Compare commits
10 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 35c7712f85 | |||
| 84d09f6dbb | |||
| c5ff6e555a | |||
| e4a70e0e43 | |||
| 6522809dce | |||
| 19f46bd01f | |||
| e48cf674a5 | |||
| 36721abdb9 | |||
| 0e5c4e3e9f | |||
| 5c1a0693b3 |
4
.gitignore
vendored
4
.gitignore
vendored
@@ -39,5 +39,5 @@ out/
|
||||
### Kotlin ###
|
||||
.kotlin
|
||||
|
||||
### cert ###
|
||||
cert/
|
||||
#### Hlæja ###
|
||||
/cert/
|
||||
|
||||
80
README.md
80
README.md
@@ -5,19 +5,32 @@ Classes and endpoints, to shape and to steer, Devices and sensors, their purpose
|
||||
## Properties for deployment
|
||||
|
||||
| name | required | info |
|
||||
|-------------------------------|----------|--------------------------|
|
||||
| spring.profiles.active | * | Spring Boot environment |
|
||||
| server.port | * | HTTP port |
|
||||
| server.ssl.enabled | * | HTTP Enable SSL |
|
||||
| server.ssl.key-store | * | HTTP Keystore |
|
||||
| server.ssl.key-store-type | * | HTTP Cert Type |
|
||||
| server.ssl.key-store-password | ** | HTTP Cert Pass |
|
||||
| jwt.public-key | * | JWT public key |
|
||||
| device-registry.url | * | Device Register URL |
|
||||
| device-data.url | * | Device Data URL |
|
||||
| device-configuration.url | * | Device Configuration URL |
|
||||
|----------------------------------------------|:--------:|----------------------------------------------|
|
||||
| spring.profiles.active | ✓ | Spring Boot environment |
|
||||
| server.port | ✓ | HTTP port |
|
||||
| server.ssl.enabled | ✓ | HTTP Enable SSL |
|
||||
| server.ssl.key-store | ✓ | HTTP Keystore |
|
||||
| server.ssl.key-store-type | ✓ | HTTP Cert Type |
|
||||
| server.ssl.key-store-password | ✗ | HTTP Cert Pass |
|
||||
| spring.cache.type | | Cache type (redis) |
|
||||
| spring.data.redis.host | ✓ | Redis host |
|
||||
| spring.data.redis.port | | Redis port |
|
||||
| spring.data.redis.database | ✓ | Redis database |
|
||||
| spring.data.redis.password | ✗ | Redis password |
|
||||
| cache.time-to-live | | Cache time to live (minutes) |
|
||||
| jwt.public-key | ✓ | JWT public key |
|
||||
| device-registry.url | ✓ | Device Register URL |
|
||||
| device-data.url | ✓ | Device Data URL |
|
||||
| device-configuration.url | ✓ | Device Configuration URL |
|
||||
| management.influx.metrics.export.api-version | | InfluxDB API version |
|
||||
| management.influx.metrics.export.enabled | | Enable/Disable exporting metrics to InfluxDB |
|
||||
| management.influx.metrics.export.bucket | ✓ | InfluxDB bucket name |
|
||||
| management.influx.metrics.export.org | ✓ | InfluxDB organization |
|
||||
| management.influx.metrics.export.token | ✗ | InfluxDB token |
|
||||
| management.influx.metrics.export.uri | ✓ | InfluxDB URL |
|
||||
| management.metrics.tags.application | ✓ | Application instance tag for metrics |
|
||||
|
||||
Required: * can be stored as text, and ** need to be stored as secret.
|
||||
*Required: ✓ can be stored as text, and ✗ need to be stored as secret.*
|
||||
|
||||
## Releasing Service
|
||||
|
||||
@@ -27,43 +40,32 @@ Run `release.sh` script from `master` branch.
|
||||
|
||||
### Developer Keystore
|
||||
|
||||
1. Open `hosts` file:
|
||||
* On Unix-like systems (Linux, macOS), this directory is typically `/etc/hosts`.
|
||||
* On Windows, this directory is typically `%SystemRoot%\System32\drivers\etc\hosts`.
|
||||
|
||||
2. Add the following lines to the `hosts` file:
|
||||
```text
|
||||
127.0.0.1 deviceapi # Hlæja Device API
|
||||
```
|
||||
|
||||
3. Generate Keystores
|
||||
```shell
|
||||
keytool -genkeypair -alias device-api -keyalg RSA -keysize 2048 -validity 3650 -dname "CN=deviceapi" -keypass password -keystore ./cert/keystore.p12 -storetype PKCS12 -storepass password
|
||||
```
|
||||
|
||||
4. Export the public certificate
|
||||
```shell
|
||||
keytool -export -alias device-api -keystore ./cert/keystore.p12 -storepass password -file ./cert/device-api.cer -rfc
|
||||
```
|
||||
We use a keystore to enable HTTPS for our API. To set up your developer environment for local development, please refer to [generate keystore](https://github.com/swordsteel/hlaeja-development/blob/master/doc/keystore.md) documentation. When generating and exporting the certificate for local development, please store it in the `./cert/keystore.p12` folder at the project root.
