summaryrefslogtreecommitdiff
path: root/lib/chef/http/auth_credentials.rb
blob: a1542d1f9384946c14bf22751e6b1497ee98723f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
#
# Author:: Adam Jacob (<adam@chef.io>)
# Author:: Thom May (<thom@clearairturbulence.org>)
# Author:: Nuo Yan (<nuo@chef.io>)
# Author:: Christopher Brown (<cb@chef.io>)
# Author:: Christopher Walters (<cw@chef.io>)
# Author:: Daniel DeLeo (<dan@chef.io>)
# Copyright:: Copyright 2009-2016, Chef Software Inc.
# License:: Apache License, Version 2.0
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
require_relative "../log"
require "mixlib/authentication/signedheaderauth"

class Chef
  class HTTP
    class AuthCredentials
      attr_reader :client_name, :key

      def initialize(client_name = nil, key = nil, use_ssh_agent: false)
        @client_name = client_name
        @key = key
        @use_ssh_agent = use_ssh_agent
      end

      def sign_requests?
        !!key
      end

      def signature_headers(request_params = {})
        raise ArgumentError, "Cannot sign the request without a client name, check that :node_name is assigned" if client_name.nil?

        Chef::Log.trace("Signing the request as #{client_name}")

        # params_in = {:http_method => :GET, :path => "/clients", :body => "", :host => "localhost"}
        request_params                 = request_params.dup
        request_params[:timestamp]     = Time.now.utc.iso8601
        request_params[:user_id]       = client_name
        request_params[:proto_version] = Chef::Config[:authentication_protocol_version]
        host = request_params.delete(:host) || "localhost"

        sign_obj = Mixlib::Authentication::SignedHeaderAuth.signing_object(request_params)
        signed = sign_obj.sign(key, use_ssh_agent: @use_ssh_agent).merge({ host: host })
        signed.inject({}) { |memo, kv| memo[(kv[0].to_s.upcase).to_s] = kv[1]; memo }
      end

    end
  end
end