adding pods method of package managing
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2015 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_AUTH_CONTEXT_H
|
||||
#define GRPCPP_SECURITY_AUTH_CONTEXT_H
|
||||
|
||||
#include <grpcpp/impl/codegen/security/auth_context.h>
|
||||
|
||||
#endif // GRPCPP_SECURITY_AUTH_CONTEXT_H
|
||||
@@ -0,0 +1,30 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2019 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_H
|
||||
#define GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_H
|
||||
|
||||
#include <grpcpp/security/auth_metadata_processor_impl.h>
|
||||
|
||||
namespace grpc {
|
||||
|
||||
typedef ::grpc_impl::AuthMetadataProcessor AuthMetadataProcessor;
|
||||
|
||||
} // namespace grpc
|
||||
|
||||
#endif // GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_H
|
||||
@@ -0,0 +1,61 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2015 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_IMPL_H
|
||||
#define GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_IMPL_H
|
||||
|
||||
#include <map>
|
||||
|
||||
#include <grpcpp/security/auth_context.h>
|
||||
#include <grpcpp/support/status.h>
|
||||
#include <grpcpp/support/string_ref.h>
|
||||
|
||||
namespace grpc_impl {
|
||||
|
||||
/// Interface allowing custom server-side authorization based on credentials
|
||||
/// encoded in metadata. Objects of this type can be passed to
|
||||
/// \a ServerCredentials::SetAuthMetadataProcessor().
|
||||
class AuthMetadataProcessor {
|
||||
public:
|
||||
typedef std::multimap<grpc::string_ref, grpc::string_ref> InputMetadata;
|
||||
typedef std::multimap<grpc::string, grpc::string> OutputMetadata;
|
||||
|
||||
virtual ~AuthMetadataProcessor() {}
|
||||
|
||||
/// If this method returns true, the \a Process function will be scheduled in
|
||||
/// a different thread from the one processing the call.
|
||||
virtual bool IsBlocking() const { return true; }
|
||||
|
||||
/// context is read/write: it contains the properties of the channel peer and
|
||||
/// it is the job of the Process method to augment it with properties derived
|
||||
/// from the passed-in auth_metadata.
|
||||
/// consumed_auth_metadata needs to be filled with metadata that has been
|
||||
/// consumed by the processor and will be removed from the call.
|
||||
/// response_metadata is the metadata that will be sent as part of the
|
||||
/// response.
|
||||
/// If the return value is not Status::OK, the rpc call will be aborted with
|
||||
/// the error code and error message sent back to the client.
|
||||
virtual grpc::Status Process(const InputMetadata& auth_metadata,
|
||||
grpc::AuthContext* context,
|
||||
OutputMetadata* consumed_auth_metadata,
|
||||
OutputMetadata* response_metadata) = 0;
|
||||
};
|
||||
|
||||
} // namespace grpc_impl
|
||||
|
||||
#endif // GRPCPP_SECURITY_AUTH_METADATA_PROCESSOR_IMPL_H
|
||||
+143
@@ -0,0 +1,143 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2015 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_CREDENTIALS_H
|
||||
#define GRPCPP_SECURITY_CREDENTIALS_H
|
||||
|
||||
#include <grpcpp/security/credentials_impl.h>
|
||||
|
||||
namespace grpc {
|
||||
|
||||
typedef ::grpc_impl::ChannelCredentials ChannelCredentials;
|
||||
typedef ::grpc_impl::CallCredentials CallCredentials;
|
||||
typedef ::grpc_impl::SslCredentialsOptions SslCredentialsOptions;
|
||||
typedef ::grpc_impl::SecureCallCredentials SecureCallCredentials;
|
||||
typedef ::grpc_impl::SecureChannelCredentials SecureChannelCredentials;
|
||||
typedef ::grpc_impl::MetadataCredentialsPlugin MetadataCredentialsPlugin;
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::ChannelCredentials>
|
||||
GoogleDefaultCredentials() {
|
||||
return ::grpc_impl::GoogleDefaultCredentials();
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<ChannelCredentials> SslCredentials(
|
||||
const SslCredentialsOptions& options) {
|
||||
return ::grpc_impl::SslCredentials(options);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
GoogleComputeEngineCredentials() {
|
||||
return ::grpc_impl::GoogleComputeEngineCredentials();
|
||||
}
|
||||
|
||||
/// Constant for maximum auth token lifetime.
