feat(cert-manager): Zertifikatspaket hochladen, erkennen und in jedem Format herunterladen
Neuer erster Reiter Übersicht: mehrere Dateien oder die ZIP vom Aussteller auf einmal ablegen. Der Server erkennt jedes Teil (Server-, Zwischen-, Stammzertifikat, privater Schlüssel, CSR, auch aus PFX/P7B), fasst Duplikate zusammen, ordnet Schlüssel/CSR dem Zertifikat zu und baut die Kette. Unter jedem Teil stehen Download-Knöpfe für alle passenden Formate (crt, cer, Fullchain, p7b, pfx mit Schlüssel und Kette; key PKCS#8/PKCS#1/ DER; csr PEM/DER). Geschützte PFX lassen sich mit Passwort entsperren. Neue Endpunkte POST analyze (Dateien/ZIP, Begrenzung Anzahl und Größe vor dem Entpacken) und POST export (JSON, zustandslos). Modultexte siezen jetzt durchgehend; Gültigkeit in UTC wie im Zertifikat. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -10,6 +10,12 @@ import {
|
||||
import { FileInterceptor, FilesInterceptor } from '@nestjs/platform-express';
|
||||
import { UseModule } from '../module-registry/module.guard';
|
||||
import type { UploadedFileLike } from '../auth/types/auth-user';
|
||||
import {
|
||||
analyzeBundle,
|
||||
type BundleExportFormat,
|
||||
type BundleItemKind,
|
||||
exportBundleItem,
|
||||
} from './cert-bundle';
|
||||
import { CertManagerService } from './cert-manager.service';
|
||||
|
||||
/**
|
||||
@@ -118,4 +124,50 @@ export class CertManagerController {
|
||||
}
|
||||
return this.certManagerService.convertCert({ file, pemText, targetFormat, password });
|
||||
}
|
||||
|
||||
/**
|
||||
* POST /modules/cert-manager/analyze (quick-261001-l4q)
|
||||
* Zertifikatspaket: mehrere Dateien oder ZIP hochladen, jedes Teil erkennen
|
||||
* (Server-/Zwischen-/Stammzertifikat, privater Schluessel, CSR), Duplikate
|
||||
* zusammenfassen, Schluessel und Kette zuordnen.
|
||||
*
|
||||
* T-09-03: 20 Dateien, je 5 MB; ZIP-Inhalt zusaetzlich begrenzt (cert-bundle.ts).
|
||||
* T-09-02: password is never passed to the logger
|
||||
*/
|
||||
@Post('analyze')
|
||||
@UseInterceptors(
|
||||
FilesInterceptor('files', 20, {
|
||||
limits: { fileSize: 5 * 1024 * 1024 },
|
||||
}),
|
||||
)
|
||||
async analyze(
|
||||
@UploadedFiles() files: UploadedFileLike[] | undefined,
|
||||
@Body('password') password?: string,
|
||||
) {
|
||||
return analyzeBundle(files ?? [], password ?? '');
|
||||
}
|
||||
|
||||
/**
|
||||
* POST /modules/cert-manager/export (quick-261001-l4q)
|
||||
* Ein Teil aus `analyze` (PEM) in das gewuenschte Format bringen.
|
||||
* JSON-Body; PFX verlangt ein Passwort fuer die neue Datei.
|
||||
*/
|
||||
@Post('export')
|
||||
async export(
|
||||
@Body('kind') kind: BundleItemKind,
|
||||
@Body('pem') pem: string,
|
||||
@Body('format') format: BundleExportFormat,
|
||||
@Body('baseName') baseName?: string,
|
||||
@Body('chain') chain?: string[],
|
||||
@Body('keyPem') keyPem?: string,
|
||||
@Body('password') password?: string,
|
||||
) {
|
||||
if (
|
||||
chain !== undefined &&
|
||||
(!Array.isArray(chain) || chain.some((c) => typeof c !== 'string'))
|
||||
) {
|
||||
throw new BadRequestException('chain must be a list of PEM strings');
|
||||
}
|
||||
return exportBundleItem({ kind, pem, format, baseName, chain, keyPem, password });
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user