You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

188 lines
5.1 KiB

5 years ago
8 years ago
5 years ago
5 years ago
  1. #!/usr/bin/env sh
  2. # Gandi LiveDNS v5 API
  3. # https://api.gandi.net/docs/livedns/
  4. # https://api.gandi.net/docs/authentication/ for token + apikey (deprecated) authentication
  5. # currently under beta
  6. #
  7. # Requires GANDI API KEY set in GANDI_LIVEDNS_KEY set as environment variable
  8. #
  9. #Author: Frédéric Crozat <fcrozat@suse.com>
  10. # Dominik Röttsches <drott@google.com>
  11. #Report Bugs here: https://github.com/fcrozat/acme.sh
  12. #
  13. ######## Public functions #####################
  14. GANDI_LIVEDNS_API="https://dns.api.gandi.net/api/v5"
  15. #Usage: dns_gandi_livedns_add _acme-challenge.www.domain.com "XKrxpRBosdIKFzxW_CT3KLZNf6q0HG9i01zxXp5CPBs"
  16. dns_gandi_livedns_add() {
  17. fulldomain=$1
  18. txtvalue=$2
  19. if [ -z "$GANDI_LIVEDNS_KEY" ] && [ -z "$GANDI_LIVEDNS_TOKEN" ]; then
  20. _err "No Token or API key (deprecated) specified for Gandi LiveDNS."
  21. _err "Create your token or key and export it as GANDI_LIVEDNS_KEY or GANDI_LIVEDNS_TOKEN respectively"
  22. return 1
  23. fi
  24. # Keep only one secret in configuration
  25. if [ -n "$GANDI_LIVEDNS_TOKEN" ]; then
  26. _saveaccountconf GANDI_LIVEDNS_TOKEN "$GANDI_LIVEDNS_TOKEN"
  27. _clearaccountconf GANDI_LIVEDNS_KEY
  28. elif [ -n "$GANDI_LIVEDNS_KEY" ]; then
  29. _saveaccountconf GANDI_LIVEDNS_KEY "$GANDI_LIVEDNS_KEY"
  30. _clearaccountconf GANDI_LIVEDNS_TOKEN
  31. fi
  32. _debug "First detect the root zone"
  33. if ! _get_root "$fulldomain"; then
  34. _err "invalid domain"
  35. return 1
  36. fi
  37. _debug fulldomain "$fulldomain"
  38. _debug txtvalue "$txtvalue"
  39. _debug domain "$_domain"
  40. _debug sub_domain "$_sub_domain"
  41. _dns_gandi_append_record "$_domain" "$_sub_domain" "$txtvalue"
  42. }
  43. #Usage: fulldomain txtvalue
  44. #Remove the txt record after validation.
  45. dns_gandi_livedns_rm() {
  46. fulldomain=$1
  47. txtvalue=$2
  48. _debug "First detect the root zone"
  49. if ! _get_root "$fulldomain"; then
  50. _err "invalid domain"
  51. return 1
  52. fi
  53. _debug fulldomain "$fulldomain"
  54. _debug domain "$_domain"
  55. _debug sub_domain "$_sub_domain"
  56. _debug txtvalue "$txtvalue"
  57. if ! _dns_gandi_existing_rrset_values "$_domain" "$_sub_domain"; then
  58. return 1
  59. fi
  60. _new_rrset_values=$(echo "$_rrset_values" | sed "s/...$txtvalue...//g")
  61. # Cleanup dangling commata.