|
||||
constexpr long kMaxAuthTokenLifetimeSecs =
|
||||
::grpc_impl::kMaxAuthTokenLifetimeSecs;
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
ServiceAccountJWTAccessCredentials(
|
||||
const grpc::string& json_key,
|
||||
long token_lifetime_seconds = grpc::kMaxAuthTokenLifetimeSecs) {
|
||||
return ::grpc_impl::ServiceAccountJWTAccessCredentials(
|
||||
json_key, token_lifetime_seconds);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
GoogleRefreshTokenCredentials(const grpc::string& json_refresh_token) {
|
||||
return ::grpc_impl::GoogleRefreshTokenCredentials(json_refresh_token);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
AccessTokenCredentials(const grpc::string& access_token) {
|
||||
return ::grpc_impl::AccessTokenCredentials(access_token);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials> GoogleIAMCredentials(
|
||||
const grpc::string& authorization_token,
|
||||
const grpc::string& authority_selector) {
|
||||
return ::grpc_impl::GoogleIAMCredentials(authorization_token,
|
||||
authority_selector);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<ChannelCredentials> CompositeChannelCredentials(
|
||||
const std::shared_ptr<ChannelCredentials>& channel_creds,
|
||||
const std::shared_ptr<CallCredentials>& call_creds) {
|
||||
return ::grpc_impl::CompositeChannelCredentials(channel_creds, call_creds);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
CompositeCallCredentials(const std::shared_ptr<CallCredentials>& creds1,
|
||||
const std::shared_ptr<CallCredentials>& creds2) {
|
||||
return ::grpc_impl::CompositeCallCredentials(creds1, creds2);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::ChannelCredentials>
|
||||
InsecureChannelCredentials() {
|
||||
return ::grpc_impl::InsecureChannelCredentials();
|
||||
}
|
||||
|
||||
typedef ::grpc_impl::MetadataCredentialsPlugin MetadataCredentialsPlugin;
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials>
|
||||
MetadataCredentialsFromPlugin(
|
||||
std::unique_ptr<MetadataCredentialsPlugin> plugin) {
|
||||
return ::grpc_impl::MetadataCredentialsFromPlugin(std::move(plugin));
|
||||
}
|
||||
|
||||
namespace experimental {
|
||||
|
||||
typedef ::grpc_impl::experimental::StsCredentialsOptions StsCredentialsOptions;
|
||||
|
||||
static inline grpc::Status StsCredentialsOptionsFromJson(
|
||||
const grpc::string& json_string, StsCredentialsOptions* options) {
|
||||
return ::grpc_impl::experimental::StsCredentialsOptionsFromJson(json_string,
|
||||
options);
|
||||
}
|
||||
|
||||
static inline grpc::Status StsCredentialsOptionsFromEnv(
|
||||
StsCredentialsOptions* options) {
|
||||
return grpc_impl::experimental::StsCredentialsOptionsFromEnv(options);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::CallCredentials> StsCredentials(
|
||||
const StsCredentialsOptions& options) {
|
||||
return grpc_impl::experimental::StsCredentials(options);
|
||||
}
|
||||
|
||||
typedef ::grpc_impl::experimental::AltsCredentialsOptions
|
||||
AltsCredentialsOptions;
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::ChannelCredentials> AltsCredentials(
|
||||
const AltsCredentialsOptions& options) {
|
||||
return ::grpc_impl::experimental::AltsCredentials(options);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::ChannelCredentials> LocalCredentials(
|
||||
grpc_local_connect_type type) {
|
||||
return ::grpc_impl::experimental::LocalCredentials(type);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<grpc_impl::ChannelCredentials> TlsCredentials(
|
||||
const ::grpc_impl::experimental::TlsCredentialsOptions& options) {
|
||||
return ::grpc_impl::experimental::TlsCredentials(options);
|
||||
}
|
||||
|
||||
} // namespace experimental
|
||||
} // namespace grpc
|
||||
|
||||
#endif // GRPCPP_SECURITY_CREDENTIALS_H
|
||||
@@ -0,0 +1,351 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2015 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_CREDENTIALS_IMPL_H
|
||||
#define GRPCPP_SECURITY_CREDENTIALS_IMPL_H
|
||||
|
||||
#include <map>
|
||||
#include <memory>
|
||||
#include <vector>
|
||||
|
||||
#include <grpc/grpc_security_constants.h>
|
||||
#include <grpcpp/channel_impl.h>
|
||||
#include <grpcpp/impl/codegen/client_interceptor.h>
|
||||
#include <grpcpp/impl/codegen/grpc_library.h>
|
||||
#include <grpcpp/security/auth_context.h>
|
||||
#include <grpcpp/security/tls_credentials_options.h>
|
||||
#include <grpcpp/support/channel_arguments_impl.h>
|
||||
#include <grpcpp/support/status.h>
|
||||
#include <grpcpp/support/string_ref.h>
|
||||
|
||||
struct grpc_call;
|
||||
|
||||
namespace grpc_impl {
|
||||
|
||||
class ChannelCredentials;
|
||||
class CallCredentials;
|
||||
class SecureCallCredentials;
|
||||
class SecureChannelCredentials;
|
||||
|
||||
std::shared_ptr<Channel> CreateCustomChannelImpl(
|
||||
const grpc::string& target,
|
||||
const std::shared_ptr<ChannelCredentials>& creds,
|
||||
const ChannelArguments& args);
|
||||
|
||||
namespace experimental {
|
||||
std::shared_ptr<Channel> CreateCustomChannelWithInterceptors(
|
||||
const grpc::string& target,
|
||||
const std::shared_ptr<ChannelCredentials>& creds,
|
||||
const ChannelArguments& args,
|
||||
std::vector<
|
||||
std::unique_ptr<grpc::experimental::ClientInterceptorFactoryInterface>>
|
||||
interceptor_creators);
|
||||
}
|
||||
|
||||
/// A channel credentials object encapsulates all the state needed by a client
|
||||
/// to authenticate with a server for a given channel.
|
||||
/// It can make various assertions, e.g., about the client’s identity, role
|
||||
/// for all the calls on that channel.
|
||||
///
|
||||
/// \see https://grpc.io/docs/guides/auth.html
|
||||
class ChannelCredentials : private grpc::GrpcLibraryCodegen {
|
||||
public:
|
||||
ChannelCredentials();
|
||||
~ChannelCredentials();
|
||||
|
||||
protected:
|
||||
friend std::shared_ptr<ChannelCredentials> CompositeChannelCredentials(
|
||||
const std::shared_ptr<ChannelCredentials>& channel_creds,
|
||||
const std::shared_ptr<CallCredentials>& call_creds);
|
||||
|
||||
virtual SecureChannelCredentials* AsSecureCredentials() = 0;
|
||||
|
||||
private:
|
||||
friend std::shared_ptr<Channel> CreateCustomChannelImpl(
|
||||
const grpc::string& target,
|
||||
const std::shared_ptr<ChannelCredentials>& creds,
|
||||
const ChannelArguments& args);
|
||||
|
||||
friend std::shared_ptr<Channel>
|
||||
grpc_impl::experimental::CreateCustomChannelWithInterceptors(
|
||||
const grpc::string& target,
|
||||
const std::shared_ptr<ChannelCredentials>& creds,
|
||||
const ChannelArguments& args,
|
||||
std::vector<std::unique_ptr<
|
||||
grpc::experimental::ClientInterceptorFactoryInterface>>
|
||||
interceptor_creators);
|
||||
|
||||
virtual std::shared_ptr<Channel> CreateChannelImpl(
|
||||
const grpc::string& target, const ChannelArguments& args) = 0;
|
||||
|
||||
// This function should have been a pure virtual function, but it is
|
||||
// implemented as a virtual function so that it does not break API.
