Skip to content

Commit 63af333

Browse files
committed
tls: report the identity columns instead of calling them unknown
'db_add a.example.org type=client' reported "unknown tls_mgm column 'type'", which is not true: the column exists, it just identifies the row and is passed as an argument. Name the three identity columns and say so. Parse the columns before resolving the domain as well, so that such a command is rejected right away rather than after asking for the domain and its type.
1 parent 920ca68 commit 63af333

1 file changed

Lines changed: 18 additions & 8 deletions

File tree

‎opensipscli/modules/tls.py‎

Lines changed: 18 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,9 @@
4848
# columns holding PEM content, which is read from the file they point to
4949
TLS_PEM_COLUMNS = [TLS_CERT_COL, TLS_PK_COL, TLS_CALIST_COL, TLS_DH_COL]
5050

51+
# columns identifying a row, which are not provisioned as 'column=value'
52+
TLS_ID_COLUMNS = ["id", TLS_DOMAIN_COL, TLS_TYPE_COL]
53+
5154
# as defined by CLIENT_DOMAIN_TYPE/SERVER_DOMAIN_TYPE in tls_mgm/tls_domain.h
5255
TLS_DOMAIN_TYPES = {"client": 1, "server": 2}
5356
TLS_TYPE_NAMES = {v: k for k, v in TLS_DOMAIN_TYPES.items()}
@@ -449,18 +452,20 @@ def tls_db_reload(self):
449452

450453
def tls_db_params(self, params, require_type=False):
451454
"""
452-
splits the params into the (domain, type) pair identifying the row and
453-
the 'column=value' assignments; the value of a PEM column is the path
454-
of the file holding it
455+
splits the params into the 'column=value' assignments and the
456+
(domain, type) pair identifying the row; the value of a PEM column is
457+
the path of the file holding it. The columns are parsed first, so that
458+
a bad one is reported without asking for the domain beforehand
455459
"""
456-
domain, dtype = self.tls_db_domain(
457-
[p for p in params if '=' not in p], require_type)
458-
if not domain:
459-
return None, None, None
460-
461460
cols = {}
462461
for param in [p for p in params if '=' in p]:
463462
col, val = param.split('=', 1)
463+
if col in TLS_ID_COLUMNS:
464+
logger.error("column '%s' identifies the row and cannot be "
465+
"provisioned; the domain and its type are passed as "
466+
"arguments", col)
467+
return None, None, None
468+
464469
if col not in TLS_MGM_COLUMNS:
465470
logger.error("unknown %s column '%s'", TLS_MGM_TABLE, col)
466471
return None, None, None
@@ -481,6 +486,11 @@ def tls_db_params(self, params, require_type=False):
481486

482487
cols[col] = val
483488

489+
domain, dtype = self.tls_db_domain(
490+
[p for p in params if '=' not in p], require_type)
491+
if not domain:
492+
return None, None, None
493+
484494
return domain, dtype, cols
485495

486496
def do_db_add(self, params=None, modifiers=None):

0 commit comments

Comments
 (0)