From 8e0376cec46d79a774b515cbdb0b771a0ca4f68c Mon Sep 17 00:00:00 2001 From: Chris Goller Date: Wed, 4 Jan 2017 19:35:07 -0600 Subject: [PATCH 1/2] Add insecureSkipVerify option to source to accept all influxdb certs The insecureSkipVerify defaults to false, but when true, instructs the server to accept any certificate coming from the InfluxDB server. --- CHANGELOG.md | 1 + bolt/internal/internal.go | 18 ++-- bolt/internal/internal.pb.go | 180 +++++++++++++++++---------------- bolt/internal/internal.proto | 1 + bolt/internal/internal_test.go | 10 ++ bolt/sources_test.go | 22 +++- chronograf.go | 17 ++-- influx/influx.go | 19 +++- influx/influx_test.go | 76 ++++++++++++++ server/sources.go | 1 + server/swagger.json | 6 +- 11 files changed, 238 insertions(+), 113 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e4c3bfda4b..4fcc03482b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,7 @@ 1. [#718](https://github.com/influxdata/chronograf/issues/718): Fix bug that stopped apps from displaying ### Upcoming Features + 1. [#660](https://github.com/influxdata/chronograf/issues/660): Add option to accept any certificate from InfluxDB. ## v1.1.0-beta4 [2016-12-30] diff --git a/bolt/internal/internal.go b/bolt/internal/internal.go index b83baa2bd2..20d24d87a1 100644 --- a/bolt/internal/internal.go +++ b/bolt/internal/internal.go @@ -44,14 +44,15 @@ func UnmarshalExploration(data []byte, e *chronograf.Exploration) error { // MarshalSource encodes a source to binary protobuf format. func MarshalSource(s chronograf.Source) ([]byte, error) { return proto.Marshal(&Source{ - ID: int64(s.ID), - Name: s.Name, - Type: s.Type, - Username: s.Username, - Password: s.Password, - URL: s.URL, - Default: s.Default, - Telegraf: s.Telegraf, + ID: int64(s.ID), + Name: s.Name, + Type: s.Type, + Username: s.Username, + Password: s.Password, + URL: s.URL, + InsecureSkipVerify: s.InsecureSkipVerify, + Default: s.Default, + Telegraf: s.Telegraf, }) } @@ -68,6 +69,7 @@ func UnmarshalSource(data []byte, s *chronograf.Source) error { s.Username = pb.Username s.Password = pb.Password s.URL = pb.URL + s.InsecureSkipVerify = pb.InsecureSkipVerify s.Default = pb.Default s.Telegraf = pb.Telegraf return nil diff --git a/bolt/internal/internal.pb.go b/bolt/internal/internal.pb.go index 586515e835..39291210e4 100644 --- a/bolt/internal/internal.pb.go +++ b/bolt/internal/internal.pb.go @@ -39,13 +39,13 @@ var _ = math.Inf const _ = proto.GoGoProtoPackageIsVersion2 // please upgrade the proto package type Exploration struct { - ID int64 `protobuf:"varint,1,opt,name=ID,proto3" json:"ID,omitempty"` - Name string `protobuf:"bytes,2,opt,name=Name,proto3" json:"Name,omitempty"` - UserID int64 `protobuf:"varint,3,opt,name=UserID,proto3" json:"UserID,omitempty"` - Data string `protobuf:"bytes,4,opt,name=Data,proto3" json:"Data,omitempty"` - CreatedAt int64 `protobuf:"varint,5,opt,name=CreatedAt,proto3" json:"CreatedAt,omitempty"` - UpdatedAt int64 `protobuf:"varint,6,opt,name=UpdatedAt,proto3" json:"UpdatedAt,omitempty"` - Default bool `protobuf:"varint,7,opt,name=Default,proto3" json:"Default,omitempty"` + ID int64 `protobuf:"varint,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Name string `protobuf:"bytes,2,opt,name=Name,json=name,proto3" json:"Name,omitempty"` + UserID int64 `protobuf:"varint,3,opt,name=UserID,json=userID,proto3" json:"UserID,omitempty"` + Data string `protobuf:"bytes,4,opt,name=Data,json=data,proto3" json:"Data,omitempty"` + CreatedAt int64 `protobuf:"varint,5,opt,name=CreatedAt,json=createdAt,proto3" json:"CreatedAt,omitempty"` + UpdatedAt int64 `protobuf:"varint,6,opt,name=UpdatedAt,json=updatedAt,proto3" json:"UpdatedAt,omitempty"` + Default bool `protobuf:"varint,7,opt,name=Default,json=default,proto3" json:"Default,omitempty"` } func (m *Exploration) Reset() { *m = Exploration{} } @@ -54,14 +54,15 @@ func (*Exploration) ProtoMessage() {} func (*Exploration) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{0} } type Source struct { - ID int64 `protobuf:"varint,1,opt,name=ID,proto3" json:"ID,omitempty"` - Name string `protobuf:"bytes,2,opt,name=Name,proto3" json:"Name,omitempty"` - Type string `protobuf:"bytes,3,opt,name=Type,proto3" json:"Type,omitempty"` - Username string `protobuf:"bytes,4,opt,name=Username,proto3" json:"Username,omitempty"` - Password string `protobuf:"bytes,5,opt,name=Password,proto3" json:"Password,omitempty"` - URL string `protobuf:"bytes,6,opt,name=URL,proto3" json:"URL,omitempty"` - Default bool `protobuf:"varint,7,opt,name=Default,proto3" json:"Default,omitempty"` - Telegraf string `protobuf:"bytes,8,opt,name=Telegraf,proto3" json:"Telegraf,omitempty"` + ID int64 `protobuf:"varint,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Name string `protobuf:"bytes,2,opt,name=Name,json=name,proto3" json:"Name,omitempty"` + Type string `protobuf:"bytes,3,opt,name=Type,json=type,proto3" json:"Type,omitempty"` + Username string `protobuf:"bytes,4,opt,name=Username,json=username,proto3" json:"Username,omitempty"` + Password string `protobuf:"bytes,5,opt,name=Password,json=password,proto3" json:"Password,omitempty"` + URL string `protobuf:"bytes,6,opt,name=URL,json=uRL,proto3" json:"URL,omitempty"` + Default bool `protobuf:"varint,7,opt,name=Default,json=default,proto3" json:"Default,omitempty"` + Telegraf string `protobuf:"bytes,8,opt,name=Telegraf,json=telegraf,proto3" json:"Telegraf,omitempty"` + InsecureSkipVerify bool `protobuf:"varint,9,opt,name=InsecureSkipVerify,json=insecureSkipVerify,proto3" json:"InsecureSkipVerify,omitempty"` } func (m *Source) Reset() { *m = Source{} } @@ -70,8 +71,8 @@ func (*Source) ProtoMessage() {} func (*Source) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{1} } type Dashboard struct { - ID int64 `protobuf:"varint,1,opt,name=ID,proto3" json:"ID,omitempty"` - Name string `protobuf:"bytes,2,opt,name=Name,proto3" json:"Name,omitempty"` + ID int64 `protobuf:"varint,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Name string `protobuf:"bytes,2,opt,name=Name,json=name,proto3" json:"Name,omitempty"` Cells []*DashboardCell `protobuf:"bytes,3,rep,name=cells" json:"cells,omitempty"` } @@ -103,12 +104,12 @@ func (*DashboardCell) ProtoMessage() {} func (*DashboardCell) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{3} } type Server struct { - ID int64 `protobuf:"varint,1,opt,name=ID,proto3" json:"ID,omitempty"` - Name string `protobuf:"bytes,2,opt,name=Name,proto3" json:"Name,omitempty"` - Username string `protobuf:"bytes,3,opt,name=Username,proto3" json:"Username,omitempty"` - Password string `protobuf:"bytes,4,opt,name=Password,proto3" json:"Password,omitempty"` - URL string `protobuf:"bytes,5,opt,name=URL,proto3" json:"URL,omitempty"` - SrcID int64 `protobuf:"varint,6,opt,name=SrcID,proto3" json:"SrcID,omitempty"` + ID int64 `protobuf:"varint,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Name string `protobuf:"bytes,2,opt,name=Name,json=name,proto3" json:"Name,omitempty"` + Username string `protobuf:"bytes,3,opt,name=Username,json=username,proto3" json:"Username,omitempty"` + Password string `protobuf:"bytes,4,opt,name=Password,json=password,proto3" json:"Password,omitempty"` + URL string `protobuf:"bytes,5,opt,name=URL,json=uRL,proto3" json:"URL,omitempty"` + SrcID int64 `protobuf:"varint,6,opt,name=SrcID,json=srcID,proto3" json:"SrcID,omitempty"` } func (m *Server) Reset() { *m = Server{} } @@ -117,11 +118,11 @@ func (*Server) ProtoMessage() {} func (*Server) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{4} } type Layout struct { - ID string `protobuf:"bytes,1,opt,name=ID,proto3" json:"ID,omitempty"` - Application string `protobuf:"bytes,2,opt,name=Application,proto3" json:"Application,omitempty"` - Measurement string `protobuf:"bytes,3,opt,name=Measurement,proto3" json:"Measurement,omitempty"` - Cells []*Cell `protobuf:"bytes,4,rep,name=Cells" json:"Cells,omitempty"` - Autoflow bool `protobuf:"varint,5,opt,name=Autoflow,proto3" json:"Autoflow,omitempty"` + ID string `protobuf:"bytes,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Application string `protobuf:"bytes,2,opt,name=Application,json=application,proto3" json:"Application,omitempty"` + Measurement string `protobuf:"bytes,3,opt,name=Measurement,json=measurement,proto3" json:"Measurement,omitempty"` + Cells []*Cell `protobuf:"bytes,4,rep,name=Cells,json=cells" json:"Cells,omitempty"` + Autoflow bool `protobuf:"varint,5,opt,name=Autoflow,json=autoflow,proto3" json:"Autoflow,omitempty"` } func (m *Layout) Reset() { *m = Layout{} } @@ -162,13 +163,13 @@ func (m *Cell) GetQueries() []*Query { } type Query struct { - Command string `protobuf:"bytes,1,opt,name=Command,proto3" json:"Command,omitempty"` - DB string `protobuf:"bytes,2,opt,name=DB,proto3" json:"DB,omitempty"` - RP string `protobuf:"bytes,3,opt,name=RP,proto3" json:"RP,omitempty"` - GroupBys []string `protobuf:"bytes,4,rep,name=GroupBys" json:"GroupBys,omitempty"` - Wheres []string `protobuf:"bytes,5,rep,name=Wheres" json:"Wheres,omitempty"` - Label string `protobuf:"bytes,6,opt,name=Label,proto3" json:"Label,omitempty"` - Range *Range `protobuf:"bytes,7,opt,name=Range" json:"Range,omitempty"` + Command string `protobuf:"bytes,1,opt,name=Command,json=command,proto3" json:"Command,omitempty"` + DB string `protobuf:"bytes,2,opt,name=DB,json=dB,proto3" json:"DB,omitempty"` + RP string `protobuf:"bytes,3,opt,name=RP,json=rP,proto3" json:"RP,omitempty"` + GroupBys []string `protobuf:"bytes,4,rep,name=GroupBys,json=groupBys" json:"GroupBys,omitempty"` + Wheres []string `protobuf:"bytes,5,rep,name=Wheres,json=wheres" json:"Wheres,omitempty"` + Label string `protobuf:"bytes,6,opt,name=Label,json=label,proto3" json:"Label,omitempty"` + Range *Range `protobuf:"bytes,7,opt,name=Range,json=range" json:"Range,omitempty"` } func (m *Query) Reset() { *m = Query{} } @@ -184,8 +185,8 @@ func (m *Query) GetRange() *Range { } type Range struct { - Upper int64 `protobuf:"varint,1,opt,name=Upper,proto3" json:"Upper,omitempty"` - Lower int64 `protobuf:"varint,2,opt,name=Lower,proto3" json:"Lower,omitempty"` + Upper int64 `protobuf:"varint,1,opt,name=Upper,json=upper,proto3" json:"Upper,omitempty"` + Lower int64 `protobuf:"varint,2,opt,name=Lower,json=lower,proto3" json:"Lower,omitempty"` } func (m *Range) Reset() { *m = Range{} } @@ -194,10 +195,10 @@ func (*Range) ProtoMessage() {} func (*Range) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{8} } type AlertRule struct { - ID string `protobuf:"bytes,1,opt,name=ID,proto3" json:"ID,omitempty"` - JSON string `protobuf:"bytes,2,opt,name=JSON,proto3" json:"JSON,omitempty"` - SrcID int64 `protobuf:"varint,3,opt,name=SrcID,proto3" json:"SrcID,omitempty"` - KapaID int64 `protobuf:"varint,4,opt,name=KapaID,proto3" json:"KapaID,omitempty"` + ID string `protobuf:"bytes,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + JSON string `protobuf:"bytes,2,opt,name=JSON,json=jSON,proto3" json:"JSON,omitempty"` + SrcID int64 `protobuf:"varint,3,opt,name=SrcID,json=srcID,proto3" json:"SrcID,omitempty"` + KapaID int64 `protobuf:"varint,4,opt,name=KapaID,json=kapaID,proto3" json:"KapaID,omitempty"` } func (m *AlertRule) Reset() { *m = AlertRule{} } @@ -206,8 +207,8 @@ func (*AlertRule) ProtoMessage() {} func (*AlertRule) Descriptor() ([]byte, []int) { return fileDescriptorInternal, []int{9} } type User struct { - ID uint64 `protobuf:"varint,1,opt,name=ID,proto3" json:"ID,omitempty"` - Email string `protobuf:"bytes,2,opt,name=Email,proto3" json:"Email,omitempty"` + ID uint64 `protobuf:"varint,1,opt,name=ID,json=iD,proto3" json:"ID,omitempty"` + Email string `protobuf:"bytes,2,opt,name=Email,json=email,proto3" json:"Email,omitempty"` } func (m *User) Reset() { *m = User{} } @@ -232,49 +233,52 @@ func init() { func init() { proto.RegisterFile("internal.proto", fileDescriptorInternal) } var fileDescriptorInternal = []byte{ - // 693 bytes of a gzipped FileDescriptorProto - 0x1f, 0x8b, 0x08, 0x00, 0x00, 0x09, 0x6e, 0x88, 0x02, 0xff, 0xa4, 0x54, 0xdd, 0x6e, 0xd3, 0x4a, - 0x10, 0xd6, 0xc6, 0x76, 0x12, 0x4f, 0x7a, 0x7a, 0x8e, 0x56, 0xd5, 0xc1, 0x42, 0x5c, 0x44, 0x16, - 0x48, 0x41, 0x82, 0x5e, 0xb4, 0x4f, 0x90, 0xc6, 0x15, 0x0a, 0x94, 0x52, 0xb6, 0x8d, 0xb8, 0x02, - 0x69, 0x9b, 0x6c, 0x9b, 0x48, 0x9b, 0xd8, 0xac, 0x6d, 0xd2, 0x3c, 0x02, 0x12, 0xcf, 0xc0, 0x43, - 0xc0, 0x0b, 0xf0, 0x0e, 0xbc, 0x10, 0x9a, 0xd9, 0xb5, 0xe3, 0x8a, 0x1f, 0x55, 0xe2, 0x6e, 0xbe, - 0x99, 0xf1, 0xf8, 0x9b, 0xf9, 0x3e, 0x1b, 0x76, 0x17, 0xab, 0x42, 0x99, 0x95, 0xd4, 0xfb, 0x99, - 0x49, 0x8b, 0x94, 0x77, 0x2b, 0x1c, 0x7f, 0x65, 0xd0, 0x3b, 0xbe, 0xc9, 0x74, 0x6a, 0x64, 0xb1, - 0x48, 0x57, 0x7c, 0x17, 0x5a, 0xe3, 0x24, 0x62, 0x7d, 0x36, 0xf0, 0x44, 0x6b, 0x9c, 0x70, 0x0e, - 0xfe, 0xa9, 0x5c, 0xaa, 0xa8, 0xd5, 0x67, 0x83, 0x50, 0x50, 0xcc, 0xff, 0x87, 0xf6, 0x24, 0x57, - 0x66, 0x9c, 0x44, 0x1e, 0xf5, 0x39, 0x84, 0xbd, 0x89, 0x2c, 0x64, 0xe4, 0xdb, 0x5e, 0x8c, 0xf9, - 0x03, 0x08, 0x47, 0x46, 0xc9, 0x42, 0xcd, 0x86, 0x45, 0x14, 0x50, 0xfb, 0x36, 0x81, 0xd5, 0x49, - 0x36, 0x73, 0xd5, 0xb6, 0xad, 0xd6, 0x09, 0x1e, 0x41, 0x27, 0x51, 0x57, 0xb2, 0xd4, 0x45, 0xd4, - 0xe9, 0xb3, 0x41, 0x57, 0x54, 0x30, 0xfe, 0xc6, 0xa0, 0x7d, 0x9e, 0x96, 0x66, 0xaa, 0xee, 0x44, - 0x98, 0x83, 0x7f, 0xb1, 0xc9, 0x14, 0xd1, 0x0d, 0x05, 0xc5, 0xfc, 0x3e, 0x74, 0x91, 0xf6, 0x0a, - 0x7b, 0x2d, 0xe1, 0x1a, 0x63, 0xed, 0x4c, 0xe6, 0xf9, 0x3a, 0x35, 0x33, 0xe2, 0x1c, 0x8a, 0x1a, - 0xf3, 0xff, 0xc0, 0x9b, 0x88, 0x13, 0x22, 0x1b, 0x0a, 0x0c, 0x7f, 0x4f, 0x13, 0xe7, 0x5c, 0x28, - 0xad, 0xae, 0x8d, 0xbc, 0x8a, 0xba, 0x76, 0x4e, 0x85, 0xe3, 0x77, 0x10, 0x26, 0x32, 0x9f, 0x5f, - 0xa6, 0xd2, 0xcc, 0xee, 0xb4, 0xc4, 0x53, 0x08, 0xa6, 0x4a, 0xeb, 0x3c, 0xf2, 0xfa, 0xde, 0xa0, - 0x77, 0x70, 0x6f, 0xbf, 0xd6, 0xb4, 0x9e, 0x33, 0x52, 0x5a, 0x0b, 0xdb, 0x15, 0x7f, 0x64, 0xf0, - 0xcf, 0xad, 0x02, 0xdf, 0x01, 0x76, 0x43, 0xef, 0x08, 0x04, 0xbb, 0x41, 0xb4, 0xa1, 0xf9, 0x81, - 0x60, 0x1b, 0x44, 0x6b, 0x3a, 0x4f, 0x20, 0xd8, 0x1a, 0xd1, 0x9c, 0x8e, 0x12, 0x08, 0x36, 0xc7, - 0xfd, 0xde, 0x97, 0xca, 0x2c, 0x54, 0x1e, 0x05, 0x7d, 0x6f, 0x10, 0x8a, 0x0a, 0x22, 0x4d, 0xba, - 0x9f, 0x3d, 0x06, 0xc5, 0x98, 0x2b, 0xf0, 0xd6, 0x1d, 0x9b, 0xc3, 0x38, 0xfe, 0x84, 0x72, 0x29, - 0xf3, 0x41, 0x99, 0x3b, 0x6d, 0xda, 0x94, 0xc6, 0xfb, 0x83, 0x34, 0xfe, 0xaf, 0xa5, 0x09, 0xb6, - 0xd2, 0xec, 0x41, 0x70, 0x6e, 0xa6, 0xe3, 0xc4, 0x79, 0xcb, 0x82, 0xf8, 0x33, 0x83, 0xf6, 0x89, - 0xdc, 0xa4, 0x65, 0xd1, 0xa0, 0x13, 0x12, 0x9d, 0x3e, 0xf4, 0x86, 0x59, 0xa6, 0x17, 0x53, 0xfa, - 0x1a, 0x1c, 0xab, 0x66, 0x0a, 0x3b, 0x5e, 0x2a, 0x99, 0x97, 0x46, 0x2d, 0xd5, 0xaa, 0x70, 0xfc, - 0x9a, 0x29, 0xfe, 0x10, 0x82, 0x11, 0x09, 0xe5, 0x93, 0x50, 0xbb, 0x5b, 0xa1, 0xac, 0x3e, 0x54, - 0xc4, 0x45, 0x86, 0x65, 0x91, 0x5e, 0xe9, 0x74, 0x4d, 0x8c, 0xbb, 0xa2, 0xc6, 0xf1, 0x77, 0x06, - 0xfe, 0x5f, 0x49, 0xf6, 0xf8, 0xb6, 0x64, 0xbd, 0x83, 0x7f, 0xb7, 0x24, 0x5e, 0x97, 0xca, 0x6c, - 0xb6, 0x1a, 0xee, 0x00, 0x5b, 0x38, 0x01, 0xd9, 0xa2, 0x56, 0xb4, 0xd3, 0x50, 0x34, 0x82, 0xce, - 0xc6, 0xc8, 0xd5, 0xb5, 0xca, 0xa3, 0x6e, 0xdf, 0x1b, 0x78, 0xa2, 0x82, 0x54, 0xd1, 0xf2, 0x52, - 0xe9, 0x3c, 0x0a, 0xad, 0x33, 0x1c, 0xac, 0x5d, 0x00, 0x0d, 0x17, 0x7c, 0x61, 0x10, 0xd0, 0xcb, - 0xf1, 0xb9, 0x51, 0xba, 0x5c, 0xca, 0xd5, 0xcc, 0x9d, 0xbe, 0x82, 0xa8, 0x47, 0x72, 0xe4, 0xce, - 0xde, 0x4a, 0x8e, 0x10, 0x8b, 0x33, 0x77, 0xe4, 0x96, 0x38, 0xc3, 0xab, 0x3d, 0x33, 0x69, 0x99, - 0x1d, 0x6d, 0xec, 0x79, 0x43, 0x51, 0x63, 0xfc, 0x2d, 0xbd, 0x99, 0x2b, 0x53, 0xdb, 0xd4, 0x21, - 0x34, 0xc1, 0x09, 0xb2, 0x72, 0x5b, 0x5a, 0xc0, 0x1f, 0x41, 0x20, 0x70, 0x0b, 0x5a, 0xf5, 0xd6, - 0x81, 0x28, 0x2d, 0x6c, 0x35, 0x3e, 0x74, 0x6d, 0x38, 0x65, 0x92, 0x65, 0xca, 