acf574af64
* lang/qt/src/Makefile.am, lang/qt/tests/Makefile.am (AM_CPPFLAGS): Add builddir instead of srcdir of C++ bindings as include path. * lang/qt/src/changeexpiryjob.cpp, lang/qt/src/changeexpiryjob.h, lang/qt/src/changeownertrustjob.h, lang/qt/src/dataprovider.cpp, lang/qt/src/dataprovider.h, lang/qt/src/debug.cpp, lang/qt/src/decryptverifyarchivejob.cpp, lang/qt/src/decryptverifyarchivejob.h, lang/qt/src/encryptarchivejob.cpp, lang/qt/src/encryptarchivejob.h, lang/qt/src/encryptjob.h, lang/qt/src/encryptjob_p.h, lang/qt/src/filelistdataprovider.cpp, lang/qt/src/filelistdataprovider.h, lang/qt/src/hierarchicalkeylistjob.h, lang/qt/src/importjob.cpp, lang/qt/src/importjob.h, lang/qt/src/importjob_p.h, lang/qt/src/job.h, lang/qt/src/keyformailboxjob.h, lang/qt/src/keylistjob.h, lang/qt/src/listallkeysjob.h, lang/qt/src/multideletejob.cpp, lang/qt/src/qgpgmeaddexistingsubkeyjob.cpp, lang/qt/src/qgpgmeadduseridjob.cpp, lang/qt/src/qgpgmebackend.cpp, lang/qt/src/qgpgmechangeexpiryjob.cpp, lang/qt/src/qgpgmechangeownertrustjob.cpp, lang/qt/src/qgpgmechangepasswdjob.cpp, lang/qt/src/qgpgmedecryptjob.cpp, lang/qt/src/qgpgmedecryptjob.h, lang/qt/src/qgpgmedecryptverifyarchivejob.cpp, lang/qt/src/qgpgmedecryptverifyarchivejob.h, lang/qt/src/qgpgmedecryptverifyjob.cpp, lang/qt/src/qgpgmedecryptverifyjob.h, lang/qt/src/qgpgmedeletejob.cpp, lang/qt/src/qgpgmedownloadjob.cpp, lang/qt/src/qgpgmeencryptarchivejob.cpp, lang/qt/src/qgpgmeencryptarchivejob.h, lang/qt/src/qgpgmeencryptjob.cpp, lang/qt/src/qgpgmeencryptjob.h, lang/qt/src/qgpgmeexportjob.cpp, lang/qt/src/qgpgmeimportfromkeyserverjob.cpp, lang/qt/src/qgpgmeimportfromkeyserverjob.h, lang/qt/src/qgpgmeimportjob.cpp, lang/qt/src/qgpgmeimportjob.h, lang/qt/src/qgpgmekeyformailboxjob.h, lang/qt/src/qgpgmekeygenerationjob.cpp, lang/qt/src/qgpgmekeygenerationjob.h, lang/qt/src/qgpgmekeylistjob.cpp, lang/qt/src/qgpgmekeylistjob.h, lang/qt/src/qgpgmelistallkeysjob.cpp, lang/qt/src/qgpgmelistallkeysjob.h, lang/qt/src/qgpgmenewcryptoconfig.cpp, lang/qt/src/qgpgmenewcryptoconfig.h, lang/qt/src/qgpgmequickjob.cpp, lang/qt/src/qgpgmereceivekeysjob.h, lang/qt/src/qgpgmerefreshsmimekeysjob.cpp, lang/qt/src/qgpgmerefreshsmimekeysjob.h, lang/qt/src/qgpgmerevokekeyjob.cpp, lang/qt/src/qgpgmesetprimaryuseridjob.cpp, lang/qt/src/qgpgmesignarchivejob.cpp, lang/qt/src/qgpgmesignarchivejob.h, lang/qt/src/qgpgmesignencryptarchivejob.cpp, lang/qt/src/qgpgmesignencryptarchivejob.h, lang/qt/src/qgpgmesignencryptjob.cpp, lang/qt/src/qgpgmesignencryptjob.h, lang/qt/src/qgpgmesignjob.cpp, lang/qt/src/qgpgmesignjob.h, lang/qt/src/qgpgmesignkeyjob.cpp, lang/qt/src/qgpgmetofupolicyjob.cpp, lang/qt/src/qgpgmeverifydetachedjob.cpp, lang/qt/src/qgpgmeverifydetachedjob.h, lang