Render approved IP-auth SIP endpoints for native Asterisk

This commit is contained in:
2026-10-03 11:43:39 +08:00
parent 57960c9fca
commit b68711be9c
2 changed files with 126 additions and 0 deletions
+73
View File
@@ -0,0 +1,73 @@
package asterisk
import (
"encoding/json"
"errors"
"fmt"
"net/netip"
"regexp"
"sort"
"strings"
"git.ipao.vip/rogee/go-sip/internal/configread"
"git.ipao.vip/rogee/go-sip/internal/contract"
)
var trunkName = regexp.MustCompile(`^[a-zA-Z0-9][a-zA-Z0-9_-]{0,63}$`)
type trunk struct {
ID string `json:"trunk_id"`
Host string `json:"server_host"`
Port int `json:"server_port"`
Transport *string `json:"transport"`
AuthMode *string `json:"auth_mode"`
RegistrationRequired *bool `json:"registration_required"`
Codec string `json:"codec"`
Enabled bool `json:"enabled"`
}
// Render produces only PJSIP endpoint/AOR objects. Transport is owned by the
// static, reviewed Asterisk base configuration and is never hot-reloaded.
func Render(sip configread.SIP) (string, error) {
raw, err := json.Marshal(sip)
if err != nil {
return "", fmt.Errorf("encode approved SIP snapshot: %w", err)
}
if err := contract.ValidateCurrent("config-read", raw); err != nil {
return "", fmt.Errorf("validate approved SIP snapshot: %w", err)
}
var trunks []trunk
if err := json.Unmarshal(sip.Trunks, &trunks); err != nil {
return "", fmt.Errorf("decode approved SIP trunks: %w", err)
}
seen := make(map[string]bool, len(trunks))
for _, t := range trunks {
if !trunkName.MatchString(t.ID) || seen[t.ID] {
return "", fmt.Errorf("invalid or duplicated SIP trunk ID %q", t.ID)
}
seen[t.ID] = true
if !t.Enabled {
continue
}
if t.Transport == nil || *t.Transport != "udp" || t.AuthMode == nil || (*t.AuthMode != "none" && *t.AuthMode != "ip") || t.RegistrationRequired == nil || *t.RegistrationRequired {
return "", fmt.Errorf("trunk %q uses unsupported transport, authentication or registration", t.ID)
}
addr, err := netip.ParseAddr(t.Host)
if err != nil || !addr.Is4() || t.Port < 1 || t.Port > 65535 || t.Codec != "PCMA" {
return "", fmt.Errorf("trunk %q has unsupported endpoint address or codec", t.ID)
}
}
sort.Slice(trunks, func(i, j int) bool { return trunks[i].ID < trunks[j].ID })
var text strings.Builder
text.WriteString("; Generated from the approved SIP snapshot. Do not edit manually.\n")
for _, t := range trunks {
if !t.Enabled {
continue
}
_, _ = fmt.Fprintf(&text, "\n[%s]\ntype=endpoint\ntransport=go-sip-udp\ncontext=go-sip-no-inbound\ndisallow=all\nallow=alaw\naors=%s-aor\ndirect_media=no\n\n[%s-aor]\ntype=aor\ncontact=sip:%s:%d\n", t.ID, t.ID, t.ID, t.Host, t.Port)
}
if text.Len() == 0 {
return "", errors.New("empty generated SIP configuration")
}
return text.String(), nil
}
+53
View File
@@ -0,0 +1,53 @@
package asterisk
import (
"encoding/json"
"strings"
"testing"
"git.ipao.vip/rogee/go-sip/internal/configread"
)
func testSIP(t *testing.T) configread.SIP {
t.Helper()
var sip configread.SIP
if err := json.Unmarshal([]byte(`{"resource":"sip_config","dispatcher_id":"c046b893-8628-4589-ae50-619d049248a6","revision":9,"trunks":[{"trunk_id":"trunk-shuqi","provider_id":"shuqi","codec":"PCMA","dial_prefix":"7089","enabled":true,"server_host":"61.132.228.221","server_port":5060,"transport":"udp","auth_mode":"ip","registration_required":false,"max_concurrent_calls":1,"caller_profiles":[{"caller_profile_id":"caller-shuqi","caller_id":"BD93205882"}],"schedule":{"time_zone":"Asia/Shanghai","weekly_windows":{"monday":[{"start":"09:00","end":"20:00"}],"tuesday":[],"wednesday":[],"thursday":[],"friday":[],"saturday":[],"sunday":[]}}}]}`), &sip); err != nil {
t.Fatal(err)
}
return sip
}
func TestRenderApprovedIPTrunk(t *testing.T) {
text, err := Render(testSIP(t))
if err != nil {
t.Fatal(err)
}
for _, want := range []string{"[trunk-shuqi]", "type=endpoint", "transport=go-sip-udp", "allow=alaw", "aors=trunk-shuqi-aor", "contact=sip:61.132.228.221:5060"} {
if !strings.Contains(text, want) {
t.Errorf("rendered SIP is missing %q", want)
}
}
if strings.Contains(text, "type=transport") || strings.Contains(text, "7089") || strings.Contains(text, "BD93205882") || strings.Contains(text, "register=") {
t.Fatal("per-call prefix/caller or registration leaked into static endpoint")
}
}
func TestRenderRejectsUnsupportedOrAmbiguousSIP(t *testing.T) {
for _, mutation := range []struct{ name, from, to string }{
{"digest", `"auth_mode":"ip"`, `"auth_mode":"digest"`},
{"register", `"registration_required":false`, `"registration_required":true`},
{"tcp", `"transport":"udp"`, `"transport":"tcp"`},
{"missing_transport", `"transport":"udp"`, `"transport":null`},
{"missing_auth", `"auth_mode":"ip"`, `"auth_mode":null`},
{"bad_id", `"trunk_id":"trunk-shuqi"`, `"trunk_id":"bad]\n[attacker"`},
{"bad_host", `"server_host":"61.132.228.221"`, `"server_host":"oops\npassword=bad"`},
} {
t.Run(mutation.name, func(t *testing.T) {
sip := testSIP(t)
sip.Trunks = []byte(strings.Replace(string(sip.Trunks), mutation.from, mutation.to, 1))
if _, err := Render(sip); err == nil {
t.Fatal("unsupported SIP configuration was accepted")
}
})
}
}