| Age | Commit message (Collapse) | Author | Files | Lines |
|
Refactor getDateTimeOffsetNow() to reuse the existing
details::getTimeZone() helper instead of calling
std::chrono::current_zone() directly.
This keeps timezone lookup and error logging in one place, while the
caller only handles the null case and returns empty strings when the
timezone cannot be resolved.
Also simplify two return sites by using braced return syntax in
getDateTimeOffsetNow() and getDateTimeIso8601() for readability.
Change-Id: I8737debe6b9fad34847d9aa53de01ec31d765f93
Signed-off-by: Joel P J <joelpj@ami.com>
|
|
Not clear when this header changed. But tidy flags it. Fix it.
Change-Id: Ie55980b081de8526966b90cefed3e8a107b63275
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
time_t is less specific than using the equivalents in std::chono. In
practice, most of the time we end up converting the time_t to some
std::chrono class anyway. Avoid the intermediate conversion and just
use the std::chrono version of time.
Tested: Unit tests pass. Good Coverage
Change-Id: I2e3eca78760e158feaaf4b91793631343e417f15
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
After the prior patches, this is unused. Remove it
Tested: Code builds
Change-Id: I937984c9cb98f8f8f0f515394d9cf2960409512c
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
BMC now exposes DateTime property under the Manager/<ID> in timezone
configured on the BMC (local TZ) and not in UTC, but the other date
time properties are still in UTC.
Convert date time fields to local timezone.
Tested:
1. Redfish service validator
2. Built Facebook's Catalina image with this change, ran in QEMU and
checked manually varioius endpoints.
3. Ran automated tests [1] from openbmc-test-automation repo.
4. Unit tests
[1] https://gerrit.openbmc.org/c/openbmc/openbmc-test-automation/+/88659
Change-Id: I8e587c7a1030deff8e6a550651c5e62719fe5299
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
This block of code implemented pre-gcc-13 support for time parsing.
gcc-13 is now required, so remove it.
Change-Id: I266042db97ebe4cdf52c4c62d693efab021ae16f
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Current code always return Date time in UTC, despite local timezone may
differ. This change allows to set manager timezone via redfish and show
manager's TZ and offset in manager's local timezone. When the DateTime
is being patched, the provided date time gets converted from the
provided TZ to the local timezone, but configured TZ does not get
changed. A user must explicitly patch TimeZoneName to change Manager's
TZ.
Tested:
1. Built an image, ran in QEMU, changed TZ to PST8PDT (negative offset),
UTC (0 offset), and Tokyo (positive offset). Made sure the patch works
and all the touched fields have correct values. See [1].
2. Unit tests
3. Redfish validator
[1]
```
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-19T11:03:16-07:00"
"-07:00"
"PST8PDT"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "UTC"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Thu, 19 Mar 2026 18:03:28 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-19T18:03:53+00:00"
"+00:00"
"UTC"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"TimeZoneName": "Asia/Tokyo"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Thu, 19 Mar 2026 18:04:20 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-03-20T03:04:32+09:00"
"+09:00"
"Asia/Tokyo"
$ curl -i -k -H 'Content-type: application/json' -u root:0penBmc -d '{"DateTime": "2026-01-02T11:03:16-07:00"}' -X PATCH https://localhost:8443/redfish/v1/Managers/bmc
HTTP/1.1 204 No Content
Allow: GET, PATCH
OData-Version: 4.0
Strict-Transport-Security: max-age=31536000; includeSubdomains
Pragma: no-cache
Cache-Control: no-store, max-age=0
X-Content-Type-Options: nosniff
Date: Fri, 02 Jan 2026 18:03:16 GMT
Content-Length: 0
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc | jq '.DateTime, .DateTimeLocalOffset, .TimeZoneName'
"2026-01-03T03:03:21+09:00"
"+09:00"
"Asia/Tokyo"
$ curl -s -k -H 'Content-type: application/json' -u root:0penBmc https://localhost:8443/redfish/v1/Managers/bmc/LogServices/Journal/Entries | jq '.Members[0]'
{
"@odata.id": "/redfish/v1/Managers/bmc/LogServices/Journal/Entries/cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==",
"@odata.type": "#LogEntry.v1_9_0.LogEntry",
"Created": "2025-05-29T16:30:41.794580+00:00",
"EntryType": "Oem",
"Id": "cz0zNTMzMTVkMTBjYWQ0ZTg5ODJiYjliZGVmOTc2NDE2MDtpPTE7Yj00YzU5NzY1NzQ0M2M0N2IzOWZjYTZiNzU1ZWVlY2NjOTttPTFlZjc1Yzg7dD02MzY0OGQxOTFhZTE0O3g9ZDU5MjYwNzJkZTgzMWYzYw==",
"Message": "kernel: Booting Linux on physical CPU 0xf00",
"Name": "BMC Journal Entry",
"OemRecordFormat": "BMC Journal Entry",
"Severity": "OK"
}
```
Change-Id: I5a4567b9ca6a0f56dd9d1b971d418a19bf625a10
Signed-off-by: Igor Kanyuka <ifelmail@gmail.com>
|
|
Signed-off-by: George Liu <liuxiwei@ieisystem.com>
Change-Id: If170e53077bc150d0062cd441394daea71f842b1
|
|
When taking json directly from a user, we should set some limits on
parsing depth as well as total number of value elements. Value elements
are considered any individual value, the start of an array, the start of
a dictionary, or null. This is to prevent flooding type attacks
creating large number of objects, while still keeping under the depth 10
cap. This commit makes use of the nlohmann sax parse to handle this by
injecting a new error handler in between that will impose new limits.
Currently this sets the depth limit to 10 and the total number of keys
to 500; These are intentionally high, and could be tuned or expanded on
in the future.
Tested: Unit tests pass.
Change-Id: I789543679e22b0b0ce0b2b0b71f31377b0759cd7
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
This commit is meant to kick off discussion on how we map errors from
dbus to Redfish. Currently WIP. Looking for feedback. Do we want a new
xyz.openbmc_project.Common.Error.ResourceInStandby that we can map to
Redfish's resourceInStandby? Do we think PropertyValueExternalConflict
should be mapped to something different? Are we okay with this commit,
does this work for AppliedConfig?
xyz.openbmc_project.Common.Error.Unavailable was added to Logging
Entry's Resolved Property as an error. It is used for cases when the
users attempts to set the Resolved property but is prevented until some
action is taken, "the system is not currently in a state to allow this",
the PDI review here has some more discussion[1].
The current mapping of xyz.openbmc_project.Common.Error.Unavailable to
resourceInStandby was added to SetProperty here[2] in April and comes
from this AppliedConfig error handling which was added in May 2021 by
Jonathan at Intel[3]. Mapping Error.Unavailable to resourceInStandby is
a big assumption that might apply in the AppliedConfig usecase but
wouldn't overall. PropertyValueExternalConflict is a bit broader and
might work in this AppliedConfig case? The PDI AppliedConfig[4] and
AppliedConfig in smbios[5].
Redfish doesn't have a Temporary Unavailable to mean "the system is not
currently in a state to allow this", PropertyValueExternalConflict is as
close as we get. xyz.openbmc_project.Common.Error.NotAllowed maps to
Redfish's propertyNotWritable and that is "this property can never be
wrote". We map a few things to serviceTemporarilyUnavailable, the only
Redfish error to use the word "Unavailable", but that is for temporarily
unavailable and retry in x seconds. These Redfish errors can be found
at: https://redfish.dmtf.org/registries/Base.1.19.0.json
[1]: https://gerrit.openbmc.org/c/openbmc/phosphor-dbus-interfaces/+/74019
[2]: https://github.com/openbmc/bmcweb/commit/87c449664e5375abb040af6fad63ef965c311bec
[3]: https://github.com/openbmc/bmcweb/commit/3cde86f14b7835775d7c37e993fb84a3cd01ef9d
[4]: https://github.com/openbmc/phosphor-dbus-interfaces/blob/73c931fb942daa714bfff17e950b9d5622a25842/yaml/xyz/openbmc_project/Control/Processor/CurrentOperatingConfig.interface.yaml#L13
[5]: https://github.com/openbmc/smbios-mdr/blob/1d73dccc89f0bb9d1dce3543e5af6b3e3087d5f4/src/speed_select.cpp#L160
Tested: None.
