add new endpoints for app v2 (#116)
* add some new endpoints for app v2 * add oauth * update EcoVacsHomeProducts - new attribute model * add some missing endpoints for app v2 * - use only one level subdomain urls on service list - add status * add new used subdomains (for europe) * improve docker images creation as requirements are change less often * reformat area list * add revoke expired oauths * add docker-compose example * wait for mqtt start fixes #107 * make images even smaller by copying only required folders instead of all (.git,...) * fix exception during logging * return fail if we can't get clean logs * improve docker docs. Thanks for the hit @Bustel * fix body not json serializable * add docker-compose example in separate folder
This commit is contained in:
parent
9b1ae262a8
commit
df36bdd29d
21 changed files with 2778 additions and 904 deletions
|
|
@ -53,9 +53,9 @@ I get it, you don't trust create_certs and want to do it manually. The easiest
|
|||
|
||||
### Create a Root CA
|
||||
|
||||
1. Create csrconfig.txt for use in later commands
|
||||
1. Create csrconfig_ca.txt for use in later commands
|
||||
|
||||
***csrconfig.txt***
|
||||
***csrconfig_ca.txt***
|
||||
````
|
||||
[ req ]
|
||||
default_md = sha256
|
||||
|
|
@ -70,9 +70,9 @@ keyUsage=critical,keyCertSign,cRLSign
|
|||
basicConstraints=critical,CA:true,pathlen:1
|
||||
````
|
||||
|
||||
1. Create certconfig.txt for use in later commands
|
||||
1. Create certconfig_ca.txt for use in later commands
|
||||
|
||||
***certconfig.txt***
|
||||
***certconfig_ca.txt***
|
||||
````
|
||||
[ req ]
|
||||
default_md = sha256
|
||||
|
|
@ -91,21 +91,21 @@ basicConstraints=critical,CA:true,pathlen:1
|
|||
|
||||
1. Generate the RSA private key
|
||||
|
||||
`openssl genpkey -outform PEM -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out priv.key`
|
||||
`openssl genrsa -out ca.key 4096`
|
||||
|
||||
1. Create the CSR
|
||||
|
||||
`openssl req -new -nodes -key priv.key -config csrconfig.txt -out cert.csr`
|
||||
`openssl req -new -nodes -key ca.key -config csrconfig_ca.txt -out ca.csr`
|
||||
|
||||
1. Self-sign your CSR
|
||||
|
||||
`openssl req -x509 -nodes -in cert.csr -days 3650 -key priv.key -config certconfig.txt -extensions req_ext -out cert.crt`
|
||||
`openssl req -x509 -nodes -in ca.csr -days 1095 -key ca.key -config certconfig_ca.txt -extensions req_ext -out ca.crt`
|
||||
|
||||
### Create the Server Certificate
|
||||
|
||||
1. Create csrconfig.txt for use in later commands
|
||||
1. Create csrconfig_bumper.txt for use in later commands
|
||||
|
||||
***csrconfig.txt***
|
||||
***csrconfig_bumper.txt***
|
||||
````
|
||||
[ req ]
|
||||
default_md = sha256
|
||||
|
|
@ -127,11 +127,15 @@ DNS.2 = ecouser.net
|
|||
DNS.3 = *.ecouser.net
|
||||
DNS.4 = ecovacs.net
|
||||
DNS.5 = *.ecovacs.net
|
||||
DNS.6 = *.ww.ecouser.net
|
||||
DNS.7 = *.dc-eu.ww.ecouser.net
|
||||
DNS.8 = *.dc.ww.ecouser.net
|
||||
DNS.9 = *.area.ww.ecouser.net
|
||||
````
|
||||
|
||||
1. Create certconfig.txt for use in later commands
|
||||
1. Create certconfig_bumper.txt for use in later commands
|
||||
|
||||
***certconfig.txt***
|
||||
***certconfig_bumper.txt***
|
||||
````
|
||||
[ req ]
|
||||
default_md = sha256
|
||||
|
|
@ -155,19 +159,23 @@ DNS.2 = ecouser.net
|
|||
DNS.3 = *.ecouser.net
|
||||
DNS.4 = ecovacs.net
|
||||
DNS.5 = *.ecovacs.net
|
||||
DNS.6 = *.ww.ecouser.net
|
||||
DNS.7 = *.dc-eu.ww.ecouser.net
|
||||
DNS.8 = *.dc.ww.ecouser.net
|
||||
DNS.9 = *.area.ww.ecouser.net
|
||||
````
|
||||
|
||||
1. Generate the RSA private key
|
||||
|
||||
`openssl genpkey -outform PEM -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out priv.key`
|
||||
`openssl genrsa -out bumper.key 4096`
|
||||
|
||||
1. Create the CSR
|
||||
|
||||
`openssl req -new -nodes -key priv.key -config csrconfig.txt -out cert.csr`
|
||||
`openssl req -new -nodes -key bumper.key -config csrconfig_bumper.txt -out bumper.csr`
|
||||
|
||||
1. Sign your CSR with a root CA cert
|
||||
|
||||
`openssl x509 -req -in cert.csr -days 3650 -CA ca.crt -CAkey priv.key -extfile certconfig.txt -extensions req_ext -CAserial /tmp/tmp-10593TSH1OlVSxC7C -CAcreateserial -out cert.crt`
|
||||
`openssl x509 -req -in bumper.csr -days 365 -CA ca.crt -CAkey ca.key -extfile certconfig_bumper.txt -extensions req_ext -CAcreateserial -out bumper.crt`
|
||||
|
||||
## Using a Custom CA/Self
|
||||
|
||||
|
|
|
|||
|
|
@ -26,6 +26,7 @@ If overriding DNS for the top-level domains isn't an option, you'll need to conf
|
|||
**Note:** Depending on country, your phone/robot may be using a different domain. Most of these domains contain country-specific placeholders.