|
||||
virtual std::shared_ptr<Channel> CreateChannelWithInterceptors(
|
||||
const grpc::string& /*target*/, const ChannelArguments& /*args*/,
|
||||
std::vector<std::unique_ptr<
|
||||
grpc::experimental::ClientInterceptorFactoryInterface>>
|
||||
/*interceptor_creators*/) {
|
||||
return nullptr;
|
||||
}
|
||||
};
|
||||
|
||||
/// A call credentials object encapsulates the state needed by a client to
|
||||
/// authenticate with a server for a given call on a channel.
|
||||
///
|
||||
/// \see https://grpc.io/docs/guides/auth.html
|
||||
class CallCredentials : private grpc::GrpcLibraryCodegen {
|
||||
public:
|
||||
CallCredentials();
|
||||
~CallCredentials();
|
||||
|
||||
/// Apply this instance's credentials to \a call.
|
||||
virtual bool ApplyToCall(grpc_call* call) = 0;
|
||||
|
||||
protected:
|
||||
friend std::shared_ptr<ChannelCredentials> CompositeChannelCredentials(
|
||||
const std::shared_ptr<ChannelCredentials>& channel_creds,
|
||||
const std::shared_ptr<CallCredentials>& call_creds);
|
||||
|
||||
friend std::shared_ptr<CallCredentials> CompositeCallCredentials(
|
||||
const std::shared_ptr<CallCredentials>& creds1,
|
||||
const std::shared_ptr<CallCredentials>& creds2);
|
||||
|
||||
virtual SecureCallCredentials* AsSecureCredentials() = 0;
|
||||
};
|
||||
|
||||
/// Options used to build SslCredentials.
|
||||
struct SslCredentialsOptions {
|
||||
/// The buffer containing the PEM encoding of the server root certificates. If
|
||||
/// this parameter is empty, the default roots will be used. The default
|
||||
/// roots can be overridden using the \a GRPC_DEFAULT_SSL_ROOTS_FILE_PATH
|
||||
/// environment variable pointing to a file on the file system containing the
|
||||
/// roots.
|
||||
grpc::string pem_root_certs;
|
||||
|
||||
/// The buffer containing the PEM encoding of the client's private key. This
|
||||
/// parameter can be empty if the client does not have a private key.
|
||||
grpc::string pem_private_key;
|
||||
|
||||
/// The buffer containing the PEM encoding of the client's certificate chain.
|
||||
/// This parameter can be empty if the client does not have a certificate
|
||||
/// chain.
|
||||
grpc::string pem_cert_chain;
|
||||
};
|
||||
|
||||
// Factories for building different types of Credentials The functions may
|
||||
// return empty shared_ptr when credentials cannot be created. If a
|
||||
// Credentials pointer is returned, it can still be invalid when used to create
|
||||
// a channel. A lame channel will be created then and all rpcs will fail on it.
|
||||
|
||||
/// Builds credentials with reasonable defaults.
|
||||
///
|
||||
/// \warning Only use these credentials when connecting to a Google endpoint.
|
||||
/// Using these credentials to connect to any other service may result in this
|
||||
/// service being able to impersonate your client for requests to Google
|
||||
/// services.
|
||||
std::shared_ptr<ChannelCredentials> GoogleDefaultCredentials();
|
||||
|
||||
/// Builds SSL Credentials given SSL specific options
|
||||
std::shared_ptr<ChannelCredentials> SslCredentials(
|
||||
const SslCredentialsOptions& options);
|
||||
|
||||
/// Builds credentials for use when running in GCE
|
||||
///
|
||||
/// \warning Only use these credentials when connecting to a Google endpoint.
|
||||
/// Using these credentials to connect to any other service may result in this
|
||||
/// service being able to impersonate your client for requests to Google
|
||||
/// services.
|
||||
std::shared_ptr<CallCredentials> GoogleComputeEngineCredentials();
|
||||
|
||||
constexpr long kMaxAuthTokenLifetimeSecs = 3600;
|
||||
|
||||
/// Builds Service Account JWT Access credentials.
|
||||
/// json_key is the JSON key string containing the client's private key.
|
||||
/// token_lifetime_seconds is the lifetime in seconds of each Json Web Token
|
||||
/// (JWT) created with this credentials. It should not exceed
|
||||
/// \a kMaxAuthTokenLifetimeSecs or will be cropped to this value.
|
||||
std::shared_ptr<CallCredentials> ServiceAccountJWTAccessCredentials(
|
||||
const grpc::string& json_key,
|
||||
long token_lifetime_seconds = grpc_impl::kMaxAuthTokenLifetimeSecs);
|
||||
|
||||
/// Builds refresh token credentials.
|
||||
/// json_refresh_token is the JSON string containing the refresh token along
|
||||
/// with a client_id and client_secret.
|
||||
///
|
||||
/// \warning Only use these credentials when connecting to a Google endpoint.
|
||||
/// Using these credentials to connect to any other service may result in this
|
||||
/// service being able to impersonate your client for requests to Google
|
||||
/// services.
|
||||
std::shared_ptr<CallCredentials> GoogleRefreshTokenCredentials(
|
||||
const grpc::string& json_refresh_token);
|
||||
|
||||
/// Builds access token credentials.
|
||||
/// access_token is an oauth2 access token that was fetched using an out of band
|
||||
/// mechanism.
|
||||
///
|
||||
/// \warning Only use these credentials when connecting to a Google endpoint.
|
||||
/// Using these credentials to connect to any other service may result in this
|
||||
/// service being able to impersonate your client for requests to Google
|
||||
/// services.
