12"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 6"
|
||||
}
|
||||
},
|
||||
"node_modules/forwarded": {
|
||||
"version": "0.2.0",
|
||||
"resolved": "https://registry.npmjs.org/forwarded/-/forwarded-0.2.0.tgz",
|
||||
@@ -11082,9 +11137,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/hasown": {
|
||||
"version": "2.0.2",
|
||||
"resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.2.tgz",
|
||||
"integrity": "sha512-0hJU9SCPvmMzIBdZFqNPXWa6dqh7WdH0cII9y+CyS8rG3nL48Bclra9HmKhVVUHyPWNH5Y7xDwAB7bfgSjkUMQ==",
|
||||
"version": "2.0.4",
|
||||
"resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.4.tgz",
|
||||
"integrity": "sha512-T2UbfbBEF32wiepXIsMlTW9+dDYC6wMh/t/vYA4tuOMKqWz/n3vr1NFSxQiyP+zk2mXsoMA/i/7qV6LKut1t1A==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"function-bind": "^1.1.2"
|
||||
@@ -11344,9 +11399,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/http-proxy-middleware": {
|
||||
"version": "2.0.9",
|
||||
"resolved": "https://registry.npmjs.org/http-proxy-middleware/-/http-proxy-middleware-2.0.9.tgz",
|
||||
"integrity": "sha512-c1IyJYLYppU574+YI7R4QyX2ystMtVXZwIdzazUIPIJsHuWNd+mho2j+bKoHftndicGj9yh+xjd+l0yj7VeT1Q==",
|
||||
"version": "2.0.10",
|
||||
"resolved": "https://registry.npmjs.org/http-proxy-middleware/-/http-proxy-middleware-2.0.10.tgz",
|
||||
"integrity": "sha512-RKzRWNPxUZqbuk3BC5mGVJbBnWgr+diEnjJexIOytFbBzDy88Fbh/YvBr3DsNrl1jYAfjWfpATEv0NO35FDuPQ==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -15165,20 +15220,6 @@
|
||||
"integrity": "sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==",
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/js-yaml": {
|
||||
"version": "3.14.2",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz",
|
||||
"integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^1.0.7",
|
||||
"esprima": "^4.0.0"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
}
|
||||
},
|
||||
"node_modules/jsdom": {
|
||||
"version": "16.7.0",
|
||||
"resolved": "https://registry.npmjs.org/jsdom/-/jsdom-16.7.0.tgz",
|
||||
@@ -15227,16 +15268,16 @@
|
||||
}
|
||||
},
|
||||
"node_modules/jsdom/node_modules/form-data": {
|
||||
"version": "3.0.4",
|
||||
"resolved": "https://registry.npmjs.org/form-data/-/form-data-3.0.4.tgz",
|
||||
"integrity": "sha512-f0cRzm6dkyVYV3nPoooP8XlccPQukegwhAnpoLcXy+X+A8KfpGOoXwDr9FLZd3wzgLaBGQBE3lY93Zm/i1JvIQ==",
|
||||
"version": "3.0.5",
|
||||
"resolved": "https://registry.npmjs.org/form-data/-/form-data-3.0.5.tgz",
|
||||
"integrity": "sha512-j23EibVLnp4zNXGW7LjryXYa2X6U/M96yoOX+ybZxwkYajdxRNEqYY3zhh7y0i6kfISKS2jr+EJq1YTUDEv5+w==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"asynckit": "^0.4.0",
|
||||
"combined-stream": "^1.0.8",
|
||||
"es-set-tostringtag": "^2.1.0",
|
||||
"hasown": "^2.0.2",
|
||||
"hasown": "^2.0.4",
|
||||
"mime-types": "^2.1.35"
|
||||
},
|
||||
"engines": {
|
||||
@@ -15431,14 +15472,14 @@
|
||||
}
|
||||
},
|
||||
"node_modules/launch-editor": {
|
||||
"version": "2.13.2",
|
||||
"resolved": "https://registry.npmjs.org/launch-editor/-/launch-editor-2.13.2.tgz",
|
||||
"integrity": "sha512-4VVDnbOpLXy/s8rdRCSXb+zfMeFR0WlJWpET1iA9CQdlZDfwyLjUuGQzXU4VeOoey6AicSAluWan7Etga6Kcmg==",
|
||||
"version": "2.14.1",
|
||||
"resolved": "https://registry.npmjs.org/launch-editor/-/launch-editor-2.14.1.tgz",
|
||||
"integrity": "sha512-QWBrQsMpH7gPr965dsKD/3cKWiNoTjpATQf++Xq63N6sKRGMwlVXz41O1IZTMfZQgBctD/K5Zt06+/I6pP6+HA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"picocolors": "^1.1.1",
|
||||
"shell-quote": "^1.8.3"
|
||||
"shell-quote": "^1.8.4"
|
||||
}
|
||||
},
|
||||
"node_modules/leven": {
|
||||
@@ -16685,9 +16726,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/postcss": {
|
||||
"version": "8.5.8",
|
||||
"resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.8.tgz",
|
||||
"integrity": "sha512-OW/rX8O/jXnm82Ey1k44pObPtdblfiuWnrd8X7GJ7emImCOstunGbXUpp7HdBrFQX6rJzn3sPT397Wp5aCwCHg==",
|
||||
"version": "8.5.10",
|
||||
"resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.10.tgz",
|
||||
"integrity": "sha512-pMMHxBOZKFU6HgAZ4eyGnwXF/EvPGGqUr0MnZ5+99485wwW41kW91A4LOGxSHhgugZmSChL5AlElNdwlNgcnLQ==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
@@ -19155,12 +19196,12 @@
|
||||
}
|
||||
},
|
||||
"node_modules/react-router": {
|
||||
"version": "6.30.3",
|
||||
"resolved": "https://registry.npmjs.org/react-router/-/react-router-6.30.3.tgz",
|
||||
"integrity": "sha512-XRnlbKMTmktBkjCLE8/XcZFlnHvr2Ltdr1eJX4idL55/9BbORzyZEaIkBFDhFGCEWBBItsVrDxwx3gnisMitdw==",
|
||||
"version": "6.30.4",
|
||||
"resolved": "https://registry.npmjs.org/react-router/-/react-router-6.30.4.tgz",
|
||||
"integrity": "sha512-SVUsDe+DybHM/WmYKIVYhZh1o5Dcuf16yM6WjG02Q9XVFMZIJyHYhwrr6bFBXZkVP6z69kNkMyBCujt8FaFLJA==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@remix-run/router": "1.23.2"
|
||||
"@remix-run/router": "1.23.3"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=14.0.0"
|
||||
@@ -19170,13 +19211,13 @@
|
||||
}
|
||||
},
|
||||
"node_modules/react-router-dom": {
|
||||
"version": "6.30.3",
|
||||
"resolved": "https://registry.npmjs.org/react-router-dom/-/react-router-dom-6.30.3.tgz",
|
||||
"integrity": "sha512-pxPcv1AczD4vso7G4Z3TKcvlxK7g7TNt3/FNGMhfqyntocvYKj+GCatfigGDjbLozC4baguJ0ReCigoDJXb0ag==",
|
||||
"version": "6.30.4",
|
||||
"resolved": "https://registry.npmjs.org/react-router-dom/-/react-router-dom-6.30.4.tgz",
|
||||
"integrity": "sha512-q4HvNl+mmDdkS0g+MqiBZNteQJCuimWoOyHMy4T/RQLAn9Z29+E91QXRaxOujeMl2HTzRSS0KFPd7lxX3PjV0Q==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@remix-run/router": "1.23.2",
|
||||
"react-router": "6.30.3"
|
||||
"@remix-run/router": "1.23.3",
|
||||
"react-router": "6.30.4"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=14.0.0"
|
||||
@@ -19667,32 +19708,20 @@
|
||||
}
|
||||
},
|
||||
"node_modules/resolve-url-loader": {
|
||||
"version": "4.0.0",
|
||||
"resolved": "https://registry.npmjs.org/resolve-url-loader/-/resolve-url-loader-4.0.0.tgz",
|
||||
"integrity": "sha512-05VEMczVREcbtT7Bz+C+96eUO5HDNvdthIiMB34t7FcF8ehcu4wC0sSgPUubs3XW2Q3CNLJk/BJrCU9wVRymiA==",
|
||||
"version": "5.0.0",
|
||||
"resolved": "https://registry.npmjs.org/resolve-url-loader/-/resolve-url-loader-5.0.0.tgz",
|
||||
"integrity": "sha512-uZtduh8/8srhBoMx//5bwqjQ+rfYOUq8zC9NrMUGtjBiGTtFJM42s58/36+hTqeqINcnYe08Nj3LkK9lW4N8Xg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"adjust-sourcemap-loader": "^4.0.0",
|
||||
"convert-source-map": "^1.7.0",
|
||||
"loader-utils": "^2.0.0",
|
||||
"postcss": "^7.0.35",
|
||||
"postcss": "^8.2.14",
|
||||
"source-map": "0.6.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=8.9"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"rework": "1.0.1",
|
||||
"rework-visit": "1.0.0"
|
||||
},
|
||||
"peerDependenciesMeta": {
|
||||
"rework": {
|
||||
"optional": true
|
||||
},
|
||||
"rework-visit": {
|
||||
"optional": true
|
||||
}
|
||||
"node": ">=12"
|
||||
}
|
||||
},
|
||||
"node_modules/resolve-url-loader/node_modules/convert-source-map": {
|
||||
@@ -19702,31 +19731,6 @@
|
||||
"dev": true,
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/resolve-url-loader/node_modules/picocolors": {
|
||||
"version": "0.2.1",
|
||||
"resolved": "https://registry.npmjs.org/picocolors/-/picocolors-0.2.1.tgz",
|
||||
"integrity": "sha512-cMlDqaLEqfSaW8Z7N5Jw+lyIW869EzT73/F5lhtY9cLGoVxSXznfgfXMO0Z5K0o0Q2TkTXq+0KFsdnSe3jDViA==",
|
||||
"dev": true,
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/resolve-url-loader/node_modules/postcss": {
|
||||
"version": "7.0.39",
|
||||
"resolved": "https://registry.npmjs.org/postcss/-/postcss-7.0.39.tgz",
