Packages
erldns
7.0.0-rc2
11.0.2
11.0.1
11.0.0
10.6.0
10.5.6
10.5.5
10.5.4
10.5.3
10.5.2
10.5.1
10.5.0
10.4.4
10.4.3
10.4.2
10.4.1
10.4.0
10.3.0
10.2.1
10.2.0
10.1.0
10.0.0
10.0.0-rc4
10.0.0-rc3
10.0.0-rc2
10.0.0-rc1
9.1.0
9.0.0
9.0.0-rc3
9.0.0-rc2
9.0.0-rc1
8.1.0
8.0.0
8.0.0-rc6
8.0.0-rc5
8.0.0-rc4
8.0.0-rc3
8.0.0-rc2
8.0.0-rc1
7.0.0
7.0.0-rc9
7.0.0-rc8
7.0.0-rc7
7.0.0-rc6
7.0.0-rc5
7.0.0-rc4
7.0.0-rc3
7.0.0-rc2
7.0.0-rc12
7.0.0-rc11
7.0.0-rc10
7.0.0-rc1
6.0.2
6.0.1
6.0.0
5.0.0
4.3.1
4.3.0
4.2.4
4.2.3
4.2.2
4.2.1
4.2.0
4.1.2
4.1.1
4.1.0
4.0.0
3.0.0
1.0.0
Erlang Authoritative DNS Server
Current section
Files
Jump to
Current section
Files
src/admin/erldns_admin.erl
%% Copyright (c) 2012-2019, DNSimple Corporation
%%
%% Permission to use, copy, modify, and/or distribute this software for any
%% purpose with or without fee is hereby granted, provided that the above
%% copyright notice and this permission notice appear in all copies.
%%
%% THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
%% WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
%% MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
%% ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
%% WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
%% ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
%% OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
%% @doc Process for an administrative HTTP API.
%%
%% Provides zone quering and command-and-control functionality.
-module(erldns_admin).
-moduledoc """
Erldns admin API.
### Configuration:
This application will read from your `sys.config` the following example:
```erlang
{erldns, [
{admin, [
{credentials, {<<"username">>, <<"password">>}},
{port, 8083},
{middleware, [my_custom_middleware, another_middleware]}
]}
]}
```
where `credentials` is a tuple of `username` and `password` as either strings or binaries,
`port` is a valid Unix port to listen on, and `middleware` is an optional list of
middleware modules that will be applied to all admin API requests.
""".
-define(DEFAULT_PORT, 8083).
-include_lib("kernel/include/logger.hrl").
-export([maybe_start/0, is_authorized/2]).
-ifdef(TEST).
-export([middleware/1]).
-endif.
-doc """
Configuration parameters, see the module documentation for details.
""".
-type config() :: #{
port := 0..65535,
username := binary(),
password := binary(),
middleware => [module()]
}.
-doc "Common state for all handlers".
-opaque handler_state() :: #{
username := binary(),
password := binary()
}.
-export_type([config/0, handler_state/0]).
-type env() :: [{atom(), term()}].
-spec maybe_start() -> ok | {ok, pid()} | {error, any()}.
maybe_start() ->
case ensure_valid_config() of
disabled ->
ok;
false ->
error(bad_configuration);
Config ->
start(Config)
end.
-spec start(config()) -> {ok, pid()} | {error, any()}.
start(#{port := Port, username := Username, password := Password} = Config) ->
State = #{username => Username, password => Password},
Dispatch = cowboy_router:compile(
[
{'_', [
{"/", erldns_admin_root_handler, State},
{"/zones/:zone_name", erldns_admin_zone_resource_handler, State},
{"/zones/:zone_name/records[/:record_name]", erldns_admin_zone_records_resource_handler, State},
{"/zones/:zone_name/:action", erldns_admin_zone_control_handler, State}
]}
]
),
TransportOpts = #{socket_opts => [inet, {ip, {0, 0, 0, 0}}, {port, Port}]},
Middleware = maps:get(middleware, Config, []),
ProtocolOpts = #{
env => #{dispatch => Dispatch},
middlewares => [cowboy_router] ++ Middleware ++ [cowboy_handler]
},
cowboy:start_clear(?MODULE, TransportOpts, ProtocolOpts).
-doc false.
-spec is_authorized(cowboy_req:req(), handler_state()) ->
{true | {false, iodata()}, cowboy_req:req(), handler_state()}
| {stop, cowboy_req:req(), handler_state()}.
is_authorized(Req, #{username := ValidUsername, password := ValidPassword} = State) ->
maybe
{basic, GivenUsername, GivenPassword} ?= cowboy_req:parse_header(<<"authorization">>, Req),
true ?= is_binary_of_equal_size(GivenUsername, ValidUsername),
true ?= is_binary_of_equal_size(GivenPassword, ValidPassword),
true ?= crypto:hash_equals(GivenUsername, ValidUsername) andalso
crypto:hash_equals(GivenPassword, ValidPassword),
{true, Req, State}
else
_ ->
{{false, <<"Basic realm=\"erldns admin\"">>}, Req, State}
end.
-spec is_binary_of_equal_size(term(), term()) -> boolean().
is_binary_of_equal_size(Bin1, Bin2) ->
is_binary(Bin1) andalso is_binary(Bin2) andalso byte_size(Bin1) =:= byte_size(Bin2).
-spec ensure_valid_config() -> false | disabled | config().
ensure_valid_config() ->
maybe
{true, Env} ?= env(),
{true, Port} ?= port(Env),
{true, Username, Password} ?= credentials(Env),
{true, Middleware} ?= middleware(Env),
#{port => Port, username => Username, password => Password, middleware => Middleware}
end.
-spec port(env()) -> {true, 1..65535} | false.
port(Env) ->
case proplists:get_value(port, Env, ?DEFAULT_PORT) of
Port when is_integer(Port), 0 < Port, Port =< 65535 ->
{true, Port};
OtherPort ->
?LOG_ERROR(#{what => erldns_admin_bad_config, port => OtherPort}),
false
end.
-spec credentials(env()) -> {true, binary(), binary()} | false.
credentials(Env) ->
case lists:keyfind(credentials, 1, Env) of
{credentials, {Username, Password}} when is_list(Username), is_list(Password) ->
{true, list_to_binary(Username), list_to_binary(Password)};
{credentials, {Username, Password}} when is_binary(Username), is_binary(Password) ->
{true, Username, Password};
OtherValue ->
?LOG_ERROR(#{what => erldns_admin_bad_config, credentials => OtherValue}),
false
end.
-spec middleware(env()) -> {true, [module()]}.
middleware(Env) ->
case lists:keyfind(middleware, 1, Env) of
{middleware, Modules} when is_list(Modules) ->
case lists:all(fun is_atom/1, Modules) of
true ->
{true, Modules};
false ->
?LOG_ERROR(#{what => erldns_admin_bad_config, middleware => Modules}),
{true, []}
end;
false ->
{true, []};
OtherValue ->
?LOG_ERROR(#{what => erldns_admin_bad_config, middleware => OtherValue}),
{true, []}
end.
-spec env() -> {true, env()} | false | disabled.
env() ->
case application:get_env(erldns, admin) of
{ok, Env} when is_list(Env) -> {true, Env};
{ok, _} -> false;
_ -> disabled
end.