refactor: move enable-crypto to new core option secure to set the TLS setting
This commit is contained in:
parent
53b36801e1
commit
ff4c9dc421
11 changed files with 61 additions and 18 deletions
|
|
@ -52,7 +52,7 @@ Client::Client(
|
||||||
m_socketFactory(socketFactory),
|
m_socketFactory(socketFactory),
|
||||||
m_screen(screen),
|
m_screen(screen),
|
||||||
m_events(events),
|
m_events(events),
|
||||||
m_useSecureNetwork(args.m_enableCrypto),
|
m_useSecureNetwork(Settings::value(Settings::Security::TlsEnabled).toBool()),
|
||||||
m_args(args)
|
m_args(args)
|
||||||
{
|
{
|
||||||
assert(m_socketFactory != nullptr);
|
assert(m_socketFactory != nullptr);
|
||||||
|
|
@ -388,7 +388,7 @@ void Client::setupConnecting()
|
||||||
{
|
{
|
||||||
assert(m_stream != nullptr);
|
assert(m_stream != nullptr);
|
||||||
|
|
||||||
if (m_args.m_enableCrypto) {
|
if (Settings::value(Settings::Security::TlsEnabled).toBool()) {
|
||||||
m_events->addHandler(EventTypes::DataSocketSecureConnected, m_stream->getEventTarget(), [this](const auto &) {
|
m_events->addHandler(EventTypes::DataSocketSecureConnected, m_stream->getEventTarget(), [this](const auto &) {
|
||||||
handleConnected();
|
handleConnected();
|
||||||
});
|
});
|
||||||
|
|
|
||||||
|
|
@ -131,7 +131,6 @@ private:
|
||||||
constexpr static auto s_helpGeneralArgs = //
|
constexpr static auto s_helpGeneralArgs = //
|
||||||
" -1, --no-restart do not try to restart on failure.\n"
|
" -1, --no-restart do not try to restart on failure.\n"
|
||||||
"* --restart restart the server automatically if it fails.\n"
|
"* --restart restart the server automatically if it fails.\n"
|
||||||
" --enable-crypto enable TLS encryption.\n"
|
|
||||||
" --tls-cert specify the path to the TLS certificate file.\n";
|
" --tls-cert specify the path to the TLS certificate file.\n";
|
||||||
|
|
||||||
constexpr static auto s_helpVersionArgs = //
|
constexpr static auto s_helpVersionArgs = //
|
||||||
|
|
|
||||||
|
|
@ -139,8 +139,6 @@ bool ArgParser::parseGenericArgs(int argc, const char *const *argv, int &i) cons
|
||||||
// HACK: stop error happening when using portable (deskflowp)
|
// HACK: stop error happening when using portable (deskflowp)
|
||||||
} else if (isArg(i, argc, argv, nullptr, "--client")) {
|
} else if (isArg(i, argc, argv, nullptr, "--client")) {
|
||||||
// HACK: stop error happening when using portable (deskflowp)
|
// HACK: stop error happening when using portable (deskflowp)
|
||||||
} else if (isArg(i, argc, argv, nullptr, "--enable-crypto")) {
|
|
||||||
argsBase().m_enableCrypto = true;
|
|
||||||
} else if (isArg(i, argc, argv, nullptr, "--tls-cert", 1)) {
|
} else if (isArg(i, argc, argv, nullptr, "--tls-cert", 1)) {
|
||||||
argsBase().m_tlsCertFile = argv[++i];
|
argsBase().m_tlsCertFile = argv[++i];
|
||||||
} else if (isArg(i, argc, argv, nullptr, "--prevent-sleep")) {
|
} else if (isArg(i, argc, argv, nullptr, "--prevent-sleep")) {
|
||||||
|
|
|
||||||
|
|
@ -50,9 +50,6 @@ public:
|
||||||
/// @brief Will cause the application to exit with fail code when set to true
|
/// @brief Will cause the application to exit with fail code when set to true
