|
cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
|
HTTPS JSON POST with the authenticated-Date clock cross-check. More...
#include "https_post.h"#include "civil_time.h"#include <string.h>#include <strings.h>#include <time.h>#include <inttypes.h>#include "CW_Utils.h"#include "esp_log.h"#include "esp_http_client.h"#include "esp_crt_bundle.h"#include "wdt.h"Go to the source code of this file.
Classes | |
| struct | resp_hdrs_t |
| Response headers captured during fetch (see http_event_cb). More... | |
Macros | |
| #define | RESP_LOG_MAX 80 |
| #define | CLOCK_SKEW_MAX_S 300 |
Functions | |
| static esp_err_t | http_event_cb (esp_http_client_event_t *evt) |
| HTTP event hook that captures the response Date header. | |
| static bool | clock_corroborated (const char *date_hdr) |
| Cross-check the system clock against the server's HTTP Date header. | |
| bool | https_post_json (const char *url, const char *body, char *resp_buf, size_t resp_buf_size, const char *user, const char *pass, const char *ca_pem) |
| POST a JSON body over HTTPS and read the response. | |
Variables | |
| static const char *const | TAG = "https" |
HTTPS JSON POST with the authenticated-Date clock cross-check.
Definition in file https_post.cpp.
| #define CLOCK_SKEW_MAX_S 300 |
Definition at line 44 of file https_post.cpp.
Referenced by clock_corroborated().
| #define RESP_LOG_MAX 80 |
Definition at line 37 of file https_post.cpp.
|
static |
Cross-check the system clock against the server's HTTP Date header.
SNTP gave us the clock over plain unauthenticated UDP, so a network attacker can dictate it. This header arrives inside the encrypted, authenticated TLS channel — without the CA's private key it can be neither forged nor altered, which makes it a strictly better time source than the handshake (ServerHello.random's gmt_unix_time is pure random in TLS 1.3 and esp_http_client does not expose it anyway).
Must be called after esp_http_client_fetch_headers().
A missing or non-conforming header yields "not corroborated", not "disagrees": the response already passed TLS validation, so an absent header means the provider genuinely omitted it, and failing the payment over that would be a self-inflicted outage. An attacker cannot induce this case without breaking TLS.
| [in] | date_hdr | Captured Date value; "" when the server sent none. |
Definition at line 105 of file https_post.cpp.
References civil_parse_http_date(), CLOCK_SKEW_MAX_S, and TAG.
Referenced by https_post_json().
|
static |
HTTP event hook that captures the response Date header.
Response headers are ONLY reachable this way. esp_http_client_get_header() looks up client->request->headers — the headers we send — so it can never return the server's Date, however plausible the name looks.
| [in] | evt | Event; user_data points at the caller's resp_hdrs_t. |
Definition at line 66 of file https_post.cpp.
References resp_hdrs_t::date.
Referenced by https_post_json().
| bool https_post_json | ( | const char * | url, |
| const char * | body, | ||
| char * | resp_buf, | ||
| size_t | resp_buf_size, | ||
| const char * | user, | ||
| const char * | pass, | ||
| const char * | ca_pem ) |
POST a JSON body over HTTPS and read the response.
The response is read until EOF or buffer-full and is always NUL-terminated. The server's Date header is cross-checked against the system clock; a parseable header that disagrees by more than five minutes fails the call (see https_post.cpp for why that is the right verdict).
| [in] | url | Full HTTPS endpoint URL. |
| [in] | body | JSON request body (NUL-terminated). |
| [out] | resp_buf | Response buffer, NUL-terminated on return. |
| [in] | resp_buf_size | Capacity of resp_buf. |
| [in] | user | HTTP Basic Auth username, or NULL/"" for none. |
| [in] | pass | HTTP Basic Auth password, or NULL/"" for none. |
| [in] | ca_pem | PEM certificate to validate against instead of the Mozilla CA bundle, or NULL for the bundle. |
Definition at line 140 of file https_post.cpp.
References clock_corroborated(), resp_hdrs_t::date, http_event_cb(), RESP_LOG_MAX, TAG, and wdt_feed().
Referenced by do_post(), and tron_post().
|
static |
Definition at line 33 of file https_post.cpp.