File
Blob: src/node/internal/internal_tls_common.ts
| 1 | // Copyright (c) 2017-2022 Cloudflare, Inc. |
| 2 | // Licensed under the Apache 2.0 license found in the LICENSE file or at: |
| 3 | // https://opensource.org/licenses/Apache-2.0 |
| 4 | // |
| 5 | // Copyright Joyent, Inc. and other Node contributors. |
| 6 | // |
| 7 | // Permission is hereby granted, free of charge, to any person obtaining a |
| 8 | // copy of this software and associated documentation files (the |
| 9 | // "Software"), to deal in the Software without restriction, including |
| 10 | // without limitation the rights to use, copy, modify, merge, publish, |
| 11 | // distribute, sublicense, and/or sell copies of the Software, and to permit |
| 12 | // persons to whom the Software is furnished to do so, subject to the |
| 13 | // following conditions: |
| 14 | // |
| 15 | // The above copyright notice and this permission notice shall be included |
| 16 | // in all copies or substantial portions of the Software. |
| 17 | // |
| 18 | // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS |
| 19 | // OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF |
| 20 | // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN |
| 21 | // NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, |
| 22 | // DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR |
| 23 | // OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE |
| 24 | // USE OR OTHER DEALINGS IN THE SOFTWARE. |
| 25 | |
| 26 | import type tls from 'node:tls'; |
| 27 | import { validateInteger } from 'node-internal:validators'; |
| 28 | |
| 29 | // @ts-expect-error TS2323 Redeclare error. |
| 30 | export declare class SecureContext { |
| 31 | context: unknown; |
| 32 | constructor( |
| 33 | _secureProtocol?: string, |
| 34 | secureOptions?: number, |
| 35 | minVersion?: string, |
| 36 | maxVersion?: string |
| 37 | ); |
| 38 | } |
| 39 | |
| 40 | // This is intentionally not fully compatible with Node.js implementation |
| 41 | // since creating and customizing an actually equivalent SecureContext is not supported. |
| 42 | // @ts-expect-error TS2323 Redeclare error. |
| 43 | export function SecureContext( |
| 44 | this: SecureContext, |
| 45 | secureProtocol?: string, |
| 46 | secureOptions?: number, |
| 47 | minVersion?: string, |
| 48 | maxVersion?: string |
| 49 | ): SecureContext { |
| 50 | if (!(this instanceof SecureContext)) { |
| 51 | return new SecureContext( |
| 52 | secureProtocol, |
| 53 | secureOptions, |
| 54 | minVersion, |
| 55 | maxVersion |
| 56 | ); |
| 57 | } |
| 58 | // We do not support the minVersion and maxVersion options at this |
| 59 | // time and will just ignore them if they are passed. |
| 60 | // We have to omit these errors in order to support mssql. |
| 61 | // |
| 62 | // if (minVersion !== undefined) { |
| 63 | // throw new ERR_OPTION_NOT_IMPLEMENTED('minVersion'); |
| 64 | // } |
| 65 | // if (maxVersion !== undefined) { |
| 66 | // throw new ERR_OPTION_NOT_IMPLEMENTED('maxVersion'); |
| 67 | // } |
| 68 | |
| 69 | if (secureOptions !== undefined) { |
| 70 | validateInteger(secureOptions, 'secureOptions'); |
| 71 | } |
| 72 | |
| 73 | this.context = undefined; |
| 74 | return this; |
| 75 | } |
| 76 | |
| 77 | export function createSecureContext( |
| 78 | options: tls.SecureContextOptions = {} |
| 79 | ): SecureContext { |
| 80 | return new SecureContext( |
| 81 | options.secureProtocol, |
| 82 | options.secureOptions, |
| 83 | options.minVersion, |
| 84 | options.maxVersion |
| 85 | ); |
| 86 | } |
| 87 | |
| 88 | // Translate some fields from the handle's C-friendly format into more idiomatic |
| 89 | // javascript object representations before passing them back to the user. Can |
| 90 | // be used on any cert object, but changing the name would be semver-major. |
| 91 | export function translatePeerCertificate( |
| 92 | c?: tls.DetailedPeerCertificate |
| 93 | ): null | tls.DetailedPeerCertificate { |
| 94 | if (!c) return null; |
| 95 | |
| 96 | // eslint-disable-next-line @typescript-eslint/no-unnecessary-condition |
| 97 | if (c.issuerCertificate != null && c.issuerCertificate !== c) { |
| 98 | c.issuerCertificate = translatePeerCertificate( |
| 99 | c.issuerCertificate |
| 100 | ) as tls.DetailedPeerCertificate; |
| 101 | } |
| 102 | if (c.infoAccess != null) { |
| 103 | // Type is ignored due to @types/node inconsistency |
| 104 | const info = c.infoAccess as unknown as string; |
| 105 | // @ts-expect-error TS2322 Ignored due to missing __proto__ type. |
| 106 | c.infoAccess = { __proto__: null }; |
| 107 | |
| 108 | // XXX: More key validation? |
| 109 | info.replace( |
| 110 | /([^\n:]*):([^\n]*)(?:\n|$)/g, |
| 111 | // @ts-expect-error TS2349 @types/node inconsistency |
| 112 | (_all: string, key: string, val: string): void => { |
| 113 | if (val.charCodeAt(0) === 0x22) { |
| 114 | // The translatePeerCertificate function is only |
| 115 | // used on internally created legacy certificate |
| 116 | // objects, and any value that contains a quote |
| 117 | // will always be a valid JSON string literal, |
| 118 | // so this should never throw. |
| 119 | val = JSON.parse(val) as string; |
| 120 | } |
| 121 | if (c.infoAccess != null) { |
| 122 | c.infoAccess[key] ??= []; |
| 123 | c.infoAccess[key].push(val); |
| 124 | } |
| 125 | } |
| 126 | ); |
| 127 | } |
| 128 | return c; |
| 129 | } |