|
||||
|
||||
### Public RSA Key
|
||||
|
||||
To validate devices, copy file named `public_key.pem` from `./cert` generated for local development in **Hlæja Device Register** in to `./cert`.
|
||||
This service uses the public key from **[Hlæja Device Register](https://github.com/swordsteel/hlaeja-device-registry)** to identify devices. To set up device identification for local development, copy the `public_key.pem` file from the `./cert` directory in **Hlæja Device Register** into the `./cert` directory of this project.
|
||||
|
||||
### Global gradle properties
|
||||
*Note: For more information on generating RSA keys, please refer to our [generate RSA key](https://github.com/swordsteel/hlaeja-development/blob/master/doc/rsa_key.md) documentation.*
|
||||
|
||||
To authenticate with Gradle to access repositories that require authentication, you can set your user and token in the `gradle.properties` file.
|
||||
### Global Settings
|
||||
|
||||
Here's how you can do it:
|
||||
This services rely on a set of global settings to configure development environments. These settings, managed through Gradle properties or environment variables.
|
||||
|
||||
1. Open or create the `gradle.properties` file in your Gradle user home directory:
|
||||
*Note: For more information on global properties, please refer to our [global settings](https://github.com/swordsteel/hlaeja-development/blob/master/doc/global_settings.md) documentation.*
|
||||
|
||||
- On Unix-like systems (Linux, macOS), this directory is typically `~/.gradle/`.
|
||||
- On Windows, this directory is typically `C:\Users\<YourUsername>\.gradle\`.
|
||||
#### Gradle Properties
|
||||
|
||||
2. Add the following lines to the `gradle.properties` file:
|
||||
```properties
|
||||
repository.user=your_user
|
||||
repository.token=your_token_value
|
||||
influxdb.token=your_token_value
|
||||
```
|
||||
|
||||
#### Environment Variables
|
||||
|
||||
```properties
|
||||
REPOSITORY_USER=your_user
|
||||
REPOSITORY_TOKEN=your_token_value
|
||||
INFLUXDB_TOKEN=your_token_value
|
||||
```
|
||||
or use environment variables `REPOSITORY_USER` and `REPOSITORY_TOKEN`
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
import com.bmuschko.gradle.docker.tasks.container.DockerCreateContainer
|
||||
|
||||
plugins {
|
||||
alias(hlaeja.plugins.kotlin.jvm)
|
||||
alias(hlaeja.plugins.kotlin.spring)
|
||||
alias(hlaeja.plugins.ltd.hlaeja.plugin.certificate)
|
||||
alias(hlaeja.plugins.ltd.hlaeja.plugin.service)
|
||||
alias(hlaeja.plugins.spring.dependency.management)
|
||||
alias(hlaeja.plugins.springframework.boot)
|
||||
@@ -12,13 +15,14 @@ dependencies {
|
||||
implementation(hlaeja.kotlin.logging)
|
||||
implementation(hlaeja.kotlin.reflect)
|
||||
implementation(hlaeja.kotlinx.coroutines)
|
||||
implementation(hlaeja.micrometer.registry.influx)
|
||||
implementation(hlaeja.library.hlaeja.common.messages)
|
||||
implementation(hlaeja.library.hlaeja.jwt)
|
||||
implementation(hlaeja.springboot.starter.actuator)
|
||||
implementation(hlaeja.springboot.starter.cache)
|
||||
implementation(hlaeja.springboot.starter.redis)
|
||||
implementation(hlaeja.springboot.starter.webflux)
|
||||
|
||||
runtimeOnly(hlaeja.jjwt.impl)
|
||||
runtimeOnly(hlaeja.jjwt.jackson)
|
||||
|
||||
testImplementation(hlaeja.kotlin.test.junit5)
|
||||
testImplementation(hlaeja.kotlinx.coroutines.test)
|
||||
testImplementation(hlaeja.mockk)
|
||||
@@ -30,20 +34,17 @@ dependencies {
|
||||
|
||||
group = "ltd.hlaeja"
|
||||
|
||||
fun influxDbToken(): String = config.findOrDefault("influxdb.token", "INFLUXDB_TOKEN", "")
|
||||
|
||||
tasks {
|
||||
named("containerCreate", DockerCreateContainer::class) {
|
||||
withEnvVar("MANAGEMENT_INFLUX_METRICS_EXPORT_TOKEN", influxDbToken())
|
||||
}
|
||||
withType<ProcessResources> {
|
||||
filesMatching("**/application.yml") { filter { it.replace("%INFLUXDB_TOKEN%", influxDbToken()) } }
|
||||
onlyIf { file("src/main/resources/application.yml").exists() }
|
||||
}
|
||||
named("processResources") {
|
||||
dependsOn("copyKeystore", "copyPublicKey")
|
||||
}
|
||||
register<Copy>("copyKeystore") {
|
||||
group = "hlaeja"
|
||||
from("cert/keystore.p12")
|
||||
into("${layout.buildDirectory.get()}/resources/main/cert")
|
||||
onlyIf { file("cert/keystore.p12").exists() }
|
||||
}
|
||||
register<Copy>("copyPublicKey") {
|
||||
group = "hlaeja"
|
||||
from("cert/public_key.pem")
|
||||
into("${layout.buildDirectory.get()}/resources/main/cert")
|
||||
onlyIf { file("cert/public_key.pem").exists() }
|
||||
dependsOn("copyCertificates")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
kotlin.code.style=official
|
||||
org.gradle.jvmargs=-Xmx1g
|
||||
version=0.1.0
|
||||
catalog=0.5.0
|
||||
version=0.4.0
|
||||
catalog=0.8.0
|
||||
docker.port.expose=8443
|
||||
container.port.expose=8443
|
||||
container.port.host=9000
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
### get measurement
|
||||
### get configuration
|
||||
GET {{hostname}}/configuration
|
||||
Identity: 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
|
||||
Identity: {{identity}}
|
||||
|
||||
@@ -1,8 +1,10 @@
|
||||
{
|
||||
"development": {
|
||||
"hostname": "https://localhost:8443"
|
||||
"hostname": "https://localhost:8443",
|
||||
"identity": "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ"
|
||||
},
|
||||
"docker": {
|
||||
"hostname": "https://localhost:9000"
|
||||
"hostname": "https://localhost:9000",
|
||||
"identity": "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
### get measurement
|
||||
GET {{hostname}}/measurement
|
||||
Identity: 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
|
||||
Identity: {{identity}}
|
||||
|
||||
### add measurement for all
|
||||
POST {{hostname}}/measurement
|
||||
Content-Type: application/json
|
||||
Identity: 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
|
||||
Identity: {{identity}}
|
||||
|
||||
{
|
||||
"button0": 0,
|
||||
@@ -16,8 +16,8 @@ Identity: 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVW
|
||||
### add measurement for one
|
||||
POST {{hostname}}/measurement
|
||||
Content-Type: application/json
|
||||
Identity: 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ.0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
|
||||
Identity: {{identity}}
|
||||
|
||||
{
|
||||
"button0": 0
|
||||
"button0": 1
|
||||
}
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
package ltd.hlaeja
|
||||
|
||||
import ltd.hlaeja.property.CacheProperty
|
||||
import ltd.hlaeja.property.DeviceConfigurationProperty
|
||||
import ltd.hlaeja.property.DeviceDataProperty
|
||||
import ltd.hlaeja.property.DeviceRegistryProperty
|
||||
@@ -7,8 +8,11 @@ import ltd.hlaeja.property.JwtProperty
|
||||
import org.springframework.boot.autoconfigure.SpringBootApplication
|
||||
import org.springframework.boot.context.properties.EnableConfigurationProperties
|
||||
import org.springframework.boot.runApplication
|
||||
import org.springframework.cache.annotation.EnableCaching
|
||||
|
||||
@EnableCaching
|
||||
@EnableConfigurationProperties(
|
||||
CacheProperty::class,
|
||||
DeviceConfigurationProperty::class,
|
||||
DeviceDataProperty::class,
|
||||
DeviceRegistryProperty::class,
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
package ltd.hlaeja.configuration
|
||||
|
||||
import java.time.Duration
|
||||
import ltd.hlaeja.exception.CacheException
|
||||
import ltd.hlaeja.property.CacheProperty
|
||||
import org.springframework.context.annotation.Bean
|
||||
import org.springframework.context.annotation.Configuration
|
||||
import org.springframework.data.redis.cache.RedisCacheConfiguration
|
||||
import org.springframework.data.redis.cache.RedisCacheManager
|
||||
import org.springframework.data.redis.core.RedisTemplate
|
||||
|
||||
@Configuration
|
||||
class RedisCacheConfiguration(
|
||||
private val cacheProperty: CacheProperty,
|
||||
) {
|
||||
|
||||
@Bean
|
||||
fun cacheManager(
|
||||
redisTemplate: RedisTemplate<String, String>,
|
||||
): RedisCacheManager = redisTemplate.connectionFactory
|
||||
?.let { RedisCacheManager.builder(it).cacheDefaults(getRedisCacheConfiguration()).build() }
|
||||
?: throw CacheException("Redis connection factory is not set")
|
||||
|
||||
private fun getRedisCacheConfiguration(): RedisCacheConfiguration = RedisCacheConfiguration.defaultCacheConfig()
|
||||
.entryTtl(Duration.ofMinutes(cacheProperty.timeToLive))
|
||||
}
|
||||
@@ -1,7 +1,9 @@
|
||||
package ltd.hlaeja.controller
|
||||
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.jwt.service.PublicJwtService
|
||||
import ltd.hlaeja.service.DeviceConfigurationService
|
||||
import ltd.hlaeja.service.JwtService
|
||||
import ltd.hlaeja.service.DeviceRegistryService
|
||||
import ltd.hlaeja.util.toDeviceResponse
|
||||
import org.springframework.web.bind.annotation.GetMapping
|
||||
import org.springframework.web.bind.annotation.RequestHeader
|
||||
@@ -12,12 +14,17 @@ import org.springframework.web.bind.annotation.RestController
|
||||
@RequestMapping("/configuration")
|
||||
class ConfigurationController(
|
||||
private val configurationService: DeviceConfigurationService,
|
||||
private val jwtService: JwtService,
|
||||
private val deviceRegistry: DeviceRegistryService,
|
||||
private val publicJwtService: PublicJwtService,
|
||||
) {
|
||||
|
||||
@GetMapping
|
||||
suspend fun getNodeConfiguration(