|
||||
"integrity": "sha512-yioayjNbHn6z1/Bywyb2Y4s3yvDAeXGOyxqD+LnVOinq6Mdmd++SW2wUNVzavyyHxd6+DxzWGIuosg6P1Rj8uA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"picocolors": "^0.2.1",
|
||||
"source-map": "^0.6.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=6.0.0"
|
||||
},
|
||||
"funding": {
|
||||
"type": "opencollective",
|
||||
"url": "https://opencollective.com/postcss/"
|
||||
}
|
||||
},
|
||||
"node_modules/resolve-url-loader/node_modules/source-map": {
|
||||
"version": "0.6.1",
|
||||
"resolved": "https://registry.npmjs.org/source-map/-/source-map-0.6.1.tgz",
|
||||
@@ -21191,6 +21195,20 @@
|
||||
"node": ">=4"
|
||||
}
|
||||
},
|
||||
"node_modules/svgo/node_modules/js-yaml": {
|
||||
"version": "3.15.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.15.0.tgz",
|
||||
"integrity": "sha512-ttBQIIQPDeLjpPOohtUdXuXUVoA2uIB6fEH9HyJ7234s5mBJ5wTx20njxplLZQgLaOfpmPQA7X2t5AX6tIPbog==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^1.0.7",
|
||||
"esprima": "^4.0.0"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
}
|
||||
},
|
||||
"node_modules/svgo/node_modules/nth-check": {
|
||||
"version": "1.0.2",
|
||||
"resolved": "https://registry.npmjs.org/nth-check/-/nth-check-1.0.2.tgz",
|
||||
@@ -21315,6 +21333,24 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"node_modules/tailwindcss/node_modules/yaml": {
|
||||
"version": "2.9.0",
|
||||
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz",
|
||||
"integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==",
|
||||
"dev": true,
|
||||
"license": "ISC",
|
||||
"optional": true,
|
||||
"peer": true,
|
||||
"bin": {
|
||||
"yaml": "bin.mjs"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 14.6"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/eemeli"
|
||||
}
|
||||
},
|
||||
"node_modules/tapable": {
|
||||
"version": "2.3.2",
|
||||
"resolved": "https://registry.npmjs.org/tapable/-/tapable-2.3.2.tgz",
|
||||
@@ -22332,9 +22368,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/webpack-dev-server/node_modules/ws": {
|
||||
"version": "8.20.0",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.20.0.tgz",
|
||||
"integrity": "sha512-sAt8BhgNbzCtgGbt2OxmpuryO63ZoDk/sqaB/znQm94T4fCEsy/yV+7CdC1kJhOU9lboAEU7R3kquuycDoibVA==",
|
||||
"version": "8.21.0",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.21.0.tgz",
|
||||
"integrity": "sha512-Vsp28b7DRcimFQvrqu2Wek3z1iYxDCWqHYB8Qsnk/S4RfaCQzPGPyBNuVjJV3cd6UiKtUtp6sNM77gWvzcCH+g==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
@@ -22429,9 +22465,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/websocket-driver": {
|
||||
"version": "0.7.4",
|
||||
"resolved": "https://registry.npmjs.org/websocket-driver/-/websocket-driver-0.7.4.tgz",
|
||||
"integrity": "sha512-b17KeDIQVjvb0ssuSDF2cYXSg2iztliJ4B9WdsuB6J952qCPKmnVq4DyW5motImXHDC1cBT/1UezrJVsKw5zjg==",
|
||||
"version": "0.7.5",
|
||||
"resolved": "https://registry.npmjs.org/websocket-driver/-/websocket-driver-0.7.5.tgz",
|
||||
"integrity": "sha512-ZL2+3c7kMBdIRCMz6l8jQMHyGVxj+UL+xVk74Ombiciboca8rHa15L86B19E5oh1pL9Ii/uj54gtsIrZGMo6zA==",
|
||||
"dev": true,
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
@@ -23010,9 +23046,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/ws": {
|
||||
"version": "7.5.10",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-7.5.10.tgz",
|
||||
"integrity": "sha512-+dbF1tHwZpXcbOJdVOkzLDxZP1ailvSxM6ZweXTegylPny803bFhA+vqBYw4s31NSAk4S2Qz+AKXK9a4wkdjcQ==",
|
||||
"version": "7.5.11",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-7.5.11.tgz",
|
||||
"integrity": "sha512-zS54Oen9bITtp7kp2XM3AydrCIq1D+HwJOuH+c+e4LfpL/lotP5osijd+UoMnxwAam1GN8R4KtLAyIrIcBNpiA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
|
||||
+17
-2
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"name": "haproxy-openmanager-frontend",
|
||||
"version": "1.8.2",
|
||||
"version": "1.10.1",
|
||||
"description": "HAProxy Load Balancer Management UI",
|
||||
"license": "AGPL-3.0-or-later",
|
||||
"dependencies": {
|
||||
"react": "^18.2.0",
|
||||
"react-dom": "^18.2.0",
|
||||
"react-router-dom": "^6.8.0",
|
||||
"react-router-dom": "^6.30.4",
|
||||
"axios": "^1.16.0",
|
||||
"antd": "^5.2.0",
|
||||
"@ant-design/icons": "^5.0.0",
|
||||
@@ -30,6 +30,21 @@
|
||||
"@testing-library/user-event": "^14.4.3",
|
||||
"@babel/plugin-proposal-private-property-in-object": "^7.21.0"
|
||||
},
|
||||
"overrides": {
|
||||
"ws": "7.5.11",
|
||||
"webpack-dev-server": { "ws": "8.21.0" },
|
||||
"form-data": "4.0.6",
|
||||
"jsdom": { "form-data": "3.0.5" },
|
||||
"js-yaml": "3.15.0",
|
||||
"eslint": { "js-yaml": "4.2.0" },
|
||||
"@eslint/eslintrc": { "js-yaml": "4.2.0" },
|
||||
"http-proxy-middleware": "2.0.10",
|
||||
"launch-editor": "2.14.1",
|
||||
"postcss": "8.5.10",
|
||||
"resolve-url-loader": "5.0.0",
|
||||
"@babel/core": "7.29.6",
|
||||
"websocket-driver": "0.7.5"
|
||||
},
|
||||
"scripts": {
|
||||
"start": "react-scripts start",
|
||||
"build": "react-scripts build",
|
||||
|
||||
@@ -53,19 +53,19 @@ const MATCH_TYPE_GROUPS = [
|
||||
{ label: 'Advanced', options: MATCH_TYPES.filter(m => m.category === 'Advanced') },
|
||||
];
|
||||
|
||||
// Phase K Phase D follow-up (Bulgu #12 round 3) — the `-f <file>`
|
||||
// flag was removed from the visual builder because HAProxy OpenManager
|
||||
// does not provision pattern files onto the HAProxy node filesystem.
|
||||
// Allowing `-f` in the visual builder produced ACL rules that passed
|
||||
// every UI / Pydantic / heuristic check but ALWAYS failed HAProxy's
|
||||
// real `-c` parse at apply time with "failed to open pattern file".
|
||||
// Operators reported a multi-page wizard run ending at the Apply
|
||||
// Management red-badge for a footgun the UI made trivial to step on.
|
||||
// The Pydantic validators on the manual API + wizard reject `-f`
|
||||
// universally; the visual builder simply removes the option from the
|
||||
// dropdown so operators cannot author the unsupported state.
|
||||
// Issue #38 follow-up — `-f <file>` is back in the visual builder:
|
||||
// the Bulgu #12 removal (and the matching Pydantic rejects) assumed a
|
||||
// missing pattern file would surprise the operator at apply time, but
|
||||
// the agent runs `haproxy -c` before every reload so a missing file
|
||||
// fails safely (previous config keeps running), and bulk import plus
|
||||
// the free-form fields always accepted `-f`. Pattern files are
|
||||
// operator-managed host files, same policy as SPOE filter configs
|
||||
// (v1.8.8). The value field carries the file path (e.g. flag `-f`
|
||||
// + value `/etc/haproxy/blacklist.lst`); an informational note is
|
||||
// rendered on rules that use it.
|
||||
const FLAGS = [
|
||||
{ value: '-i', label: '-i (case insensitive)' },
|
||||
{ value: '-f', label: '-f (pattern file on host)' },
|
||||
{ value: '-m beg', label: '-m beg (begins with)' },
|
||||
{ value: '-m end', label: '-m end (ends with)' },
|
||||
{ value: '-m sub', label: '-m sub (contains)' },
|
||||
@@ -396,25 +396,23 @@ function ACLDefinitionCard({ rule, index, onChange, onDelete }) {
|
||||
};
|
||||
const isRaw = rule.raw !== undefined;
|
||||
|
||||
// Phase K Phase D follow-up (Bulgu #12 round 3) — surface `-f` flag
|
||||
// usage inline. The Pydantic validator rejects the rule server-side,
|
||||
// but operators benefit from seeing the error AS they type / when
|
||||
// they re-open a draft that carries a `-f`-flagged rule (e.g. from
|
||||
// a pre-fix draft). The error message matches the Pydantic error
|
||||
// verbatim so support flows are consistent.
