mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-09-30 05:14:52 +02:00
Change authoris* to the US spelling of authoriz* for consistency.
This commit is contained in:
@@ -36,11 +36,11 @@ log_info() {
|
||||
}
|
||||
|
||||
if [ "$1" == "krill" ]; then
|
||||
# Does the opreator want to use their own API token? If so they must
|
||||
# Does the operator want to use their own API token? If so they must
|
||||
# supply the KRILL_AUTH_TOKEN env var.
|
||||
if [ "${KRILL_AUTH_TOKEN}" == "None" ]; then
|
||||
# Generate a unique hard to guess authorisation token and export it
|
||||
# so that the Krill daemon uses it (unless overriden by the Krill
|
||||
# Generate a unique hard to guess authorization token and export it
|
||||
# so that the Krill daemon uses it (unless overridden by the Krill
|
||||
# daemon config file). Only do this if the operator didn't already
|
||||
# supply a token when launching the Docker container.
|
||||
export KRILL_AUTH_TOKEN=$(uuidgen)
|
||||
|
||||
@@ -122,7 +122,7 @@ impl AsRef<TypedPrefix> for RoaDefinition {
|
||||
/// on its resource certificates.
|
||||
///
|
||||
/// Multiple updates are sent as a single delta, because it's important that
|
||||
/// all authorisations for a given prefix are published together in order to
|
||||
/// all authorizations for a given prefix are published together in order to
|
||||
/// avoid invalidating announcements.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct RoaDefinitionUpdates {
|
||||
@@ -423,10 +423,10 @@ pub enum AuthorizationFmtError {
|
||||
#[display(fmt = "Invalid asn in string: {}", _0)]
|
||||
Asn(String),
|
||||
|
||||
#[display(fmt = "Invalid authorisation string: {}", _0)]
|
||||
#[display(fmt = "Invalid authorization string: {}", _0)]
|
||||
Auth(String),
|
||||
|
||||
#[display(fmt = "Invalid authorisation delta string: {}", _0)]
|
||||
#[display(fmt = "Invalid authorization delta string: {}", _0)]
|
||||
Delta(String),
|
||||
}
|
||||
|
||||
|
||||
@@ -165,7 +165,7 @@ impl fmt::Display for RoaTable {
|
||||
writeln!(f)?;
|
||||
writeln!(f, "\tDefinition: {}", roa.definition)?;
|
||||
writeln!(f)?;
|
||||
writeln!(f, "\t\tAuthorises:")?;
|
||||
writeln!(f, "\t\tAuthorizes:")?;
|
||||
for ann in roa.authorizes.iter() {
|
||||
writeln!(f, "\t\t{}", ann)?;
|
||||
}
|
||||
@@ -265,7 +265,7 @@ impl fmt::Display for RoaSummmaryEntry {
|
||||
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
|
||||
let state_str = match self.state {
|
||||
RoaSummaryState::Valid => "announcement 'valid'",
|
||||
RoaSummaryState::InvalidAsn => "announcement 'invalid': unauthorised asn",
|
||||
RoaSummaryState::InvalidAsn => "announcement 'invalid': unauthorized asn",
|
||||
RoaSummaryState::InvalidLength => "announcement 'invalid': more specific than allowed",
|
||||
RoaSummaryState::NotFound => "announcement 'not found': not covered by your ROAs",
|
||||
RoaSummaryState::Stale => {
|
||||
|
||||
+17
-17
@@ -179,7 +179,7 @@ pub enum Error {
|
||||
CaChildExtraResources(Handle, ChildHandle),
|
||||
|
||||
#[display(fmt = "CA '{}' does not know id certificate for child '{}'", _0, _1)]
|
||||
CaChildUnauthorised(Handle, ChildHandle),
|
||||
CaChildUnauthorized(Handle, ChildHandle),
|
||||
|
||||
#[display(
|
||||
fmt = "You can only update one aspect for child '{}' of CA '{}' at a time - i.e. either resources or ID cert",
|
||||
@@ -190,16 +190,16 @@ pub enum Error {
|
||||
|
||||
// RouteAuthorizations - ROAs
|
||||
#[display(fmt = "Cannot remove unknown ROA '{}' from CA '{}'", _0, _1)]
|
||||
CaAuthorisationUnknown(Handle, RouteAuthorization),
|
||||
CaAuthorizationUnknown(Handle, RouteAuthorization),
|
||||
|
||||
#[display(fmt = "Duplicate ROA '{}' for CA '{}'", _1, _0)]
|
||||
CaAuthorisationDuplicate(Handle, RouteAuthorization),
