Skip to main content

acme_proxy/config/types/
challenge.rs

1//! `[challenge]` — which challenge types an authorization offers, and how each
2//! one is validated.
3//!
4//! Re-exported flat from [`super`], so nothing outside this directory names
5//! the submodule.
6
7use serde::Deserialize;
8
9use super::empty_string_is_no_values;
10
11/// Challenge configuration.
12#[derive(Debug, Clone, Deserialize)]
13#[serde(default)]
14pub struct ChallengeConfig {
15    #[serde(deserialize_with = "empty_string_is_no_values")]
16    pub enabled: Vec<String>,
17    /// Skip domain-control validation entirely: a triggered challenge is marked
18    /// `valid` with no network check.
19    ///
20    /// Defaults to `false`. It defaulted to `true` — convenient for development,
21    /// but it meant a server started with no configuration at all, bound to
22    /// `[::]:3000` on every interface, would issue a certificate for **any**
23    /// name to **anyone** who could reach the port, since `filter.enabled` is
24    /// empty by default too. A certificate authority's safe direction is to
25    /// prove control; the convenience of not proving it is worth having, but
26    /// worth having to ask for.
27    pub bypass: bool,
28    pub timeout_ms: u64,
29    pub http_01: Http01Config,
30    pub tls_alpn_01: TlsAlpnConfig,
31}
32
33impl Default for ChallengeConfig {
34    fn default() -> Self {
35        Self {
36            enabled: vec!["http-01".to_string()],
37            bypass: false,
38            timeout_ms: 5000,
39            http_01: Http01Config::default(),
40            tls_alpn_01: TlsAlpnConfig::default(),
41        }
42    }
43}
44/// Configuration for the `http-01` challenge.
45#[derive(Debug, Clone, Deserialize)]
46#[serde(default)]
47pub struct Http01Config {
48    pub port: u16,
49    pub https_port: u16,
50    pub follow_redirects: bool,
51    pub max_redirects: u8,
52    pub max_response_bytes: usize,
53}
54
55impl Default for Http01Config {
56    fn default() -> Self {
57        Self {
58            port: 80,
59            https_port: 443,
60            follow_redirects: true,
61            max_redirects: 5,
62            max_response_bytes: 4096,
63        }
64    }
65}
66/// Configuration for the `tls-alpn-01` challenge.
67#[derive(Debug, Clone, Deserialize)]
68#[serde(default)]
69pub struct TlsAlpnConfig {
70    pub port: u16,
71}
72
73impl Default for TlsAlpnConfig {
74    fn default() -> Self {
75        Self { port: 443 }
76    }
77}