/qt/src/qgpgmeverifyopaquejob.cpp, lang/qt/src/qgpgmeverifyopaquejob.h, lang/qt/src/qgpgmewkdlookupjob.cpp, lang/qt/src/qgpgmewkdrefreshjob.cpp, lang/qt/src/qgpgmewkdrefreshjob.h, lang/qt/src/qgpgmewkspublishjob.cpp, lang/qt/src/quickjob.h, lang/qt/src/signarchivejob.cpp, lang/qt/src/signarchivejob.h, lang/qt/src/signencryptarchivejob.cpp, lang/qt/src/signencryptarchivejob.h, lang/qt/src/signencryptjob.h, lang/qt/src/signencryptjob_p.h, lang/qt/src/signjob.h, lang/qt/src/signjob_p.h, lang/qt/src/threadedjobmixin.cpp, lang/qt/src/threadedjobmixin.h, lang/qt/src/tofupolicyjob.h, lang/qt/src/util.cpp, lang/qt/src/wkdlookupresult.cpp, lang/qt/src/wkdlookupresult.h, lang/qt/src/wkdrefreshjob_p.h, lang/qt/tests/run-decryptverifyarchivejob.cpp, lang/qt/tests/run-decryptverifyjob.cpp, lang/qt/tests/run-encryptarchivejob.cpp, lang/qt/tests/run-encryptjob.cpp, lang/qt/tests/run-exportjob.cpp, lang/qt/tests/run-importjob.cpp, lang/qt/tests/run-keyformailboxjob.cpp, lang/qt/tests/run-receivekeysjob.cpp, lang/qt/tests/run-refreshkeysjob.cpp, lang/qt/tests/run-signarchivejob.cpp, lang/qt/tests/run-signjob.cpp, lang/qt/tests/run-verifydetachedjob.cpp, lang/qt/tests/run-verifyopaquejob.cpp, lang/qt/tests/run-wkdrefreshjob.cpp, lang/qt/tests/t-addexistingsubkey.cpp, lang/qt/tests/t-changeexpiryjob.cpp, lang/qt/tests/t-config.cpp, lang/qt/tests/t-decryptverify.cpp, lang/qt/tests/t-encrypt.cpp, lang/qt/tests/t-import.cpp, lang/qt/tests/t-keylist.cpp, lang/qt/tests/t-keylocate.cpp, lang/qt/tests/t-ownertrust.cpp, lang/qt/tests/t-remarks.cpp, lang/qt/tests/t-revokekey.cpp, lang/qt/tests/t-setprimaryuserid.cpp, lang/qt/tests/t-support.cpp, lang/qt/tests/t-support.h, lang/qt/tests/t-tofuinfo.cpp, lang/qt/tests/t-trustsignatures.cpp, lang/qt/tests/t-various.cpp, lang/qt/tests/t-verify.cpp, lang/qt/tests/t-wkdlookup.cpp, lang/qt/tests/t-wkspublish.cpp: Include GpgME++ headers with gpgme++/ prefix. -- This prepares the Qt bindings for building them separately from the C++ bindings. GnuPG-bug-id: 7110
243 lines
7.7 KiB
C++
243 lines
7.7 KiB
C++
/*
|
|
qgpgmesignkeyjob.cpp
|
|
|
|
This file is part of qgpgme, the Qt API binding for gpgme
|
|
Copyright (c) 2008 Klarälvdalens Datakonsult AB
|
|
Copyright (c) 2016 by Bundesamt für Sicherheit in der Informationstechnik
|
|
Software engineering by Intevation GmbH
|
|
|
|
QGpgME is free software; you can redistribute it and/or
|
|
modify it under the terms of the GNU General Public License as
|
|
published by the Free Software Foundation; either version 2 of the
|
|
License, or (at your option) any later version.
|
|
|
|
QGpgME is distributed in the hope that it will be useful,
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
General Public License for more details.