0x38, 0xef, 0x5a, - 0x40, 0xb3, 0xd3, 0xb5, 0x32, 0x44, 0xd9, 0x13, 0x16, 0xc4, 0x6f, 0x21, 0x1c, 0x6a, 0x65, 0x0a, - 0x51, 0x6a, 0xf5, 0x93, 0xc5, 0x38, 0xf8, 0xcf, 0xcf, 0x5f, 0x9d, 0x56, 0x8e, 0xc7, 0x78, 0xeb, - 0x53, 0xaf, 0xe1, 0x53, 0x5c, 0xe8, 0x85, 0xcc, 0xe4, 0x38, 0x21, 0x61, 0x3d, 0xe1, 0x50, 0xfc, - 0x04, 0x7c, 0xfc, 0x1e, 0x1a, 0x93, 0x7d, 0x9a, 0xbc, 0x07, 0xc1, 0xf1, 0x52, 0x2e, 0xb4, 0x1b, - 0x6d, 0xc1, 0x65, 0x9b, 0x7e, 0xf9, 0x87, 0x3f, 0x02, 0x00, 0x00, 0xff, 0xff, 0x31, 0x9b, 0xcb, - 0xb7, 0x04, 0x06, 0x00, 0x00, + // 750 bytes of a gzipped FileDescriptorProto + 0x1f, 0x8b, 0x08, 0x00, 0x00, 0x09, 0x6e, 0x88, 0x02, 0xff, 0xa4, 0x55, 0x6d, 0x6e, 0xdb, 0x46, + 0x10, 0xc5, 0x8a, 0x5c, 0x8a, 0x5c, 0xb9, 0x6e, 0xb1, 0x30, 0x5a, 0xa2, 0xe8, 0x0f, 0x81, 0x68, + 0x01, 0x15, 0x68, 0xfd, 0xc3, 0x3e, 0x81, 0x2c, 0x1a, 0x85, 0x5a, 0xd5, 0x76, 0x57, 0x56, 0xfb, + 0xab, 0x05, 0xd6, 0xe2, 0xc8, 0x62, 0xbd, 0x22, 0xd9, 0x25, 0x59, 0x99, 0x47, 0x08, 0x90, 0x33, + 0xe4, 0x10, 0xc9, 0x51, 0x72, 0x91, 0x1c, 0x21, 0xd8, 0xe1, 0xea, 0x0b, 0x4e, 0x02, 0x03, 0xf9, + 0xf9, 0x66, 0x46, 0xc3, 0x37, 0xef, 0x3d, 0x8a, 0xec, 0x38, 0xcd, 0x2a, 0xd0, 0x99, 0x54, 0xa7, + 0x85, 0xce, 0xab, 0x9c, 0xfb, 0x1b, 0x1c, 0xbd, 0x21, 0xac, 0x77, 0xf9, 0x58, 0xa8, 0x5c, 0xcb, + 0x2a, 0xcd, 0x33, 0x7e, 0xcc, 0x3a, 0xe3, 0x38, 0x24, 0x7d, 0x32, 0x70, 0x44, 0x27, 0x8d, 0x39, + 0x67, 0xee, 0x95, 0x5c, 0x41, 0xd8, 0xe9, 0x93, 0x41, 0x20, 0xdc, 0x4c, 0xae, 0x80, 0x7f, 0xcd, + 0xbc, 0x59, 0x09, 0x7a, 0x1c, 0x87, 0x0e, 0xce, 0x79, 0x35, 0x22, 0x33, 0x1b, 0xcb, 0x4a, 0x86, + 0x6e, 0x3b, 0x9b, 0xc8, 0x4a, 0xf2, 0xef, 0x58, 0x30, 0xd2, 0x20, 0x2b, 0x48, 0x86, 0x55, 0x48, + 0x71, 0x3c, 0x98, 0x6f, 0x0a, 0xa6, 0x3b, 0x2b, 0x12, 0xdb, 0xf5, 0xda, 0x6e, 0xbd, 0x29, 0xf0, + 0x90, 0x75, 0x63, 0x58, 0xc8, 0x5a, 0x55, 0x61, 0xb7, 0x4f, 0x06, 0xbe, 0xe8, 0x26, 0x2d, 0x8c, + 0xde, 0x11, 0xe6, 0x4d, 0xf3, 0x5a, 0xcf, 0xe1, 0x59, 0x84, 0x39, 0x73, 0x6f, 0x9b, 0x02, 0x90, + 0x6e, 0x20, 0xdc, 0xaa, 0x29, 0x80, 0x7f, 0xcb, 0x7c, 0x73, 0x84, 0xe9, 0x5b, 0xc2, 0x7e, 0x6d, + 0xb1, 0xe9, 0xdd, 0xc8, 0xb2, 0x5c, 0xe7, 0x3a, 0x41, 0xce, 0x81, 0xf0, 0x0b, 0x8b, 0xf9, 0x57, + 0xcc, 0x99, 0x89, 0x09, 0x92, 0x0d, 0x84, 0x53, 0x8b, 0xc9, 0xc7, 0x69, 0x9a, 0x3d, 0xb7, 0xa0, + 0xe0, 0x5e, 0xcb, 0x45, 0xe8, 0xb7, 0x7b, 0x2a, 0x8b, 0xf9, 0x29, 0xe3, 0xe3, 0xac, 0x84, 0x79, + 0xad, 0x61, 0xfa, 0x90, 0x16, 0x7f, 0x82, 0x4e, 0x17, 0x4d, 0x18, 0xe0, 0x02, 0x9e, 0x3e, 0xe9, + 0x44, 0xff, 0xb0, 0x20, 0x96, 0xe5, 0xf2, 0x2e, 0x97, 0x3a, 0x79, 0xd6, 0xd1, 0x3f, 0x33, 0x3a, + 0x07, 0xa5, 0xca, 0xd0, 0xe9, 0x3b, 0x83, 0xde, 0xd9, 0x37, 0xa7, 0xdb, 0x0c, 0x6c, 0xf7, 0x8c, + 0x40, 0x29, 0xd1, 0x4e, 0x45, 0x2f, 0x08, 0xfb, 0xe2, 0xa0, 0xc1, 0x8f, 0x18, 0x79, 0xc4, 0x67, + 0x50, 0x41, 0x1e, 0x0d, 0x6a, 0x70, 0x3f, 0x15, 0xa4, 0x31, 0x68, 0x8d, 0x72, 0x52, 0x41, 0xd6, + 0x06, 0x2d, 0x51, 0x44, 0x2a, 0xc8, 0xd2, 0xe8, 0xf1, 0x5f, 0x0d, 0x3a, 0x85, 0x32, 0xa4, 0x7d, + 0x67, 0x10, 0x88, 0x0d, 0x34, 0x34, 0x51, 0x6f, 0xef, 0xd0, 0x1b, 0xe3, 0x07, 0x4a, 0x67, 0xbd, + 0x89, 0x5e, 0x1a, 0x7b, 0x41, 0xff, 0x0f, 0xfa, 0x59, 0x97, 0xee, 0x5b, 0xe9, 0x7c, 0xc2, 0x4a, + 0xf7, 0xc3, 0x56, 0xd2, 0x9d, 0x95, 0x27, 0x8c, 0x4e, 0xf5, 0x7c, 0x1c, 0xdb, 0x2c, 0xd2, 0xd2, + 0x80, 0xe8, 0x15, 0x61, 0xde, 0x44, 0x36, 0x79, 0x5d, 0xed, 0xd1, 0x09, 0x90, 0x4e, 0x9f, 0xf5, + 0x86, 0x45, 0xa1, 0xd2, 0x39, 0xbe, 0x3d, 0x96, 0x55, 0x4f, 0xee, 0x4a, 0x66, 0xe2, 0x77, 0x90, + 0x65, 0xad, 0x61, 0x05, 0x59, 0x65, 0xf9, 0xf5, 0x56, 0xbb, 0x12, 0xff, 0x9e, 0xd1, 0x11, 0x1a, + 0xe5, 0xa2, 0x51, 0xc7, 0x3b, 0xa3, 0xf6, 0xfc, 0x31, 0x87, 0x0c, 0xeb, 0x2a, 0x5f, 0xa8, 0x7c, + 0x8d, 0x8c, 0x7d, 0xe1, 0x4b, 0x8b, 0xa3, 0xb7, 0x84, 0xb9, 0x9f, 0x65, 0xd9, 0x8f, 0x87, 0x96, + 0xf5, 0xce, 0xbe, 0xdc, 0x91, 0xf8, 0xa3, 0x06, 0xdd, 0xec, 0x3c, 0x3c, 0x62, 0x24, 0xb5, 0x06, + 0x92, 0x74, 0xeb, 0x68, 0x77, 0xcf, 0x8e, 0x90, 0x75, 0x1b, 0x2d, 0xb3, 0x7b, 0x28, 0x43, 0xbf, + 0xef, 0x0c, 0x1c, 0xb1, 0x81, 0xd8, 0x51, 0xf2, 0x0e, 0x54, 0x19, 0x06, 0x6d, 0x32, 0x2c, 0xdc, + 0xa6, 0x80, 0xed, 0xa5, 0xe0, 0x35, 0x61, 0x14, 0x1f, 0x6e, 0x7e, 0x37, 0xca, 0x57, 0x2b, 0x99, + 0x25, 0x56, 0xfa, 0xee, 0xbc, 0x85, 0xc6, 0x8f, 0xf8, 0xc2, 0xca, 0xde, 0x49, 0x2e, 0x0c, 0x16, + 0x37, 0x56, 0xe4, 0x8e, 0xbe, 0x31, 0xaa, 0xfd, 0xa2, 0xf3, 0xba, 0xb8, 0x68, 0x5a, 0x79, 0x03, + 0xe1, 0xdf, 0x5b, 0x6c, 0xfe, 0xc6, 0xfe, 0x5a, 0x82, 0xde, 0xc6, 0xd4, 0x5b, 0x23, 0x32, 0x21, + 0x98, 0x18, 0x56, 0xf6, 0x4a, 0x8a, 0x14, 0xf9, 0x0f, 0x8c, 0x0a, 0x73, 0x05, 0x9e, 0x7a, 0x20, + 0x10, 0x96, 0x05, 0xc5, 0x1b, 0xa3, 0x73, 0x3b, 0x66, 0xb6, 0xcc, 0x8a, 0x02, 0xb4, 0xcd, 0x2e, + 0xad, 0x0d, 0xc0, 0xdd, 0xf9, 0x1a, 0x34, 0x52, 0x76, 0x04, 0x55, 0x06, 0x44, 0x7f, 0xb3, 0x60, + 0xa8, 0x40, 0x57, 0xa2, 0x56, 0xf0, 0x24, 0x62, 0x9c, 0xb9, 0xbf, 0x4e, 0xaf, 0xaf, 0x36, 0x89, + 0xff, 0x77, 0x7a, 0x7d, 0xb5, 0xcb, 0xa9, 0xb3, 0x97, 0x53, 0x73, 0xd0, 0x6f, 0xb2, 0x90, 0xe3, + 0x18, 0x8d, 0x75, 0x84, 0xf7, 0x80, 0x28, 0xfa, 0x89, 0xb9, 0xe6, 0xfd, 0xd8, 0xdb, 0xec, 0xe2, + 0xe6, 0x13, 0x46, 0x2f, 0x57, 0x32, 0x55, 0x76, 0x35, 0x05, 0x03, 0xee, 0x3c, 0xfc, 0x44, 0x9c, + 0xbf, 0x0f, 0x00, 0x00, 0xff, 0xff, 0xfb, 0x83, 0xb5, 0x2a, 0x34, 0x06, 0x00, 0x00, } diff --git a/bolt/internal/internal.proto b/bolt/internal/internal.proto index 790bcb1b23..94a17b2d28 100644 --- a/bolt/internal/internal.proto +++ b/bolt/internal/internal.proto @@ -20,6 +20,7 @@ message Source { string URL = 6; // URL are the connections to the source bool Default = 7; // Flags an exploration as the default. string Telegraf = 8; // Telegraf is the db telegraf is written to. By default it is "telegraf" + bool InsecureSkipVerify = 9; // InsecureSkipVerify accepts any certificate from the influx server } message Dashboard { diff --git a/bolt/internal/internal_test.go b/bolt/internal/internal_test.go index 880a7baa85..52d4534651 100644 --- a/bolt/internal/internal_test.go +++ b/bolt/internal/internal_test.go @@ -50,6 +50,16 @@ func TestMarshalSource(t *testing.T) { } else if !reflect.DeepEqual(v, vv) { t.Fatalf("source protobuf copy error: got %#v, expected %#v", vv, v) } + + // Test if the new insecureskipverify works + v.InsecureSkipVerify = true + if buf, err := internal.MarshalSource(v); err != nil { + t.Fatal(err) + } else if err := internal.UnmarshalSource(buf, &vv); err != nil { + t.Fatal(err) + } else if !reflect.DeepEqual(v, vv) { + t.Fatalf("source protobuf copy error: got %#v, expected %#v", vv, v) + } } func TestMarshalServer(t *testing.T) { diff --git a/bolt/sources_test.go b/bolt/sources_test.go index 708c596c78..c326a2d01e 100644 --- a/bolt/sources_test.go +++ b/bolt/sources_test.go @@ -38,6 +38,15 @@ func TestSourceStore(t *testing.T) { URL: "toyota-hilux.lyon-estates.local", Default: true, }, + chronograf.Source{ + Name: "HipToBeSquare", + Type: "influx", + Username: "calvinklein", + Password: "chuck b3rry", + URL: "https://toyota-hilux.lyon-estates.local", + InsecureSkipVerify: true, + Default: false, + }, } ctx := context.Background() @@ -94,7 +103,7 @@ func TestSourceStore(t *testing.T) { Default: true, }) - srcs[2] = mustAddSource(t, s, srcs[2]) + srcs[3] = mustAddSource(t, s, srcs[3]) if srcs, err := s.All(ctx); err != nil { t.Fatal(err) } else { @@ -121,22 +130,25 @@ func TestSourceStore(t *testing.T) { } // Delete the other source we created - if err := s.Delete(ctx, srcs[2]); err != nil { + if err := s.Delete(ctx, srcs[3]); err != nil { t.Fatal(err) } if bsrcs, err := s.All(ctx); err != nil { t.Fatal(err) - } else if len(bsrcs) != 1 { - t.Fatalf("After delete All returned incorrect number of srcs; got %d, expected %d", len(bsrcs), 1) + } else if len(bsrcs) != 2 { + t.Fatalf("After delete All returned incorrect number of srcs; got %d, expected %d", len(bsrcs), 2) } else if !reflect.DeepEqual(bsrcs[0], srcs[1]) { t.Fatalf("After delete