Files
drop/server/internal/clients/ca-store.ts
DecDuck 63ac2b8ffc Depot API & v4 (#298)
* feat: nginx + torrential basics & services system

* fix: lint + i18n

* fix: update torrential to remove openssl

* feat: add torrential to Docker build

* feat: move to self hosted runner

* fix: move off self-hosted runner

* fix: update nginx.conf

* feat: torrential cache invalidation

* fix: update torrential for cache invalidation

* feat: integrity check task

* fix: lint

* feat: move to version ids

* fix: client fixes and client-side checks

* feat: new depot apis and version id fixes

* feat: update torrential

* feat: droplet bump and remove unsafe update functions

* fix: lint

* feat: v4 featureset: emulators, multi-launch commands

* fix: lint

* fix: mobile ui for game editor

* feat: launch options

* fix: lint

* fix: remove axios, use $fetch

* feat: metadata and task api improvements

* feat: task actions

* fix: slight styling issue

* feat: fix style and lints

* feat: totp backend routes

* feat: oidc groups

* fix: update drop-base

* feat: creation of passkeys & totp

* feat: totp signin

* feat: webauthn mfa/signin

* feat: launch selecting ui

* fix: manually running tasks

* feat: update add company game modal to use new SelectorGame

* feat: executor selector

* fix(docker): update rust to rust nightly for torrential build (#305)

* feat: new version ui

* feat: move package lookup to build time to allow for deno dev

* fix: lint

* feat: localisation cleanup

* feat: apply localisation cleanup

* feat: potential i18n refactor logic

* feat: remove args from commands

* fix: lint

* fix: lockfile

---------

Co-authored-by: Aden Lindsay <140392385+AdenMGB@users.noreply.github.com>
2026-01-13 15:32:39 +11:00

99 lines
2.7 KiB
TypeScript

import path from "path";
import fs from "fs";
import type { CertificateBundle } from "./ca";
import prisma from "../db/database";
import { systemConfig } from "../config/sys-conf";
export type CertificateStore = {
store(name: string, data: CertificateBundle): Promise<void>;
fetch(name: string): Promise<CertificateBundle | undefined>;
blacklistCertificate(name: string): Promise<void>;
checkBlacklistCertificate(name: string): Promise<boolean>;
};
export const fsCertificateStore = () => {
const base = path.join(systemConfig.getDataFolder(), "certs");
const blacklist = path.join(base, ".blacklist");
fs.mkdirSync(blacklist, { recursive: true });
const store: CertificateStore = {
async store(name: string, data: CertificateBundle) {
const filepath = path.join(base, name);
fs.writeFileSync(filepath, JSON.stringify(data));
},
async fetch(name: string) {
const filepath = path.join(base, name);
if (!fs.existsSync(filepath)) return undefined;
return JSON.parse(fs.readFileSync(filepath, "utf-8"));
},
async blacklistCertificate(name: string) {
const filepath = path.join(blacklist, name);
fs.writeFileSync(filepath, Buffer.from([]));
},
async checkBlacklistCertificate(name: string): Promise<boolean> {
const filepath = path.join(blacklist, name);
return fs.existsSync(filepath);
},
};
return store;
};
export const dbCertificateStore = () => {
const store: CertificateStore = {
async store(name: string, data: CertificateBundle) {
await prisma.certificate.upsert({
where: {
id: name,
},
create: {
id: name,
privateKey: data.priv,
certificate: data.cert,
},
update: {
privateKey: data.priv,
certificate: data.cert,
},
});
},
async fetch(name: string) {
const result = await prisma.certificate.findUnique({
where: {
id: name,
},
select: {
privateKey: true,
certificate: true,
},
});
if (result === null) return undefined;
return {
priv: result.privateKey,
cert: result.certificate,
};
},
async blacklistCertificate(name: string) {
await prisma.certificate.updateMany({
where: {
id: name,
},
data: {
blacklisted: true,
},
});
},
async checkBlacklistCertificate(name: string): Promise<boolean> {
const result = await prisma.certificate.findUnique({
where: {
id: name,
},
select: {
blacklisted: true,
},
});
if (result === null) return true;
return result.blacklisted;
},
};
return store;
};