-
-
Notifications
You must be signed in to change notification settings - Fork 48
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: create an httpc profile which disables keep-alive/pipelining
As noted in #318 (comment), `httpc` by default will re-use existing connections. This is great if you're using normal HTTPS, but if you're using client authentication then you need to make sure that every time `httpc` connects to a host, it's using the client authentication, which is impossible in practice. This works around that, by creating a new profile which disables that functionality. Using that profile for requests which provide SSL overrides will ensure that each of those requests will use the client certificate.
- Loading branch information
1 parent
6f7a895
commit d3da95b
Showing
14 changed files
with
260 additions
and
33 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
# Regenerating `jwk_cert.pem` | ||
|
||
``` bash | ||
openssl x509 -signkey jwk.pem -in jwk.csr -req -days 3650 -out jwk_cert.pem | ||
``` | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
-----BEGIN CERTIFICATE REQUEST----- | ||
MIICezCCAWMCAQAwNjEkMCIGA1UECgwbRXJsYW5nIEVjb3N5c3RlbSBGb3VuZGF0 | ||
aW9uMQ4wDAYDVQQDDAVPaWRjYzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC | ||
ggEBAKIBNjF96IT2TkwDlkXJ/uneGbYfg/5YqwOZtzscwSDKRGmevVQPiD+8kTG9 | ||
0j8ie7CryjjHJTxtxLq93H6gg74OWmVCffTf2pA0dMGizg3Ua0QPPXmwtHZfmKbJ | ||
cKelCSPTDngQQkkomn+2ROs4xXtDmxeyjKovk/ECOEOV005KTfv0Nh0ZqZlxgmHI | ||
Ot0XBFD4II1pESeiL3l8RE4RLDPq10V3jlWnfNORnNNAY0HgbryuggZGVifcxpnB | ||
DAcRL5BPGaw5lCZn5Yul4ts8JoLpqLcglHbWVoTJnSUxlSKEI/kteOvMiQqwoUPG | ||
KnuG1sktCEm3Wv+hUeq/1B3S7J8CAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQBY | ||
WZ6HCP6Yrws9/jOWWYS3JOEilIjqLfxgtEM7tOz8zID225DLV0m75UFkl7JIwwxY | ||
Tx4U2FhoDqfVLbarrw31kZ2tbMRELdt9zLZbTv4b9QsB1Q+fXLn5x8W5m6qXK7kh | ||
WIfMfbpUwmuIlcUMxwWuEN3a5XSuHbOqsaY7V9H0c4YSVdyE2C5M2VP0oUECCPjC | ||
p3D6c47qHRkWYY2ssutK2U9cW5IusEUrcjyVIoOcW14pUjkcd3e+lr9S/59onAY1 | ||
Pkb2wd8CsEvdsr+P58uXleWwuHBxwybwAySp5GRvkuEPuuI1YUoDuwkgOeY8Y+te | ||
6LBUBw2DW+Z0QBSleoqs | ||
-----END CERTIFICATE REQUEST----- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
-----BEGIN CERTIFICATE----- | ||
MIIDGzCCAgOgAwIBAgIUGnShYZbN8W/ZJ5no7hh/WRLKougwDQYJKoZIhvcNAQEL | ||
BQAwNjEkMCIGA1UECgwbRXJsYW5nIEVjb3N5c3RlbSBGb3VuZGF0aW9uMQ4wDAYD | ||
VQQDDAVPaWRjYzAeFw0yNDAxMDcxNjQwMTBaFw0zNDAxMDQxNjQwMTBaMDYxJDAi | ||
BgNVBAoMG0VybGFuZyBFY29zeXN0ZW0gRm91bmRhdGlvbjEOMAwGA1UEAwwFT2lk | ||
Y2MwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCiATYxfeiE9k5MA5ZF | ||
yf7p3hm2H4P+WKsDmbc7HMEgykRpnr1UD4g/vJExvdI/Inuwq8o4xyU8bcS6vdx+ | ||
oIO+DlplQn3039qQNHTBos4N1GtEDz15sLR2X5imyXCnpQkj0w54EEJJKJp/tkTr | ||
OMV7Q5sXsoyqL5PxAjhDldNOSk379DYdGamZcYJhyDrdFwRQ+CCNaREnoi95fERO | ||
ESwz6tdFd45Vp3zTkZzTQGNB4G68roIGRlYn3MaZwQwHES+QTxmsOZQmZ+WLpeLb | ||
PCaC6ai3IJR21laEyZ0lMZUihCP5LXjrzIkKsKFDxip7htbJLQhJt1r/oVHqv9Qd | ||
0uyfAgMBAAGjITAfMB0GA1UdDgQWBBQJXpMge7QiKlfQFkpIx9ailJL21TANBgkq | ||
hkiG9w0BAQsFAAOCAQEAfRspbVWaRIC0ZQv8Y3TrmqzxKcmyHi/ixVn3fW9Ygeq2 | ||
Uasq6r0XE52gnU+Lb/3X8J0n0ENE1ovPjczjxAtrXwdM1l59C1YR7trVZJfRzNGy | ||
2ItO7efI3fCLYPxk4OkTeSubvuxklvyVALSo5dgsZg/7PLy3Vgkzz7XPfJPtFKQ+ | ||
xAOmul26zaJPNz49KT+m/2z77WoJHEyhEleJDo1DUABUwplI6BNecUW6VU+1BiCo | ||
x0Oc3CF+DkU5cKBHulRm5XP+8KvAW8Az52ZNpUGe4YkFKLsyipgFiqiE182QYtVA | ||
vWrEMdmPNr9xbPb5GGg3lropINwy4T8w/WKEdjPttg== | ||
-----END CERTIFICATE----- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
-module(oidcc_app). | ||
|
||
-export([start/2]). | ||
-export([stop/1]). | ||
-export([init/1]). | ||
-export([handle_call/3]). | ||
-export([handle_cast/2]). | ||