All returned incorrect source; got %v, expected %v", bsrcs[0], srcs[1]) } - // Delete the final source + // Delete the final sources if err := s.Delete(ctx, srcs[1]); err != nil { t.Fatal(err) } + if err := s.Delete(ctx, srcs[2]); err != nil { + t.Fatal(err) + } // Try to add one source as a non-default and ensure that it becomes a // default diff --git a/chronograf.go b/chronograf.go index 4cc6c87965..6311d086e2 100644 --- a/chronograf.go +++ b/chronograf.go @@ -78,14 +78,15 @@ type Response interface { // Source is connection information to a time-series data store. type Source struct { - ID int `json:"id,omitempty,string"` // ID is the unique ID of the source - Name string `json:"name"` // Name is the user-defined name for the source - Type string `json:"type,omitempty"` // Type specifies which kinds of source (enterprise vs oss) - Username string `json:"username,omitempty"` // Username is the username to connect to the source - Password string `json:"password,omitempty"` // Password is in CLEARTEXT - URL string `json:"url"` // URL are the connections to the source - Default bool `json:"default"` // Default specifies the default source for the application - Telegraf string `json:"telegraf"` // Telegraf is the db telegraf is written to. By default it is "telegraf" + ID int `json:"id,omitempty,string"` // ID is the unique ID of the source + Name string `json:"name"` // Name is the user-defined name for the source + Type string `json:"type,omitempty"` // Type specifies which kinds of source (enterprise vs oss) + Username string `json:"username,omitempty"` // Username is the username to connect to the source + Password string `json:"password,omitempty"` // Password is in CLEARTEXT + URL string `json:"url"` // URL are the connections to the source + InsecureSkipVerify bool `json:"insecureSkipVerify,omitempty"` // InsecureSkipVerify as true means any certificate presented by the source is accepted. + Default bool `json:"default"` // Default specifies the default source for the application + Telegraf string `json:"telegraf"` // Telegraf is the db telegraf is written to. By default it is "telegraf" } // SourcesStore stores connection information for a `TimeSeries` diff --git a/influx/influx.go b/influx/influx.go index 8970f95ff1..bd19e3632e 100644 --- a/influx/influx.go +++ b/influx/influx.go @@ -2,6 +2,7 @@ package influx import ( "context" + "crypto/tls" "encoding/json" "fmt" "net/http" @@ -12,7 +13,8 @@ import ( // Client is a device for retrieving time series data from an InfluxDB instance type Client struct { - URL *url.URL + URL *url.URL + InsecureSkipVerify bool Logger chronograf.Logger } @@ -64,8 +66,15 @@ func (c *Client) query(u *url.URL, q chronograf.Query) (chronograf.Response, err params.Set("rp", q.RP) params.Set("epoch", "ms") req.URL.RawQuery = params.Encode() - httpClient := &http.Client{} - resp, err := httpClient.Do(req) + + hc := &http.Client{} + if c.InsecureSkipVerify { + tr := &http.Transport{ + TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, + } + hc.Transport = tr + } + resp, err := hc.Do(req) if err != nil { return nil, err } @@ -145,6 +154,10 @@ func (c *Client) Connect(ctx context.Context, src *chronograf.Source) error { return err } u.User = url.UserPassword(src.Username, src.Password) + // Only allow acceptance of all certs if the scheme is https AND the user opted into to the setting. + if u.Scheme == "https" && src.InsecureSkipVerify { + c.InsecureSkipVerify = src.InsecureSkipVerify + } c.URL = u return nil } diff --git a/influx/influx_test.go b/influx/influx_test.go index 1a89e219e4..8fabd3b795 100644 --- a/influx/influx_test.go +++ b/influx/influx_test.go @@ -44,6 +44,82 @@ func Test_Influx_MakesRequestsToQueryEndpoint(t *testing.T) { } } +func Test_Influx_HTTPS_Failure(t *testing.T) { + called := false + ts := httptest.NewTLSServer(http.HandlerFunc(func(rw http.ResponseWriter, r *http.Request) { + called = true + })) + defer ts.Close() + + ctx := context.Background() + var series chronograf.TimeSeries + series, err := influx.NewClient(ts.URL, log.New(log.DebugLevel)) + if err != nil { + t.Fatal("Unexpected error initializing client: err:", err) + } + + src := chronograf.Source{ + URL: ts.URL, + } + if err := series.Connect(ctx, &src); err != nil { + t.Fatal("Unexpected error connecting to client: err:", err) + } + + query := chronograf.Query{ + Command: "show databases", + } + _, err = series.Query(ctx, query) + if err == nil { + t.Error("Expected error but was successful") + } + + if called == true { + t.Error("Expected http request to fail, but, succeeded") + } + +} + +func Test_Influx_HTTPS_InsecureSkipVerify(t *testing.T) { + t.Parallel() + called := false + ts := httptest.NewTLSServer(http.HandlerFunc(func(rw http.ResponseWriter, r *http.Request) { + rw.WriteHeader(http.StatusOK) + rw.Write([]byte(`{}`)) + called = true + if path := r.URL.Path; path != "/query" { + t.Error("Expected the path to contain `/query` but was", path) + } + })) + defer ts.Close() + + ctx := context.Background() + var series chronograf.TimeSeries + series, err := influx.NewClient(ts.URL, log.New(log.DebugLevel)) + if err != nil { + t.Fatal("Unexpected error initializing client: err:", err) + } + + src := chronograf.Source{ + URL: ts.URL, + InsecureSkipVerify: true, + } + if err := series.Connect(ctx, &src); err != nil { + t.Fatal("Unexpected error connecting to client: err:", err) + } + + query := chronograf.Query{ + Command: "show databases", + } + _, err = series.Query(ctx, query) + if err != nil { + t.Fatal("Expected no error but was", err) + } + + if called == false { + t.Error("Expected http request to Influx but there was none") + } +} + func Test_Influx_CancelsInFlightRequests(t *testing.T) { t.Parallel() diff --git a/server/sources.go b/server/sources.go index 2ba2d29e5a..74c5ca3e09 100644 --- a/server/sources.go +++ b/server/sources.go @@ -150,6 +150,7 @@ func (h *Service) UpdateSource(w http.ResponseWriter, r *http.Request) { } src.Default = req.Default + src.InsecureSkipVerify = req.InsecureSkipVerify if req.Name != "" { src.Name = req.Name } diff --git a/server/swagger.json b/server/swagger.json index 042bf44538..aaa8518eeb 100644 --- a/server/swagger.json +++ b/server/swagger.json @@ -1747,7 +1747,7 @@ } } } - }, + } }, "definitions": { "Kapacitors": { @@ -1969,6 +1969,10 @@ "format": "url", "description": "URL for the time series data source backend (e.g. http://localhost:8086)" }, + "insecureSkipVerify": { + "type": "boolean", + "description": "True means any certificate presented by the source is accepted. Typically used for self-signed certs. Probably should only be used for testing." + }, "default": { "type": "boolean", "description": "Indicates whether this source is the default source" From 834f9919e54d2fa68a9b327ab2133e7a36933e20 Mon Sep 17 00:00:00 2001 From: Chris Goller Date: Thu, 5 Jan 2017 15:59:46 -0600 Subject: [PATCH 2/2] Fix formatting of swagger.json --- server/swagger.json | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/server/swagger.json b/server/swagger.json index aaa8518eeb..33c8640669 100644 --- a/server/swagger.json +++ b/server/swagger.json @@ -1969,10 +1969,10 @@ "format": "url", "description": "URL for the time series data source backend (e.g. http://localhost:8086)" }, - "insecureSkipVerify": { - "type": "boolean", - "description": "True means any certificate presented by the source is accepted. Typically used for self-signed certs. Probably should only be used for testing." - }, + "insecureSkipVerify": { + "type": "boolean", + "description": "True means any certificate presented by the source is accepted. Typically used for self-signed certs. Probably should only be used for testing." + }, "default": { "type": "boolean", "description": "Indicates whether this source is the default source"