X-Git-Url: https://code.wpia.club/?p=gigi.git;a=blobdiff_plain;f=src%2Forg%2Fcacert%2Fgigi%2FdbObjects%2FDomain.java;h=6b0e82830d07a2f9e0c4121a0910c3217d7674aa;hp=056af154173b7ae9616c1f7c0b4eb07528997e4f;hb=b47144d6f3bf6b6eb1ec477de9d2af38256f074f;hpb=e409ba881965634f63f0b67824bc93dda4ec4327 diff --git a/src/org/cacert/gigi/dbObjects/Domain.java b/src/org/cacert/gigi/dbObjects/Domain.java index 056af154..6b0e8283 100644 --- a/src/org/cacert/gigi/dbObjects/Domain.java +++ b/src/org/cacert/gigi/dbObjects/Domain.java @@ -1,13 +1,23 @@ package org.cacert.gigi.dbObjects; -import java.sql.PreparedStatement; -import java.sql.ResultSet; -import java.sql.SQLException; +import java.io.IOException; +import java.io.InputStream; +import java.net.IDN; +import java.util.Arrays; +import java.util.Collections; +import java.util.HashSet; +import java.util.LinkedList; +import java.util.List; +import java.util.Properties; +import java.util.Set; import org.cacert.gigi.GigiApiException; import org.cacert.gigi.database.DatabaseConnection; +import org.cacert.gigi.database.GigiPreparedStatement; +import org.cacert.gigi.database.GigiResultSet; +import org.cacert.gigi.util.PublicSuffixes; -public class Domain implements IdCachable { +public class Domain implements IdCachable, Verifyable { private User owner; @@ -15,13 +25,25 @@ public class Domain implements IdCachable { private int id; - public Domain(int id) throws SQLException { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT memid, domain FROM `domains` WHERE id=? AND deleted IS NULL"); + private static final Set IDNEnabledTLDs; + + static { + Properties CPS = new Properties(); + try (InputStream resourceAsStream = Domain.class.getResourceAsStream("CPS.properties")) { + CPS.load(resourceAsStream); + IDNEnabledTLDs = Collections.unmodifiableSet(new HashSet<>(Arrays.asList(CPS.getProperty("IDN-enabled").split(",")))); + } catch (IOException e) { + throw new Error(e); + } + } + + private Domain(int id) { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT `memid`, `domain` FROM `domains` WHERE `id`=? AND `deleted` IS NULL"); ps.setInt(1, id); - ResultSet rs = ps.executeQuery(); + GigiResultSet rs = ps.executeQuery(); if ( !rs.next()) { - throw new IllegalArgumentException("Invalid email id " + id); + throw new IllegalArgumentException("Invalid domain id " + id); } this.id = id; owner = User.getById(rs.getInt(1)); @@ -30,64 +52,109 @@ public class Domain implements IdCachable { } public Domain(User owner, String suffix) throws GigiApiException { - this.owner = owner; - this.suffix = suffix; + synchronized (Domain.class) { + checkCertifyableDomain(suffix, owner.isInGroup(Group.CODESIGNING)); + this.owner = owner; + this.suffix = suffix; + insert(); + } + } + public static void checkCertifyableDomain(String s, boolean hasPunycodeRight) throws GigiApiException { + String[] parts = s.split("\\.", -1); + if (parts.length < 2) { + throw new GigiApiException("Domain does not contain '.'."); + } + for (int i = parts.length - 1; i >= 0; i--) { + if ( !isVaildDomainPart(parts[i], hasPunycodeRight)) { + throw new GigiApiException("Syntax error in Domain"); + } + } + String publicSuffix = PublicSuffixes.getInstance().getRegistrablePart(s); + if ( !s.equals(publicSuffix)) { + throw new GigiApiException("You may only register a domain with exactly one lable before the public suffix."); + } + checkPunycode(parts[0], s.substring(parts[0].length() + 1)); } - private static void checkInsert(String suffix) throws GigiApiException { + private static void checkPunycode(String label, String domainContext) throws GigiApiException { + if (label.charAt(2) != '-' || label.charAt(3) != '-') { + return; // is no punycode + } + if ( !IDNEnabledTLDs.contains(domainContext)) { + throw new GigiApiException("Punycode label could not be positively verified."); + } + if ( !label.startsWith("xn--")) { + throw new GigiApiException("Unknown ACE prefix."); + } try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT 1 FROM `domains` WHERE (domain=RIGHT(?,LENGTH(domain)) OR RIGHT(domain,LENGTH(?))