|
||||
CaAuthorizationDuplicate(Handle, RouteAuthorization),
|
||||
|
||||
#[display(fmt = "Invalid max length in ROA: '{}' for CA '{}", _1, _0)]
|
||||
CaAuthorisationInvalidMaxlength(Handle, RouteAuthorization),
|
||||
CaAuthorizationInvalidMaxlength(Handle, RouteAuthorization),
|
||||
|
||||
#[display(fmt = "Prefix in ROA '{}' not held by CA '{}'.", _1, _0)]
|
||||
CaAuthorisationNotEntitled(Handle, RouteAuthorization),
|
||||
CaAuthorizationNotEntitled(Handle, RouteAuthorization),
|
||||
|
||||
//-----------------------------------------------------------------
|
||||
// Key Usage Issues
|
||||
@@ -496,8 +496,8 @@ impl Error {
|
||||
.with_ca(ca)
|
||||
.with_child(child)
|
||||
}
|
||||
Error::CaChildUnauthorised(ca, child) => {
|
||||
ErrorResponse::new("ca-child-unauthorised", &self)
|
||||
Error::CaChildUnauthorized(ca, child) => {
|
||||
ErrorResponse::new("ca-child-unauthorized", &self)
|
||||
.with_ca(ca)
|
||||
.with_child(child)
|
||||
}
|
||||
@@ -509,23 +509,23 @@ impl Error {
|
||||
}
|
||||
|
||||
// RouteAuthorizations
|
||||
Error::CaAuthorisationUnknown(ca, auth) => ErrorResponse::new("ca-roa-unknown", &self)
|
||||
Error::CaAuthorizationUnknown(ca, auth) => ErrorResponse::new("ca-roa-unknown", &self)
|
||||
.with_ca(ca)
|
||||
.with_auth(auth),
|
||||
|
||||
Error::CaAuthorisationDuplicate(ca, auth) => {
|
||||
Error::CaAuthorizationDuplicate(ca, auth) => {
|
||||
ErrorResponse::new("ca-roa-duplicate", &self)
|
||||
.with_ca(ca)
|
||||
.with_auth(auth)
|
||||
}
|
||||
|
||||
Error::CaAuthorisationInvalidMaxlength(ca, auth) => {
|
||||
Error::CaAuthorizationInvalidMaxlength(ca, auth) => {
|
||||
ErrorResponse::new("ca-roa-invalid-max-length", &self)
|
||||
.with_ca(ca)
|
||||
.with_auth(auth)
|
||||
}
|
||||
|
||||
Error::CaAuthorisationNotEntitled(ca, auth) => {
|
||||
Error::CaAuthorizationNotEntitled(ca, auth) => {
|
||||
ErrorResponse::new("ca-roa-not-entitled", &self)
|
||||
.with_ca(ca)
|
||||
.with_auth(auth)
|
||||
@@ -834,32 +834,32 @@ mod tests {
|
||||
);
|
||||
verify(
|
||||
include_str!(
|
||||
"../../test-resources/api/regressions/v0_6_0/errors/ca-child-unauthorised.json"
|
||||
"../../test-resources/api/regressions/v0_6_0/errors/ca-child-unauthorized.json"
|
||||
),
|
||||
Error::CaChildUnauthorised(ca.clone(), child),
|
||||
Error::CaChildUnauthorized(ca.clone(), child),
|
||||
);
|
||||
|
||||
verify(
|
||||
include_str!("../../test-resources/api/regressions/v0_6_0/errors/ca-roa-unknown.json"),
|
||||
Error::CaAuthorisationUnknown(ca.clone(), auth),
|
||||
Error::CaAuthorizationUnknown(ca.clone(), auth),
|
||||
);
|
||||
verify(
|
||||
include_str!(
|
||||
"../../test-resources/api/regressions/v0_6_0/errors/ca-roa-duplicate.json"
|
||||
),
|
||||
Error::CaAuthorisationDuplicate(ca.clone(), auth),
|
||||
Error::CaAuthorizationDuplicate(ca.clone(), auth),
|
||||
);
|
||||
verify(
|
||||
include_str!(
|
||||
"../../test-resources/api/regressions/v0_6_0/errors/ca-roa-invalid-max-length.json"
|
||||
),
|
||||
Error::CaAuthorisationInvalidMaxlength(ca.clone(), auth),
|
||||
Error::CaAuthorizationInvalidMaxlength(ca.clone(), auth),
|
||||
);
|
||||
verify(
|
||||
include_str!(
|
||||
"../../test-resources/api/regressions/v0_6_0/errors/ca-roa-not-entitled.json"
|
||||
),
|
||||
Error::CaAuthorisationNotEntitled(ca, auth),
|
||||
Error::CaAuthorizationNotEntitled(ca, auth),
|
||||
);
|
||||
|
||||
verify(
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ use crate::commons::api::Token;
|
||||
|
||||
//------------ Authorizer ----------------------------------------------------
|
||||
|
||||
/// This type is responsible for checking authorisations when the API is
|
||||
/// This type is responsible for checking authorizations when the API is
|
||||
/// accessed.
