kanidmd_lib/valueset/
jws.rs1use crate::prelude::*;
2use crate::schema::SchemaAttribute;
3use crate::valueset::ScimResolveStatus;
4use crate::valueset::{DbValueSetV2, ValueSet};
5use base64urlsafedata::Base64UrlSafeData;
6use compact_jwt::{crypto::JwsRs256Signer, JwsEs256Signer, JwsSigner};
7use crypto_glue::traits::Zeroizing;
8use hashbrown::HashSet;
9
10#[derive(Debug, Clone)]
11pub struct ValueSetJwsKeyEs256 {
12 set: HashSet<JwsEs256Signer>,
13}
14
15impl ValueSetJwsKeyEs256 {
16 pub fn new(k: JwsEs256Signer) -> Box<Self> {
17 let mut set = HashSet::new();
18 set.insert(k);
19 Box::new(ValueSetJwsKeyEs256 { set })
20 }
21
22 pub fn push(&mut self, k: JwsEs256Signer) -> bool {
23 self.set.insert(k)
24 }
25
26 pub fn from_dbvs2(data: &[Zeroizing<Vec<u8>>]) -> Result<ValueSet, OperationError> {
27 let set = data
28 .iter()
29 .map(|b| {
30 JwsEs256Signer::from_es256_der(b).map_err(|e| {
31 debug!(?e, "Error occurred parsing ES256 DER");
32 OperationError::InvalidValueState
33 })
34 })
35 .collect::<Result<HashSet<_>, _>>()?;
36 Ok(Box::new(ValueSetJwsKeyEs256 { set }))
37 }
38
39 pub fn from_repl_v1(data: &[Base64UrlSafeData]) -> Result<ValueSet, OperationError> {
40 let set = data
41 .iter()
42 .map(|b| {
43 JwsEs256Signer::from_es256_der(b.as_slice()).map_err(|e| {
44 debug!(?e, "Error occurred parsing ES256 DER");
45 OperationError::InvalidValueState
46 })
47 })
48 .collect::<Result<HashSet<_>, _>>()?;
49 Ok(Box::new(ValueSetJwsKeyEs256 { set }))
50 }
51
52 #[allow(clippy::should_implement_trait)]
55 pub fn from_iter<T>(iter: T) -> Option<Box<ValueSetJwsKeyEs256>>
56 where
57 T: IntoIterator<Item = JwsEs256Signer>,
58 {
59 let set: HashSet<JwsEs256Signer> = iter.into_iter().collect();
60 Some(Box::new(ValueSetJwsKeyEs256 { set }))
61 }
62}
63
64impl ValueSetT for ValueSetJwsKeyEs256 {
65 fn insert_checked(&mut self, value: Value) -> Result<bool, OperationError> {
66 match value {
67 Value::JwsKeyEs256(k) => Ok(self.set.insert(k)),
68 _ => {
69 debug_assert!(false);
70 Err(OperationError::InvalidValueState)
71 }
72 }
73 }
74
75 fn clear(&mut self) {
76 self.set.clear();
77 }
78
79 fn remove(&mut self, pv: &PartialValue, _cid: &Cid) -> bool {
80 match pv {
81 PartialValue::Iutf8(kid) => {
82 let x = self.set.len();
83 self.set.retain(|k| k.get_kid() != kid);
84 x != self.set.len()
85 }
86 _ => false,
87 }
88 }
89
90 fn contains(&self, pv: &PartialValue) -> bool {
91 match pv {
92 PartialValue::Iutf8(kid) => self.set.iter().any(|k| k.get_kid() == kid),
93 _ => false,
94 }
95 }
96
97 fn substring(&self, _pv: &PartialValue) -> bool {
98 false
99 }
100
101 fn startswith(&self, _pv: &PartialValue) -> bool {
102 false
103 }
104
105 fn endswith(&self, _pv: &PartialValue) -> bool {
106 false
107 }
108
109 fn lessthan(&self, _pv: &PartialValue) -> bool {
110 false
111 }
112
113 fn len(&self) -> usize {
114 self.set.len()
115 }
116
117 fn generate_idx_eq_keys(&self) -> Vec<String> {
118 self.set.iter().map(|k| k.get_kid().to_string()).collect()
119 }
120
121 fn syntax(&self) -> SyntaxType {
122 SyntaxType::JwsKeyEs256
123 }
124
125 fn validate(&self, _schema_attr: &SchemaAttribute) -> bool {
126 true
127 }
128
129 fn to_proto_string_clone_iter(&self) -> Box<dyn Iterator<Item = String> + '_> {
130 Box::new(self.set.iter().map(|k| k.get_kid().to_string()))
131 }
132
133 fn to_scim_value(&self) -> Option<ScimResolveStatus> {
134 None
135 }
136
137 fn to_db_valueset_v2(&self) -> DbValueSetV2 {
138 DbValueSetV2::JwsKeyEs256(self.set.iter()
139 .map(|k| {
140 #[allow(clippy::expect_used)]
141 k.private_key_to_der()
142 .expect("Unable to process private key to der, likely corrupted. You must restore from backup.")
