mirror of
https://github.com/certbot/certbot.git
synced 2026-08-04 12:21:51 +02:00
Merge pull request #9541 from certbot/remove-legacy-new-authz-support
account: stop storing legacy new_authzr_uri
This commit is contained in:
@@ -17,6 +17,7 @@ Certbot adheres to [Semantic Versioning](https://semver.org/).
|
|||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
|
* Fixed a crash when registering an account with BuyPass' ACME server.
|
||||||
* Fixed a bug where Certbot would crash with `AttributeError: can't set attribute` on ACME server errors in Python 3.11. See [GH #9539](https://github.com/certbot/certbot/issues/9539).
|
* Fixed a bug where Certbot would crash with `AttributeError: can't set attribute` on ACME server errors in Python 3.11. See [GH #9539](https://github.com/certbot/certbot/issues/9539).
|
||||||
|
|
||||||
More details about these changes can be found on our GitHub repo.
|
More details about these changes can be found on our GitHub repo.
|
||||||
|
|||||||
@@ -126,18 +126,6 @@ class AccountMemoryStorage(interfaces.AccountStorage):
|
|||||||
raise errors.AccountNotFound(account_id)
|
raise errors.AccountNotFound(account_id)
|
||||||
|
|
||||||
|
|
||||||
class RegistrationResourceWithNewAuthzrURI(messages.RegistrationResource):
|
|
||||||
"""A backwards-compatible RegistrationResource with a new-authz URI.
|
|
||||||
|
|
||||||
Hack: Certbot versions pre-0.11.1 expect to load
|
|
||||||
new_authzr_uri as part of the account. Because people
|
|
||||||
sometimes switch between old and new versions, we will
|
|
||||||
continue to write out this field for some time so older
|
|
||||||
clients don't crash in that scenario.
|
|
||||||
"""
|
|
||||||
new_authzr_uri: str = jose.field('new_authzr_uri')
|
|
||||||
|
|
||||||
|
|
||||||
class AccountFileStorage(interfaces.AccountStorage):
|
class AccountFileStorage(interfaces.AccountStorage):
|
||||||
"""Accounts file storage.
|
"""Accounts file storage.
|
||||||
|
|
||||||
@@ -254,20 +242,19 @@ class AccountFileStorage(interfaces.AccountStorage):
|
|||||||
dir_path = self._prepare(account)
|
dir_path = self._prepare(account)
|
||||||
self._create(account, dir_path)
|
self._create(account, dir_path)
|
||||||
self._update_meta(account, dir_path)
|
self._update_meta(account, dir_path)
|
||||||
self._update_regr(account, client, dir_path)
|
self._update_regr(account, dir_path)
|
||||||
except IOError as error:
|
except IOError as error:
|
||||||
raise errors.AccountStorageError(error)
|
raise errors.AccountStorageError(error)
|
||||||
|
|
||||||
def update_regr(self, account: Account, client: ClientV2) -> None:
|
def update_regr(self, account: Account) -> None:
|
||||||
"""Update the registration resource.
|
"""Update the registration resource.
|
||||||
|
|
||||||
:param Account account: account to update
|
:param Account account: account to update
|
||||||
:param ClientV2 client: ACME client associated to the account
|
|
||||||
|
|
||||||
"""
|
"""
|
||||||
try:
|
try:
|
||||||
dir_path = self._prepare(account)
|
dir_path = self._prepare(account)
|
||||||
self._update_regr(account, client, dir_path)
|
self._update_regr(account, dir_path)
|
||||||
except IOError as error:
|
except IOError as error:
|
||||||
raise errors.AccountStorageError(error)
|
raise errors.AccountStorageError(error)
|
||||||
|
|
||||||
@@ -358,22 +345,11 @@ class AccountFileStorage(interfaces.AccountStorage):
|
|||||||
with util.safe_open(self._key_path(dir_path), "w", chmod=0o400) as key_file:
|
with util.safe_open(self._key_path(dir_path), "w", chmod=0o400) as key_file:
|
||||||
key_file.write(account.key.json_dumps())
|
key_file.write(account.key.json_dumps())
|
||||||
|
|
||||||
def _update_regr(self, account: Account, acme: ClientV2, dir_path: str) -> None:
|
def _update_regr(self, account: Account, dir_path: str) -> None:
|
||||||
with open(self._regr_path(dir_path), "w") as regr_file:
|
with open(self._regr_path(dir_path), "w") as regr_file:
