mirror of
https://github.com/jambonz/sbc-inbound.git
synced 2026-10-04 02:04:22 +00:00
Feat: jambonz clients (#104)
* authenticate user * authenticate user * update db helper * update db helper * fix jslint * use digest-utils
This commit is contained in:
@@ -76,7 +76,8 @@ const {
|
|||||||
lookupAccountBySipRealm,
|
lookupAccountBySipRealm,
|
||||||
lookupAccountBySid,
|
lookupAccountBySid,
|
||||||
lookupAccountCapacitiesBySid,
|
lookupAccountCapacitiesBySid,
|
||||||
queryCallLimits
|
queryCallLimits,
|
||||||
|
lookupClientByAccountAndUsername
|
||||||
} = require('@jambonz/db-helpers')({
|
} = require('@jambonz/db-helpers')({
|
||||||
host: process.env.JAMBONES_MYSQL_HOST,
|
host: process.env.JAMBONES_MYSQL_HOST,
|
||||||
port: process.env.JAMBONES_MYSQL_PORT || 3306,
|
port: process.env.JAMBONES_MYSQL_PORT || 3306,
|
||||||
@@ -125,7 +126,8 @@ srf.locals = {...srf.locals,
|
|||||||
lookupAccountBySid,
|
lookupAccountBySid,
|
||||||
lookupAccountBySipRealm,
|
lookupAccountBySipRealm,
|
||||||
lookupAccountCapacitiesBySid,
|
lookupAccountCapacitiesBySid,
|
||||||
queryCallLimits
|
queryCallLimits,
|
||||||
|
lookupClientByAccountAndUsername
|
||||||
},
|
},
|
||||||
realtimeDbHelpers: {
|
realtimeDbHelpers: {
|
||||||
createSet,
|
createSet,
|
||||||
|
|||||||
+9
-40
@@ -1,8 +1,8 @@
|
|||||||
const debug = require('debug')('jambonz:sbc-inbound');
|
const debug = require('debug')('jambonz:sbc-inbound');
|
||||||
const assert = require('assert');
|
const assert = require('assert');
|
||||||
const Emitter = require('events');
|
|
||||||
const parseUri = require('drachtio-srf').parseUri;
|
const parseUri = require('drachtio-srf').parseUri;
|
||||||
const {nudgeCallCounts, roundTripTime} = require('./utils');
|
const {nudgeCallCounts, roundTripTime} = require('./utils');
|
||||||
|
const digestChallenge = require('@jambonz/digest-utils');
|
||||||
const msProxyIps = process.env.MS_TEAMS_SIP_PROXY_IPS ?
|
const msProxyIps = process.env.MS_TEAMS_SIP_PROXY_IPS ?
|
||||||
process.env.MS_TEAMS_SIP_PROXY_IPS.split(',').map((i) => i.trim()) :
|
process.env.MS_TEAMS_SIP_PROXY_IPS.split(',').map((i) => i.trim()) :
|
||||||
[];
|
[];
|
||||||
@@ -22,42 +22,8 @@ const initCdr = (req) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
module.exports = function(srf, logger) {
|
module.exports = function(srf, logger) {
|
||||||
class AuthOutcomeReporter extends Emitter {
|
|
||||||
constructor(stats) {
|
|
||||||
super();
|
|
||||||
this
|
|
||||||
.on('regHookOutcome', ({rtt, status}) => {
|
|
||||||
stats.histogram('app.hook.response_time', rtt, ['hook_type:auth', `status:${status}`]);
|
|
||||||
})
|
|
||||||
.on('error', async(err, req) => {
|
|
||||||
const {account_sid, account} = req.locals;
|
|
||||||
const {writeAlerts, AlertType} = req.srf.locals;
|
|
||||||
if (account_sid) {
|
|
||||||
let opts = {account_sid, service_provider_sid: account.service_provider_sid};
|
|
||||||
if (err.code === 'ECONNREFUSED') {
|
|
||||||
opts = {...opts, alert_type: AlertType.WEBHOOK_CONNECTION_FAILURE, url: err.hook};
|
|
||||||
}
|
|
||||||
else if (err.code === 'ENOTFOUND') {
|
|
||||||
opts = {...opts, alert_type: AlertType.WEBHOOK_CONNECTION_FAILURE, url: err.hook};
|
|
||||||
}
|
|
||||||
else if (err.name === 'StatusError') {
|
|
||||||
opts = {...opts, alert_type: AlertType.WEBHOOK_STATUS_FAILURE, url: err.hook, status: err.statusCode};
|
|
||||||
}
|
|
||||||
|
|
||||||
if (opts.alert_type) {
|
|
||||||
try {
|
|
||||||
await writeAlerts(opts);
|
|
||||||
} catch (err) {
|
|
||||||
logger.error({err, opts}, 'Error writing alert');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const {
|
const {
|
||||||
lookupAuthHook,
|
|
||||||
lookupAppByTeamsTenant,
|
lookupAppByTeamsTenant,