143 })
144 .collect())
145 }
146
147 fn to_partialvalue_iter(&self) -> Box<dyn Iterator<Item = PartialValue> + '_> {
148 Box::new(
149 self.set
150 .iter()
151 .map(|k| PartialValue::new_iutf8(k.get_kid())),
152 )
153 }
154
155 fn to_value_iter(&self) -> Box<dyn Iterator<Item = Value> + '_> {
156 Box::new(self.set.iter().cloned().map(Value::JwsKeyEs256))
157 }
158
159 fn equal(&self, other: &ValueSet) -> bool {
160 if let Some(other) = other.as_jws_key_es256_set() {
161 &self.set == other
162 } else {
163 debug_assert!(false);
164 false
165 }
166 }
167
168 fn merge(&mut self, other: &ValueSet) -> Result<(), OperationError> {
169 if let Some(b) = other.as_jws_key_es256_set() {
170 mergesets!(self.set, b)
171 } else {
172 debug_assert!(false);
173 Err(OperationError::InvalidValueState)
174 }
175 }
176
177 fn to_jws_key_es256_single(&self) -> Option<&JwsEs256Signer> {
178 if self.set.len() == 1 {
179 self.set.iter().take(1).next()
180 } else {
181 None
182 }
183 }
184
185 fn as_jws_key_es256_set(&self) -> Option<&HashSet<JwsEs256Signer>> {
186 Some(&self.set)
187 }
188}
189
190#[derive(Debug, Clone)]
191pub struct ValueSetJwsKeyRs256 {
192 set: HashSet<JwsRs256Signer>,
193}
194
195impl ValueSetJwsKeyRs256 {
196 pub fn new(k: JwsRs256Signer) -> Box<Self> {
197 let mut set = HashSet::new();
198 set.insert(k);
199 Box::new(ValueSetJwsKeyRs256 { set })
200 }
201
202 pub fn push(&mut self, k: JwsRs256Signer) -> bool {
203 self.set.insert(k)
204 }
205
206 pub fn from_dbvs2(data: &[Vec<u8>]) -> Result<ValueSet, OperationError> {
207 let set = data
208 .iter()
209 .map(|b| {
210 JwsRs256Signer::from_rs256_der(b).map_err(|e| {
211 debug!(?e, "Error occurred parsing RS256 DER");
212 OperationError::InvalidValueState
213 })
214 })
215 .collect::<Result<HashSet<_>, _>>()?;
216 Ok(Box::new(ValueSetJwsKeyRs256 { set }))
217 }
218
219 #[allow(clippy::should_implement_trait)]
222 pub fn from_iter<T>(iter: T) -> Option<Box<ValueSetJwsKeyRs256>>
223 where
224 T: IntoIterator<Item = JwsRs256Signer>,
225 {
226 let set: HashSet<JwsRs256Signer> = iter.into_iter().collect();
227 Some(Box::new(ValueSetJwsKeyRs256 { set }))
228 }
229}
230
231impl ValueSetT for ValueSetJwsKeyRs256 {
232 fn insert_checked(&mut self, value: Value) -> Result<bool, OperationError> {
233 match value {
234 Value::JwsKeyRs256(k) => Ok(self.set.insert(k)),
235 _ => {
236 debug_assert!(false);
237 Err(OperationError::InvalidValueState)
238 }
239 }
240 }
241
242 fn clear(&mut self) {
243 self.set.clear();
244 }
245
