mirror of https://github.com/grpc/grpc.git
commit
ad6b4bb81a
34 changed files with 1138 additions and 240 deletions
@ -0,0 +1,93 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Threading; |
||||||
|
|
||||||
|
using Google.Apis.Auth.OAuth2; |
||||||
|
using Grpc.Core; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
|
||||||
|
namespace Grpc.Auth |
||||||
|
{ |
||||||
|
/// <summary> |
||||||
|
/// Factory methods to create instances of <see cref="ChannelCredentials"/> and <see cref="CallCredentials"/> classes. |
||||||
|
/// </summary> |
||||||
|
public static class GrpcCredentials |
||||||
|
{ |
||||||
|
/// <summary> |
||||||
|
/// Creates a <see cref="MetadataCredentials"/> instance that will obtain access tokens |
||||||
|
/// from any credential that implements <c>ITokenAccess</c>. (e.g. <c>GoogleCredential</c>). |
||||||
|
/// </summary> |
||||||
|
/// <param name="credential">The credential to use to obtain access tokens.</param> |
||||||
|
/// <returns>The <c>MetadataCredentials</c> instance.</returns> |
||||||
|
public static MetadataCredentials Create(ITokenAccess credential) |
||||||
|
{ |
||||||
|
return new MetadataCredentials(AuthInterceptors.FromCredential(credential)); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Convenience method to create a <see cref="ChannelCredentials"/> instance from |
||||||
|
/// <c>ITokenAccess</c> credential and <c>SslCredentials</c> instance. |
||||||
|
/// </summary> |
||||||
|
/// <param name="credential">The credential to use to obtain access tokens.</param> |
||||||
|
/// <param name="sslCredentials">The <c>SslCredentials</c> instance.</param> |
||||||
|
/// <returns>The channel credentials for access token based auth over a secure channel.</returns> |
||||||
|
public static ChannelCredentials Create(ITokenAccess credential, SslCredentials sslCredentials) |
||||||
|
{ |
||||||
|
return ChannelCredentials.Create(sslCredentials, Create(credential)); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates an instance of <see cref="MetadataCredentials"/> that will use given access token to authenticate |
||||||
|
/// with a gRPC service. |
||||||
|
/// </summary> |
||||||
|
/// <param name="accessToken">OAuth2 access token.</param> |
||||||
|
/// /// <returns>The <c>MetadataCredentials</c> instance.</returns> |
||||||
|
public static MetadataCredentials FromAccessToken(string accessToken) |
||||||
|
{ |
||||||
|
return new MetadataCredentials(AuthInterceptors.FromAccessToken(accessToken)); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Converts a <c>ITokenAccess</c> object into a <see cref="MetadataCredentials"/> object supported |
||||||
|
/// by gRPC. |
||||||
|
/// </summary> |
||||||
|
/// <param name="credential"></param> |
||||||
|
/// <returns></returns> |
||||||
|
public static MetadataCredentials ToGrpcCredentials(this ITokenAccess credential) |
||||||
|
{ |
||||||
|
return GrpcCredentials.Create(credential); |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,73 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Diagnostics; |
||||||
|
using System.Runtime.InteropServices; |
||||||
|
using System.Threading; |
||||||
|
using System.Threading.Tasks; |
||||||
|
using Grpc.Core; |
||||||
|
using Grpc.Core.Internal; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
using NUnit.Framework; |
||||||
|
|
||||||
|
namespace Grpc.Core.Tests |
||||||
|
{ |
||||||
|
public class ChannelCredentialsTest |
||||||
|
{ |
||||||
|
[Test] |
||||||
|
public void InsecureCredentials_IsNonComposable() |
||||||
|
{ |
||||||
|
Assert.IsFalse(ChannelCredentials.Insecure.IsComposable); |
||||||
|
} |
||||||
|
|
||||||
|
[Test] |
||||||
|
public void ChannelCredentials_CreateComposite() |
||||||
|
{ |
||||||
|
var composite = ChannelCredentials.Create(new FakeChannelCredentials(true), new FakeCallCredentials()); |
||||||
|
Assert.IsFalse(composite.IsComposable); |
||||||
|
|
||||||
|
Assert.Throws(typeof(ArgumentNullException), () => ChannelCredentials.Create(null, new FakeCallCredentials())); |
