Merge branch 'starttls' of https://github.com/wiml/Nim into wiml-starttls
Conflicts: lib/pure/net.nim
This commit is contained in:
commit
8853dfb353
2 changed files with 89 additions and 53 deletions
|
|
@ -472,6 +472,15 @@ when defined(ssl):
|
||||||
socket.bioOut = bioNew(bio_s_mem())
|
socket.bioOut = bioNew(bio_s_mem())
|
||||||
sslSetBio(socket.sslHandle, socket.bioIn, socket.bioOut)
|
sslSetBio(socket.sslHandle, socket.bioIn, socket.bioOut)
|
||||||
|
|
||||||
|
proc wrapSocket*(ctx: SslContext, socket: AsyncSocket, handshake: SslHandshakeType) =
|
||||||
|
wrapSocket(ctx, socket)
|
||||||
|
|
||||||
|
case handshake
|
||||||
|
of handshakeAsClient:
|
||||||
|
sslSetConnectState(socket.sslHandle)
|
||||||
|
of handshakeAsServer:
|
||||||
|
sslSetAcceptState(socket.sslHandle)
|
||||||
|
|
||||||
proc getSockOpt*(socket: AsyncSocket, opt: SOBool, level = SOL_SOCKET): bool {.
|
proc getSockOpt*(socket: AsyncSocket, opt: SOBool, level = SOL_SOCKET): bool {.
|
||||||
tags: [ReadIOEffect].} =
|
tags: [ReadIOEffect].} =
|
||||||
## Retrieves option ``opt`` as a boolean value.
|
## Retrieves option ``opt`` as a boolean value.
|
||||||
|
|
|
||||||
|
|
@ -35,6 +35,9 @@ when defined(ssl):
|
||||||
SslAcceptResult* = enum
|
SslAcceptResult* = enum
|
||||||
AcceptNoClient = 0, AcceptNoHandshake, AcceptSuccess
|
AcceptNoClient = 0, AcceptNoHandshake, AcceptSuccess
|
||||||
|
|
||||||
|
SslHandshakeType* = enum
|
||||||
|
handshakeAsClient, handshakeAsServer
|
||||||
|
|
||||||
{.deprecated: [ESSL: SSLError, TSSLCVerifyMode: SSLCVerifyMode,
|
{.deprecated: [ESSL: SSLError, TSSLCVerifyMode: SSLCVerifyMode,
|
||||||
TSSLProtVersion: SSLProtVersion, PSSLContext: SSLContext,
|
TSSLProtVersion: SSLProtVersion, PSSLContext: SSLContext,
|
||||||
TSSLAcceptResult: SSLAcceptResult].}
|
TSSLAcceptResult: SSLAcceptResult].}
|
||||||
|
|
@ -98,6 +101,8 @@ type
|
||||||
|
|
||||||
proc isIpAddress*(address_str: string): bool {.tags: [].}
|
proc isIpAddress*(address_str: string): bool {.tags: [].}
|
||||||
proc parseIpAddress*(address_str: string): IpAddress
|
proc parseIpAddress*(address_str: string): IpAddress
|
||||||
|
proc socketError*(socket: Socket, err: int = -1, async = false,
|
||||||
|
lastError = (-1).OSErrorCode): void
|
||||||
|
|
||||||
proc isDisconnectionError*(flags: set[SocketFlag],
|
proc isDisconnectionError*(flags: set[SocketFlag],
|
||||||
lastError: OSErrorCode): bool =
|
lastError: OSErrorCode): bool =
|
||||||
|
|
@ -236,9 +241,13 @@ when defined(ssl):
|
||||||
## Wraps a socket in an SSL context. This function effectively turns
|
## Wraps a socket in an SSL context. This function effectively turns
|
||||||
## ``socket`` into an SSL socket.
|
## ``socket`` into an SSL socket.
|
||||||
##
|
##
|
||||||
|
## This must be called on an unconnected socket; an SSL session will
|
||||||
|
## be started when the socket is connected.
|
||||||
|
##
|
||||||
## **Disclaimer**: This code is not well tested, may be very unsafe and
|
## **Disclaimer**: This code is not well tested, may be very unsafe and
|
||||||
## prone to security vulnerabilities.
|
## prone to security vulnerabilities.
|
||||||
|
|
||||||
|
assert (not socket.isSSL)
|
||||||
socket.isSSL = true
|
socket.isSSL = true
|
||||||
socket.sslContext = ctx
|
socket.sslContext = ctx
|
||||||
socket.sslHandle = SSLNew(SSLCTX(socket.sslContext))
|
socket.sslHandle = SSLNew(SSLCTX(socket.sslContext))
|
||||||
|
|
@ -250,6 +259,24 @@ when defined(ssl):
|
||||||
if SSLSetFd(socket.sslHandle, socket.fd) != 1:
|
if SSLSetFd(socket.sslHandle, socket.fd) != 1:
|
||||||
raiseSSLError()
|
raiseSSLError()
|
||||||
|
|
||||||
|
proc wrapSocket*(ctx: SSLContext, socket: Socket, handshake: SslHandshakeType) =
|
||||||
|
## Wraps a socket in an SSL context. This function effectively turns
|
||||||
|
## ``socket`` into an SSL socket.
|
||||||
|
##
|
||||||
|
## This should be called on a connected socket, and will perform
|
||||||
|
## an SSL handshake immediately.
|
||||||
|
##
|
||||||
|
## **Disclaimer**: This code is not well tested, may be very unsafe and
|
||||||
|
## prone to security vulnerabilities.
|
||||||
|
wrapSocket(ctx, socket)
|
||||||
|
case handshake
|
||||||
|
of handshakeAsClient:
|
||||||
|
let ret = SSLConnect(socket.sslHandle)
|
||||||
|
socketError(socket, ret)
|
||||||
|
of handshakeAsServer:
|
||||||
|
let ret = SSLAccept(socket.sslHandle)
|
||||||
|
socketError(socket, ret)
|
||||||
|
|
||||||
proc getSocketError*(socket: Socket): OSErrorCode =
|
proc getSocketError*(socket: Socket): OSErrorCode =
|
||||||
## Checks ``osLastError`` for a valid error. If it has been reset it uses
|
## Checks ``osLastError`` for a valid error. If it has been reset it uses
|
||||||
## the last error stored in the socket object.
|
## the last error stored in the socket object.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue