Skip to content

Commit b3e63a0

Browse files
committed
tls: require the domain type in db_update and db_delete
A tls_mgm row is identified by (domain, type), so defaulting the type when it is not given lets these two commands change a different domain than the intended one. Require it for the commands that modify an existing row; db_add and db_show keep falling back to tls_db_type. Also guard against read_param() returning None when there is no terminal to prompt on, which made the type default path raise an AttributeError instead of reporting the missing value.
1 parent a45a669 commit b3e63a0

2 files changed

Lines changed: 19 additions & 6 deletions

File tree

‎docs/modules/tls.md‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,9 @@ as paths to files. A TLS domain is identified by its name and its type
2020
```
2121
opensips-cli -x tls db_delete a.example.org server
2222
```
23+
`db_add` and `db_show` fall back to the `tls_db_type` setting, and then to
24+
`server`, when no type is given. `db_update` and `db_delete` always require
25+
it, so that they cannot change a different domain than the intended one.
2326

2427
`db_add` and `db_update` take the remaining `tls_mgm` columns as `column=value`
2528
arguments, in any order and after the domain and the type:

‎opensipscli/modules/tls.py‎

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -408,9 +408,11 @@ def tls_db_connect(self):
408408

409409
return db
410410

411-
def tls_db_domain(self, params):
411+
def tls_db_domain(self, params, require_type=False):
412412
"""
413-
resolves the (domain, type) pair identifying a tls_mgm row
413+
resolves the (domain, type) pair identifying a tls_mgm row; commands
414+
that change an existing row require the type, so that they cannot pick
415+
a different row than the intended one
414416
"""
415417
if len(params) > 0:
416418
domain = params[0]
@@ -423,9 +425,16 @@ def tls_db_domain(self, params):
423425

424426
if len(params) > 1:
425427
dtype = params[1]
428+
elif require_type:
429+
logger.error("no TLS domain type specified: "
430+
"expected 'server' or 'client'")
431+
return None, None
426432
else:
427433
dtype = cfg.read_param("tls_db_type",
428434
"TLS domain type (server/client)", "server")
435+
if not dtype:
436+
logger.error("no TLS domain type specified!")
437+
return None, None
429438

430439
if dtype.lower() not in TLS_DOMAIN_TYPES:
431440
logger.error("invalid TLS domain type '%s': "
@@ -442,13 +451,14 @@ def tls_db_reload(self):
442451
logger.warning("could not reload the TLS domains; "
443452
"OpenSIPS will load them at the next restart")
444453

445-
def tls_db_params(self, params):
454+
def tls_db_params(self, params, require_type=False):
446455
"""
447456
splits the params into the (domain, type) pair identifying the row and
448457
the 'column=value' assignments; the value of a PEM column is the path
449458
of the file holding it
450459
"""
451-
domain, dtype = self.tls_db_domain([p for p in params if '=' not in p])
460+
domain, dtype = self.tls_db_domain(
461+
[p for p in params if '=' not in p], require_type)
452462
if not domain:
453463
return None, None, None
454464

@@ -511,7 +521,7 @@ def do_db_update(self, params=None, modifiers=None):
511521
"""
512522
changes the given columns of an existing TLS domain
513523
"""
514-
domain, dtype, cols = self.tls_db_params(params or [])
524+
domain, dtype, cols = self.tls_db_params(params or [], True)
515525
if not domain:
516526
return -1
517527

@@ -619,7 +629,7 @@ def do_db_delete(self, params=None, modifiers=None):
619629
"""
620630
removes a TLS domain from the database
621631
"""
622-
domain, dtype = self.tls_db_domain(params or [])
632+
domain, dtype = self.tls_db_domain(params or [], True)
623633
if not domain:
624634
return -1
625635

0 commit comments

Comments
 (0)