mirror of
https://github.com/passbolt/go-passbolt.git
synced 2025-05-14 19:38:22 +00:00
move and rework secret Validation
This commit is contained in:
parent
f57fc2e8ac
commit
5cf7839a42
2 changed files with 63 additions and 45 deletions
63
helper/secret.go
Normal file
63
helper/secret.go
Normal file
|
@ -0,0 +1,63 @@
|
||||||
|
package helper
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/passbolt/go-passbolt/api"
|
||||||
|
"github.com/santhosh-tekuri/jsonschema"
|
||||||
|
)
|
||||||
|
|
||||||
|
func validateSecretData(rType *api.ResourceType, secretData string) error {
|
||||||
|
var schemaDefinition api.ResourceTypeSchema
|
||||||
|
definition := rType.Definition
|
||||||
|
|
||||||
|
// Fallback schema
|
||||||
|
if string(definition) == "[]" || string(definition) == "\"[]\"" {
|
||||||
|
tmp, ok := api.ResourceSchemas[rType.Slug]
|
||||||
|
if !ok {
|
||||||
|
return fmt.Errorf("Server Does not have the Required json Schema and there is no fallback available for type: %v", rType.Slug)
|
||||||
|
}
|
||||||
|
definition = tmp
|
||||||
|
}
|
||||||
|
|
||||||
|
err := json.Unmarshal([]byte(definition), &schemaDefinition)
|
||||||
|
if err != nil {
|
||||||
|
// Workaround for inconsistant API Responses where sometime the Schema is embedded directly and sometimes it's escaped as a string
|
||||||
|
if err.Error() == "json: cannot unmarshal string into Go value of type api.ResourceTypeSchema" {
|
||||||
|
var tmp string
|
||||||
|
err = json.Unmarshal([]byte(definition), &tmp)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("Workaround Unmarshal Json Schema String: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = json.Unmarshal([]byte(tmp), &schemaDefinition)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("Workaround Unmarshal Json Schema: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
} else {
|
||||||
|
return fmt.Errorf("Unmarshal Json Schema: %w", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
comp := jsonschema.NewCompiler()
|
||||||
|
|
||||||
|
err = comp.AddResource("secret.json", bytes.NewReader(schemaDefinition.Secret))
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("Adding Json Schema: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
schema, err := comp.Compile("secret.json")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("Compiling Json Schema: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = schema.Validate(strings.NewReader(secretData))
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("Validating Secret Data: %w", err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
|
@ -1,13 +1,9 @@
|
||||||
package helper
|
package helper
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"strings"
|
|
||||||
|
|
||||||
"github.com/passbolt/go-passbolt/api"
|
"github.com/passbolt/go-passbolt/api"
|
||||||
"github.com/santhosh-tekuri/jsonschema"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func getPublicKeyByUserID(userID string, Users []api.User) (string, error) {
|
func getPublicKeyByUserID(userID string, Users []api.User) (string, error) {
|
||||||
|
@ -36,44 +32,3 @@ func getSecretByResourceID(secrets []api.Secret, resourceID string) (*api.Secret
|
||||||
}
|
}
|
||||||
return nil, fmt.Errorf("Cannot Find Secret for id %v", resourceID)
|
return nil, fmt.Errorf("Cannot Find Secret for id %v", resourceID)
|
||||||
}
|
}
|
||||||
|
|
||||||
func validateSecretData(rType *api.ResourceType, secretData string) error {
|
|
||||||
var schemaDefinition api.ResourceTypeSchema
|
|
||||||
err := json.Unmarshal([]byte(rType.Definition), &schemaDefinition)
|
|
||||||
if err != nil {
|
|
||||||
// Workaround for inconsistant API Responses where sometime the Schema is embedded directly and sometimes it's escaped as a string
|
|
||||||
if err.Error() == "json: cannot unmarshal string into Go value of type api.ResourceTypeSchema" {
|
|
||||||
var tmp string
|
|
||||||
err = json.Unmarshal([]byte(rType.Definition), &tmp)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("Workaround Unmarshal Json Schema String: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
err = json.Unmarshal([]byte(tmp), &schemaDefinition)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("Workaround Unmarshal Json Schema: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
} else {
|
|
||||||
return fmt.Errorf("Unmarshal Json Schema: %w", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
comp := jsonschema.NewCompiler()
|
|
||||||
|
|
||||||
err = comp.AddResource("secret.json", bytes.NewReader(schemaDefinition.Secret))
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("Adding Json Schema: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
schema, err := comp.Compile("secret.json")
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("Compiling Json Schema: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
err = schema.Validate(strings.NewReader(secretData))
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("Validating Secret Data: %w", err)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue