7 #include <log/logger.hpp>
10 PostgresJobProvider::PostgresJobProvider( const std::string& server, const std::string& user, const std::string& password, const std::string& database ):
11 c( "dbname=" + database + " host=" + server + " user=" + user + " password=" + password + " client_encoding=UTF-8 application_name=cassiopeia-client" ) {
12 // TODO better connection string generation??
14 pqxx::result version = txn.exec( "SELECT \"version\" FROM \"schemeVersion\"" );
16 if( version.size() != 1 ) {
17 throw std::runtime_error( "Only one version row expected but multiple found." );
20 if( version[0][0].as<int>() < 33 ) {
21 throw std::runtime_error( "Requires at least database schema version 33. Please update gigi before restarting cassiopeia." );
26 std::shared_ptr<Job> PostgresJobProvider::fetchJob() {
27 std::string q = "SELECT id, \"targetId\", task, \"executeFrom\", \"executeTo\", attempt FROM jobs WHERE state='open' AND attempt < 3";
29 pqxx::result result = txn.exec( q );
32 auto job = std::make_shared<Job>();
34 if( result.size() == 0 ) {
38 job->id = result[0]["id"].as<std::string>();
39 job->target = result[0]["\"targetId\""].as<std::string>();
40 job->task = result[0]["task"].as<std::string>();
41 job->from = result[0]["\"executeFrom\""].as<std::string>( "" );
42 job->to = result[0]["\"executeTo\""].as<std::string>( "" );
43 job->attempt = result[0]["attempt"].as<std::string>();
45 logger::notef( "Got a job: (id=%s, target=%s, task=%s, from=%s, to=%s, attempts=%s)", job->id, job->target, job->task, job->from, job->to, job->attempt );
49 void PostgresJobProvider::finishJob( std::shared_ptr<Job> job ) {
52 std::string q = "UPDATE jobs SET state='done' WHERE id=" + txn.quote( job->id );
53 pqxx::result r = txn.exec( q );
55 if( r.affected_rows() != 1 ) {
56 throw std::runtime_error( "No database entry found." );
59 c.prepare( "insertLog", "INSERT INTO \"jobLog\"(\"jobid\", \"attempt\", \"content\") VALUES($1,$2,$3)" );
60 txn.prepared( "insertLog" )( job->id )( job->attempt )( job->log.str() ).exec();
65 void PostgresJobProvider::failJob( std::shared_ptr<Job> job ) {
68 std::string q = "UPDATE jobs SET attempt = attempt + 1 WHERE id=" + txn.quote( job->id );
69 pqxx::result r = txn.exec( q );
71 if( r.affected_rows() != 1 ) {
72 throw std::runtime_error( "No database entry found." );
75 c.prepare( "insertLog", "INSERT INTO \"jobLog\"(\"jobid\", \"attempt\", \"content\") VALUES($1,$2,$3)" );
76 txn.prepared( "insertLog" )( job->id )( job->attempt )( job->log.str() ).exec();
81 std::shared_ptr<TBSCertificate> PostgresJobProvider::fetchTBSCert( std::shared_ptr<Job> job ) {
83 auto cert = std::make_shared<TBSCertificate>();
84 std::string q = "SELECT md, profile, csr_type, keyname, att.content AS csr FROM certs INNER JOIN profiles ON profiles.id = certs.profile INNER JOIN \"certificateAttachment\" att ON att.certid=certs.id AND att.type='CSR' WHERE certs.id=" + txn.quote( job->target );
85 pqxx::result r = txn.exec( q );
88 throw std::runtime_error( "Error, no or multiple certs found" );
93 std::string profileName = ro["keyname"].as<std::string>();
95 cert->md = ro["md"].as<std::string>();
96 std::string profileId = ro["profile"].as<std::string>();
98 while( profileId.size() < 4 ) {
99 profileId = "0" + profileId;
102 cert->profile = profileId + "-" + profileName;
104 cert->csr_content = ro["csr"].as<std::string>();
105 cert->csr_type = ro["csr_type"].as<std::string>();
107 cert->SANs = std::vector<std::shared_ptr<SAN>>();
109 q = "SELECT contents, type FROM \"subjectAlternativeNames\" WHERE \"certId\"=" + txn.quote( job->target );
112 std::cout << "Fetching SANs" << std::endl;
114 for( auto row = r.begin(); row != r.end(); ++row ) {
115 auto nSAN = std::make_shared<SAN>();
116 nSAN->content = row["contents"].as<std::string>();
117 nSAN->type = row["type"].as<std::string>();
118 cert->SANs.push_back( nSAN );
121 q = "SELECT name, value FROM \"certAvas\" WHERE \"certId\"=" + txn.quote( job->target );
124 for( auto row = r.begin(); row != r.end(); ++row ) {
125 auto nAVA = std::make_shared<AVA>();
126 nAVA->name = row["name"].as<std::string>();
127 nAVA->value = row["value"].as<std::string>();
128 cert->AVAs.push_back( nAVA );
134 std::string pgTime( std::string isoTime ) {
135 return isoTime.substr( 0, 8 ) + " " + isoTime.substr( 8, 6 );
138 void PostgresJobProvider::writeBack( std::shared_ptr<Job> job, std::shared_ptr<SignedCertificate> res ) {
140 std::string id = "SELECT id FROM cacerts WHERE keyname=" + txn.quote( res->ca_name );
141 pqxx::result r = txn.exec( id );
145 if( r.size() != 1 ) {
146 throw std::runtime_error( "Error while inserting new ca cert not found" );
148 read_id = r[0]["id"].as<std::string>();
151 std::string serial = res->serial;
152 std::transform( serial.begin(), serial.end(), serial.begin(), ::tolower );
154 if( serial[0] == '0' ) {
155 serial = serial.substr( 1 );
158 std::string q = "UPDATE certs SET serial=" + txn.quote( serial ) + ", \"caid\" = " + txn.quote( read_id ) + ", created=" + txn.quote( pgTime( res->before ) ) + ", expire=" + txn.quote( pgTime( res->after ) ) + " WHERE id=" + txn.quote( job->target );
159 // TODO write more thingies back
163 if( r.affected_rows() != 1 ) {
164 throw std::runtime_error( "Only one row should be updated." );
167 c.prepare( "insertCrt", "INSERT INTO \"certificateAttachment\"(\"certid\", \"type\", \"content\") VALUES($1,'CRT',$2)" );
168 txn.prepared( "insertCrt" )( job->target )( res->certificate ).exec();
173 std::pair<std::string, std::string> PostgresJobProvider::getRevocationInfo( std::shared_ptr<Job> job ) {
175 std::string q = "SELECT certs.serial, cacerts.keyname FROM certs INNER JOIN cacerts ON certs.\"caid\" = cacerts.id WHERE certs.id = " + txn.quote( job->target );
177 pqxx::result r = txn.exec( q );
179 if( r.size() != 1 ) {
180 throw std::runtime_error( "Only one row expected but multiple found." );
183 return {r[0][0].as<std::string>(), r[0][1].as<std::string>()};
186 void PostgresJobProvider::writeBackRevocation( std::shared_ptr<Job> job, std::string date ) {
187 logger::notef( "Revoking at %s", date );
189 logger::note( "executing" );
190 pqxx::result r = txn.exec( "UPDATE certs SET revoked = " + txn.quote( pgTime( date ) ) + " WHERE id = " + txn.quote( job->target ) );
192 if( r.affected_rows() != 1 ) {
193 throw std::runtime_error( "Only one row should be updated." );
196 logger::note( "committing" );
198 logger::note( "committed" );