# CIIMS web service message exchange proxy A thin HTTP proxy that translates JSON POST requests into SOAP/XML calls to a CIIMS ExchangeService backend. Designed for airport operational message exchange (AODB/FLOP). ## API ### POST /send Send a message to CIIMS. Request body (JSON): ```json { "url": "http://domain.tld", // optional, overrides CIIMS_SERVER "user": "ciims username", // required "pass": "ciims password", // required "event": "route event id", // required "priority": 0, // optional, defaults to 0 "val": false, // optional, defaults to false "msg": "ciims xml body" // required } ``` ### POST /receive Receive messages from CIIMS. Request body (JSON): ```json { "url": "http://domain.tld", // optional, overrides CIIMS_SERVER "user": "ciims username", // required "pass": "ciims password", // required "count": 3 // required, 1-1000 } ``` ### GET /ping Health check — returns `{"message": "pong"}`. ## Configuration | Environment Variable | Description | Default | |---|---|---| | `CIIMS_SERVER` | Base URL of the default CIIMS ExchangeService | (required) | | `CIIMS_ALLOWED_SERVERS` | Comma-separated extra CIIMS base URLs allowed for request `url` overrides | empty | | `PROXY_LISTEN` | Bind address for the proxy HTTP server | `:9090` | | `CIIMS_TIMEOUT` | Outbound request timeout in seconds | `240` | ## Security Considerations - **Authentication:** This proxy does not authenticate callers. Deploy behind a firewall or add a reverse-proxy layer (nginx, envoy) with API key / basic auth. - **TLS:** Use a TLS-terminating reverse proxy in production. The proxy itself serves plain HTTP and transmits CIIMS credentials with every request. - **Input limits:** Request bodies are limited to 1 MB, CIIMS responses are limited to 64 MiB, and the `count` parameter on `/receive` is capped at 1000. - **URL overrides:** Per-request `url` values are accepted only when they match `CIIMS_SERVER` or an entry in `CIIMS_ALLOWED_SERVERS` after normalization. - **Credentials:** CIIMS usernames and passwords are XML-escaped before being embedded in SOAP envelopes. They are not logged. ## Build ```bash go build -o ciimsproxy ./cmd/main/ ``` ## Example ```bash # Start the proxy CIIMS_SERVER=http://192.168.1.100:8080 ./ciimsproxy # Send a message curl -X POST http://localhost:9090/send \ -H 'Content-Type: application/json' \ -d '{"user":"FIMS","pass":"FIMS","event":"FLOP-CHDT","msg":""}' # Receive messages curl -X POST http://localhost:9090/receive \ -H 'Content-Type: application/json' \ -d '{"user":"FIMS","pass":"FIMS","count":5}' ```