|
||||
@RequestHeader("Identity") identityToken: String,
|
||||
): Map<String, String> = jwtService.getIdentity(identityToken)
|
||||
): Map<String, String> = readIdentityToken(identityToken)
|
||||
.let { deviceRegistry.getIdentityFromDevice(it) }
|
||||
.let { configurationService.getConfiguration(it.node).toDeviceResponse() }
|
||||
|
||||
private fun readIdentityToken(identityToken: String): UUID = publicJwtService
|
||||
.verify(identityToken) { claims -> UUID.fromString(claims.payload["device"] as String) }
|
||||
}
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
package ltd.hlaeja.controller
|
||||
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.jwt.service.PublicJwtService
|
||||
import ltd.hlaeja.library.deviceData.MeasurementData
|
||||
import ltd.hlaeja.library.deviceRegistry.Identity
|
||||
import ltd.hlaeja.service.DeviceDataService
|
||||
import ltd.hlaeja.service.JwtService
|
||||
import ltd.hlaeja.service.DeviceRegistryService
|
||||
import org.springframework.http.HttpStatus.CREATED
|
||||
import org.springframework.web.bind.annotation.GetMapping
|
||||
import org.springframework.web.bind.annotation.PostMapping
|
||||
@@ -16,13 +19,14 @@ import org.springframework.web.bind.annotation.RestController
|
||||
@RequestMapping("/measurement")
|
||||
class MeasurementController(
|
||||
private val dataService: DeviceDataService,
|
||||
private val jwtService: JwtService,
|
||||
private val deviceRegistry: DeviceRegistryService,
|
||||
private val publicJwtService: PublicJwtService,
|
||||
) {
|
||||
|
||||
@GetMapping
|
||||
suspend fun getNodeMeasurement(
|
||||
@RequestHeader("Identity") identityToken: String,
|
||||
): Map<String, Number> = jwtService.getIdentity(identityToken)
|
||||
): Map<String, Number> = readIdentityToken(identityToken)
|
||||
.let { dataService.getMeasurement(it.client, it.node).fields }
|
||||
|
||||
@PostMapping
|
||||
@@ -31,7 +35,7 @@ class MeasurementController(
|
||||
@RequestHeader("Identity") identityToken: String,
|
||||
@RequestBody measurement: Map<String, Number>,
|
||||
) {
|
||||
return jwtService.getIdentity(identityToken)
|
||||
return readIdentityToken(identityToken)
|
||||
.let {
|
||||
dataService.addMeasurement(
|
||||
it.client,
|
||||
@@ -45,4 +49,8 @@ class MeasurementController(
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
private suspend fun readIdentityToken(identityToken: String): Identity.Response = publicJwtService
|
||||
.verify(identityToken) { claims -> UUID.fromString(claims.payload["device"] as String) }
|
||||
.let { deviceRegistry.getIdentityFromDevice(it) }
|
||||
}
|
||||
|
||||
23
src/main/kotlin/ltd/hlaeja/exception/CacheException.kt
Normal file
23
src/main/kotlin/ltd/hlaeja/exception/CacheException.kt
Normal file
@@ -0,0 +1,23 @@
|
||||
package ltd.hlaeja.exception
|
||||
|
||||
@Suppress("unused")
|
||||
class CacheException : Exception {
|
||||
|
||||
constructor() : super()
|
||||
|
||||
constructor(message: String) : super(message)
|
||||
|
||||
constructor(cause: Throwable) : super(cause)
|
||||
|
||||
constructor(
|
||||
message: String,
|
||||
cause: Throwable,
|
||||
) : super(message, cause)
|
||||
|
||||
constructor(
|
||||
message: String,
|
||||
cause: Throwable,
|
||||
enableSuppression: Boolean,
|
||||
writableStackTrace: Boolean,
|
||||
) : super(message, cause, enableSuppression, writableStackTrace)
|
||||
}
|
||||
8
src/main/kotlin/ltd/hlaeja/property/CacheProperty.kt
Normal file
8
src/main/kotlin/ltd/hlaeja/property/CacheProperty.kt
Normal file
@@ -0,0 +1,8 @@
|
||||
package ltd.hlaeja.property
|
||||
|
||||
import org.springframework.boot.context.properties.ConfigurationProperties
|
||||
|
||||
@ConfigurationProperties(prefix = "cache")
|
||||
data class CacheProperty(
|
||||
val timeToLive: Long,
|
||||
)
|
||||
@@ -1,28 +1,47 @@
|
||||
package ltd.hlaeja.service
|
||||
|
||||
import io.github.oshai.kotlinlogging.KotlinLogging
|
||||
import io.micrometer.core.instrument.Counter
|
||||
import io.micrometer.core.instrument.MeterRegistry
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.library.deviceConfiguration.Node
|
||||
import ltd.hlaeja.property.DeviceConfigurationProperty
|
||||
import ltd.hlaeja.util.logCall
|
||||
import org.springframework.http.HttpStatus.NOT_FOUND
|
||||
import org.springframework.http.HttpStatus.NO_CONTENT
|
||||
import org.springframework.http.HttpStatus.REQUEST_TIMEOUT
|
||||
import ltd.hlaeja.util.deviceConfigurationGetConfiguration
|
||||
import org.springframework.http.HttpStatus.SERVICE_UNAVAILABLE
|
||||
import org.springframework.stereotype.Service
|
||||
import org.springframework.web.ErrorResponseException
|
||||
