Add more aggressive key caching
parent: tbd commit: 5bc92ad
1 | use ; |
2 | |
3 | use Error; |
4 | use Future; |
5 | use |
6 | , |
7 | , | Instance
8 | , | User
9 | ; |
10 | use ; |
11 | use |
12 | , |
13 | , |
14 | , | Sha256
15 | , | Verifier
16 | RsaPublicKey, |
17 | ; |
18 | use ; |
19 | use Value; |
20 | |
21 | use crate ConnectionState; |
22 | |
23 | ; |
24 | |
25 | |
26 | type Target = ; |
27 | |
28 | |
29 | &self.0 |
30 | |
31 | |
32 | |
33 | ; |
34 | |
35 | |
36 | |
37 | |
38 | Missing, |
39 | // #[error("{0}")] |
40 | // InstanceAuthentication(#[from] Error), |
41 | |
42 | InvalidToken, |
43 | |
44 | Other, |
45 | |
46 | |
47 | ; |
48 | |
49 | |
50 | |
51 | &self.0 |
52 | |
53 | |
54 | |
55 | |
56 | |
57 | async ; |
58 | |
59 | |
60 | |
61 | |
62 | async |
63 | network_message: &NetworkMessage, |
64 | state: &ConnectionState, |
65 | |
66 | let message: AuthenticatedPayload = |
67 | map_err?; | from_slice .
68 | |
69 | let = message |
70 | .source |
71 | .iter |
72 | .filter_map |
73 | if let User = auth |
74 | Some |
75 | else |
76 | None |
77 | |
78 | |
79 | .next |
80 | .ok_or_else?; |
81 | |
82 | let authenticated_instance = |
83 | ?; | from_message .await
84 | |
85 | let public_key_raw = state.public_key .await?; |
86 | let verification_key = from_rsa_pem .unwrap; |
87 | |
88 | let data: = decode |
89 | auth_token.as_ref, |
90 | &verification_key, |
91 | & new, |
92 | |
93 | .unwrap; |
94 | |
95 | if data.claims.user != *auth_user |
96 | || data.claims.generated_for != *authenticated_instance.inner |
97 | |
98 | Err |
99 | else |
100 | Ok |
101 | |
102 | |
103 | |
104 | |
105 | |
106 | |
107 | async |
108 | network_message: &NetworkMessage, |
109 | state: &ConnectionState, |
110 | |
111 | let message: AuthenticatedPayload = |
112 | map_err?; | from_slice .
113 | |
114 | let = message |
115 | .source |
116 | .iter |
117 | .filter_map |
118 | if let Instance |
119 | instance, |
120 | signature, |
121 | = auth |
122 | |
123 | Some |
124 | else |
125 | None |
126 | |
127 | |
128 | .next |
129 | // TODO: Instance authentication error |
130 | .ok_or_else?; |
131 | |
132 | let public_key = from_pkcs1_pem .unwrap; |
133 | |
134 | let verifying_key: = new; |
135 | |
136 | verifying_key.verify |
137 | &message.payload, |
138 | & try_from .unwrap, |
139 | ?; |
140 | |
141 | Ok |
142 | |
143 | |
144 | |
145 | |
146 | |
147 | |
148 | T: , |
149 | S: Send + Sync + 'static, |
150 | |
151 | async |
152 | Ok |
153 | |
154 | |
155 | |
156 | |
157 | |
158 | async ; |
159 | |
160 | |
161 | |
162 | |
163 | T: FnOnce(T1) -> F + Clone + Send + 'static, |
164 | F: + Send, |
165 | T1: + Send, |
166 | S: Send + Sync, |
167 | E: Error + Send + Sync + 'static, |
168 | |
169 | async |
170 | let value = T1 from_message .await?; |
171 | self .await.map_err |
172 | |
173 | |
174 | |
175 | |
176 | |
177 | |
178 | T: FnOnce(T1, T2) -> F + Clone + Send + 'static, |
179 | F: + Send, |
180 | T1: + Send, |
181 | T2: + Send, |
182 | S: Send + Sync, |
183 | E: Error + Send + Sync + 'static, |
184 | |
185 | async |
186 | let value = T1 from_message .await?; |
187 | let value_2 = T2 from_message .await?; |
188 | self .await.map_err |
189 | |
190 | |
191 | |
192 | |
193 | |
194 | |
195 | T: FnOnce(T1, T2, T3) -> F + Clone + Send + 'static, |
196 | F: + Send, |
197 | T1: + Send, |
198 | T2: + Send, |
199 | T3: + Send, |
200 | S: Send + Sync, |
201 | E: Error + Send + Sync + 'static, |
202 | |
203 | async |
204 | let value = T1 from_message .await?; |
205 | let value_2 = T2 from_message .await?; |
206 | let value_3 = T3 from_message .await?; |
207 | |
208 | self |
209 | .await |
210 | .map_err |
211 | |
212 | |
213 | |
214 | ; |
215 | |
216 | |
217 | |
218 | |
219 | T: Clone + Send + Sync, |
220 | |
221 | async |
222 | Ok |
223 | |
224 | |
225 | |
226 | // Temp |
227 | |
228 | |
229 | |
230 | T: DeserializeOwned + Send + Sync + Serialize + Debug, |
231 | S: Clone + Send + Sync, |
232 | |
233 | async |
234 | let payload: AuthenticatedPayload = from_slice?; |
235 | let payload = deserialize?; |
236 | |
237 | info!; |
238 | |
239 | Ok |
240 | |
241 | |
242 | |
243 | ; |
244 | |
245 | /// Handshake-specific message type. |
246 | /// |
247 | /// Uses basic serde_json-based deserialization to maintain the highest |
248 | /// level of compatibility across versions. |
249 | ; |
250 | |
251 | |
252 | |
253 | |
254 | T: DeserializeOwned + Send + Sync + Serialize, |
255 | S: Clone + Send + Sync, |
256 | |
257 | async |
258 | Ok |
259 | |
260 | |
261 |