Files
ciimsproxy/README.md
T

85 lines
2.7 KiB
Markdown
Raw Normal View History

2020-09-16 10:59:14 +08:00
# CIIMS web service message exchange proxy
A thin HTTP proxy that translates JSON POST requests into SOAP/XML calls to a CIIMS
ExchangeService backend. Designed for airport operational message exchange (AODB/FLOP).
2020-09-16 10:59:14 +08:00
## API
2020-09-16 10:59:14 +08:00
### POST /send
Send a message to CIIMS.
Request body (JSON):
2020-09-16 10:59:14 +08:00
```json
{
"url": "http://domain.tld", // optional, overrides CIIMS_SERVER
"user": "ciims username", // required
"pass": "ciims password", // required
"event": "route event id", // required
"priority": 0, // optional, defaults to 0
"val": false, // optional, defaults to false
"msg": "ciims xml body" // required
2020-09-16 10:59:14 +08:00
}
```
### POST /receive
2020-09-16 10:59:14 +08:00
Receive messages from CIIMS.
Request body (JSON):
2020-09-16 10:59:14 +08:00
```json
{
"url": "http://domain.tld", // optional, overrides CIIMS_SERVER
"user": "ciims username", // required
"pass": "ciims password", // required
"count": 3 // required, 1-1000
2020-09-16 10:59:14 +08:00
}
2020-09-16 11:02:55 +08:00
```
### GET /ping
Health check — returns `{"message": "pong"}`.
## Configuration
| Environment Variable | Description | Default |
|---|---|---|
| `CIIMS_SERVER` | Base URL of the default CIIMS ExchangeService | (required) |
| `CIIMS_ALLOWED_SERVERS` | Comma-separated extra CIIMS base URLs allowed for request `url` overrides | empty |
| `PROXY_LISTEN` | Bind address for the proxy HTTP server | `:9090` |
| `CIIMS_TIMEOUT` | Outbound request timeout in seconds | `240` |
## Security Considerations
- **Authentication:** This proxy does not authenticate callers. Deploy behind a firewall or
add a reverse-proxy layer (nginx, envoy) with API key / basic auth.
- **TLS:** Use a TLS-terminating reverse proxy in production. The proxy itself serves plain
HTTP and transmits CIIMS credentials with every request.
- **Input limits:** Request bodies are limited to 1 MB, CIIMS responses are limited to 64 MiB, and the `count` parameter on `/receive`
is capped at 1000.
- **URL overrides:** Per-request `url` values are accepted only when they match `CIIMS_SERVER` or an entry in `CIIMS_ALLOWED_SERVERS` after normalization.
- **Credentials:** CIIMS usernames and passwords are XML-escaped before being embedded in
SOAP envelopes. They are not logged.
## Build
```bash
go build -o ciimsproxy ./cmd/main/
```
## Example
```bash
# Start the proxy
CIIMS_SERVER=http://192.168.1.100:8080 ./ciimsproxy
# Send a message
curl -X POST http://localhost:9090/send \
-H 'Content-Type: application/json' \
-d '{"user":"FIMS","pass":"FIMS","event":"FLOP-CHDT","msg":"<MSG/>"}'
# Receive messages
curl -X POST http://localhost:9090/receive \
-H 'Content-Type: application/json' \
-d '{"user":"FIMS","pass":"FIMS","count":5}'
```