From 8c37fc1181e00deb004fccf9d8ad1bb5b559c7d1 Mon Sep 17 00:00:00 2001
From: Philippe Loctaux
Date: Sun, 12 Mar 2023 18:45:55 +0100
Subject: [PATCH] database: added keys migration, get/insert, insert keys at
launch if none are present
---
.../migrations/20230312153840_keys.down.sql | 1 +
.../migrations/20230312153840_keys.up.sql | 8 +
crates/database/queries/keys/get_all.sql | 8 +
.../database/queries/keys/get_all_revoked.sql | 9 +
.../database/queries/keys/get_all_valid.sql | 9 +
.../database/queries/keys/get_most_recent.sql | 10 +
crates/database/queries/keys/insert.sql | 2 +
crates/database/sqlx-data.json | 178 ++++++++++++++++++
crates/database/src/tables.rs | 2 +
crates/database/src/tables/keys.rs | 66 +++++++
crates/ezidam/src/database.rs | 80 +++++++-
crates/jwt/Cargo.toml | 2 +
crates/jwt/src/database.rs | 76 ++++++++
crates/jwt/src/error.rs | 3 +
crates/jwt/src/lib.rs | 1 +
15 files changed, 453 insertions(+), 2 deletions(-)
create mode 100644 crates/database/migrations/20230312153840_keys.down.sql
create mode 100644 crates/database/migrations/20230312153840_keys.up.sql
create mode 100644 crates/database/queries/keys/get_all.sql
create mode 100644 crates/database/queries/keys/get_all_revoked.sql
create mode 100644 crates/database/queries/keys/get_all_valid.sql
create mode 100644 crates/database/queries/keys/get_most_recent.sql
create mode 100644 crates/database/queries/keys/insert.sql
create mode 100644 crates/database/src/tables/keys.rs
create mode 100644 crates/jwt/src/database.rs
diff --git a/crates/database/migrations/20230312153840_keys.down.sql b/crates/database/migrations/20230312153840_keys.down.sql
new file mode 100644
index 0000000..067ec35
--- /dev/null
+++ b/crates/database/migrations/20230312153840_keys.down.sql
@@ -0,0 +1 @@
+drop table if exists keys;
diff --git a/crates/database/migrations/20230312153840_keys.up.sql b/crates/database/migrations/20230312153840_keys.up.sql
new file mode 100644
index 0000000..8900993
--- /dev/null
+++ b/crates/database/migrations/20230312153840_keys.up.sql
@@ -0,0 +1,8 @@
+create table if not exists keys
+(
+ id TEXT not null primary key,
+ created_at TEXT not null default CURRENT_TIMESTAMP,
+ revoked_at TEXT,
+ private_der BLOB not null,
+ public_der BLOB not null
+);
diff --git a/crates/database/queries/keys/get_all.sql b/crates/database/queries/keys/get_all.sql
new file mode 100644
index 0000000..9cbb506
--- /dev/null
+++ b/crates/database/queries/keys/get_all.sql
@@ -0,0 +1,8 @@
+select id,
+ created_at as "created_at: DateTime",
+ revoked_at as "revoked_at: DateTime",
+ private_der,
+ public_der
+
+from keys
+order by created_at desc
diff --git a/crates/database/queries/keys/get_all_revoked.sql b/crates/database/queries/keys/get_all_revoked.sql
new file mode 100644
index 0000000..95d08d3
--- /dev/null
+++ b/crates/database/queries/keys/get_all_revoked.sql
@@ -0,0 +1,9 @@
+select id,
+ created_at as "created_at: DateTime",
+ revoked_at as "revoked_at: DateTime",
+ private_der,
+ public_der
+
+from keys
+where revoked_at is not null
+order by created_at desc
diff --git a/crates/database/queries/keys/get_all_valid.sql b/crates/database/queries/keys/get_all_valid.sql
new file mode 100644
index 0000000..ac49af8
--- /dev/null
+++ b/crates/database/queries/keys/get_all_valid.sql
@@ -0,0 +1,9 @@
+select id,
+ created_at as "created_at: DateTime",
+ revoked_at as "revoked_at: DateTime",
+ private_der,
+ public_der
+
+from keys
+where revoked_at is null
+order by created_at desc
diff --git a/crates/database/queries/keys/get_most_recent.sql b/crates/database/queries/keys/get_most_recent.sql
new file mode 100644
index 0000000..a806881
--- /dev/null
+++ b/crates/database/queries/keys/get_most_recent.sql
@@ -0,0 +1,10 @@
+select id,
+ created_at as "created_at: DateTime",
+ revoked_at as "revoked_at: DateTime",
+ private_der,
+ public_der
+
+from keys
+where revoked_at is null
+order by created_at desc
+limit 1
diff --git a/crates/database/queries/keys/insert.sql b/crates/database/queries/keys/insert.sql
new file mode 100644
index 0000000..c244fea
--- /dev/null
+++ b/crates/database/queries/keys/insert.sql
@@ -0,0 +1,2 @@
+insert into keys (id, private_der, public_der)
+values (?, ?, ?)