import org.springframework.web.reactive.function.client.WebClient
|
||||
import org.springframework.web.reactive.function.client.awaitBodyOrNull
|
||||
import org.springframework.web.reactive.function.client.WebClientRequestException
|
||||
import org.springframework.web.server.ResponseStatusException
|
||||
|
||||
private val log = KotlinLogging.logger {}
|
||||
|
||||
@Service
|
||||
class DeviceConfigurationService(
|
||||
meterRegistry: MeterRegistry,
|
||||
private val webClient: WebClient,
|
||||
private val deviceConfigurationProperty: DeviceConfigurationProperty,
|
||||
) {
|
||||
|
||||
private val deviceConfigurationSuccess = Counter.builder("device.configuration.success")
|
||||
.description("Number of successful device configuration calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
private val deviceConfigurationFailure = Counter.builder("device.configuration.failure")
|
||||
.description("Number of failed device configuration calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
suspend fun getConfiguration(
|
||||
node: UUID,
|
||||
): Node.Response = webClient.get()
|
||||
.uri("${deviceConfigurationProperty.url}/node-$node".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NO_CONTENT) }
|
||||
.awaitBodyOrNull<Node.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
): Node.Response = try {
|
||||
webClient.deviceConfigurationGetConfiguration(node, deviceConfigurationProperty)
|
||||
.also { deviceConfigurationSuccess.increment() }
|
||||
} catch (e: ErrorResponseException) {
|
||||
deviceConfigurationFailure.increment()
|
||||
throw e
|
||||
} catch (e: WebClientRequestException) {
|
||||
deviceConfigurationFailure.increment()
|
||||
log.error(e) { "Error device registry" }
|
||||
throw ResponseStatusException(SERVICE_UNAVAILABLE)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,39 +1,65 @@
|
||||
package ltd.hlaeja.service
|
||||
|
||||
import io.github.oshai.kotlinlogging.KotlinLogging
|
||||
import io.micrometer.core.instrument.Counter
|
||||
import io.micrometer.core.instrument.MeterRegistry
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.library.deviceData.MeasurementData
|
||||
import ltd.hlaeja.property.DeviceDataProperty
|
||||
import ltd.hlaeja.util.logCall
|
||||
import org.springframework.http.HttpStatus.NOT_FOUND
|
||||
import org.springframework.http.HttpStatus.NO_CONTENT
|
||||
import org.springframework.http.HttpStatus.REQUEST_TIMEOUT
|
||||
import ltd.hlaeja.util.deviceDataAddMeasurement
|
||||
import ltd.hlaeja.util.deviceDataGetMeasurement
|
||||
import org.springframework.http.HttpStatus.SERVICE_UNAVAILABLE
|
||||
import org.springframework.http.ResponseEntity
|
||||
import org.springframework.stereotype.Service
|
||||
import org.springframework.web.ErrorResponseException
|
||||
import org.springframework.web.reactive.function.client.WebClient
|
||||
import org.springframework.web.reactive.function.client.awaitBodilessEntity
|
||||
import org.springframework.web.reactive.function.client.awaitBodyOrNull
|
||||
import org.springframework.web.reactive.function.client.WebClientRequestException
|
||||
import org.springframework.web.server.ResponseStatusException
|
||||
|
||||
private val log = KotlinLogging.logger {}
|
||||
|
||||
@Service
|
||||
class DeviceDataService(
|
||||
meterRegistry: MeterRegistry,
|
||||
private val webClient: WebClient,
|
||||
private val deviceDataProperty: DeviceDataProperty,
|
||||
) {
|
||||
|
||||
private val deviceDataSuccess = Counter.builder("device.data.success")
|
||||
.description("Number of successful device data calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
private val deviceDataFailure = Counter.builder("device.data.failure")
|
||||
.description("Number of failed device data calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
suspend fun getMeasurement(
|
||||
client: UUID,
|
||||
node: UUID,
|
||||
): MeasurementData.Response = webClient.get()
|
||||
.uri("${deviceDataProperty.url}/client-$client/node-$node".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NO_CONTENT) }
|
||||
.awaitBodyOrNull<MeasurementData.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
): MeasurementData.Response = try {
|
||||
webClient.deviceDataGetMeasurement(client, node, deviceDataProperty)
|
||||
.also { deviceDataSuccess.increment() }
|
||||
} catch (e: ErrorResponseException) {
|
||||
deviceDataFailure.increment()
|
||||
throw e
|
||||
} catch (e: WebClientRequestException) {
|
||||
deviceDataFailure.increment()
|
||||
log.error(e) { "Error device registry" }
|
||||
throw ResponseStatusException(SERVICE_UNAVAILABLE)
|
||||
}
|
||||
|
||||
suspend fun addMeasurement(
|
||||
client: UUID,
|
||||
request: MeasurementData.Request,