|
|
|
|
You should have received a copy of the GNU General Public License along
|
|
with this program; if not, write to the Free Software Foundation, Inc.,
|
|
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
|
|
|
In addition, as a special exception, the copyright holders give
|
|
permission to link the code of this program with any edition of
|
|
the Qt library by Trolltech AS, Norway (or with modified versions
|
|
of Qt that use the same license as Qt), and distribute linked
|
|
combinations including the two. You must obey the GNU General
|
|
Public License in all respects for all of the code used other than
|
|
Qt. If you modify this file, you may extend this exception to
|
|
your version of the file, but you are not obligated to do so. If
|
|
you do not wish to do so, delete this exception statement from
|
|
your version.
|
|
*/
|
|
|
|
#ifdef HAVE_CONFIG_H
|
|
#include "config.h"
|
|
#endif
|
|
|
|
#include "qgpgmesignkeyjob.h"
|
|
|
|
#include <QDate>
|
|
#include <QString>
|
|
|
|
#include "dataprovider.h"
|
|
|
|
#include <gpgme++/context.h>
|
|
#include <gpgme++/data.h>
|
|
#include <gpgme++/gpgsignkeyeditinteractor.h>
|
|
|
|
#include "qgpgme_debug.h"
|
|
|
|
#include <cassert>
|
|
|
|
using namespace QGpgME;
|
|
using namespace GpgME;
|
|
|
|
namespace
|
|
{
|
|
struct TrustSignatureProperties {
|
|
TrustSignatureProperties() = default;
|
|
// needed for C++11 because until C++14 "aggregate initialization requires
|
|
// class type, that has no default member initializers"
|
|
TrustSignatureProperties(TrustSignatureTrust trust_, unsigned int depth_, const QString &scope_)
|
|
: trust{trust_}
|
|
, depth{depth_}
|
|
, scope{scope_}
|
|
{}
|
|
|
|
TrustSignatureTrust trust = TrustSignatureTrust::None;
|
|
unsigned int depth = 0;
|
|
QString scope;
|
|
};
|
|
}
|
|
|
|
class QGpgMESignKeyJob::Private
|
|
{
|
|
public:
|
|
Private() = default;
|
|
|
|
std::vector<unsigned int> m_userIDsToSign;
|
|
GpgME::Key m_signingKey;
|
|
unsigned int m_checkLevel = 0;
|
|
bool m_exportable = false;
|
|
bool m_nonRevocable = false;
|
|
bool m_started = false;
|
|
bool m_dupeOk = false;
|
|
QString m_remark;
|
|
TrustSignatureProperties m_trustSignature;
|
|
QDate m_expiration;
|
|
};
|
|
|
|
QGpgMESignKeyJob::QGpgMESignKeyJob(Context *context)
|
|
: mixin_type(context)
|
|
, d{std::unique_ptr<Private>(new Private())}
|
|
{
|
|
lateInitialization();
|
|
}
|
|
|
|
QGpgMESignKeyJob::~QGpgMESignKeyJob() {}
|
|
|
|
static QGpgMESignKeyJob::result_type sign_key(Context *ctx, const Key &key, const std::vector<unsigned int> &uids,
|
|
unsigned int checkLevel, const Key &signer, unsigned int opts,
|
|
bool dupeOk, const QString &remark,
|
|
const TrustSignatureProperties &trustSignature,
|
|
const QDate &expirationDate)
|
|
{
|
|
QGpgME::QByteArrayDataProvider dp;
|
|
Data data(&dp);
|
|
|
|
GpgSignKeyEditInteractor *skei(new GpgSignKeyEditInteractor);
|
|
skei->setUserIDsToSign(uids);
|
|
skei->setCheckLevel(checkLevel);
|
|
skei->setSigningOptions(opts);
|
|
skei->setKey(key);
|
|
|
|
if (dupeOk) {
|
|
ctx->setFlag("extended-edit", "1");
|
|
skei->setDupeOk(true);
|
|
}
|
|
|
|
if (!remark.isEmpty()) {
|
|
ctx->addSignatureNotation("rem@gnupg.org", remark.toUtf8().constData());
|
|
}
|
|
|
|
if (opts & GpgSignKeyEditInteractor::Trust) {
|
|
skei->setTrustSignatureTrust(trustSignature.trust);
|
|
skei->setTrustSignatureDepth(trustSignature.depth);
|
|
skei->setTrustSignatureScope(trustSignature.scope.toUtf8().toStdString());
|
|
}
|
|
|
|
if (!signer.isNull()) {
|
|
if (const Error err = ctx->addSigningKey(signer)) {
|
|
return std::make_tuple(err, QString(), Error());
|
|
}
|
|
}
|
|
|