|
||||||
regr = account.regr
|
|
||||||
# If we have a value for new-authz, save it for forwards
|
|
||||||
# compatibility with older versions of Certbot. If we don't
|
|
||||||
# have a value for new-authz, this is an ACMEv2 directory where
|
|
||||||
# an older version of Certbot won't work anyway.
|
|
||||||
if hasattr(acme.directory, "new-authz"):
|
|
||||||
regr = RegistrationResourceWithNewAuthzrURI(
|
|
||||||
new_authzr_uri=acme.directory.new_authz,
|
|
||||||
body={},
|
|
||||||
uri=regr.uri)
|
|
||||||
else:
|
|
||||||
regr = messages.RegistrationResource(
|
regr = messages.RegistrationResource(
|
||||||
body={},
|
body={},
|
||||||
uri=regr.uri)
|
uri=account.regr.uri)
|
||||||
regr_file.write(regr.json_dumps())
|
regr_file.write(regr.json_dumps())
|
||||||
|
|
||||||
def _update_meta(self, account: Account, dir_path: str) -> None:
|
def _update_meta(self, account: Account, dir_path: str) -> None:
|
||||||
|
|||||||
@@ -948,7 +948,7 @@ def update_account(config: configuration.NamespaceConfig,
|
|||||||
# the v2 uri. Since it's the same object on disk, put it back to the v1 uri
|
# the v2 uri. Since it's the same object on disk, put it back to the v1 uri
|
||||||
# so that we can also continue to use the account object with acmev1.
|
# so that we can also continue to use the account object with acmev1.
|
||||||
acc.regr = acc.regr.update(uri=prev_regr_uri)
|
acc.regr = acc.regr.update(uri=prev_regr_uri)
|
||||||
account_storage.update_regr(acc, cb_client.acme)
|
account_storage.update_regr(acc)
|
||||||
|
|
||||||
if not config.email:
|
if not config.email:
|
||||||
display_util.notify("Any contact information associated "
|
display_util.notify("Any contact information associated "
|
||||||
|
|||||||
@@ -109,19 +109,16 @@ class AccountFileStorageTest(test_util.ConfigTestCase):
|
|||||||
self.storage = AccountFileStorage(self.config)
|
self.storage = AccountFileStorage(self.config)
|
||||||
|
|
||||||
from certbot._internal.account import Account
|
from certbot._internal.account import Account
|
||||||
new_authzr_uri = "hi"
|
|
||||||
meta = Account.Meta(
|
meta = Account.Meta(
|
||||||
creation_host="test.example.org",
|
creation_host="test.example.org",
|
||||||
creation_dt=datetime.datetime(
|
creation_dt=datetime.datetime(
|
||||||
2021, 1, 5, 14, 4, 10, tzinfo=pytz.UTC))
|
2021, 1, 5, 14, 4, 10, tzinfo=pytz.UTC))
|
||||||
self.acc = Account(
|
self.acc = Account(
|
||||||
regr=messages.RegistrationResource(
|
regr=messages.RegistrationResource(
|
||||||
uri=None, body=messages.Registration(),
|
uri=None, body=messages.Registration()),
|
||||||
new_authzr_uri=new_authzr_uri),
|
|
||||||
key=KEY,
|
key=KEY,
|
||||||
meta=meta)
|
meta=meta)
|
||||||
self.mock_client = mock.MagicMock()
|
self.mock_client = mock.MagicMock()
|
||||||
self.mock_client.directory.new_authz = new_authzr_uri
|
|
||||||
|
|
||||||
def test_init_creates_dir(self):
|
def test_init_creates_dir(self):
|
||||||
self.assertTrue(os.path.isdir(
|
self.assertTrue(os.path.isdir(
|
||||||
@@ -141,16 +138,8 @@ class AccountFileStorageTest(test_util.ConfigTestCase):
|
|||||||
loaded = self.storage.load(self.acc.id)
|
loaded = self.storage.load(self.acc.id)
|
||||||
self.assertEqual(self.acc, loaded)
|
self.assertEqual(self.acc, loaded)
|
||||||
|
|
||||||
def test_save_and_restore_old_version(self):
|
|
||||||
"""Saved regr should include a new_authzr_uri for older Certbots"""
|
|
||||||
self.storage.save(self.acc, self.mock_client)
|
|
||||||
path = os.path.join(self.config.accounts_dir, self.acc.id, "regr.json")
|
|
||||||
with open(path, "r") as f:
|
|
||||||
regr = json.load(f)
|
|
||||||
self.assertIn("new_authzr_uri", regr)
|
|
||||||
|
|
||||||
def test_update_regr(self):
|
def test_update_regr(self):
|
||||||
self.storage.update_regr(self.acc, self.mock_client)
|
self.storage.update_regr(self.acc)
|
||||||
account_path = os.path.join(self.config.accounts_dir, self.acc.id)
|
account_path = os.path.join(self.config.accounts_dir, self.acc.id)
|
||||||
self.assertTrue(os.path.exists(account_path))
|
self.assertTrue(os.path.exists(account_path))
|
||||||
self.assertTrue(os.path.exists(os.path.join(account_path, "regr.json")))
|
self.assertTrue(os.path.exists(os.path.join(account_path, "regr.json")))
|
||||||
|
|||||||
Reference in New Issue
Block a user