blob: 69d0ec9fdedaf8f5696155e0cc12886f21d7b678 [file] [log] [blame]
Junxiao Shid7631272016-08-17 04:16:31 +00001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/**
3 * Copyright (c) 2014-2016, Regents of the University of California,
4 * Arizona Board of Regents,
5 * Colorado State University,
6 * University Pierre & Marie Curie, Sorbonne University,
7 * Washington University in St. Louis,
8 * Beijing Institute of Technology,
9 * The University of Memphis.
10 *
11 * This file is part of NFD (Named Data Networking Forwarding Daemon).
12 * See AUTHORS.md for complete list of NFD authors and contributors.
13 *
14 * NFD is free software: you can redistribute it and/or modify it under the terms
15 * of the GNU General Public License as published by the Free Software Foundation,
16 * either version 3 of the License, or (at your option) any later version.
17 *
18 * NFD is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
19 * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
20 * PURPOSE. See the GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License along with
23 * NFD, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
24 */
25
26#ifndef NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP
27#define NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP
28
29#include "core/config-file.hpp"
30#include <ndn-cxx/mgmt/dispatcher.hpp>
31#include <ndn-cxx/security/command-interest-validator.hpp>
32#include <ndn-cxx/security/public-key.hpp>
33
34namespace nfd {
35
36/** \brief provides ControlCommand authorization according to NFD configuration file
37 */
38class CommandAuthenticator : public enable_shared_from_this<CommandAuthenticator>, noncopyable
39{
40public:
41 static shared_ptr<CommandAuthenticator>
42 create();
43
44 void
45 setConfigFile(ConfigFile& configFile);
46
47 /** \return an Authorization function for module/verb command
48 * \param module management module name
49 * \param verb command verb; currently it's ignored
50 * \note This must be called before parsing configuration file
51 */
52 ndn::mgmt::Authorization
53 makeAuthorization(const std::string& module, const std::string& verb);
54
55private:
56 CommandAuthenticator();
57
58 /** \brief process "authorizations" section
59 * \throw ConfigFile::Error on parse error
60 */
61 void
62 processConfig(const ConfigSection& section, bool isDryRun, const std::string& filename);
63
64 static std::pair<bool, Name>
65 extractKeyName(const Interest& interest);
66
67private:
68 struct AuthorizedCerts
69 {
70 bool allowAny = false;
71 std::unordered_map<Name, ndn::PublicKey> certs; ///< keyName => publicKey
72 };
73 std::unordered_map<std::string, AuthorizedCerts> m_moduleAuth; ///< module => certs
74
75 ndn::security::CommandInterestValidator m_validator;
76};
77
78} // namespace nfd
79
80#endif // NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP