Fix license compliance and fix things up, add reverse proxy, fix some security flaws with HttpUtils

This commit is contained in:
2026-08-31 20:57:18 -05:00
parent 313e75b14c
commit 3bce736834
41 changed files with 2227 additions and 384 deletions
@@ -21,6 +21,7 @@
#pragma once
#include "../Streams/Stream.hpp"
#include "Crypto.hpp"
namespace Tesses::Framework::Crypto {
/**
@@ -59,6 +60,32 @@ class ClientTLSStream : public Tesses::Framework::Streams::Stream {
ClientTLSStream(
std::shared_ptr<Tesses::Framework::Streams::Stream> innerStream,
bool verify, std::string domain, std::string cert);
/**
* @brief Construct a new Client TLS Stream object, with mTLS
*
* @param innerStream the underlying encrypted in transit stream
* @param verify do we verify the certificate
* @param domain the domain name
* @param keyStore the keystore for mTLS
*/
ClientTLSStream(
std::shared_ptr<Tesses::Framework::Streams::Stream> innerStream,
bool verify, std::string domain, CertificateKeyStore keyStore);
/**
* @brief Construct a new Client TLS Stream object with an alternative
* certificate chain (for server with self signed certificates) for mTLS
*
* @param innerStream the underlying encrypted in transit stream
* @param verify do we verify the certificate
* @param domain the domain name
* @param cert the actual certificate
* @param keyStore the keystore for mTLS
*/
ClientTLSStream(
std::shared_ptr<Tesses::Framework::Streams::Stream> innerStream,
bool verify, std::string domain, std::string cert,
CertificateKeyStore keyStore);
/**
* @brief Read from the stream
*
@@ -96,6 +123,10 @@ class ClientTLSStream : public Tesses::Framework::Streams::Stream {
* @return false no
*/
bool EndOfStream();
void Shutdown(Tesses::Framework::Streams::StreamShutdownMode sdm);
void SetSendTimeout(uint64_t seconds);
void SetRecvTimeout(uint64_t seconds);
~ClientTLSStream();
};
+24 -1
View File
@@ -316,6 +316,29 @@ typedef enum {
*/
bool PBKDF2(std::vector<uint8_t> &output, std::string pass,
std::vector<uint8_t> &salt, long itterations, ShaVersion version);
/**
* @brief Get secure random bytes
*
* @param output The buffer to write random bytes to
* @param personal_str Some string to ensure the rng is unique (for mbedtls at
* least)
* @return true successfully generated the bytes
* @return false we failed to generate the bytes
*/
bool RandomBytes(std::vector<uint8_t> &output, std::string personal_str);
struct CertificateKeyStore {
CertificateKeyStore() = default;
CertificateKeyStore(std::string certificate, std::string key,
std::optional<std::string> chain = std::nullopt,
std::string password = "")
: certificate(certificate), key(key), chain(chain), password(password) {
}
std::string certificate;
std::string key;
std::optional<std::string> chain;
std::string password;
};
} // namespace Tesses::Framework::Crypto