+val dispatcher =
+ Config.dispatcher ^ ":" ^ Int.toString Config.dispatcherPort
+
+fun request fname =
+ let
+ val uid = Posix.ProcEnv.getuid ()
+ val user = Posix.SysDB.Passwd.name (Posix.SysDB.getpwuid uid)
+
+ val () = Acl.read Config.aclFile
+ val () = Domain.setUser user
+ val _ = check fname
+
+ val context = OpenSSL.context (Config.certDir ^ "/" ^ user ^ ".pem",
+ Config.keyDir ^ "/" ^ user ^ ".pem",
+ Config.trustStore)
+
+ val bio = OpenSSL.connect (context, dispatcher)
+
+ val inf = TextIO.openIn fname
+
+ fun loop () =
+ case TextIO.inputLine inf of
+ NONE => ()
+ | SOME line => (OpenSSL.writeAll (bio, line);
+ loop ())
+ in
+ loop ();
+ TextIO.closeIn inf;
+ OpenSSL.close bio
+ end
+ handle ErrorMsg.Error => ()
+
+fun service () =
+ let
+ val () = Acl.read Config.aclFile
+
+ val context = OpenSSL.context (Config.serverCert,
+ Config.serverKey,
+ Config.trustStore)
+
+ val sock = OpenSSL.listen (context, Config.dispatcherPort)
+
+ fun loop () =
+ case OpenSSL.accept sock of
+ NONE => ()
+ | SOME bio =>
+ let
+ val user = OpenSSL.peerCN bio
+ val () = print ("\nConnection from " ^ user ^ "\n")
+ val () = Domain.setUser user
+
+ val outname = OS.FileSys.tmpName ()
+ val outf = TextIO.openOut outname
+
+ fun loop' () =
+ case OpenSSL.readOne bio of
+ NONE => ()
+ | SOME line => (TextIO.output (outf, line);
+ loop' ())
+ in
+ (loop' ();
+ TextIO.closeOut outf;
+ eval outname
+ handle ErrorMsg.Error => ();
+ OS.FileSys.remove outname;
+ OpenSSL.close bio)
+ handle OpenSSL.OpenSSL _ => ();
+ loop ()
+ end
+ in
+ loop ();
+ OpenSSL.shutdown sock
+ end
+