Commit Graph

181 Commits

Author SHA1 Message Date
Andrew Martinez b562fb5c07 splits API specs into composible modules
- splits Open API 2.0 (swagger) into client/management APIs
- uses go-swaggers flatten capabilities
- uses newer version of go-swagger (v0.27.0)
- introduces /edge/client/v1, /edge/management/v1
- non-prefixed URLs default to /edge/client/v1
- splits some shared management/client API handlers
- renames some REST models to "client" instead of "limited"
- passes all apitests, fails dataflow upd test (main fails this as well)
- updates generate rest script for powershell
- todo: test generate rest script for bash
- todo: use xweb (different branch)
2021-05-04 11:30:32 -04:00
Andrew Martinez 54af8801e7 adds posture check type PROCESS_MULTI
- adds a new posture check for dealing with multiple processes
- supports anyOf and allOf semantics
- does not require new posture responses, current process responses
  suffice
- tests
2021-04-20 08:52:23 -04:00
Andrew Martinez 4a9b226f0e adds the ability for router to extend their enrollment
- routers can now opt to extend their enrollment at any time with a
  previous or new key
- adds tests for router enrollment
- adds tests for router enrollment extension
2021-04-14 09:21:59 -04:00
Andrew Martinez b278f611d0 add policyType to posture query sets
- also fixes policy ids being set as the same value due to pointer in
  for loop reference
2021-04-13 15:26:17 -04:00
Paul Lorenz b493cce490 Add app data to identity and edge router. Add isSystem to ERP 2021-04-06 10:07:57 -04:00
Paul Lorenz 8f6234842e Add per-service identity hosting precedence/costs 2021-04-06 09:51:22 -04:00
Andrew Martinez a753022e37 unify api session modeling 2021-03-24 13:51:26 -04:00
Andrew Martinez 1100d6f388 update service update on posture data change, tests 2021-03-23 09:54:47 -04:00
Andrew Martinez 993f51f7ab set mfa posture on enroll
- update api session session state on mfa enroll
- update posture data state on mfa enroll
- centralize setting mfa posture data
- pass isMfaRequired and isMfaComplete in apiSession/currentApiSession
2021-03-23 09:54:46 -04:00
Paul Lorenz 680852f80e Allow tunnel to run over xgress directly 2021-03-22 14:33:54 -04:00
Andrew Martinez 5449b655b8 moves posture-data/failed-service-requests
- GET /identities/{id}/posture-data/failed-service-requests is now under
  /identities/{id}/failed-service-requests
2021-03-19 10:30:26 -04:00
Andrew Martinez c54a007202 formalize posture data API output, add service request errors
- GET /identity/{id}/posture-data is now formalized in the swagger.yml
- posture data output now includes the last 100 failed service requests
  with temporal posture data state
- added ziti controller instance id header to detect restarts
- add GET /identity/{id}/failed-service-requests
2021-03-19 09:49:44 -04:00
Andrew Martinez 7e559771f3 fixed cachedLastActivityAt 2021-03-19 09:10:23 -04:00
Andrew Martinez fccdc0591e fix expiresAt and expirationSeconds 2021-03-19 08:59:50 -04:00
Andrew Martinez 623681db87 add lastActivityAt
- as updates to API Sessions can now happen later than the last time
  they were active, updatedAt is no longer the correct representation of
  the last activity an API Session had
- move all logic that used updatedAt to lastActivityAt
- add migration to set lastActivityAt
2021-03-17 13:49:12 -04:00
Paul Lorenz 71a3a1643e Pass FieldChecker to toBoltEntityForPatch. Add some ReadByName methods. Move some code to allow re-use 2021-03-17 10:41:21 -04:00
Andrew Martinez 4dba6e95ab on invalid token ignore and check bool status only 2021-03-11 13:33:51 -05:00
Andrew Martinez 90ca54adb8 adds thread safe router state
Router state used to be stored and accessed in a thread unsafe way.
State is now locks on a mutex for setting values and values are copied
out for referencing.
2021-03-08 14:55:36 -05:00
Andrew Martinez 1b253839fc Merge branch 'main' into add.session.route 2021-03-04 09:47:10 -05:00
Andrew Martinez 5eb8649186 move routePath to /sessions/id/route-path 2021-03-04 09:44:12 -05:00
Paul Lorenz 735eb1d80f Move ApiError and FieldError to foundation 2021-03-03 14:44:26 -05:00
Andrew Martinez 005234cb39 add route path to session 2021-03-01 18:02:25 -05:00
Andrew Martinez 7e60583043 fix swagger parameter names, allow mfa codes on headers for get/delete
- swagger copy pasta was using the same parameter name for everything,
  "body", which made error messages read "error in body for body"
- parameter rename ripples into parameter property definitions
- allow mfa codes in GET and DELETe as libuv doesn't allow them to have
  bodies (-.-)
2021-02-25 14:23:12 -05:00
Andrew Martinez 75029f8600 centralize edge router properties, add supportedProtocols to edge
session