|
||||
// Issue #38 follow-up — `-f <file>` pattern-file references are
|
||||
// ACCEPTED now (the Bulgu #12 reject was removed server-side too).
|
||||
// We still detect them, but only to render an informational note:
|
||||
// the referenced file is operator-managed and must exist on every
|
||||
// HAProxy host; a missing file fails safely at the agent's
|
||||
// pre-reload `haproxy -c`.
|
||||
const rawHasFileFlag = isRaw && typeof rule.raw === 'string' && ACL_FILE_FLAG_PATTERN.test(rule.raw);
|
||||
const structuredHasFileFlag =
|
||||
!isRaw && Array.isArray(rule.flags) && rule.flags.includes('-f');
|
||||
const hasFileFlag = rawHasFileFlag || structuredHasFileFlag;
|
||||
const cardStyleWithError = hasFileFlag
|
||||
? { ...ruleCardStyle, border: `1px solid ${token.colorError}` }
|
||||
: ruleCardStyle;
|
||||
const cardStyleWithError = ruleCardStyle;
|
||||
const FILE_FLAG_TOOLTIP =
|
||||
"ACL pattern-file references (-f <file>) are not supported by "
|
||||
+ "HAProxy OpenManager: the product does not provision pattern "
|
||||
+ "files onto the HAProxy node filesystem, so the reference "
|
||||
+ "would fail at HAProxy reload time. Remove '-f' and use inline "
|
||||
+ "values instead.";
|
||||
"This rule references a pattern file (-f <file>). The file must "
|
||||
+ "exist at that exact path on every HAProxy host in the cluster — "
|
||||
+ "HAProxy OpenManager does not create or distribute pattern files. "
|
||||
+ "A missing file fails safely at 'haproxy -c' (the previous config "
|
||||
+ "keeps running).";
|
||||
|
||||
if (isRaw) {
|
||||
return (
|
||||
@@ -427,11 +425,10 @@ function ACLDefinitionCard({ rule, index, onChange, onDelete }) {
|
||||
onChange={(e) => onChange(index, { raw: e.target.value })}
|
||||
placeholder="Raw ACL rule (e.g. my_acl path_beg /api)"
|
||||
prefix={<Tag color="default" style={{ marginRight: 4 }}>RAW</Tag>}
|
||||
status={hasFileFlag ? 'error' : undefined}
|
||||
/>
|
||||
</Tooltip>
|
||||
{hasFileFlag && (
|
||||
<Text type="danger" style={{ fontSize: 11, display: 'block', marginTop: 2 }}>
|
||||
<Text type="secondary" style={{ fontSize: 11, display: 'block', marginTop: 2 }}>
|
||||
{FILE_FLAG_TOOLTIP}
|
||||
</Text>
|
||||
)}
|
||||
@@ -549,12 +546,11 @@ function ACLDefinitionCard({ rule, index, onChange, onDelete }) {
|
||||
onChange={(e) => onChange(index, { ...rule, value: e.target.value })}
|
||||
placeholder={matchDef?.placeholder || 'Value'}
|
||||
size="small"
|
||||
status={structuredHasFileFlag ? 'error' : undefined}
|
||||
/>
|
||||
);
|
||||
})()}
|
||||
{structuredHasFileFlag && (
|
||||
<Text type="danger" style={{ fontSize: 11, display: 'block', marginTop: 2 }}>
|
||||
<Text type="secondary" style={{ fontSize: 11, display: 'block', marginTop: 2 }}>
|
||||
{FILE_FLAG_TOOLTIP}
|
||||
</Text>
|
||||
)}
|
||||
@@ -891,11 +887,11 @@ export default function ACLRuleBuilder({ aclRules = [], useBackendRules = [], re
|
||||
.map(d => d.name);
|
||||
}, [aclDefs]);
|
||||
|
||||
// Phase K Phase D follow-up (Bulgu #12 round 3) — count rules that
|
||||
// still carry the unsupported `-f <file>` flag. Surfaced as a
|
||||
// section-level Alert so operators know the section as a whole
|
||||
// has invalid rules even if individual cards / raw text would
|
||||
// otherwise need scrolling to find them.
|
||||
// Issue #38 follow-up — count rules that reference a `-f <file>`
|
||||
// pattern file. Surfaced as a section-level informational Alert
|
||||
// (non-blocking): the file is operator-managed and must exist on
|
||||
// every HAProxy host; a missing file fails safely at the agent's
|
||||
// pre-reload `haproxy -c`.
|
||||
const fileFlagRuleCount = useMemo(() => {
|
||||
let count = 0;
|
||||
for (const d of aclDefs) {
|
||||
@@ -1153,19 +1149,19 @@ export default function ACLRuleBuilder({ aclRules = [], useBackendRules = [], re
|
||||
Define named conditions to match incoming requests by path, header, source IP, and more.
|
||||
</Text>
|
||||
|
||||
{/* Phase K Phase D follow-up (Bulgu #12 round 3) — section-
|
||||
level warning when one or more rules still carry the
|
||||
unsupported `-f <file>` pattern-file flag. Render as a
|
||||
blocking-style Alert so the operator notices BEFORE
|
||||
Submit. The Pydantic validator rejects the same shape
|
||||
server-side; this is the up-front authoring guardrail. */}
|
||||
{/* Issue #38 follow-up — section-level informational note
|
||||
when one or more rules reference `-f <file>` pattern
|
||||
files. Non-blocking: pattern files are operator-managed
|
||||
host files (the Bulgu #12 reject was removed) and a
|
||||
missing file fails safely at the agent's pre-reload
|
||||
`haproxy -c`. */}
|
||||
{fileFlagRuleCount > 0 && (
|
||||
<Alert
|
||||
type="error"
|
||||
type="info"
|
||||
showIcon
|
||||
style={{ marginBottom: 8 }}
|
||||
message={`${fileFlagRuleCount} ACL rule${fileFlagRuleCount === 1 ? '' : 's'} use the unsupported \`-f <file>\` flag`}
|
||||
description="HAProxy OpenManager does not provision pattern files onto the HAProxy node filesystem, so any `-f /path/...` reference would fail HAProxy reload at apply time with 'failed to open pattern file'. Remove the `-f` flag and switch to inline values (e.g. `src 10.0.0.0/24` instead of `src -f /etc/haproxy/admins.lst`)."
|
||||
message={`${fileFlagRuleCount} ACL rule${fileFlagRuleCount === 1 ? '' : 's'} reference a \`-f <file>\` pattern file`}
|
||||
description="The referenced file must exist at that exact path on every HAProxy host in the cluster — HAProxy OpenManager does not create or distribute pattern files. A missing file fails safely at 'haproxy -c' (the previous config keeps running)."
