rushlink/internal/handlers/handlers.go

396 lines
10 KiB
Go
Raw Normal View History

package handlers
2019-08-25 21:33:56 +02:00
//go:generate go get github.com/go-bindata/go-bindata
//go:generate go get -u github.com/go-bindata/go-bindata/...
//go:generate go-bindata -pkg $GOPACKAGE -prefix ../../assets ../../assets/...
2019-08-25 21:33:56 +02:00
import (
2019-09-01 12:04:43 +02:00
"bytes"
2019-08-25 21:33:56 +02:00
"crypto/rand"
2019-09-01 01:41:01 +02:00
"crypto/subtle"
"encoding/base64"
2019-08-25 21:33:56 +02:00
"fmt"
"io"
"log"
"net/http"
"net/url"
2019-09-01 01:41:01 +02:00
"strings"
2019-09-06 00:07:50 +02:00
"text/template"
2019-08-25 21:33:56 +02:00
"time"
2019-09-01 01:41:01 +02:00
"unicode"
2019-08-25 21:33:56 +02:00
2019-08-29 23:40:24 +02:00
"github.com/gorilla/mux"
"github.com/pkg/errors"
2019-08-25 21:33:56 +02:00
bolt "go.etcd.io/bbolt"
"gitea.hashru.nl/dsprenkels/rushlink/internal/db"
"gitea.hashru.nl/dsprenkels/rushlink/pkg/gobmarsh"
2019-08-25 21:33:56 +02:00
)
type PasteType int
type PasteState int
2019-08-25 21:33:56 +02:00
type StoredPaste struct {
Type PasteType
State PasteState
Content []byte
2019-08-29 00:50:26 +02:00
Key []byte
2019-09-01 01:41:01 +02:00
OwnerToken [16]byte
2019-08-25 21:33:56 +02:00
TimeCreated time.Time
}
const (
TypePaste PasteType = iota
TypeRedirect
)
const (
StatePresent PasteState = iota
StateDeleted
2019-08-25 21:33:56 +02:00
)
2019-09-01 01:41:01 +02:00
const CookieOwnerToken = "owner_token"
2019-09-01 12:04:43 +02:00
// These keys are designated reserved, and will not be randomly chosen
var ReservedPasteKeys [][]byte = [][]byte{[]byte("xd42"), []byte("example")}
2019-09-01 01:41:01 +02:00
// Base64 encoding and decoding
var base64Alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_"
var base64Encoder = base64.RawURLEncoding.WithPadding(base64.NoPadding)
2019-09-01 01:41:01 +02:00
// Page contents
2019-09-06 00:07:50 +02:00
var baseTemplate = template.New("empty")
var indexTemplate = template.Must(baseTemplate.Parse(string(MustAsset("text/index.txt"))))
2019-08-25 21:33:56 +02:00
2019-09-01 01:41:01 +02:00
func (t PasteType) String() (string, error) {
switch t {
case TypePaste:
return "paste", nil
case TypeRedirect:
return "redirect", nil
default:
return "", fmt.Errorf("invalid PasteType (%v)", t)
}
}
func (t PasteState) String() (string, error) {
switch t {
case StatePresent:
return "present", nil
case StateDeleted:
return "deleted", nil
default:
return "", fmt.Errorf("invalid PasteState (%v)", t)
}
}
func IndexGetHandler(w http.ResponseWriter, r *http.Request) {
2019-09-06 00:07:50 +02:00
if err := indexTemplate.Execute(w, nil); err != nil {
panic(err)
}
2019-08-25 21:33:56 +02:00
}
func IndexPostHandler(w http.ResponseWriter, r *http.Request) {
2019-08-25 21:33:56 +02:00
if err := r.ParseMultipartForm(50 * 1000 * 1000); err != nil {
w.WriteHeader(http.StatusInternalServerError)
fmt.Fprintf(w, "Internal server error: %v\n", err)
2019-08-25 21:33:56 +02:00
return
}
// Determine what kind of post this is, currently only `shorten=...`
if len(r.PostForm) == 0 {
w.WriteHeader(http.StatusBadRequest)
var buf []byte
r.Body.Read(buf)
io.WriteString(w, "empty body in POST request\n")
2019-08-25 21:33:56 +02:00
return
}
