efcdaa43a3
* lib/uplink: encryption context Change-Id: I5c23dca3286a46b713b30c4997e9ae6e630b2280 * lib/uplink: bucket operation examples Change-Id: Ia0f6e69f365dcff0cf11c731f51b30842bce053b * lib/uplink: encryption key sharing test cases Change-Id: I3a172d565f33f4e591402cdcb9460664a7cc7fbe * fix encrypted path prefix restriction issue Change-Id: I8f3921f9d52aaf4b84039de608b8cbbc88769554 * implement panics in libuplink encryption code todo on cipher suite selection as well as an api concern Change-Id: Ifa39eb3cc4b3443f7d96f9304df9b2ac4ec4085d * implement GetProjectInfo api call to get salt Change-Id: Ic5f6b3be9ea35df48c1aa214ab5d355fb328e2cf * some fixes and accessors for encryption store Change-Id: I3bb61f6712a037900e2a96e72ad4029ec1d3f718 * general fixes to builds/tests/etc Change-Id: I9930fa96acb3b221d9a001f8e274af5729cc8a47 * java bindings changes Change-Id: Ia2bd4c9c69739c8d3154d79616cff1f36fb403b6 * get libuplink examples passing Change-Id: I828f09a144160e0a5dd932324f78491ae2ec8a07 * fix proto.lock file Change-Id: I2fbbf4d0976a7d0473c2645e6dcb21aaa3be7651 * fix proto.lock again Change-Id: I92702cf49e1a340eef6379c2be4f7c4a268112a9 * fix golint issues Change-Id: I631ff9f43307a58e3b25a58cbb4a4cc2495f5eb6 * more linting fixes Change-Id: I51f8f30b367b5bca14c94b15417b9a4c9e7aa0ce * bug fixed by structs bump Change-Id: Ibb03c691fce7606c35c08721b3ef0781ab48a38a * retrigger Change-Id: Ieee0470b6a2d07168a1578552e8e7f271ae93a13 * retrigger Change-Id: I753d63853171e6a436c104ce176048892eb974c5 * semantic merge conflict Change-Id: I9419448496de90340569047a6a16a1b858a7978a * update total to match prod defaults Change-Id: I693d55c1ebb28b5803ee1d26e9e198decf82308b * retrigger Change-Id: I28b74d5d6202f61aa3866fe407d423f6a0a14b9e * retrigger Change-Id: I6fd054885c715f602e2cef623fd464c42e88742c * retrigger Change-Id: I6a01bae88c72406d4ed5a8f13bf8a2b3c650bd2d
162 lines
3.9 KiB
Go
162 lines
3.9 KiB
Go
// Copyright (C) 2019 Storj Labs, Inc.
|
|
// See LICENSE for copying information.
|
|
|
|
package uplink_test
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"io"
|
|
"io/ioutil"
|
|
"os"
|
|
"strings"
|
|
|
|
"github.com/zeebo/errs"
|
|
|
|
"storj.io/storj/lib/uplink"
|
|
)
|
|
|
|
func CreateEncryptionKeyExampleByAdmin1(ctx context.Context, satelliteAddress, apiKey string, cfg *uplink.Config, out io.Writer) (serializedEncCtx string, err error) {
|
|
errCatch := func(fn func() error) { err = errs.Combine(err, fn()) }
|
|
|
|
// First, create an Uplink handle.
|
|
ul, err := uplink.NewUplink(ctx, cfg)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
defer errCatch(ul.Close)
|
|
|
|
// Parse the API key. API keys are "macaroons" that allow you to create new, restricted API keys.
|
|
key, err := uplink.ParseAPIKey(apiKey)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
// Open the project in question. Projects are identified by a specific Satellite and API key
|
|
p, err := ul.OpenProject(ctx, satelliteAddress, key)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
defer errCatch(p.Close)
|
|
|
|
// Make a key
|
|
encKey, err := p.SaltedKeyFromPassphrase(ctx, "my secret passphrase")
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
// Make an encryption context
|
|
encCtx := uplink.NewEncryptionCtxWithDefaultKey(*encKey)
|
|
// serialize it
|
|
serializedEncCtx, err = encCtx.Serialize()
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
// Create a bucket
|
|
_, err = p.CreateBucket(ctx, "prod", nil)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
// Open bucket
|
|
bucket, err := p.OpenBucket(ctx, "prod", encCtx)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
defer errCatch(bucket.Close)
|
|
|
|
// Upload a file
|
|
err = bucket.UploadObject(ctx, "webserver/logs/log.txt", strings.NewReader("hello world"), nil)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
|
|
fmt.Fprintln(out, "success!")
|
|
return serializedEncCtx, nil
|
|
}
|
|
|
|
func CreateEncryptionKeyExampleByAdmin2(ctx context.Context, satelliteAddress, apiKey string, serializedEncCtx string, cfg *uplink.Config, out io.Writer) (err error) {
|
|
errCatch := func(fn func() error) { err = errs.Combine(err, fn()) }
|
|
|
|
// First, create an Uplink handle.
|
|
ul, err := uplink.NewUplink(ctx, cfg)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer errCatch(ul.Close)
|
|
|
|
// Parse the API key. API keys are "macaroons" that allow you to create new, restricted API keys.
|
|
key, err := uplink.ParseAPIKey(apiKey)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Open the project in question. Projects are identified by a specific Satellite and API key
|
|
p, err := ul.OpenProject(ctx, satelliteAddress, key)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer errCatch(p.Close)
|
|
|
|
// Parse the encryption context
|
|
encCtx, err := uplink.ParseEncryptionCtx(serializedEncCtx)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Open bucket
|
|
bucket, err := p.OpenBucket(ctx, "prod", encCtx)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer errCatch(bucket.Close)
|
|
|
|
// Open file
|
|
obj, err := bucket.OpenObject(ctx, "webserver/logs/log.txt")
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer errCatch(obj.Close)
|
|
|
|
// Get a reader for the entire file
|
|
r, err := obj.DownloadRange(ctx, 0, -1)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer errCatch(r.Close)
|
|
|
|
// Read the file
|
|
data, err := ioutil.ReadAll(r)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Print it!
|
|
fmt.Fprintln(out, string(data))
|
|
return nil
|
|
}
|
|
|
|
func Example_createEncryptionKey() {
|
|
// The satellite address is the address of the satellite your API key is valid on
|
|
satelliteAddress := "us-central-1.tardigrade.io:7777"
|
|
|
|
// The API key can be created in the web interface
|
|
admin1APIKey := "qPSUM3k0bZyOIyil2xrVWiSuc9HuB2yBP3qDrA2Gc"
|
|
admin2APIKey := "udP0lzCC2rgwRZfdY70PcwWrXzrq9cl5usbiFaeyo"
|
|
|
|
ctx := context.Background()
|
|
|
|
// Admin1 is going to create an encryption context and share it
|
|
encCtx, err := CreateEncryptionKeyExampleByAdmin1(ctx, satelliteAddress, admin1APIKey, &uplink.Config{}, os.Stdout)
|
|
if err != nil {
|
|
panic(err)
|
|
}
|
|
|
|
// Admin2 is going to use the provided encryption context to load the uploaded file
|
|
err = CreateEncryptionKeyExampleByAdmin2(ctx, satelliteAddress, admin2APIKey, encCtx, &uplink.Config{}, os.Stdout)
|
|
if err != nil {
|
|
panic(err)
|
|
}
|
|
}
|