From ad795b4fd172f24cd09b83c1dd0441ef4dbb1c1d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Matej=20Ba=C4=8Do?= Date: Wed, 17 Sep 2025 17:42:36 +0200 Subject: [PATCH] Improve extensability of certificate validator --- composer.lock | 23 ++++++++----------- .../Platform/Modules/Proxy/Action.php | 7 +++--- .../Modules/Proxy/Http/Rules/API/Create.php | 6 +++-- .../Proxy/Http/Rules/Function/Create.php | 6 +++-- .../Proxy/Http/Rules/Redirect/Create.php | 6 +++-- .../Modules/Proxy/Http/Rules/Site/Create.php | 6 +++-- .../Proxy/Http/Rules/Verification/Update.php | 6 +++-- .../Platform/Workers/Certificates.php | 6 +++-- 8 files changed, 37 insertions(+), 29 deletions(-) diff --git a/composer.lock b/composer.lock index 0ed0d05dc5..ec7b0b73a8 100644 --- a/composer.lock +++ b/composer.lock @@ -5278,16 +5278,16 @@ }, { "name": "laravel/pint", - "version": "v1.24.0", + "version": "v1.25.0", "source": { "type": "git", "url": "https://github.com/laravel/pint.git", - "reference": "0345f3b05f136801af8c339f9d16ef29e6b4df8a" + "reference": "595de38458c6b0ab4cae4bcc769c2e5c5d5b8e96" }, "dist": { "type": "zip", - "url": "https://api.github.com/repos/laravel/pint/zipball/0345f3b05f136801af8c339f9d16ef29e6b4df8a", - "reference": "0345f3b05f136801af8c339f9d16ef29e6b4df8a", + "url": "https://api.github.com/repos/laravel/pint/zipball/595de38458c6b0ab4cae4bcc769c2e5c5d5b8e96", + "reference": "595de38458c6b0ab4cae4bcc769c2e5c5d5b8e96", "shasum": "" }, "require": { @@ -5298,9 +5298,9 @@ "php": "^8.2.0" }, "require-dev": { - "friendsofphp/php-cs-fixer": "^3.82.2", - "illuminate/view": "^11.45.1", - "larastan/larastan": "^3.5.0", + "friendsofphp/php-cs-fixer": "^3.87.2", + "illuminate/view": "^11.46.0", + "larastan/larastan": "^3.7.1", "laravel-zero/framework": "^11.45.0", "mockery/mockery": "^1.6.12", "nunomaduro/termwind": "^2.3.1", @@ -5311,9 +5311,6 @@ ], "type": "project", "autoload": { - "files": [ - "overrides/Runner/Parallel/ProcessFactory.php" - ], "psr-4": { "App\\": "app/", "Database\\Seeders\\": "database/seeders/", @@ -5343,7 +5340,7 @@ "issues": "https://github.com/laravel/pint/issues", "source": "https://github.com/laravel/pint" }, - "time": "2025-07-10T18:09:32+00:00" + "time": "2025-09-17T01:36:44+00:00" }, { "name": "matthiasmullie/minify", @@ -8509,7 +8506,7 @@ ], "aliases": [], "minimum-stability": "stable", - "stability-flags": {}, + "stability-flags": [], "prefer-stable": false, "prefer-lowest": false, "platform": { @@ -8533,5 +8530,5 @@ "platform-overrides": { "php": "8.3" }, - "plugin-api-version": "2.6.0" + "plugin-api-version": "2.3.0" } diff --git a/src/Appwrite/Platform/Modules/Proxy/Action.php b/src/Appwrite/Platform/Modules/Proxy/Action.php index 972bb2cd12..72072dd2f0 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Action.php +++ b/src/Appwrite/Platform/Modules/Proxy/Action.php @@ -14,9 +14,8 @@ use Utopia\Validator\IP; class Action extends PlatformAction { - protected function getDNSValidator(): string + public function __construct(protected string $dnsValidatorClass = DNS::class) { - return DNS::class; } /** @@ -28,9 +27,9 @@ class Action extends PlatformAction * @param string|null $verificationDomainFunction Override for expected Function rule value during verification * @return void */ - public static function verifyRule(Document $rule, ?Log $log = null, ?string $verificationDomainAPI = null, ?string $verificationDomainFunction = null): void + public function verifyRule(Document $rule, ?Log $log = null, ?string $verificationDomainAPI = null, ?string $verificationDomainFunction = null): void { - $dnsValidatorClass = self::getDNSValidator(); + $dnsValidatorClass = $this->dnsValidatorClass; $domain = new Domain($rule->getAttribute('domain', '')); diff --git a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/API/Create.php b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/API/Create.php index 2d5e1ecda2..23fcf795e1 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/API/Create.php +++ b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/API/Create.php @@ -29,8 +29,10 @@ class Create extends Action return 'createAPIRule'; } - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->setHttpMethod(Action::HTTP_REQUEST_METHOD_POST) ->setHttpPath('/v1/proxy/rules/api') @@ -162,7 +164,7 @@ class Create extends Action if ($rule->getAttribute('status', '') === RULE_STATUS_VERIFICATION_FAILED) { try { - self::verifyRule($rule, $log); + $this->verifyRule($rule, $log); $rule->setAttribute('status', RULE_STATUS_GENERATING_CERTIFICATE); } catch (Exception $err) { $rule->setAttribute('verificationLogs', $err->getMessage()); diff --git