|
||||||
lookupAccountBySipRealm,
|
lookupAccountBySipRealm,
|
||||||
lookupAccountBySid,
|
lookupAccountBySid,
|
||||||
@@ -65,10 +31,6 @@ module.exports = function(srf, logger) {
|
|||||||
queryCallLimits
|
queryCallLimits
|
||||||
} = srf.locals.dbHelpers;
|
} = srf.locals.dbHelpers;
|
||||||
const {stats, writeCdrs} = srf.locals;
|
const {stats, writeCdrs} = srf.locals;
|
||||||
const authenticator = require('@jambonz/http-authenticator')(lookupAuthHook, logger, {
|
|
||||||
blacklistUnknownRealms: true,
|
|
||||||
emitter: new AuthOutcomeReporter(stats)
|
|
||||||
});
|
|
||||||
|
|
||||||
const initLocals = (req, res, next) => {
|
const initLocals = (req, res, next) => {
|
||||||
const callId = req.get('Call-ID');
|
const callId = req.get('Call-ID');
|
||||||
@@ -240,6 +202,13 @@ module.exports = function(srf, logger) {
|
|||||||
account,
|
account,
|
||||||
application_sid: account.device_calling_application_sid,
|
application_sid: account.device_calling_application_sid,
|
||||||
webhook_secret: account.webhook_secret,
|
webhook_secret: account.webhook_secret,
|
||||||
|
realm: uri.host,
|
||||||
|
...(account.registration_hook && {
|
||||||
|
registration_hook_url: account.registration_hook.url,
|
||||||
|
registration_hook_method: account.registration_hook.method,
|
||||||
|
registration_hook_username: account.registration_hook.username,
|
||||||
|
registration_hook_password: account.registration_hook.password
|
||||||
|
}),
|
||||||
...req.locals
|
...req.locals
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -382,7 +351,7 @@ module.exports = function(srf, logger) {
|
|||||||
try {
|
try {
|
||||||
/* TODO: check if this is a gateway that we have an ACL for */
|
/* TODO: check if this is a gateway that we have an ACL for */
|
||||||
if (req.locals.originator !== 'user') return next();
|
if (req.locals.originator !== 'user') return next();
|
||||||
return authenticator(req, res, next);
|
return digestChallenge(req, res, next);
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
stats.increment('sbc.terminations', ['sipStatus:500']);
|
stats.increment('sbc.terminations', ['sipStatus:500']);
|
||||||
logger.error(err, `${req.get('Call-ID')} Error looking up related info for inbound call`);
|
logger.error(err, `${req.get('Call-ID')} Error looking up related info for inbound call`);
|
||||||
|
|||||||
Generated
+18
-20
@@ -9,8 +9,8 @@
|
|||||||
"version": "0.8.3",
|
"version": "0.8.3",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@jambonz/db-helpers": "^0.9.0",
|
"@jambonz/db-helpers": "^0.9.1",
|
||||||
"@jambonz/http-authenticator": "^0.2.2",
|
"@jambonz/digest-utils": "^0.0.2",
|
||||||
"@jambonz/http-health-check": "^0.0.1",
|
"@jambonz/http-health-check": "^0.0.1",
|
||||||
"@jambonz/realtimedb-helpers": "^0.8.6",
|
"@jambonz/realtimedb-helpers": "^0.8.6",
|
||||||
"@jambonz/rtpengine-utils": "^0.4.3",
|
"@jambonz/rtpengine-utils": "^0.4.3",
|
||||||
@@ -600,9 +600,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@jambonz/db-helpers": {
|
"node_modules/@jambonz/db-helpers": {
|
||||||
"version": "0.9.0",
|
"version": "0.9.1",
|
||||||
"resolved": "https://registry.npmjs.org/@jambonz/db-helpers/-/db-helpers-0.9.0.tgz",
|
"resolved": "https://registry.npmjs.org/@jambonz/db-helpers/-/db-helpers-0.9.1.tgz",
|
||||||
"integrity": "sha512-4fvwONj4jQNIHyG76WGdE7AuMt9vDl4sfHmHrY3PSgOh+kf2BCtBEYqoxyJ96/NH9OeUYkuXoM6fjSvpS7GYVw==",
|
"integrity": "sha512-asQQdeQEl1jCyQAxp2kMljZzExQbcG/mBxVYA2Jf0E1ReZctC206LWMWmY/rvbSHHXNZBzJlNxhD0dQB+FtJYA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"cidr-matcher": "^2.1.1",
|
"cidr-matcher": "^2.1.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
@@ -611,14 +611,13 @@
|
|||||||
"uuid": "^8.3.2"
