Commit c6d8b7f
Track which CA signed each device certificate (#3024)
A device certificate names its signer by key id:
`device_certificates.aki` holds the CA's `ski`. There's no foreign key,
and nothing in the UI followed that link. Opening a device told you it
had a certificate but not who signed it, and the Certificate Authorities
list gave no way to tell a signer with a fleet behind it from one
nothing uses.
Closes #659
## Device settings
Each certificate now shows `Signer CA:` alongside its serial and
validity, linking to the CA.
The lookup is scoped to the device's org, so a certificate signed by
another org's CA reads "Unknown" rather than exposing that CA.
Certificates whose signer was never registered read "Unknown" too. That
includes the NervesHubCA-signed certificates the AKI validation lets
through from other orgs.
## A show page for a CA
There wasn't one. The only per-CA page was the edit form, whose save is
gated on `certificate_authority:update`, so it's the wrong place to send
a viewer who just wants to look.
`/org/:org/settings/certificates/:serial` shows the CA's details and a
Devices card: the total, then a row per product linking to that
product's device list filtered by this CA.
The device list is scoped to one product and a CA is scoped to the org,
so per-product rows are the only shape a working link can take.
The list page loses its per-row Edit and Delete buttons and the `Check
expiration?` / `JITP Enabled?` columns; the serial links to the show
page, and Delete lives there now. It gains a Devices count.
## Filtering
A `Signer CA` select in the device list sidebar, built from the CAs that
signed a certificate held by a device in this product. That's the same
treatment the firmware version filter got in #3020, and it carries the
same kind of hint tooltip explaining why a CA you expected might be
missing. A "No known CA" option covers shared secret devices and
unregistered signers.
It goes through the same filter map as every other sidebar filter, so
`filters[signer_ca]` works on the device list API. There's a matching
`signer_ca` advanced query column supporting `=` and `!=`:
```
signer_ca = "613033017807900175"
signer_ca != ":not_set" and connection = "connected"
```
Autosuggest shows the CA's description and sends the serial, the way
`firmware` shows a version and sends a UUID. The OpenAPI spec documents
both.
## The index
`device_certificates` had no index on `aki`, so every count and every
filtered device list would sequential-scan it. This adds `(aki,
device_id)` concurrently. The device id is in there so the counts can be
answered from the index alone.
## Two things in `CAHelpers` that stopped working
Both are casualties of #2494, which deleted the old SCSS. The components
survived; the CSS they depended on didn't.
`check_expiration_tooltip/1` styles nothing: `tooltip-info` and
`tooltip-text` have no rules behind them any more, and `display: none`
was the line that made it a tooltip. Without it the text is always on,
which is the paragraph sitting in the middle of the new and edit CA
forms. It's rebuilt on the `ToolTip` hook, the same shape `HealthStatus`
uses, so it degrades to hidden rather than to visible. The show page
calls it instead of carrying its own copy.
`certificate_status/1` had the same problem with more at stake:
`.certificate-status-expired` (red) and
`.certificate-status-expiring-soon` (amber) went with the SCSS, so an
expired CA rendered in the same colour as a current one. It now returns
`text-alert-content` / `text-warning-content` / `text-base-400` rather
than class names Tailwind's `@source` scanning can't see.
Writing the first test for `certificate_status/1` turned up a third
problem. "Expiring Soon" was unreachable:
```elixir
DateTime.after?(DateTime.shift(DateTime.utc_now(), month: -3), assigns.not_after)
```
A negative shift puts the cutoff three months in the *past*, so the
clause only matched certificates that expired over three months ago,
which the `Expired` clause above it had already taken. The shift is now
positive, and the status has test coverage for all three branches.
## Noticed but not fixed
The edit page looks a CA up by serial alone, with no org check. Serials
are globally unique, so a member of one org can open and save another
org's CA. The show page added here uses
`get_ca_certificate_by_org_and_serial/2`. Fixing edit is a separate
change.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent 870243f commit c6d8b7f
25 files changed
Lines changed: 923 additions & 59 deletions
File tree
- lib
- nerves_hub_web
- components
- device_page
- controllers/api/openapi
- live
- devices
- org
- certificate_authority_templates
- nerves_hub/devices
- advanced_query
- priv/repo/migrations
- test
- nerves_hub_web
- components
- live
- devices
- show
- org
- nerves_hub/devices
- advanced_query
- support
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
111 | 111 | | |
112 | 112 | | |
113 | 113 | | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
114 | 135 | | |
115 | 136 | | |
116 | 137 | | |
| |||
164 | 185 | | |
165 | 186 | | |
166 | 187 | | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
167 | 202 | | |
168 | 203 | | |
169 | 204 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| |||
65 | 66 | | |
66 | 67 | | |
67 | 68 | | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
68 | 75 | | |
69 | 76 | | |
70 | 77 | | |
| |||
242 | 249 | | |
243 | 250 | | |
244 | 251 | | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
245 | 260 | | |
246 | 261 | | |
247 | 262 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
| 16 | + | |
15 | 17 | | |
16 | 18 | | |
17 | 19 | | |
| |||
94 | 96 | | |
95 | 97 | | |
96 | 98 | | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
97 | 184 | | |
98 | 185 | | |
99 | 186 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| 17 | + | |
17 | 18 | | |
18 | 19 | | |
19 | 20 | | |
| |||
39 | 40 | | |
40 | 41 | | |
41 | 42 | | |
| 43 | + | |
42 | 44 | | |
43 | 45 | | |
44 | 46 | | |
| |||
189 | 191 | | |
190 | 192 | | |
191 | 193 | | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
192 | 200 | | |
193 | 201 | | |
194 | 202 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
4 | 19 | | |
5 | 20 | | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
12 | 30 | | |
13 | 31 | | |
14 | 32 | | |
| |||
18 | 36 | | |
19 | 37 | | |
20 | 38 | | |
21 | | - | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
22 | 43 | | |
23 | 44 | | |
24 | 45 | | |
| |||
37 | 58 | | |
38 | 59 | | |
39 | 60 | | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
48 | 66 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
9 | 10 | | |
| 11 | + | |
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| |||
28 | 30 | | |
29 | 31 | | |
30 | 32 | | |
31 | | - | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
32 | 42 | | |
33 | 43 | | |
34 | 44 | | |
| |||
201 | 211 | | |
202 | 212 | | |
203 | 213 | | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
204 | 219 | | |
205 | 220 | | |
206 | 221 | | |
| |||
309 | 324 | | |
310 | 325 | | |
311 | 326 | | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
312 | 344 | | |
313 | 345 | | |
314 | 346 | | |
| |||
Lines changed: 7 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| 57 | + | |
57 | 58 | | |
58 | 59 | | |
59 | 60 | | |
| |||
67 | 68 | | |
68 | 69 | | |
69 | 70 | | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
70 | 77 | | |
71 | 78 | | |
72 | 79 | | |
| |||
0 commit comments