. /** * ActivityPub implementation for GNU social * * @package GNUsocial * @author Diogo Cordeiro * @copyright 2018-2019 Free Software Foundation, Inc http://www.fsf.org * @license https://www.gnu.org/licenses/agpl.html GNU AGPL v3 or later * @link http://www.gnu.org/software/social/ */ defined('GNUSOCIAL') || die(); /** * ActivityPub Keys System * * @category Plugin * @package GNUsocial * @author Diogo Cordeiro * @license https://www.gnu.org/licenses/agpl.html GNU AGPL v3 or later */ class Activitypub_rsa extends Managed_DataObject { public $__table = 'activitypub_rsa'; public $profile_id; // int(4) primary_key not_null public $private_key; // text() not_null public $public_key; // text() not_null public $created; // datetime() not_null default_CURRENT_TIMESTAMP public $modified; // datetime() not_null default_CURRENT_TIMESTAMP /** * Return table definition for Schema setup and DB_DataObject usage. * * @return array array of column definitions * @author Diogo Cordeiro */ public static function schemaDef() { return [ 'fields' => [ 'profile_id' => ['type' => 'int', 'not null' => true], 'private_key' => ['type' => 'text'], 'public_key' => ['type' => 'text', 'not null' => true], 'created' => ['type' => 'datetime', 'not null' => true, 'default' => 'CURRENT_TIMESTAMP', 'description' => 'date this record was created'], 'modified' => ['type' => 'datetime', 'not null' => true, 'default' => 'CURRENT_TIMESTAMP', 'description' => 'date this record was modified'], ], 'primary key' => ['profile_id'], 'foreign keys' => [ 'activitypub_profile_profile_id_fkey' => ['profile', ['profile_id' => 'id']], ], ]; } /** * Private key getter * * @param Profile $profile * @return string * @throws ServerException * @throws Exception */ public function get_private_key(Profile $profile): string { $this->profile_id = $profile->getID(); $apRSA = self::getKV('profile_id', $this->profile_id); if (!$apRSA instanceof Activitypub_rsa) { // No existing key pair for this profile if ($profile->isLocal()) { self::generate_keys($this->private_key, $this->public_key); $this->store_keys(); $apRSA->private_key = $this->private_key; } else { throw new Exception('This is a remote Profile, there is no Private Key for this Profile.'); } } return $apRSA->private_key; } /** * Guarantees a Public Key for a given profile. * * @param Profile $profile * @param bool $fetch * @return string The public key * @throws ServerException It should never occur, but if so, we break everything! * @throws Exception * @author Diogo Cordeiro */ public function ensure_public_key(Profile $profile, bool $fetch = true): string { $this->profile_id = $profile->getID(); $apRSA = self::getKV('profile_id', $this->profile_id); if (!$apRSA instanceof Activitypub_rsa) { // No existing key pair for this profile if ($profile->isLocal()) { self::generate_keys($this->private_key, $this->public_key); $this->store_keys(); $apRSA->public_key = $this->public_key; } else { // This should never happen, but try to recover! if ($fetch) { $res = Activitypub_explorer::get_remote_user_activity(ActivityPubPlugin::actor_uri($profile)); Activitypub_rsa::update_public_key($profile, $res['publicKey']['publicKeyPem']); return self::ensure_public_key($profile, false); } else { throw new ServerException('Activitypub_rsa: Failed to find keys for given profile. That should have not happened!'); } } } return $apRSA->public_key; } /** * Insert the current object variables into the database. * * @throws ServerException * @author Diogo Cordeiro * @access public */ public function store_keys(): void { $this->created = $this->modified = common_sql_now(); $ok = $this->insert(); if ($ok === false) { throw new ServerException('Cannot save ActivityPub RSA.'); } } /** * Generates a pair of RSA keys. * * @param string $private_key in/out * @param string $public_key in/out * @author PHP Manual Contributed Notes */ public static function generate_keys(string &$private_key, string &$public_key): void { $config = [ 'digest_alg' => 'sha512', 'private_key_bits' => 2048, 'private_key_type' => OPENSSL_KEYTYPE_RSA, ]; // Create the private and public key $res = openssl_pkey_new($config); // Extract the private key from $res to $private_key openssl_pkey_export($res, $private_key); // Extract the public key from $res to $pubKey $pubKey = openssl_pkey_get_details($res); $public_key = $pubKey["key"]; unset($pubKey); } /** * Update public key. * * @param Profile|Activitypub_profile $profile * @param string $public_key * @throws Exception * @author Diogo Cordeiro */ public static function update_public_key($profile, string $public_key): void { // Public Key $apRSA = new Activitypub_rsa(); $apRSA->profile_id = $profile->getID(); $apRSA->public_key = $public_key; $apRSA->modified = common_sql_now(); if (!$apRSA->update()) { $apRSA->insert(); } } }