database: added keys migration, get/insert, insert keys at launch if none are present

This commit is contained in:
Philippe Loctaux 2023-03-12 18:45:55 +01:00
parent 7f11016a34
commit 8c37fc1181
15 changed files with 453 additions and 2 deletions

View file

@ -0,0 +1 @@
drop table if exists keys;

View file

@ -0,0 +1,8 @@
create table if not exists keys
(
id TEXT not null primary key,
created_at TEXT not null default CURRENT_TIMESTAMP,
revoked_at TEXT,
private_der BLOB not null,
public_der BLOB not null
);

View file

@ -0,0 +1,8 @@
select id,
created_at as "created_at: DateTime<Utc>",
revoked_at as "revoked_at: DateTime<Utc>",
private_der,
public_der
from keys
order by created_at desc

View file

@ -0,0 +1,9 @@
select id,
created_at as "created_at: DateTime<Utc>",
revoked_at as "revoked_at: DateTime<Utc>",
private_der,
public_der
from keys
where revoked_at is not null
order by created_at desc

View file

@ -0,0 +1,9 @@
select id,
created_at as "created_at: DateTime<Utc>",
revoked_at as "revoked_at: DateTime<Utc>",
private_der,
public_der
from keys
where revoked_at is null
order by created_at desc

View file

@ -0,0 +1,10 @@
select id,
created_at as "created_at: DateTime<Utc>",
revoked_at as "revoked_at: DateTime<Utc>",
private_der,
public_der
from keys
where revoked_at is null
order by created_at desc
limit 1

View file

@ -0,0 +1,2 @@
insert into keys (id, private_der, public_der)
values (?, ?, ?)

View file

@ -30,6 +30,90 @@
},
"query": "insert into users (id, is_admin, username, password)\nvalues (?, ?, ?, ?)\n"
},
"56a9c0dff010858189a95087d014c7d0ce930da5d841b9d788a9c0e84b580bc6": {
"describe": {
"columns": [
{
"name": "id",
"ordinal": 0,
"type_info": "Text"
},
{
"name": "created_at: DateTime<Utc>",
"ordinal": 1,
"type_info": "Text"
},
{
"name": "revoked_at: DateTime<Utc>",
"ordinal": 2,
"type_info": "Text"
},
{
"name": "private_der",
"ordinal": 3,
"type_info": "Blob"
},
{
"name": "public_der",
"ordinal": 4,
"type_info": "Blob"
}
],
"nullable": [
false,
false,
true,
false,
false
],
"parameters": {
"Right": 0
}
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n revoked_at as \"revoked_at: DateTime<Utc>\",\n private_der,\n public_der\n\nfrom keys\norder by created_at desc\n"
},
"5f946348ad62389fab3c97a1563d1592cbc5180abbba6d5abd44326bf0862669": {
"describe": {
"columns": [
{
"name": "id",
"ordinal": 0,
"type_info": "Text"
},
{
"name": "created_at: DateTime<Utc>",
"ordinal": 1,
"type_info": "Text"
},
{
"name": "revoked_at: DateTime<Utc>",
"ordinal": 2,
"type_info": "Text"
},
{
"name": "private_der",
"ordinal": 3,
"type_info": "Blob"
},
{
"name": "public_der",
"ordinal": 4,
"type_info": "Blob"
}
],
"nullable": [
false,
false,
true,
false,
false
],
"parameters": {
"Right": 0
}
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n revoked_at as \"revoked_at: DateTime<Utc>\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is not null\norder by created_at desc\n"
},
"62c75412f673f6a293b0d188d79c50676ec21cf94e2e50e18f9279c91e6b85c8": {
"describe": {
"columns": [],
@ -166,6 +250,48 @@
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n updated_at as \"updated_at: DateTime<Utc>\",\n is_admin as \"is_admin: bool\",\n username,\n name,\n email,\n password,\n password_recover,\n paper_key,\n is_archived as \"is_archived: bool\"\nfrom users\n\nwhere email is (?)\n"
},
"6e1431ff2b4f589daaa7b221c1bc2a08ee378949fb27988531210ee75fc88298": {
"describe": {
"columns": [
{
"name": "id",
"ordinal": 0,
"type_info": "Text"
},
{
"name": "created_at: DateTime<Utc>",
"ordinal": 1,
"type_info": "Text"
},
{
"name": "revoked_at: DateTime<Utc>",
"ordinal": 2,
"type_info": "Text"
},
{
"name": "private_der",
"ordinal": 3,
"type_info": "Blob"
},
{
"name": "public_der",
"ordinal": 4,
"type_info": "Blob"
}
],
"nullable": [
false,
false,
true,
false,
false
],
"parameters": {
"Right": 0
}
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n revoked_at as \"revoked_at: DateTime<Utc>\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is null\norder by created_at desc\nlimit 1\n"
},
"87906834faa6f185aee0e4d893b9754908b1c173e9dce383663d723891a89cd1": {
"describe": {
"columns": [],
@ -342,6 +468,48 @@
},
"query": "select u.id,\n u.created_at as \"created_at: DateTime<Utc>\",\n u.updated_at as \"updated_at: DateTime<Utc>\",\n u.is_admin as \"is_admin: bool\",\n u.username,\n u.name,\n u.email,\n u.password,\n u.password_recover,\n u.paper_key,\n u.is_archived as \"is_archived: bool\"\nfrom users u\n\n inner join settings s on u.id = s.first_admin\n\nwhere u.is_admin is 1\n and u.is_archived is 0\n and u.id is s.first_admin\n\nlimit 1"
},
"d166553746afb2d3eaa1ddcb9986b7b9723258f4051bce8287038e3dd1ac928a": {
"describe": {
"columns": [
{
"name": "id",
"ordinal": 0,
"type_info": "Text"
},
{
"name": "created_at: DateTime<Utc>",
"ordinal": 1,
"type_info": "Text"
},
{
"name": "revoked_at: DateTime<Utc>",
"ordinal": 2,
"type_info": "Text"
},
{
"name": "private_der",
"ordinal": 3,
"type_info": "Blob"
},
{
"name": "public_der",
"ordinal": 4,
"type_info": "Blob"
}
],
"nullable": [
false,
false,
true,
false,
false
],
"parameters": {
"Right": 0
}
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n revoked_at as \"revoked_at: DateTime<Utc>\",\n private_der,\n public_der\n\nfrom keys\nwhere revoked_at is null\norder by created_at desc\n"
},
"f4edf4567542eaead2e0db14b0d4197c5d3c1bc02da1897b571bf63bfcb4526a": {
"describe": {
"columns": [
@ -419,5 +587,15 @@
}
},
"query": "select id,\n created_at as \"created_at: DateTime<Utc>\",\n updated_at as \"updated_at: DateTime<Utc>\",\n is_admin as \"is_admin: bool\",\n username,\n name,\n email,\n password,\n password_recover,\n paper_key,\n is_archived as \"is_archived: bool\"\nfrom users\n\nwhere id is (?)\n"
},
"f705411720bd037562f7e3622832262ac4c0a8fc0921fbd934d2b98146d3f413": {
"describe": {
"columns": [],
"nullable": [],
"parameters": {
"Right": 3
}
},
"query": "insert into keys (id, private_der, public_der)\nvalues (?, ?, ?)\n"
}
}