|
||||
) = webClient.post()
|
||||
.uri("${deviceDataProperty.url}/client-$client".also(::logCall))
|
||||
.bodyValue(request)
|
||||
.retrieve()
|
||||
.awaitBodilessEntity()
|
||||
): ResponseEntity<Void> = try {
|
||||
webClient.deviceDataAddMeasurement(client, request, deviceDataProperty)
|
||||
.also { deviceDataSuccess.increment() }
|
||||
} catch (e: ErrorResponseException) {
|
||||
deviceDataFailure.increment()
|
||||
throw e
|
||||
} catch (e: WebClientRequestException) {
|
||||
deviceDataFailure.increment()
|
||||
log.error(e) { "Error device registry" }
|
||||
throw ResponseStatusException(SERVICE_UNAVAILABLE)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,28 +1,49 @@
|
||||
package ltd.hlaeja.service
|
||||
|
||||
import io.github.oshai.kotlinlogging.KotlinLogging
|
||||
import io.micrometer.core.instrument.Counter
|
||||
import io.micrometer.core.instrument.MeterRegistry
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.library.deviceRegistry.Identity
|
||||
import ltd.hlaeja.property.DeviceRegistryProperty
|
||||
import ltd.hlaeja.util.logCall
|
||||
import org.springframework.http.HttpStatus.NOT_ACCEPTABLE
|
||||
import org.springframework.http.HttpStatus.NOT_FOUND
|
||||
import org.springframework.http.HttpStatus.REQUEST_TIMEOUT
|
||||
import ltd.hlaeja.util.deviceRegistryIdentityDevice
|
||||
import org.springframework.cache.annotation.Cacheable
|
||||
import org.springframework.http.HttpStatus.SERVICE_UNAVAILABLE
|
||||
import org.springframework.stereotype.Service
|
||||
import org.springframework.web.ErrorResponseException
|
||||
import org.springframework.web.reactive.function.client.WebClient
|
||||
import org.springframework.web.reactive.function.client.awaitBodyOrNull
|
||||
import org.springframework.web.reactive.function.client.WebClientRequestException
|
||||
import org.springframework.web.server.ResponseStatusException
|
||||
|
||||
private val log = KotlinLogging.logger {}
|
||||
|
||||
@Service
|
||||
class DeviceRegistryService(
|
||||
meterRegistry: MeterRegistry,
|
||||
private val webClient: WebClient,
|
||||
private val deviceRegistryProperty: DeviceRegistryProperty,
|
||||
) {
|
||||
|
||||
private val identityDeviceSuccess = Counter.builder("device.identity.success")
|
||||
.description("Number of successful device identity calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
private val identityDeviceFailure = Counter.builder("device.identity.failure")
|
||||
.description("Number of failed device identity calls")
|
||||
.register(meterRegistry)
|
||||
|
||||
@Cacheable(value = ["identity"], key = "#device")
|
||||
suspend fun getIdentityFromDevice(
|
||||
device: UUID,
|
||||
): Identity.Response = webClient.get()
|
||||
.uri("${deviceRegistryProperty.url}/identity/device-$device".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NOT_ACCEPTABLE) }
|
||||
.awaitBodyOrNull<Identity.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
): Identity.Response = try {
|
||||
webClient.deviceRegistryIdentityDevice(device, deviceRegistryProperty)
|
||||
.also { identityDeviceSuccess.increment() }
|
||||
} catch (e: ErrorResponseException) {
|
||||
identityDeviceFailure.increment()
|
||||
throw e
|
||||
} catch (e: WebClientRequestException) {
|
||||
identityDeviceFailure.increment()
|
||||
log.error(e) { "Error device identity" }
|
||||
throw ResponseStatusException(SERVICE_UNAVAILABLE)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,34 +0,0 @@
|
||||
package ltd.hlaeja.service
|
||||
|
||||
import io.jsonwebtoken.JwtParser
|
||||
import io.jsonwebtoken.Jwts
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.library.deviceRegistry.Identity
|
||||
import ltd.hlaeja.property.JwtProperty
|
||||
import ltd.hlaeja.util.PublicKeyProvider
|
||||
import mu.KotlinLogging
|
||||
import org.springframework.stereotype.Service
|
||||
|
||||
private val log = KotlinLogging.logger {}
|
||||
|
||||
@Service
|
||||
class JwtService(
|
||||
jwtProperty: JwtProperty,
|
||||
private val deviceRegistry: DeviceRegistryService,
|
||||
) {
|
||||
|
||||
private val parser: JwtParser = Jwts.parser()
|
||||
.verifyWith(PublicKeyProvider.load(jwtProperty.publicKey))
|
||||
.build()
|
||||
|
||||
suspend fun getIdentity(
|
||||
identityToken: String,
|
||||
): Identity.Response = readIdentity(identityToken)
|
||||
.let { deviceRegistry.getIdentityFromDevice(it) }
|
||||
|
||||
private suspend fun readIdentity(
|
||||
identity: String,
|
||||
): UUID = parser.parseSignedClaims(identity)
|
||||
.let { UUID.fromString(it.payload["device"] as String) }
|
||||
.also { log.debug("Identified client device: {}", it) }
|
||||
}
|
||||
@@ -1,9 +1,7 @@
|
||||
package ltd.hlaeja.util
