summaryrefslogtreecommitdiff
path: root/redfish-core/src/utils
AgeCommit message (Collapse)AuthorFilesLines
2026-06-24Reuse timezone helper in getDateTimeOffsetNowJoel P J1-11/+6
Refactor getDateTimeOffsetNow() to reuse the existing details::getTimeZone() helper instead of calling std::chrono::current_zone() directly. This keeps timezone lookup and error logging in one place, while the caller only handles the null case and returns empty strings when the timezone cannot be resolved. Also simplify two return sites by using braced return syntax in getDateTimeOffsetNow() and getDateTimeIso8601() for readability. Change-Id: I8737debe6b9fad34847d9aa53de01ec31d765f93 Signed-off-by: Joel P J <joelpj@ami.com>
2026-06-03Fix sd-bus headerEd Tanous1-1/+1
Not clear when this header changed. But tidy flags it. Fix it. Change-Id: Ie55980b081de8526966b90cefed3e8a107b63275 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-21Remove time_tEd Tanous1-5/+6
time_t is less specific than using the equivalents in std::chono. In practice, most of the time we end up converting the time_t to some std::chrono class anyway. Avoid the intermediate conversion and just use the std::chrono version of time. Tested: Unit tests pass. Good Coverage Change-Id: I2e3eca78760e158feaaf4b91793631343e417f15 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-13Remove now unused functionEd Tanous1-19/+0
After the prior patches, this is unused. Remove it Tested: Code builds Change-Id: I937984c9cb98f8f8f0f515394d9cf2960409512c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-04-11Expose date/time in local timezoneIgor Kanyuka1-97/+102
BMC now exposes DateTime property under the Manager/<ID> in timezone configured on the BMC (local TZ) and not in UTC, but the other date time properties are still in UTC. Convert date time fields to local timezone. Tested: 1. Redfish service validator 2. Built Facebook's Catalina image with this change, ran in QEMU and checked manually varioius endpoints. 3. Ran automated tests [1] from openbmc-test-automation repo. 4. Unit tests [1] https://gerrit.openbmc.org/c/openbmc/openbmc-test-automation/+/88659 Change-Id: I8e587c7a1030deff8e6a550651c5e62719fe5299 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com> Signed-off-by: Ed Tanous <ed@tanous.net>
2026-04-10Remove old gcc-13 backportsEd Tanous1-131/+0
This block of code implemented pre-gcc-13 support for time parsing. gcc-13 is now required, so remove it. Change-Id: I266042db97ebe4cdf52c4c62d693efab021ae16f Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-03-20Allow to set Manager TZ and show its time in localIgor Kanyuka1-39/+135
Current code always return Date time in UTC, despite local timezone may differ. This change allows to set manager timezone via redfish and show manager's TZ and offset in manager's local timezone. When the DateTime is being patched, the provided date time gets converted from the provided TZ to the local timezone, but configured TZ does not get changed. A user must explicitly patch TimeZoneName to change Manager's TZ. Tested: 1. Built an image, ran in QEMU, changed TZ to PST8PDT (negative offset), UTC (0 offset), and Tokyo (positive offset). Made sure the patch works and all the touched fields have correct values. See [1]. 2. Unit tests 3. Redfish validator [1] ``` $ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName' "2026-03-19T11:03:16-07:00" "-07:00" "PST8PDT" $ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "UTC"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc HTTP/1.1 204 No Content Allow: GET, PATCH OData-Version: 4.0 Strict-Transport-Security: max-age=31536000; includeSubdomains Pragma: no-cache Cache-Control: no-store, max-age=0 X-Content-Type-Options: nosniff Date: Thu, 19 Mar 2026 18:03:28 GMT Content-Length: 0 $ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName' "2026-03-19T18:03:53+00:00" "+00:00" "UTC" $ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "Asia/Tokyo"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc HTTP/1.1 204 No Content Allow: GET, PATCH OData-Version: 4.0 Strict-Transport-Security: max-age=31536000; includeSubdomains Pragma: no-cache Cache-Control: no-store, max-age=0 X-Content-Type-Options: nosniff Date: Thu, 19 Mar 2026 18:04:20 GMT Content-Length: 0 $ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName' "2026-03-20T03:04:32+09:00" "+09:00" "Asia/Tokyo" $ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"DateTime": "2026-01-02T11:03:16-07:00"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc HTTP/1.1 204 No Content Allow: GET, PATCH OData-Version: 4.0 Strict-Transport-Security: max-age=31536000; includeSubdomains Pragma: no-cache Cache-Control: no-store, max-age=0 X-Content-Type-Options: nosniff Date: Fri, 02 Jan 2026 18:03:16 GMT Content-Length: 0 $ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName' "2026-01-03T03:03:21+09:00" "+09:00" "Asia/Tokyo" $ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc/LogServices/Journal/Entries | jq '.Members[0]' { "@odata.id": "/redfish/v1/Managers/bmc/LogServices/Journal/Entries/cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==", "@odata.type": "#LogEntry.v1_9_0.LogEntry", "Created": "2025-05-29T16:30:41.794580+00:00", "EntryType": "Oem", "Id": "cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==", "Message": "kernel: Booting Linux on physical CPU 0xf00", "Name": "BMC Journal Entry", "OemRecordFormat": "BMC Journal Entry", "Severity": "OK" } ``` Change-Id: I5a4567b9ca6a0f56dd9d1b971d418a19bf625a10 Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
2026-02-24Fix spelling mistakes using codespellGeorge Liu1-1/+1
Signed-off-by: George Liu <liuxiwei@ieisystem.com> Change-Id: If170e53077bc150d0062cd441394daea71f842b1
2026-02-24Be more paranoid in json parsingEd Tanous1-4/+2
When taking json directly from a user, we should set some limits on parsing depth as well as total number of value elements. Value elements are considered any individual value, the start of an array, the start of a dictionary, or null. This is to prevent flooding type attacks creating large number of objects, while still keeping under the depth 10 cap. This commit makes use of the nlohmann sax parse to handle this by injecting a new error handler in between that will impose new limits. Currently this sets the depth limit to 10 and the total number of keys to 500; These are intentionally high, and could be tuned or expanded on in the future. Tested: Unit tests pass. Change-Id: I789543679e22b0b0ce0b2b0b71f31377b0759cd7 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-06-26Map Error.Unavailable to something betterGunnar Mills1-1/+2
This commit is meant to kick off discussion on how we map errors from dbus to Redfish. Currently WIP. Looking for feedback. Do we want a new xyz.openbmc_project.Common.Error.ResourceInStandby that we can map to Redfish's resourceInStandby? Do we think PropertyValueExternalConflict should be mapped to something different? Are we okay with this commit, does this work for AppliedConfig? xyz.openbmc_project.Common.Error.Unavailable was added to Logging Entry's Resolved Property as an error. It is used for cases when the users attempts to set the Resolved property but is prevented until some action is taken, "the system is not currently in a state to allow this", the PDI review here has some more discussion[1]. The current mapping of xyz.openbmc_project.Common.Error.Unavailable to resourceInStandby was added to SetProperty here[2] in April and comes from this AppliedConfig error handling which was added in May 2021 by Jonathan at Intel[3]. Mapping Error.Unavailable to resourceInStandby is a big assumption that might apply in the AppliedConfig usecase but wouldn't overall. PropertyValueExternalConflict is a bit broader and might work in this AppliedConfig case? The PDI AppliedConfig[4] and AppliedConfig in smbios[5]. Redfish doesn't have a Temporary Unavailable to mean "the system is not currently in a state to allow this", PropertyValueExternalConflict is as close as we get. xyz.openbmc_project.Common.Error.NotAllowed maps to Redfish's propertyNotWritable and that is "this property can never be wrote". We map a few things to serviceTemporarilyUnavailable, the only Redfish error to use the word "Unavailable", but that is for temporarily unavailable and retry in x seconds. These Redfish errors can be found at: https://redfish.dmtf.org/registries/Base.1.19.0.json [1]: https://gerrit.openbmc.org/c/openbmc/phosphor-dbus-interfaces/+/74019 [2]: https://github.com/openbmc/bmcweb/commit/87c449664e5375abb040af6fad63ef965c311bec [3]: https://github.com/openbmc/bmcweb/commit/3cde86f14b7835775d7c37e993fb84a3cd01ef9d [4]: https://github.com/openbmc/phosphor-dbus-interfaces/blob/73c931fb942daa714bfff17e950b9d5622a25842/yaml/xyz/openbmc_project/Control/Processor/CurrentOperatingConfig.interface.yaml#L13 [5]: https://github.com/openbmc/smbios-mdr/blob/1d73dccc89f0bb9d1dce3543e5af6b3e3087d5f4/src/speed_select.cpp#L160 Tested: None. Change-Id: I4a48937b1801189acddd02c89aa01ca0cd15362b Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
2025-02-04clang-format: update latest spec and reformatPatrick Williams1-6/+6
Copy the latest format file from the docs repository and apply. Change-Id: I2f0b9d0fb6e01ed36a2f34c750ba52de3b6d15d1 Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2025-01-24Move time_utils to compile unitEd Tanous1-1/+465
There's no reason for these functions to be in a header, and pulling them into a compile unit can reduce compile times overall. Tested: Unit tests pass (Good coverage) Change-Id: Ia6dc50d16bf2967e647a3c7437ba13bd7ab7ca3c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2025-01-20Use SPDX identifiersEd Tanous3-15/+7
SPDX identifiers are simpler, and reduce the amount of cruft we have in code files. They are recommended by linux foundation, and therefore we should do as they allow. This patchset does not intend to modify any intent on any existing copyrights or licenses, only to standardize their inclusion. [1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-12-12Fix clang-tidy for gcc-14Ed Tanous1-0/+2
We use these pragmas, that we must've been getting transitively through chrono in the past. Now we need to include them explicitly. Change-Id: Iee4c0a8866981b91adaa17bee0678b2c10e65ea9 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-11-20Enable gcc-14 buildsEd Tanous1-0/+2
gcc-14 enables the std::chrono features we need for doing lots of time conversions. For whatever reason, std::chrono accepts a an hour of 60, whereas date.h didn't. This test case is really just a corner case, so accept either answer. Tested: Unit tests pass. Good coverage. Change-Id: I2fb7fcbebb2a4126b36f99d27b216b835d1e2994 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-10-15clang-tidy: add misc-include-cleaner fixesPatrick Williams1-0/+1
Fix the following clang-tidy errors: ``` ../redfish-core/src/filter_expr_executor.cpp:102:21: error: no header providing "nlohmann::json" is directly included [misc-include-cleaner,-warnings-as-errors] 7 | const nlohmann::json& body; ``` Signed-off-by: Patrick Williams <patrick@stwcx.xyz> Change-Id: I2e0d66bb35c1010607b9795d00b3321dc20d6d65
2024-10-05dateStringToEpoch: add the additional formatHieu Huynh1-1/+2
This adds the additional format for ISO 8601, such as YYYYMMDD or YYYYMMDDThhmmssZ. Tested: Test case 1: The input ISO 8601 timestamp: 20230531T000000Z The output Epoch timestamp: 1685491200000000 Test case 2: The input ISO 8601 timestamp: 20230531 The output Epoch timestamp: 1685491200000000 Signed-off-by: Hieu Huynh <hieuh@os.amperecomputing.com> Change-Id: I23080a466b2edeecb5d8a4fb7ec0b00739454056
2024-09-11Remove duplicated block commentsEd Tanous1-13/+13
Static analysis flags that these two comments are redundant[1], which seem to be duplicated a lot in copyright headers. Although there is a larger discussion that can likely be had. [1] https://sonarcloud.io/project/issues?issueStatuses=OPEN%2CCONFIRMED&id=edtanous_bmcweb&open=AY9_HYjgKXKyw1ZFwgVP Tested: Comment change only. Code compiles. Change-Id: Ia960317761f558a87842347ca0b5f3da63f8e730 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-08-24Make PATCH return 204 againEd Tanous1-2/+2
It was correctly pointed out that for PATCH, we cannot return 200 success without also returning the object, per Redfish. This commit partially reverts cdf25ff, to give PATCH the old (204) behavior again. Tested: Patch now returns 204 Change-Id: I8ede932a73ae064586d94c47393e4418350adb00 Signed-off-by: Ed Tanous <etanous@nvidia.com>
2024-08-17clang-format: re-format for clang-18Patrick Williams1-5/+4
clang-format-18 isn't compatible with the clang-format-17 output, so we need to reformat the code with the latest version. The way clang-18 handles lambda formatting also changed, so we have made changes to the organization default style format to better handle lambda formatting. See I5e08687e696dd240402a2780158664b7113def0e for updated style. See Iea0776aaa7edd483fa395e23de25ebf5a6288f71 for clang-18 enablement. Change-Id: Iceec1dc95b6c908ec6c21fb40093de9dd18bf11a Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
2024-08-17Make set properties return 200 Success not 204Ed Tanous1-4/+4
Both 200 and 204 are allowed by the Redfish specification. Table 11 states: 200 OK Success, and the action's schema definition does not contain an action response. 204 No Content: Success, and the action's schema definition does not contain an action response. While both of these are allowed, we accidentally changed behavior in the following commit: 87c4496 Move to Redfish setProperty call When we transitioned these over to the common dbus calling methods. This commit restores the old behavior of returning 200 success on actions, which some implementations are expecting. Tested: WIP. Change-Id: I02e47585acf85bd04dcb9d428ef3e39a21d9c75f Signed-off-by: Ed Tanous <ed@tanous.net>
