1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210
defmodule ExOvh.Auth.Openstack.Swift.Cache do
@moduledoc :false
use GenServer
use Openstex.Cache
alias ExOvh.Auth.Openstack.Swift.Cache.Cloudstorage
alias ExOvh.Auth.Openstack.Swift.Cache.Webstorage
alias Openstex.Keystone.V2.Helpers.Identity
import ExOvh.Utils, only: [ets_tablename: 1]
@get_identity_retries 5
@get_identity_interval 1000
# Public
def start_link({ovh_client, swift_client}) do
Og.context(__ENV__, :debug)
GenServer.start_link(__MODULE__, {ovh_client, swift_client}, [name: swift_client])
end
# Pulic Opestex.Cache callbacks (public 'interface' to the Cache module)
def get_swift_public_url(swift_client) do
get_identity(swift_client)
|> Map.get(:service_catalog)
|> Enum.find(fn(%Identity.Service{} = service) -> service.name == "swift" end)
|> Map.get(:endpoints)
|> Enum.find(fn(%Identity.Endpoint{} = endpoint) -> endpoint.region == swift_client.config()[:region] end)
|> Map.get(:public_url)
end
def get_xauth_token(swift_client) do
get_identity(swift_client) |> Map.get(:token) |> Map.get(:id)
end
def get_account_tempurl_key(swift_client) do
swift_client.config() |> Keyword.fetch!(:account_temp_url_key)
end
# get_swift_endpoint/1-- use default implementation for `use Openstex.Cache`.
# get_swift_account/1 -- use default implementation for `use Openstex.Cache`.
# Genserver Callbacks
# trap exits so that terminate callback is invoked
# the :lock key is to allow for locking during the brief moment that the access token is being refreshed
def init({ovh_client, swift_client}) do
Og.context(__ENV__, :debug)
:erlang.process_flag(:trap_exit, :true)
create_ets_table(swift_client)
config = swift_client.config()
identity = create_identity({ovh_client, swift_client}, config, config[:type])
identity = Map.put(identity, :lock, :false)
:ets.insert(ets_tablename(swift_client), {:identity, identity})
try_to_set_temp_url_key(swift_client)
expiry = to_seconds(identity)
Task.start_link(fn -> monitor_expiry(expiry) end)
{:ok, {swift_client, identity}}
end
def handle_call(:add_lock, _from, {swift_client, identity}) do
Og.context(__ENV__, :debug)
new_identity = Map.put(identity, :lock, :true)
:ets.insert(ets_tablename(swift_client), {:identity, new_identity})
{:reply, :ok, {swift_client, new_identity}}
end
def handle_call(:remove_lock, _from, {swift_client, identity}) do
Og.context(__ENV__, :debug)
new_identity = Map.put(identity, :lock, :false)
:ets.insert(ets_tablename(swift_client), {:identity, new_identity})
{:reply, :ok, {swift_client, new_identity}}
end
def handle_call(:update_identity, _from, {swift_client, identity}) do
Og.context(__ENV__, :debug)
{:ok, new_identity} = get_identity(swift_client)
|> Map.put(identity, :lock, :false)
:ets.insert(ets_tablename(swift_client), {:identity, new_identity})
{:reply, :ok, {swift_client, new_identity}}
end
def handle_call(:stop, _from, state) do
Og.context(__ENV__, :debug)
{:stop, :shutdown, :ok, state}
end
def terminate(:shutdown, {swift_client, _identity}) do
Og.context(__ENV__, :debug)
:ets.delete(ets_tablename(swift_client)) # explicilty remove
:ok
end
# private
defp create_identity({ovh_client, swift_client}, config, :webstorage) do
Og.context(__ENV__, :debug)
Webstorage.create_identity({ovh_client, swift_client}, config)
end
defp create_identity({ovh_client, swift_client}, config, :cloudstorage) do
Og.context(__ENV__, :debug)
Cloudstorage.create_identity({ovh_client, swift_client}, config)
end
defp create_identity({_ovh_client, _swift_client}, _config, type) do
Og.context(__ENV__, :debug)
raise "create_identity/3 is only supported for the :webstorage and :cloudstorage types, #{inspect(type)}"
end
defp try_to_set_temp_url_key(swift_client) do
if Keyword.has_key?(swift_client.config(), :account_temp_url_key) do
temp_key = Keyword.get(swift_client.config(), :account_temp_url_key, :nil)
account = swift_client.account()
if temp_key != :nil do
resp = Openstex.Swift.V1.Query.account_info(account) |> swift_client.request!()
unless Map.has_key?(resp.headers, "X-Account-Meta-Temp-Url-Key") do
%Openstex.Openstack.Swift.Query{method: :post, uri: account, params: %{}}
|> swift_client.prepare_request()
|> Openstex.Utils.put_http_headers(%{"X-Account-Meta-Temp-URL-Key" => temp_key})
|> swift_client.request!()
end
end
end
end
defp get_identity(swift_client) do
get_identity(swift_client, 0)
end
defp get_identity(swift_client, index) do
Og.context(__ENV__, :debug)
retry = fn(swift_client, index) ->
if index > @get_identity_retries do
raise "Cannot retrieve openstack identity, #{__ENV__.module}, #{__ENV__.line}, client: #{swift_client}"
else
:timer.sleep(@get_identity_interval)
get_identity(swift_client, index + 1)
end
end
if ets_tablename(swift_client) in :ets.all() do
table = :ets.lookup(ets_tablename(swift_client), :identity)
case table do
[identity: identity] ->
if identity.lock === :true do
retry.(swift_client, index)
else
identity
end
[] -> retry.(swift_client, index)
end
else
retry.(swift_client, index)
end
end
defp monitor_expiry(expires) do
Og.context(__ENV__, :debug)
interval = (expires - 30) * 1000
:timer.sleep(interval)
{:reply, :ok, _identity} = GenServer.call(self(), :add_lock)
{:reply, :ok, _identity} = GenServer.call(self(), :update_identity)
{:reply, :ok, identity} = GenServer.call(self(), :remove_lock)
expires = to_seconds(identity.token.expires)
monitor_expiry(expires)
end
defp create_ets_table(swift_client) do
Og.context(__ENV__, :debug)
ets_options = [
:set, # type
:protected, # read - all, write this process only.
:named_table,
{:heir, :none}, # don't let any process inherit the table. when the ets table dies, it dies.
{:write_concurrency, :false},
{:read_concurrency, :true}
]
unless ets_tablename(swift_client) in :ets.all() do
:ets.new(ets_tablename(swift_client), ets_options)
end
end
defp to_seconds(identity) do
iso_time = identity.token.expires
{:ok, expiry_ndt, offset} = Calendar.NaiveDateTime.Parse.iso8601(iso_time)
offset =
case offset do
:nil -> 0
offset -> offset
end
{:ok, expiry_dt_utc} = Calendar.NaiveDateTime.with_offset_to_datetime_utc(expiry_ndt, offset)
{:ok, now} = Calendar.DateTime.from_erl(:calendar.universal_time(), "UTC")
{:ok, seconds, _microseconds, _when} = Calendar.DateTime.diff(expiry_dt_utc, now)
if seconds > 0 do
seconds
else
0
end
end
end