]> dgit.raspbian.org Git - nextcloud-desktop.git/commitdiff
can now generate the CSR again if the first try to upload failed
authorMatthieu Gallien <matthieu.gallien@nextcloud.com>
Thu, 20 Apr 2023 19:28:11 +0000 (21:28 +0200)
committerMatthieu Gallien <matthieu_gallien@yahoo.fr>
Fri, 30 Jun 2023 13:32:03 +0000 (15:32 +0200)
Signed-off-by: Matthieu Gallien <matthieu.gallien@nextcloud.com>
src/libsync/clientsideencryption.cpp
src/libsync/clientsideencryption.h

index 3b7211e9bd72aa6bf590c88fde498dc397d0c873..e1d782a27e627464831fc67f1a18485bf4a2135c 100644 (file)
@@ -1294,17 +1294,19 @@ void ClientSideEncryption::generateKeyPair(const AccountPtr &account)
         qCInfo(lcCse()) << "Could not read private key from bio.";
         return;
     }
-    QByteArray key = BIO2ByteArray(privKey);
+    auto privateKey = PKey::readPrivateKey(privKey);
+    const auto key = BIO2ByteArray(privKey);
     //_privateKey = QSslKey(key, QSsl::Rsa, QSsl::Pem, QSsl::PrivateKey);
     _privateKey = key;
 
     qCInfo(lcCse()) << "Keys generated correctly, sending to server.";
-    auto csrOutput = generateCSR(account, std::move(localKeyPair));
+    auto csrOutput = generateCSR(account, std::move(localKeyPair), std::move(privateKey));
     writeMnemonic(account, [account, keyPair = std::move(csrOutput.second), output = std::move(csrOutput.first), this]() mutable -> void {writeKeyPair(account, std::move(keyPair), output);});
 }
 
 std::pair<QByteArray, ClientSideEncryption::PKey> ClientSideEncryption::generateCSR(AccountPtr account,
-                                                                                    PKey keyPair)
+                                                                                    PKey keyPair,
+                                                                                    PKey privateKey)
 {
     auto result = QByteArray{};
 
@@ -1348,9 +1350,9 @@ std::pair<QByteArray, ClientSideEncryption::PKey> ClientSideEncryption::generate
         return {result, std::move(keyPair)};
     }
 
-    ret = X509_REQ_sign(x509_req, keyPair, EVP_sha1());    // return x509_req->signature->length
+    ret = X509_REQ_sign(x509_req, privateKey, EVP_sha1());    // return x509_req->signature->length
     if (ret <= 0){
-        qCInfo(lcCse()) << "Error setting the public key on the csr";
+        qCInfo(lcCse()) << "Error signing the csr with the private key";
         return {result, std::move(keyPair)};
     }
 
@@ -1464,9 +1466,16 @@ void ClientSideEncryption::checkServerHasSavedKeys(AccountPtr account)
     const auto keyIsNotOnServer = [account, this] () {
         qCInfo(lcCse) << "server is missing keys. upload is necessary";
 
+        Bio publicKeyBio;
+        const auto publicKeyData = _publicKey.toPem();
+        BIO_write(publicKeyBio, publicKeyData.constData(), publicKeyData.size());
+        auto publicKey = PKey::readPublicKey(publicKeyBio);
+
         Bio privateKeyBio;
-        auto keyPair = PKey::readPublicKey(privateKeyBio);
-        auto csrData = generateCSR(account, std::move(keyPair));
+        BIO_write(privateKeyBio, _privateKey.constData(), _privateKey.size());
+        auto privateKey = PKey::readPrivateKey(privateKeyBio);
+
+        auto csrData = generateCSR(account, std::move(publicKey), std::move(privateKey));
         sendSignRequestCSR(account, std::move(csrData.second), std::move(csrData.first));
     };
 
index 5b61a9035fb749d72d1bad0919596029353c69c3..dffeee3ddd83f676a0ee147278b877cf2b8cde4d 100644 (file)
@@ -166,8 +166,10 @@ private slots:
 
 private:
     void generateMnemonic();
+
     [[nodiscard]] std::pair<QByteArray, PKey> generateCSR(AccountPtr account,
-                                                          PKey keyPair);
+                                                          PKey keyPair,
+                                                          PKey privateKey);
 
     void sendSignRequestCSR(AccountPtr account,
                             PKey keyPair,