Add ability to drop privileges after binding to port

This commit is contained in:
Tobias Reisinger 2023-11-27 17:36:44 +01:00
parent 3b596de06f
commit 7ed3a9e52d
Signed by: serguzim
GPG key ID: 13AD60C237A28DFE
7 changed files with 79 additions and 4 deletions
emgauwa-core/src

View file

@ -1,9 +1,11 @@
use actix_cors::Cors;
use std::net::TcpListener;
use std::str::FromStr;
use actix_web::middleware::TrailingSlash;
use actix_web::{middleware, web, App, HttpServer};
use emgauwa_lib::handlers;
use emgauwa_lib::utils::drop_privileges;
use log::{trace, LevelFilter};
use simple_logger::SimpleLogger;
@ -22,6 +24,18 @@ async fn main() -> std::io::Result<()> {
.init()
.expect("Error initializing logger.");
let listener = TcpListener::bind(format!("{}:{}", settings.host, settings.port))
.expect("Error creating listener");
if !settings.user.is_empty() && !settings.group.is_empty() {
log::info!(
"Dropping privileges to {}:{}",
settings.user,
settings.group
);
drop_privileges(&settings.user, &settings.group).expect("Error dropping privileges");
}
let pool = emgauwa_lib::db::init(&settings.database).await;
log::info!("Starting server on {}:{}", settings.host, settings.port);
@ -55,7 +69,7 @@ async fn main() -> std::io::Result<()> {
.service(handlers::v1::schedules::delete)
.service(handlers::v1::ws::controllers::index)
})
.bind(format!("{}:{}", settings.host, settings.port))?
.listen(listener)?
.run()
.await
}