Change-Id: I4a48937b1801189acddd02c89aa01ca0cd15362b
Signed-off-by: Gunnar Mills <gmills@us.ibm.com>
|
|
Copy the latest format file from the docs repository and apply.
Change-Id: I2f0b9d0fb6e01ed36a2f34c750ba52de3b6d15d1
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
There's no reason for these functions to be in a header, and pulling
them into a compile unit can reduce compile times overall.
Tested: Unit tests pass (Good coverage)
Change-Id: Ia6dc50d16bf2967e647a3c7437ba13bd7ab7ca3c
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
SPDX identifiers are simpler, and reduce the amount of cruft we have in
code files. They are recommended by linux foundation, and therefore we
should do as they allow.
This patchset does not intend to modify any intent on any existing
copyrights or licenses, only to standardize their inclusion.
[1] https://www.linuxfoundation.org/blog/blog/copyright-notices-in-open-source-software-projects
Change-Id: I935c7c0156caa78fc368c929cebd0f068031e830
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
We use these pragmas, that we must've been getting transitively through
chrono in the past. Now we need to include them explicitly.
Change-Id: Iee4c0a8866981b91adaa17bee0678b2c10e65ea9
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
gcc-14 enables the std::chrono features we need for doing lots of time
conversions. For whatever reason, std::chrono accepts a an hour of 60,
whereas date.h didn't. This test case is really just a corner case, so
accept either answer.
Tested: Unit tests pass. Good coverage.
Change-Id: I2fb7fcbebb2a4126b36f99d27b216b835d1e2994
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
Fix the following clang-tidy errors:
```
../redfish-core/src/filter_expr_executor.cpp:102:21: error: no header providing "nlohmann::json" is directly included [misc-include-cleaner,-warnings-as-errors]
7 | const nlohmann::json& body;
```
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
Change-Id: I2e0d66bb35c1010607b9795d00b3321dc20d6d65
|
|
This adds the additional format for ISO 8601, such as YYYYMMDD or
YYYYMMDDThhmmssZ.
Tested:
Test case 1:
The input ISO 8601 timestamp: 20230531T000000Z
The output Epoch timestamp: 1685491200000000
Test case 2:
The input ISO 8601 timestamp: 20230531
The output Epoch timestamp: 1685491200000000
Signed-off-by: Hieu Huynh <hieuh@os.amperecomputing.com>
Change-Id: I23080a466b2edeecb5d8a4fb7ec0b00739454056
|
|
Static analysis flags that these two comments are redundant[1], which
seem to be duplicated a lot in copyright headers. Although there is a
larger discussion that can likely be had.
[1] https://sonarcloud.io/project/issues?issueStatuses=OPEN%2CCONFIRMED&id=edtanous_bmcweb&open=AY9_HYjgKXKyw1ZFwgVP
Tested: Comment change only. Code compiles.
Change-Id: Ia960317761f558a87842347ca0b5f3da63f8e730
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
It was correctly pointed out that for PATCH, we cannot return 200
success without also returning the object, per Redfish. This commit
partially reverts cdf25ff, to give PATCH the old (204) behavior again.
Tested: Patch now returns 204
Change-Id: I8ede932a73ae064586d94c47393e4418350adb00
Signed-off-by: Ed Tanous <etanous@nvidia.com>
|
|
clang-format-18 isn't compatible with the clang-format-17 output, so we
need to reformat the code with the latest version. The way clang-18
handles lambda formatting also changed, so we have made changes to the
organization default style format to better handle lambda formatting.
See I5e08687e696dd240402a2780158664b7113def0e for updated style.
See Iea0776aaa7edd483fa395e23de25ebf5a6288f71 for clang-18 enablement.
Change-Id: Iceec1dc95b6c908ec6c21fb40093de9dd18bf11a
Signed-off-by: Patrick Williams <patrick@stwcx.xyz>
|
|
Both 200 and 204 are allowed by the Redfish specification. Table 11
states:
200 OK Success, and the action's schema definition does not contain an
action response.
204 No Content: Success, and the action's schema definition does not
contain an action response.
