/* * Copyright (c) 2010-2016 Isode Limited. * All rights reserved. * See the COPYING file for more information. */ #pragma once #include #include #include #include #include #include #include #include namespace Swift { class CertificateTrustChecker; class ClientAuthenticator; class CryptoProvider; class IDNConverter; class Stanza; class StanzaAckRequester; class StanzaAckResponder; class TimerFactory; class Timer; class SWIFTEN_API ClientSession : public std::enable_shared_from_this { public: enum class State { Initial, WaitingForStreamStart, Negotiating, Compressing, WaitingForEncrypt, Encrypting, WaitingForCredentials, Authenticating, EnablingSessionManagement, BindingResource, StartingSession, Initialized, Finishing, Finished }; struct Error : public Swift::Error { enum Type { AuthenticationFailedError, CompressionFailedError, ServerVerificationFailedError, NoSupportedAuthMechanismsError, UnexpectedElementError, ResourceBindError, SessionStartError, TLSClientCertificateError, TLSError, StreamError, StreamEndError, // The server send a closing stream tag. } type; std::shared_ptr errorCode; Error(Type type) : type(type) {} }; enum UseTLS { NeverUseTLS, UseTLSWhenAvailable, RequireTLS }; ~ClientSession(); static std::shared_ptr create(const JID& jid, std::shared_ptr stream, IDNConverter* idnConverter, CryptoProvider* crypto, TimerFactory* timerFactory) { return std::shared_ptr(new ClientSession(jid, stream, idnConverter, crypto, timerFactory)); } State getState() const { return state; } void setAllowPLAINOverNonTLS(bool b) { allowPLAINOverNonTLS = b; } void setUseStreamCompression(bool b) { useStreamCompression = b; } void setUseTLS(UseTLS b) { useTLS = b; } void setUseAcks(bool b) { useAcks = b; } bool getStreamManagementEnabled() const { // Explicitly convert to bool. In C++11, it would be cleaner to // compare to nullptr. return static_cast(stanzaAckRequester_); } bool getRosterVersioningSupported() const { return rosterVersioningSupported; } std::vector getPeerCertificateChain() const { return stream->getPeerCertificateChain(); } const JID& getLocalJID() const { return localJID; } void start(); void finish(); bool isFinished() const { return getState() == State::Finished; } void sendCredentials(const SafeByteArray& password); void sendStanza(std::shared_ptr); void setCertificateTrustChecker(CertificateTrustChecker* checker) { certificateTrustChecker = checker; } void setSingleSignOn(bool b) { singleSignOn = b; } /** * Sets the port number used in Kerberos authentication * Does not affect network connectivity. */ void setAuthenticationPort(int i) { authenticationPort = i; } void setSessionShutdownTimeout(int timeoutInMilliseconds) { sessionShutdownTimeoutInMilliseconds = timeoutInMilliseconds; } public: boost::signals2::signal onNeedCredentials; boost::signals2::signal onInitialized; boost::signals2::signal)> onFinished; boost::signals2::signal)> onStanzaReceived; boost::signals2::signal)> onStanzaAcked; private: ClientSession( const JID& jid, std::shared_ptr, IDNConverter* idnConverter, CryptoProvider* crypto, TimerFactory* timerFactory); void finishSession(Error::Type error); void finishSession(std::shared_ptr error); JID getRemoteJID() const { return JID("", localJID.getDomain()); } void sendStreamHeader(); void handleElement(std::shared_ptr); void handleStreamStart(const ProtocolHeader&); void handleStreamEnd(); void handleStreamClosed(std::shared_ptr); void handleStreamShutdownTimeout(); void handleTLSEncrypted(); bool checkState(State); void continueSessionInitialization(); void requestAck(); void handleStanzaAcked(std::shared_ptr stanza); void ack(unsigned int handledStanzasCount); void continueAfterTLSEncrypted(); void checkTrustOrFinish(const std::vector& certificateChain, std::shared_ptr error); void initiateShutdown(bool sendFooter); private: JID localJID; State state; std::shared_ptr stream; IDNConverter* idnConverter = nullptr; CryptoProvider* crypto = nullptr; TimerFactory* timerFactory = nullptr; std::shared_ptr streamShutdownTimeout; int sessionShutdownTimeoutInMilliseconds = 10000; bool allowPLAINOverNonTLS; bool useStreamCompression; UseTLS useTLS; bool useAcks; bool needSessionStart; bool needResourceBind; bool needAcking; bool rosterVersioningSupported; ClientAuthenticator* authenticator; std::shared_ptr stanzaAckRequester_; std::shared_ptr stanzaAckResponder_; std::shared_ptr error_; CertificateTrustChecker* certificateTrustChecker; bool singleSignOn; int authenticationPort; }; }