=?) AND deleted IS NULL"); - ps.setString(1, suffix); - ps.setString(2, suffix); - ps.setString(3, suffix); - ResultSet rs = ps.executeQuery(); - boolean existed = rs.next(); - rs.close(); - if (existed) { - throw new GigiApiException("Domain could not be inserted. Domain is already valid."); + String unicode = IDN.toUnicode(label); + if (unicode.startsWith("xn--")) { + throw new GigiApiException("Punycode label could not be positively verified."); } - } catch (SQLException e) { - throw new GigiApiException(e); + } catch (IllegalArgumentException e) { + throw new GigiApiException("Punycode label could not be positively verified."); + } + } + + public static boolean isVaildDomainPart(String s, boolean allowPunycode) { + if ( !s.matches("[a-z0-9-]+")) { + return false; + } + if (s.charAt(0) == '-' || s.charAt(s.length() - 1) == '-') { + return false; + } + if (s.length() > 63) { + return false; } + boolean canBePunycode = s.length() >= 4 && s.charAt(2) == '-' && s.charAt(3) == '-'; + if (canBePunycode && !allowPunycode) { + return false; + } + return true; } - public void insert() throws GigiApiException { + private static void checkInsert(String suffix) throws GigiApiException { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT 1 FROM `domains` WHERE (`domain`=? OR (CONCAT('.', `domain`)=RIGHT(?,LENGTH(`domain`)+1) OR RIGHT(`domain`,LENGTH(?)+1)=CONCAT('.',?))) AND `deleted` IS NULL"); + ps.setString(1, suffix); + ps.setString(2, suffix); + ps.setString(3, suffix); + ps.setString(4, suffix); + GigiResultSet rs = ps.executeQuery(); + boolean existed = rs.next(); + rs.close(); + if (existed) { + throw new GigiApiException("Domain could not be inserted. Domain is already valid."); + } + } + + private void insert() throws GigiApiException { if (id != 0) { throw new GigiApiException("already inserted."); } - synchronized (Domain.class) { - checkInsert(suffix); - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("INSERT INTO `domains` SET memid=?, domain=?"); - ps.setInt(1, owner.getId()); - ps.setString(2, suffix); - ps.execute(); - id = DatabaseConnection.lastInsertId(ps); - myCache.put(this); - } catch (SQLException e) { - throw new GigiApiException(e); - } - } + checkInsert(suffix); + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("INSERT INTO `domains` SET memid=?, domain=?"); + ps.setInt(1, owner.getId()); + ps.setString(2, suffix); + ps.execute(); + id = ps.lastInsertId(); + myCache.put(this); } public void delete() throws GigiApiException { if (id == 0) { throw new GigiApiException("not inserted."); } - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("UPDATE `domains` SET deleted=CURRENT_TIMESTAMP WHERE id=?"); - ps.setInt(1, id); - ps.execute(); - } catch (SQLException e) { - throw new GigiApiException(e); - } + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("UPDATE `domains` SET `deleted`=CURRENT_TIMESTAMP WHERE `id`=?"); + ps.setInt(1, id); + ps.execute(); } public User getOwner() { return owner; } + @Override public int getId() { return id; } @@ -96,75 +163,81 @@ public class Domain implements IdCachable { return suffix; } - public void addPing(String type, String config) throws GigiApiException { - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("INSERT INTO pingconfig SET domainid=?, type=?, info=?"); + private LinkedList configs = null; + + public List getConfiguredPings() throws GigiApiException { + LinkedList configs = this.configs; + if (configs == null) { + configs = new LinkedList<>(); + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT id FROM pingconfig WHERE domainid=?"); ps.setInt(1, id); - ps.setString(2, type); - ps.setString(3, config); - ps.execute(); - } catch (SQLException e) { - throw new GigiApiException(e); + GigiResultSet rs = ps.executeQuery(); + while (rs.next()) { + configs.add(DomainPingConfiguration.getById(rs.getInt(1))); + } + rs.close(); + this.configs = configs; + } + return Collections.unmodifiableList(configs); } - public void verify(String hash) throws GigiApiException { - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("UPDATE domainPinglog SET state='success' WHERE challenge=? AND configId IN (SELECT id FROM pingconfig WHERE domainId=?)"); - ps.setString(1, hash); - ps.setInt(2, id); - ps.executeUpdate(); - } catch (SQLException e) { - throw new GigiApiException(e); - } + public void addPing(DomainPingType type, String config) throws GigiApiException { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("INSERT INTO `pingconfig` SET `domainid`=?, `type`=?::`pingType`, `info`=?"); + ps.setInt(1, id); + ps.setString(2, type.toString().toLowerCase()); + ps.setString(3, config); + ps.execute(); + configs = null; + } + + public synchronized void verify(String hash) throws GigiApiException { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("UPDATE `domainPinglog` SET `state`='success' WHERE `challenge`=? AND `configId` IN (SELECT `id` FROM `pingconfig` WHERE `domainid`=?)"); + ps.setString(1, hash); + ps.setInt(2, id); + ps.executeUpdate(); } public boolean isVerified() { - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT 1 FROM domainPinglog INNER JOIN pingconfig ON pingconfig.id=domainPinglog.configId WHERE domainid=? AND state='success'"); - ps.setInt(1, id); - ResultSet rs = ps.executeQuery(); - return rs.next(); - } catch (SQLException e) { - e.printStackTrace(); - } - return false; + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT 1 FROM `domainPinglog` INNER JOIN `pingconfig` ON `pingconfig`.`id`=`domainPinglog`.`configId` WHERE `domainid`=? AND `state`='success'"); + ps.setInt(1, id); + GigiResultSet rs = ps.executeQuery(); + return rs.next(); } - public String[][] getPings() throws GigiApiException { - try { - PreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT state, type, info, result FROM domainPinglog INNER JOIN pingconfig ON pingconfig.id=domainPinglog.configid WHERE pingconfig.domainid=? ORDER BY `when` DESC;"); - ps.setInt(1, id); - ResultSet rs = ps.executeQuery(); - rs.last(); - String[][] contents = new String[rs.getRow()][]; - rs.beforeFirst(); - for (int i = 0; i < contents.length && rs.next(); i++) { - contents[i] = new String[] { - rs.getString(1), rs.getString(2), rs.getString(3), rs.getString(4) - }; - } - return contents; - } catch (SQLException e) { - throw new GigiApiException(e); + public DomainPingExecution[] getPings() throws GigiApiException { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepareScrollable("SELECT `state`, `type`, `info`, `result`, `configId` FROM `domainPinglog` INNER JOIN `pingconfig` ON `pingconfig`.`id`=`domainPinglog`.`configId` WHERE `pingconfig`.`domainid`=? ORDER BY `when` DESC;"); + ps.setInt(1, id); + GigiResultSet rs = ps.executeQuery(); + rs.last(); + DomainPingExecution[] contents = new DomainPingExecution[rs.getRow()]; + rs.beforeFirst(); + for (int i = 0; i < contents.length && rs.next(); i++) { + contents[i] = new DomainPingExecution(rs); } + return contents; } - private static ObjectCache myCache = new ObjectCache<>(); + private static final ObjectCache myCache = new ObjectCache<>(); - public static Domain getById(int id) throws IllegalArgumentException { + public static synchronized Domain getById(int id) throws IllegalArgumentException { Domain em = myCache.get(id); if (em == null) { - try { - synchronized (Domain.class) { - myCache.put(em = new Domain(id)); - } - } catch (SQLException e1) { - throw new IllegalArgumentException(e1); - } + myCache.put(em = new Domain(id)); } return em; } + public static int searchUserIdByDomain(String domain) { + GigiPreparedStatement ps = DatabaseConnection.getInstance().prepare("SELECT `memid` FROM `domains` WHERE `domain` = ?"); + ps.setString(1, domain); + GigiResultSet res = ps.executeQuery(); + if (res.next()) { + return res.getInt(1); + } else { + return -1; + } + } + }