Mercurial > hg > orthanc-gcp
annotate Plugin/GoogleUpdater.cpp @ 16:25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
author | Sebastien Jodogne <s.jodogne@gmail.com> |
---|---|
date | Wed, 26 Jun 2019 11:29:25 +0200 |
parents | 520cba9a0d42 |
children | 2514880d4f0b |
rev | line source |
---|---|
0 | 1 /** |
2 * Google Cloud Platform credentials for DICOMweb and Orthanc | |
3 * Copyright (C) 2019 Osimis S.A., Belgium | |
4 * | |
5 * This program is free software: you can redistribute it and/or | |
6 * modify it under the terms of the GNU General Public License as | |
7 * published by the Free Software Foundation, either version 3 of the | |
8 * License, or (at your option) any later version. | |
9 * | |
10 * In addition, as a special exception, the copyright holders of this | |
11 * program give permission to link the code of its release with the | |
12 * OpenSSL project's "OpenSSL" library (or with modified versions of it | |
13 * that use the same license as the "OpenSSL" library), and distribute | |
14 * the linked executables. You must obey the GNU General Public License | |
15 * in all respects for all of the code used other than "OpenSSL". If you | |
16 * modify file(s) with this exception, you may extend this exception to | |
17 * your version of the file(s), but you are not obligated to do so. If | |
18 * you do not wish to do so, delete this exception statement from your | |
19 * version. If you delete this exception statement from all source files | |
20 * in the program, then also delete it here. | |
21 * | |
22 * This program is distributed in the hope that it will be useful, but | |
23 * WITHOUT ANY WARRANTY; without even the implied warranty of | |
24 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
25 * General Public License for more details. | |
26 * | |
27 * You should have received a copy of the GNU General Public License | |
28 * along with this program. If not, see <http://www.gnu.org/licenses/>. | |
29 **/ | |
30 | |
31 | |
32 #include "GoogleUpdater.h" | |
33 | |
34 #include "GoogleConfiguration.h" | |
35 | |
36 #include <google/cloud/storage/internal/curl_handle_factory.h> | |
37 #include <google/cloud/storage/oauth2/google_credentials.h> | |
38 | |
39 | |
40 namespace | |
41 { | |
42 class CurlBuilder : public google::cloud::storage::internal::CurlRequestBuilder | |
43 { | |
44 private: | |
45 class HandleFactory : public google::cloud::storage::internal::DefaultCurlHandleFactory | |
46 { | |
47 public: | |
48 google::cloud::storage::internal::CurlPtr CreateHandle() override | |
49 { | |
50 google::cloud::storage::internal::CurlPtr handle | |
51 (google::cloud::storage::internal::DefaultCurlHandleFactory::CreateHandle()); | |
52 | |
53 const GoogleConfiguration& configuration = GoogleConfiguration::GetInstance(); | |
54 | |
55 long timeout = static_cast<long>(configuration.GetTimeoutSeconds()); | |
56 | |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
57 if (!configuration.GetCaInfo().empty() && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
58 curl_easy_setopt(handle.get(), CURLOPT_CAINFO, configuration.GetCaInfo().c_str()) != CURLE_OK) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
59 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
60 throw Orthanc::OrthancException(Orthanc::ErrorCode_InternalError, |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
61 "Cannot set the trusted Certificate Authorities"); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
62 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
63 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
64 bool ok; |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
65 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
66 if (configuration.IsHttpsVerifyPeers()) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
67 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
68 ok = (curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYHOST, 2) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
69 curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYPEER, 1) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
70 curl_easy_setopt(handle.get(), CURLOPT_TIMEOUT, timeout) == CURLE_OK); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
71 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
72 else |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
73 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
74 ok = (curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYHOST, 0) == CURLE_OK && |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
75 curl_easy_setopt(handle.get(), CURLOPT_SSL_VERIFYPEER, 0) == CURLE_OK); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
76 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
77 |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
78 if (!ok) |
0 | 79 { |
80 throw Orthanc::OrthancException(Orthanc::ErrorCode_InternalError, | |
81 "Cannot initialize a libcurl handle"); | |
82 } | |
83 | |
84 return handle; | |
85 } | |
86 | |
87 google::cloud::storage::internal::CurlMulti CreateMultiHandle() override | |
