Aws s3 connection parameters extension (#89)

* Aws s3 connection parameters extension

* Changed 'save password?' popup to 'change secrets?'

* missing docs
This commit is contained in:
Christian Visintin
2022-01-06 10:44:34 +01:00
parent 53271966da
commit 7d55563556
25 changed files with 830 additions and 114 deletions
+127 -3
View File
@@ -167,7 +167,38 @@ impl BookmarksClient {
*pwd = decrypted_pwd;
}
Err(err) => {
error!("Failed to decrypt password for bookmark: {}", err);
error!("Failed to decrypt `password` for bookmark {}: {}", key, err);
}
}
}
// Decrypt AWS-S3 params
if let Some(s3) = entry.s3.as_mut() {
// Access key
if let Some(access_key) = s3.access_key.as_mut() {
match self.decrypt_str(access_key.as_str()) {
Ok(plain) => {
*access_key = plain;
}
Err(err) => {
error!(
"Failed to decrypt `access_key` for bookmark {}: {}",
key, err
);
}
}
}
// Secret access key
if let Some(secret_access_key) = s3.secret_access_key.as_mut() {
match self.decrypt_str(secret_access_key.as_str()) {
Ok(plain) => {
*secret_access_key = plain;
}
Err(err) => {
error!(
"Failed to decrypt `secret_access_key` for bookmark {}: {}",
key, err
);
}
}
}
}
@@ -190,9 +221,13 @@ impl BookmarksClient {
// Make bookmark
info!("Added bookmark {}", name);
let mut host: Bookmark = self.make_bookmark(params);
// If not save_password, set password to `None`
// If not save_password, set secrets to `None`
if !save_password {
host.password = None;
if let Some(s3) = host.s3.as_mut() {
s3.access_key = None;
s3.secret_access_key = None;
}
}
self.hosts.bookmarks.insert(name, host);
}
@@ -221,6 +256,10 @@ impl BookmarksClient {
let mut host: Bookmark = self.make_bookmark(params);
// Null password for recents
host.password = None;
if let Some(s3) = host.s3.as_mut() {
s3.access_key = None;
s3.secret_access_key = None;
}
// Check if duplicated
for (key, value) in &self.hosts.recents {
if *value == host {
@@ -321,6 +360,15 @@ impl BookmarksClient {
if let Some(pwd) = bookmark.password {
bookmark.password = Some(self.encrypt_str(pwd.as_str()));
}
// Encrypt aws s3 params
if let Some(s3) = bookmark.s3.as_mut() {
if let Some(access_key) = s3.access_key.as_mut() {
*access_key = self.encrypt_str(access_key.as_str());
}
if let Some(secret_access_key) = s3.secret_access_key.as_mut() {
*secret_access_key = self.encrypt_str(secret_access_key.as_str());
}
}
bookmark
}
@@ -346,7 +394,7 @@ impl BookmarksClient {
mod tests {
use super::*;
use crate::filetransfer::params::GenericProtocolParams;
use crate::filetransfer::params::{AwsS3Params, GenericProtocolParams};
use crate::filetransfer::{FileTransferProtocol, ProtocolParams};
use pretty_assertions::assert_eq;
@@ -441,6 +489,69 @@ mod tests {
assert_eq!(bookmark.4, None);
}
#[test]
fn should_make_s3_bookmark_with_secrets() {
let tmp_dir: tempfile::TempDir = TempDir::new().ok().unwrap();
let (cfg_path, key_path): (PathBuf, PathBuf) = get_paths(tmp_dir.path());
// Initialize a new bookmarks client
let mut client: BookmarksClient =
BookmarksClient::new(cfg_path.as_path(), key_path.as_path(), 16).unwrap();
// Add s3 bookmark
client.add_bookmark("my-bucket", make_s3_ftparams(), true);
// Verify bookmark
let bookmark = client.get_bookmark("my-bucket").unwrap();
assert_eq!(bookmark.protocol, FileTransferProtocol::AwsS3);
let params = bookmark.params.s3_params().unwrap();
assert_eq!(params.access_key.as_deref().unwrap(), "pippo");
assert_eq!(params.profile.as_deref().unwrap(), "test");
assert_eq!(params.secret_access_key.as_deref().unwrap(), "pluto");
assert_eq!(params.bucket_name.as_str(), "omar");
assert_eq!(params.region.as_str(), "eu-west-1");
}
#[test]
fn should_make_s3_bookmark_without_secrets() {
let tmp_dir: tempfile::TempDir = TempDir::new().ok().unwrap();
let (cfg_path, key_path): (PathBuf, PathBuf) = get_paths(tmp_dir.path());
// Initialize a new bookmarks client
let mut client: BookmarksClient =
BookmarksClient::new(cfg_path.as_path(), key_path.as_path(), 16).unwrap();
// Add s3 bookmark
