OmniSciDB  1dac507f6e
 All Classes Namespaces Files Functions Variables Typedefs Enumerations Enumerator Friends Macros Pages
ThriftClient.cpp
Go to the documentation of this file.
1 /*
2  * Copyright 2018, OmniSci, Inc.
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  * http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 #include "Shared/ThriftClient.h"
17 #include <boost/algorithm/string.hpp>
18 #include <boost/core/ignore_unused.hpp>
19 #include <boost/filesystem.hpp>
20 #include <iostream>
21 #include <sstream>
22 using namespace ::apache::thrift::transport;
24 
25 class InsecureAccessManager : public AccessManager {
26  public:
27  Decision verify(const sockaddr_storage& sa) throw() override {
28  boost::ignore_unused(sa);
29  return ALLOW;
30  };
31  Decision verify(const std::string& host, const char* name, int size) throw() override {
32  boost::ignore_unused(host);
33  boost::ignore_unused(name);
34  boost::ignore_unused(size);
35  return ALLOW;
36  };
37  Decision verify(const sockaddr_storage& sa,
38  const char* data,
39  int size) throw() override {
40  boost::ignore_unused(sa);
41  boost::ignore_unused(data);
42  boost::ignore_unused(size);
43  return ALLOW;
44  };
45 };
46 
47 /*
48  * The Http client that comes with Thrift constructs a very simple set of HTTP
49  * headers, ignoring cookies. This class simply inherits from THttpClient to
50  * override the two methods - parseHeader (where it collects any cookies) and
51  * flush where it inserts the cookies into the http header.
52  *
53  * The methods that are over ridden here are virtual in the parent class, as is
54  * the parents class's destructor.
55  *
56  */
57 class ProxyTHttpClient : public THttpClient {
58  public:
59  // mimic and call the super constructors.
60  ProxyTHttpClient(mapd::shared_ptr<TTransport> transport,
61  std::string host,
62  std::string path)
63  : THttpClient(transport, host, path) {}
64 
65  ProxyTHttpClient(std::string host, int port, std::string path)
66  : THttpClient(host, port, path) {}
67 
68  ~ProxyTHttpClient() override {}
69  // thrift parseHeader d and call the super constructor.
70  void parseHeader(char* header) override {
71  // note boost::istarts_with is case insensitive
72  if (boost::istarts_with(header, "set-cookie:")) {
73  std::string tmp(header);
74  std::string cookie = tmp.substr(tmp.find(":") + 1, std::string::npos);
75  cookies_.push_back(cookie);
76  }
77  THttpClient::parseHeader(header);
78  }
79 
80  void flush() override {
81  /*
82  * Unfortunately the decision to write the header and the body in the same
83  * method precludes using the parent class's flush method here; in what is
84  * effectively a copy of 'flush' in THttpClient with the addition of
85  * cookies, a better error report for a header that is too large and
86  * 'Connection: keep-alive'.
87  */
88  uint8_t* buf;
89  uint32_t len;
90  writeBuffer_.getBuffer(&buf, &len);
91 
92  std::ostringstream h;
93  h << "POST " << path_ << " HTTP/1.1" << THttpClient::CRLF << "Host: " << host_
94  << THttpClient::CRLF << "Content-Type: application/x-thrift" << THttpClient::CRLF
95  << "Content-Length: " << len << THttpClient::CRLF << "Accept: application/x-thrift"
96  << THttpClient::CRLF << "User-Agent: Thrift/" << THRIFT_PACKAGE_VERSION
97  << " (C++/THttpClient)" << THttpClient::CRLF << "Connection: keep-alive"
98  << THttpClient::CRLF;
99  if (!cookies_.empty()) {
100  std::string cookie = "Cookie:" + boost::algorithm::join(cookies_, ";");
101  h << cookie << THttpClient::CRLF;
102  }
103  h << THttpClient::CRLF;
104 
105  cookies_.clear();
106  std::string header = h.str();
107  if (header.size() > (std::numeric_limits<uint32_t>::max)()) {
108  throw TTransportException(
109  "Header too big [" + std::to_string(header.size()) +
110  "]. Max = " + std::to_string((std::numeric_limits<uint32_t>::max)()));
111  }
112  // Write the header, then the data, then flush
113  transport_->write((const uint8_t*)header.c_str(),
114  static_cast<uint32_t>(header.size()));
115  transport_->write(buf, len);
116  transport_->flush();
117 
118  // Reset the buffer and header variables
119  writeBuffer_.resetBuffer();
120  readHeaders_ = true;
121  }
122 
123  std::vector<std::string> cookies_;
124 };
127  const std::string& server_host,
128  const int port,
129  const ThriftConnectionType conn_type,
130  bool skip_host_verify,
131  mapd::shared_ptr<TSSLSocketFactory> factory)
132  : server_host_(server_host)
133  , port_(port)
134  , conn_type_(conn_type)
135  , skip_host_verify_(skip_host_verify)
136  , trust_cert_file_("") {
137  if (factory && (conn_type_ == ThriftConnectionType::BINARY_SSL ||
139  using_X509_store_ = true;
140  factory_ = factory;
141  factory_->ciphers("ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH");
142  if (skip_host_verify_) {
143  factory_->access(
144  mapd::shared_ptr<InsecureAccessManager>(new InsecureAccessManager()));
145  }
146  }
147 }
148 
149 mapd::shared_ptr<TProtocol> ThriftClientConnection::get_protocol() {
150  mapd::shared_ptr<apache::thrift::transport::TTransport> mytransport;
154  port_,
158 
159  } else {
161  }
162 
163  try {
164  mytransport->open();