||||||
|
Assert.Throws(typeof(ArgumentNullException), () => ChannelCredentials.Create(new FakeChannelCredentials(true), null)); |
||||||
|
|
||||||
|
// forbid composing non-composable |
||||||
|
Assert.Throws(typeof(ArgumentException), () => ChannelCredentials.Create(new FakeChannelCredentials(false), new FakeCallCredentials())); |
||||||
|
} |
||||||
|
|
||||||
|
[Test] |
||||||
|
public void ChannelCredentials_CreateWrapped() |
||||||
|
{ |
||||||
|
ChannelCredentials.Create(new FakeCallCredentials()); |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,73 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Diagnostics; |
||||||
|
using System.Runtime.InteropServices; |
||||||
|
using System.Threading; |
||||||
|
using System.Threading.Tasks; |
||||||
|
using Grpc.Core; |
||||||
|
using Grpc.Core.Internal; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
using NUnit.Framework; |
||||||
|
|
||||||
|
namespace Grpc.Core.Tests |
||||||
|
{ |
||||||
|
internal class FakeChannelCredentials : ChannelCredentials |
||||||
|
{ |
||||||
|
readonly bool composable; |
||||||
|
|
||||||
|
public FakeChannelCredentials(bool composable) |
||||||
|
{ |
||||||
|
this.composable = composable; |
||||||
|
} |
||||||
|
|
||||||
|
internal override bool IsComposable |
||||||
|
{ |
||||||
|
get { return composable; } |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return null; |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
internal class FakeCallCredentials : CallCredentials |
||||||
|
{ |
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return null; |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,142 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Collections.Generic; |
||||||
|
using System.Threading.Tasks; |
||||||
|
|
||||||
|
using Grpc.Core.Internal; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
|
||||||
|
namespace Grpc.Core |
||||||
|
{ |
||||||
|
/// <summary> |
||||||
|
/// Client-side call credentials. Provide authorization with per-call granularity. |
||||||
|
/// </summary> |
||||||
|
public abstract class CallCredentials |
||||||
|
{ |
||||||
|
/// <summary> |
||||||
|
/// Composes multiple multiple <c>CallCredentials</c> objects into |
||||||
|
/// a single <c>CallCredentials</c> object. |
||||||
|
/// </summary> |
||||||
|
/// <param name="credentials">credentials to compose</param> |
||||||
|
/// <returns>The new <c>CompositeCallCredentials</c></returns> |
||||||
|
public static CallCredentials Compose(params CallCredentials[] credentials) |
||||||
|
{ |
||||||
|
return new CompositeCallCredentials(credentials); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates native object for the credentials. |
||||||
|
/// </summary> |
||||||
|
/// <returns>The native credentials.</returns> |
||||||
|
internal abstract CredentialsSafeHandle ToNativeCredentials(); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Asynchronous authentication interceptor for <see cref="MetadataCredentials"/>. |
||||||
|
/// </summary> |
||||||
|
/// <param name="authUri">URL of a service to which current remote call needs to authenticate</param> |
||||||
|
/// <param name="metadata">Metadata to populate with entries that will be added to outgoing call's headers.</param> |
||||||
|
/// <returns></returns> |
||||||
|
public delegate Task AsyncAuthInterceptor(string authUri, Metadata metadata); |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Client-side credentials that delegate metadata based auth to an interceptor. |
||||||
|
/// The interceptor is automatically invoked for each remote call that uses <c>MetadataCredentials.</c> |
||||||
|
/// </summary> |
||||||
|
public class MetadataCredentials : CallCredentials |
||||||
|
{ |
||||||
|
readonly AsyncAuthInterceptor interceptor; |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Initializes a new instance of <c>MetadataCredentials</c> class. |
||||||
|
/// </summary> |
||||||