|
||||
|
||||
Not all domains have been documented at this point, and this list will be updated as more are identified/seen. The preferred way to ensure Bumper works is to override the full domains as above.
|
||||
**Note:** The app dynamically gets the required domains from the endpoint `api/appsvr/service/list` and therefore ecovacs can use different domains for different models.
|
||||
|
||||
Replacement Examples:
|
||||
|
||||
|
|
@ -46,6 +47,7 @@ Replacement Examples:
|
|||
| `eco-{countrycode}-api.ecovacs.com` | Used for Login |
|
||||
| `gl-{countrycode}-api.ecovacs.com` | Used by EcoVacs Home app |
|
||||
| `gl-{countrycode}-openapi.ecovacs.com` | Used by EcoVacs Home app |
|
||||
| `portal.ecouser.net` | Used for Login and Rest API |
|
||||
| `portal-{countrycode}.ecouser.net` | Used for Login and Rest API |
|
||||
| `portal-{region}.ecouser.net` | Used for Login and Rest API |
|
||||
| `portal-ww.ecouser.net` | Used for various Rest APIs |
|
||||
|
|
@ -59,4 +61,11 @@ Replacement Examples:
|
|||
| `recommender.ecovacs.com` | Used by Ecovacs Home app |
|
||||
| `bigdata-international.ecovacs.com` | Telemetry/tracking |
|
||||
| `bigdata-northamerica.ecovacs.com` | Telemetry/tracking |
|
||||
| `bigdata-europe.ecovacs.com` | Telemetry/tracking |
|
||||
| `bigdata-{unknown regions}.ecovacs.com` | Telemetry/tracking |
|
||||
| `api-app.ww.ecouser.net` | Api for App (v2+) |
|
||||
| `api-app.dc-{region}.ww.ecouser.net` | Api for App (v2+) |
|
||||
| `users-base.dc-{region}.ww.ecouser.net` | Accounts for App (v2+) |
|
||||
| `jmq-ngiot-{region}.dc.ww.ecouser.net` | MQTT for App (v2+) |
|
||||
| `api-rop.dc-{region}.ww.ecouser.net` | App (v2+) |
|
||||
| `jmq-ngiot-{region}.area.ww.ecouser.net`| App (v2+) |
|
||||
|
|
@ -41,4 +41,14 @@ Optionally you can map existing directories for logs, data, and certs.
|
|||
|
||||
````
|
||||
docker run -it -e "BUMPER_ANNOUNCE_IP=X.X.X.X" -p 443:443 -p 8007:8007 -p 8883:8883 -p 5223:5223 -v /home/user/bumper/data:/bumper/data --name bumper bmartin5692/bumper
|
||||
````
|
||||
````
|
||||
|
||||
# Docker-compose
|
||||
|
||||
A docker-compose example can be found in the ["example" folder](https://github.com/bmartin5692/bumper/tree/master/example/docker-compose).
|
||||
|
||||
The docker-compose starts two services:
|
||||
- bumper itself
|
||||
- nginx proxy, which redirects MQTT traffic on port `443` to port `8883`
|
||||
|
||||
The redirection is required as the app v2+ and robots with a newer firmware are connecting to the mqtt server on port 433.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue