Adapt to new sql model
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -95,8 +95,7 @@ func (w *CacheStore) WarmCache(ctx context.Context) error {
|
|||||||
|
|
||||||
func (w *CacheStore) warmDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
func (w *CacheStore) warmDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
||||||
var loadedDomain coredata.CustomDomain
|
var loadedDomain coredata.CustomDomain
|
||||||
scope := coredata.NewScope(domain.OrganizationID.TenantID())
|
if err := loadedDomain.LoadByID(ctx, conn, coredata.NewNoScope(), w.encryptionKey, domain.ID); err != nil {
|
||||||
if err := loadedDomain.LoadByID(ctx, conn, scope, w.encryptionKey, domain.ID); err != nil {
|
|
||||||
return fmt.Errorf("cannot load domain with decrypted values: %w", err)
|
return fmt.Errorf("cannot load domain with decrypted values: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -130,10 +130,8 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
// Update domain with challenge details and set to PROVISIONING
|
|
||||||
scope := coredata.NewScope(domain.OrganizationID.TenantID())
|
|
||||||
fullDomain := &coredata.CustomDomain{}
|
fullDomain := &coredata.CustomDomain{}
|
||||||
if err := fullDomain.LoadByIDForUpdate(ctx, conn, scope, p.encryptionKey, domain.ID); err != nil {
|
if err := fullDomain.LoadByIDForUpdate(ctx, conn, coredata.NewNoScope(), p.encryptionKey, domain.ID); err != nil {
|
||||||
return fmt.Errorf("cannot load domain for update: %w", err)
|
return fmt.Errorf("cannot load domain for update: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -143,7 +141,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
fullDomain.HTTPOrderURL = &challenge.OrderURL
|
fullDomain.HTTPOrderURL = &challenge.OrderURL
|
||||||
fullDomain.SSLStatus = coredata.CustomDomainSSLStatusProvisioning
|
fullDomain.SSLStatus = coredata.CustomDomainSSLStatusProvisioning
|
||||||
|
|
||||||
if err := fullDomain.Update(ctx, conn, scope, p.encryptionKey); err != nil {
|
if err := fullDomain.Update(ctx, conn, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
||||||
return fmt.Errorf("failed to update domain with challenge: %w", err)
|
return fmt.Errorf("failed to update domain with challenge: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -157,7 +155,6 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// Domain already has challenge details, complete it
|
|
||||||
challenge := &HTTPChallenge{
|
challenge := &HTTPChallenge{
|
||||||
Domain: domain.Domain,
|
Domain: domain.Domain,
|
||||||
Token: *domain.HTTPChallengeToken,
|
Token: *domain.HTTPChallengeToken,
|
||||||
@@ -185,9 +182,8 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
log.Time("expires_at", cert.ExpiresAt),
|
log.Time("expires_at", cert.ExpiresAt),
|
||||||
)
|
)
|
||||||
|
|
||||||
scope := coredata.NewScope(domain.OrganizationID.TenantID())
|
|
||||||
fullDomain := &coredata.CustomDomain{}
|
fullDomain := &coredata.CustomDomain{}
|
||||||
if err := fullDomain.LoadByID(ctx, conn, scope, p.encryptionKey, domain.ID); err != nil {
|
if err := fullDomain.LoadByID(ctx, conn, coredata.NewNoScope(), p.encryptionKey, domain.ID); err != nil {
|
||||||
return fmt.Errorf("cannot load domain: %w", err)
|
return fmt.Errorf("cannot load domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -203,7 +199,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
fullDomain.HTTPChallengeURL = nil
|
fullDomain.HTTPChallengeURL = nil
|
||||||
fullDomain.HTTPOrderURL = nil
|
fullDomain.HTTPOrderURL = nil
|
||||||
|
|
||||||
if err := fullDomain.Update(ctx, conn, scope, p.encryptionKey); err != nil {
|
if err := fullDomain.Update(ctx, conn, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
||||||
return fmt.Errorf("cannot update domain: %w", err)
|
return fmt.Errorf("cannot update domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -128,10 +128,8 @@ func (r *Renewer) checkAndRenew(ctx context.Context) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (r *Renewer) renewDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