|
/// <param name="interceptor">authentication interceptor</param> |
||||||
|
public MetadataCredentials(AsyncAuthInterceptor interceptor) |
||||||
|
{ |
||||||
|
this.interceptor = interceptor; |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
NativeMetadataCredentialsPlugin plugin = new NativeMetadataCredentialsPlugin(interceptor); |
||||||
|
return plugin.Credentials; |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Credentials that allow composing multiple credentials objects into one <see cref="CallCredentials"/> object. |
||||||
|
/// </summary> |
||||||
|
internal sealed class CompositeCallCredentials : CallCredentials |
||||||
|
{ |
||||||
|
readonly List<CallCredentials> credentials; |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Initializes a new instance of <c>CompositeCallCredentials</c> class. |
||||||
|
/// The resulting credentials object will be composite of all the credentials specified as parameters. |
||||||
|
/// </summary> |
||||||
|
/// <param name="credentials">credentials to compose</param> |
||||||
|
public CompositeCallCredentials(params CallCredentials[] credentials) |
||||||
|
{ |
||||||
|
Preconditions.CheckArgument(credentials.Length >= 2, "Composite credentials object can only be created from 2 or more credentials."); |
||||||
|
this.credentials = new List<CallCredentials>(credentials); |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return ToNativeRecursive(0); |
||||||
|
} |
||||||
|
|
||||||
|
// Recursive descent makes managing lifetime of intermediate CredentialSafeHandle instances easier. |
||||||
|
// In practice, we won't usually see composites from more than two credentials anyway. |
||||||
|
private CredentialsSafeHandle ToNativeRecursive(int startIndex) |
||||||
|
{ |
||||||
|
if (startIndex == credentials.Count - 1) |
||||||
|
{ |
||||||
|
return credentials[startIndex].ToNativeCredentials(); |
||||||
|
} |
||||||
|
|
||||||
|
using (var cred1 = credentials[startIndex].ToNativeCredentials()) |
||||||
|
using (var cred2 = ToNativeRecursive(startIndex + 1)) |
||||||
|
{ |
||||||
|
var nativeComposite = CredentialsSafeHandle.CreateComposite(cred1, cred2); |
||||||
|
if (nativeComposite.IsInvalid) |
||||||
|
{ |
||||||
|
throw new ArgumentException("Error creating native composite credentials. Likely, this is because you are trying to compose incompatible credentials."); |
||||||
|
} |
||||||
|
return nativeComposite; |
||||||
|
} |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,238 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Collections.Generic; |
||||||
|
using System.Threading.Tasks; |
||||||
|
|
||||||
|
using Grpc.Core.Internal; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
|
||||||
|
namespace Grpc.Core |
||||||
|
{ |
||||||
|
/// <summary> |
||||||
|
/// Client-side channel credentials. Used for creation of a secure channel. |
||||||
|
/// </summary> |
||||||
|
public abstract class ChannelCredentials |
||||||
|
{ |
||||||
|
static readonly ChannelCredentials InsecureInstance = new InsecureCredentialsImpl(); |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Returns instance of credentials that provides no security and |
||||||
|
/// will result in creating an unsecure channel with no encryption whatsoever. |
||||||
|
/// </summary> |
||||||
|
public static ChannelCredentials Insecure |
||||||
|
{ |
||||||
|
get |
||||||
|
{ |
||||||
|
return InsecureInstance; |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates a new instance of <c>ChannelCredentials</c> class by composing |
||||||
|
/// given channel credentials with call credentials. |
||||||
|
/// </summary> |
||||||
|
/// <param name="channelCredentials">Channel credentials.</param> |
||||||
|
/// <param name="callCredentials">Call credentials.</param> |
||||||
|
/// <returns>The new composite <c>ChannelCredentials</c></returns> |
||||||
|
public static ChannelCredentials Create(ChannelCredentials channelCredentials, CallCredentials callCredentials) |