|
||||
/>
|
||||
)}
|
||||
|
||||
|
||||
@@ -2378,7 +2378,7 @@ const AgentManagement = () => {
|
||||
const element = document.createElement('a');
|
||||
const file = new Blob([installScript], { type: 'text/plain' });
|
||||
element.href = URL.createObjectURL(file);
|
||||
element.download = `install-haproxy-agent-${selectedPlatform}.sh`;
|
||||
element.download = `install-agent-${selectedPlatform}.sh`;
|
||||
document.body.appendChild(element);
|
||||
element.click();
|
||||
document.body.removeChild(element);
|
||||
@@ -2516,7 +2516,7 @@ const AgentManagement = () => {
|
||||
const element = document.createElement('a');
|
||||
const file = new Blob([uninstallScript], { type: 'text/plain' });
|
||||
element.href = URL.createObjectURL(file);
|
||||
element.download = `uninstall-haproxy-agent-${selectedPlatform}.sh`;
|
||||
element.download = `uninstall-agent-${selectedPlatform}.sh`;
|
||||
document.body.appendChild(element);
|
||||
element.click();
|
||||
document.body.removeChild(element);
|
||||
@@ -3147,7 +3147,7 @@ const AgentManagement = () => {
|
||||
const element = document.createElement('a');
|
||||
const file = new Blob([deleteUninstallScript], { type: 'text/plain' });
|
||||
element.href = URL.createObjectURL(file);
|
||||
element.download = `uninstall-haproxy-agent-${agentToDelete.platform || 'linux'}.sh`;
|
||||
element.download = `uninstall-agent-${agentToDelete.platform || 'linux'}.sh`;
|
||||
document.body.appendChild(element);
|
||||
element.click();
|
||||
document.body.removeChild(element);
|
||||
|
||||
@@ -458,6 +458,8 @@ backend web-backend
|
||||
{record.request_headers && <Tag color="blue">Req Headers</Tag>}
|
||||
{record.response_headers && <Tag color="green">Resp Headers</Tag>}
|
||||
{record.tcp_request_rules && <Tag color="purple">TCP Rules</Tag>}
|
||||
{record.filters && <Tag color="magenta">Filters</Tag>}
|
||||
{record.log_format && <Tag color="geekblue">Log Format</Tag>}
|
||||
{record.acl_rules && record.acl_rules.length > 0 && <Tag color="orange">{record.acl_rules.length} ACLs</Tag>}
|
||||
{record.use_backend_rules && record.use_backend_rules.length > 0 && <Tag color="cyan">{record.use_backend_rules.length} Routes</Tag>}
|
||||
</Space>
|
||||
@@ -1076,8 +1078,9 @@ backend web-backend
|
||||
size="small"
|
||||
expandable={{
|
||||
expandedRowRender: (frontend) => {
|
||||
const hasDetails = frontend.request_headers || frontend.response_headers ||
|
||||
frontend.options || frontend.tcp_request_rules ||
|
||||
const hasDetails = frontend.request_headers || frontend.response_headers ||
|
||||
frontend.options || frontend.tcp_request_rules ||
|
||||
frontend.filters || frontend.log_format ||
|
||||
(frontend.acl_rules && frontend.acl_rules.length > 0) ||
|
||||
(frontend.use_backend_rules && frontend.use_backend_rules.length > 0);
|
||||
|
||||
@@ -1157,12 +1160,52 @@ backend web-backend
|
||||
</span>
|
||||
}
|
||||
>
|
||||
<MultiLineDiffRenderer
|
||||
<MultiLineDiffRenderer
|
||||
value={frontend.tcp_request_rules}
|
||||
changeInfo={frontend._changes?.tcp_request_rules}
|
||||
/>
|
||||
</Descriptions.Item>
|
||||
)}
|
||||
{/* Issue #38: SPOE filters */}
|
||||
{frontend.filters && (
|
||||
<Descriptions.Item
|
||||
label={
|
||||
<span>
|
||||
Filters (SPOE/WAF)
|
||||
{frontend._changes?.filters && (
|
||||
<Tag color="green" style={{ marginLeft: 8, fontSize: '10px' }}>
|
||||
{frontend._changes.filters.old ? 'CHANGED' : 'NEW'}
|
||||
</Tag>
|
||||
)}
|
||||
</span>
|
||||
}
|
||||
>
|
||||
<MultiLineDiffRenderer
|
||||
value={frontend.filters}
|
||||
changeInfo={frontend._changes?.filters}
|
||||
/>
|
||||
</Descriptions.Item>
|
||||
)}
|
||||
{/* Issue #38: frontend log-format */}
|
||||
{frontend.log_format && (
|
||||
<Descriptions.Item
|
||||
label={
|
||||
<span>
|
||||
Log Format
|
||||
{frontend._changes?.log_format && (
|
||||
<Tag color="green" style={{ marginLeft: 8, fontSize: '10px' }}>
|
||||
{frontend._changes.log_format.old ? 'CHANGED' : 'NEW'}
|
||||
</Tag>
|
||||
)}
|
||||
</span>
|
||||
}
|
||||
>
|
||||
<MultiLineDiffRenderer
|
||||
value={frontend.log_format}
|
||||
changeInfo={frontend._changes?.log_format}
|
||||
/>
|
||||
</Descriptions.Item>
|
||||
)}
|
||||
{frontend.acl_rules && frontend.acl_rules.length > 0 && (
|
||||
<Descriptions.Item label={`ACL Rules (${frontend.acl_rules.length})`}>
|
||||
{frontend.acl_rules.map((acl, idx) => (
|
||||
|
||||
@@ -0,0 +1,886 @@
|
||||
import React, { useState, useEffect, useCallback } from 'react';
|
||||
import {
|
||||
Card, Table, Button, Modal, Form, Input, Space, message,
|
||||
Popconfirm, Tag, Tooltip, Row, Col, Typography, Alert, Select,
|
||||
Collapse, Descriptions, Badge
|
||||
} from 'antd';
|
||||
import {
|
||||
PlusOutlined, ReloadOutlined, DeleteOutlined, EyeOutlined,
|
||||
DownloadOutlined, CopyOutlined, FileProtectOutlined, ImportOutlined,
|
||||
KeyOutlined
|
||||
} from '@ant-design/icons';
|
||||
import axios from 'axios';
|
||||
import { useCluster } from '../contexts/ClusterContext';
|
||||
import { extractApiError } from '../utils/apiError';
|
||||
import { antdDomainRule, antdDomainsListRule } from '../utils/validation';
|
||||
|
||||
const { Text } = Typography;
|
||||
const { TextArea } = Input;
|
||||
|
||||
const KEY_ALGORITHM_OPTIONS = [
|
||||
{ value: 'rsa-2048', label: 'RSA 2048 (recommended)' },
|
||||
{ value: 'rsa-4096', label: 'RSA 4096' },
|
||||
{ value: 'ecdsa-p256', label: 'ECDSA P-256' },
|
||||
{ value: 'ecdsa-p384', label: 'ECDSA P-384' },
|
||||
];
|
||||
|
||||
const KEY_ALGORITHM_LABELS = {
|
||||
'rsa-2048': 'RSA 2048',
|
||||
'rsa-4096': 'RSA 4096',
|
||||
'ecdsa-p256': 'ECDSA P-256',
|
||||
'ecdsa-p384': 'ECDSA P-384',
|
||||
};
|
||||
|
||||
// CSR creation (v1.9.0): generate the private key + CSR server-side, submit
|
||||
// the CSR to an external CA, then import the signed certificate. The private
|
||||
// key never leaves the backend — this component only ever handles the CSR
|
||||
// PEM and the CA's certificate response.
|
||||
const CSRManagement = ({ onCertificateImported }) => {
|
||||
const { clusters } = useCluster();
|
||||
const [csrs, setCsrs] = useState([]);
|
||||
const [loading, setLoading] = useState(false);
|
||||
const [createModalOpen, setCreateModalOpen] = useState(false);
|
||||
const [creating, setCreating] = useState(false);
|
||||
const [viewCsr, setViewCsr] = useState(null);
|
||||
const [importCsr, setImportCsr] = useState(null);
|
||||
const [importing, setImporting] = useState(false);
|
||||
const [createForm] = Form.useForm();
|
||||
const [importForm] = Form.useForm();
|
||||
|
||||
const fetchCsrs = useCallback(async () => {
|
||||
setLoading(true);
|
||||
try {
|
||||
const response = await axios.get('/api/ssl/csrs', {
|
||||
headers: {
|
||||
'Cache-Control': 'no-cache, no-store, must-revalidate',
|
||||
'Pragma': 'no-cache',
|
||||
},
|
||||
});
|
||||
setCsrs(Array.isArray(response.data) ? response.data : []);
|
||||
} catch (error) {
|
||||
console.error('Error fetching CSRs:', error);
|
||||
message.error(extractApiError(error, 'Failed to fetch CSRs'));
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
fetchCsrs();
|
||||
}, [fetchCsrs]);
|
||||
|
||||
const handleCreate = async (values) => {
|
||||
setCreating(true);
|
||||
try {
|
||||
const payload = {
|
||||
name: values.name,
|
||||
common_name: values.common_name,
|
||||
sans: values.sans || [],
|
||||
key_algorithm: values.key_algorithm || 'rsa-2048',
|
||||
organization: values.organization || null,
|
||||
organizational_unit: values.organizational_unit || null,
|
||||
locality: values.locality || null,
|
||||
state: values.state || null,
|
||||
country: values.country || null,
|
||||
email: values.email || null,
|
||||
};
|
||||
const response = await axios.post('/api/ssl/csrs', payload);
|
||||
message.success(
|
||||
<div>
|
||||
<strong>CSR '{values.name}' created</strong>
|
||||
<br />
|
||||
<small>Submit the CSR to your Certificate Authority for signing.</small>
|
||||
</div>,
|
||||
5
|
||||
);
|
||||
setCreateModalOpen(false);
|
||||
createForm.resetFields();
|
||||
fetchCsrs();
|
||||
// Open the view modal immediately so the operator can copy/download
|
||||
// the CSR PEM in one round trip.
