diff --git a/.DEBIAN/env.default b/.DEBIAN/env.default new file mode 100644 index 0000000..835f29e --- /dev/null +++ b/.DEBIAN/env.default @@ -0,0 +1,27 @@ +# Toggle debug mode +#DEBUG=false + +# Where the client can find the DLS server +DLS_URL=127.0.0.1 +DLS_PORT=443 + +# CORS configuration +## comma separated list without spaces +#CORS_ORIGINS="https://$DLS_URL:$DLS_PORT" + +# Lease expiration in days +LEASE_EXPIRE_DAYS=90 +LEASE_RENEWAL_PERIOD=0.2 + +# Database location +## https://docs.sqlalchemy.org/en/14/core/engines.html +DATABASE=sqlite:////etc/fastapi-dls/db.sqlite + +# UUIDs for identifying the instance +#SITE_KEY_XID="00000000-0000-0000-0000-000000000000" +#INSTANCE_REF="10000000-0000-0000-0000-000000000001" +#ALLOTMENT_REF="20000000-0000-0000-0000-000000000001" + +# Site-wide signing keys +INSTANCE_KEY_RSA=/etc/fastapi-dls/instance.private.pem +INSTANCE_KEY_PUB=/etc/fastapi-dls/instance.public.pem diff --git a/.DEBIAN/fastapi-dls.service b/.DEBIAN/fastapi-dls.service new file mode 100644 index 0000000..368d494 --- /dev/null +++ b/.DEBIAN/fastapi-dls.service @@ -0,0 +1,25 @@ +[Unit] +Description=Service for fastapi-dls +Documentation=https://git.collinwebdesigns.de/oscar.krause/fastapi-dls +After=network.target + +[Service] +User=www-data +Group=www-data +AmbientCapabilities=CAP_NET_BIND_SERVICE +WorkingDirectory=/usr/share/fastapi-dls/app +EnvironmentFile=/etc/fastapi-dls/env +ExecStart=uvicorn main:app \ + --env-file /etc/fastapi-dls/env \ + --host $DLS_URL --port $DLS_PORT \ + --app-dir /usr/share/fastapi-dls/app \ + --ssl-keyfile /etc/fastapi-dls/webserver.key \ + --ssl-certfile /etc/fastapi-dls/webserver.crt \ + --proxy-headers +Restart=always +KillSignal=SIGQUIT +Type=simple +NotifyAccess=all + +[Install] +WantedBy=multi-user.target diff --git a/.DEBIAN/postinst b/.DEBIAN/postinst index d4ceee0..fbf9b82 100644 --- a/.DEBIAN/postinst +++ b/.DEBIAN/postinst @@ -3,89 +3,26 @@ WORKING_DIR=/usr/share/fastapi-dls CONFIG_DIR=/etc/fastapi-dls -echo "> Create config directory ..." -mkdir -p $CONFIG_DIR - -# normally we would define services in `conffiles` and as separate file, but we like to keep thinks simple. -echo "> Install service ..." -cat </etc/systemd/system/fastapi-dls.service -[Unit] -Description=Service for fastapi-dls -Documentation=https://git.collinwebdesigns.de/oscar.krause/fastapi-dls -After=network.target - -[Service] -User=www-data -Group=www-data -AmbientCapabilities=CAP_NET_BIND_SERVICE -WorkingDirectory=$WORKING_DIR/app -EnvironmentFile=$CONFIG_DIR/env -ExecStart=uvicorn main:app \\ - --env-file /etc/fastapi-dls/env \\ - --host \$DLS_URL --port \$DLS_PORT \\ - --app-dir $WORKING_DIR/app \\ - --ssl-keyfile /etc/fastapi-dls/webserver.key \\ - --ssl-certfile /etc/fastapi-dls/webserver.crt \\ - --proxy-headers -Restart=always -KillSignal=SIGQUIT -Type=simple -NotifyAccess=all - -[Install] -WantedBy=multi-user.target - -EOF - -systemctl daemon-reload - -# normally we would define configfiles in `conffiles` and as separate file, but we like to keep thinks simple. -if [[ ! -f $CONFIG_DIR/env ]]; then - echo "> Writing initial config ..." - touch $CONFIG_DIR/env - cat <$CONFIG_DIR/env -# Toggle debug mode -#DEBUG=false - -# Where the client can find the DLS server -DLS_URL=127.0.0.1 -DLS_PORT=443 - -# CORS configuration -## comma separated list without spaces -#CORS_ORIGINS="https://$DLS_URL:$DLS_PORT" - -# Lease expiration in days -LEASE_EXPIRE_DAYS=90 - -# Database location -## https://docs.sqlalchemy.org/en/14/core/engines.html -DATABASE=sqlite:///$CONFIG_DIR/db.sqlite - -# UUIDs for identifying the instance -#SITE_KEY_XID="00000000-0000-0000-0000-000000000000" -#INSTANCE_REF="00000000-0000-0000-0000-000000000000" - -# Site-wide signing keys -INSTANCE_KEY_RSA=$CONFIG_DIR/instance.private.pem -INSTANCE_KEY_PUB=$CONFIG_DIR/instance.public.pem - -EOF +if [[ ! -f $CONFIG_DIR/instance.private.pem ]]; then + echo "> Create dls-instance keypair ..." + openssl genrsa -out $CONFIG_DIR/instance.private.pem 2048 + openssl rsa -in $CONFIG_DIR/instance.private.pem -outform PEM -pubout -out $CONFIG_DIR/instance.public.pem +else + echo "> Create dls-instance keypair skipped! (exists)" fi -echo "> Create dls-instance keypair ..." -openssl genrsa -out $CONFIG_DIR/instance.private.pem 2048 -openssl rsa -in $CONFIG_DIR/instance.private.pem -outform PEM -pubout -out $CONFIG_DIR/instance.public.pem - while true; do - read -p "> Do you wish to create self-signed webserver certificate? [Y/n]" yn - yn=${yn:-y} # ${parameter:-word} If parameter is unset or null, the expansion of word is substituted. Otherwise, the value of parameter is substituted. + [[ -f $CONFIG_DIR/webserver.key ]] && default_answer="N" || default_answer="Y" + [[ $default_answer == "Y" ]] && V="Y/n" || V="y/N" + read -p "> Do you wish to create self-signed webserver certificate? [${V}]" yn + yn=${yn:-$default_answer} # ${parameter:-word} If parameter is unset or null, the expansion of word is substituted. Otherwise, the value of parameter is substituted. case $yn in [Yy]*) + echo "> Generating keypair ..." openssl req -x509 -nodes -days 3650 -newkey rsa:2048 -keyout $CONFIG_DIR/webserver.key -out $CONFIG_DIR/webserver.crt break ;; - [Nn]*) break ;; + [Nn]*) echo "> Generating keypair skipped! (exists)"; break ;; *) echo "Please answer [y] or [n]." ;; esac done @@ -115,7 +52,7 @@ cat < [ origin ]: {origin_ref}: {j}') @@ -256,13 +256,13 @@ async def auth_v1_origin(request: Request): "sync_timestamp": cur_time.isoformat() } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_auth/test/test_origins_controller.py @app.post('/auth/v1/origin/update', description='update an origin evidence') async def auth_v1_origin_update(request: Request): - j, cur_time = json.loads((await request.body()).decode('utf-8')), datetime.utcnow() + j, cur_time = json_loads((await request.body()).decode('utf-8')), datetime.utcnow() origin_ref = j.get('origin_ref') logging.info(f'> [ update ]: {origin_ref}: {j}') @@ -282,14 +282,14 @@ async def auth_v1_origin_update(request: Request): "sync_timestamp": cur_time.isoformat() } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_auth/test/test_auth_controller.py # venv/lib/python3.9/site-packages/nls_core_auth/auth.py - CodeResponse @app.post('/auth/v1/code', description='get an authorization code') async def auth_v1_code(request: Request): - j, cur_time = json.loads((await request.body()).decode('utf-8')), datetime.utcnow() + j, cur_time = json_loads((await request.body()).decode('utf-8')), datetime.utcnow() origin_ref = j.get('origin_ref') logging.info(f'> [ code ]: {origin_ref}: {j}') @@ -314,22 +314,27 @@ async def auth_v1_code(request: Request): "prompts": None } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_auth/test/test_auth_controller.py # venv/lib/python3.9/site-packages/nls_core_auth/auth.py - TokenResponse @app.post('/auth/v1/token', description='exchange auth code and verifier for token') async def auth_v1_token(request: Request): - j, cur_time = json.loads((await request.body()).decode('utf-8')), datetime.utcnow() - payload = jwt.decode(token=j.get('auth_code'), key=jwt_decode_key) + j, cur_time = json_loads((await request.body()).decode('utf-8')), datetime.utcnow() + + try: + payload = jwt.decode(token=j.get('auth_code'), key=jwt_decode_key) + except JWTError as e: + return JSONr(status_code=400, content={'status': 400, 'title': 'invalid token', 'detail': str(e)}) origin_ref = payload.get('origin_ref') logging.info(f'> [ auth ]: {origin_ref}: {j}') # validate the code challenge - if payload.get('challenge') != b64enc(sha256(j.get('code_verifier').encode('utf-8')).digest()).rstrip(b'=').decode('utf-8'): - raise HTTPException(status_code=401, detail='expected challenge did not match verifier') + challenge = b64enc(sha256(j.get('code_verifier').encode('utf-8')).digest()).rstrip(b'=').decode('utf-8') + if payload.get('challenge') != challenge: + return JSONr(status_code=401, content={'status': 401, 'detail': 'expected challenge did not match verifier'}) access_expires_on = cur_time + TOKEN_EXPIRE_DELTA @@ -352,13 +357,18 @@ async def auth_v1_token(request: Request): "sync_timestamp": cur_time.isoformat(), } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_lease/test/test_lease_multi_controller.py @app.post('/leasing/v1/lessor', description='request multiple leases (borrow) for current