summary |
shortlog |
log |
commit | commitdiff |
review |
tree
raw |
patch |
inline | side by side (from parent 1:
1d24a50)
Change-Id: If8ef53f8a0a57bf6d19b0da3d13a7794a8d0eef9
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
ADD_DEFINITIONS(-DUSE_MAGIC_MIME_TYPE)
PKG_CHECK_MODULES(libsystemd REQUIRED libsystemd>=222)
ADD_DEFINITIONS(-DUSE_MAGIC_MIME_TYPE)
PKG_CHECK_MODULES(libsystemd REQUIRED libsystemd>=222)
-PKG_CHECK_MODULES(libmicrohttpd REQUIRED libmicrohttpd>=0.9.48)
+PKG_CHECK_MODULES(libmicrohttpd REQUIRED libmicrohttpd>=0.9.54)
PKG_CHECK_MODULES(openssl REQUIRED openssl)
PKG_CHECK_MODULES(uuid REQUIRED uuid)
PKG_CHECK_MODULES(openssl REQUIRED openssl)
PKG_CHECK_MODULES(uuid REQUIRED uuid)
+PKG_CHECK_MODULES(cynara cynara-client)
+
+IF(cynara_FOUND)
+ ADD_DEFINITIONS(-DBACKEND_PERMISSION_IS_CYNARA)
+ENDIF(cynara_FOUND)
INCLUDE_DIRECTORIES(
${include_dirs}
INCLUDE_DIRECTORIES(
${include_dirs}
${libmicrohttpd_INCLUDE_DIRS}
${uuid_INCLUDE_DIRS}
${openssl_INCLUDE_DIRS}
${libmicrohttpd_INCLUDE_DIRS}
${uuid_INCLUDE_DIRS}
${openssl_INCLUDE_DIRS}
)
ADD_LIBRARY(afb-lib STATIC
)
ADD_LIBRARY(afb-lib STATIC
${libmicrohttpd_LIBRARIES}
${uuid_LIBRARIES}
${openssl_LIBRARIES}
${libmicrohttpd_LIBRARIES}
${uuid_LIBRARIES}
${openssl_LIBRARIES}
#include "afb-auth.h"
#include "afb-context.h"
#include "afb-xreq.h"
#include "afb-auth.h"
#include "afb-context.h"
#include "afb-xreq.h"
#include "verbose.h"
static int check_permission(const char *permission, struct afb_xreq *xreq);
#include "verbose.h"
static int check_permission(const char *permission, struct afb_xreq *xreq);
+/*********************************************************************************/
#ifdef BACKEND_PERMISSION_IS_CYNARA
#ifdef BACKEND_PERMISSION_IS_CYNARA
#include <cynara-client.h>
#include <cynara-client.h>
+
+static cynara *handle;
+static pthread_mutex_t mutex = PTHREAD_MUTEX_INITIALIZER;
+
static int check_permission(const char *permission, struct afb_xreq *xreq)
{
static int check_permission(const char *permission, struct afb_xreq *xreq)
{
- static cynara *cynara;
- char uid[64];
- if (!cynara) {
- rc = cynara_initialize(&cynara, NULL);
+ /* cynara isn't reentrant */
+ pthread_mutex_lock(&mutex);
+
+ /* lazy initialisation */
+ if (!handle) {
+ rc = cynara_initialize(&handle, NULL);
if (rc != CYNARA_API_SUCCESS) {
if (rc != CYNARA_API_SUCCESS) {
ERROR("cynara initialisation failed with code %d", rc);
return 0;
}
}
ERROR("cynara initialisation failed with code %d", rc);
return 0;
}
}
- rc = cynara_check(cynara, cred->label, afb_context_uuid(&xreq->context), xreq->cred->user, permission);
+
+ /* query cynara permission */
+ rc = cynara_check(handle, xreq->cred->label, afb_context_uuid(&xreq->context), xreq->cred->user, permission);
+
+ pthread_mutex_unlock(&mutex);
return rc == CYNARA_API_ACCESS_ALLOWED;
}
return rc == CYNARA_API_ACCESS_ALLOWED;
}
+
+/*********************************************************************************/
#else
static int check_permission(const char *permission, struct afb_xreq *xreq)
{
#else
static int check_permission(const char *permission, struct afb_xreq *xreq)
{
- WARNING("Granting permission %s by default", permission);
+ WARNING("Granting permission %s by default of backend", permission);