||||||
|
{ |
||||||
|
return new CompositeChannelCredentials(channelCredentials, callCredentials); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates a new instance of <c>ChannelCredentials</c> by wrapping |
||||||
|
/// an instance of <c>CallCredentials</c>. |
||||||
|
/// </summary> |
||||||
|
/// <param name="callCredentials">Call credentials.</param> |
||||||
|
/// <returns>The <c>ChannelCredentials</c> wrapping given call credentials.</returns> |
||||||
|
public static ChannelCredentials Create(CallCredentials callCredentials) |
||||||
|
{ |
||||||
|
return new WrappedCallCredentials(callCredentials); |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates native object for the credentials. May return null if insecure channel |
||||||
|
/// should be created. |
||||||
|
/// </summary> |
||||||
|
/// <returns>The native credentials.</returns> |
||||||
|
internal abstract CredentialsSafeHandle ToNativeCredentials(); |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Returns <c>true</c> if this credential type allows being composed by <c>CompositeCredentials</c>. |
||||||
|
/// </summary> |
||||||
|
internal virtual bool IsComposable |
||||||
|
{ |
||||||
|
get { return false; } |
||||||
|
} |
||||||
|
|
||||||
|
private sealed class InsecureCredentialsImpl : ChannelCredentials |
||||||
|
{ |
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return null; |
||||||
|
} |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Client-side SSL credentials. |
||||||
|
/// </summary> |
||||||
|
public sealed class SslCredentials : ChannelCredentials |
||||||
|
{ |
||||||
|
readonly string rootCertificates; |
||||||
|
readonly KeyCertificatePair keyCertificatePair; |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates client-side SSL credentials loaded from |
||||||
|
/// disk file pointed to by the GRPC_DEFAULT_SSL_ROOTS_FILE_PATH environment variable. |
||||||
|
/// If that fails, gets the roots certificates from a well known place on disk. |
||||||
|
/// </summary> |
||||||
|
public SslCredentials() : this(null, null) |
||||||
|
{ |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates client-side SSL credentials from |
||||||
|
/// a string containing PEM encoded root certificates. |
||||||
|
/// </summary> |
||||||
|
public SslCredentials(string rootCertificates) : this(rootCertificates, null) |
||||||
|
{ |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Creates client-side SSL credentials. |
||||||
|
/// </summary> |
||||||
|
/// <param name="rootCertificates">string containing PEM encoded server root certificates.</param> |
||||||
|
/// <param name="keyCertificatePair">a key certificate pair.</param> |
||||||
|
public SslCredentials(string rootCertificates, KeyCertificatePair keyCertificatePair) |
||||||
|
{ |
||||||
|
this.rootCertificates = rootCertificates; |
||||||
|
this.keyCertificatePair = keyCertificatePair; |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// PEM encoding of the server root certificates. |
||||||
|
/// </summary> |
||||||
|
public string RootCertificates |
||||||
|
{ |
||||||
|
get |
||||||
|
{ |
||||||
|
return this.rootCertificates; |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Client side key and certificate pair. |
||||||
|
/// If null, client will not use key and certificate pair. |
||||||
|
/// </summary> |
||||||
|
public KeyCertificatePair KeyCertificatePair |
||||||
|
{ |
||||||
|
get |
||||||
|
{ |
||||||
|
return this.keyCertificatePair; |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
// Composing composite makes no sense. |
||||||
|
internal override bool IsComposable |
||||||
|
{ |
||||||
|
get { return true; } |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return CredentialsSafeHandle.CreateSslCredentials(rootCertificates, keyCertificatePair); |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Credentials that allow composing one <see cref="ChannelCredentials"/> object and |
||||||
|
