|
10 | 10 |
|
11 | 11 | from powerdns_api_proxy.config import ( |
12 | 12 | check_pdns_search_allowed, |
| 13 | + check_pdns_cryptokeys_allowed, |
13 | 14 | check_pdns_tsigkeys_allowed, |
14 | 15 | check_pdns_zone_admin, |
15 | 16 | check_pdns_zone_allowed, |
@@ -480,6 +481,115 @@ async def search_data( |
480 | 481 | return JSONResponse(content=pdns_response.data, status_code=status_code) |
481 | 482 |
|
482 | 483 |
|
| 484 | +@router_pdns.get("/servers/{server_id}/zones/{zone_id}/cryptokeys") |
| 485 | +async def list_cryptokeys(server_id: str, zone_id: str, X_API_Key: str = Header()): |
| 486 | + """ |
| 487 | + Get all CryptoKeys for a zone, except the private key. |
| 488 | +
|
| 489 | + <https://doc.powerdns.com/authoritative/http-api/cryptokey.html#get--servers-server_id-zones-zone_id-cryptokeys> |
| 490 | + """ |
| 491 | + environment = get_environment_for_token(config, X_API_Key) |
| 492 | + if not check_pdns_cryptokeys_allowed(environment, zone_id): |
| 493 | + logger.info(f"CryptoKeys not allowed for environment {environment.name}") |
| 494 | + raise ZoneNotAllowedException() |
| 495 | + resp = await pdns.get(f"/api/v1/servers/{server_id}/zones/{zone_id}/cryptokeys") |
| 496 | + pdns_response = await handle_pdns_response(resp) |
| 497 | + status_code = pdns_response.raise_for_error() |
| 498 | + return JSONResponse(content=pdns_response.data, status_code=status_code) |
| 499 | + |
| 500 | + |
| 501 | +@router_pdns.post("/servers/{server_id}/zones/{zone_id}/cryptokeys") |
| 502 | +async def create_cryptokey( |
| 503 | + request: Request, server_id: str, zone_id: str, X_API_Key: str = Header() |
| 504 | +): |
| 505 | + """ |
| 506 | + Creates a Cryptokey. |
| 507 | +
|
| 508 | + This method adds a new key to a zone. |
| 509 | +
|
| 510 | + <https://doc.powerdns.com/authoritative/http-api/cryptokey.html#post--servers-server_id-zones-zone_id-cryptokeys> |
| 511 | + """ |
| 512 | + environment = get_environment_for_token(config, X_API_Key) |
| 513 | + if not check_pdns_cryptokeys_allowed(environment, zone_id): |
| 514 | + logger.info(f"CryptoKeys not allowed for environment {environment.name}") |
| 515 | + raise ZoneNotAllowedException() |
| 516 | + resp = await pdns.post( |
| 517 | + f"/api/v1/servers/{server_id}/zones/{zone_id}/cryptokeys", |
| 518 | + payload=await request.json(), |
| 519 | + ) |
| 520 | + pdns_response = await handle_pdns_response(resp) |
| 521 | + status_code = pdns_response.raise_for_error() |
| 522 | + return JSONResponse(content=pdns_response.data, status_code=status_code) |
| 523 | + |
| 524 | + |
| 525 | +@router_pdns.get("/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}") |
| 526 | +async def fetch_cryptokey( |
| 527 | + server_id: str, zone_id: str, cryptokey_id: str, X_API_Key: str = Header() |
| 528 | +): |
| 529 | + """ |
| 530 | + Returns all data about the CryptoKey, including the private key. |
| 531 | +
|
| 532 | + <https://doc.powerdns.com/authoritative/http-api/cryptokey.html#get--servers-server_id-zones-zone_id-cryptokeys-cryptokey_id> |
| 533 | + """ |
| 534 | + environment = get_environment_for_token(config, X_API_Key) |
| 535 | + if not check_pdns_cryptokeys_allowed(environment, zone_id): |
| 536 | + logger.info(f"CryptoKeys not allowed for environment {environment.name}") |
| 537 | + raise ZoneNotAllowedException() |
| 538 | + resp = await pdns.get( |
| 539 | + f"/api/v1/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}" |
| 540 | + ) |
| 541 | + pdns_response = await handle_pdns_response(resp) |
| 542 | + status_code = pdns_response.raise_for_error() |
| 543 | + return JSONResponse(content=pdns_response.data, status_code=status_code) |
| 544 | + |
| 545 | + |
| 546 | +@router_pdns.put("/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}") |
| 547 | +async def update_cryptokey( |
| 548 | + request: Request, |
| 549 | + server_id: str, |
| 550 | + zone_id: str, |
| 551 | + cryptokey_id: str, |
| 552 | + X_API_Key: str = Header(), |
| 553 | +): |
| 554 | + """ |
| 555 | + This method (de)activates a key from zone_name specified by cryptokey_id. |
| 556 | +
|
| 557 | + <https://doc.powerdns.com/authoritative/http-api/cryptokey.html#put--servers-server_id-zones-zone_id-cryptokeys-cryptokey_id> |
| 558 | + """ |
| 559 | + environment = get_environment_for_token(config, X_API_Key) |
| 560 | + if not check_pdns_cryptokeys_allowed(environment, zone_id): |
| 561 | + logger.info(f"CryptoKeys not allowed for environment {environment.name}") |
| 562 | + raise ZoneNotAllowedException() |
| 563 | + resp = await pdns.put( |
| 564 | + f"/api/v1/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}", |
| 565 | + payload=await request.json(), |
| 566 | + ) |
| 567 | + pdns_response = await handle_pdns_response(resp) |
| 568 | + status_code = pdns_response.raise_for_error() |
| 569 | + return JSONResponse(content=pdns_response.data, status_code=status_code) |
| 570 | + |
| 571 | + |
| 572 | +@router_pdns.delete("/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}") |
| 573 | +async def delete_cryptokey( |
| 574 | + server_id: str, zone_id: str, cryptokey_id: str, X_API_Key: str = Header() |
| 575 | +): |
| 576 | + """ |
| 577 | + This method deletes a key specified by cryptokey_id. |
| 578 | +
|
| 579 | + <https://doc.powerdns.com/authoritative/http-api/cryptokey.html#delete--servers-server_id-zones-zone_id-cryptokeys-cryptokey_id> |
| 580 | + """ |
| 581 | + environment = get_environment_for_token(config, X_API_Key) |
| 582 | + if not check_pdns_cryptokeys_allowed(environment, zone_id): |
| 583 | + logger.info(f"CryptoKeys not allowed for environment {environment.name}") |
| 584 | + raise ZoneNotAllowedException() |
| 585 | + resp = await pdns.delete( |
| 586 | + f"/api/v1/servers/{server_id}/zones/{zone_id}/cryptokeys/{cryptokey_id}" |
| 587 | + ) |
| 588 | + pdns_response = await handle_pdns_response(resp) |
| 589 | + status_code = pdns_response.raise_for_error() |
| 590 | + return JSONResponse(content=pdns_response.data, status_code=status_code) |
| 591 | + |
| 592 | + |
483 | 593 | @router_pdns.get("/servers/{server_id}/tsigkeys") |
484 | 594 | async def list_tsigkeys(server_id: str, X_API_Key: str = Header()): |
485 | 595 | """ |
|
0 commit comments