|
||||
|
||||
import mu.KotlinLogging
|
||||
import io.github.oshai.kotlinlogging.KotlinLogging
|
||||
|
||||
private val log = KotlinLogging.logger {}
|
||||
|
||||
fun logCall(url: String) {
|
||||
log.debug("calling: {}", url)
|
||||
}
|
||||
fun logCall(url: String) = log.debug { "calling: $url" }
|
||||
|
||||
@@ -5,6 +5,6 @@ import ltd.hlaeja.library.deviceConfiguration.Node
|
||||
fun Node.Response.toDeviceResponse(): Map<String, String> {
|
||||
return mapOf(
|
||||
"version" to timestamp.toEpochSecond().toString(),
|
||||
"data" to configuration
|
||||
"data" to configuration,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -1,35 +0,0 @@
|
||||
package ltd.hlaeja.util
|
||||
|
||||
import java.security.KeyFactory
|
||||
import java.security.interfaces.RSAPublicKey
|
||||
import java.security.spec.X509EncodedKeySpec
|
||||
import java.util.Base64.getDecoder
|
||||
import ltd.hlaeja.exception.KeyProviderException
|
||||
|
||||
object PublicKeyProvider {
|
||||
|
||||
fun load(
|
||||
pemFile: String,
|
||||
): RSAPublicKey = readPublicPemFile(pemFile)
|
||||
.let(::makePublicKey)
|
||||
|
||||
private fun makePublicKey(
|
||||
publicKeyBytes: ByteArray,
|
||||
): RSAPublicKey = KeyFactory.getInstance("RSA")
|
||||
.generatePublic(X509EncodedKeySpec(publicKeyBytes)) as RSAPublicKey
|
||||
|
||||
private fun readPublicPemFile(
|
||||
publicKey: String,
|
||||
): ByteArray = javaClass.classLoader
|
||||
.getResource(publicKey)
|
||||
?.readText()
|
||||
?.let(::getPublicKeyByteArray)
|
||||
?: throw KeyProviderException("Could not load public key")
|
||||
|
||||
private fun getPublicKeyByteArray(
|
||||
keyText: String,
|
||||
): ByteArray = keyText.replace(Regex("[\r\n]+"), "")
|
||||
.removePrefix("-----BEGIN PUBLIC KEY-----")
|
||||
.removeSuffix("-----END PUBLIC KEY-----")
|
||||
.let { getDecoder().decode(it) }
|
||||
}
|
||||
56
src/main/kotlin/ltd/hlaeja/util/WebClientCalls.kt
Normal file
56
src/main/kotlin/ltd/hlaeja/util/WebClientCalls.kt
Normal file
@@ -0,0 +1,56 @@
|
||||
package ltd.hlaeja.util
|
||||
|
||||
import java.util.UUID
|
||||
import ltd.hlaeja.library.deviceConfiguration.Node
|
||||
import ltd.hlaeja.library.deviceData.MeasurementData
|
||||
import ltd.hlaeja.library.deviceRegistry.Identity
|
||||
import ltd.hlaeja.property.DeviceConfigurationProperty
|
||||
import ltd.hlaeja.property.DeviceDataProperty
|
||||
import ltd.hlaeja.property.DeviceRegistryProperty
|
||||
import org.springframework.http.HttpStatus.NOT_ACCEPTABLE
|
||||
import org.springframework.http.HttpStatus.NOT_FOUND
|
||||
import org.springframework.http.HttpStatus.NO_CONTENT
|
||||
import org.springframework.http.HttpStatus.REQUEST_TIMEOUT
|
||||
import org.springframework.http.ResponseEntity
|
||||
import org.springframework.web.reactive.function.client.WebClient
|
||||
import org.springframework.web.reactive.function.client.awaitBodilessEntity
|
||||
import org.springframework.web.reactive.function.client.awaitBodyOrNull
|
||||
import org.springframework.web.server.ResponseStatusException
|
||||
|
||||
suspend fun WebClient.deviceRegistryIdentityDevice(
|
||||
device: UUID,
|
||||
property: DeviceRegistryProperty,
|
||||
): Identity.Response = get()
|
||||
.uri("${property.url}/identity/device-$device".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NOT_ACCEPTABLE) }
|
||||
.awaitBodyOrNull<Identity.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
|
||||
suspend fun WebClient.deviceDataGetMeasurement(
|
||||
client: UUID,
|
||||
node: UUID,
|
||||
property: DeviceDataProperty,
|
||||
): MeasurementData.Response = get()
|
||||
.uri("${property.url}/client-$client/node-$node".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NO_CONTENT) }
|
||||
.awaitBodyOrNull<MeasurementData.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
|
||||
suspend fun WebClient.deviceDataAddMeasurement(
|
||||
client: UUID,
|
||||
request: MeasurementData.Request,
|
||||
property: DeviceDataProperty,
|
||||
): ResponseEntity<Void> = post()
|
||||
.uri("${property.url}/client-$client".also(::logCall))
|
||||
.bodyValue(request)
|
||||
.retrieve()
|
||||
.awaitBodilessEntity()
|
||||
|
||||
suspend fun WebClient.deviceConfigurationGetConfiguration(
|
||||
node: UUID,
|
||||
property: DeviceConfigurationProperty,
|
||||
): Node.Response = get()
|
||||
.uri("${property.url}/node-$node".also(::logCall))
|
||||
.retrieve()
|
||||
.onStatus(NOT_FOUND::equals) { throw ResponseStatusException(NO_CONTENT) }
|
||||
.awaitBodyOrNull<Node.Response>() ?: throw ResponseStatusException(REQUEST_TIMEOUT)
|
||||
@@ -20,11 +20,6 @@
|
||||
"type": "java.lang.String",
|
||||
"description": "Application build os version."
