package com.mongodb.internal.capi;
import com.mongodb.Block;
import com.mongodb.ConnectionString;
import com.mongodb.MongoClientException;
import com.mongodb.MongoClientSettings;
import com.mongodb.connection.ClusterSettings;
import com.mongodb.connection.SocketSettings;
import com.mongodb.crypt.capi.MongoAwsKmsProviderOptions;
import com.mongodb.crypt.capi.MongoCryptOptions;
import com.mongodb.crypt.capi.MongoLocalKmsProviderOptions;
import org.bson.BsonDocument;
import java.io.File;
import java.nio.ByteBuffer;
import java.util.ArrayList;
import java.util.List;
import java.util.Map;
import java.util.concurrent.TimeUnit;
public final class MongoCryptHelper {
public static MongoCryptOptions createMongoCryptOptions(final Map<String, Map<String, Object>> kmsProviders,
final Map<String, BsonDocument> namespaceToLocalSchemaDocumentMap) {
MongoCryptOptions.Builder mongoCryptOptionsBuilder = MongoCryptOptions.builder();
for (Map.Entry<String, Map<String, Object>> entry : kmsProviders.entrySet()) {
if (entry.getKey().equals("aws")) {
mongoCryptOptionsBuilder.awsKmsProviderOptions(
MongoAwsKmsProviderOptions.builder()
.accessKeyId((String) entry.getValue().get("accessKeyId"))
.secretAccessKey((String) entry.getValue().get("secretAccessKey"))
.build()
);
} else if (entry.getKey().equals("local")) {
mongoCryptOptionsBuilder.localKmsProviderOptions(
MongoLocalKmsProviderOptions.builder()
.localMasterKey(ByteBuffer.wrap((byte[]) entry.getValue().get("key")))
.build()
);
} else {
throw new MongoClientException("Unrecognized KMS provider key: " + entry.getKey());
}
}
mongoCryptOptionsBuilder.localSchemaMap(namespaceToLocalSchemaDocumentMap);
return mongoCryptOptionsBuilder.build();
}
@SuppressWarnings("unchecked")
public static List<String> createMongocryptdSpawnArgs(final Map<String, Object> options) {
List<String> spawnArgs = new ArrayList<String>();
String path = options.containsKey("mongocryptdSpawnPath")
? (String) options.get("mongocryptdSpawnPath")
: "mongocryptd";
spawnArgs.add(path);
if (options.containsKey("mongocryptdSpawnArgs")) {
spawnArgs.addAll((List<String>) options.get("mongocryptdSpawnArgs"));
}
if (!spawnArgs.contains("--idleShutdownTimeoutSecs")) {
spawnArgs.add("--idleShutdownTimeoutSecs");
spawnArgs.add("60");
}
return spawnArgs;
}
public static MongoClientSettings createMongocryptdClientSettings(final String connectionString) {
return MongoClientSettings.builder()
.applyToClusterSettings(new Block<ClusterSettings.Builder>() {
@Override
public void apply(final ClusterSettings.Builder builder) {
builder.serverSelectionTimeout(1, TimeUnit.SECONDS);
}
})
.applyToSocketSettings(new Block<SocketSettings.Builder>() {
@Override
public void apply(final SocketSettings.Builder builder) {
builder.readTimeout(1, TimeUnit.SECONDS);
builder.connectTimeout(1, TimeUnit.SECONDS);
}
})
.applyConnectionString(new ConnectionString((connectionString != null)
? connectionString : "mongodb://localhost:27020"))
.build();
}
public static ProcessBuilder createProcessBuilder(final Map<String, Object> options) {
return new ProcessBuilder(createMongocryptdSpawnArgs(options));
}
public static void startProcess(final ProcessBuilder processBuilder) {
try {
processBuilder.redirectErrorStream(true);
processBuilder.redirectOutput(new File(System.getProperty("os.name").startsWith("Windows") ? "NUL" : "/dev/null"));
processBuilder.start();
} catch (Throwable t) {
throw new MongoClientException("Exception starting mongocryptd process. Is `mongocryptd` on the system path?", t);
}
}
private MongoCryptHelper() {
}
}