diff --git a/crates/database/sqlx-data.json b/crates/database/sqlx-data.json
index e0fb04f..b196860 100644
--- a/crates/database/sqlx-data.json
+++ b/crates/database/sqlx-data.json
@@ -30,6 +30,90 @@
},
"query": "insert into users (id, is_admin, username, password)\nvalues (?, ?, ?, ?)\n"
},
+ "56a9c0dff010858189a95087d014c7d0ce930da5d841b9d788a9c0e84b580bc6": {
+ "describe": {
+ "columns": [
+ {
+ "name": "id",
+ "ordinal": 0,
+ "type_info": "Text"
+ },
+ {
+ "name": "created_at: DateTime",
+ "ordinal": 1,
+ "type_info": "Text"
+ },
+ {
+ "name": "revoked_at: DateTime",
+ "ordinal": 2,
+ "type_info": "Text"
+ },
+ {
+ "name": "private_der",
+ "ordinal": 3,
+ "type_info": "Blob"
+ },
+ {
+ "name": "public_der",
+ "ordinal": 4,
+ "type_info": "Blob"
+ }
+ ],
+ "nullable": [
+ false,
+ false,
+ true,
+ false,
+ false
+ ],
+ "parameters": {
+ "Right": 0
+ }
+ },
+ "query": "select id,\n created_at as \"created_at: DateTime\",\n revoked_at as \"revoked_at: DateTime\",\n private_der,\n public_der\n\nfrom keys\norder by created_at desc\n"
+ },
+ "5f946348ad62389fab3c97a1563d1592cbc5180abbba6d5abd44326bf0862669": {
+ "describe": {
+ "columns": [
+ {
+ "name": "id",
+ "ordinal": 0,
+ "type_info": "Text"
+ },
+ {
+ "name": "created_at: DateTime",
+ "ordinal": 1,
+ "type_info": "Text"
+ },
+ {
+ "name": "revoked_at: DateTime",
+ "ordinal": 2,
+ "type_info": "Text"
+ },
+ {
+ "name": "private_der",
+ "ordinal": 3,
+ "type_info": "Blob"
+ },
+ {
+ "name": "public_der",
+ "ordinal": 4,
+ "type_info": "Blob"
+ }
+ ],
+ "nullable": [
+ false,
+ false,
+ true,
+ false,
+ false
+ ],
+ "parameters": {
+ "Right": 0
+ }
+ },
+ "query": "select id,\n created_at as \"created_at: DateTime\",\n revoked_at as \"revoked_at: DateTime\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is not null\norder by created_at desc\n"
+ },
"62c75412f673f6a293b0d188d79c50676ec21cf94e2e50e18f9279c91e6b85c8": {
"describe": {
"columns": [],
@@ -166,6 +250,48 @@
},
"query": "select id,\n created_at as \"created_at: DateTime\",\n updated_at as \"updated_at: DateTime\",\n is_admin as \"is_admin: bool\",\n username,\n name,\n email,\n password,\n password_recover,\n paper_key,\n is_archived as \"is_archived: bool\"\nfrom users\n\nwhere email is (?)\n"
},
+ "6e1431ff2b4f589daaa7b221c1bc2a08ee378949fb27988531210ee75fc88298": {
+ "describe": {
+ "columns": [
+ {
+ "name": "id",
+ "ordinal": 0,
+ "type_info": "Text"
+ },
+ {
+ "name": "created_at: DateTime",
+ "ordinal": 1,
+ "type_info": "Text"
+ },
+ {
+ "name": "revoked_at: DateTime",
+ "ordinal": 2,
+ "type_info": "Text"
+ },
+ {
+ "name": "private_der",
+ "ordinal": 3,
+ "type_info": "Blob"
+ },
+ {
+ "name": "public_der",
+ "ordinal": 4,
+ "type_info": "Blob"
+ }
+ ],
+ "nullable": [
+ false,
+ false,
+ true,
+ false,
+ false
+ ],
+ "parameters": {
+ "Right": 0
+ }
+ },
+ "query": "select id,\n created_at as \"created_at: DateTime\",\n revoked_at as \"revoked_at: DateTime\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is null\norder by created_at desc\nlimit 1\n"
