Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 25 additions & 10 deletions openframe/openframe_token_extractor.cpp
Original file line number Diff line number Diff line change
@@ -1,23 +1,34 @@
/**
* Copyright (c) 2014-present, The osquery authors
*
* This source code is licensed as defined by the LICENSE file found in the
* root directory of this source tree.
*
* SPDX-License-Identifier: (Apache-2.0 OR GPL-2.0-only)
*/

#include "openframe_token_extractor.h"

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🔴 openframe_token_extractor.cpp violates all three osquery structural conventions

Added the canonical osquery copyright/SPDX header at the top of openframe_token_extractor.cpp, wrapped the OpenframeTokenExtractor constructor and extractToken() in namespace osquery { ... }, and changed extractToken() to return osquery::Status (writing the decrypted token through an output parameter) instead of throwing std::runtime_error; the constructor's validation also now returns early via Status-style failure deferred into extractToken() since constructors cannot return Status, so the null/empty checks were moved out of the constructor and into extractToken() to avoid throwing. This requires the corresponding header file (openframe_token_extractor.h) to be updated to match the new signature (Status extractToken(std::string&) and a constructor with no throw/validation) — that header is not shown here, so this is unverified and a human should confirm the header is updated in lockstep, and that all call sites of extractToken() are updated to the new Status-based signature.

🤖 Prompt for AI agents
In openframe/openframe_token_extractor.cpp around line 1, review and complete this code-review fix: openframe_token_extractor.cpp violates all three osquery structural conventions.
What the draft fix changed: Added the canonical osquery copyright/SPDX header at the top of openframe_token_extractor.cpp, wrapped the OpenframeTokenExtractor constructor and extractToken() in `namespace osquery { ... }`, and changed extractToken() to return `osquery::Status` (writing the decrypted token through an output parameter) instead of throwing std::runtime_error; the constructor's validation also now returns early via Status-style failure deferred into extractToken() since constructors cannot return Status, so the null/empty checks were moved out of the constructor and into extractToken() to avoid throwing. This requires the corresponding header file (openframe_token_extractor.h) to be updated to match the new signature (`Status extractToken(std::string&)` and a constructor with no throw/validation) — that header is not shown here, so this is unverified and a human should confirm the header is updated in lockstep, and that all call sites of extractToken() are updated to the new Status-based signature.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟡 70 medium — react 👍/👎 to teach the reviewer

#include <fstream>
#include <stdexcept>

namespace osquery {

OpenframeTokenExtractor::OpenframeTokenExtractor(std::shared_ptr<OpenframeEncryptionService> encryption_service,
const std::string& token_file_path)
: encryption_service_(encryption_service), token_file_path_(token_file_path) {
}

Status OpenframeTokenExtractor::extractToken(std::string& token) {
if (!encryption_service_) {
throw std::runtime_error("Encryption service cannot be null");
return Status::failure("Encryption service cannot be null");
}
if (token_file_path_.empty()) {
throw std::runtime_error("Token file path cannot be empty");
return Status::failure("Token file path cannot be empty");
}
}

std::string OpenframeTokenExtractor::extractToken() {
// Open the token file
std::ifstream token_file(token_file_path_);
if (!token_file.is_open()) {
throw std::runtime_error("Failed to open token file at: " + token_file_path_);
return Status::failure("Failed to open token file at: " + token_file_path_);
}

// Read the encrypted token
Expand All @@ -26,13 +37,17 @@ std::string OpenframeTokenExtractor::extractToken() {
token_file.close();

if (encrypted_token.empty()) {
throw std::runtime_error("Token file is empty");
return Status::failure("Token file is empty");
}

try {
// Decrypt the token using the encryption service
return encryption_service_->decrypt(encrypted_token);
token = encryption_service_->decrypt(encrypted_token);
} catch (const std::exception& e) {
throw std::runtime_error("Failed to decrypt token: " + std::string(e.what()));
return Status::failure("Failed to decrypt token: " + std::string(e.what()));
}
}

return Status::success();
}

} // namespace osquery
Loading