|
if (expirationDate.isValid()) {
|
|
// on 2106-02-07, the Unix time will reach 0xFFFFFFFF; since gpg uses uint32 internally
|
|
// for the expiration date clip it at 2106-02-05 to avoid problems with negative time zones
|
|
static const QDate maxAllowedDate{2106, 2, 5};
|
|
const auto clippedExpirationDate = expirationDate <= maxAllowedDate ? expirationDate : maxAllowedDate;
|
|
if (clippedExpirationDate != expirationDate) {
|
|
qCDebug(QGPGME_LOG) << "Expiration of certification has been changed to" << clippedExpirationDate;
|
|
}
|
|
// use the "days from now" format to specify the expiration date of the certification;
|
|
// this format is the most appropriate regardless of the local timezone
|
|
const auto daysFromNow = QDate::currentDate().daysTo(clippedExpirationDate);
|
|
if (daysFromNow > 0) {
|
|
const auto certExpire = std::to_string(daysFromNow) + "d";
|
|
ctx->setFlag("cert-expire", certExpire.c_str());
|
|
}
|
|
} else {
|
|
// explicitly set "cert-expire" to "0" (no expiration) to override default-cert-expire set in gpg.conf
|
|
ctx->setFlag("cert-expire", "0");
|
|
}
|
|
|
|
const Error err = ctx->edit(key, std::unique_ptr<EditInteractor> (skei), data);
|
|
Error ae;
|
|
const QString log = _detail::audit_log_as_html(ctx, ae);
|
|
return std::make_tuple(err, log, ae);
|
|
}
|
|
|
|
Error QGpgMESignKeyJob::start(const Key &key)
|
|
{
|
|
unsigned int opts = 0;
|
|
if (d->m_nonRevocable) {
|
|
opts |= GpgSignKeyEditInteractor::NonRevocable;
|
|
}
|
|
if (d->m_exportable) {
|
|
opts |= GpgSignKeyEditInteractor::Exportable;
|
|
}
|
|
switch (d->m_trustSignature.trust) {
|
|
case TrustSignatureTrust::Partial:
|
|
case TrustSignatureTrust::Complete:
|
|
opts |= GpgSignKeyEditInteractor::Trust;
|
|
break;
|
|
default:
|
|
opts &= ~GpgSignKeyEditInteractor::Trust;
|
|
break;
|
|
}
|
|
run(std::bind(&sign_key, std::placeholders::_1, key, d->m_userIDsToSign, d->m_checkLevel, d->m_signingKey,
|
|
opts, d->m_dupeOk, d->m_remark, d->m_trustSignature, d->m_expiration));
|
|
d->m_started = true;
|
|
return Error();
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setUserIDsToSign(const std::vector<unsigned int> &idsToSign)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_userIDsToSign = idsToSign;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setCheckLevel(unsigned int checkLevel)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_checkLevel = checkLevel;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setExportable(bool exportable)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_exportable = exportable;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setSigningKey(const Key &key)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_signingKey = key;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setNonRevocable(bool nonRevocable)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_nonRevocable = nonRevocable;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setRemark(const QString &remark)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_remark = remark;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setDupeOk(bool value)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_dupeOk = value;
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setTrustSignature(GpgME::TrustSignatureTrust trust, unsigned short depth, const QString &scope)
|
|
{
|
|
assert(!d->m_started);
|
|
assert(depth <= 255);
|
|
d->m_trustSignature = {trust, depth, scope};
|
|
}
|
|
|
|
void QGpgMESignKeyJob::setExpirationDate(const QDate &expiration)
|
|
{
|
|
assert(!d->m_started);
|
|
d->m_expiration = expiration;
|
|
}
|
|
|
|
#include "qgpgmesignkeyjob.moc"
|