|
||||
if (response.data?.csr) {
|
||||
setViewCsr(response.data.csr);
|
||||
}
|
||||
} catch (error) {
|
||||
console.error('Error creating CSR:', error);
|
||||
message.error(extractApiError(error, 'Failed to create CSR'));
|
||||
} finally {
|
||||
setCreating(false);
|
||||
}
|
||||
};
|
||||
|
||||
const handleView = async (record) => {
|
||||
try {
|
||||
const response = await axios.get(`/api/ssl/csrs/${record.id}`);
|
||||
setViewCsr(response.data);
|
||||
} catch (error) {
|
||||
console.error('Error fetching CSR details:', error);
|
||||
message.error(extractApiError(error, 'Failed to fetch CSR details'));
|
||||
}
|
||||
};
|
||||
|
||||
const handleDuplicate = (record) => {
|
||||
const subject = record.subject || {};
|
||||
createForm.setFieldsValue({
|
||||
name: `${record.name}-new`,
|
||||
common_name: record.common_name,
|
||||
sans: (record.sans || []).filter((s) => s !== record.common_name),
|
||||
key_algorithm: record.key_algorithm || 'rsa-2048',
|
||||
organization: subject.O || undefined,
|
||||
organizational_unit: subject.OU || undefined,
|
||||
locality: subject.L || undefined,
|
||||
state: subject.ST || undefined,
|
||||
country: subject.C || undefined,
|
||||
email: subject.emailAddress || undefined,
|
||||
});
|
||||
setCreateModalOpen(true);
|
||||
};
|
||||
|
||||
const handleDelete = async (record) => {
|
||||
try {
|
||||
const response = await axios.delete(`/api/ssl/csrs/${record.id}`);
|
||||
message.success(response.data?.message || `CSR '${record.name}' deleted`);
|
||||
fetchCsrs();
|
||||
} catch (error) {
|
||||
console.error('Error deleting CSR:', error);
|
||||
message.error(extractApiError(error, 'Failed to delete CSR'));
|
||||
}
|
||||
};
|
||||
|
||||
const handleImport = async (values) => {
|
||||
if (!importCsr) return;
|
||||
setImporting(true);
|
||||
try {
|
||||
const isGlobal = values.ssl_type === 'global';
|
||||
const payload = {
|
||||
certificate_content: values.certificate_content,
|
||||
chain_content: values.chain_content || null,
|
||||
usage_type: values.usage_type || 'frontend',
|
||||
is_global: isGlobal,
|
||||
cluster_ids: isGlobal ? null : values.cluster_ids,
|
||||
name: values.name_override ? values.name_override.trim() : null,
|
||||
};
|
||||
const response = await axios.post(
|
||||
`/api/ssl/csrs/${importCsr.id}/import`,
|
||||
payload
|
||||
);
|
||||
const warnings = response.data?.warnings || [];
|
||||
if (warnings.length > 0) {
|
||||
Modal.warning({
|
||||
title: 'Certificate imported with warnings',
|
||||
width: 560,
|
||||
content: (
|
||||
<ul style={{ paddingLeft: 18, marginTop: 8 }}>
|
||||
{warnings.map((w, i) => (
|
||||
<li key={i}>{w}</li>
|
||||
))}
|
||||
</ul>
|
||||
),
|
||||
});
|
||||
}
|
||||
message.success(
|
||||
<div>
|
||||
<strong>Certificate imported successfully</strong>
|
||||
<br />
|
||||
<small>Go to Apply Management to deploy it to the cluster(s).</small>
|
||||
</div>,
|
||||
6
|
||||
);
|
||||
setImportCsr(null);
|
||||
importForm.resetFields();
|
||||
fetchCsrs();
|
||||
if (onCertificateImported) {
|
||||
onCertificateImported();
|
||||
}
|
||||
} catch (error) {
|
||||
console.error('Error importing signed certificate:', error);
|
||||
message.error(extractApiError(error, 'Failed to import certificate'));
|
||||
} finally {
|
||||
setImporting(false);
|
||||
}
|
||||
};
|
||||
|
||||
const downloadCsrPem = (csr) => {
|
||||
if (!csr?.csr_pem) return;
|
||||
const blob = new Blob([csr.csr_pem], { type: 'application/pkcs10;charset=utf-8' });
|
||||
const url = URL.createObjectURL(blob);
|
||||
const link = document.createElement('a');
|
||||
link.href = url;
|
||||
link.download = `${csr.name}.csr`;
|
||||
document.body.appendChild(link);
|
||||
link.click();
|
||||
document.body.removeChild(link);
|
||||
URL.revokeObjectURL(url);
|
||||
};
|
||||
|
||||
const copyCsrPem = (csr) => {
|
||||
if (!csr?.csr_pem) return;
|
||||
if (navigator.clipboard && navigator.clipboard.writeText) {
|
||||
navigator.clipboard
|
||||
.writeText(csr.csr_pem)
|
||||
.then(() => message.success('CSR PEM copied to clipboard'))
|
||||
.catch(() => message.error('Failed to copy CSR PEM'));
|
||||
} else {
|
||||
message.warning('Clipboard is not available in this browser');
|
||||
}
|
||||
};
|
||||
|
||||
const columns = [
|
||||
{
|
||||
title: 'CSR',
|
||||
dataIndex: 'name',
|
||||
key: 'name',
|
||||
render: (text, record) => (
|
||||
<Space>
|
||||
<FileProtectOutlined style={{ color: '#1677ff' }} />
|
||||
<div>
|
||||
<strong>{text}</strong>
|
||||
<br />
|
||||
<Text type="secondary" style={{ fontSize: 12 }}>
|
||||
{record.common_name}
|
||||
</Text>
|
||||
</div>
|
||||
</Space>
|
||||
),
|
||||
},
|
||||
{
|
||||
title: 'SANs',
|
||||
dataIndex: 'sans',
|
||||
key: 'sans',
|
||||
render: (sans) => {
|
||||
const list = Array.isArray(sans) ? sans : [];
|
||||
if (list.length === 0) return <Text type="secondary">-</Text>;
|
||||
const visible = list.slice(0, 2);
|
||||
const rest = list.slice(2);
|
||||
return (
|
||||
<Space size={4} wrap>
|
||||
{visible.map((d) => (
|
||||
<Tag key={d}>{d}</Tag>
|
||||
))}
|
||||
{rest.length > 0 && (
|
||||
<Tooltip title={rest.join(', ')}>
|
||||
<Tag>+{rest.length}</Tag>
|
||||
</Tooltip>
|
||||
)}
|
||||
</Space>
|
||||
);
|
||||
},
|
||||
},
|
||||
{
|
||||
title: 'Key',
|
||||
dataIndex: 'key_algorithm',
|
||||
key: 'key_algorithm',
|
||||
render: (algo) => (
|
||||
<Tag icon={<KeyOutlined />} color="geekblue">
|
||||
{KEY_ALGORITHM_LABELS[algo] || algo}
|
||||
</Tag>
|
||||
),
|
||||
},
|
||||
{
|
||||
title: 'Status',
|
||||
dataIndex: 'status',
|
||||
key: 'status',
|
||||
render: (status, record) => {
|
||||
if (status === 'completed') {
|
||||
return (
|
||||
<div>
|
||||
<Badge status="success" text="Imported" />
|
||||
{record.certificate_name && (
|
||||
<>
|
||||
<br />
|
||||
<Text type="secondary" style={{ fontSize: 12 }}>
|
||||
→ {record.certificate_name}
|
||||
</Text>
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
return <Badge status="processing" text="Awaiting certificate" />;
|
||||
},
|
||||
},
|
||||
{
|
||||
title: 'Created',
|
||||
dataIndex: 'created_at',
|
||||
key: 'created_at',
|
||||
render: (date, record) => (
|
||||
<div>
|
||||
{date
|
||||
? new Date(date).toLocaleString(undefined, {
|
||||
year: 'numeric',
|
||||
month: 'short',
|
||||
day: 'numeric',
|
||||
hour: '2-digit',
|
||||
minute: '2-digit',
|
||||
})
|
||||
: '-'}
|
||||
{record.created_by_username && (
|
||||
<>
|
||||
<br />
|
||||
<Text type="secondary" style={{ fontSize: 12 }}>
|
||||
by {record.created_by_username}
|
||||
</Text>
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
),
|
||||
},
|
||||
{
|
||||
title: 'Actions',
|
||||
key: 'actions',
|
||||
render: (_, record) => (
|
||||
<Space size="small">
|
||||
<Tooltip title="View / download CSR">
|
||||
<Button
|
||||
type="text"
|
||||
size="small"
|
||||
icon={<EyeOutlined />}
|
||||
onClick={() => handleView(record)}
|
||||
/>
|
||||
</Tooltip>
|
||||
{record.status === 'pending' && (
|
||||
<Tooltip title="Import signed certificate">
|
||||
<Button
|
||||
type="primary"
|
||||
size="small"
|
||||
icon={<ImportOutlined />}
|
||||
onClick={() => {
|
||||
importForm.resetFields();
|
||||
setImportCsr(record);
|
||||
}}
|
||||
>
|
||||
Import
|
||||
</Button>
|
||||
</Tooltip>
|
||||
)}
|
||||
<Tooltip title="Duplicate (pre-fill a new CSR)">
|
||||
<Button
|
||||
type="text"
|
||||
size="small"
|
||||
icon={<CopyOutlined />}
|
||||
onClick={() => handleDuplicate(record)}
|
||||
/>
|
||||
</Tooltip>
|
||||
<Popconfirm
|
||||
title="Delete this CSR?"
|
||||
description={
|
||||
record.status === 'pending'
|
||||
? 'The private key will be permanently destroyed — any certificate later signed from this CSR becomes unusable.'
|
||||
: 'Only the CSR history entry is removed — the imported certificate is not affected.'
|
||||
}
|
||||
onConfirm={() => handleDelete(record)}
|
||||
okText="Delete"
|
||||
okType="danger"
|
||||
cancelText="Cancel"
|
||||
>
|
||||
<Tooltip title="Delete CSR">
|
||||
<Button type="text" size="small" danger icon={<DeleteOutlined />} />
|
||||
</Tooltip>
|
||||
</Popconfirm>
|
||||
</Space>
|
||||
),
|
||||
},
|
||||
];
|
||||
|
||||
const pendingCount = csrs.filter((c) => c.status === 'pending').length;
|
||||
|
||||
return (
|
||||
<div>
|
||||
<Alert
|
||||
type="info"
|
||||
showIcon
|
||||
style={{ marginBottom: 16 }}
|
||||
message="Certificate Signing Requests for external CAs"
|
||||
description="Generate a private key and CSR here, submit the CSR to your Certificate Authority, then import the signed certificate. The private key never leaves the server; the imported certificate goes through the normal Apply Management deployment flow."