a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Function/Create.php b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Function/Create.php index ed1b70203b..80b7e8483c 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Function/Create.php +++ b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Function/Create.php @@ -31,8 +31,10 @@ class Create extends Action return 'createFunctionRule'; } - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->setHttpMethod(Action::HTTP_REQUEST_METHOD_POST) ->setHttpPath('/v1/proxy/rules/function') @@ -183,7 +185,7 @@ class Create extends Action if ($rule->getAttribute('status', '') === RULE_STATUS_VERIFICATION_FAILED) { try { - self::verifyRule($rule, $log); + $this->verifyRule($rule, $log); $rule->setAttribute('status', RULE_STATUS_GENERATING_CERTIFICATE); } catch (Exception $err) { $rule->setAttribute('verificationLogs', $err->getMessage()); diff --git a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Redirect/Create.php b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Redirect/Create.php index ebc3475cdc..096c0e80f8 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Redirect/Create.php +++ b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Redirect/Create.php @@ -32,8 +32,10 @@ class Create extends Action return 'createRedirectRule'; } - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->setHttpMethod(Action::HTTP_REQUEST_METHOD_POST) ->setHttpPath('/v1/proxy/rules/redirect') @@ -189,7 +191,7 @@ class Create extends Action if ($rule->getAttribute('status', '') === RULE_STATUS_VERIFICATION_FAILED) { try { - self::verifyRule($rule, $log); + $this->verifyRule($rule, $log); $rule->setAttribute('status', RULE_STATUS_GENERATING_CERTIFICATE); } catch (Exception $err) { $rule->setAttribute('verificationLogs', $err->getMessage()); diff --git a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Site/Create.php b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Site/Create.php index 25d21065b0..ed4ade3d5b 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Site/Create.php +++ b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Site/Create.php @@ -31,8 +31,10 @@ class Create extends Action return 'createSiteRule'; } - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->setHttpMethod(Action::HTTP_REQUEST_METHOD_POST) ->setHttpPath('/v1/proxy/rules/site') @@ -183,7 +185,7 @@ class Create extends Action if ($rule->getAttribute('status', '') === RULE_STATUS_VERIFICATION_FAILED) { try { - self::verifyRule($rule, $log); + $this->verifyRule($rule, $log); $rule->setAttribute('status', RULE_STATUS_GENERATING_CERTIFICATE); } catch (Exception $err) { $rule->setAttribute('verificationLogs', $err->getMessage()); diff --git a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Verification/Update.php b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Verification/Update.php index 6e2a30a5ee..14472a72e6 100644 --- a/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Verification/Update.php +++ b/src/Appwrite/Platform/Modules/Proxy/Http/Rules/Verification/Update.php @@ -25,8 +25,10 @@ class Update extends Action return 'updateRuleVerification'; } - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->setHttpMethod(Action::HTTP_REQUEST_METHOD_PATCH) ->setHttpPath('/v1/proxy/rules/:ruleId/verification') @@ -83,7 +85,7 @@ class Update extends Action $updates = new Document(); try { - self::verifyRule($rule, $log); + $this->verifyRule($rule, $log); $updates->setAttribute('verificationLogs', ''); } catch (Exception $err) { $dbForPlatform->updateDocument('rules', $rule->getId(), new Document([ diff --git a/src/Appwrite/Platform/Workers/Certificates.php b/src/Appwrite/Platform/Workers/Certificates.php index 44651953f7..7ea8032b50 100644 --- a/src/Appwrite/Platform/Workers/Certificates.php +++ b/src/Appwrite/Platform/Workers/Certificates.php @@ -41,8 +41,10 @@ class Certificates extends Action /** * @throws Exception */ - public function __construct() + public function __construct(...$params) { + parent::__construct(...$params); + $this ->desc('Certificates worker') ->inject('message') @@ -409,7 +411,7 @@ class Certificates extends Action private function validateDomain(Document $rule, bool $isMainDomain, Log $log, ?string $verificationDomainAPI = null, ?string $verificationDomainFunction = null): void { if (!$isMainDomain) { - self::verifyRule($rule, $log, $verificationDomainAPI, $verificationDomainFunction); + $this->verifyRule($rule, $log, $verificationDomainAPI, $verificationDomainFunction); } else { // Main domain validation // TODO: Would be awesome to check A/AAAA record here. Maybe dry run?