/// one or more <see cref="CallCredentials"/> objects into a single <see cref="ChannelCredentials"/>. |
||||||
|
/// </summary> |
||||||
|
internal sealed class CompositeChannelCredentials : ChannelCredentials |
||||||
|
{ |
||||||
|
readonly ChannelCredentials channelCredentials; |
||||||
|
readonly CallCredentials callCredentials; |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Initializes a new instance of <c>CompositeChannelCredentials</c> class. |
||||||
|
/// The resulting credentials object will be composite of all the credentials specified as parameters. |
||||||
|
/// </summary> |
||||||
|
/// <param name="channelCredentials">channelCredentials to compose</param> |
||||||
|
/// <param name="callCredentials">channelCredentials to compose</param> |
||||||
|
public CompositeChannelCredentials(ChannelCredentials channelCredentials, CallCredentials callCredentials) |
||||||
|
{ |
||||||
|
this.channelCredentials = Preconditions.CheckNotNull(channelCredentials); |
||||||
|
this.callCredentials = Preconditions.CheckNotNull(callCredentials); |
||||||
|
Preconditions.CheckArgument(channelCredentials.IsComposable, "Supplied channel credentials do not allow composition."); |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
using (var cred1 = channelCredentials.ToNativeCredentials()) |
||||||
|
using (var cred2 = callCredentials.ToNativeCredentials()) |
||||||
|
{ |
||||||
|
var nativeComposite = CredentialsSafeHandle.CreateComposite(cred1, cred2); |
||||||
|
if (nativeComposite.IsInvalid) |
||||||
|
{ |
||||||
|
throw new ArgumentException("Error creating native composite credentials. Likely, this is because you are trying to compose incompatible credentials."); |
||||||
|
} |
||||||
|
return nativeComposite; |
||||||
|
} |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Credentials wrapping <see cref="CallCredentials"/> as <see cref="ChannelCredentials"/>. |
||||||
|
/// </summary> |
||||||
|
internal sealed class WrappedCallCredentials : ChannelCredentials |
||||||
|
{ |
||||||
|
readonly CallCredentials callCredentials; |
||||||
|
|
||||||
|
/// <summary> |
||||||
|
/// Wraps instance of <c>CallCredentials</c> as <c>ChannelCredentials</c>. |
||||||
|
/// </summary> |
||||||
|
/// <param name="callCredentials">credentials to wrap</param> |
||||||
|
public WrappedCallCredentials(CallCredentials callCredentials) |
||||||
|
{ |
||||||
|
this.callCredentials = Preconditions.CheckNotNull(callCredentials); |
||||||
|
} |
||||||
|
|
||||||
|
internal override CredentialsSafeHandle ToNativeCredentials() |
||||||
|
{ |
||||||
|
return callCredentials.ToNativeCredentials(); |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -1,138 +0,0 @@ |
|||||||
#region Copyright notice and license |
|
||||||
|
|
||||||
// Copyright 2015, Google Inc. |
|
||||||
// All rights reserved. |
|
||||||
// |
|
||||||
// Redistribution and use in source and binary forms, with or without |
|
||||||
// modification, are permitted provided that the following conditions are |
|
||||||
// met: |
|
||||||
// |
|
||||||
// * Redistributions of source code must retain the above copyright |
|
||||||
// notice, this list of conditions and the following disclaimer. |
|
||||||
// * Redistributions in binary form must reproduce the above |
|
||||||
// copyright notice, this list of conditions and the following disclaimer |
|
||||||
// in the documentation and/or other materials provided with the |
|
||||||
// distribution. |
|
||||||
// * Neither the name of Google Inc. nor the names of its |
|
||||||
// contributors may be used to endorse or promote products derived from |
|
||||||
// this software without specific prior written permission. |
|
||||||
// |
|
||||||
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
|
||||||
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
|
||||||
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
|
||||||
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
|
||||||
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
