Give better errors when incorrect KDMs are used (#1326).
[dcpomatic.git] / src / lib / dcp.cc
1 /*
2     Copyright (C) 2014-2018 Carl Hetherington <cth@carlh.net>
3
4     This file is part of DCP-o-matic.
5
6     DCP-o-matic is free software; you can redistribute it and/or modify
7     it under the terms of the GNU General Public License as published by
8     the Free Software Foundation; either version 2 of the License, or
9     (at your option) any later version.
10
11     DCP-o-matic is distributed in the hope that it will be useful,
12     but WITHOUT ANY WARRANTY; without even the implied warranty of
13     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14     GNU General Public License for more details.
15
16     You should have received a copy of the GNU General Public License
17     along with DCP-o-matic.  If not, see <http://www.gnu.org/licenses/>.
18
19 */
20
21 #include "dcp.h"
22 #include "config.h"
23 #include "dcp_content.h"
24 #include <dcp/dcp.h>
25 #include <dcp/decrypted_kdm.h>
26 #include <dcp/exceptions.h>
27 #include <boost/foreach.hpp>
28
29 #include "i18n.h"
30
31 using std::list;
32 using std::string;
33 using boost::shared_ptr;
34
35 /** Find all the CPLs in our directories, cross-add assets and return the CPLs */
36 list<shared_ptr<dcp::CPL> >
37 DCP::cpls () const
38 {
39         list<shared_ptr<dcp::DCP> > dcps;
40         list<shared_ptr<dcp::CPL> > cpls;
41
42         BOOST_FOREACH (boost::filesystem::path i, _dcp_content->directories()) {
43                 shared_ptr<dcp::DCP> dcp (new dcp::DCP (i));
44                 dcp->read (false, 0, true);
45                 dcps.push_back (dcp);
46                 BOOST_FOREACH (shared_ptr<dcp::CPL> i, dcp->cpls()) {
47                         cpls.push_back (i);
48                 }
49         }
50
51         BOOST_FOREACH (shared_ptr<dcp::DCP> i, dcps) {
52                 BOOST_FOREACH (shared_ptr<dcp::DCP> j, dcps) {
53                         if (i != j) {
54                                 i->resolve_refs (j->assets (true));
55                         }
56                 }
57         }
58
59         if (_dcp_content->kdm ()) {
60                 BOOST_FOREACH (shared_ptr<dcp::DCP> i, dcps) {
61                         try {
62                                 i->add (dcp::DecryptedKDM (_dcp_content->kdm().get(), Config::instance()->decryption_chain()->key().get ()));
63                         } catch (dcp::KDMDecryptionError& e) {
64                                 /* Flesh out the error a bit */
65                                 string const kdm_subject_name = _dcp_content->kdm()->recipient_x509_subject_name();
66                                 bool on_chain = false;
67                                 shared_ptr<const dcp::CertificateChain> dc = Config::instance()->decryption_chain();
68                                 BOOST_FOREACH (dcp::Certificate i, dc->root_to_leaf()) {
69                                         if (i.subject() == kdm_subject_name) {
70                                                 on_chain = true;
71                                         }
72                                 }
73                                 if (!on_chain) {
74                                         throw KDMError (_("KDM was not made for DCP-o-matic's decryption certificate."), e.what());
75                                 } else if (on_chain && kdm_subject_name != dc->leaf().subject()) {
76                                         throw KDMError (_("KDM was made for DCP-o-matic but not for its leaf certificate."), e.what());
77                                 }
78                         }
79                 }
80         }
81
82         return cpls;
83 }