View file

@ -1,5 +1,7 @@
mod keys;
mod settings;
mod users;
pub use keys::Keys;
pub use settings::Settings;
pub use users::Users;

View file

@ -0,0 +1,66 @@
use crate::error::{handle_error, Error};
use sqlx::sqlite::SqliteQueryResult;
use sqlx::types::chrono::{DateTime, Utc};
use sqlx::{FromRow, SqliteExecutor};
#[derive(FromRow)]
pub struct Keys {
pub id: String,
pub created_at: DateTime<Utc>,
pub revoked_at: Option<DateTime<Utc>>,
pub private_der: Vec<u8>,
pub public_der: Vec<u8>,
}
impl Keys {
pub async fn insert(
conn: impl SqliteExecutor<'_>,
id: &str,
private_der: &[u8],
public_der: &[u8],
) -> Result<Option<()>, Error> {
let query: SqliteQueryResult =
sqlx::query_file!("queries/keys/insert.sql", id, private_der, public_der)
.execute(conn)
.await
.map_err(handle_error)?;
Ok((query.rows_affected() == 1).then_some(()))
}
pub async fn get_most_recent(conn: impl SqliteExecutor<'_>) -> Result<Option<Self>, Error> {
sqlx::query_file_as!(Self, "queries/keys/get_most_recent.sql")
.fetch_optional(conn)
.await
.map_err(handle_error)
}
pub async fn get_all(
conn: impl SqliteExecutor<'_>,
filter_get_revoked: Option<bool>,
) -> Result<Vec<Self>, Error> {
match filter_get_revoked {
Some(true) => {
// Get all revoked keys
sqlx::query_file_as!(Self, "queries/keys/get_all_revoked.sql")
.fetch_all(conn)
.await
.map_err(handle_error)
}
Some(false) => {
// Get all valid keys
sqlx::query_file_as!(Self, "queries/keys/get_all_valid.sql")
.fetch_all(conn)
.await
.map_err(handle_error)
}
None => {
// Get all keys
sqlx::query_file_as!(Self, "queries/keys/get_all.sql")
.fetch_all(conn)
.await
.map_err(handle_error)
}
}
}
}