246 fn remove(&mut self, pv: &PartialValue, _cid: &Cid) -> bool {
247 match pv {
248 PartialValue::Iutf8(kid) => {
249 let x = self.set.len();
250 self.set.retain(|k| k.get_kid() != kid);
251 x != self.set.len()
252 }
253 _ => false,
254 }
255 }
256
257 fn contains(&self, _pv: &PartialValue) -> bool {
258 false
259 }
260
261 fn substring(&self, _pv: &PartialValue) -> bool {
262 false
263 }
264
265 fn startswith(&self, _pv: &PartialValue) -> bool {
266 false
267 }
268
269 fn endswith(&self, _pv: &PartialValue) -> bool {
270 false
271 }
272
273 fn lessthan(&self, _pv: &PartialValue) -> bool {
274 false
275 }
276
277 fn len(&self) -> usize {
278 self.set.len()
279 }
280
281 fn generate_idx_eq_keys(&self) -> Vec<String> {
282 self.set.iter().map(|k| k.get_kid().to_string()).collect()
283 }
284
285 fn syntax(&self) -> SyntaxType {
286 SyntaxType::JwsKeyRs256
287 }
288
289 fn validate(&self, _schema_attr: &SchemaAttribute) -> bool {
290 true
291 }
292
293 fn to_proto_string_clone_iter(&self) -> Box<dyn Iterator<Item = String> + '_> {
294 Box::new(self.set.iter().map(|k| k.get_kid().to_string()))
295 }
296
297 fn to_scim_value(&self) -> Option<ScimResolveStatus> {
298 None
299 }
300
301 fn to_db_valueset_v2(&self) -> DbValueSetV2 {
302 DbValueSetV2::JwsKeyRs256(self.set.iter()
303 .map(|k| {
304 #[allow(clippy::expect_used)]
305 k.private_key_to_der()
306 .expect("Unable to process private key to der, likely corrupted. You must restore from backup.")
307 })
308 .collect())
309 }
310
311 fn to_partialvalue_iter(&self) -> Box<dyn Iterator<Item = PartialValue> + '_> {
312 Box::new(
313 self.set
314 .iter()
315 .map(|k| PartialValue::new_iutf8(k.get_kid())),
316 )
317 }
318
319 fn to_value_iter(&self) -> Box<dyn Iterator<Item = Value> + '_> {
320 Box::new(self.set.iter().cloned().map(Value::JwsKeyRs256))
321 }
322
323 fn equal(&self, other: &ValueSet) -> bool {
324 if let Some(other) = other.as_jws_key_rs256_set() {
325 &self.set == other
326 } else {
327 debug_assert!(false);
328 false
329 }
330 }
331
332 fn merge(&mut self, other: &ValueSet) -> Result<(), OperationError> {
333 if let Some(b) = other.as_jws_key_rs256_set() {
334 mergesets!(self.set, b)
335 } else {
336 debug_assert!(false);
337 Err(OperationError::InvalidValueState)
338 }
339 }
340
341 fn to_jws_key_rs256_single(&self) -> Option<&JwsRs256Signer> {
342 if self.set.len() == 1 {
343 self.set.iter().take(1).next()
344 } else {
345 None
346 }
347 }
348
349 fn as_jws_key_rs256_set(&self) -> Option<&HashSet<JwsRs256Signer>> {
350 Some(&self.set)
351 }
352}