func (r *Renewer) renewDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
||||||
scope := coredata.NewScope(domain.OrganizationID.TenantID())
|
|
||||||
|
|
||||||
lockedDomain := &coredata.CustomDomain{}
|
lockedDomain := &coredata.CustomDomain{}
|
||||||
if err := lockedDomain.LoadByIDForUpdate(ctx, conn, scope, r.encryptionKey, domain.ID); err != nil {
|
if err := lockedDomain.LoadByIDForUpdate(ctx, conn, coredata.NewNoScope(), r.encryptionKey, domain.ID); err != nil {
|
||||||
return fmt.Errorf("cannot lock domain for renewal: %w", err)
|
return fmt.Errorf("cannot lock domain for renewal: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -166,7 +164,7 @@ func (r *Renewer) renewDomain(ctx context.Context, conn pg.Conn, domain *coredat
|
|||||||
lockedDomain.HTTPOrderURL = &challenge.OrderURL
|
lockedDomain.HTTPOrderURL = &challenge.OrderURL
|
||||||
lockedDomain.SSLStatus = coredata.CustomDomainSSLStatusRenewing
|
lockedDomain.SSLStatus = coredata.CustomDomainSSLStatusRenewing
|
||||||
|
|
||||||
if err := lockedDomain.Update(ctx, conn, scope, r.encryptionKey); err != nil {
|
if err := lockedDomain.Update(ctx, conn, coredata.NewNoScope(), r.encryptionKey); err != nil {
|
||||||
return fmt.Errorf("cannot update domain with renewal challenge: %w", err)
|
return fmt.Errorf("cannot update domain with renewal challenge: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -195,7 +193,7 @@ func (r *Renewer) renewDomain(ctx context.Context, conn pg.Conn, domain *coredat
|
|||||||
lockedDomain.HTTPChallengeURL = nil
|
lockedDomain.HTTPChallengeURL = nil
|
||||||
lockedDomain.HTTPOrderURL = nil
|
lockedDomain.HTTPOrderURL = nil
|
||||||
|
|
||||||
if err := lockedDomain.Update(ctx, conn, scope, r.encryptionKey); err != nil {
|
if err := lockedDomain.Update(ctx, conn, coredata.NewNoScope(), r.encryptionKey); err != nil {
|
||||||
return fmt.Errorf("cannot update domain with renewed certificate: %w", err)
|
return fmt.Errorf("cannot update domain with renewed certificate: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -28,9 +28,9 @@ import (
|
|||||||
|
|
||||||
type (
|
type (
|
||||||
Selector struct {
|
Selector struct {
|
||||||
pg *pg.Client
|
pg *pg.Client
|
||||||
cache sync.Map
|
cache sync.Map
|
||||||
encryptionKey cipher.EncryptionKey
|
encryptionKey cipher.EncryptionKey
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -44,7 +44,6 @@ func NewSelector(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
func (s *Selector) GetCertificate(hello *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
func (s *Selector) GetCertificate(hello *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
||||||
domain := hello.ServerName
|
domain := hello.ServerName
|
||||||
|
|
||||||
@@ -114,10 +113,6 @@ func (s *Selector) rebuildCacheEntry(ctx context.Context, conn pg.Conn, domain s
|
|||||||
return fmt.Errorf("cannot load domain: %w", err)
|
return fmt.Errorf("cannot load domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
if !customDomain.IsActive {
|
|
||||||
return fmt.Errorf("domain is not active")
|
|
||||||
}
|
|
||||||
|
|
||||||
if customDomain.SSLStatus != coredata.CustomDomainSSLStatusActive {
|
if customDomain.SSLStatus != coredata.CustomDomainSSLStatusActive {
|
||||||
return fmt.Errorf("domain does not have active SSL certificate")
|
return fmt.Errorf("domain does not have active SSL certificate")
|
||||||
}
|
}
|
||||||
@@ -153,7 +148,6 @@ func (s *Selector) rebuildCacheEntry(ctx context.Context, conn pg.Conn, domain s
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
func (s *Selector) ClearCache() {
|
func (s *Selector) ClearCache() {
|
||||||
s.cache.Range(
|
s.cache.Range(
|
||||||
func(key, _ any) bool {
|
func(key, _ any) bool {
|
||||||
|
|||||||
Reference in New Issue
Block a user