cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
https_post.cpp File Reference

HTTPS JSON POST with the authenticated-Date clock cross-check. More...

#include "https_post.h"
#include "civil_time.h"
#include <string.h>
#include <strings.h>
#include <time.h>
#include <inttypes.h>
#include "CW_Utils.h"
#include "esp_log.h"
#include "esp_http_client.h"
#include "esp_crt_bundle.h"
#include "wdt.h"
Include dependency graph for https_post.cpp:

Go to the source code of this file.

Classes

struct  resp_hdrs_t
 Response headers captured during fetch (see http_event_cb). More...

Macros

#define RESP_LOG_MAX   80
#define CLOCK_SKEW_MAX_S   300

Functions

static esp_err_t http_event_cb (esp_http_client_event_t *evt)
 HTTP event hook that captures the response Date header.
static bool clock_corroborated (const char *date_hdr)
 Cross-check the system clock against the server's HTTP Date header.
bool https_post_json (const char *url, const char *body, char *resp_buf, size_t resp_buf_size, const char *user, const char *pass, const char *ca_pem)
 POST a JSON body over HTTPS and read the response.

Variables

static const char *const TAG = "https"

Detailed Description

HTTPS JSON POST with the authenticated-Date clock cross-check.

Definition in file https_post.cpp.

Macro Definition Documentation

◆ CLOCK_SKEW_MAX_S

#define CLOCK_SKEW_MAX_S   300

Definition at line 44 of file https_post.cpp.

Referenced by clock_corroborated().

◆ RESP_LOG_MAX

#define RESP_LOG_MAX   80

Definition at line 37 of file https_post.cpp.

Function Documentation

◆ clock_corroborated()

bool clock_corroborated ( const char * date_hdr)
static

Cross-check the system clock against the server's HTTP Date header.

SNTP gave us the clock over plain unauthenticated UDP, so a network attacker can dictate it. This header arrives inside the encrypted, authenticated TLS channel — without the CA's private key it can be neither forged nor altered, which makes it a strictly better time source than the handshake (ServerHello.random's gmt_unix_time is pure random in TLS 1.3 and esp_http_client does not expose it anyway).

Must be called after esp_http_client_fetch_headers().

A missing or non-conforming header yields "not corroborated", not "disagrees": the response already passed TLS validation, so an absent header means the provider genuinely omitted it, and failing the payment over that would be a self-inflicted outage. An attacker cannot induce this case without breaking TLS.

Parameters
[in]date_hdrCaptured Date value; "" when the server sent none.
Returns
false only when a parseable Date disagrees with the local clock by more than CLOCK_SKEW_MAX_S; true otherwise.

Definition at line 105 of file https_post.cpp.

References civil_parse_http_date(), CLOCK_SKEW_MAX_S, and TAG.

Referenced by https_post_json().

◆ http_event_cb()

esp_err_t http_event_cb ( esp_http_client_event_t * evt)
static

HTTP event hook that captures the response Date header.

Response headers are ONLY reachable this way. esp_http_client_get_header() looks up client->request->headers — the headers we send — so it can never return the server's Date, however plausible the name looks.

Parameters
[in]evtEvent; user_data points at the caller's resp_hdrs_t.
Returns
ESP_OK always (never fail a transfer over a header we merely want).

Definition at line 66 of file https_post.cpp.

References resp_hdrs_t::date.

Referenced by https_post_json().

◆ https_post_json()

bool https_post_json ( const char * url,
const char * body,
char * resp_buf,
size_t resp_buf_size,
const char * user,
const char * pass,
const char * ca_pem )

POST a JSON body over HTTPS and read the response.

The response is read until EOF or buffer-full and is always NUL-terminated. The server's Date header is cross-checked against the system clock; a parseable header that disagrees by more than five minutes fails the call (see https_post.cpp for why that is the right verdict).

Parameters
[in]urlFull HTTPS endpoint URL.
[in]bodyJSON request body (NUL-terminated).
[out]resp_bufResponse buffer, NUL-terminated on return.
[in]resp_buf_sizeCapacity of resp_buf.
[in]userHTTP Basic Auth username, or NULL/"" for none.
[in]passHTTP Basic Auth password, or NULL/"" for none.
[in]ca_pemPEM certificate to validate against instead of the Mozilla CA bundle, or NULL for the bundle.
Returns
true only if at least one byte was read AND the server answered HTTP 200; false on transport error, non-200 status or clock refusal.

Definition at line 140 of file https_post.cpp.

References clock_corroborated(), resp_hdrs_t::date, http_event_cb(), RESP_LOG_MAX, TAG, and wdt_feed().

Referenced by do_post(), and tron_post().

Variable Documentation

◆ TAG

const char* const TAG = "https"
static

Definition at line 33 of file https_post.cpp.