88 { | |
89 throw Orthanc::OrthancException(Orthanc::ErrorCode_NotImplemented); | |
90 } | |
91 }; | |
92 | |
93 public: | |
94 CurlBuilder(std::string base_url, | |
95 std::shared_ptr<google::cloud::storage::internal::CurlHandleFactory> factory) : | |
96 CurlRequestBuilder(base_url, std::make_shared<HandleFactory>()) | |
97 { | |
98 } | |
99 }; | |
100 } | |
101 | |
102 | |
103 | |
104 static boost::posix_time::ptime GetNow() | |
105 { | |
106 return boost::posix_time::second_clock::local_time(); | |
107 } | |
108 | |
109 | |
110 void GoogleUpdater::Worker(const State* state, | |
111 const GoogleAccount* account, | |
112 long refreshIntervalSeconds) | |
113 { | |
114 std::shared_ptr<google::cloud::storage::oauth2::Credentials> credentials; | |
115 | |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
116 try |
0 | 117 { |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
118 switch (account->GetType()) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
119 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
120 case GoogleAccount::Type_ServiceAccount: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
121 credentials = std::make_shared<google::cloud::storage::oauth2::ServiceAccountCredentials |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
122 <CurlBuilder>>(account->GetServiceAccount()); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
123 break; |
0 | 124 |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
125 case GoogleAccount::Type_AuthorizedUser: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
126 credentials = std::make_shared<google::cloud::storage::oauth2::AuthorizedUserCredentials |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
127 <CurlBuilder>>(account->GetAuthorizedUser()); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
128 break; |
0 | 129 |
16
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
130 default: |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
131 throw Orthanc::OrthancException(Orthanc::ErrorCode_NotImplemented); |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
132 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
133 } |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
134 catch (Orthanc::OrthancException& e) |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
135 { |
25292488ff8f
using option HttpsVerifyPeers from Orthanc configuration
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
0
diff
changeset
|
136 credentials.reset(); |
0 | 137 } |
138 | |
139 if (credentials.get() == NULL) | |
140 { | |
141 LOG(ERROR) << "Cannot initialize the token updater for Google Cloud Platform account: " | |
142 << account->GetName(); | |
143 return; | |
144 } | |
145 | |
146 const std::string dicomWebPluginRoot = GoogleConfiguration::GetInstance().GetDicomWebPluginRoot(); | |
147 const std::string baseGoogleUrl = GoogleConfiguration::GetInstance().GetBaseGoogleUrl(); | |
148 | |
149 std::string lastToken; | |
150 std::unique_ptr<boost::posix_time::ptime> lastUpdate; | |
151 | |
152 while (*state == State_Running) | |
153 { | |
154 if (lastUpdate.get() == NULL || | |
155 (GetNow() - *lastUpdate).total_seconds() >= refreshIntervalSeconds) | |
156 { | |
157 google::cloud::StatusOr<std::string> token = credentials->AuthorizationHeader(); | |
158 if (!token) | |
159 { | |
160 LOG(WARNING) << "Cannot generate Google Cloud Platform token for account: " << account->GetName(); | |
161 } | |
162 else if (*token != lastToken && | |
163 account->UpdateServerDefinition(dicomWebPluginRoot, baseGoogleUrl, *token)) | |
164 { | |
165 lastToken = *token; | |
166 } | |
167 | |
168 lastUpdate.reset(new boost::posix_time::ptime(GetNow())); | |
169 } | |
170 | |
171 boost::this_thread::sleep(boost::posix_time::milliseconds(100)); | |
172 } | |
173 } | |
174 | |
175 | |
176 GoogleUpdater::~GoogleUpdater() | |
177 { | |
178 if (state_ == State_Running) | |
179 { | |
180 LOG(ERROR) << "GoogleUpdater::Stop() should have been manually called"; | |
181 Stop(); | |
182 } | |
183 } | |
184 | |
185 | |
186 void GoogleUpdater::Start() | |
187 { | |
188 if (state_ != State_Setup) | |
189 { | |
190 throw Orthanc::OrthancException(Orthanc::ErrorCode_BadSequenceOfCalls); | |
191 } | |
192 | |
193 state_ = State_Running; | |
194 | |
195 const GoogleConfiguration& configuration = GoogleConfiguration::GetInstance(); | |
196 | |
197 workers_.resize(configuration.GetAccountsCount()); | |
198 | |
199 for (size_t i = 0; i < workers_.size(); i++) | |
200 { | |
201 workers_[i] = new boost::thread(Worker, &state_, &configuration.GetAccount(i), | |
202 configuration.GetRefreshIntervalSeconds()); | |
203 } | |
204 } | |
205 | |
206 | |
207 void GoogleUpdater::Stop() | |
208 { | |
209 if (state_ == State_Running) | |
210 { | |
211 state_ = State_Done; | |
212 | |
213 for (size_t i = 0; i < workers_.size(); i++) | |
214 { | |
215 if (workers_[i] != NULL) | |
216 { | |
217 if (workers_[i]->joinable()) | |
218 { | |
219 workers_[i]->join(); | |
220 } | |
221 | |
222 delete workers_[i]; | |
223 } | |
224 } | |
225 | |
226 workers_.clear(); | |
227 } | |
228 } |