2024-06-25Remove nlohmann::json::items()Ed Tanous1-1/+1
nlohmann::json::items() throws an exception if the object in question is not a json object. This has the potential to cause problems, and isn't in line with the standard that we code against. Replace all uses of items with iterating the nlohmann::json::object_t. This adds a new error check for pulling the object_t out of the nlohmann::json object before each iteration, to ensure that we're handling errors. Tested: Redfish service validator passes. Change-Id: I2934c9450ec296c76544c2a7c5855c9b519eae7f Signed-off-by: Ed Tanous <ed@tanous.net>
2024-04-29Break out formattersEd Tanous1-0/+1
In the change made to move to std::format, we defined some custom type formatters in logging.hpp. This had the unintended effect of making all compile units pull in the majority of boost::url, and nlohmann::json as includes. This commit breaks out boost and json formatters into their own separate includes. Tested: Code compiles. Logging changes only. Change-Id: I6a788533169f10e19130a1910cd3be0cc729b020 Signed-off-by: Ed Tanous <ed@tanous.net>
2024-04-19Add missing headersEd Tanous1-1/+6
Most of these were found by breaking every redfish class handler into its own compile unit: When that's done, these missing headers become compile errors. We should just fix them. In addition, this allows us to enable automatic header checking in clang-tidy using misc-header-cleaner. Because the compiler can now "see" all the defines, it no longer tries to remove headers that it thinks are unused. [1] https://github.com/openbmc/bmcweb/commit/4fdee9e39e9f03122ee16a6fb251a380681f56ac Tested: Code compiles. Change-Id: Ifa27ac4a512362b7ded7cc3068648dc4aea6ad7b Signed-off-by: Ed Tanous <ed@tanous.net>
2024-04-15Move to Redfish setProperty callAsmitha Karunanithi1-0/+11
This commit changes sdbusplus setProperty calls (in various files) to setDbusProperty method in Redfish namespace that handles all DBus errors in a consistent manner. It also handles and translates additional DBus errors to Redfish specific errors in dbus_utils file. Tested By: Not tested yet Change-Id: If440774879413754f4c24f9b6572c3c9fa1fd033 Signed-off-by: Asmitha Karunanithi <asmitk01@in.ibm.com>
2024-04-09Move to Redfish Action specific setProperty callAsmitha Karunanithi1-1/+48
This commit will migrate all the setProperty calls initiated by a redfish"Action" to "setDbusProperty" method in Redfish namespace that handles all DBuserrors in a consistent manner. This method will determine if a setProperty is called during redfish "Action" or just setting of a dbus property and internally call appropriate methods that handles different set of errors. All the Redfish action specific errors are defined in error_messages.hpp file. This specific change moves setProperty call in hypervisor_system.hpp and covers errors in the mentioned file only. Tested-By: <Yet to test this usecase> Change-Id: I3da48fbeabcdcf088c4481021232f08a44797c86 Signed-off-by: Asmitha Karunanithi <asmitk01@in.ibm.com> Signed-off-by: Ed Tanous <ed@tanous.net>
2024-03-28Create Redfish specific setProperty callEd Tanous1-0/+76
There are currently 78 sdbusplus::asio::setProperty calls in redfish-core. The error handler for nearly all of them looks something like: ``` if (ec) { const sd_bus_error* dbusError = msg.get_error(); if ((dbusError != nullptr) && (dbusError->name == std::string_view( "xyz.openbmc_project.Common.Error.InvalidArgument"))) { BMCWEB_LOG_WARNING("DBUS response error: {}", ec); messages::propertyValueIncorrect(asyncResp->res, "<PropertyName>", <PropertyValue>); return; } messages::internalError(asyncResp->res); return; } messages::success(asyncResp->res); ``` In some cases there are more errors handled that translate to more error messages, but the vast majority only handle InvalidArgument. Many of these, like the ones in account_service.hpp, do the error handling in a lambda, which causes readability problems. This commit starts to make things more consistent, and easier for trivial property sets. This commit invents a setDbusProperty method in the redfish namespace that tries to handle all DBus errors in a consistent manner. Looking for input on whether this will work before changing over the other 73 calls. Overall this is less code, fewer inline lambdas, and defaults that should work for MOST use cases of calling an OpenBMC