- centralized edge router properties so adding/altering affects all
  edge router output
- adds supportedProtocols to edge session create response
- mark urls on edge session create response as deprecated
2021-02-23 15:07:43 -05:00
Andrew Martinez a51cf270f2 ignore duplicate connecting routers, do not dereference er hostnames
hostnames may be a nil pointer at times now due to the fact that edge
routers may be waiting to sync and may be "online" but edge hellos
have not been exchanged.
2021-02-19 10:19:26 -05:00
Andrew Martinez d07618c9d5 modular edge router sync
- edge router sync is now modular and can have different strategies
- plans to make this configurabe in the future with multiple strat
- legacy strategy is called "instant" and is the only option
- instant strat now supports control signaling and resync requests
- edge routers now do not remove connections till after a full sync
- added the ability for the controller to report the er sync status
- added er syn status to GET /edge-routers list and detail
- improved log output in sync logic
2021-02-15 13:22:07 -05:00
Andrew Martinez 6a2c82deca add timeout posture query property, -1 == no timeout
Provides a location for future configurable timeouts and allows
SDKs to detect whether no timeout/timeouts are supported.
2021-02-10 17:13:23 -05:00
Andrew Martinez 5b5fe97961 fix ptr to string in error message 2021-02-09 14:01:20 -05:00
Andrew Martinez 9fab8e6ed0 fix formatting message
Some deps altered after a go test ./... and go mod tidy
2021-02-09 13:57:49 -05:00
Andrew Martinez 46166db9cc fixes orphaned ottca enrollments
- deletes ottca enrollment when CA is deleted
- adds API tests
- adds migration to remove currently orphaned ottca enrollments
- migration tested on a v15 database with orphaned ottca enrollments
2021-02-09 13:55:03 -05:00
Andrew 18513f7ee4 Merge pull request #504 from openziti/api.session.performance
moves hasApiSession lookup to api model and limit 1
2021-02-04 09:32:01 -05:00
Andrew Martinez 65832b8da5 fix missing formatted log call, spelling 2021-02-04 09:24:00 -05:00
Andrew Martinez e34d25b0dd fixes #484 adds current identity edge router lookup 2021-02-03 15:37:15 -05:00
Andrew Martinez 5c47c31016 moves hasApiSession lookup to api model and limit 1
This move isolates the cost of hasApiSession to the identity endpoint
lookups in the REST API. Being in the model caused this cost to be
shared on all identity lookups for internal logic.

Limit 1 is an attempt to reduce the cost of searching over a large set.
API Sessions do not have an index on identity id so there is still some
cost.
2021-02-03 14:01:53 -05:00
Andrew 5de4d629f3 Merge pull request #498 from openziti/add.server.header
fixes #497 send session header
2021-02-01 15:07:24 -05:00
Andrew Martinez df1f2a1a75 fixes #497 send session header
- add server headers during HTTP handler delegation rather than at HTTP
  response time
- remove all old header setting locations
- remove unused status writer and other response code
- add manual set on authentication for session headers
2021-02-01 14:28:29 -05:00
Andrew Martinez cab720ed47 limit public query options to 500 whe "none" is specified 2021-02-01 09:27:55 -05:00
Andrew Martinez 252e105f3c add typeId to authQuery 2021-01-26 15:12:22 -05:00
Andrew Martinez 4051c47dd5 Merge branch 'main' into mfa 2021-01-26 13:52:59 -05:00
Andrew 5e5aa87c39 Merge pull request #485 from openziti/bulk.posture.response
bulk posture response endpoint
2021-01-26 09:11:27 -05:00
Andrew Martinez f2431ab9b3 bulk posture response 2021-01-25 13:55:41 -05:00
Paul Lorenz e1e31c2ecb Fix edge-router association lists 2021-01-23 14:54:03 -05:00
Andrew 8d4397c0d9 Merge pull request #474 from openziti/fix.misspelled.builddate
fixes buildDate spelling (missing d)
2021-01-20 10:44:57 -05:00
Paul Lorenz f5dc8e5799 Fix return status 2021-01-20 10:12:39 -05:00
Paul Lorenz 4882da1970 Add service list timer. Fix tunneler leak 2021-01-20 09:29:33 -05:00
Paul Lorenz 744fa99b8a Add check integrity guardrails so we can only run a single operation at a time 2021-01-19 16:18:10 -05:00
Andrew Martinez 4fbacdcdc8 fixes buildDate spelling (missing d) 2021-01-19 14:00:50 -05:00
Andrew Martinez 2d61799c24 add posture check MFA tests 2021-01-19 08:37:29 -05:00
Andrew Martinez 308d7f3a10 mfa initial
- add mfa read endpoints
- add mfa enroll enpoints
- fix mfa library timing issues
- adds mfa at tests
- adds admin mfa management endpoints
- adds admin mfa at tests
- improve at tests
- fix auth check vs auth query
- fix swagger for auth queryies
- fix swagger doc
- adds more api tests for validation
- redo auth query structure
- redo mfa endpoints
- move mfa verify to authenticate router:wq
- add recovery code support and tests
- add partial session authentication status
2021-01-19 08:36:27 -05:00
Andrew Martinez 65be49c609 Add appId and appVersion to sdkInfo 2021-01-18 10:38:43 -05:00