While both of these are allowed, we accidentally changed behavior in the
following commit:
87c4496 Move to Redfish setProperty call
When we transitioned these over to the common dbus calling methods.
This commit restores the old behavior of returning 200 success on
actions, which some implementations are expecting.
Tested: WIP.
Change-Id: I02e47585acf85bd04dcb9d428ef3e39a21d9c75f
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
nlohmann::json::items() throws an exception if the object in question is
not a json object. This has the potential to cause problems, and isn't
in line with the standard that we code against.
Replace all uses of items with iterating the nlohmann::json::object_t.
This adds a new error check for pulling the object_t out of the
nlohmann::json object before each iteration, to ensure that we're
handling errors.
Tested: Redfish service validator passes.
Change-Id: I2934c9450ec296c76544c2a7c5855c9b519eae7f
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
In the change made to move to std::format, we defined some custom type
formatters in logging.hpp. This had the unintended effect of making
all compile units pull in the majority of boost::url, and nlohmann::json
as includes.
This commit breaks out boost and json formatters into their own separate
includes.
Tested: Code compiles. Logging changes only.
Change-Id: I6a788533169f10e19130a1910cd3be0cc729b020
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
Most of these were found by breaking every redfish class handler into
its own compile unit:
When that's done, these missing headers become compile errors. We
should just fix them.
In addition, this allows us to enable automatic header checking in
clang-tidy using misc-header-cleaner. Because the compiler can now
"see" all the defines, it no longer tries to remove headers that it
thinks are unused.
[1] https://github.com/openbmc/bmcweb/commit/4fdee9e39e9f03122ee16a6fb251a380681f56ac
Tested: Code compiles.
Change-Id: Ifa27ac4a512362b7ded7cc3068648dc4aea6ad7b
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
This commit changes sdbusplus setProperty calls (in various files) to
setDbusProperty method in Redfish namespace that handles all DBus
errors in a consistent manner.
It also handles and translates additional DBus errors to Redfish
specific errors in dbus_utils file.
Tested By:
Not tested yet
Change-Id: If440774879413754f4c24f9b6572c3c9fa1fd033
Signed-off-by: Asmitha Karunanithi <asmitk01@in.ibm.com>
|
|
This commit will migrate all the setProperty calls initiated by a
redfish"Action" to "setDbusProperty" method in Redfish namespace that
handles all DBuserrors in a consistent manner.
This method will determine if a setProperty is called during redfish
"Action" or just setting of a dbus property and internally call
appropriate methods that handles different set of errors.
All the Redfish action specific errors are defined in error_messages.hpp
file.
This specific change moves setProperty call in hypervisor_system.hpp and
covers errors in the mentioned file only.
Tested-By:
<Yet to test this usecase>
Change-Id: I3da48fbeabcdcf088c4481021232f08a44797c86
Signed-off-by: Asmitha Karunanithi <asmitk01@in.ibm.com>
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
There are currently 78 sdbusplus::asio::setProperty calls in
redfish-core. The error handler for nearly all of them looks something
like:
```
if (ec)
{
const sd_bus_error* dbusError = msg.get_error();
if ((dbusError != nullptr) &&
(dbusError->name ==
std::string_view(
"xyz.openbmc_project.Common.Error.InvalidArgument")))
{
BMCWEB_LOG_WARNING("DBUS response error: {}", ec);
messages::propertyValueIncorrect(asyncResp->res, "<PropertyName>", <PropertyValue>);
return;
}
messages::internalError(asyncResp->res);
return;
}
messages::success(asyncResp->res);
```
In some cases there are more errors handled that translate to more error
messages, but the vast majority only handle InvalidArgument. Many of
these, like the ones in account_service.hpp, do the error handling in a
lambda, which causes readability problems. This commit starts to make
things more consistent, and easier for trivial property sets.
This commit invents a setDbusProperty method in the redfish namespace
that tries to handle all DBus errors in a consistent manner. Looking
for input on whether this will work before changing over the other 73
calls. Overall this is less code, fewer inline lambdas, and defaults
that should work for MOST use cases of calling an OpenBMC daemon, and
fall back to more generic errors when calling a "normal" dbus daemon.