|
||||||
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
|
||||||
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
|
||||||
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
|
||||||
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
|
||||||
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
|
||||||
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
|
||||||
|
|
||||||
#endregion |
|
||||||
|
|
||||||
using System; |
|
||||||
using Grpc.Core.Internal; |
|
||||||
|
|
||||||
namespace Grpc.Core |
|
||||||
{ |
|
||||||
/// <summary> |
|
||||||
/// Client-side credentials. Used for creation of a secure channel. |
|
||||||
/// </summary> |
|
||||||
public abstract class Credentials |
|
||||||
{ |
|
||||||
static readonly Credentials InsecureInstance = new InsecureCredentialsImpl(); |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Returns instance of credential that provides no security and |
|
||||||
/// will result in creating an unsecure channel with no encryption whatsoever. |
|
||||||
/// </summary> |
|
||||||
public static Credentials Insecure |
|
||||||
{ |
|
||||||
get |
|
||||||
{ |
|
||||||
return InsecureInstance; |
|
||||||
} |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Creates native object for the credentials. May return null if insecure channel |
|
||||||
/// should be created. |
|
||||||
/// </summary> |
|
||||||
/// <returns>The native credentials.</returns> |
|
||||||
internal abstract CredentialsSafeHandle ToNativeCredentials(); |
|
||||||
|
|
||||||
private sealed class InsecureCredentialsImpl : Credentials |
|
||||||
{ |
|
||||||
internal override CredentialsSafeHandle ToNativeCredentials() |
|
||||||
{ |
|
||||||
return null; |
|
||||||
} |
|
||||||
} |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Client-side SSL credentials. |
|
||||||
/// </summary> |
|
||||||
public sealed class SslCredentials : Credentials |
|
||||||
{ |
|
||||||
readonly string rootCertificates; |
|
||||||
readonly KeyCertificatePair keyCertificatePair; |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Creates client-side SSL credentials loaded from |
|
||||||
/// disk file pointed to by the GRPC_DEFAULT_SSL_ROOTS_FILE_PATH environment variable. |
|
||||||
/// If that fails, gets the roots certificates from a well known place on disk. |
|
||||||
/// </summary> |
|
||||||
public SslCredentials() : this(null, null) |
|
||||||
{ |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Creates client-side SSL credentials from |
|
||||||
/// a string containing PEM encoded root certificates. |
|
||||||
/// </summary> |
|
||||||
public SslCredentials(string rootCertificates) : this(rootCertificates, null) |
|
||||||
{ |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Creates client-side SSL credentials. |
|
||||||
/// </summary> |
|
||||||
/// <param name="rootCertificates">string containing PEM encoded server root certificates.</param> |
|
||||||
/// <param name="keyCertificatePair">a key certificate pair.</param> |
|
||||||
public SslCredentials(string rootCertificates, KeyCertificatePair keyCertificatePair) |
|
||||||
{ |
|
||||||
this.rootCertificates = rootCertificates; |
|
||||||
this.keyCertificatePair = keyCertificatePair; |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// PEM encoding of the server root certificates. |
|
||||||
/// </summary> |
|
||||||
public string RootCertificates |
|
||||||
{ |
|
||||||
get |
|
||||||
{ |
|
||||||
return this.rootCertificates; |
|
||||||
} |
|
||||||
} |
|
||||||
|
|
||||||
/// <summary> |
|
||||||
/// Client side key and certificate pair. |
|
||||||
/// If null, client will not use key and certificate pair. |
|
||||||
/// </summary> |
|
||||||
public KeyCertificatePair KeyCertificatePair |
|
||||||
{ |
|
||||||
get |
|
||||||
{ |
|
||||||
return this.keyCertificatePair; |
|
||||||
} |
|
||||||
} |
|
||||||
|
|
||||||
internal override CredentialsSafeHandle ToNativeCredentials() |
|
||||||
{ |
|
||||||