|
||||
/>
|
||||
<Row gutter={16} style={{ marginBottom: 16 }}>
|
||||
<Col flex="auto">
|
||||
{pendingCount > 0 && (
|
||||
<Text type="secondary">
|
||||
{pendingCount} CSR{pendingCount > 1 ? 's' : ''} awaiting a signed
|
||||
certificate
|
||||
</Text>
|
||||
)}
|
||||
</Col>
|
||||
<Col>
|
||||
<Space>
|
||||
<Button icon={<ReloadOutlined />} onClick={fetchCsrs} loading={loading}>
|
||||
Refresh
|
||||
</Button>
|
||||
<Button
|
||||
type="primary"
|
||||
icon={<PlusOutlined />}
|
||||
onClick={() => {
|
||||
createForm.resetFields();
|
||||
setCreateModalOpen(true);
|
||||
}}
|
||||
>
|
||||
Create CSR
|
||||
</Button>
|
||||
</Space>
|
||||
</Col>
|
||||
</Row>
|
||||
|
||||
<Card>
|
||||
<Table
|
||||
columns={columns}
|
||||
dataSource={csrs}
|
||||
rowKey="id"
|
||||
loading={loading}
|
||||
pagination={{
|
||||
showSizeChanger: true,
|
||||
showQuickJumper: true,
|
||||
showTotal: (total) => `Total ${total} CSRs`,
|
||||
}}
|
||||
/>
|
||||
</Card>
|
||||
|
||||
{/* Create CSR Modal */}
|
||||
<Modal
|
||||
title="Create Certificate Signing Request"
|
||||
open={createModalOpen}
|
||||
onCancel={() => {
|
||||
setCreateModalOpen(false);
|
||||
createForm.resetFields();
|
||||
}}
|
||||
footer={null}
|
||||
width={700}
|
||||
forceRender
|
||||
>
|
||||
<Form form={createForm} layout="vertical" onFinish={handleCreate}>
|
||||
<Form.Item
|
||||
name="name"
|
||||
label="Name"
|
||||
rules={[
|
||||
{ required: true, message: 'Please enter a CSR name' },
|
||||
{
|
||||
pattern: /^[a-zA-Z0-9_.-]+$/,
|
||||
message:
|
||||
'Only letters, digits, underscore, hyphen and dot are allowed',
|
||||
},
|
||||
{ max: 100, message: 'Name must be 100 characters or fewer' },
|
||||
{
|
||||
validator: (_, value) => {
|
||||
if (!value) return Promise.resolve();
|
||||
if (value.includes('..')) {
|
||||
return Promise.reject(new Error('Name must not contain ".."'));
|
||||
}
|
||||
if (value.startsWith('.') || value.startsWith('-')) {
|
||||
return Promise.reject(
|
||||
new Error('Name must not start with "." or "-"')
|
||||
);
|
||||
}
|
||||
return Promise.resolve();
|
||||
},
|
||||
},
|
||||
]}
|
||||
extra="Becomes the certificate name and file path at import: /etc/ssl/haproxy/{name}.pem"
|
||||
>
|
||||
<Input placeholder="e.g. www-example-com" />
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="common_name"
|
||||
label="Common Name (CN)"
|
||||
rules={[
|
||||
{ required: true, message: 'Please enter the Common Name' },
|
||||
antdDomainRule,
|
||||
{ max: 64, message: 'Common Name must be 64 characters or fewer' },
|
||||
]}
|
||||
extra="The primary domain, e.g. www.example.com or *.example.com"
|
||||
>
|
||||
<Input placeholder="www.example.com" />
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="sans"
|
||||
label="Subject Alternative Names (SANs)"
|
||||
rules={[antdDomainsListRule]}
|
||||
extra="Additional DNS names — the Common Name is included automatically"
|
||||
>
|
||||
<Select
|
||||
mode="tags"
|
||||
tokenSeparators={[',', ' ']}
|
||||
placeholder="api.example.com, cdn.example.com"
|
||||
open={false}
|
||||
suffixIcon={null}
|
||||
/>
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="key_algorithm"
|
||||
label="Key Algorithm"
|
||||
initialValue="rsa-2048"
|
||||
rules={[{ required: true }]}
|
||||
>
|
||||
<Select options={KEY_ALGORITHM_OPTIONS} />
|
||||
</Form.Item>
|
||||
|
||||
<Collapse
|
||||
style={{ marginBottom: 16 }}
|
||||
items={[
|
||||
{
|
||||
key: 'subject',
|
||||
label: 'Subject details (optional)',
|
||||
children: (
|
||||
<>
|
||||
<Row gutter={12}>
|
||||
<Col span={12}>
|
||||
<Form.Item
|
||||
name="organization"
|
||||
label="Organization (O)"
|
||||
rules={[{ max: 64 }]}
|
||||
>
|
||||
<Input placeholder="Example Corp" />
|
||||
</Form.Item>
|
||||
</Col>
|
||||
<Col span={12}>
|
||||
<Form.Item
|
||||
name="organizational_unit"
|
||||
label="Organizational Unit (OU)"
|
||||
rules={[{ max: 64 }]}
|
||||
>
|
||||
<Input placeholder="IT Department" />
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
<Row gutter={12}>
|
||||
<Col span={8}>
|
||||
<Form.Item name="locality" label="Locality (L)" rules={[{ max: 64 }]}>
|
||||
<Input placeholder="Istanbul" />
|
||||
</Form.Item>
|
||||
</Col>
|
||||
<Col span={8}>
|
||||
<Form.Item name="state" label="State / Province (ST)" rules={[{ max: 64 }]}>
|
||||
<Input placeholder="Marmara" />
|
||||
</Form.Item>
|
||||
</Col>
|
||||
<Col span={8}>
|
||||
<Form.Item
|
||||
name="country"
|
||||
label="Country (C)"
|
||||
rules={[
|
||||
{
|
||||
pattern: /^[A-Za-z]{2}$/,
|
||||
message: 'Exactly 2 letters (e.g. TR, US)',
|
||||
},
|
||||
]}
|
||||
>
|
||||
<Input placeholder="TR" maxLength={2} />
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
<Form.Item
|
||||
name="email"
|
||||
label="Email"
|
||||
rules={[{ type: 'email', message: 'Invalid email address' }]}
|
||||
>
|
||||
<Input placeholder="ops@example.com" />
|
||||
</Form.Item>
|
||||
</>
|
||||
),
|
||||
},
|
||||
]}
|
||||
/>
|
||||
|
||||
<Alert
|
||||
type="info"
|
||||
showIcon
|
||||
style={{ marginBottom: 16 }}
|
||||
message="🔐 The private key is generated and stored server-side"
|
||||
description="You will only receive the CSR to hand to your CA. After the signed certificate is imported, the key is available on the certificate itself."
|
||||
/>
|
||||
|
||||
<Form.Item style={{ textAlign: 'right', marginBottom: 0 }}>
|
||||
<Space>
|
||||
<Button
|
||||
onClick={() => {
|
||||
setCreateModalOpen(false);
|
||||
createForm.resetFields();
|
||||
}}
|
||||
>
|
||||
Cancel
|
||||
</Button>
|
||||
<Button type="primary" htmlType="submit" loading={creating}>
|
||||
Generate CSR
|
||||
</Button>
|
||||
</Space>
|
||||
</Form.Item>
|
||||
</Form>
|
||||
</Modal>
|
||||
|
||||
{/* View CSR Modal */}
|
||||
<Modal
|
||||
title={
|
||||
<Space>
|
||||
<FileProtectOutlined />
|
||||
{viewCsr ? `CSR: ${viewCsr.name}` : 'CSR'}
|
||||
</Space>
|
||||
}
|
||||
open={!!viewCsr}
|
||||
onCancel={() => setViewCsr(null)}
|
||||
width={760}
|
||||
footer={[
|
||||
<Button key="close" onClick={() => setViewCsr(null)}>
|
||||
Close
|
||||
</Button>,
|
||||
]}
|
||||
>
|
||||
{viewCsr && (
|
||||
<div>
|
||||
<Descriptions size="small" column={2} bordered style={{ marginBottom: 12 }}>
|
||||
<Descriptions.Item label="Common Name" span={2}>
|
||||
{viewCsr.common_name}
|
||||
</Descriptions.Item>
|
||||
<Descriptions.Item label="Key">
|
||||
{KEY_ALGORITHM_LABELS[viewCsr.key_algorithm] || viewCsr.key_algorithm}
|
||||
</Descriptions.Item>
|
||||
<Descriptions.Item label="Status">
|
||||
{viewCsr.status === 'completed' ? (
|
||||
<Badge status="success" text="Imported" />
|
||||
) : (
|
||||
<Badge status="processing" text="Awaiting certificate" />
|
||||
)}
|
||||
</Descriptions.Item>
|
||||
{viewCsr.subject && Object.keys(viewCsr.subject).length > 0 && (
|
||||
<Descriptions.Item label="Subject" span={2}>
|
||||
{Object.entries(viewCsr.subject)
|
||||
.map(([k, v]) => `${k}=${v}`)
|
||||
.join(', ')}
|
||||
</Descriptions.Item>
|
||||
)}
|
||||
</Descriptions>
|
||||
|
||||
{Array.isArray(viewCsr.sans) && viewCsr.sans.length > 0 && (
|
||||
<div style={{ marginBottom: 12 }}>
|
||||
<Text strong>SANs: </Text>
|
||||
<Space size={4} wrap>
|
||||
{viewCsr.sans.map((d) => (
|
||||
<Tag key={d}>{d}</Tag>
|
||||
))}
|
||||
</Space>
|
||||
</div>
|
||||
)}
|
||||
|
||||
<Row justify="space-between" align="middle" style={{ marginBottom: 8 }}>
|
||||
<Col>
|
||||
<Text strong>CSR (PEM)</Text>
|
||||
</Col>
|
||||
<Col>
|
||||
<Space>
|
||||
<Button
|
||||
size="small"
|
||||
icon={<CopyOutlined />}
|
||||
onClick={() => copyCsrPem(viewCsr)}
|
||||
>
|
||||
Copy
|
||||
</Button>
|
||||
<Button
|
||||
size="small"
|
||||
type="primary"
|
||||
icon={<DownloadOutlined />}
|
||||
onClick={() => downloadCsrPem(viewCsr)}
|
||||
>
|
||||
Download .csr
|
||||
</Button>
|
||||
</Space>
|
||||
</Col>
|
||||
</Row>
|
||||
<TextArea
|
||||
value={viewCsr.csr_pem}
|
||||
rows={12}
|
||||
readOnly
|
||||
style={{ fontFamily: 'monospace', fontSize: 12 }}
|
||||
/>
|
||||
{viewCsr.status !== 'completed' && (
|
||||
<Alert
|
||||
type="info"
|
||||
showIcon
|
||||
style={{ marginTop: 12 }}
|
||||
message="Next step"
|
||||
description="Submit this CSR to your Certificate Authority. When you receive the signed certificate, come back and click Import on this CSR."
