From 61d2ae52d29c3422cc98bbf48e95bceeb616156b Mon Sep 17 00:00:00 2001 From: Trent Clarke Date: Thu, 10 Feb 2022 16:27:19 +1100 Subject: [PATCH] Adds Application certificate path to profile (#10043) Adds Application certificate path to profile Prior to this patch, the API Profile type had no way of exposing the path to an application certificate. While this could be constructed manually using the `keypaths` package, this was fragile and easy to miss should the profile layout ever change. This patch adds `GetAppCertPath()` to the API profile, providing a centralised and integrated method for finding application certificates. --- api/profile/profile.go | 7 +++++++ api/profile/profile_test.go | 24 +++++++++++++++++++----- 2 files changed, 26 insertions(+), 5 deletions(-) diff --git a/api/profile/profile.go b/api/profile/profile.go index 1c687d4b11f..ba63ce65d65 100644 --- a/api/profile/profile.go +++ b/api/profile/profile.go @@ -362,3 +362,10 @@ func (p *Profile) OldSSHCertPath() string { func (p *Profile) KnownHostsPath() string { return keypaths.KnownHostsPath(p.Dir) } + +// AppCertPath returns the path to the profile's certificate for a given +// application. Note that this function merely constructs the path - there +// is no guarantee that there is an actual certificate at that location. +func (p *Profile) AppCertPath(appName string) string { + return keypaths.AppCertPath(p.Dir, p.Name(), p.Username, p.SiteName, appName) +} diff --git a/api/profile/profile_test.go b/api/profile/profile_test.go index affbc8d5dcc..3b15fc45a32 100644 --- a/api/profile/profile_test.go +++ b/api/profile/profile_test.go @@ -18,7 +18,6 @@ limitations under the License. package profile_test import ( - "io/ioutil" "os" "path/filepath" "testing" @@ -34,9 +33,7 @@ import ( func TestProfileBasics(t *testing.T) { t.Parallel() - dir, err := ioutil.TempDir("", "teleport") - require.NoError(t, err) - defer os.RemoveAll(dir) + dir := t.TempDir() p := &profile.Profile{ WebProxyAddr: "proxy:3088", @@ -52,7 +49,7 @@ func TestProfileBasics(t *testing.T) { require.Equal(t, "proxy", p.Name()) // save to a file: - err = p.SaveToDir(dir, false) + err := p.SaveToDir(dir, false) require.NoError(t, err) // verify that the resulting file exists and is of the form `/.yaml`. @@ -86,3 +83,20 @@ func TestProfileBasics(t *testing.T) { require.NoError(t, err) require.Equal(t, *p, *clone) } + +func TestAppPath(t *testing.T) { + t.Parallel() + + dir := t.TempDir() + + p := &profile.Profile{ + WebProxyAddr: "proxy:3088", + SSHProxyAddr: "proxy:3023", + Username: "testuser", + Dir: dir, + SiteName: "example.com", + } + + expected := filepath.Join(dir, "keys", "proxy", "testuser-app", "example.com", "banana-x509.pem") + require.Equal(t, expected, p.AppCertPath("banana")) +}