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct Authorizer {
|
||||
|
||||
@@ -538,7 +538,7 @@ impl<S: Signer> CertAuth<S> {
|
||||
|
||||
let child_cert = child
|
||||
.id_cert()
|
||||
.ok_or_else(|| Error::CaChildUnauthorised(self.handle.clone(), child_handle.clone()))?;
|
||||
.ok_or_else(|| Error::CaChildUnauthorized(self.handle.clone(), child_handle.clone()))?;
|
||||
|
||||
msg.validate(child_cert)
|
||||
.map_err(|_| Error::Rfc6492SignatureInvalid)?;
|
||||
@@ -687,7 +687,7 @@ impl<S: Signer> CertAuth<S> {
|
||||
|
||||
/// Certifies a child, unless:
|
||||
/// = the child is unknown,
|
||||
/// = the child is not authorised,
|
||||
/// = the child is not authorized,
|
||||
/// = the csr is invalid,
|
||||
/// = the limit exceeds the child allocation,
|
||||
/// = the signer throws up..
|
||||
@@ -1480,7 +1480,7 @@ impl<S: Signer> CertAuth<S> {
|
||||
///
|
||||
impl<S: Signer> CertAuth<S> {
|
||||
/// Updates the route authorizations for this CA, and update ROAs. Will return
|
||||
/// an error in case authorisations are added for which this CA does not hold
|
||||
/// an error in case authorizations are added for which this CA does not hold
|
||||
/// the prefix.
|
||||
fn route_authorizations_update(
|
||||
&self,
|
||||
@@ -1502,15 +1502,15 @@ impl<S: Signer> CertAuth<S> {
|
||||
|
||||
for auth in added {
|
||||
if !auth.max_length_valid() {
|
||||
return Err(Error::CaAuthorisationInvalidMaxlength(
|
||||
return Err(Error::CaAuthorizationInvalidMaxlength(
|
||||
self.handle.clone(),
|
||||
auth,
|
||||
));
|
||||
}
|
||||
if current_auths.contains(&auth) {
|
||||
return Err(Error::CaAuthorisationDuplicate(self.handle.clone(), auth));
|
||||
return Err(Error::CaAuthorizationDuplicate(self.handle.clone(), auth));
|
||||
} else if !all_resources.contains(&auth.prefix().into()) {
|
||||
return Err(Error::CaAuthorisationNotEntitled(self.handle.clone(), auth));
|
||||
return Err(Error::CaAuthorizationNotEntitled(self.handle.clone(), auth));
|
||||
} else {
|
||||
current_auths.insert(auth);
|
||||
res.push(StoredEvent::new(
|
||||
@@ -1532,7 +1532,7 @@ impl<S: Signer> CertAuth<S> {
|
||||
));
|
||||
version += 1;
|
||||
} else {
|
||||
return Err(Error::CaAuthorisationUnknown(self.handle.clone(), auth));
|
||||
return Err(Error::CaAuthorizationUnknown(self.handle.clone(), auth));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -44,7 +44,7 @@ pub struct KrillServer {
|
||||
// The base working directory, used for various storage
|
||||
work_dir: PathBuf,
|
||||
|
||||
// Component responsible for API authorisation checks
|
||||
// Component responsible for API authorization checks
|
||||
authorizer: Authorizer,
|
||||
|
||||
// Publication server, with configured publishers
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
{"label":"ca-child-unauthorised","msg":"CA 'ca' does not know id certificate for child 'child'","args":{"ca":"ca","child":"child"}}
|
||||
@@ -0,0 +1 @@
|
||||
{"label":"ca-child-unauthorized","msg":"CA 'ca' does not know id certificate for child 'child'","args":{"ca":"ca","child":"child"}}
|
||||
Reference in New Issue
Block a user