|
@@ -376,6 +376,27 @@ Result<void> CredentialStore::update(const std::string& id, const UpdateCredenti
|
|
|
};
|
|
};
|
|
|
break;
|
|
break;
|
|
|
}
|
|
}
|
|
|
|
|
+ case CredentialType::ClientCertificate: {
|
|
|
|
|
+ // Without this case the switch fell through to nothing, leaving
|
|
|
|
|
+ // data_to_encrypt null - so saving any edit to an mTLS
|
|
|
|
|
+ // credential encrypted an empty blob over the certificate and
|
|
|
|
|
+ // its key, and the credential silently stopped authenticating.
|
|
|
|
|
+ auto data = ClientCertificateData::fromJson(request_data);
|
|
|
|
|
+ if (data.certificate_pem.empty() || data.private_key_pem.empty()) {
|
|
|
|
|
+ return Error(ErrorCode::InvalidArgument,
|
|
|
|
|
+ "A client certificate needs both the certificate and its "
|
|
|
|
|
+ "private key");
|
|
|
|
|
+ }
|
|
|
|
|
+ data_to_encrypt = data.toJson();
|
|
|
|
|
+ public_data = {{"hasPrivateKey", true}};
|
|
|
|
|
+ break;
|
|
|
|
|
+ }
|
|
|
|
|
+ default:
|
|
|
|
|
+ // Every type this store knows how to create it must also know
|
|
|
|
|
+ // how to update. Anything else refuses loudly rather than
|
|
|
|
|
+ // encrypting nothing over the top of a working credential.
|
|
|
|
|
+ return Error(ErrorCode::InvalidArgument,
|
|
|
|
|
+ "This credential type cannot be updated");
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
auto encrypt_result = encryptData(data_to_encrypt);
|
|
auto encrypt_result = encryptData(data_to_encrypt);
|