shorten_values, prs := r.PostForm["shorten"]
if !prs {
w.WriteHeader(http.StatusBadRequest)
io.WriteString(w, "no 'shorten' param supplied\n")
2019-08-25 21:33:56 +02:00
return
}
if len(shorten_values) != 1 {
w.WriteHeader(http.StatusBadRequest)
io.WriteString(w, "only one 'shorten' param is allowed per request\n")
2019-08-25 21:33:56 +02:00
return
}
ShortenPostHandler(w, r)
2019-08-25 21:33:56 +02:00
}
func PasteGetHandler(w http.ResponseWriter, r *http.Request) {
2019-09-01 01:41:01 +02:00
pasteGetHandlerInner(w, r, false, false)
}
func PasteGetHandlerNoRedirect(w http.ResponseWriter, r *http.Request) {
2019-09-01 01:41:01 +02:00
pasteGetHandlerInner(w, r, true, false)
}
func PasteGetHandlerMeta(w http.ResponseWriter, r *http.Request) {
2019-09-01 01:41:01 +02:00
pasteGetHandlerInner(w, r, false, true)
}
func pasteGetHandlerInner(w http.ResponseWriter, r *http.Request, noRedirect, showMeta bool) {
2019-08-29 00:50:26 +02:00
vars := mux.Vars(r)
key := vars["key"]
var storedPaste *StoredPaste
if err := db.DB.View(func(tx *bolt.Tx) error {
2019-08-29 00:50:26 +02:00
var err error
storedPaste, err = getURL(tx, []byte(key))
2019-08-29 00:50:26 +02:00
return err
}); err != nil {
w.WriteHeader(http.StatusInternalServerError)
2019-08-29 00:50:26 +02:00
log.Printf("error: %v\n", err)
fmt.Fprintf(w, "internal server error: %v\n", err)
2019-08-29 00:50:26 +02:00
return
}
if storedPaste == nil {
w.WriteHeader(http.StatusNotFound)
fmt.Fprintf(w, "url key not found in the database\n")
2019-09-01 01:41:01 +02:00
return
}
if showMeta {
typeString, err := storedPaste.Type.String()
if err != nil {
w.WriteHeader(http.StatusInternalServerError)
2019-09-01 01:41:01 +02:00
log.Printf("error: %v\n", err)
fmt.Fprintf(w, "internal server error: %v\n", err)
2019-09-01 01:41:01 +02:00
return
}
stateString, err := storedPaste.State.String()
if err != nil {
w.WriteHeader(http.StatusInternalServerError)
2019-09-01 01:41:01 +02:00
log.Printf("error: %v\n", err)
fmt.Fprintf(w, "internal server error: %v\n", err)
2019-09-01 01:41:01 +02:00
return
}
isOwner := "no"
ownerToken, ok := getOwnerTokenFromRequest(r)
if ok && subtle.ConstantTimeCompare(ownerToken[:], storedPaste.OwnerToken[:]) == 1 {
isOwner = "yes"
}
w.WriteHeader(http.StatusOK)
fmt.Fprintf(w, "key: %v\n", string(storedPaste.Key))
fmt.Fprintf(w, "type: %v\n", typeString)
fmt.Fprintf(w, "state: %v\n", stateString)
fmt.Fprintf(w, "created: %v\n", storedPaste.TimeCreated.String())
fmt.Fprintf(w, "are you the owner: %v\n", isOwner)
return
2019-08-29 00:50:26 +02:00
}
2019-09-01 01:41:01 +02:00
switch storedPaste.State {
case StatePresent:
if !noRedirect {
rawurl := string(storedPaste.Content)
urlParse, err := url.Parse(rawurl)
if err != nil {
w.WriteHeader(http.StatusInternalServerError)
log.Printf("error: invalid URL ('%v') in database for key '%v': %v\n", rawurl, storedPaste.Key, err)
fmt.Fprintf(w, "internal server error: invalid url in database\n")
return
}
http.Redirect(w, r, urlParse.String(), http.StatusSeeOther)
}
w.Write(storedPaste.Content)
case StateDeleted:
w.WriteHeader(http.StatusGone)
fmt.Fprintf(w, "key has been deleted\n")
2019-08-29 00:50:26 +02:00
default:
w.WriteHeader(http.StatusInternalServerError)