As part of this, I've ported over several examples. Some things that
might be up in the air:
1. Do we always return 204 no_content on property sets? Today there's a
mix of 200, with a Base::Success message, and 204, with an empty body.
2. Do all DBus response codes map to the same error? A majority are
covered by xyz.openbmc_project.Common.Error.InvalidArgument, but there
are likely differences. If we allow any daemon to return any return
code, does that cause compatibility problems later?
Tested:
```
curl -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"HostName":"openbmc@#"}' https://192.168.7.2/redfish/v1/Managers/bmc/EthernetInterfaces/eth0
```
Returns the appropriate error in the response
Base.1.16.0.PropertyValueIncorrect
Change-Id: If033a1112ba516792c9386c997d090c8f9094f3a
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
And fix the includes that are wrong.
Note, there is a very large ignore list included in the .clang-tidy
configcfile. These are things that clang-tidy doesn't yet handle
well, like knowing about a details include.
Change-Id: Ie3744f2c8cba68a8700b406449d6c2018a736952
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
Internally inside phosphor-time-manager, the elapsed(uint64) dbus call
just forwards the request directly to systemd after static casting to
int64_t (signed).
bmcweb should just call systemd directly, for several reasons.
phosphor-timesyncd might block on other calls, given it's a single
threaded blocking design, due to bugs like #264. Calling systemd
directly means that calls that don't require phosphor networkd won't be
blocked.
Calling systemd directly allows bmcweb to drop some code that parses a
date as int64_t, then converts it to uint64_t to fulfill the phosphor
datetime interface. We can now keep int64_t all the way through.
Calling systemd directly allows bmcweb to give a more specific error
code in the case there NTP is enabled, registering a
PropertyValueConflict error, instead of a 500 InternalError.
Tested:
Patching DateTime property with NTP enabled returns 400,
PropertyValueConflict
```
curl -vvvv -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"DateTime":"2020-12-15T15:40:52+00:00"}' https://192.168.7.2/redfish/v1/Managers/bmc
```
Disabling NTP using the following command:
```
curl -vvvv -k --user "root:0penBmc" -H "Content-Type: application/json" -X PATCH -d '{"NTP":{"ProtocolEnabled":false}}' https://192.168.7.2/redfish/v1/Managers/bmc/NetworkProtocol
```
Allows the prior command to succeed.
[1] https://github.com/openbmc/phosphor-time-manager/blob/5ce9ac0e56440312997b25771507585905e8b360/bmc_epoch.cpp#L126
Change-Id: I6fbb6f63e17de8ab847ca5ed4eadc2bd313586d2
Signed-off-by: Ed Tanous <ed@tanous.net>
|
|
This code as it stands pulls in the full datetime library from boost,
including io, and a bunch of timezone code. The bmc doesn't make use of
any of this, so we can rely on a much simplified version.
Unfortunately for us, gcc still doesn't implement the c++20
std::chrono::parse[1]. There is a reference library available from [2]
that backports the parse function to compilers that don't yet support
it, and is the basis for the libc++ version. This commit opts to copy
in the header as-written, under the assumption that we will never need
to pull in new versions of this library, and will move to the std
ersion as soon as it's available in the next gcc version.
This commit simplifies things down to improve compile times and binary
size. It saves ~22KB of compressed binary size, or about 3%.
Tested: Unit tests pass. Pretty good coverage.
[1] https://en.cppreference.com/w/cpp/chrono/parse
[2] https://github.com/HowardHinnant/date/blob/master/include/date/date.h
Signed-off-by: Ed Tanous <edtanous@google.com>
Change-Id: I706b91cc3d9df3f32068125bc47ff0c374eb8d87
|
|
Add a utility function which estimates the size of the JSON tree.
It is used in the children change to limit the reponse size of expand
query.
Tested:
1. unit test passed;
2. tested on hardware, the following are real sizes and estimation
```
Real payload size, Estimation, query
15.69 KB, 10.21 KB, redfish/v1?$expand=.($levels=1)
95.76 KB, 62.11 KB, redfish/v1?$expand=.($levels=2)
117.14 KB, 72.71 KB, redfish/v1?$expand=.($levels=3)
127.65 KB, 77.64 KB, redfish/v1?$expand=.($levels=4)
```
Signed-off-by: Nan Zhou <nanzhoumails@gmail.com>
Change-Id: Iae26d6732a6ec63ecc59eacf657b4bf33c07c046
|
|
Per cpp core guidelines, these should be methods.