origin') async def leasing_v1_lessor(request: Request): - j, token, cur_time = json.loads((await request.body()).decode('utf-8')), __get_token(request), datetime.utcnow() + j, token, cur_time = json_loads((await request.body()).decode('utf-8')), __get_token(request), datetime.utcnow() + + try: + token = __get_token(request) + except JWTError: + return JSONr(status_code=401, content={'status': 401, 'detail': 'token is not valid'}) origin_ref = token.get('origin_ref') scope_ref_list = j.get('scope_ref_list') @@ -367,7 +377,7 @@ async def leasing_v1_lessor(request: Request): lease_result_list = [] for scope_ref in scope_ref_list: # if scope_ref not in [ALLOTMENT_REF]: - # raise HTTPException(status_code=500, detail=f'no service instances found for scopes: ["{scope_ref}"]') + # return JSONr(status_code=500, detail=f'no service instances found for scopes: ["{scope_ref}"]') lease_ref = str(uuid4()) expires = cur_time + LEASE_EXPIRE_DELTA @@ -394,7 +404,7 @@ async def leasing_v1_lessor(request: Request): "prompts": None } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_lease/test/test_lease_multi_controller.py @@ -414,7 +424,7 @@ async def leasing_v1_lessor_lease(request: Request): "prompts": None } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_lease/test/test_lease_single_controller.py @@ -428,7 +438,7 @@ async def leasing_v1_lease_renew(request: Request, lease_ref: str): entity = Lease.find_by_origin_ref_and_lease_ref(db, origin_ref, lease_ref) if entity is None: - raise HTTPException(status_code=404, detail='requested lease not available') + return JSONr(status_code=404, content={'status': 404, 'detail': 'requested lease not available'}) expires = cur_time + LEASE_EXPIRE_DELTA response = { @@ -442,7 +452,7 @@ async def leasing_v1_lease_renew(request: Request, lease_ref: str): Lease.renew(db, entity, expires, cur_time) - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_lease/test/test_lease_single_controller.py @@ -455,12 +465,12 @@ async def leasing_v1_lease_delete(request: Request, lease_ref: str): entity = Lease.find_by_lease_ref(db, lease_ref) if entity.origin_ref != origin_ref: - raise HTTPException(status_code=403, detail='access or operation forbidden') + return JSONr(status_code=403, content={'status': 403, 'detail': 'access or operation forbidden'}) if entity is None: - raise HTTPException(status_code=404, detail='requested lease not available') + return JSONr(status_code=404, content={'status': 404, 'detail': 'requested lease not available'}) if Lease.delete(db, lease_ref) == 0: - raise HTTPException(status_code=404, detail='lease not found') + return JSONr(status_code=404, content={'status': 404, 'detail': 'lease not found'}) response = { "lease_ref": lease_ref, @@ -468,7 +478,7 @@ async def leasing_v1_lease_delete(request: Request, lease_ref: str): "sync_timestamp": cur_time.isoformat(), } - return JSONResponse(response) + return JSONr(response) # venv/lib/python3.9/site-packages/nls_services_lease/test/test_lease_multi_controller.py @@ -489,12 +499,12 @@ async def leasing_v1_lessor_lease_remove(request: Request): "prompts": None } - return JSONResponse(response) + return JSONr(response) @app.post('/leasing/v1/lessor/shutdown', description='shutdown all leases') async def leasing_v1_lessor_shutdown(request: Request): - j, cur_time = json.loads((await request.body()).decode('utf-8')), datetime.utcnow() + j, cur_time = json_loads((await request.body()).decode('utf-8')), datetime.utcnow() token = j.get('token') token = jwt.decode(token=token, key=jwt_decode_key, algorithms=ALGORITHMS.RS256, options={'verify_aud': False}) @@ -511,7 +521,7 @@ async def leasing_v1_lessor_shutdown(request: Request): "prompts": None } - return JSONResponse(response) + return JSONr(response) if __name__ == '__main__': diff --git a/docker-compose.yml b/docker-compose.yml index 77dcc07..2ebd525 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,7 +1,7 @@ version: '3.9' x-dls-variables: &dls-variables - DLS_URL: localhost # REQUIRED + DLS_URL: localhost # REQUIRED, change to your ip or hostname DLS_PORT: 443 # must match nginx listen port LEASE_EXPIRE_DAYS: 90 DATABASE: sqlite:////app/database/db.sqlite