client.add_bookmark("my-bucket", make_s3_ftparams(), false);
// Verify bookmark
let bookmark = client.get_bookmark("my-bucket").unwrap();
assert_eq!(bookmark.protocol, FileTransferProtocol::AwsS3);
let params = bookmark.params.s3_params().unwrap();
assert_eq!(params.profile.as_deref().unwrap(), "test");
assert_eq!(params.bucket_name.as_str(), "omar");
assert_eq!(params.region.as_str(), "eu-west-1");
// secrets
assert_eq!(params.access_key, None);
assert_eq!(params.secret_access_key, None);
}
#[test]
fn should_make_s3_recent() {
let tmp_dir: tempfile::TempDir = TempDir::new().ok().unwrap();
let (cfg_path, key_path): (PathBuf, PathBuf) = get_paths(tmp_dir.path());
// Initialize a new bookmarks client
let mut client: BookmarksClient =
BookmarksClient::new(cfg_path.as_path(), key_path.as_path(), 16).unwrap();
// Add s3 bookmark
client.add_recent(make_s3_ftparams());
// Verify bookmark
let bookmark = client.iter_recents().next().unwrap();
let bookmark = client.get_recent(bookmark).unwrap();
assert_eq!(bookmark.protocol, FileTransferProtocol::AwsS3);
let params = bookmark.params.s3_params().unwrap();
assert_eq!(params.profile.as_deref().unwrap(), "test");
assert_eq!(params.bucket_name.as_str(), "omar");
assert_eq!(params.region.as_str(), "eu-west-1");
// secrets
assert_eq!(params.access_key, None);
assert_eq!(params.secret_access_key, None);
}
#[test]
fn test_system_bookmarks_manipulate_bookmarks() {
@@ -734,6 +845,19 @@ mod tests {
FileTransferParams::new(protocol, params)
}
fn make_s3_ftparams() -> FileTransferParams {
FileTransferParams::new(
FileTransferProtocol::AwsS3,
ProtocolParams::AwsS3(
AwsS3Params::new("omar", "eu-west-1", Some("test"))
.access_key(Some("pippo"))
.secret_access_key(Some("pluto"))
.security_token(Some("omar"))
.session_token(Some("gerry-scotti")),
),
)
}
fn ftparams_to_tup(
params: FileTransferParams,
) -> (String, u16, FileTransferProtocol, String, Option<String>) {
+28 -27
View File
@@ -37,32 +37,6 @@ pub struct SshKeyStorage {
}
impl SshKeyStorage {
/// Create a `SshKeyStorage` starting from a `ConfigClient`
pub fn storage_from_config(cfg_client: &ConfigClient) -> Self {
let mut hosts: HashMap<String, PathBuf> =
HashMap::with_capacity(cfg_client.iter_ssh_keys().count());
debug!("Setting up SSH key storage");
// Iterate over keys
for key in cfg_client.iter_ssh_keys() {
match cfg_client.get_ssh_key(key) {
Ok(host) => match host {
Some((addr, username, rsa_key_path)) => {
let key_name: String = Self::make_mapkey(&addr, &username);
hosts.insert(key_name, rsa_key_path);
}
None => continue,
},
Err(err) => {
error!("Failed to get SSH key for {}: {}", key, err);
continue;
}
}
info!("Got SSH key for {}", key);
}
// Return storage
SshKeyStorage { hosts }
}
/// Create an empty ssh key storage; used in case `ConfigClient` is not available
#[cfg(test)]
pub fn empty() -> Self {
@@ -92,6 +66,33 @@ impl SshKeyStorageT for SshKeyStorage {
}
}
impl From<&ConfigClient> for SshKeyStorage {
fn from(cfg_client: &ConfigClient) -> Self {
let mut hosts: HashMap<String, PathBuf> =
HashMap::with_capacity(cfg_client.iter_ssh_keys().count());
debug!("Setting up SSH key storage");
// Iterate over keys
for key in cfg_client.iter_ssh_keys() {
match cfg_client.get_ssh_key(key) {
Ok(host) => match host {
Some((addr, username, rsa_key_path)) => {
let key_name: String = Self::make_mapkey(&addr, &username);
hosts.insert(key_name, rsa_key_path);
}
None => continue,
},
Err(err) => {
error!("Failed to get SSH key for {}: {}", key, err);
continue;
}
}
info!("Got SSH key for {}", key);
}
// Return storage
SshKeyStorage { hosts }
}
}
#[cfg(test)]
mod tests {
@@ -113,7 +114,7 @@ mod tests {
.add_ssh_key("192.168.1.31", "pi", "piroporopero")
.is_ok());
// Create ssh key storage
let storage: SshKeyStorage = SshKeyStorage::storage_from_config(&client);
let storage: SshKeyStorage = SshKeyStorage::from(&client);
// Verify key exists
let mut exp_key_path: PathBuf = key_path.clone();
exp_key_path.push("pi@192.168.1.31.key");