33 lines
1.2 KiB
Go
33 lines
1.2 KiB
Go
package rpc
|
|
|
|
import (
|
|
"context"
|
|
|
|
agentpb "git.ipao.vip/rogee/go-sip/gen/agent"
|
|
"google.golang.org/grpc/codes"
|
|
"google.golang.org/grpc/credentials"
|
|
"google.golang.org/grpc/peer"
|
|
"google.golang.org/grpc/status"
|
|
)
|
|
|
|
func verifyRecordingPeer(ctx context.Context, meta *agentpb.RequestMeta, fingerprints map[string]struct{}) error {
|
|
if meta == nil {
|
|
return status.Error(codes.InvalidArgument, "agent request metadata is required")
|
|
}
|
|
p, ok := peer.FromContext(ctx)
|
|
if !ok || p.AuthInfo == nil {
|
|
return status.Error(codes.Unauthenticated, "verified mTLS agent certificate is required")
|
|
}
|
|
tlsInfo, ok := p.AuthInfo.(credentials.TLSInfo)
|
|
if !ok || len(tlsInfo.State.VerifiedChains) == 0 || len(tlsInfo.State.VerifiedChains[0]) == 0 {
|
|
return status.Error(codes.Unauthenticated, "verified mTLS agent certificate is required")
|
|
}
|
|
if len(fingerprints) == 0 {
|
|
return status.Error(codes.PermissionDenied, "approved agent certificate fingerprints are required")
|
|
}
|
|
if _, allowed := fingerprints[CertificateFingerprint(tlsInfo.State.VerifiedChains[0][0])]; !allowed {
|
|
return status.Error(codes.PermissionDenied, "agent certificate fingerprint is not approved")
|
|
}
|
|
return nil
|
|
}
|