|
||||
std::shared_ptr<CallCredentials> AccessTokenCredentials(
|
||||
const grpc::string& access_token);
|
||||
|
||||
/// Builds IAM credentials.
|
||||
///
|
||||
/// \warning Only use these credentials when connecting to a Google endpoint.
|
||||
/// Using these credentials to connect to any other service may result in this
|
||||
/// service being able to impersonate your client for requests to Google
|
||||
/// services.
|
||||
std::shared_ptr<CallCredentials> GoogleIAMCredentials(
|
||||
const grpc::string& authorization_token,
|
||||
const grpc::string& authority_selector);
|
||||
|
||||
/// Combines a channel credentials and a call credentials into a composite
|
||||
/// channel credentials.
|
||||
std::shared_ptr<ChannelCredentials> CompositeChannelCredentials(
|
||||
const std::shared_ptr<ChannelCredentials>& channel_creds,
|
||||
const std::shared_ptr<CallCredentials>& call_creds);
|
||||
|
||||
/// Combines two call credentials objects into a composite call credentials.
|
||||
std::shared_ptr<CallCredentials> CompositeCallCredentials(
|
||||
const std::shared_ptr<CallCredentials>& creds1,
|
||||
const std::shared_ptr<CallCredentials>& creds2);
|
||||
|
||||
/// Credentials for an unencrypted, unauthenticated channel
|
||||
std::shared_ptr<ChannelCredentials> InsecureChannelCredentials();
|
||||
|
||||
/// User defined metadata credentials.
|
||||
class MetadataCredentialsPlugin {
|
||||
public:
|
||||
virtual ~MetadataCredentialsPlugin() {}
|
||||
|
||||
/// If this method returns true, the Process function will be scheduled in
|
||||
/// a different thread from the one processing the call.
|
||||
virtual bool IsBlocking() const { return true; }
|
||||
|
||||
/// Type of credentials this plugin is implementing.
|
||||
virtual const char* GetType() const { return ""; }
|
||||
|
||||
/// Gets the auth metatada produced by this plugin.
|
||||
/// The fully qualified method name is:
|
||||
/// service_url + "/" + method_name.
|
||||
/// The channel_auth_context contains (among other things), the identity of
|
||||
/// the server.
|
||||
virtual grpc::Status GetMetadata(
|
||||
grpc::string_ref service_url, grpc::string_ref method_name,
|
||||
const grpc::AuthContext& channel_auth_context,
|
||||
std::multimap<grpc::string, grpc::string>* metadata) = 0;
|
||||
};
|
||||
|
||||
std::shared_ptr<CallCredentials> MetadataCredentialsFromPlugin(
|
||||
std::unique_ptr<MetadataCredentialsPlugin> plugin);
|
||||
|
||||
namespace experimental {
|
||||
|
||||
/// Options for creating STS Oauth Token Exchange credentials following the IETF
|
||||
/// draft https://tools.ietf.org/html/draft-ietf-oauth-token-exchange-16.
|
||||
/// Optional fields may be set to empty string. It is the responsibility of the
|
||||
/// caller to ensure that the subject and actor tokens are refreshed on disk at
|
||||
/// the specified paths.
|
||||
struct StsCredentialsOptions {
|
||||
grpc::string token_exchange_service_uri; // Required.
|
||||
grpc::string resource; // Optional.
|
||||
grpc::string audience; // Optional.
|
||||
grpc::string scope; // Optional.
|
||||
grpc::string requested_token_type; // Optional.
|
||||
grpc::string subject_token_path; // Required.
|
||||
grpc::string subject_token_type; // Required.
|
||||
grpc::string actor_token_path; // Optional.
|
||||
grpc::string actor_token_type; // Optional.
|
||||
};
|
||||
|
||||
/// Creates STS Options from a JSON string. The JSON schema is as follows:
|
||||
/// {
|
||||
/// "title": "STS Credentials Config",
|
||||
/// "type": "object",
|
||||
/// "required": ["token_exchange_service_uri", "subject_token_path",
|
||||
/// "subject_token_type"],
|
||||
/// "properties": {
|
||||
/// "token_exchange_service_uri": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "resource": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "audience": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "scope": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "requested_token_type": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "subject_token_path": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "subject_token_type": {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "actor_token_path" : {
|
||||
/// "type": "string"
|
||||
/// },
|
||||
/// "actor_token_type": {
|
||||
/// "type": "string"
|
||||
/// }
|
||||
/// }
|
||||
/// }
|
||||
grpc::Status StsCredentialsOptionsFromJson(const grpc::string& json_string,
|
||||
StsCredentialsOptions* options);
|
||||
|
||||
/// Creates STS credentials options from the $STS_CREDENTIALS environment
|
||||
/// variable. This environment variable points to the path of a JSON file
|
||||
/// comforming to the schema described above.
|
||||
grpc::Status StsCredentialsOptionsFromEnv(StsCredentialsOptions* options);
|
||||
|
||||
std::shared_ptr<CallCredentials> StsCredentials(
|
||||
const StsCredentialsOptions& options);
|
||||
|
||||
std::shared_ptr<CallCredentials> MetadataCredentialsFromPlugin(
|
||||
std::unique_ptr<MetadataCredentialsPlugin> plugin,
|
||||
grpc_security_level min_security_level);
|
||||
|
||||
/// Options used to build AltsCredentials.
|
||||
struct AltsCredentialsOptions {
|
||||
/// service accounts of target endpoint that will be acceptable
|
||||
/// by the client. If service accounts are provided and none of them matches
|
||||
/// that of the server, authentication will fail.
|
||||
std::vector<grpc::string> target_service_accounts;
|
||||
};
|
||||
|
||||
/// Builds ALTS Credentials given ALTS specific options
|
||||
std::shared_ptr<ChannelCredentials> AltsCredentials(
|
||||
const AltsCredentialsOptions& options);
|
||||
|
||||
/// Builds Local Credentials.