  62. _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/, ,/ ,/g")
  63. _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/, *\]/\]/g")
  64. _new_rrset_values=$(echo "$_new_rrset_values" | sed "s/\[ *,/\[/g")
  65. _debug "New rrset_values" "$_new_rrset_values"
  66. _gandi_livedns_rest PUT \
  67. "domains/$_domain/records/$_sub_domain/TXT" \
  68. "{\"rrset_ttl\": 300, \"rrset_values\": $_new_rrset_values}" &&
  69. _contains "$response" '{"message": "DNS Record Created"}' &&
  70. _info "Removing record $(__green "success")"
  71. }
  72. #################### Private functions below ##################################
  73. #_acme-challenge.www.domain.com
  74. #returns
  75. # _sub_domain=_acme-challenge.www
  76. # _domain=domain.com
  77. _get_root() {
  78. domain=$1
  79. i=2
  80. p=1
  81. while true; do
  82. h=$(printf "%s" "$domain" | cut -d . -f $i-100)
  83. _debug h "$h"
  84. if [ -z "$h" ]; then
  85. #not valid
  86. return 1
  87. fi
  88. if ! _gandi_livedns_rest GET "domains/$h"; then
  89. return 1
  90. fi
  91. if _contains "$response" '"code": 401'; then
  92. _err "$response"
  93. return 1
  94. elif _contains "$response" '"code": 404'; then
  95. _debug "$h not found"
  96. else
  97. _sub_domain=$(printf "%s" "$domain" | cut -d . -f 1-$p)
  98. _domain="$h"
  99. return 0
  100. fi
  101. p="$i"
  102. i=$(_math "$i" + 1)
  103. done
  104. return 1
  105. }
  106. _dns_gandi_append_record() {
  107. domain=$1
  108. sub_domain=$2
  109. txtvalue=$3
  110. if _dns_gandi_existing_rrset_values "$domain" "$sub_domain"; then
  111. _debug "Appending new value"
  112. _rrset_values=$(echo "$_rrset_values" | sed "s/\"]/\",\"$txtvalue\"]/")
  113. else
  114. _debug "Creating new record" "$_rrset_values"
  115. _rrset_values="[\"$txtvalue\"]"
  116. fi
  117. _debug new_rrset_values "$_rrset_values"
  118. _gandi_livedns_rest PUT "domains/$_domain/records/$sub_domain/TXT" \
  119. "{\"rrset_ttl\": 300, \"rrset_values\": $_rrset_values}" &&
  120. _contains "$response" '{"message": "DNS Record Created"}' &&
  121. _info "Adding record $(__green "success")"
  122. }
  123. _dns_gandi_existing_rrset_values() {
  124. domain=$1
  125. sub_domain=$2
  126. if ! _gandi_livedns_rest GET "domains/$domain/records/$sub_domain"; then
  127. return 1
  128. fi
  129. if ! _contains "$response" '"rrset_type": "TXT"'; then
  130. _debug "Does not have a _acme-challenge TXT record yet."
  131. return 1
  132. fi
  133. if _contains "$response" '"rrset_values": \[\]'; then
  134. _debug "Empty rrset_values for TXT record, no previous TXT record."
  135. return 1
  136. fi
  137. _debug "Already has TXT record."
  138. _rrset_values=$(echo "$response" | _egrep_o 'rrset_values.*\[.*\]' |
  139. _egrep_o '\[".*\"]')
  140. return 0
  141. }
  142. _gandi_livedns_rest() {
  143. m=$1
  144. ep="$2"
  145. data="$3"
  146. _debug "$ep"
  147. export _H1="Content-Type: application/json"
  148. if [ -n "$GANDI_LIVEDNS_TOKEN" ]; then
  149. export _H2="Authorization: Bearer $GANDI_LIVEDNS_TOKEN"
  150. else
  151. export _H2="X-Api-Key: $GANDI_LIVEDNS_KEY"
  152. fi
  153. if [ "$m" = "GET" ]; then
  154. response="$(_get "$GANDI_LIVEDNS_API/$ep")"
  155. else
  156. _debug data "$data"
  157. response="$(_post "$data" "$GANDI_LIVEDNS_API/$ep" "" "$m")"
  158. fi
  159. if [ "$?" != "0" ]; then
  160. _err "error $ep"
  161. return 1
  162. fi
  163. _debug2 response "$response"
  164. return 0
  165. }