daemon, and fall back to more generic errors when calling a "normal" dbus daemon. As part of this, I've ported over several examples. Some things that might be up in the air: 1. Do we always return 204 no_content on property sets? Today there's a mix of 200, with a Base::Success message, and 204, with an empty body. 2. Do all DBus response codes map to the same error? A majority are covered by xyz.openbmc_project.Common.Error.InvalidArgument, but there are likely differences. If we allow any daemon to return any return code, does that cause compatibility problems later? Tested: ``` curl -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"HostName":"openbmc@#"}' https://192.168.7.2/redfish/v1/Managers/bmc/EthernetInterfaces/eth0 ``` Returns the appropriate error in the response Base.1.16.0.PropertyValueIncorrect Change-Id: If033a1112ba516792c9386c997d090c8f9094f3a Signed-off-by: Ed Tanous <ed@tanous.net>
2024-03-28Add misc-include-cleanerEd Tanous2-1/+3
And fix the includes that are wrong. Note, there is a very large ignore list included in the .clang-tidy configcfile. These are things that clang-tidy doesn't yet handle well, like knowing about a details include. Change-Id: Ie3744f2c8cba68a8700b406449d6c2018a736952 Signed-off-by: Ed Tanous <ed@tanous.net>
2024-03-19Call systemd SetTime directlyEd Tanous1-3/+3
Internally inside phosphor-time-manager, the elapsed(uint64) dbus call just forwards the request directly to systemd after static casting to int64_t (signed). bmcweb should just call systemd directly, for several reasons. phosphor-timesyncd might block on other calls, given it's a single threaded blocking design, due to bugs like #264. Calling systemd directly means that calls that don't require phosphor networkd won't be blocked. Calling systemd directly allows bmcweb to drop some code that parses a date as int64_t, then converts it to uint64_t to fulfill the phosphor datetime interface. We can now keep int64_t all the way through. Calling systemd directly allows bmcweb to give a more specific error code in the case there NTP is enabled, registering a PropertyValueConflict error, instead of a 500 InternalError. Tested: Patching DateTime property with NTP enabled returns 400, PropertyValueConflict ``` curl -vvvv -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"DateTime":"2020-12-15T15:40:52+00:00"}' https://192.168.7.2/redfish/v1/Managers/bmc ``` Disabling NTP using the following command: ``` curl -vvvv -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"NTP":{"ProtocolEnabled":false}}' https://192.168.7.2/redfish/v1/Managers/bmc/NetworkProtocol ``` Allows the prior command to succeed. [1] https://github.com/openbmc/phosphor-time-manager/blob/5ce9ac0e56440312997b25771507585905e8b360/bmc_epoch.cpp#L126 Change-Id: I6fbb6f63e17de8ab847ca5ed4eadc2bd313586d2 Signed-off-by: Ed Tanous <ed@tanous.net>
2023-09-08Simplify datetime parsingEd Tanous1-0/+44
This code as it stands pulls in the full datetime library from boost, including io, and a bunch of timezone code. The bmc doesn't make use of any of this, so we can rely on a much simplified version. Unfortunately for us, gcc still doesn't implement the c++20 std::chrono::parse[1]. There is a reference library available from [2] that backports the parse function to compilers that don't yet support it, and is the basis for the libc++ version. This commit opts to copy in the header as-written, under the assumption that we will never need to pull in new versions of this library, and will move to the std ersion as soon as it's available in the next gcc version. This commit simplifies things down to improve compile times and binary size. It saves ~22KB of compressed binary size, or about 3%. Tested: Unit tests pass. Pretty good coverage. [1] https://en.cppreference.com/w/cpp/chrono/parse [2] https://github.com/HowardHinnant/date/blob/master/include/date/date.h Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: I706b91cc3d9df3f32068125bc47ff0c374eb8d87
2023-06-21json utils: add getEstimatedJsonSizeNan Zhou1-0/+49
Add a utility function which estimates the size of the JSON tree. It is used in the children change to limit the reponse size of expand query. Tested: 1. unit test passed; 2. tested on hardware, the following are real sizes and estimation ``` Real payload size, Estimation, query 15.69 KB, 10.21 KB, redfish/v1?$expand=.($levels=1) 95.76 KB, 62.11 KB, redfish/v1?$expand=.($levels=2) 117.14 KB, 72.71 KB, redfish/v1?$expand=.($levels=3) 127.65 KB, 77.64 KB, redfish/v1?$expand=.($levels=4) ``` Signed-off-by: Nan Zhou <nanzhoumails@gmail.com> Change-Id: Iae26d6732a6ec63ecc59eacf657b4bf33c07c046
