blob: 0924e9bc3c6aa08d338d09d34b2f62b4a504af49 [file] [log] [blame]
Junxiao Shid7631272016-08-17 04:16:31 +00001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/**
Alexander Afanasyev635bf202017-03-09 21:57:34 +00003 * Copyright (c) 2014-2017, Regents of the University of California,
Junxiao Shid7631272016-08-17 04:16:31 +00004 * Arizona Board of Regents,
5 * Colorado State University,
6 * University Pierre & Marie Curie, Sorbonne University,
7 * Washington University in St. Louis,
8 * Beijing Institute of Technology,
9 * The University of Memphis.
10 *
11 * This file is part of NFD (Named Data Networking Forwarding Daemon).
12 * See AUTHORS.md for complete list of NFD authors and contributors.
13 *
14 * NFD is free software: you can redistribute it and/or modify it under the terms
15 * of the GNU General Public License as published by the Free Software Foundation,
16 * either version 3 of the License, or (at your option) any later version.
17 *
18 * NFD is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
19 * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
20 * PURPOSE. See the GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License along with
23 * NFD, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
24 */
25
26#ifndef NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP
27#define NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP
28
29#include "core/config-file.hpp"
30#include <ndn-cxx/mgmt/dispatcher.hpp>
Junxiao Shi16a3adf2017-05-26 17:38:51 +000031#include <ndn-cxx/security/v2/certificate.hpp>
Junxiao Shid7631272016-08-17 04:16:31 +000032
33namespace nfd {
34
35/** \brief provides ControlCommand authorization according to NFD configuration file
36 */
37class CommandAuthenticator : public enable_shared_from_this<CommandAuthenticator>, noncopyable
38{
39public:
40 static shared_ptr<CommandAuthenticator>
41 create();
42
43 void
44 setConfigFile(ConfigFile& configFile);
45
46 /** \return an Authorization function for module/verb command
47 * \param module management module name
48 * \param verb command verb; currently it's ignored
49 * \note This must be called before parsing configuration file
50 */
51 ndn::mgmt::Authorization
52 makeAuthorization(const std::string& module, const std::string& verb);
53
54private:
55 CommandAuthenticator();
56
57 /** \brief process "authorizations" section
58 * \throw ConfigFile::Error on parse error
59 */
60 void
61 processConfig(const ConfigSection& section, bool isDryRun, const std::string& filename);
62
63 static std::pair<bool, Name>
64 extractKeyName(const Interest& interest);
65
66private:
67 struct AuthorizedCerts
68 {
69 bool allowAny = false;
Junxiao Shi16a3adf2017-05-26 17:38:51 +000070 std::unordered_map<Name, ndn::security::v2::Certificate> certs; ///< keyName => cert
Junxiao Shid7631272016-08-17 04:16:31 +000071 };
72 std::unordered_map<std::string, AuthorizedCerts> m_moduleAuth; ///< module => certs
Junxiao Shid7631272016-08-17 04:16:31 +000073};
74
75} // namespace nfd
76
77#endif // NFD_DAEMON_MGMT_COMMAND_AUTHENTICATOR_HPP