You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

SignedPushConfig.java 4.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155
  1. /*
  2. * Copyright (C) 2015, Google Inc.
  3. * and other copyright owners as documented in the project's IP log.
  4. *
  5. * This program and the accompanying materials are made available
  6. * under the terms of the Eclipse Distribution License v1.0 which
  7. * accompanies this distribution, is reproduced below, and is
  8. * available at http://www.eclipse.org/org/documents/edl-v10.php
  9. *
  10. * All rights reserved.
  11. *
  12. * Redistribution and use in source and binary forms, with or
  13. * without modification, are permitted provided that the following
  14. * conditions are met:
  15. *
  16. * - Redistributions of source code must retain the above copyright
  17. * notice, this list of conditions and the following disclaimer.
  18. *
  19. * - Redistributions in binary form must reproduce the above
  20. * copyright notice, this list of conditions and the following
  21. * disclaimer in the documentation and/or other materials provided
  22. * with the distribution.
  23. *
  24. * - Neither the name of the Eclipse Foundation, Inc. nor the
  25. * names of its contributors may be used to endorse or promote
  26. * products derived from this software without specific prior
  27. * written permission.
  28. *
  29. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
  30. * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
  31. * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  32. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  33. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  34. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  35. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  36. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  37. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  38. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  39. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  40. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
  41. * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  42. */
  43. package org.eclipse.jgit.transport;
  44. import org.eclipse.jgit.lib.Config;
  45. import org.eclipse.jgit.lib.Config.SectionParser;
  46. /**
  47. * Configuration for server-side signed push verification.
  48. *
  49. * @since 4.1
  50. */
  51. public class SignedPushConfig {
  52. /** Key for {@link Config#get(SectionParser)}. */
  53. public static final SectionParser<SignedPushConfig> KEY =
  54. SignedPushConfig::new;
  55. private String certNonceSeed;
  56. private int certNonceSlopLimit;
  57. private NonceGenerator nonceGenerator;
  58. /**
  59. * Create a new config with default values disabling push verification.
  60. */
  61. public SignedPushConfig() {
  62. }
  63. SignedPushConfig(Config cfg) {
  64. setCertNonceSeed(cfg.getString("receive", null, "certnonceseed")); //$NON-NLS-1$ //$NON-NLS-2$
  65. certNonceSlopLimit = cfg.getInt("receive", "certnonceslop", 0); //$NON-NLS-1$ //$NON-NLS-2$
  66. }
  67. /**
  68. * Set the seed used by the nonce verifier.
  69. * <p>
  70. * Setting this to a non-null value enables push certificate verification
  71. * using the default
  72. * {@link org.eclipse.jgit.transport.HMACSHA1NonceGenerator} implementation,
  73. * if a different implementation was not set using
  74. * {@link #setNonceGenerator(NonceGenerator)}.
  75. *
  76. * @param seed
  77. * new seed value.
  78. */
  79. public void setCertNonceSeed(String seed) {
  80. certNonceSeed = seed;
  81. }
  82. /**
  83. * Get the configured seed.
  84. *
  85. * @return the configured seed.
  86. */
  87. public String getCertNonceSeed() {
  88. return certNonceSeed;
  89. }
  90. /**
  91. * Set the nonce slop limit.
  92. * <p>
  93. * Old but valid nonces within this limit will be accepted.
  94. *
  95. * @param limit
  96. * new limit in seconds.
  97. */
  98. public void setCertNonceSlopLimit(int limit) {
  99. certNonceSlopLimit = limit;
  100. }
  101. /**
  102. * Get the configured nonce slop limit.
  103. *
  104. * @return the configured nonce slop limit.
  105. */
  106. public int getCertNonceSlopLimit() {
  107. return certNonceSlopLimit;
  108. }
  109. /**
  110. * Set the {@link org.eclipse.jgit.transport.NonceGenerator} used for signed
  111. * pushes.
  112. * <p>
  113. * Setting this to a non-null value enables push certificate verification.
  114. * If this method is called, this implementation will be used instead of the
  115. * default {@link org.eclipse.jgit.transport.HMACSHA1NonceGenerator} even if
  116. * {@link #setCertNonceSeed(String)} was called.
  117. *
  118. * @param generator
  119. * new nonce generator.
  120. */
  121. public void setNonceGenerator(NonceGenerator generator) {
  122. nonceGenerator = generator;
  123. }
  124. /**
  125. * Get the {@link org.eclipse.jgit.transport.NonceGenerator} used for signed
  126. * pushes.
  127. * <p>
  128. * If {@link #setNonceGenerator(NonceGenerator)} was used to set a non-null
  129. * implementation, that will be returned. If no custom implementation was
  130. * set but {@link #setCertNonceSeed(String)} was called, returns a
  131. * newly-created {@link org.eclipse.jgit.transport.HMACSHA1NonceGenerator}.
  132. *
  133. * @return the configured nonce generator.
  134. */
  135. public NonceGenerator getNonceGenerator() {
  136. if (nonceGenerator != null) {
  137. return nonceGenerator;
  138. } else if (certNonceSeed != null) {
  139. return new HMACSHA1NonceGenerator(certNonceSeed);
  140. }
  141. return null;
  142. }
  143. }