Tested: on last patchset of the series.
Signed-off-by: Ed Tanous <edtanous@google.com>
Change-Id: Ib16479db9d2b68da68e7ad6e825c7e205c64f1de
|
|
For systems implementing to the OWASP security guidelines[1] (of which all
should ideally) we should be checking the content-type header all times
that we parse a request as JSON.
This commit adds an option for parsing content-type, and sets a default
of "must get content-type". Ideally this would not be a breaking
change, but given the number of guides and scripts that omit the content
type, it seems worthwhile to add a trapdoor, such that people can opt
into their own model on how they would like to see this checking work.
Tested:
```
curl --insecure -H "Content-Type: application/json" -X POST -D headers.txt https://${bmc}/redfish/v1/SessionService/Sessions -d '{"UserName":"root", "Password":"0penBmc"}'
```
Succeeds.
Removing Content-Type argument causes bmc to return
Base.1.13.0.UnrecognizedRequestBody.
[1] cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html
Change-Id: Iaa47dd563b40036ff2fc2cacb70d941fd8853038
Signed-off-by: Ed Tanous <edtanous@google.com>
|
|
Makes the Redfish error reporting interface automatically handle
setting the http status and JSON content in the response object.
When using an AsyncResp object, this allows for simply calling
the Redfish error and returning.
Change-Id: Icfdce2de763225f070e8dd61e591f296703f46bb
Signed-off-by: Jason M. Bills <jason.m.bills@linux.intel.com>
|
|
The existing way of decoding json structures, while fast has some disadvantages.
1. it's very verbose to write.
2. It requires in depth knowlege of redfish error messages to get
correct.
3. It _can_ lead to undesired behavior, like half of a patch being
applied, if only some of the values have bad types.
This commit implements a new interface for decoding redfish json
named.... readJson. It is a templated function, that lets you decode
json values based on type easily, while still handling all the correct
error codes that were handled previously. Use is done similar to the
example below:
std::string required;
boost::optional<std::string> optional;
if (!json_util::readJson(req, res, "OptionalParam", optional,
"RequiredParam", required))
{
return;
}
if (optional){
// optional param was given, take action.
}
As part of this patchset, the systems schema is moved to the new
interface, which deletes some of the code involved and shows the
improvement in clarity.
Change-Id: I041a97c84d294df8cd4de4c2702e5ee22c0bc120
Signed-off-by: Ed Tanous <ed.tanous@intel.com>
|
|
This commit moves the codebase to the lastest clang-format file from
upstream, as well as clang-format-6.0.
Change-Id: Ice8313468097c0c42317fbb9e10ddf036e8cff4c
Signed-off-by: Ed Tanous <ed.tanous@intel.com>
|
|
This patchset moves bmcweb over to the upstream style naming
conventions for variables, classes, and functions, as well as imposes
the latest clang-format file.
This changeset was mostly built automatically by the included
.clang-tidy file, which has the ability to autoformat and auto rename
variables. At some point in the future I would like to see this in
greater use, but for now, we will impose it on bmcweb, and see how it
goes.
Tested: Code still compiles, and appears to run, although other issues
are possible and likely.
Change-Id: If422a2e36df924e897736b3feffa89f411d9dac1
Signed-off-by: Ed Tanous <ed.tanous@intel.com>
|
|
This commit is the beginings of attempting to transition away from
crow, and toward boost::beast. Unit tests are passing, and
implementation appears to be slightly faster than crow.
Change-Id: Ic8d946dc7a04f514c67b1098f181eee1ced69171
|
|
These functions are not yet used, but will be required by at least two upcoming
patchsets. This functionality has been cut out from Configuration patchset for
easier merge without having to wait for that commit.
Change-Id: Ibe5d5cefd874d4a2d896b42a2b7cfc17480f3c5a
Signed-off-by: Kowalski, Kamil <kamil.kowalski@intel.com>
|