log.Printf("error: invalid storedPaste.State (%v) for key '%v'\n", storedPaste.State, storedPaste.Key)
fmt.Fprintf(w, "internal server error: invalid storedPaste.State (%v\n)", storedPaste.State)
2019-08-29 00:50:26 +02:00
}
}
func ShortenPostHandler(w http.ResponseWriter, r *http.Request) {
2019-08-25 21:33:56 +02:00
rawurl := r.PostForm.Get("shorten")
userURL, err := url.ParseRequestURI(rawurl)
if err != nil {
w.WriteHeader(http.StatusBadRequest)
fmt.Fprintf(w, "invalid url (%v): %v\n", err, rawurl)
2019-08-25 21:33:56 +02:00
return
}
if userURL.Scheme == "" {
w.WriteHeader(http.StatusBadRequest)
fmt.Fprintf(w, "invalid url (unspecified scheme)\n", rawurl)
2019-08-25 21:33:56 +02:00
return
}
if userURL.Host == "" {
w.WriteHeader(http.StatusBadRequest)
fmt.Fprintf(w, "invalid url (unspecified host)\n", rawurl)
2019-08-25 21:33:56 +02:00
return
}
var storedPaste *StoredPaste
if err := db.DB.Update(func(tx *bolt.Tx) error {
2019-09-01 01:41:01 +02:00
ownerKey, ok := getOwnerTokenFromRequest(r)
if ok == false {
// Owner key not supplied or invalid, generate a new one
ownerKey, err = generateOwnerToken()
if err != nil {
return errors.Wrap(err, "generating OwnerToken")
}
}
sp, err := shortenURL(tx, userURL, ownerKey)
storedPaste = sp
2019-08-25 21:33:56 +02:00
return err
}); err != nil {
w.WriteHeader(http.StatusInternalServerError)
2019-08-29 00:50:26 +02:00
log.Printf("error: %v\n", err)
fmt.Fprintf(w, "internal server error: %v\n", err)
2019-08-25 21:33:56 +02:00
return
}
2019-09-01 01:41:01 +02:00
saveURL, err := r.URL.Parse(string(storedPaste.Key))
if err != nil {
2019-09-06 00:07:50 +02:00
err = errors.Wrap(err, "parsing url")
log.Printf("error: %v\n", err)
fmt.Fprintf(w, "internal server error: %v\n", err)
return
2019-09-01 01:41:01 +02:00
}
var base64OwnerToken = make([]byte, 24)
base64Encoder.Encode(base64OwnerToken, storedPaste.OwnerToken[:])
w.WriteHeader(http.StatusOK)
fmt.Fprintf(w, "URL saved at %v\n", saveURL)
2019-09-01 01:41:01 +02:00
isNotPrint := func(r rune) bool { return !unicode.IsPrint(r) }
fmt.Fprintf(w, "Owner key is %s\n", strings.TrimRightFunc(string(base64OwnerToken), isNotPrint))
2019-08-29 00:50:26 +02:00
}
// Retrieve a URL from the database
func getURL(tx *bolt.Tx, key []byte) (*StoredPaste, error) {
shortenBucket := tx.Bucket([]byte(db.BUCKET_PASTES))
2019-08-29 00:50:26 +02:00
if shortenBucket == nil {
return nil, fmt.Errorf("bucket %v does not exist", db.BUCKET_PASTES)
2019-08-29 00:50:26 +02:00
}
storedBytes := shortenBucket.Get(key)
if storedBytes == nil {
return nil, nil
}
storedPaste := &StoredPaste{}
err := gobmarsh.Unmarshal(storedBytes, storedPaste)
return storedPaste, err
2019-08-25 21:33:56 +02:00
}
// Add a new URL to the database
//
// Returns the new ID if the url was successfully shortened
2019-09-01 01:41:01 +02:00
func shortenURL(tx *bolt.Tx, userURL *url.URL, ownerKey [16]byte) (*StoredPaste, error) {
shortenBucket := tx.Bucket([]byte(db.BUCKET_PASTES))
2019-08-25 21:33:56 +02:00
if shortenBucket == nil {
return nil, fmt.Errorf("bucket %v does not exist", db.BUCKET_PASTES)
2019-08-25 21:33:56 +02:00
}
// Generate a key until it is not in the database, this occurs in O(log N),
// where N is the amount of keys stored in the url-shorten database.
