mirror of
https://github.com/status-im/status-go.git
synced 2026-08-27 15:11:09 +00:00
`server` was one Go package doing three unrelated jobs. Each moves to where it belongs: server/pairing/ -> services/pairing/ server_media*.go, handlers*.go, testdata/ -> services/media/ server.go, certs.go, ips.go, timeout.go, device.go, listen_*.go, servertest/ -> internal/httpserver/ MediaServer is renamed to media.Server (and NewMediaServer to media.NewServer) now that it has a package to be named against. Deliberately untouched: StatusNode.MediaServer(), which is an accessor method rather than the type, and the unrelated identifiers that only share the prefix (MediaServerImageID, MediaServerContactIcon, MediaServerEnableTLS, ...). Two identifiers had to be reassigned to make the boundary clean: - certs.go held both the generic X509/TLS helpers and the media server's process-global certificate. Split: the generic half stays in internal/httpserver, generateMediaTLSCert and PublicMediaTLSCert move to services/media. - HandlerPatternMap was declared in handlers.go but is a plain HTTP type that server.go depends on; it moves to internal/httpserver. The media server URL tests moved with the type, and reached three unexported Server fields they could touch while everything shared a package. internal/httpserver now exposes ListeningAddr() and CachedPort() (both reasonable API) plus a clearly-marked SetURLStateForTest. Nothing else crossed the boundary, and the split is one-directional: services/media and services/pairing import internal/httpserver, never the reverse. refs #7067
83 lines
2.4 KiB
Go
83 lines
2.4 KiB
Go
package httpserver
|
|
|
|
import (
|
|
"crypto/ecdsa"
|
|
"crypto/elliptic"
|
|
"crypto/rand"
|
|
"crypto/tls"
|
|
"crypto/x509"
|
|
"crypto/x509/pkix"
|
|
"encoding/pem"
|
|
"math/big"
|
|
"net"
|
|
"time"
|
|
)
|
|
|
|
func makeRandomSerialNumber() (*big.Int, error) {
|
|
serialNumberLimit := new(big.Int).Lsh(big.NewInt(1), 128)
|
|
return rand.Int(rand.Reader, serialNumberLimit)
|
|
}
|
|
|
|
func GenerateX509Cert(sn *big.Int, from, to time.Time, IPAddresses []net.IP, DNSNames []string) *x509.Certificate {
|
|
return &x509.Certificate{
|
|
SerialNumber: sn,
|
|
Subject: pkix.Name{Organization: []string{"Self-signed cert"}},
|
|
NotBefore: from,
|
|
NotAfter: to,
|
|
KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageCertSign,
|
|
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
|
BasicConstraintsValid: true,
|
|
IsCA: true,
|
|
IPAddresses: IPAddresses,
|
|
DNSNames: DNSNames,
|
|
}
|
|
}
|
|
|
|
func GenerateX509PEMs(cert *x509.Certificate, key *ecdsa.PrivateKey) (certPem, keyPem []byte, err error) {
|
|
derBytes, err := x509.CreateCertificate(rand.Reader, cert, cert, &key.PublicKey, key)
|
|
if err != nil {
|
|
return
|
|
}
|
|
certPem = pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: derBytes})
|
|
|
|
privBytes, err := x509.MarshalPKCS8PrivateKey(key)
|
|
if err != nil {
|
|
return
|
|
}
|
|
keyPem = pem.EncodeToMemory(&pem.Block{Type: "PRIVATE KEY", Bytes: privBytes})
|
|
|
|
return
|
|
}
|
|
|
|
func GenerateTLSCert(notBefore, notAfter time.Time, IPAddresses []net.IP, DNSNames []string) (*tls.Certificate, []byte, error) {
|
|
priv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
|
if err != nil {
|
|
return nil, nil, err
|
|
}
|
|
|
|
sn, err := makeRandomSerialNumber()
|
|
if err != nil {
|
|
return nil, nil, err
|
|
}
|
|
|
|
cert := GenerateX509Cert(sn, notBefore, notAfter, IPAddresses, DNSNames)
|
|
certPem, keyPem, err := GenerateX509PEMs(cert, priv)
|
|
if err != nil {
|
|
return nil, nil, err
|
|
}
|
|
|
|
finalCert, err := tls.X509KeyPair(certPem, keyPem)
|
|
return &finalCert, certPem, err
|
|
}
|
|
|
|
// ToECDSA takes a []byte of D and uses it to create an ecdsa.PublicKey on the elliptic.P256 curve
|
|
// this function is basically a P256 curve version of eth-node/crypto.ToECDSA without all the nice validation
|
|
func ToECDSA(d []byte) *ecdsa.PrivateKey {
|
|
k := new(ecdsa.PrivateKey)
|
|
k.D = new(big.Int).SetBytes(d)
|
|
k.PublicKey.Curve = elliptic.P256()
|
|
|
|
k.PublicKey.X, k.PublicKey.Y = k.PublicKey.Curve.ScalarBaseMult(d)
|
|
return k
|
|
}
|