return CredentialsSafeHandle.CreateSslCredentials(rootCertificates, keyCertificatePair); |
|
||||||
} |
|
||||||
} |
|
||||||
} |
|
@ -0,0 +1,112 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
#endregion |
||||||
|
using System; |
||||||
|
using System.Runtime.InteropServices; |
||||||
|
using System.Threading; |
||||||
|
using System.Threading.Tasks; |
||||||
|
|
||||||
|
using Grpc.Core.Logging; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
|
||||||
|
namespace Grpc.Core.Internal |
||||||
|
{ |
||||||
|
internal delegate void NativeMetadataInterceptor(IntPtr statePtr, IntPtr serviceUrlPtr, IntPtr callbackPtr, IntPtr userDataPtr, bool isDestroy); |
||||||
|
|
||||||
|
internal class NativeMetadataCredentialsPlugin |
||||||
|
{ |
||||||
|
const string GetMetadataExceptionMsg = "Exception occured in metadata credentials plugin."; |
||||||
|
static readonly ILogger Logger = GrpcEnvironment.Logger.ForType<NativeMetadataCredentialsPlugin>(); |
||||||
|
|
||||||
|
[DllImport("grpc_csharp_ext.dll")] |
||||||
|
static extern CredentialsSafeHandle grpcsharp_metadata_credentials_create_from_plugin(NativeMetadataInterceptor interceptor); |
||||||
|
|
||||||
|
[DllImport("grpc_csharp_ext.dll", CharSet = CharSet.Ansi)] |
||||||
|
static extern void grpcsharp_metadata_credentials_notify_from_plugin(IntPtr callbackPtr, IntPtr userData, MetadataArraySafeHandle metadataArray, StatusCode statusCode, string errorDetails); |
||||||
|
|
||||||
|
AsyncAuthInterceptor interceptor; |
||||||
|
GCHandle gcHandle; |
||||||
|
NativeMetadataInterceptor nativeInterceptor; |
||||||
|
CredentialsSafeHandle credentials; |
||||||
|
|
||||||
|
public NativeMetadataCredentialsPlugin(AsyncAuthInterceptor interceptor) |
||||||
|
{ |
||||||
|
this.interceptor = Preconditions.CheckNotNull(interceptor, "interceptor"); |
||||||
|
this.nativeInterceptor = NativeMetadataInterceptorHandler; |
||||||
|
|
||||||
|
// Make sure the callback doesn't get garbage collected until it is destroyed. |
||||||
|
this.gcHandle = GCHandle.Alloc(this.nativeInterceptor, GCHandleType.Normal); |
||||||
|
this.credentials = grpcsharp_metadata_credentials_create_from_plugin(nativeInterceptor); |
||||||
|
} |
||||||
|
|
||||||
|
public CredentialsSafeHandle Credentials |
||||||
|
{ |
||||||
|
get { return credentials; } |
||||||
|
} |
||||||
|
|
||||||
|
private void NativeMetadataInterceptorHandler(IntPtr statePtr, IntPtr serviceUrlPtr, IntPtr callbackPtr, IntPtr userDataPtr, bool isDestroy) |
||||||
|
{ |
||||||
|
if (isDestroy) |
||||||
|
{ |
||||||
|
gcHandle.Free(); |
||||||
|
return; |
||||||
|
} |
||||||
|
|
||||||
|
try |
||||||
|
{ |
||||||
|
string serviceUrl = Marshal.PtrToStringAnsi(serviceUrlPtr); |
||||||
|
StartGetMetadata(serviceUrl, callbackPtr, userDataPtr); |
||||||
|
} |
||||||
|
catch (Exception e) |
||||||
|
{ |
||||||
|
grpcsharp_metadata_credentials_notify_from_plugin(callbackPtr, userDataPtr, null, StatusCode.Unknown, GetMetadataExceptionMsg); |
||||||
|
Logger.Error(e, GetMetadataExceptionMsg); |
||||||
|
} |
||||||
|
} |
||||||
|
|
||||||
|
private async void StartGetMetadata(string serviceUrl, IntPtr callbackPtr, IntPtr userDataPtr) |
||||||
|
{ |
||||||
|
try |
||||||
|
{ |
||||||
|
var metadata = new Metadata(); |
||||||
|
await interceptor(serviceUrl, metadata); |
||||||
|
using (var metadataArray = MetadataArraySafeHandle.Create(metadata)) |
||||||
|
{ |
||||||
|
grpcsharp_metadata_credentials_notify_from_plugin(callbackPtr, userDataPtr, metadataArray, StatusCode.OK, null); |
||||||
|
} |
||||||
|
} |
||||||
|
catch (Exception e) |
||||||
|
{ |
||||||
|
grpcsharp_metadata_credentials_notify_from_plugin(callbackPtr, userDataPtr, null, StatusCode.Unknown, GetMetadataExceptionMsg); |
||||||
|
Logger.Error(e, GetMetadataExceptionMsg); |
||||||
|
} |
||||||
|
} |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,97 @@ |
|||||||
|
#region Copyright notice and license |
||||||
|
|
||||||
|
// Copyright 2015, Google Inc. |