|
||||
/>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
</Modal>
|
||||
|
||||
{/* Import Signed Certificate Modal */}
|
||||
<Modal
|
||||
title={
|
||||
<Space>
|
||||
<ImportOutlined />
|
||||
{importCsr ? `Import Signed Certificate — ${importCsr.name}` : 'Import'}
|
||||
</Space>
|
||||
}
|
||||
open={!!importCsr}
|
||||
onCancel={() => {
|
||||
setImportCsr(null);
|
||||
importForm.resetFields();
|
||||
}}
|
||||
footer={null}
|
||||
width={800}
|
||||
>
|
||||
{importCsr && (
|
||||
<div>
|
||||
<Alert
|
||||
type="info"
|
||||
showIcon
|
||||
style={{ marginBottom: 16 }}
|
||||
message={`CSR: ${importCsr.name} (CN: ${importCsr.common_name})`}
|
||||
description="Paste the certificate your CA issued for this CSR. It will be verified against the stored private key before anything is saved."
|
||||
/>
|
||||
<Form
|
||||
form={importForm}
|
||||
layout="vertical"
|
||||
onFinish={handleImport}
|
||||
initialValues={{ ssl_type: 'cluster', usage_type: 'frontend' }}
|
||||
>
|
||||
<Row gutter={12}>
|
||||
<Col span={12}>
|
||||
<Form.Item
|
||||
name="usage_type"
|
||||
label="Usage Type"
|
||||
rules={[{ required: true }]}
|
||||
>
|
||||
<Select
|
||||
options={[
|
||||
{ value: 'frontend', label: 'Frontend SSL (HTTPS termination)' },
|
||||
{ value: 'server', label: 'Server SSL (backend verification)' },
|
||||
]}
|
||||
/>
|
||||
</Form.Item>
|
||||
</Col>
|
||||
<Col span={12}>
|
||||
<Form.Item name="ssl_type" label="Scope" rules={[{ required: true }]}>
|
||||
<Select
|
||||
options={[
|
||||
{ value: 'global', label: 'Global (all clusters)' },
|
||||
{ value: 'cluster', label: 'Cluster-specific' },
|
||||
]}
|
||||
/>
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
|
||||
<Form.Item
|
||||
noStyle
|
||||
shouldUpdate={(prev, cur) => prev.ssl_type !== cur.ssl_type}
|
||||
>
|
||||
{({ getFieldValue }) =>
|
||||
getFieldValue('ssl_type') === 'cluster' && (
|
||||
<Form.Item
|
||||
name="cluster_ids"
|
||||
label="Clusters"
|
||||
rules={[
|
||||
{ required: true, message: 'Select at least one cluster' },
|
||||
]}
|
||||
>
|
||||
<Select
|
||||
mode="multiple"
|
||||
placeholder="Select cluster(s)"
|
||||
options={(clusters || []).map((c) => ({
|
||||
value: c.id,
|
||||
label: c.name,
|
||||
}))}
|
||||
/>
|
||||
</Form.Item>
|
||||
)
|
||||
}
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="certificate_content"
|
||||
label="Signed Certificate (PEM)"
|
||||
rules={[
|
||||
{ required: true, message: 'Please paste the signed certificate' },
|
||||
{
|
||||
validator: (_, value) => {
|
||||
if (!value) return Promise.resolve();
|
||||
if (
|
||||
value.includes('-----BEGIN CERTIFICATE-----') &&
|
||||
value.includes('-----END CERTIFICATE-----')
|
||||
) {
|
||||
return Promise.resolve();
|
||||
}
|
||||
return Promise.reject(
|
||||
new Error('Certificate must be in PEM format')
|
||||
);
|
||||
},
|
||||
},
|
||||
]}
|
||||
>
|
||||
<TextArea
|
||||
rows={8}
|
||||
placeholder={'-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----'}
|
||||
style={{ fontFamily: 'monospace', fontSize: 12 }}
|
||||
/>
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="name_override"
|
||||
label="Certificate name override (optional)"
|
||||
rules={[
|
||||
{
|
||||
pattern: /^[a-zA-Z0-9_.-]+$/,
|
||||
message:
|
||||
'Only letters, digits, underscore, hyphen and dot are allowed',
|
||||
},
|
||||
{ max: 100, message: 'Name must be 100 characters or fewer' },
|
||||
]}
|
||||
extra={`Leave empty to use the CSR name ('${importCsr.name}'). Use this only if that name is now taken by another certificate.`}
|
||||
>
|
||||
<Input placeholder={importCsr.name} />
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item
|
||||
name="chain_content"
|
||||
label="Certificate Chain (PEM, optional)"
|
||||
rules={[
|
||||
{
|
||||
validator: (_, value) => {
|
||||
if (!value || !value.trim()) return Promise.resolve();
|
||||
if (
|
||||
value.includes('-----BEGIN CERTIFICATE-----') &&
|
||||
value.includes('-----END CERTIFICATE-----')
|
||||
) {
|
||||
return Promise.resolve();
|
||||
}
|
||||
return Promise.reject(
|
||||
new Error('Certificate chain must be in PEM format')
|
||||
);
|
||||
},
|
||||
},
|
||||
]}
|
||||
>
|
||||
<TextArea
|
||||
rows={4}
|
||||
placeholder={'-----BEGIN CERTIFICATE-----\n(intermediate CA)\n-----END CERTIFICATE-----'}
|
||||
style={{ fontFamily: 'monospace', fontSize: 12 }}
|
||||
/>
|
||||
</Form.Item>
|
||||
|
||||
<Form.Item style={{ textAlign: 'right', marginBottom: 0 }}>
|
||||
<Space>
|
||||
<Button
|
||||
onClick={() => {
|
||||
setImportCsr(null);
|
||||
importForm.resetFields();
|
||||
}}
|
||||
>
|
||||
Cancel
|
||||
</Button>
|
||||
<Button type="primary" htmlType="submit" loading={importing}>
|
||||
Import Certificate
|
||||
</Button>
|
||||
</Space>
|
||||
</Form.Item>
|
||||
</Form>
|
||||
</div>
|
||||
)}
|
||||
</Modal>
|
||||
</div>
|
||||
);
|
||||
};
|
||||
|
||||
export default CSRManagement;
|
||||
@@ -642,7 +642,11 @@ const FrontendManagement = () => {
|
||||
// Explicitly set options field to handle null/undefined case (NEW field)
|
||||
options: frontend.options || '',
|
||||
// BUGFIX: Explicitly set tcp_request_rules field to handle null/undefined case
|
||||
tcp_request_rules: frontend.tcp_request_rules || ''
|
||||
tcp_request_rules: frontend.tcp_request_rules || '',
|
||||
// Issue #38: SPOE filters + frontend log-format (null → '' so the
|
||||
// TextAreas populate on edit and round-trip on save, preventing null-wipe)
|
||||
log_format: frontend.log_format || '',
|
||||
filters: frontend.filters || ''
|
||||
});
|
||||
|
||||
// Update SSL field visibility after setting values
|
||||
@@ -862,31 +866,13 @@ const FrontendManagement = () => {
|
||||
return;
|
||||
}
|
||||
|
||||
// Phase K Phase D follow-up (Bulgu #12 round 3) — hard-gate any
|
||||
// ACL / use_backend / redirect rule that carries the unsupported
|
||||
// HAProxy `-f <file>` pattern-file flag. The Pydantic validator
|
||||
// on the backend (`models/frontend.py::validate_acl_rules`)
|
||||
// rejects the same shape; blocking here surfaces the error
|
||||
// immediately at the manual frontend form and matches the wizard
|
||||
// gate so operators see consistent behaviour between the two
|
||||
// entry points.
|
||||
const FILE_FLAG_RE = /(?:^|\s)-f(?:\s|$)/;
|
||||
const aclRulesAll = [
|
||||
...(aclBuilderData.aclRules || []),
|
||||
...(aclBuilderData.useBackendRules || []),
|
||||
...(aclBuilderData.redirectRules || []).map(
|
||||
(r) => (typeof r === 'string' ? r : ''),
|
||||
),
|
||||
];
|
||||
if (aclRulesAll.some((r) => typeof r === 'string' && FILE_FLAG_RE.test(r))) {
|
||||
message.error(
|
||||
'One or more ACL / routing / redirect rules use the unsupported HAProxy ' +
|
||||
'`-f <file>` pattern-file flag. HAProxy OpenManager does not provision ' +
|
||||
'pattern files onto the HAProxy node filesystem, so the reference would ' +
|
||||
'fail at reload time. Remove the `-f` flag and use inline values instead.'