|
||||
std::shared_ptr<ChannelCredentials> LocalCredentials(
|
||||
grpc_local_connect_type type);
|
||||
|
||||
/// Builds TLS Credentials given TLS options.
|
||||
std::shared_ptr<ChannelCredentials> TlsCredentials(
|
||||
const TlsCredentialsOptions& options);
|
||||
|
||||
} // namespace experimental
|
||||
} // namespace grpc_impl
|
||||
|
||||
#endif // GRPCPP_SECURITY_CREDENTIALS_IMPL_H
|
||||
@@ -0,0 +1,91 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2019 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_SERVER_CREDENTIALS_H
|
||||
#define GRPCPP_SECURITY_SERVER_CREDENTIALS_H
|
||||
|
||||
#include <grpcpp/security/server_credentials_impl.h>
|
||||
|
||||
namespace grpc_impl {
|
||||
|
||||
class Server;
|
||||
} // namespace grpc_impl
|
||||
namespace grpc {
|
||||
|
||||
typedef ::grpc_impl::ServerCredentials ServerCredentials;
|
||||
|
||||
/// Options to create ServerCredentials with SSL
|
||||
struct SslServerCredentialsOptions {
|
||||
/// \warning Deprecated
|
||||
SslServerCredentialsOptions()
|
||||
: force_client_auth(false),
|
||||
client_certificate_request(GRPC_SSL_DONT_REQUEST_CLIENT_CERTIFICATE) {}
|
||||
SslServerCredentialsOptions(
|
||||
grpc_ssl_client_certificate_request_type request_type)
|
||||
: force_client_auth(false), client_certificate_request(request_type) {}
|
||||
|
||||
struct PemKeyCertPair {
|
||||
grpc::string private_key;
|
||||
grpc::string cert_chain;
|
||||
};
|
||||
grpc::string pem_root_certs;
|
||||
std::vector<PemKeyCertPair> pem_key_cert_pairs;
|
||||
/// \warning Deprecated
|
||||
bool force_client_auth;
|
||||
|
||||
/// If both \a force_client_auth and \a client_certificate_request
|
||||
/// fields are set, \a force_client_auth takes effect, i.e.
|
||||
/// \a REQUEST_AND_REQUIRE_CLIENT_CERTIFICATE_AND_VERIFY
|
||||
/// will be enforced.
|
||||
grpc_ssl_client_certificate_request_type client_certificate_request;
|
||||
};
|
||||
|
||||
static inline std::shared_ptr<ServerCredentials> SslServerCredentials(
|
||||
const SslServerCredentialsOptions& options) {
|
||||
return ::grpc_impl::SslServerCredentials(options);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<ServerCredentials> InsecureServerCredentials() {
|
||||
return ::grpc_impl::InsecureServerCredentials();
|
||||
}
|
||||
|
||||
namespace experimental {
|
||||
|
||||
typedef ::grpc_impl::experimental::AltsServerCredentialsOptions
|
||||
AltsServerCredentialsOptions;
|
||||
|
||||
static inline std::shared_ptr<ServerCredentials> AltsServerCredentials(
|
||||
const AltsServerCredentialsOptions& options) {
|
||||
return ::grpc_impl::experimental::AltsServerCredentials(options);
|
||||
}
|
||||
|
||||
static inline std::shared_ptr<ServerCredentials> LocalServerCredentials(
|
||||
grpc_local_connect_type type) {
|
||||
return ::grpc_impl::experimental::LocalServerCredentials(type);
|
||||
}
|
||||
|
||||
/// Builds TLS ServerCredentials given TLS options.
|
||||
static inline std::shared_ptr<ServerCredentials> TlsServerCredentials(
|
||||
const ::grpc_impl::experimental::TlsCredentialsOptions& options) {
|
||||
return ::grpc_impl::experimental::TlsServerCredentials(options);
|
||||
}
|
||||
|
||||
} // namespace experimental
|
||||
} // namespace grpc
|
||||
|
||||
#endif // GRPCPP_SECURITY_SERVER_CREDENTIALS_H
|
||||
@@ -0,0 +1,90 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2015 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_SERVER_CREDENTIALS_IMPL_H
|
||||
#define GRPCPP_SECURITY_SERVER_CREDENTIALS_IMPL_H
|
||||
|
||||
#include <memory>
|
||||
#include <vector>
|
||||
|
||||
#include <grpc/grpc_security_constants.h>
|
||||
#include <grpcpp/security/auth_metadata_processor.h>
|
||||
#include <grpcpp/security/tls_credentials_options.h>
|
||||
#include <grpcpp/support/config.h>
|
||||
|
||||
struct grpc_server;
|
||||
|
||||
namespace grpc {
|
||||
|
||||
struct SslServerCredentialsOptions;
|
||||
} // namespace grpc
|
||||
namespace grpc_impl {
|
||||
class Server;
|
||||
|
||||
/// Wrapper around \a grpc_server_credentials, a way to authenticate a server.
|
||||
class ServerCredentials {
|
||||
public:
|
||||
virtual ~ServerCredentials();
|
||||
|
||||
/// This method is not thread-safe and has to be called before the server is
|
||||
/// started. The last call to this function wins.
|
||||
virtual void SetAuthMetadataProcessor(
|
||||
const std::shared_ptr<grpc::AuthMetadataProcessor>& processor) = 0;
|
||||
|
||||
private:
|
||||
friend class ::grpc_impl::Server;
|
||||
|
||||
/// Tries to bind \a server to the given \a addr (eg, localhost:1234,
|
||||
/// 192.168.1.1:31416, [::1]:27182, etc.)
|
||||
///
|
||||
/// \return bound port number on success, 0 on failure.
|
||||
// TODO(dgq): the "port" part seems to be a misnomer.
