Mercurial > hg > orthanc-gcp
annotate Plugin/GoogleUpdater.cpp @ 41:1a96ab7b6877
trying to upgrade openssl to 1.1.1 in static builds
author | Sebastien Jodogne <s.jodogne@gmail.com> |
---|---|
date | Thu, 17 Dec 2020 10:02:04 +0100 |
parents | 16cf7c2eb806 |
children | 21499c134785 |
rev | line source |
---|---|
0 | 1 /** |
2 * Google Cloud Platform credentials for DICOMweb and Orthanc | |
26
d9e1b60a9aa6
upgrade to year 2020
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
17
diff
changeset
|
3 * Copyright (C) 2019-2020 Osimis S.A., Belgium |
0 | 4 * |
5 * This program is free software: you can redistribute it and/or | |
6 * modify it under the terms of the GNU General Public License as | |
7 * published by the Free Software Foundation, either version 3 of the | |
8 * License, or (at your option) any later version. | |
9 * | |
10 * In addition, as a special exception, the copyright holders of this | |
11 * program give permission to link the code of its release with the | |
12 * OpenSSL project's "OpenSSL" library (or with modified versions of it | |
13 * that use the same license as the "OpenSSL" library), and distribute | |
14 * the linked executables. You must obey the GNU General Public License | |
15 * in all respects for all of the code used other than "OpenSSL". If you | |
16 * modify file(s) with this exception, you may extend this exception to | |
17 * your version of the file(s), but you are not obligated to do so. If | |
18 * you do not wish to do so, delete this exception statement from your | |
19 * version. If you delete this exception statement from all source files | |
20 * in the program, then also delete it here. | |
21 * | |
22 * This program is distributed in the hope that it will be useful, but | |
23 * WITHOUT ANY WARRANTY; without even the implied warranty of | |
24 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
25 * General Public License for more details. | |
26 * | |
27 * You should have received a copy of the GNU General Public License | |
28 * along with this program. If not, see <http://www.gnu.org/licenses/>. | |
29 **/ | |
30 | |
31 | |
32 #include "GoogleUpdater.h" | |
33 | |
34 #include "GoogleConfiguration.h" | |
35 | |
40 | 36 #include <Logging.h> |
37 | |
0 | 38 #include <google/cloud/storage/internal/curl_handle_factory.h> |
39 #include <google/cloud/storage/oauth2/google_credentials.h> | |
40 | |
41 | |
42 namespace | |
43 { | |
44 class CurlBuilder : public google::cloud::storage::internal::CurlRequestBuilder | |
45 { | |
46 private: | |
47 class HandleFactory : public google::cloud::storage::internal::DefaultCurlHandleFactory | |
48 { | |
49 public: | |
50 google::cloud::storage::internal::CurlPtr CreateHandle() override | |
51 { | |
52 google::cloud::storage::internal::CurlPtr handle | |
53 (google::cloud::storage::internal::DefaultCurlHandleFactory::CreateHandle()); | |
54 | |
55 const GoogleConfiguration& configuration = GoogleConfiguration::GetInstance(); | |
56 | |
57 long timeout = static_cast<long>(configuration.GetTimeoutSeconds()); | |
58 | |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
59 if (!configuration.GetCaInfo().empty() && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
60 curl_easy_setopt(handle.get(), CURLOPT_CAINFO, configuration.GetCaInfo().c_str()) != CURLE_OK) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
61 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
62 throw Orthanc::OrthancException(Orthanc::ErrorCode_InternalError, |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
63 "Cannot set the trusted Certificate Authorities"); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
64 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
65 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
66 bool ok; |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
67 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
68 if (configuration.IsHttpsVerifyPeers()) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
69 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
70 ok = (curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYHOST, 2) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
71 curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYPEER, 1) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
72 curl_easy_setopt(handle.get(), CURLOPT_TIMEOUT, timeout) == CURLE_OK); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
73 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
74 else |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
75 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
76 ok = (curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYHOST, 0) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
77 curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYPEER, 0) == CURLE_OK); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
78 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
79 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
80 if (!ok) |
0 | 81 { |
82 throw Orthanc::OrthancException(Orthanc::ErrorCode_InternalError, | |
83 "Cannot initialize a libcurl handle"); | |
84 } | |