2023-03-11Remove body member from RequestEd Tanous1-1/+1
Per cpp core guidelines, these should be methods. Tested: on last patchset of the series. Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: Ib16479db9d2b68da68e7ad6e825c7e205c64f1de
2023-02-17Add option for validating content-type headerEd Tanous1-3/+13
For systems implementing to the OWASP security guidelines[1] (of which all should ideally) we should be checking the content-type header all times that we parse a request as JSON. This commit adds an option for parsing content-type, and sets a default of "must get content-type". Ideally this would not be a breaking change, but given the number of guides and scripts that omit the content type, it seems worthwhile to add a trapdoor, such that people can opt into their own model on how they would like to see this checking work. Tested: ``` curl --insecure -H "Content-Type: application/json" -X POST -D headers.txt https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName":"root", "Password":"0penBmc"}' ``` Succeeds. Removing Content-Type argument causes bmc to return Base.1.13.0.UnrecognizedRequestBody. [1] cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html Change-Id: Iaa47dd563b40036ff2fc2cacb70d941fd8853038 Signed-off-by: Ed Tanous <edtanous@google.com>
2018-10-23Improve the Redfish error reporting interfaceJason M. Bills1-481/+1
Makes the Redfish error reporting interface automatically handle setting the http status and JSON content in the response object. When using an AsyncResp object, this allows for simply calling the Redfish error and returning. Change-Id: Icfdce2de763225f070e8dd61e591f296703f46bb Signed-off-by: Jason M. Bills <jason.m.bills@linux.intel.com>
2018-10-22Implement a new way of unpacking json to structsEd Tanous1-3/+0
The existing way of decoding json structures, while fast has some disadvantages. 1. it's very verbose to write. 2. It requires in depth knowlege of redfish error messages to get correct. 3. It _can_ lead to undesired behavior, like half of a patch being applied, if only some of the values have bad types. This commit implements a new interface for decoding redfish json named.... readJson. It is a templated function, that lets you decode json values based on type easily, while still handling all the correct error codes that were handled previously. Use is done similar to the example below: std::string required; boost::optional<std::string> optional; if (!json_util::readJson(req, res, "OptionalParam", optional, "RequiredParam", required)) { return; } if (optional){ // optional param was given, take action. } As part of this patchset, the systems schema is moved to the new interface, which deletes some of the code involved and shows the improvement in clarity. Change-Id: I041a97c84d294df8cd4de4c2702e5ee22c0bc120 Signed-off-by: Ed Tanous <ed.tanous@intel.com>
2018-09-05Move to clang-format-6.0Ed Tanous1-299/+371
This commit moves the codebase to the lastest clang-format file from upstream, as well as clang-format-6.0. Change-Id: Ice8313468097c0c42317fbb9e10ddf036e8cff4c Signed-off-by: Ed Tanous <ed.tanous@intel.com>
2018-07-27Move over to upstream c++ styleEd Tanous1-2/+2
This patchset moves bmcweb over to the upstream style naming conventions for variables, classes, and functions, as well as imposes the latest clang-format file. This changeset was mostly built automatically by the included .clang-tidy file, which has the ability to autoformat and auto rename variables. At some point in the future I would like to see this in greater use, but for now, we will impose it on bmcweb, and see how it goes. Tested: Code still compiles, and appears to run, although other issues are possible and likely. Change-Id: If422a2e36df924e897736b3feffa89f411d9dac1 Signed-off-by: Ed Tanous <ed.tanous@intel.com>
2018-06-29Boost beastEd Tanous1-2/+1
This commit is the beginings of attempting to transition away from crow, and toward boost::beast. Unit tests are passing, and implementation appears to be slightly faster than crow. Change-Id: Ic8d946dc7a04f514c67b1098f181eee1ced69171
2018-06-29Added JSON utilities to allow easy exception-less usage of nlohmann JSON.Kowalski, Kamil1-0/+454
These functions are not yet used, but will be required by at least two upcoming patchsets. This functionality has been cut out from Configuration patchset for easier merge without having to wait for that commit. Change-Id: Ibe5d5cefd874d4a2d896b42a2b7cfc17480f3c5a Signed-off-by: Kowalski, Kamil <kamil.kowalski@intel.com>