|
||||
virtual int AddPortToServer(const grpc::string& addr,
|
||||
grpc_server* server) = 0;
|
||||
};
|
||||
|
||||
/// Builds SSL ServerCredentials given SSL specific options
|
||||
std::shared_ptr<ServerCredentials> SslServerCredentials(
|
||||
const grpc::SslServerCredentialsOptions& options);
|
||||
|
||||
/// Builds insecure server credentials.
|
||||
std::shared_ptr<ServerCredentials> InsecureServerCredentials();
|
||||
|
||||
namespace experimental {
|
||||
|
||||
/// Options to create ServerCredentials with ALTS
|
||||
struct AltsServerCredentialsOptions {
|
||||
/// Add fields if needed.
|
||||
};
|
||||
|
||||
/// Builds ALTS ServerCredentials given ALTS specific options
|
||||
std::shared_ptr<ServerCredentials> AltsServerCredentials(
|
||||
const AltsServerCredentialsOptions& options);
|
||||
|
||||
/// Builds Local ServerCredentials.
|
||||
std::shared_ptr<ServerCredentials> LocalServerCredentials(
|
||||
grpc_local_connect_type type);
|
||||
|
||||
/// Builds TLS ServerCredentials given TLS options.
|
||||
std::shared_ptr<ServerCredentials> TlsServerCredentials(
|
||||
const TlsCredentialsOptions& options);
|
||||
|
||||
} // namespace experimental
|
||||
} // namespace grpc_impl
|
||||
|
||||
#endif // GRPCPP_SECURITY_SERVER_CREDENTIALS_IMPL_H
|
||||
@@ -0,0 +1,330 @@
|
||||
/*
|
||||
*
|
||||
* Copyright 2019 gRPC authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef GRPCPP_SECURITY_TLS_CREDENTIALS_OPTIONS_H
|
||||
#define GRPCPP_SECURITY_TLS_CREDENTIALS_OPTIONS_H
|
||||
|
||||
#include <memory>
|
||||
#include <vector>
|
||||
|
||||
#include <grpc/grpc_security_constants.h>
|
||||
#include <grpc/status.h>
|
||||
#include <grpc/support/log.h>
|
||||
#include <grpcpp/support/config.h>
|
||||
|
||||
typedef struct grpc_tls_credential_reload_arg grpc_tls_credential_reload_arg;
|
||||
typedef struct grpc_tls_credential_reload_config
|
||||
grpc_tls_credential_reload_config;
|
||||
typedef struct grpc_tls_server_authorization_check_arg
|
||||
grpc_tls_server_authorization_check_arg;
|
||||
typedef struct grpc_tls_server_authorization_check_config
|
||||
grpc_tls_server_authorization_check_config;
|
||||
typedef struct grpc_tls_credentials_options grpc_tls_credentials_options;
|
||||
|
||||
namespace grpc_impl {
|
||||
namespace experimental {
|
||||
|
||||
/** TLS key materials config, wrapper for grpc_tls_key_materials_config. It is
|
||||
* used for experimental purposes for now and subject to change. **/
|
||||
class TlsKeyMaterialsConfig {
|
||||
public:
|
||||
struct PemKeyCertPair {
|
||||
grpc::string private_key;
|
||||
grpc::string cert_chain;
|
||||
};
|
||||
|
||||
/** Getters for member fields. **/
|
||||
const grpc::string pem_root_certs() const { return pem_root_certs_; }
|
||||
const std::vector<PemKeyCertPair>& pem_key_cert_pair_list() const {
|
||||
return pem_key_cert_pair_list_;
|
||||
}
|
||||
int version() const { return version_; }
|
||||
|
||||
/** Setter for key materials that will be called by the user. Ownership of the
|
||||
* arguments will not be transferred. **/
|
||||
void set_pem_root_certs(const grpc::string& pem_root_certs);
|
||||
void add_pem_key_cert_pair(const PemKeyCertPair& pem_key_cert_pair);
|
||||
void set_key_materials(
|
||||
const grpc::string& pem_root_certs,
|
||||
const std::vector<PemKeyCertPair>& pem_key_cert_pair_list);
|
||||
void set_version(int version) { version_ = version; };
|
||||
|
||||
private:
|
||||
int version_ = 0;
|
||||
std::vector<PemKeyCertPair> pem_key_cert_pair_list_;
|
||||
grpc::string pem_root_certs_;
|
||||
};
|
||||
|
||||
/** TLS credential reload arguments, wraps grpc_tls_credential_reload_arg. It is
|
||||
* used for experimental purposes for now and it is subject to change.
|
||||
*
|
||||
* The credential reload arg contains all the info necessary to schedule/cancel
|
||||
* a credential reload request. The callback function must be called after
|
||||
* finishing the schedule operation. See the description of the
|
||||
* grpc_tls_credential_reload_arg struct in grpc_security.h for more details.
