blob: fb2572b9934e971d9fb7f0d5a93b5eda29d73dc5 [file] [log] [blame]
Yingdi Yu6ac97982014-01-30 14:49:21 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil -*- */
2/**
3 * Copyright (C) 2013 Regents of the University of California.
4 * @author: Yingdi Yu <yingdi@cs.ucla.edu>
5 * See COPYING for copyright and distribution information.
6 */
7
Yingdi Yufc40d872014-02-18 12:56:04 -08008#ifndef NDN_SECURITY_VALIDATOR_REGEX_HPP
9#define NDN_SECURITY_VALIDATOR_REGEX_HPP
Yingdi Yu6ac97982014-01-30 14:49:21 -080010
11#include "validator.hpp"
12#include "identity-certificate.hpp"
13#include "sec-rule-relative.hpp"
14#include "certificate-cache.hpp"
15#include "../util/regex.hpp"
16
Yingdi Yu6ac97982014-01-30 14:49:21 -080017namespace ndn {
18
19class ValidatorRegex : public Validator
20{
21public:
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070022 class Error : public Validator::Error
23 {
24 public:
25 explicit
26 Error(const std::string& what)
27 : Validator::Error(what)
28 {
29 }
30 };
Yingdi Yu6ac97982014-01-30 14:49:21 -080031
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070032 static const shared_ptr<CertificateCache> DEFAULT_CERTIFICATE_CACHE;
33
Yingdi Yu96e64062014-04-15 19:57:33 -070034 ValidatorRegex(Face& face,
35 shared_ptr<CertificateCache> certificateCache = DEFAULT_CERTIFICATE_CACHE,
36 const int stepLimit = 3);
37
38 /**
39 * \deprecated Use the other version of the constructor
40 */
41 ValidatorRegex(const shared_ptr<Face>& face,
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070042 shared_ptr<CertificateCache> certificateCache = DEFAULT_CERTIFICATE_CACHE,
Yingdi Yu6ac97982014-01-30 14:49:21 -080043 const int stepLimit = 3);
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070044
45 virtual
46 ~ValidatorRegex()
47 {
48 }
49
Yingdi Yu6ac97982014-01-30 14:49:21 -080050 /**
51 * @brief Add a rule for data verification.
52 *
53 * @param policy The verification rule
54 */
55 inline void
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070056 addDataVerificationRule(shared_ptr<SecRuleRelative> rule);
57
Yingdi Yu6ac97982014-01-30 14:49:21 -080058 /**
59 * @brief Add a trust anchor
60 *
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070061 * @param certificate The trust anchor
Yingdi Yu6ac97982014-01-30 14:49:21 -080062 */
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070063 inline void
Yingdi Yu6ac97982014-01-30 14:49:21 -080064 addTrustAnchor(shared_ptr<IdentityCertificate> certificate);
65
66protected:
67 virtual void
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070068 checkPolicy(const Data& data,
Yingdi Yu4b8c6a22014-04-15 23:00:54 -070069 int nSteps,
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070070 const OnDataValidated& onValidated,
71 const OnDataValidationFailed& onValidationFailed,
72 std::vector<shared_ptr<ValidationRequest> >& nextSteps);
Yingdi Yu6ac97982014-01-30 14:49:21 -080073
Yingdi Yu9a335352014-01-31 11:57:46 -080074 virtual void
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070075 checkPolicy(const Interest& interest,
Yingdi Yu4b8c6a22014-04-15 23:00:54 -070076 int nSteps,
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070077 const OnInterestValidated& onValidated,
78 const OnInterestValidationFailed& onValidationFailed,
79 std::vector<shared_ptr<ValidationRequest> >& nextSteps)
80 {
81 onValidationFailed(interest.shared_from_this(), "No policy for signed interest checking");
82 }
Yingdi Yu9a335352014-01-31 11:57:46 -080083
Yingdi Yu6ac97982014-01-30 14:49:21 -080084 void
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070085 onCertificateValidated(const shared_ptr<const Data>& signCertificate,
86 const shared_ptr<const Data>& data,
87 const OnDataValidated& onValidated,
88 const OnDataValidationFailed& onValidationFailed);
89
Yingdi Yu6ac97982014-01-30 14:49:21 -080090 void
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070091 onCertificateValidationFailed(const shared_ptr<const Data>& signCertificate,
Yingdi Yu40587c02014-02-21 16:40:48 -080092 const std::string& failureInfo,
Yingdi Yu48e8c0c2014-03-19 12:01:55 -070093 const shared_ptr<const Data>& data,
94 const OnDataValidationFailed& onValidationFailed);
95
Yingdi Yu6ac97982014-01-30 14:49:21 -080096protected:
97 typedef std::vector< shared_ptr<SecRuleRelative> > RuleList;
98 typedef std::vector< shared_ptr<Regex> > RegexList;
99
100 int m_stepLimit;
101 shared_ptr<CertificateCache> m_certificateCache;
102 RuleList m_mustFailVerify;
103 RuleList m_verifyPolicies;
104 std::map<Name, shared_ptr<IdentityCertificate> > m_trustAnchors;
105};
106
Yingdi Yu48e8c0c2014-03-19 12:01:55 -0700107inline void
108ValidatorRegex::addDataVerificationRule(shared_ptr<SecRuleRelative> rule)
109{
110 rule->isPositive() ? m_verifyPolicies.push_back(rule) : m_mustFailVerify.push_back(rule);
111}
112
113inline void
Yingdi Yu6ac97982014-01-30 14:49:21 -0800114ValidatorRegex::addTrustAnchor(shared_ptr<IdentityCertificate> certificate)
Yingdi Yu48e8c0c2014-03-19 12:01:55 -0700115{
116 m_trustAnchors[certificate->getName().getPrefix(-1)] = certificate;
117}
Yingdi Yu6ac97982014-01-30 14:49:21 -0800118
Yingdi Yufc40d872014-02-18 12:56:04 -0800119} // namespace ndn
Yingdi Yu6ac97982014-01-30 14:49:21 -0800120
Yingdi Yufc40d872014-02-18 12:56:04 -0800121#endif //NDN_SECURITY_VALIDATOR_REGEX_HPP