85 | |
86 return handle; | |
87 } | |
88 | |
89 google::cloud::storage::internal::CurlMulti CreateMultiHandle() override | |
90 { | |
91 throw Orthanc::OrthancException(Orthanc::ErrorCode_NotImplemented); | |
92 } | |
93 }; | |
94 | |
95 public: | |
17 | 96 CurlBuilder(const std::string& base_url, |
97 const std::shared_ptr<google::cloud::storage::internal::CurlHandleFactory>& factory) : | |
0 | 98 CurlRequestBuilder(base_url, std::make_shared<HandleFactory>()) |
99 { | |
100 } | |
101 }; | |
102 } | |
103 | |
104 | |
105 | |
106 static boost::posix_time::ptime GetNow() | |
107 { | |
108 return boost::posix_time::second_clock::local_time(); | |
109 } | |
110 | |
111 | |
112 void GoogleUpdater::Worker(const State* state, | |
113 const GoogleAccount* account, | |
114 long refreshIntervalSeconds) | |
115 { | |
116 std::shared_ptr<google::cloud::storage::oauth2::Credentials> credentials; | |
117 | |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
118 try |
0 | 119 { |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
120 switch (account->GetType()) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
121 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
122 case GoogleAccount::Type_ServiceAccount: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
123 credentials = std::make_shared<google::cloud::storage::oauth2::ServiceAccountCredentials |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
124 <CurlBuilder>>(account->GetServiceAccount()); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
125 break; |
0 | 126 |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
127 case GoogleAccount::Type_AuthorizedUser: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
128 credentials = std::make_shared<google::cloud::storage::oauth2::AuthorizedUserCredentials |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
129 <CurlBuilder>>(account->GetAuthorizedUser()); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
130 break; |
0 | 131 |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
132 default: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
133 throw Orthanc::OrthancException(Orthanc::ErrorCode_NotImplemented); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
134 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
135 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
136 catch (Orthanc::OrthancException& e) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
137 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
138 credentials.reset(); |
0 | 139 } |
140 | |
141 if (credentials.get() == NULL) | |
142 { | |
143 LOG(ERROR) << "Cannot initialize the token updater for Google Cloud Platform account: " | |
144 << account->GetName(); | |
145 return; | |
146 } | |
147 | |
148 const std::string dicomWebPluginRoot = GoogleConfiguration::GetInstance().GetDicomWebPluginRoot(); | |
149 const std::string baseGoogleUrl = GoogleConfiguration::GetInstance().GetBaseGoogleUrl(); | |
150 | |
151 std::string lastToken; | |
152 std::unique_ptr<boost::posix_time::ptime> lastUpdate; | |
153 | |
154 while (*state == State_Running) | |
155 { | |
156 if (lastUpdate.get() == NULL || | |
157 (GetNow() - *lastUpdate).total_seconds() >= refreshIntervalSeconds) | |
158 { | |
159 google::cloud::StatusOr<std::string> token = credentials->AuthorizationHeader(); | |
160 if (!token) | |
161 { | |
162 LOG(WARNING) << "Cannot generate Google Cloud Platform token for account: " << account->GetName(); | |
163 } | |
164 else if (*token != lastToken && | |
165 account->UpdateServerDefinition(dicomWebPluginRoot, baseGoogleUrl, *token)) | |
166 { | |
167 lastToken = *token; | |
168 } | |
169 | |
170 lastUpdate.reset(new boost::posix_time::ptime(GetNow())); | |
171 } | |
172 | |
173 boost::this_thread::sleep(boost::posix_time::milliseconds(100)); | |
174 } | |
175 } | |
176 | |
177 | |
178 GoogleUpdater::~GoogleUpdater() | |
179 { | |
180 if (state_ == State_Running) | |
181 { | |
182 LOG(ERROR) << "GoogleUpdater::Stop() should have been manually called"; | |
183 Stop(); | |
184 } | |
185 } | |
186 | |
187 | |
188 void GoogleUpdater::Start() | |
189 { | |
190 if (state_ != State_Setup) | |
191 { | |
192 throw Orthanc::OrthancException(Orthanc::ErrorCode_BadSequenceOfCalls); | |
193 } | |
194 | |
195 state_ = State_Running; | |
196 | |
197 const GoogleConfiguration& configuration = GoogleConfiguration::GetInstance(); | |
198 | |
199 workers_.resize(configuration.GetAccountsCount()); | |
200 | |
201 for (size_t i = 0; i < workers_.size(); i++) | |
202 { | |
203 workers_[i] = new boost::thread(Worker, &state_, &configuration.GetAccount(i), | |
204 configuration.GetRefreshIntervalSeconds()); | |
205 } | |
206 } | |
207 | |
208 | |
209 void GoogleUpdater::Stop() | |
210 { | |
211 if (state_ == State_Running) | |
212 { | |
213 state_ = State_Done; | |
214 | |
215 for (size_t i = 0; i < workers_.size(); i++) | |
216 { | |
217 if (workers_[i] != NULL) | |
218 { | |
219 if (workers_[i]->joinable()) | |
220 { | |
221 workers_[i]->join(); | |
222 } | |
223 | |
224 delete workers_[i]; | |
225 } | |
226 } | |
227 | |
228 workers_.clear(); | |
229 } | |
230 } |