-export([handle_info/2]). | ||
-export([terminate/2]). | ||
-export([httpc_profile/0]). | ||
|
||
-behaviour(application). | ||
-behaviour(gen_server). | ||
|
||
%% @private | ||
httpc_profile() -> | ||
oidcc. | ||
|
||
%% Application Callbacks | ||
|
||
%% @private | ||
start(_StartType, StartArgs) -> | ||
gen_server:start_link(oidcc_app, StartArgs, []). | ||
|
||
%% @private | ||
stop(_State) -> | ||
ok. | ||
|
||
%% GenServer Callbacks | ||
%% @private | ||
init(_Args) -> | ||
{ok, Pid} = inets:start(httpc, [{profile, httpc_profile()}]), | ||
% disable keep-alive | ||
httpc:set_options( | ||
[ | ||
{pipeline_timeout, 0}, | ||
{keep_alive_timeout, 0}, | ||
{max_sessions, 1} | ||
], | ||
Pid | ||
), | ||
|
||
{ok, Pid, hibernate}. | ||
|
||
handle_call(_Call, _From, State) -> | ||
{stop, unexpected_call, State}. | ||
|
||
handle_cast(_Call, State) -> | ||
{stop, unexpected_cast, State}. | ||
|
||
handle_info(_Call, State) -> | ||
{stop, unexpected_info, State}. | ||
|
||
terminate(_Reason, Pid) -> | ||
inets:stop(httpc, Pid), | ||
ok. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,106 @@ | ||
-module(oidcc_http_util_SUITE). | ||
|
||
-export([all/0]). | ||
-export([init_per_suite/1]). | ||
-export([end_per_suite/1]). | ||
-export([bad_ssl/1]). | ||
-export([client_cert/1]). | ||
|
||
-include_lib("common_test/include/ct.hrl"). | ||
-include_lib("stdlib/include/assert.hrl"). | ||
|
||
all() -> | ||
[ | ||
bad_ssl, | ||
client_cert | ||
]. | ||
|
||
init_per_suite(_Config) -> | ||
{ok, _} = application:ensure_all_started(oidcc), | ||
[]. | ||
|
||
end_per_suite(_Config) -> | ||
ok = application:stop(oidcc). | ||
|
||
telemetry_opts() -> | ||
#{ | ||
topic => [oidcc, oidcc_http_util_SUITE] | ||
}. | ||
|
||
bad_ssl(_Config) -> | ||
?assertMatch( | ||
{error, {failed_connect, _}}, | ||
oidcc_http_util:request(get, {"https://expired.badssl.com/", []}, telemetry_opts(), #{}) | ||
), | ||
|
||
?assertMatch( | ||
{error, {failed_connect, _}}, | ||
oidcc_http_util:request(get, {"https://wrong.host.badssl.com/", []}, telemetry_opts(), #{}) | ||
), | ||
|
||
?assertMatch( | ||
{error, {failed_connect, _}}, | ||
oidcc_http_util:request(get, {"https://self-signed.badssl.com/", []}, telemetry_opts(), #{}) | ||
), | ||
|
||
?assertMatch( | ||
{error, {failed_connect, _}}, | ||
oidcc_http_util:request( | ||
get, {"https://untrusted-root.badssl.com/", []}, telemetry_opts(), #{} | ||
) | ||
), | ||
|
||
?assertMatch( | ||
{error, {failed_connect, _}}, | ||
oidcc_http_util:request( | ||
get, {"https://tls-v1-1.badssl.com:1011/", []}, telemetry_opts(), #{} | ||
) | ||
), | ||
|
||
ok. | ||
|
||
client_cert(_Config) -> | ||
PrivDir = code:priv_dir(oidcc), | ||
KeyFile = | ||
PrivDir ++ | ||
"/test/fixtures/jwk.pem", | ||
CertFile = | ||
PrivDir ++ | ||
"/test/fixtures/jwk_cert.pem", | ||
CertsKeys = [ | ||
#{ | ||
certfile => CertFile, | ||
keyfile => KeyFile | ||
} | ||
], | ||
?assertMatch( | ||
{ok, { | ||
{json, #{ | ||
<<"SSL_CLIENT_I_DN">> := <<"CN=Oidcc,O=Erlang Ecosystem Foundation">> | ||
}}, | ||
_ | ||
}}, | ||
oidcc_http_util:request( | ||
get, {"https://certauth.idrix.fr/json/", []}, telemetry_opts(), #{ | ||
ssl => [ | ||
{verify, verify_peer}, | ||
{cacerts, public_key:cacerts_get()}, | ||
{certs_keys, CertsKeys} | ||
] | ||
} | ||
) | ||
), | ||
|
||
?assertMatch( | ||
{error, {http_error, 403, <<"">>}}, | ||
oidcc_http_util:request( | ||
get, {"https://certauth.idrix.fr/json/", []}, telemetry_opts(), #{ | ||
ssl => [ | ||
{verify, verify_peer}, | ||
{cacerts, public_key:cacerts_get()} | ||
] | ||
} | ||
) | ||
), | ||
|
||
ok. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.