|
||||
* **/
|
||||
class TlsCredentialReloadArg {
|
||||
public:
|
||||
/** TlsCredentialReloadArg does not take ownership of the C arg that is passed
|
||||
* to the constructor. One must remember to free any memory allocated to the
|
||||
* C arg after using the setter functions below. **/
|
||||
TlsCredentialReloadArg(grpc_tls_credential_reload_arg* arg);
|
||||
~TlsCredentialReloadArg();
|
||||
|
||||
/** Getters for member fields. **/
|
||||
void* cb_user_data() const;
|
||||
bool is_pem_key_cert_pair_list_empty() const;
|
||||
grpc_ssl_certificate_config_reload_status status() const;
|
||||
grpc::string error_details() const;
|
||||
|
||||
/** Setters for member fields. Ownership of the arguments will not be
|
||||
* transferred. **/
|
||||
void set_cb_user_data(void* cb_user_data);
|
||||
void set_pem_root_certs(const grpc::string& pem_root_certs);
|
||||
void add_pem_key_cert_pair(
|
||||
const TlsKeyMaterialsConfig::PemKeyCertPair& pem_key_cert_pair);
|
||||
void set_key_materials(const grpc::string& pem_root_certs,
|
||||
std::vector<TlsKeyMaterialsConfig::PemKeyCertPair>
|
||||
pem_key_cert_pair_list);
|
||||
void set_key_materials_config(
|
||||
const std::shared_ptr<TlsKeyMaterialsConfig>& key_materials_config);
|
||||
void set_status(grpc_ssl_certificate_config_reload_status status);
|
||||
void set_error_details(const grpc::string& error_details);
|
||||
|
||||
/** Calls the C arg's callback function. **/
|
||||
void OnCredentialReloadDoneCallback();
|
||||
|
||||
private:
|
||||
grpc_tls_credential_reload_arg* c_arg_;
|
||||
};
|
||||
|
||||
/** An interface that the application derives and uses to instantiate a
|
||||
* TlsCredentialReloadConfig instance. Refer to the definition of the
|
||||
* grpc_tls_credential_reload_config in grpc_tls_credentials_options.h for more
|
||||
* details on the expectations of the member functions of the interface. **/
|
||||
struct TlsCredentialReloadInterface {
|
||||
virtual ~TlsCredentialReloadInterface() = default;
|
||||
/** A callback that invokes the credential reload. **/
|
||||
virtual int Schedule(TlsCredentialReloadArg* arg) = 0;
|
||||
/** A callback that cancels a credential reload request. **/
|
||||
virtual void Cancel(TlsCredentialReloadArg* /* arg */) {}
|
||||
};
|
||||
|
||||
/** TLS credential reloag config, wraps grpc_tls_credential_reload_config. It is
|
||||
* used for experimental purposes for now and it is subject to change. **/
|
||||
class TlsCredentialReloadConfig {
|
||||
public:
|
||||
TlsCredentialReloadConfig(std::shared_ptr<TlsCredentialReloadInterface>
|
||||
credential_reload_interface);
|
||||
~TlsCredentialReloadConfig();
|
||||
|
||||
int Schedule(TlsCredentialReloadArg* arg) const {
|
||||
if (credential_reload_interface_ == nullptr) {
|
||||
gpr_log(GPR_ERROR, "credential reload interface is nullptr");
|
||||
if (arg != nullptr) {
|
||||
arg->set_status(GRPC_SSL_CERTIFICATE_CONFIG_RELOAD_FAIL);
|
||||
arg->set_error_details(
|
||||
"the interface of the credential reload config is nullptr");
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
return credential_reload_interface_->Schedule(arg);
|
||||
}
|
||||
|
||||
void Cancel(TlsCredentialReloadArg* arg) const {
|
||||
if (credential_reload_interface_ == nullptr) {
|
||||
gpr_log(GPR_ERROR, "credential reload interface is nullptr");
|
||||
if (arg != nullptr) {
|
||||
arg->set_status(GRPC_SSL_CERTIFICATE_CONFIG_RELOAD_FAIL);
|
||||
arg->set_error_details(
|
||||
"the interface of the credential reload config is nullptr");
|
||||
}
|
||||
return;
|
||||
}
|
||||
credential_reload_interface_->Cancel(arg);
|
||||
}
|
||||
|
||||
/** Returns a C struct for the credential reload config. **/
|
||||
grpc_tls_credential_reload_config* c_config() const { return c_config_; }
|
||||
|
||||
private:
|
||||
grpc_tls_credential_reload_config* c_config_;
|
||||
std::shared_ptr<TlsCredentialReloadInterface> credential_reload_interface_;
|
||||
};
|
||||
|
||||
/** TLS server authorization check arguments, wraps
|
||||
* grpc_tls_server_authorization_check_arg. It is used for experimental
|
||||
* purposes for now and it is subject to change.
|
||||
*
|
||||
* The server authorization check arg contains all the info necessary to
|
||||
* schedule/cancel a server authorization check request. The callback function
|
||||
* must be called after finishing the schedule operation. See the description
|
||||
* of the grpc_tls_server_authorization_check_arg struct in grpc_security.h for
|
||||
* more details. **/
|
||||
class TlsServerAuthorizationCheckArg {
|
||||
public:
|
||||
/** TlsServerAuthorizationCheckArg does not take ownership of the C arg passed
|
||||
* to the constructor. One must remember to free any memory allocated to the
|
||||
* C arg after using the setter functions below. **/
|
||||
TlsServerAuthorizationCheckArg(grpc_tls_server_authorization_check_arg* arg);
|
||||
~TlsServerAuthorizationCheckArg();
|
||||
|
||||
/** Getters for member fields. **/
|
||||
void* cb_user_data() const;
|
||||
int success() const;
|
||||
grpc::string target_name() const;
|
||||
grpc::string peer_cert() const;
|
||||
grpc::string peer_cert_full_chain() const;
|
||||
grpc_status_code status() const;
|
||||
grpc::string error_details() const;
|
||||
|
||||
/** Setters for member fields. **/
|
||||
void set_cb_user_data(void* cb_user_data);
|
||||
void set_success(int success);
|
||||
void set_target_name(const grpc::string& target_name);
|
||||
void set_peer_cert(const grpc::string& peer_cert);
|
||||
void set_peer_cert_full_chain(const grpc::string& peer_cert_full_chain);
|
||||
void set_status(grpc_status_code status);
|
||||
void set_error_details(const grpc::string& error_details);
|
||||
|
||||
/** Calls the C arg's callback function. **/
|
||||
void OnServerAuthorizationCheckDoneCallback();
|
||||
|
||||
private:
|
||||
grpc_tls_server_authorization_check_arg* c_arg_;
|
||||
};
|
||||
|
||||
/** An interface that the application derives and uses to instantiate a
|
||||
* TlsServerAuthorizationCheckConfig instance. Refer to the definition of the
|
||||
* grpc_tls_server_authorization_check_config in grpc_tls_credentials_options.h
|
||||
* for more details on the expectations of the member functions of the
|
||||
* interface.