165  } catch (const apache::thrift::TException& e) {
166  throw apache::thrift::TException(std::string(e.what()) + ": host " + server_host_ +
167  ", port " + std::to_string(port_));
168  }
171  return mapd::shared_ptr<TProtocol>(new TJSONProtocol(mytransport));
172  } else {
173  return mapd::shared_ptr<TProtocol>(new TBinaryProtocol(mytransport));
174  }
175 }
176 
178  const std::string& server_host,
179  const int port,
180  const std::string& ca_cert_name,
181  bool with_timeout,
182  unsigned connect_timeout,
183  unsigned recv_timeout,
184  unsigned send_timeout) {
185  mapd::shared_ptr<TTransport> transport;
186 
187  if (!factory_ && !ca_cert_name.empty()) {
188  // need to build a factory once for ssl conection
189  factory_ =
190  mapd::shared_ptr<TSSLSocketFactory>(new TSSLSocketFactory(SSLProtocol::SSLTLS));
191  factory_->ciphers("ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH");
192  factory_->loadTrustedCertificates(ca_cert_name.c_str());
193  factory_->authenticate(false);
194  factory_->access(
195  mapd::shared_ptr<InsecureAccessManager>(new InsecureAccessManager()));
196  }
197  if (!using_X509_store_ && ca_cert_name.empty()) {
198  const auto socket = mapd::make_shared<TSocket>(server_host, port);
199  if (with_timeout) {
200  socket->setConnTimeout(connect_timeout);
201  socket->setRecvTimeout(recv_timeout);
202  socket->setSendTimeout(send_timeout);
203  }
204  transport = mapd::make_shared<TBufferedTransport>(socket);
205  } else {
206  mapd::shared_ptr<TSocket> secure_socket = factory_->createSocket(server_host, port);
207  if (with_timeout) {
208  secure_socket->setConnTimeout(connect_timeout);
209  secure_socket->setRecvTimeout(recv_timeout);
210  secure_socket->setSendTimeout(send_timeout);
211  }
212  transport = mapd::shared_ptr<TTransport>(new TBufferedTransport(secure_socket));
213  }
214 
215  return transport;
216 }
217 
219  const std::string& server_host,
220  const int port,
221  const std::string& trust_cert_fileX,
222  bool use_https,
223  bool skip_verify) {
224  std::string trust_cert_file{trust_cert_fileX};
225  if (trust_cert_file_.empty()) {
226  static std::list<std::string> v_known_ca_paths({
227  "/etc/ssl/certs/ca-certificates.crt",
228  "/etc/pki/tls/certs/ca-bundle.crt",
229  "/usr/share/ssl/certs/ca-bundle.crt",
230  "/usr/local/share/certs/ca-root.crt",
231  "/etc/ssl/cert.pem",
232  "/etc/ssl/ca-bundle.pem",
233  });
234  for (const auto& known_ca_path : v_known_ca_paths) {
235  if (boost::filesystem::exists(known_ca_path)) {
236  trust_cert_file = known_ca_path;
237  break;
238  }
239  }
240  }
241 
242  if (!factory_) {
243  factory_ =
244  mapd::shared_ptr<TSSLSocketFactory>(new TSSLSocketFactory(SSLProtocol::SSLTLS));
245  }
246  mapd::shared_ptr<TTransport> transport;
247  mapd::shared_ptr<TTransport> socket;
248  if (use_https) {
249  if (skip_verify) {
250  factory_->authenticate(false);
251  factory_->access(
252  mapd::shared_ptr<InsecureAccessManager>(new InsecureAccessManager()));
253  }
254  if (!using_X509_store_) {
255  factory_->loadTrustedCertificates(trust_cert_file.c_str());
256  }
257  socket = factory_->createSocket(server_host, port);
258  // transport = mapd::shared_ptr<TTransport>(new THttpClient(socket,
259  // server_host,
260  // "/"));
261  transport =
262  mapd::shared_ptr<TTransport>(new ProxyTHttpClient(socket, server_host, "/"));
263  } else {
264  transport =
265  mapd::shared_ptr<TTransport>(new ProxyTHttpClient(server_host, port, "/"));
266  }
267  return transport;
268 }
ThriftConnectionType conn_type_
Definition: ThriftClient.h:79
ThriftConnectionType
Definition: ThriftClient.h:32
ProxyTHttpClient(mapd::shared_ptr< TTransport > transport, std::string host, std::string path)
std::string join(T const &container, std::string const &delim)
mapd::shared_ptr< TTransport > open_http_client_transport(const std::string &server_host, const int port, const std::string &trust_cert_file_, bool use_https, bool skip_verify)
virtual ~ThriftClientConnection()
unsigned connect_timeout
Definition: MapDServer.cpp:70
mapd::shared_ptr< TSSLSocketFactory > factory_
Definition: ThriftClient.h:84
std::string to_string(char const *&&v)
mapd::shared_ptr< TProtocol > get_protocol()
std::vector< std::string > cookies_
mapd::shared_ptr< TTransport > open_buffered_client_transport(const std::string &server_host, const int port, const std::string &ca_cert_name, const bool with_timeout=false, const unsigned connect_timeout=0, const unsigned recv_timeount=0, const unsigned send_timeout=0)
Decision verify(const sockaddr_storage &sa) override
Decision verify(const std::string &host, const char *name, int size) override
Decision verify(const sockaddr_storage &sa, const char *data, int size) override
std::string ca_cert_name_
Definition: ThriftClient.h:81
std::string trust_cert_file_
Definition: ThriftClient.h:82
std::string server_host_
Definition: ThriftClient.h:77
unsigned send_timeout
Definition: MapDServer.cpp:72
ProxyTHttpClient(std::string host, int port, std::string path)
void flush() override
void parseHeader(char *header) override
unsigned recv_timeout
Definition: MapDServer.cpp:71
AccessManager::Decision Decision
~ProxyTHttpClient() override