Verify a self-signed request and turn it into a delegate identity. The verification is the point: it proves whoever produced the request holds the private half of the key it names. Without it, `--request` would be a way to talk someone into signing a certificate for a key chosen by an attacker.
(&self, path: &str)
| 313 | /// would be a way to talk someone into signing a certificate for a key |
| 314 | /// chosen by an attacker. |
| 315 | fn delegate_from_request(&self, path: &str) -> CliResult<Identity> { |
| 316 | let raw = if path == "-" { |
| 317 | use std::io::Read; |
| 318 | let mut buf = String::new(); |
| 319 | std::io::stdin().read_to_string(&mut buf)?; |
| 320 | buf |
| 321 | } else { |
| 322 | std::fs::read_to_string(path)? |
| 323 | }; |
| 324 | |
| 325 | let value: serde_json::Value = |
| 326 | serde_json::from_str(&raw).map_err(|e| CliError::InvalidArgument { |
| 327 | message: format!("{path} is not valid JSON: {e}"), |
| 328 | })?; |
| 329 | |
| 330 | let request = cert::verify_request(&value).map_err(|e| CliError::DelegationError { |
| 331 | message: format!( |
| 332 | "The request in {path} does not verify: {e}\n \ |
| 333 | Only countersign a request whose self-signature checks out — it is the \ |
| 334 | only evidence the far end actually holds that key." |
| 335 | ), |
| 336 | })?; |
| 337 | |
| 338 | let public_key = |
| 339 | atomic_identity::PublicKey::from_did_key(&request.delegate_key).map_err(|e| { |
| 340 | CliError::DelegationError { |
| 341 | message: format!("Request carries a malformed key: {e}"), |
| 342 | } |
| 343 | })?; |
| 344 | |
| 345 | print_hint(&format!( |
| 346 | "Countersigning a verified request from '{}' ({})", |
| 347 | request.delegate_name, request.delegate |
| 348 | )); |
| 349 | |
| 350 | let mut builder = Identity::builder(&request.delegate_name) |
| 351 | .identity_type(IdentityType::Agent) |
| 352 | .public_key(public_key); |
| 353 | if let Some(agent) = &request.software_agent { |
| 354 | builder = builder.description(format!("software-agent:{agent}")); |
| 355 | } |
| 356 | builder |
| 357 | .build() |
| 358 | .map_err(|e| CliError::Internal(anyhow::anyhow!("Failed to build delegate: {e}"))) |
| 359 | } |
| 360 | } |
| 361 | |
| 362 | /// Recover the software-agent URN we stash in an identity description. |
no test coverage detected