/** * gcr_secret_exchange_get_protocol: * @self: a #GcrSecretExchange object * Get the secret exchange protocol. * * Will return %NULL if no protocol was specified, and either * gcr_secret_exchange_begin() or gcr_secret_exchange_receive() have not been * called successfully. * * Returns: the protocol or %NULL */ const gchar * gcr_secret_exchange_get_protocol (GcrSecretExchange *self) { g_return_val_if_fail (GCR_IS_SECRET_EXCHANGE (self), NULL); if (self->pv->explicit_protocol || self->pv->generated) return GCR_SECRET_EXCHANGE_PROTOCOL_1; return NULL; }
/** * gcr_secret_exchange_receive: * @self: a #GcrSecretExchange object * @exchange: the string received * * Receive a string from the other side of secret exchange. This string will * have been created by gcr_secret_exchange_begin() or gcr_secret_exchange_send(). * * After this call completes successfully the value returned from * gcr_secret_exchange_get_secret() will have changed. * * Returns: whether the string was successfully parsed and received */ gboolean gcr_secret_exchange_receive (GcrSecretExchange *self, const gchar *exchange) { GcrSecretExchangeClass *klass; gchar *secret = NULL; gsize n_secret = 0; GKeyFile *input; gboolean ret; g_return_val_if_fail (GCR_IS_SECRET_EXCHANGE (self), FALSE); g_return_val_if_fail (exchange != NULL, FALSE); klass = GCR_SECRET_EXCHANGE_GET_CLASS (self); g_return_val_if_fail (klass->generate_exchange_key, FALSE); g_return_val_if_fail (klass->derive_transport_key, FALSE); gchar *string = g_strescape (exchange, ""); g_debug ("receiving secret exchange: %s", string); g_free (string); /* Parse the input */ input = g_key_file_new (); if (!g_key_file_load_from_data (input, exchange, strlen (exchange), G_KEY_FILE_NONE, NULL)) { g_key_file_free (input); g_message ("couldn't parse secret exchange data"); return FALSE; } if (!self->pv->generated) { if (!(klass->generate_exchange_key) (self, GCR_SECRET_EXCHANGE_PROTOCOL_1, &self->pv->publi, &self->pv->n_publi)) g_return_val_if_reached (FALSE); self->pv->generated = TRUE; } ret = TRUE; if (!self->pv->derived) { if (!derive_key (self, input)) ret = FALSE; } if (ret && g_key_file_has_key (input, GCR_SECRET_EXCHANGE_PROTOCOL_1, "secret", NULL)) ret = perform_decrypt (self, input, (guchar **)&secret, &n_secret); if (ret) { egg_secure_free (self->pv->secret); self->pv->secret = secret; self->pv->n_secret = n_secret; } g_key_file_free (input); return ret; }
/** * gcr_secret_exchange_get_secret: * @self: a #GcrSecretExchange object * @secret_len: (allow-none): optionally, a location to store the length of returned secret * * Returns the last secret received. If no secret has yet been received this * will return %NULL. The string is owned by the #GcrSecretExchange object * and will be valid until the next time that gcr_secret_exchange_receive() * is called on this object, or the object is destroyed. * * Depending on the secret passed into the other side of the secret exchange, * the result may be a binary string. It does however have a null terminator, * so if you're certain that it is does not contain arbitrary binary data, * it can be used as a string. * * Returns: (transfer none) (array length=secret_len): the last secret received */ const gchar * gcr_secret_exchange_get_secret (GcrSecretExchange *self, gsize *secret_len) { g_return_val_if_fail (GCR_IS_SECRET_EXCHANGE (self), NULL); if (secret_len) *secret_len = self->pv->n_secret; return self->pv->secret; }
/** * gcr_secret_exchange_send: * @self: a #GcrSecretExchange object * @secret: (allow-none): optionally, a secret to send to the other side * @secret_len: length of @secret, or -1 if null terminated * * Send a reply to the other side of the secret exchange, optionally sending a * secret. * * gcr_secret_exchange_receive() must have been successfully called at least * once on this object. In other words this object must have received data * from the other side of the secret exchange, before we can send a secret. * * Returns: (transfer full): a newly allocated string to be sent to the other * side of the secret exchange */ gchar * gcr_secret_exchange_send (GcrSecretExchange *self, const gchar *secret, gssize secret_len) { GKeyFile *output; gchar *result; g_return_val_if_fail (GCR_IS_SECRET_EXCHANGE (self), NULL); if (!self->pv->derived) { g_warning ("gcr_secret_exchange_receive() must be called " "before calling this function"); return NULL; } output = g_key_file_new (); key_file_set_base64 (output, GCR_SECRET_EXCHANGE_PROTOCOL_1, "public", self->pv->publi, self->pv->n_publi); if (secret != NULL) { if (secret_len < 0) secret_len = strlen (secret); if (!perform_encrypt (self, output, secret, secret_len)) { g_key_file_free (output); return NULL; } } result = g_key_file_to_data (output, NULL, NULL); g_return_val_if_fail (result != NULL, NULL); g_strchug (result); gchar *string = g_strescape (result, ""); g_debug ("sending the secret exchange: %s", string); g_free (string); if (!g_str_has_prefix (result, SECRET_EXCHANGE_PROTOCOL_1_PREFIX)) g_warning ("the prepared data does not have the correct protocol prefix: %s", result); g_key_file_free (output); return result; }
/** * gcr_secret_exchange_begin: * @self: a #GcrSecretExchange object * * Begin the secret exchange. The resulting string should be sent to the other * side of the exchange. The other side should use gcr_secret_exchange_receive() * to process the string. * * Returns: (transfer full): A newly allocated string to be sent to the other * side of the secret exchange */ gchar * gcr_secret_exchange_begin (GcrSecretExchange *self) { GcrSecretExchangeClass *klass; GKeyFile *output; gchar *result; g_return_val_if_fail (GCR_IS_SECRET_EXCHANGE (self), NULL); klass = GCR_SECRET_EXCHANGE_GET_CLASS (self); g_return_val_if_fail (klass->generate_exchange_key, NULL); clear_secret_exchange (self); output = g_key_file_new (); if (!(klass->generate_exchange_key) (self, GCR_SECRET_EXCHANGE_PROTOCOL_1, &self->pv->publi, &self->pv->n_publi)) g_return_val_if_reached (NULL); self->pv->generated = TRUE; key_file_set_base64 (output, GCR_SECRET_EXCHANGE_PROTOCOL_1, "public", self->pv->publi, self->pv->n_publi); result = g_key_file_to_data (output, NULL, NULL); g_return_val_if_fail (result != NULL, NULL); g_strchug (result); gchar *string = g_strescape (result, ""); g_debug ("beginning the secret exchange: %s", string); g_free (string); if (!g_str_has_prefix (result, SECRET_EXCHANGE_PROTOCOL_1_PREFIX)) g_warning ("the prepared data does not have the correct protocol prefix"); g_key_file_free (output); return result; }