|
||||
* **/
|
||||
struct TlsServerAuthorizationCheckInterface {
|
||||
virtual ~TlsServerAuthorizationCheckInterface() = default;
|
||||
/** A callback that invokes the server authorization check. **/
|
||||
virtual int Schedule(TlsServerAuthorizationCheckArg* arg) = 0;
|
||||
/** A callback that cancels a server authorization check request. **/
|
||||
virtual void Cancel(TlsServerAuthorizationCheckArg* /* arg */) {}
|
||||
};
|
||||
|
||||
/** TLS server authorization check config, wraps
|
||||
* grps_tls_server_authorization_check_config. It is used for experimental
|
||||
* purposes for now and it is subject to change. **/
|
||||
class TlsServerAuthorizationCheckConfig {
|
||||
public:
|
||||
TlsServerAuthorizationCheckConfig(
|
||||
std::shared_ptr<TlsServerAuthorizationCheckInterface>
|
||||
server_authorization_check_interface);
|
||||
~TlsServerAuthorizationCheckConfig();
|
||||
|
||||
int Schedule(TlsServerAuthorizationCheckArg* arg) const {
|
||||
if (server_authorization_check_interface_ == nullptr) {
|
||||
gpr_log(GPR_ERROR, "server authorization check interface is nullptr");
|
||||
if (arg != nullptr) {
|
||||
arg->set_status(GRPC_STATUS_NOT_FOUND);
|
||||
arg->set_error_details(
|
||||
"the interface of the server authorization check config is "
|
||||
"nullptr");
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
return server_authorization_check_interface_->Schedule(arg);
|
||||
}
|
||||
|
||||
void Cancel(TlsServerAuthorizationCheckArg* arg) const {
|
||||
if (server_authorization_check_interface_ == nullptr) {
|
||||
gpr_log(GPR_ERROR, "server authorization check interface is nullptr");
|
||||
if (arg != nullptr) {
|
||||
arg->set_status(GRPC_STATUS_NOT_FOUND);
|
||||
arg->set_error_details(
|
||||
"the interface of the server authorization check config is "
|
||||
"nullptr");
|
||||
}
|
||||
return;
|
||||
}
|
||||
server_authorization_check_interface_->Cancel(arg);
|
||||
}
|
||||
|
||||
/** Returns C struct for the server authorization check config. **/
|
||||
grpc_tls_server_authorization_check_config* c_config() const {
|
||||
return c_config_;
|
||||
}
|
||||
|
||||
private:
|
||||
grpc_tls_server_authorization_check_config* c_config_;
|
||||
std::shared_ptr<TlsServerAuthorizationCheckInterface>
|
||||
server_authorization_check_interface_;
|
||||
};
|
||||
|
||||
/** TLS credentials options, wrapper for grpc_tls_credentials_options. It is
|
||||
* used for experimental purposes for now and it is subject to change. See the
|
||||
* description of the grpc_tls_credentials_options struct in grpc_security.h for
|
||||
* more details. **/
|
||||
class TlsCredentialsOptions {
|
||||
public:
|
||||
TlsCredentialsOptions(
|
||||
grpc_ssl_client_certificate_request_type cert_request_type,
|
||||
grpc_tls_server_verification_option server_verification_option,
|
||||
std::shared_ptr<TlsKeyMaterialsConfig> key_materials_config,
|
||||
std::shared_ptr<TlsCredentialReloadConfig> credential_reload_config,
|
||||
std::shared_ptr<TlsServerAuthorizationCheckConfig>
|
||||
server_authorization_check_config);
|
||||
~TlsCredentialsOptions();
|
||||
|
||||
/** Getters for member fields. **/
|
||||
grpc_ssl_client_certificate_request_type cert_request_type() const {
|
||||
return cert_request_type_;
|
||||
}
|
||||
grpc_tls_server_verification_option server_verification_option() const {
|
||||
return server_verification_option_;
|
||||
}
|
||||
std::shared_ptr<TlsKeyMaterialsConfig> key_materials_config() const {
|
||||
return key_materials_config_;
|
||||
}
|
||||
std::shared_ptr<TlsCredentialReloadConfig> credential_reload_config() const {
|
||||
return credential_reload_config_;
|
||||
}
|
||||
std::shared_ptr<TlsServerAuthorizationCheckConfig>
|
||||
server_authorization_check_config() const {
|
||||
return server_authorization_check_config_;
|
||||
}
|
||||
grpc_tls_credentials_options* c_credentials_options() const {
|
||||
return c_credentials_options_;
|
||||
}
|
||||
|
||||
private:
|
||||
/** The cert_request_type_ flag is only relevant when the
|
||||
* TlsCredentialsOptions are used to instantiate server credentials; the flag
|
||||
* goes unused when creating channel credentials, and the user can set it to
|
||||
* GRPC_SSL_DONT_REQUEST_CLIENT_CERTIFICATE. **/
|
||||
grpc_ssl_client_certificate_request_type cert_request_type_;
|
||||
/** The server_verification_option_ flag is only relevant when the
|
||||
* TlsCredentialsOptions are used to instantiate client credentials; **/
|
||||
grpc_tls_server_verification_option server_verification_option_;
|
||||
std::shared_ptr<TlsKeyMaterialsConfig> key_materials_config_;
|
||||
std::shared_ptr<TlsCredentialReloadConfig> credential_reload_config_;
|
||||
std::shared_ptr<TlsServerAuthorizationCheckConfig>
|
||||
server_authorization_check_config_;
|
||||
grpc_tls_credentials_options* c_credentials_options_;
|
||||
};
|
||||
|
||||
} // namespace experimental
|
||||
} // namespace grpc_impl
|
||||
|
||||
#endif // GRPCPP_SECURITY_TLS_CREDENTIALS_OPTIONS_H
|
||||
Reference in New Issue
Block a user