+ },
"87906834faa6f185aee0e4d893b9754908b1c173e9dce383663d723891a89cd1": {
"describe": {
"columns": [],
@@ -342,6 +468,48 @@
},
"query": "select u.id,\n u.created_at as \"created_at: DateTime\",\n u.updated_at as \"updated_at: DateTime\",\n u.is_admin as \"is_admin: bool\",\n u.username,\n u.name,\n u.email,\n u.password,\n u.password_recover,\n u.paper_key,\n u.is_archived as \"is_archived: bool\"\nfrom users u\n\n inner join settings s on u.id = s.first_admin\n\nwhere u.is_admin is 1\n and u.is_archived is 0\n and u.id is s.first_admin\n\nlimit 1"
},
+ "d166553746afb2d3eaa1ddcb9986b7b9723258f4051bce8287038e3dd1ac928a": {
+ "describe": {
+ "columns": [
+ {
+ "name": "id",
+ "ordinal": 0,
+ "type_info": "Text"
+ },
+ {
+ "name": "created_at: DateTime",
+ "ordinal": 1,
+ "type_info": "Text"
+ },
+ {
+ "name": "revoked_at: DateTime",
+ "ordinal": 2,
+ "type_info": "Text"
+ },
+ {
+ "name": "private_der",
+ "ordinal": 3,
+ "type_info": "Blob"
+ },
+ {
+ "name": "public_der",
+ "ordinal": 4,
+ "type_info": "Blob"
+ }
+ ],
+ "nullable": [
+ false,
+ false,
+ true,
+ false,
+ false
+ ],
+ "parameters": {
+ "Right": 0
+ }
+ },
+ "query": "select id,\n created_at as \"created_at: DateTime\",\n revoked_at as \"revoked_at: DateTime\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is null\norder by created_at desc\n"
+ },
"f4edf4567542eaead2e0db14b0d4197c5d3c1bc02da1897b571bf63bfcb4526a": {
"describe": {
"columns": [
@@ -419,5 +587,15 @@
}
},
"query": "select id,\n created_at as \"created_at: DateTime\",\n updated_at as \"updated_at: DateTime\",\n is_admin as \"is_admin: bool\",\n username,\n name,\n email,\n password,\n password_recover,\n paper_key,\n is_archived as \"is_archived: bool\"\nfrom users\n\nwhere id is (?)\n"
+ },
+ "f705411720bd037562f7e3622832262ac4c0a8fc0921fbd934d2b98146d3f413": {
+ "describe": {
+ "columns": [],
+ "nullable": [],
+ "parameters": {
+ "Right": 3
+ }
+ },
+ "query": "insert into keys (id, private_der, public_der)\nvalues (?, ?, ?)\n"
}
}
\ No newline at end of file
diff --git a/crates/database/src/tables.rs b/crates/database/src/tables.rs
index 8458c40..dcfaaf0 100644
--- a/crates/database/src/tables.rs
+++ b/crates/database/src/tables.rs
@@ -1,5 +1,7 @@
+mod keys;
mod settings;
mod users;
+pub use keys::Keys;
pub use settings::Settings;
pub use users::Users;
diff --git a/crates/database/src/tables/keys.rs b/crates/database/src/tables/keys.rs
new file mode 100644
index 0000000..fe664fa
--- /dev/null
+++ b/crates/database/src/tables/keys.rs
@@ -0,0 +1,66 @@
+use crate::error::{handle_error, Error};
+use sqlx::sqlite::SqliteQueryResult;
+use sqlx::types::chrono::{DateTime, Utc};
+use sqlx::{FromRow, SqliteExecutor};
+
+#[derive(FromRow)]
+pub struct Keys {
+ pub id: String,
+ pub created_at: DateTime,
+ pub revoked_at: Option>,
+ pub private_der: Vec,
+ pub public_der: Vec,
+}
+
+impl Keys {
+ pub async fn insert(
+ conn: impl SqliteExecutor<'_>,
+ id: &str,
+ private_der: &[u8],
+ public_der: &[u8],
+ ) -> Result