epoch := 0
var urlKey []byte
for {
var err error
urlKey, err = generateURLKey(epoch)
if err != nil {
return nil, errors.Wrap(err, "url-key generation failed")
}
2019-09-01 12:04:43 +02:00
2019-08-25 21:33:56 +02:00
found := shortenBucket.Get(urlKey)
if found == nil {
break
}
2019-09-01 12:04:43 +02:00
isReserved := false
for _, reservedKey := range ReservedPasteKeys {
if bytes.HasPrefix(urlKey, reservedKey) {
isReserved = true
break
}
}
if !isReserved {
break
}
2019-08-25 21:33:56 +02:00
epoch++
}
// Store the new key
storedPaste := StoredPaste{
Type: TypeRedirect,
State: StatePresent,
Content: []byte(userURL.String()),
2019-08-29 00:50:26 +02:00
Key: urlKey,
2019-09-01 01:41:01 +02:00
OwnerToken: ownerKey,
2019-08-25 21:33:56 +02:00
TimeCreated: time.Now().UTC(),
}
storedBytes, err := gobmarsh.Marshal(storedPaste)
2019-08-25 21:33:56 +02:00
if err != nil {
return nil, errors.Wrap(err, "encoding for database failed")
}
if err := shortenBucket.Put(urlKey, storedBytes); err != nil {
return nil, errors.Wrap(err, "database transaction failed")
}
return &storedPaste, nil
2019-08-25 21:33:56 +02:00
}
func generateURLKey(epoch int) ([]byte, error) {
urlKey := make([]byte, 4+epoch)
_, err := rand.Read(urlKey)
if err != nil {
return nil, err
}
// Put all the values in the range 0..64 for easier base64-encoding
for i := 0; i < len(urlKey); i++ {
urlKey[i] &= 0x3F
}
// Implement truncate-resistance by forcing the prefix to
// 0b111110xxxxxxxxxx
// ^----- {epoch} ones followed by a single 0
//
// Example when epoch is 1: prefix is 0b10.
i := 0
for i < epoch {
// Set this bit to 1
limb := i / 6
bit := i % 6
urlKey[limb] |= 1 << uint(5-bit)
i++
}
// Finally set the next bit to 0
limb := i / 6
bit := i % 6
urlKey[limb] &= ^(1 << uint(5-bit))
// Convert this ID to a canonical base64 notation
2019-08-29 00:50:26 +02:00
for i := range urlKey {
urlKey[i] = base64Alphabet[urlKey[i]]
}
2019-08-25 21:33:56 +02:00
return urlKey, nil
}
2019-09-01 01:41:01 +02:00
func generateOwnerToken() ([16]byte, error) {
var ownerKey [16]byte
_, err := rand.Read(ownerKey[:])
if err != nil {
return ownerKey, err
}
return ownerKey, nil
}
func getOwnerTokenFromRequest(r *http.Request) ([16]byte, bool) {
var ownerKey [16]byte
ownerKeyCookie, err := r.Cookie(CookieOwnerToken)
if err != nil && err != http.ErrNoCookie {
return ownerKey, false
}
if ownerKeyCookie != nil {
n, err := base64Encoder.Strict().Decode(ownerKey[:], []byte(ownerKeyCookie.Value))
if err == nil || n == 16 {
return ownerKey, true
}
}
return ownerKey, false
}