|
||||
},
|
||||
{
|
||||
"name": "jwt.public-key",
|
||||
"type": "java.lang.String",
|
||||
"description": "Jwt public key file."
|
||||
},
|
||||
{
|
||||
"name": "device-registry.url",
|
||||
"type": "java.lang.String",
|
||||
@@ -39,6 +34,11 @@
|
||||
"name": "device-configuration.url",
|
||||
"type": "java.lang.String",
|
||||
"description": "Url for device configuration service."
|
||||
},
|
||||
{
|
||||
"name": "cache.time-to-live",
|
||||
"type": "java.lang.Long",
|
||||
"description": "Cache expiration in minutes."
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -9,6 +9,34 @@ spring:
|
||||
os:
|
||||
name: "%APP_BUILD_OS_NAME%"
|
||||
version: "%APP_BUILD_OS_VERSION%"
|
||||
cache:
|
||||
type: redis
|
||||
data:
|
||||
redis:
|
||||
port: 6379
|
||||
database: 1
|
||||
|
||||
management:
|
||||
endpoints:
|
||||
enabled-by-default: false
|
||||
web:
|
||||
exposure:
|
||||
include: "health,info"
|
||||
endpoint:
|
||||
health:
|
||||
enabled: true
|
||||
show-details: always
|
||||
info:
|
||||
enabled: true
|
||||
influx:
|
||||
metrics:
|
||||
export:
|
||||
api-version: v2
|
||||
bucket: hlaeja
|
||||
org: hlaeja_ltd
|
||||
|
||||
cache:
|
||||
time-to-live: 10
|
||||
|
||||
jwt:
|
||||
public-key: cert/public_key.pem
|
||||
@@ -21,6 +49,19 @@ spring:
|
||||
config:
|
||||
activate:
|
||||
on-profile: development
|
||||
data:
|
||||
redis:
|
||||
host: localhost
|
||||
|
||||
management:
|
||||
metrics:
|
||||
tags:
|
||||
application: device-api
|
||||
influx:
|
||||
metrics:
|
||||
export:
|
||||
enabled: false
|
||||
token: %INFLUXDB_TOKEN%
|
||||
|
||||
server:
|
||||
port: 8443
|
||||
@@ -47,6 +88,18 @@ spring:
|
||||
config:
|
||||
activate:
|
||||
on-profile: docker
|
||||
data:
|
||||
redis:
|
||||
host: Redis
|
||||
|
||||
management:
|
||||
metrics:
|
||||
tags:
|
||||
application: device-api
|
||||
influx:
|
||||
metrics:
|
||||
export:
|
||||
uri: http://InfluxDB:8086
|
||||
|
||||
server:
|
||||
port: 8443
|
||||
|
||||
10
src/test/resources/application.yml
Normal file
10
src/test/resources/application.yml
Normal file
@@ -0,0 +1,10 @@
|
||||
jwt:
|
||||
public-key: cert/valid-public-key.pem
|
||||
device-registry:
|
||||
url: http://localhost:9010
|
||||
device-data:
|
||||
url: http://localhost:9020
|
||||
device-configuration:
|
||||
url: http://localhost:9030
|
||||
cache:
|
||||
time-to-live: 10
|
||||
9
src/test/resources/cert/valid-public-key.pem
Normal file
9
src/test/resources/cert/valid-public-key.pem
Normal file
@@ -0,0 +1,9 @@
|
||||
-----BEGIN PUBLIC KEY-----
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3ZdlbISX729m5Ur1pVhg
|
||||
XIvazcgUt0T0G32ML0tfwQ4aWTfwPII0SQRThaN6eiiBMRa0V8JMih1LT8JmGgst
|
||||
dEx2nhMbVs/Osu8MhmP86c+HB/jPa1+0IR1TZKXoZoF52D2ZtoVf+mOWggAcm1R+
|
||||
V0Fj2cR/pgLkVt3GKUE2OokFC1iFUQFjThd1EzKcOv53TUek8FY8t66npQ4t3unD
|
||||
bXZKoGXMuXCqZVykMbGTUQFRuT3NAOXRrJP+UDeY2uM2Yk98J+8FtLDYD6jpmyi0
|
||||
ghv6k8pK1w1n5NI3atVv5ZMUeQZ36AXL8SZi1105mamhLVQ0e0JixoMOPh7ziFyv
|
||||
uwIDAQAB
|
||||
-----END PUBLIC KEY-----
|
||||
Reference in New Issue
Block a user