|
||||||
bool m_shouldExitFail = false;
|
bool m_shouldExitFail = false;
|
||||||
|
|
||||||
/// @brief Should the connections be TLS encrypted
|
|
||||||
bool m_enableCrypto = false;
|
|
||||||
|
|
||||||
/// @brief Contains the location of the TLS certificate file
|
/// @brief Contains the location of the TLS certificate file
|
||||||
std::string m_tlsCertFile;
|
std::string m_tlsCertFile;
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -72,6 +72,13 @@ void CoreArgParser::parse()
|
||||||
} else {
|
} else {
|
||||||
Settings::setValue(Settings::Log::ToFile, false);
|
Settings::setValue(Settings::Log::ToFile, false);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (m_parser.isSet(CoreArgs::secureOption)) {
|
||||||
|
bool value =
|
||||||
|
((m_parser.value(CoreArgs::secureOption).toLower() == "true") || (m_parser.value(CoreArgs::secureOption) == "1")
|
||||||
|
);
|
||||||
|
Settings::setValue(Settings::Security::TlsEnabled, value);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
[[noreturn]] void CoreArgParser::showHelpText() const
|
[[noreturn]] void CoreArgParser::showHelpText() const
|
||||||
|
|
|
||||||
|
|
@ -38,6 +38,9 @@ struct CoreArgs
|
||||||
|
|
||||||
inline static const auto logFileOption = QCommandLineOption({"l", "log"}, "Write messages to file", "file");
|
inline static const auto logFileOption = QCommandLineOption({"l", "log"}, "Write messages to file", "file");
|
||||||
|
|
||||||
inline static const auto options = {helpOption, versionOption, configOption, interfaceOption,
|
inline static const auto secureOption =
|
||||||
portOption, nameOption, logLevelOption, logFileOption};
|
QCommandLineOption("secure", "Enable TLS encryption (default: true)", "value");
|
||||||
|
|
||||||
|
inline static const auto options = {helpOption, versionOption, configOption, interfaceOption, portOption,
|
||||||
|
nameOption, logLevelOption, logFileOption, secureOption};
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -516,7 +516,7 @@ ClientListener *ServerApp::openClientListener(const NetworkAddress &address)
|
||||||
{
|
{
|
||||||
using enum SecurityLevel;
|
using enum SecurityLevel;
|
||||||
auto securityLevel = PlainText;
|
auto securityLevel = PlainText;
|
||||||
if (args().m_enableCrypto) {
|
if (Settings::value(Settings::Security::TlsEnabled).toBool()) {
|
||||||
if (args().m_chkPeerCert) {
|
if (args().m_chkPeerCert) {
|
||||||
securityLevel = PeerAuth;
|
securityLevel = PeerAuth;
|
||||||
} else {
|
} else {
|
||||||
|
|
|
||||||
|
|
@ -456,10 +456,6 @@ void CoreProcess::cleanup()
|
||||||
|
|
||||||
bool CoreProcess::addGenericArgs(QStringList &args) const
|
bool CoreProcess::addGenericArgs(QStringList &args) const
|
||||||
{
|
{
|
||||||
if (Settings::value(Settings::Security::TlsEnabled).toBool()) {
|
|
||||||
args << "--enable-crypto";
|
|
||||||
}
|
|
||||||
|
|
||||||
if (Settings::value(Settings::Core::PreventSleep).toBool()) {
|
if (Settings::value(Settings::Core::PreventSleep).toBool()) {
|
||||||
args << "--prevent-sleep";
|
args << "--prevent-sleep";
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -238,12 +238,11 @@ void ArgParserTests::client_commonArgs()