||||||
|
// All rights reserved. |
||||||
|
// |
||||||
|
// Redistribution and use in source and binary forms, with or without |
||||||
|
// modification, are permitted provided that the following conditions are |
||||||
|
// met: |
||||||
|
// |
||||||
|
// * Redistributions of source code must retain the above copyright |
||||||
|
// notice, this list of conditions and the following disclaimer. |
||||||
|
// * Redistributions in binary form must reproduce the above |
||||||
|
// copyright notice, this list of conditions and the following disclaimer |
||||||
|
// in the documentation and/or other materials provided with the |
||||||
|
// distribution. |
||||||
|
// * Neither the name of Google Inc. nor the names of its |
||||||
|
// contributors may be used to endorse or promote products derived from |
||||||
|
// this software without specific prior written permission. |
||||||
|
// |
||||||
|
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
||||||
|
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
||||||
|
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
||||||
|
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
||||||
|
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
||||||
|
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
||||||
|
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
||||||
|
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
||||||
|
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
|
||||||
|
#endregion |
||||||
|
|
||||||
|
using System; |
||||||
|
using System.Collections.Generic; |
||||||
|
using System.IO; |
||||||
|
using System.Linq; |
||||||
|
using System.Threading; |
||||||
|
using System.Threading.Tasks; |
||||||
|
using Grpc.Core; |
||||||
|
using Grpc.Core.Utils; |
||||||
|
using Grpc.Testing; |
||||||
|
using NUnit.Framework; |
||||||
|
|
||||||
|
namespace Grpc.IntegrationTesting |
||||||
|
{ |
||||||
|
public class MetadataCredentialsTest |
||||||
|
{ |
||||||
|
const string Host = "localhost"; |
||||||
|
Server server; |
||||||
|
Channel channel; |
||||||
|
TestService.ITestServiceClient client; |
||||||
|
|
||||||
|
[TestFixtureSetUp] |
||||||
|
public void Init() |
||||||
|
{ |
||||||
|
var serverCredentials = new SslServerCredentials(new[] { new KeyCertificatePair(File.ReadAllText(TestCredentials.ServerCertChainPath), File.ReadAllText(TestCredentials.ServerPrivateKeyPath)) }); |
||||||
|
server = new Server |
||||||
|
{ |
||||||
|
Services = { TestService.BindService(new TestServiceImpl()) }, |
||||||
|
Ports = { { Host, ServerPort.PickUnused, serverCredentials } } |
||||||
|
}; |
||||||
|
server.Start(); |
||||||
|
|
||||||
|
var options = new List<ChannelOption> |
||||||
|
{ |
||||||
|
new ChannelOption(ChannelOptions.SslTargetNameOverride, TestCredentials.DefaultHostOverride) |
||||||
|
}; |
||||||
|
|
||||||
|
var asyncAuthInterceptor = new AsyncAuthInterceptor(async (authUri, metadata) => |
||||||
|
{ |
||||||
|
await Task.Delay(100); // make sure the operation is asynchronous. |
||||||
|
metadata.Add("authorization", "SECRET_TOKEN"); |
||||||
|
}); |
||||||
|
|
||||||
|
var clientCredentials = ChannelCredentials.Create( |
||||||
|
new SslCredentials(File.ReadAllText(TestCredentials.ClientCertAuthorityPath)), |
||||||
|
new MetadataCredentials(asyncAuthInterceptor)); |
||||||
|
channel = new Channel(Host, server.Ports.Single().BoundPort, clientCredentials, options); |
||||||
|
client = TestService.NewClient(channel); |
||||||
|
} |
||||||
|
|
||||||
|
[TestFixtureTearDown] |
||||||
|
public void Cleanup() |
||||||
|
{ |
||||||
|
channel.ShutdownAsync().Wait(); |
||||||
|
server.ShutdownAsync().Wait(); |
||||||
|
} |
||||||
|
|
||||||
|
[Test] |
||||||
|
public void MetadataCredentials() |
||||||
|
{ |
||||||
|
var response = client.UnaryCall(new SimpleRequest { ResponseSize = 10 }); |
||||||
|
Assert.AreEqual(10, response.Payload.Body.Length); |
||||||
|
} |
||||||
|
} |
||||||
|
} |
Loading…
Reference in new issue