sig-auth/main.go

125 lines
2.3 KiB
Go
Raw Normal View History

2025-02-10 23:07:41 -05:00
package main
import (
"bytes"
"crypto"
"encoding/json"
2025-02-14 19:41:22 -05:00
"flag"
2025-02-10 23:07:41 -05:00
"fmt"
2025-02-14 19:41:22 -05:00
"io"
2025-02-10 23:07:41 -05:00
"log"
2025-02-14 19:41:22 -05:00
"net/http"
2025-02-10 23:07:41 -05:00
"os"
"crispbyte.dev/sig-auth/client"
2025-02-14 19:41:22 -05:00
"crispbyte.dev/sig-auth/server"
2025-02-14 19:41:22 -05:00
"github.com/opencontainers/go-digest"
2025-02-10 23:07:41 -05:00
"golang.org/x/crypto/ssh"
)
func main() {
2025-02-14 19:41:22 -05:00
useClient := flag.Bool("c", false, "Run client")
2025-02-16 13:57:24 -05:00
keyPath := flag.String("key", "", "Path to the private key (client mode) or public key (server mode) to use - Required")
2025-02-14 19:41:22 -05:00
2025-02-16 13:51:53 -05:00
simulateCaddy := flag.Bool("caddy", false, "Simulate caddy reverse proxy")
2025-02-14 19:41:22 -05:00
flag.Parse()
2025-02-16 13:57:24 -05:00
if *keyPath == "" {
flag.PrintDefaults()
return
}
2025-02-14 19:41:22 -05:00
if *useClient {
2025-02-16 13:51:53 -05:00
runClient(keyPath, *simulateCaddy)
2025-02-14 19:41:22 -05:00
} else {
2025-02-16 13:51:53 -05:00
runServer(keyPath, *simulateCaddy)
2025-02-14 19:41:22 -05:00
}
}
2025-02-16 13:51:53 -05:00
func runClient(keyFile *string, simulateCaddy bool) {
2025-02-10 23:07:41 -05:00
testData := map[string]string{"hello": "world"}
json_data, _ := json.Marshal(testData)
2025-02-14 19:41:22 -05:00
key, err := loadPrivateKey(*keyFile)
2025-02-10 23:07:41 -05:00
if err != nil {
log.Fatal(err)
}
client, err := client.GetSigningClient(key, "test-id")
if err != nil {
log.Fatal(err)
}
2025-02-14 19:41:22 -05:00
id := digest.FromBytes(json_data)
2025-02-16 13:51:53 -05:00
var req *http.Request
req, err = http.NewRequest("POST", "http://localhost:8080/post", bytes.NewBuffer(json_data))
2025-02-14 19:41:22 -05:00
if err != nil {
log.Fatal(err)
}
req.Header.Add("Content-Digest", string(id.Algorithm())+"="+id.Encoded())
req.Header.Add("Content-Type", "application/json")
2025-02-16 13:51:53 -05:00
if simulateCaddy {
req.Header.Add("X-Forwarded-Method", req.Method)
req.Header.Add("X-Forwarded-Uri", req.RequestURI)
}
2025-02-14 19:41:22 -05:00
resp, err := client.Do(req)
2025-02-10 23:07:41 -05:00
if err != nil {
log.Fatal(err)
}
defer resp.Body.Close()
2025-02-14 19:41:22 -05:00
out, err := io.ReadAll(resp.Body)
if err != nil {
log.Fatal(err)
}
fmt.Println(resp.StatusCode)
2025-02-16 13:51:53 -05:00
fmt.Println(resp.Header)
2025-02-14 19:41:22 -05:00
fmt.Println(string(out[:]))
}
2025-02-16 13:51:53 -05:00
func runServer(keyFile *string, simulateCaddy bool) {
2025-02-14 19:41:22 -05:00
key, err := loadPublicKey(*keyFile)
2025-02-10 23:07:41 -05:00
2025-02-14 19:41:22 -05:00
if err != nil {
log.Fatal(err)
}
2025-02-10 23:07:41 -05:00
2025-02-16 13:51:53 -05:00
server.Start(key, simulateCaddy)
2025-02-10 23:07:41 -05:00
}
func loadPrivateKey(keyFile string) (crypto.PrivateKey, error) {
keyBytes, err := os.ReadFile(keyFile)
if err != nil {
return nil, err
}
return ssh.ParseRawPrivateKey(keyBytes)
}
2025-02-14 19:41:22 -05:00
func loadPublicKey(keyFile string) (crypto.PublicKey, error) {
keyBytes, err := os.ReadFile(keyFile)
if err != nil {
return nil, err
}
pk, _, _, _, err := ssh.ParseAuthorizedKey(keyBytes)
return pk.(ssh.CryptoPublicKey).CryptoPublicKey(), err
}