51 feature support tls connections to crowdsec not signed by a public ca (#53)

*  Add support for insecure tls connections to LAPI

* 📝 Add documentation for the TLS insecure parameter

* 🚧 Add tls authority certificate and checks for params

* 📝 Add example for tls communication in readme and folder

* 📝 Update documentation and example for tls

* 🚨 Fix easy lint errors

* 🦺 logic to fetch certificates

* 🚨 Fix lint on readme

* ♻️ Refactor validate to fix lint and clean

* 🚧 Add doc, cert gen for crowdsec example

* 🚧 Progress on setting up Crowdsec with tls

* 🚧 Update certs validation for example

* ♻️ Add load variable from file or value and get client cert

* ♻️ Refactor getting variables

* 🚨 Fix lint, no new line on new files

* 🐛 Fix bug on condition check lapi key cert

* ♻️ Update after review

* ♻️ Update after review

* 🍱 fix mathieu code

* ♻️ Refactor logic of loading tls certificates

* 🍱 clean code

* 🍱 last fix

* 🍱 fix lint

* ♻️ Add documentation in readme, fix lint, remove unfinished tests

* 🐛 Fix conditions logics

* 🚨 Fix Lint

* ♻️ simplify code on getVariable

Co-authored-by: Max Lerebourg <maxlerebourg@gmail.com>
This commit is contained in:
mathieuHa
2022-11-30 17:54:49 +01:00
committed by GitHub
co-authored by Max Lerebourg
parent b2ed600d5e
commit a2fe60c621
19 changed files with 817 additions and 68 deletions
+64 -2
View File
@@ -7,7 +7,70 @@ import (
"testing"
)
func TestCrowdSec(t *testing.T) {
func TestCreation(t *testing.T) {
cfg := CreateConfig()
cfg.CrowdsecLapiKey = "test"
ctx := context.Background()
next := http.HandlerFunc(func(rw http.ResponseWriter, req *http.Request) {})
handler, err := New(ctx, next, cfg, "demo-plugin")
if err != nil {
t.Fatal(err)
}
recorder := httptest.NewRecorder()
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "http://localhost", nil)
if err != nil {
t.Fatal(err)
}
handler.ServeHTTP(recorder, req)
}
// func TestValidateParamsCrowdsecLapiKey(t *testing.T) {
// cfg := CreateConfig()
// err := validateParams(cfg)
// fmt.Println(err.Error())
// if err == nil {
// t.Errorf("Need error here %s", err.Error())
// }
// }
// func TestValidateParamsCrowdsecLapiScheme(t *testing.T) {
// cfg := CreateConfig()
// cfg.CrowdsecLapiKey = "test"
// cfg.CrowdsecLapiScheme = "bad"
// err := validateParams(cfg)
// fmt.Println(err.Error())
// if err == nil {
// t.Errorf("Need error here %s", err.Error())
// }
// }
// func TestValidateParamsCrowdsecMode(t *testing.T) {
// cfg := CreateConfig()
// cfg.CrowdsecLapiKey = "test"
// cfg.CrowdsecMode = "bad"
// err := validateParams(cfg)
// fmt.Println(err.Error())
// if err == nil {
// t.Errorf("Need error here %s", err.Error())
// }
// }
// func TestValidateParamsUpdateIntervalSeconds(t *testing.T) {
// cfg := CreateConfig()
// cfg.CrowdsecLapiKey = "test"
// cfg.UpdateIntervalSeconds = 0
// err := validateParams(cfg)
// fmt.Println(err.Error())
// if err == nil {
// t.Errorf("Need error here %s", err.Error())
// }
// }
func TestServeHTTP(t *testing.T) {
cfg := CreateConfig()
cfg.CrowdsecLapiKey = "test"
@@ -20,7 +83,6 @@ func TestCrowdSec(t *testing.T) {
}
recorder := httptest.NewRecorder()
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "http://localhost", nil)
if err != nil {
t.Fatal(err)