|
||||
);
|
||||
return;
|
||||
}
|
||||
// Issue #38 follow-up — the Bulgu #12 client-side hard gate for
|
||||
// the ACL `-f <file>` pattern-file flag was removed together with
|
||||
// the server-side Pydantic rejects: pattern files are operator-
|
||||
// managed host files (same policy as SPOE filter configs since
|
||||
// v1.8.8) and the agent's pre-reload `haproxy -c` makes a missing
|
||||
// file fail safely. The server response now carries a non-blocking
|
||||
// warning listing the referenced files (rendered below).
|
||||
|
||||
// Phase K Phase D follow-up (Bulgu #13) — gate for
|
||||
// self-contradictory routing / redirect conditions (`X !X`).
|
||||
@@ -1178,8 +1164,31 @@ const FrontendManagement = () => {
|
||||
} else {
|
||||
message.success('Frontend created successfully');
|
||||
}
|
||||
|
||||
// Issue #38 follow-up — surface server-emitted warnings on
|
||||
// CREATE too (e.g. the `-f <file>` pattern-file advisory).
|
||||
// Mirrors the update-branch rendering above.
|
||||
const createWarnings = Array.isArray(response.data?.warnings)
|
||||
? response.data.warnings
|
||||
: [];
|
||||
if (createWarnings.length > 0) {
|
||||
message.warning(
|
||||
<div>
|
||||
<div><strong>Frontend saved, but the server flagged {createWarnings.length} rule warning(s):</strong></div>
|
||||
<div style={{ marginTop: 6, fontSize: '12px', fontFamily: 'monospace' }}>
|
||||
{createWarnings.slice(0, 5).map((w, i) => (
|
||||
<div key={i}>• {w.length > 240 ? `${w.slice(0, 237)}...` : w}</div>
|
||||
))}
|
||||
{createWarnings.length > 5 && (
|
||||
<div>(+{createWarnings.length - 5} more)</div>
|
||||
)}
|
||||
</div>
|
||||
</div>,
|
||||
10,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
setModalVisible(false);
|
||||
fetchFrontends();
|
||||
fetchSSLCertificates(); // Refresh SSL certificates after frontend update
|
||||
@@ -2250,6 +2259,40 @@ tcp-request connection reject if { src -f /etc/haproxy/blacklist.lst }`}
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
|
||||
{/* Issue #38: SPOE filters + frontend log-format */}
|
||||
<Row gutter={16}>
|
||||
<Col span={24}>
|
||||
<Form.Item
|
||||
name="filters"
|
||||
label="Filters (SPOE / WAF)"
|
||||
extra="HAProxy filter directives (one per line). Emitted before send-spoe-group rules."
|
||||
tooltip="e.g. Coraza WAF via SPOE. The referenced engine config file and its SPOA backend must exist on the HAProxy host."
|
||||
>
|
||||
<TextArea
|
||||
rows={3}
|
||||
placeholder={`Examples:
|
||||
filter spoe engine coraza config /etc/haproxy/coraza.cfg`}
|
||||
/>
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
|
||||
<Row gutter={16}>
|
||||
<Col span={24}>
|
||||
<Form.Item
|
||||
name="log_format"
|
||||
label="Custom Log Format"
|
||||
extra="HAProxy log-format / log-format-sd directive (kept verbatim)"
|
||||
tooltip="Overrides option httplog/tcplog. Use the full directive including the quoted format string."
|
||||
>
|
||||
<TextArea
|
||||
rows={3}
|
||||
placeholder={'log-format "%ci:%cp [%t] %ft %b/%s %ST %B %{+Q}r"'}
|
||||
/>
|
||||
</Form.Item>
|
||||
</Col>
|
||||
</Row>
|
||||
</Panel>
|
||||
</Collapse>
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@ import {
|
||||
PlayCircleOutlined, EditOutlined,
|
||||
CloudServerOutlined, CheckCircleOutlined, SyncOutlined,
|
||||
ExclamationCircleOutlined, CloseCircleOutlined, ClockCircleOutlined,
|
||||
ThunderboltOutlined
|
||||
ThunderboltOutlined, FileProtectOutlined
|
||||
} from '@ant-design/icons';
|
||||
import axios from 'axios';
|
||||
import { useSearchParams } from 'react-router-dom';
|
||||
@@ -22,6 +22,7 @@ import { useProgress } from '../contexts/ProgressContext';
|
||||
import { formatEntityForSync } from '../utils/agentSync';
|
||||
import { extractApiError } from '../utils/apiError';
|
||||
import ACMEAutomation from './ACMEAutomation';
|
||||
import CSRManagement from './CSRManagement';
|
||||
|
||||
const { Title, Text } = Typography;
|
||||
const { TextArea } = Input;
|
||||
@@ -643,12 +644,21 @@ const SSLManagement = () => {
|
||||
title: 'Source',
|
||||
dataIndex: 'source',
|
||||
key: 'source',
|
||||
render: (source) => (
|
||||
<Tag color={source === 'letsencrypt' ? 'green' : 'default'}
|
||||
icon={source === 'letsencrypt' ? <SafetyCertificateOutlined /> : null}>
|
||||
{source === 'letsencrypt' ? 'Auto (ACME)' : 'Manual'}
|
||||
</Tag>
|
||||
),
|
||||
render: (source) => {
|
||||
if (source === 'csr') {
|
||||
return (
|
||||
<Tag color="blue" icon={<FileProtectOutlined />}>
|
||||
CSR
|
||||
</Tag>
|
||||
);
|
||||
}
|
||||
return (
|
||||
<Tag color={source === 'letsencrypt' ? 'green' : 'default'}
|
||||
icon={source === 'letsencrypt' ? <SafetyCertificateOutlined /> : null}>
|
||||
{source === 'letsencrypt' ? 'Auto (ACME)' : 'Manual'}
|
||||
</Tag>
|
||||
);
|
||||
},
|
||||
},
|
||||
{
|
||||
title: 'Sync Status',
|
||||
@@ -1020,6 +1030,11 @@ const SSLManagement = () => {
|
||||
label: <span><ThunderboltOutlined /> ACME Automation</span>,
|
||||
children: <ACMEAutomation />,
|
||||
},
|
||||
{
|
||||
key: 'csr',
|
||||
label: <span><FileProtectOutlined /> CSR</span>,
|
||||
children: <CSRManagement onCertificateImported={fetchCertificates} />,
|
||||
},
|
||||
]}
|
||||
/>
|
||||
|
||||
|
||||
@@ -3177,36 +3177,15 @@ const SiteWizard = () => {
|
||||
);
|
||||
return;
|
||||
}
|
||||
// Phase K Phase D follow-up (Bulgu #12 round 3) —
|
||||
// hard-gate the Step 2 → Step 3 advance on any ACL
|
||||
// rule that carries the unsupported `-f <file>`
|
||||
// pattern-file flag. The Pydantic validator rejects
|
||||
// the same shape at submit, but blocking the Next
|
||||
// button here surfaces the error immediately at
|
||||
// its source step (the ACL builder is right above)
|
||||
// instead of bouncing the operator from Step 4's
|
||||
// dry-run card back to Step 2 with a less-specific
|
||||
// jumpback button. The ACLRuleBuilder ALSO renders
|
||||
// a section-level red Alert when this state is
|
||||
// active so the operator already sees what to fix.
|
||||
const FILE_FLAG_RE = /(?:^|\s)-f(?:\s|$)/;
|
||||
const aclRulesAll = [
|
||||
...(aclBuilderData.aclRules || []),
|
||||
...(aclBuilderData.useBackendRules || []),
|
||||
...(aclBuilderData.redirectRules || []).map(
|
||||
(r) => (typeof r === 'string' ? r : ''),
|
||||
),
|
||||
];
|
||||
if (aclRulesAll.some((r) => typeof r === 'string' && FILE_FLAG_RE.test(r))) {
|
||||
message.error(
|
||||
'One or more rules use the unsupported HAProxy `-f <file>` ' +
|
||||
'pattern-file flag. HAProxy OpenManager does not provision ' +
|
||||
'pattern files onto the HAProxy node filesystem, so the ' +
|
||||
'reference would fail at reload time. Remove the `-f` flag ' +
|
||||
'and use inline values instead before continuing.'
|
||||
);
|
||||
return;
|
||||
}
|
||||
// Issue #38 follow-up — the Bulgu #12 Step 2 → 3
|
||||
// hard gate for the ACL `-f <file>` pattern-file
|
||||
// flag was removed together with the server-side
|
||||
// Pydantic rejects: pattern files are operator-
|
||||
// managed host files (same policy as SPOE filter
|
||||
// configs since v1.8.8) and the agent's pre-reload
|
||||
// `haproxy -c` makes a missing file fail safely.
|
||||
// The ACLRuleBuilder renders an informational note
|
||||
// on `-f` rules instead of a blocking error.
|
||||
// Phase K Phase D follow-up (Bulgu #13) — block
|
||||
// advance when any routing / redirect rule has a
|
||||
// self-contradictory condition (`acl1 !acl1`).
|
||||
|
||||
@@ -22,7 +22,7 @@ spec:
|
||||
serviceAccountName: haproxy-openmanager-redis
|
||||
containers:
|
||||
- name: redis
|
||||
image: redis:7-alpine
|
||||
image: redis:8.8.0-alpine
|
||||
command:
|
||||
- redis-server
|
||||
- /usr/local/etc/redis/redis.conf
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
{
|
||||
"version": "1.8.2",
|
||||
"releaseName": "ACME nonce fix (ZeroSSL registration)",
|
||||
"releaseDate": "2026-06-25"
|
||||
}
|
||||
Reference in New Issue
Block a user