|
"uuid": "^8.3.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@jambonz/http-authenticator": {
|
"node_modules/@jambonz/digest-utils": {
|
||||||
"version": "0.2.2",
|
"version": "0.0.2",
|
||||||
"resolved": "https://registry.npmjs.org/@jambonz/http-authenticator/-/http-authenticator-0.2.2.tgz",
|
"resolved": "https://registry.npmjs.org/@jambonz/digest-utils/-/digest-utils-0.0.2.tgz",
|
||||||
"integrity": "sha512-yl6CajF8c8BOTrXEB/AbTXgqrT6XeymwVZbJWeJG8HZA21UXkKCcM26b8f0P9qqokSvFj0ObjCk22Ks2ytSLNg==",
|
"integrity": "sha512-TcUpHQZZ+69mnU6wA3pBcq17l9NbRZCQLJY7g/i9eaRONpAfw6vYkRWF7GtIaJat9Gu18tVs4idHvbfiqx40tA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"bent": "^7.3.12",
|
"bent": "^7.3.12",
|
||||||
"debug": "^4.3.1",
|
"debug": "^4.3.4",
|
||||||
"drachtio-srf": "^4.4.63",
|
|
||||||
"nonce": "^1.0.4",
|
"nonce": "^1.0.4",
|
||||||
"qs": "^6.9.4"
|
"qs": "^6.9.4"
|
||||||
}
|
}
|
||||||
@@ -5748,9 +5747,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"@jambonz/db-helpers": {
|
"@jambonz/db-helpers": {
|
||||||
"version": "0.9.0",
|
"version": "0.9.1",
|
||||||
"resolved": "https://registry.npmjs.org/@jambonz/db-helpers/-/db-helpers-0.9.0.tgz",
|
"resolved": "https://registry.npmjs.org/@jambonz/db-helpers/-/db-helpers-0.9.1.tgz",
|
||||||
"integrity": "sha512-4fvwONj4jQNIHyG76WGdE7AuMt9vDl4sfHmHrY3PSgOh+kf2BCtBEYqoxyJ96/NH9OeUYkuXoM6fjSvpS7GYVw==",
|
"integrity": "sha512-asQQdeQEl1jCyQAxp2kMljZzExQbcG/mBxVYA2Jf0E1ReZctC206LWMWmY/rvbSHHXNZBzJlNxhD0dQB+FtJYA==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"cidr-matcher": "^2.1.1",
|
"cidr-matcher": "^2.1.1",
|
||||||
"debug": "^4.3.4",
|
"debug": "^4.3.4",
|
||||||
@@ -5759,14 +5758,13 @@
|
|||||||
"uuid": "^8.3.2"
|
"uuid": "^8.3.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"@jambonz/http-authenticator": {
|
"@jambonz/digest-utils": {
|
||||||
"version": "0.2.2",
|
"version": "0.0.2",
|
||||||
"resolved": "https://registry.npmjs.org/@jambonz/http-authenticator/-/http-authenticator-0.2.2.tgz",
|
"resolved": "https://registry.npmjs.org/@jambonz/digest-utils/-/digest-utils-0.0.2.tgz",
|
||||||
"integrity": "sha512-yl6CajF8c8BOTrXEB/AbTXgqrT6XeymwVZbJWeJG8HZA21UXkKCcM26b8f0P9qqokSvFj0ObjCk22Ks2ytSLNg==",
|
"integrity": "sha512-TcUpHQZZ+69mnU6wA3pBcq17l9NbRZCQLJY7g/i9eaRONpAfw6vYkRWF7GtIaJat9Gu18tVs4idHvbfiqx40tA==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"bent": "^7.3.12",
|
"bent": "^7.3.12",
|
||||||
"debug": "^4.3.1",
|
"debug": "^4.3.4",
|
||||||
"drachtio-srf": "^4.4.63",
|
|
||||||
"nonce": "^1.0.4",
|
"nonce": "^1.0.4",
|
||||||
"qs": "^6.9.4"
|
"qs": "^6.9.4"
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-2
@@ -25,14 +25,14 @@
|
|||||||
"jslint": "eslint app.js lib"
|
"jslint": "eslint app.js lib"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@jambonz/db-helpers": "^0.9.0",
|
"@jambonz/db-helpers": "^0.9.1",
|
||||||
"@jambonz/http-authenticator": "^0.2.2",
|
|
||||||
"@jambonz/http-health-check": "^0.0.1",
|
"@jambonz/http-health-check": "^0.0.1",
|
||||||
"@jambonz/realtimedb-helpers": "^0.8.6",
|
"@jambonz/realtimedb-helpers": "^0.8.6",
|
||||||
"@jambonz/rtpengine-utils": "^0.4.3",
|
"@jambonz/rtpengine-utils": "^0.4.3",
|
||||||
"@jambonz/siprec-client-utils": "^0.2.5",
|
"@jambonz/siprec-client-utils": "^0.2.5",
|
||||||
"@jambonz/stats-collector": "^0.1.8",
|
"@jambonz/stats-collector": "^0.1.8",
|
||||||
"@jambonz/time-series": "^0.2.5",
|
"@jambonz/time-series": "^0.2.5",
|
||||||
|
"@jambonz/digest-utils": "^0.0.2",
|
||||||
"aws-sdk": "^2.1354.0",
|
"aws-sdk": "^2.1354.0",
|
||||||
"bent": "^7.3.12",
|
"bent": "^7.3.12",
|
||||||
"cidr-matcher": "^2.1.1",
|
"cidr-matcher": "^2.1.1",
|
||||||
|
|||||||
Reference in New Issue
Block a user