Skip to content

Commit

Permalink
perf: add encrypted key api
Browse files Browse the repository at this point in the history
  • Loading branch information
LeeEirc committed Dec 11, 2024
1 parent 0f4a482 commit 0c21bcc
Show file tree
Hide file tree
Showing 4 changed files with 45 additions and 0 deletions.
6 changes: 6 additions & 0 deletions pkg/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,8 @@ type Config struct {

DisableInputAsCommand bool `mapstructure:"DISABLE_INPUT_AS_COMMAND"`

SecretEncryptKey string `mapstructure:"SECRET_ENCRYPT_KEY"`

RootPath string
DataFolderPath string
LogDirPath string
Expand All @@ -82,6 +84,10 @@ func (c *Config) EnsureConfigValid() {
}
}

func (c *Config) UpdateRedisPassword(val string) {
c.RedisPassword = val
}

func GetConf() Config {
if GlobalConfig == nil {
return getDefaultConfig()
Expand Down
14 changes: 14 additions & 0 deletions pkg/jms-sdk-go/service/jms_terminal.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
package service

func (s *JMService) GetEncryptedConfigValue(encryptKey, encryptedValue string) (resp ResultValue, err error) {
data := map[string]string{
"secret_encrypt_key": encryptKey,
"encrypted_value": encryptedValue,
}
_, err = s.authClient.Post(TerminalEncryptedConfigURL, data, &resp)
return
}

type ResultValue struct {
Value string `json:"value"`
}
2 changes: 2 additions & 0 deletions pkg/jms-sdk-go/service/url.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ const (
TerminalRegisterURL = "/api/v1/terminal/terminal-registrations/" // 注册
TerminalConfigURL = "/api/v1/terminal/terminals/config/" // 获取配置
TerminalHeartBeatURL = "/api/v1/terminal/terminals/status/"

TerminalEncryptedConfigURL = "/api/v1/terminal/encrypted-config/"
)

// 用户登陆认证使用的API
Expand Down
23 changes: 23 additions & 0 deletions pkg/koko/koko.go
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ func RunForever(confPath string) {
gracefulStop := make(chan os.Signal, 1)
signal.Notify(gracefulStop, syscall.SIGTERM, syscall.SIGINT, syscall.SIGQUIT)
jmsService := MustJMService()
bootstrapWithJMService(jmsService)
webSrv := httpd.NewServer(jmsService)
sshSrv := sshd.NewSSHServer(jmsService)
app := &Koko{
Expand All @@ -55,9 +56,31 @@ func RunForever(confPath string) {
func bootstrap() {
i18n.Initial()
logger.Initial()
}

func bootstrapWithJMService(jmsService *service.JMService) {
updateEncryptConfigValue(jmsService)
exchange.Initial()
}

func updateEncryptConfigValue(jmsService *service.JMService) {
cfg := config.GlobalConfig
encryptKey := cfg.SecretEncryptKey
if encryptKey != "" {
redisPassword := cfg.RedisPassword
ret, err := jmsService.GetEncryptedConfigValue(encryptKey, redisPassword)
if err != nil {
logger.Error("Get encrypted config value failed: " + err.Error())
return
}
if ret.Value != "" {
cfg.UpdateRedisPassword(ret.Value)
} else {
logger.Error("Get encrypted config value failed: empty value")
}
}
}

func runTasks(jmsService *service.JMService) {
if config.GetConf().UploadFailedReplay {
go uploadRemainReplay(jmsService)
Expand Down

0 comments on commit 0c21bcc

Please sign in to comment.