diff --git a/lib/db_base.cpp b/lib/db_base.cpp index e8c8c8a2..dfabb260 100644 --- a/lib/db_base.cpp +++ b/lib/db_base.cpp @@ -219,8 +219,8 @@ void db_base::insertPKI(pki_base *pki) } lookup[pki->getSqlItemId().toULongLong()] = pki; inToCont(pki); - emit columnsContentChanged(); TransCommit(); + emit columnsContentChanged(); } QString db_base::pem2QString(QModelIndexList indexes) const diff --git a/lib/db_x509.cpp b/lib/db_x509.cpp index d87d1f18..856eea13 100644 --- a/lib/db_x509.cpp +++ b/lib/db_x509.cpp @@ -85,11 +85,14 @@ pki_base *db_x509::newPKI(enum pki_type type) QList db_x509::getAllIssuers() { /* Select X509 CA certificates with available private key */ - return sqlSELECTpki( - "SELECT DISTINCT x.item " - "FROM (private_keys, tokens) JOIN x509super x " - "ON x.pkey = private_keys.item OR x.pkey = tokens.item " - "JOIN certs ON certs.item = x.item WHERE certs.ca=1"); + return sqlSELECTpki("SELECT x509super.item FROM x509super " + "JOIN private_keys ON x509super.pkey = private_keys.item " + "JOIN certs ON certs.item = x509super.item " + "WHERE certs.ca=1") + + sqlSELECTpki("SELECT x509super.item FROM x509super " + "JOIN tokens ON x509super.pkey = tokens.item " + "JOIN certs ON certs.item = x509super.item " + "WHERE certs.ca=1"); } void db_x509::remFromCont(QModelIndex &idx) @@ -175,7 +178,7 @@ static bool recursiveSigning(pki_x509 *cert, pki_x509 *client) void db_x509::inToCont(pki_base *pki) { - pki_x509 *cert = (pki_x509*)pki; + pki_x509 *cert = static_cast(pki); cert->setParent(NULL); pki_base *root = cert->getSigner(); if (!treeview || root == cert || root == NULL) @@ -378,6 +381,36 @@ pki_x509 *db_x509::get1SelectedCert() return static_cast(index.internalPointer()); } +void db_x509::markRequestSigned(pki_x509req *req, pki_x509 *cert) +{ + if (!req || !cert) + return; + pki_x509 *issuer = cert->getSigner(); + + Transaction; + if (!TransBegin()) + return; + + XSqlQuery q; + req->setDone(); + SQL_PREPARE(q, "UPDATE requests SET signed=? WHERE item=?"); + q.bindValue(0, req->getDone()); + q.bindValue(1, req->getSqlItemId()); + q.exec(); + + a1time a; + QString comment = req->getComment(); + req->setComment(comment + "\n" + tr("Signed on %1 by '%2'") + .arg(a.toPretty()) + .arg(issuer ? issuer->getIntName() : tr("Unknown"))); + SQL_PREPARE(q, "UPDATE items SET comment=? WHERE id=?"); + q.bindValue(0, req->getComment()); + q.bindValue(1, req->getSqlItemId()); + q.exec(); + + TransCommit(); +} + void db_x509::newItem() { NewX509 *dlg = new NewX509(mainwin); @@ -429,7 +462,7 @@ void db_x509::newCert(pki_x509 *cert) delete dlg; } -void db_x509::newCert(NewX509 *dlg) +pki_x509 *db_x509::newCert(NewX509 *dlg) { pki_x509 *cert = NULL; pki_x509 *signcert = NULL; @@ -440,19 +473,19 @@ void db_x509::newCert(NewX509 *dlg) QString intname; try { - + Transaction; // Step 1 - Subject and key if (!dlg->fromReqCB->isChecked()) { clientkey = dlg->getSelectedKey(); if (!clientkey) - return; + return NULL; subject = dlg->getX509name(); intname = dlg->description->text(); } else { // A PKCS#10 Request was selected req = dlg->getSelectedReq(); if (!req) - return; + return NULL; clientkey = req->getRefKey(); if (clientkey == NULL) { clientkey = req->getPubKey(); @@ -475,8 +508,10 @@ void db_x509::newCert(NewX509 *dlg) // Step 2 - select Signing if (dlg->foreignSignRB->isChecked()) { signcert = dlg->getSelectedSigner(); - if (!signcert) - return; + if (!signcert) { + delete cert; + return NULL; + } serial = getUniqueSerial(signcert); signkey = signcert->getRefKey(); } else { @@ -524,6 +559,11 @@ void db_x509::newCert(NewX509 *dlg) // and finally sign the request cert->sign(signkey, hashAlgo); + if (!TransBegin()) { + delete cert; + throw errorEx("Database trnasaction failed"); + } + // set the comment field cert->setComment(dlg->comment->toPlainText()); cert->pkiSource = dlg->getPkiSource(); @@ -543,6 +583,8 @@ void db_x509::newCert(NewX509 *dlg) } if (tempkey != NULL) delete(tempkey); + markRequestSigned(req, cert); + TransCommit(); } catch (errorEx &err) { @@ -550,7 +592,9 @@ void db_x509::newCert(NewX509 *dlg) delete cert; if (tempkey != NULL) delete(tempkey); + cert = NULL; } + return cert; } void db_x509::store(QModelIndex idx) diff --git a/lib/db_x509.h b/lib/db_x509.h index 76b87dd4..85900661 100644 --- a/lib/db_x509.h +++ b/lib/db_x509.h @@ -44,7 +44,8 @@ class db_x509: public db_x509super void writeIndex(const QString fname, bool hierarchy); void writeAllCerts(const QString fname, bool unrevoked); pki_base *insert(pki_base *item); - void newCert(NewX509 *dlg); + void markRequestSigned(pki_x509req *req, pki_x509 *cert); + pki_x509 *newCert(NewX509 *dlg); void newCert(pki_x509 *cert); void writePKCS12(pki_x509 *cert, QString s, bool chain); void writePKCS7(pki_x509 *cert, QString s, diff --git a/lib/sql.cpp b/lib/sql.cpp index 3a017568..2d4cd31e 100644 --- a/lib/sql.cpp +++ b/lib/sql.cpp @@ -42,6 +42,8 @@ bool DbTransaction::begin(const char *file, int line) bool DbTransaction::finish(const char *oper, const char *file, int line) { + if (!has_begun) + return true; if (mutex > 0) mutex--; else