|
||||||
{
|
{
|
||||||
deskflow::ClientArgs clientArgs;
|
deskflow::ClientArgs clientArgs;
|
||||||
clientArgs.m_enableLangSync = false;
|
clientArgs.m_enableLangSync = false;
|
||||||
const int argc = 5;
|
const int argc = 4;
|
||||||
std::array<const char *, argc> kLangCmd = {"stub", "--enable-crypto", "--tls-cert", "tlsCertPath", "--prevent-sleep"};
|
std::array<const char *, argc> kLangCmd = {"stub", "--tls-cert", "tlsCertPath", "--prevent-sleep"};
|
||||||
|
|
||||||
m_parser.parseClientArgs(clientArgs, argc, kLangCmd.data());
|
m_parser.parseClientArgs(clientArgs, argc, kLangCmd.data());
|
||||||
|
|
||||||
QVERIFY(clientArgs.m_enableCrypto);
|
|
||||||
QVERIFY(clientArgs.m_preventSleep);
|
QVERIFY(clientArgs.m_preventSleep);
|
||||||
QCOMPARE(clientArgs.m_tlsCertFile, "tlsCertPath");
|
QCOMPARE(clientArgs.m_tlsCertFile, "tlsCertPath");
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -110,4 +110,44 @@ void CoreArgParserTests::logFileWithSpace()
|
||||||
QCOMPARE(Settings::value(Settings::Log::File).toString(), "mock filename");
|
QCOMPARE(Settings::value(Settings::Log::File).toString(), "mock filename");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
void CoreArgParserTests::secure_false()
|
||||||
|
{
|
||||||
|
QStringList args = {"stub", "client", "--secure", "false"};
|
||||||
|
|
||||||
|
CoreArgParser parser(args);
|
||||||
|
parser.parse();
|
||||||
|
|
||||||
|
QVERIFY(!Settings::value(Settings::Security::TlsEnabled).toBool());
|
||||||
|
}
|
||||||
|
|
||||||
|
void CoreArgParserTests::secure_true()
|
||||||
|
{
|
||||||
|
QStringList args = {"stub", "client", "--secure", "true"};
|
||||||
|
|
||||||
|
CoreArgParser parser(args);
|
||||||
|
parser.parse();
|
||||||
|
|
||||||
|
QVERIFY(Settings::value(Settings::Security::TlsEnabled).toBool());
|
||||||
|
}
|
||||||
|
|
||||||
|
void CoreArgParserTests::secure_0()
|
||||||
|
{
|
||||||
|
QStringList args = {"stub", "client", "--secure", "0"};
|
||||||
|
|
||||||
|
CoreArgParser parser(args);
|
||||||
|
parser.parse();
|
||||||
|
|
||||||
|
QVERIFY(!Settings::value(Settings::Security::TlsEnabled).toBool());
|
||||||
|
}
|
||||||
|
|
||||||
|
void CoreArgParserTests::secure_1()
|
||||||
|
{
|
||||||
|
QStringList args = {"stub", "client", "--secure", "1"};
|
||||||
|
|
||||||
|
CoreArgParser parser(args);
|
||||||
|
parser.parse();
|
||||||
|
|
||||||
|
QVERIFY(Settings::value(Settings::Security::TlsEnabled).toBool());
|
||||||
|
}
|
||||||
|
|
||||||
QTEST_MAIN(CoreArgParserTests)
|
QTEST_MAIN(CoreArgParserTests)
|
||||||
|
|
|
||||||
|
|
@ -23,6 +23,10 @@ private Q_SLOTS:
|
||||||
void logLevel();
|
void logLevel();
|
||||||
void logFile();
|
void logFile();
|
||||||
void logFileWithSpace();
|
void logFileWithSpace();
|
||||||
|
void secure_false();
|
||||||
|
void secure_true();
|
||||||
|
void secure_0();
|
||||||
|
void secure_1();
|
||||||
|
|
||||||
private:
|
private:
|
||||||
inline static const QString m_settingsPath = QStringLiteral("tmp/test");
|
inline static const QString m_settingsPath = QStringLiteral("tmp/test");
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue