Compare commits
	
		
			24 Commits
		
	
	
		
			d583db5450
			...
			v0.3.12
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| c6eb147e2c | |||
| 150ffc3400 | |||
| ee761d4006 | |||
| 8ae5ee64bb | |||
| 5e186b28ce | |||
| 26c9fb5bfd | |||
| f78c68d46c | |||
| 030806b0c4 | |||
| e7b0c5fa33 | |||
| 763d691b6c | |||
| 46401c1b98 | |||
| b559d28a38 | |||
| bde2a38931 | |||
| 1a3ebcb1df | |||
| 17a484db91 | |||
| 889894a737 | |||
| 0e76cad5d7 | |||
| f664c886eb | |||
| 121b0396fa | |||
| 6822cd6bfe | |||
| db41f565ca | |||
| 20cb97f90f | |||
| ed4a10c966 | |||
| ff8c6aca64 | 
							
								
								
									
										35
									
								
								.golangci.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										35
									
								
								.golangci.yml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,35 @@
 | 
			
		||||
run:
 | 
			
		||||
  tests: false
 | 
			
		||||
linters:
 | 
			
		||||
  enable:
 | 
			
		||||
    - deadcode
 | 
			
		||||
    - errcheck
 | 
			
		||||
    - gosimple
 | 
			
		||||
    - govet
 | 
			
		||||
    - ineffassign
 | 
			
		||||
    - staticcheck
 | 
			
		||||
    - structcheck
 | 
			
		||||
    - typecheck
 | 
			
		||||
    - unused
 | 
			
		||||
    - varcheck
 | 
			
		||||
    - gosec
 | 
			
		||||
    - asciicheck
 | 
			
		||||
    - bidichk
 | 
			
		||||
    - bodyclose
 | 
			
		||||
    - gomnd
 | 
			
		||||
    - ifshort
 | 
			
		||||
    - misspell
 | 
			
		||||
    - prealloc
 | 
			
		||||
    - tagliatelle
 | 
			
		||||
    - ireturn
 | 
			
		||||
    - gocritic
 | 
			
		||||
    - whitespace
 | 
			
		||||
    - wsl
 | 
			
		||||
    - stylecheck
 | 
			
		||||
    - exportloopref
 | 
			
		||||
    - godot
 | 
			
		||||
 | 
			
		||||
linters-settings:
 | 
			
		||||
  gomnd:
 | 
			
		||||
    ignored-functions:
 | 
			
		||||
      - "strconv.ParseUint"
 | 
			
		||||
@@ -6,6 +6,7 @@ before:
 | 
			
		||||
    - go mod tidy
 | 
			
		||||
    # you may remove this if you don't need go generate
 | 
			
		||||
    - go generate ./...
 | 
			
		||||
 | 
			
		||||
builds:
 | 
			
		||||
  - id: "gpaste-client"
 | 
			
		||||
    binary: "gpaste"
 | 
			
		||||
@@ -28,22 +29,42 @@ builds:
 | 
			
		||||
    goarch:
 | 
			
		||||
      - amd64
 | 
			
		||||
    main: ./cmd/server/server.go
 | 
			
		||||
 | 
			
		||||
archives:
 | 
			
		||||
  - format_overrides:
 | 
			
		||||
      - goos: windows
 | 
			
		||||
        format: zip
 | 
			
		||||
 | 
			
		||||
checksum:
 | 
			
		||||
  name_template: 'checksums.txt'
 | 
			
		||||
 | 
			
		||||
snapshot:
 | 
			
		||||
  name_template: "{{ incpatch .Version }}-next"
 | 
			
		||||
 | 
			
		||||
changelog:
 | 
			
		||||
  sort: asc
 | 
			
		||||
  filters:
 | 
			
		||||
    exclude:
 | 
			
		||||
      - '^docs:'
 | 
			
		||||
      - '^test:'
 | 
			
		||||
 | 
			
		||||
scoop:
 | 
			
		||||
  url_template: "https://git.t-juice.club/torjus/gpaste/releases/download/{{ .Tag }}/{{ .ArtifactName }}"
 | 
			
		||||
  bucket:
 | 
			
		||||
    owner: torjus
 | 
			
		||||
    name: scoop-tjuice
 | 
			
		||||
    branch: master
 | 
			
		||||
  folder: bucket
 | 
			
		||||
  commit_author:
 | 
			
		||||
    name: ci.t-juice.club
 | 
			
		||||
    email: ci@t-juice.club
 | 
			
		||||
  commit_msg_template: "Scoop update for {{ .ProjectName }} version {{ .Tag }}"
 | 
			
		||||
  homepage: "https://git.t-juice.club/torjus/gpaste"
 | 
			
		||||
  description: "Simple pastebin-style thingie."
 | 
			
		||||
 | 
			
		||||
gitea_urls:
 | 
			
		||||
  api: https://git.t-juice.club/api/v1/
 | 
			
		||||
  download: https://git.t-juice.club
 | 
			
		||||
 | 
			
		||||
env_files:
 | 
			
		||||
  gitea_token: gitea_token
 | 
			
		||||
 
 | 
			
		||||
@@ -4,12 +4,19 @@ pipeline:
 | 
			
		||||
    commands:
 | 
			
		||||
      - go build -o gpaste-client ./cmd/client/client.go
 | 
			
		||||
      - go build -o gpaste-server ./cmd/server/server.go
 | 
			
		||||
      - go test -v ./...
 | 
			
		||||
      - go test -cover ./...
 | 
			
		||||
      - go vet ./...
 | 
			
		||||
    when:
 | 
			
		||||
      branch: master
 | 
			
		||||
      event: [push, pull_request, tag, deployment]
 | 
			
		||||
 | 
			
		||||
  lint:
 | 
			
		||||
    image: golangci/golangci-lint:v1.43.0
 | 
			
		||||
    commands:
 | 
			
		||||
      - golangci-lint run
 | 
			
		||||
    when:
 | 
			
		||||
      event: [push, pull_request]
 | 
			
		||||
 | 
			
		||||
  image-latest:
 | 
			
		||||
    image: plugins/docker
 | 
			
		||||
    settings:
 | 
			
		||||
 
 | 
			
		||||
@@ -10,4 +10,5 @@ RUN go build -o gpaste-server ./cmd/server/server.go
 | 
			
		||||
FROM alpine:latest
 | 
			
		||||
COPY --from=builder /src/gpaste /bin/gpaste
 | 
			
		||||
COPY --from=builder /src/gpaste-server /bin/gpaste-server
 | 
			
		||||
EXPOSE 8080
 | 
			
		||||
CMD ["/bin/gpaste-server"]
 | 
			
		||||
							
								
								
									
										35
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										35
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,35 @@
 | 
			
		||||

 | 
			
		||||
 | 
			
		||||
# gpaste
 | 
			
		||||
 | 
			
		||||
Simple pastebin-style webapp.
 | 
			
		||||
 | 
			
		||||
## Build
 | 
			
		||||
 | 
			
		||||
### gpaste-server
 | 
			
		||||
 | 
			
		||||
```text
 | 
			
		||||
go build -o gpaste-server cmd/server/server.go
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
### gpaste-client
 | 
			
		||||
 | 
			
		||||
```text
 | 
			
		||||
go build -o gpaste cmd/client/client.go
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
## Run using docker
 | 
			
		||||
 | 
			
		||||
### From registry
 | 
			
		||||
 | 
			
		||||
```text
 | 
			
		||||
docker pull registry.t-juice.club/gpaste:latest
 | 
			
		||||
docker run --rm -it -p 8080:8080 registry.t-juice.club/gpaste:latest
 | 
			
		||||
```
 | 
			
		||||
 | 
			
		||||
### From Dockerfile
 | 
			
		||||
 | 
			
		||||
```text
 | 
			
		||||
docker build -t gpaste:latest .
 | 
			
		||||
docker run --rm -it p 8080:8080 gpaste:latest
 | 
			
		||||
```
 | 
			
		||||
							
								
								
									
										143
									
								
								api/http.go
									
									
									
									
									
								
							
							
						
						
									
										143
									
								
								api/http.go
									
									
									
									
									
								
							@@ -4,7 +4,10 @@ import (
 | 
			
		||||
	"encoding/json"
 | 
			
		||||
	"io"
 | 
			
		||||
	"net/http"
 | 
			
		||||
	"path"
 | 
			
		||||
	"strconv"
 | 
			
		||||
	"strings"
 | 
			
		||||
	"time"
 | 
			
		||||
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/files"
 | 
			
		||||
@@ -15,6 +18,8 @@ import (
 | 
			
		||||
	"go.uber.org/zap"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
const multipartMaxMemory = 1024 * 1024 * 100
 | 
			
		||||
 | 
			
		||||
type HTTPServer struct {
 | 
			
		||||
	Files        files.FileStore
 | 
			
		||||
	Users        users.UserStore
 | 
			
		||||
@@ -30,16 +35,11 @@ func NewHTTPServer(cfg *gpaste.ServerConfig) *HTTPServer {
 | 
			
		||||
		config:       cfg,
 | 
			
		||||
		Logger:       zap.NewNop().Sugar(),
 | 
			
		||||
		AccessLogger: zap.NewNop().Sugar(),
 | 
			
		||||
		Files:        files.NewMemoryFileStore(),
 | 
			
		||||
		Users:        users.NewMemoryUserStore(),
 | 
			
		||||
	}
 | 
			
		||||
	srv.Files = files.NewMemoryFileStore()
 | 
			
		||||
	srv.Users = users.NewMemoryUserStore()
 | 
			
		||||
	srv.Auth = gpaste.NewAuthService(srv.Users, []byte(srv.config.SigningSecret))
 | 
			
		||||
 | 
			
		||||
	// Create initial user
 | 
			
		||||
	// TODO: Do properly
 | 
			
		||||
	user := &users.User{Username: "admin", Role: users.RoleAdmin}
 | 
			
		||||
	user.SetPassword("admin")
 | 
			
		||||
	srv.Users.Store(user)
 | 
			
		||||
	signingSecret, _ := uuid.Must(uuid.NewRandom()).MarshalBinary()
 | 
			
		||||
	srv.Auth = gpaste.NewAuthService(srv.Users, signingSecret)
 | 
			
		||||
 | 
			
		||||
	r := chi.NewRouter()
 | 
			
		||||
	r.Use(middleware.RealIP)
 | 
			
		||||
@@ -49,6 +49,7 @@ func NewHTTPServer(cfg *gpaste.ServerConfig) *HTTPServer {
 | 
			
		||||
	r.Get("/", srv.HandlerIndex)
 | 
			
		||||
	r.Post("/api/file", srv.HandlerAPIFilePost)
 | 
			
		||||
	r.Get("/api/file/{id}", srv.HandlerAPIFileGet)
 | 
			
		||||
	r.Delete("/api/file/{id}", srv.HandlerAPIFileDelete)
 | 
			
		||||
	r.Post("/api/login", srv.HandlerAPILogin)
 | 
			
		||||
	r.Post("/api/user", srv.HandlerAPIUserCreate)
 | 
			
		||||
	srv.Handler = r
 | 
			
		||||
@@ -61,10 +62,6 @@ func (s *HTTPServer) HandlerIndex(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) HandlerAPIFilePost(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	f := &files.File{
 | 
			
		||||
		ID:   uuid.Must(uuid.NewRandom()).String(),
 | 
			
		||||
		Body: r.Body,
 | 
			
		||||
	}
 | 
			
		||||
	reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
	// Check if multipart form
 | 
			
		||||
@@ -73,23 +70,34 @@ func (s *HTTPServer) HandlerAPIFilePost(w http.ResponseWriter, r *http.Request)
 | 
			
		||||
		s.processMultiPartFormUpload(w, r)
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	f := fileFromParams(r)
 | 
			
		||||
	f.ID = uuid.NewString()
 | 
			
		||||
	f.Body = r.Body
 | 
			
		||||
 | 
			
		||||
	err := s.Files.Store(f)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		w.WriteHeader(http.StatusInternalServerError)
 | 
			
		||||
		s.Logger.Warnw("Error storing file.", "req_id", reqID, "error", err, "id", f.ID, "remote_addr", r.RemoteAddr)
 | 
			
		||||
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	s.Logger.Infow("Stored file.", "req_id", reqID, "id", f.ID, "remote_addr", r.RemoteAddr)
 | 
			
		||||
	var resp = struct {
 | 
			
		||||
		Message string `json:"message"`
 | 
			
		||||
		ID      string `json:"id"`
 | 
			
		||||
		URL     string `json:"url"`
 | 
			
		||||
	}{
 | 
			
		||||
 | 
			
		||||
	fileURL := path.Join(s.config.URL, "/api/file", f.ID)
 | 
			
		||||
	resp := &ResponseAPIFilePost{
 | 
			
		||||
		Message: "OK",
 | 
			
		||||
		Files: []ResponseAPIFilePostFiles{
 | 
			
		||||
			{
 | 
			
		||||
				ID:  f.ID,
 | 
			
		||||
		URL:     "TODO",
 | 
			
		||||
				URL: fileURL,
 | 
			
		||||
			},
 | 
			
		||||
		},
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	w.WriteHeader(http.StatusAccepted)
 | 
			
		||||
 | 
			
		||||
	encoder := json.NewEncoder(w)
 | 
			
		||||
	if err := encoder.Encode(&resp); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error encoding response to client.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
@@ -111,55 +119,81 @@ func (s *HTTPServer) HandlerAPIFileGet(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	w.WriteHeader(http.StatusOK)
 | 
			
		||||
 | 
			
		||||
	if _, err := io.Copy(w, f.Body); err != nil {
 | 
			
		||||
		reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
		s.Logger.Warnw("Error writing file to client.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) HandlerAPIFileDelete(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	// TODO: Require auth
 | 
			
		||||
	id := chi.URLParam(r, "id")
 | 
			
		||||
	if id == "" {
 | 
			
		||||
		w.WriteHeader(http.StatusBadRequest)
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if err := s.Files.Delete(id); err != nil {
 | 
			
		||||
		w.WriteHeader(http.StatusBadRequest)
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
	s.Logger.Infow("Deleted file", "id", id, "req_id", reqID)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) processMultiPartFormUpload(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
	var responses []ResponseAPIFilePost
 | 
			
		||||
	var resp ResponseAPIFilePost
 | 
			
		||||
 | 
			
		||||
	if err := r.ParseMultipartForm(1024 * 1024 * 10); err != nil {
 | 
			
		||||
	if err := r.ParseMultipartForm(multipartMaxMemory); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error parsing multipart form.", "req_id", reqID, "err", err)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	for k := range r.MultipartForm.File {
 | 
			
		||||
		ff, fh, err := r.FormFile(k)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			s.Logger.Warnw("Error reading file from multipart form.", "req_id", reqID, "error", err)
 | 
			
		||||
			return
 | 
			
		||||
		}
 | 
			
		||||
		f := &files.File{
 | 
			
		||||
			ID:               uuid.Must(uuid.NewRandom()).String(),
 | 
			
		||||
			OriginalFilename: fh.Filename,
 | 
			
		||||
			Body:             ff,
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		f := fileFromParams(r)
 | 
			
		||||
		f.ID = uuid.NewString()
 | 
			
		||||
		f.OriginalFilename = fh.Filename
 | 
			
		||||
		f.Body = ff
 | 
			
		||||
 | 
			
		||||
		if err := s.Files.Store(f); err != nil {
 | 
			
		||||
			w.WriteHeader(http.StatusInternalServerError)
 | 
			
		||||
			s.Logger.Warnw("Error storing file.", "req_id", reqID, "error", err, "id", f.ID, "remote_addr", r.RemoteAddr)
 | 
			
		||||
 | 
			
		||||
			return
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		s.Logger.Infow("Stored file.", "req_id", reqID, "id", f.ID, "filename", f.OriginalFilename, "remote_addr", r.RemoteAddr)
 | 
			
		||||
 | 
			
		||||
		responses = append(responses, ResponseAPIFilePost{Message: "OK", ID: f.ID, URL: "TODO"})
 | 
			
		||||
 | 
			
		||||
		fileURL := path.Join(s.config.URL, "/api/file", f.ID)
 | 
			
		||||
		fileResponse := ResponseAPIFilePostFiles{ID: f.ID, URL: fileURL}
 | 
			
		||||
		resp.Files = append(resp.Files, fileResponse)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	w.WriteHeader(http.StatusAccepted)
 | 
			
		||||
	encoder := json.NewEncoder(w)
 | 
			
		||||
	if err := encoder.Encode(&responses); err != nil {
 | 
			
		||||
 | 
			
		||||
	if err := encoder.Encode(&resp); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error encoding response to client.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) HandlerAPILogin(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
	var expectedRequest RequestAPILogin
 | 
			
		||||
 | 
			
		||||
	decoder := json.NewDecoder(r.Body)
 | 
			
		||||
	defer r.Body.Close()
 | 
			
		||||
 | 
			
		||||
	if err := decoder.Decode(&expectedRequest); err != nil {
 | 
			
		||||
		w.WriteHeader(http.StatusBadRequest)
 | 
			
		||||
		return
 | 
			
		||||
@@ -194,26 +228,75 @@ func (s *HTTPServer) HandlerAPIUserCreate(w http.ResponseWriter, r *http.Request
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	var req RequestAPIUserCreate
 | 
			
		||||
 | 
			
		||||
	decoder := json.NewDecoder(r.Body)
 | 
			
		||||
	if err := decoder.Decode(&req); err != nil {
 | 
			
		||||
		s.Logger.Debugw("Error parsing request.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
		w.WriteHeader(http.StatusBadRequest)
 | 
			
		||||
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	// TODO: Ensure user does not already exist
 | 
			
		||||
	user := &users.User{Username: req.Username}
 | 
			
		||||
	user := &users.User{Username: req.Username, Role: users.RoleUser}
 | 
			
		||||
	if err := user.SetPassword(req.Password); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error setting user password.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
		w.WriteHeader(http.StatusBadRequest)
 | 
			
		||||
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if err := s.Users.Store(user); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error setting user password.", "req_id", reqID, "error", err, "remote_addr", r.RemoteAddr)
 | 
			
		||||
		w.WriteHeader(http.StatusInternalServerError)
 | 
			
		||||
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	w.WriteHeader(http.StatusAccepted)
 | 
			
		||||
	s.Logger.Infow("Created user.", "req_id", reqID, "remote_addr", r.RemoteAddr, "username", req.Username)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) HandlerAPIUserList(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
	reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
	l, err := s.Users.List()
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error listing users.", "req_id", reqID, "error", err)
 | 
			
		||||
		w.WriteHeader(http.StatusInternalServerError)
 | 
			
		||||
 | 
			
		||||
		return
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	encoder := json.NewEncoder(w)
 | 
			
		||||
	if err := encoder.Encode(l); err != nil {
 | 
			
		||||
		s.Logger.Warnw("Error encoding response.", "req_id", "error", err)
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func fileFromParams(r *http.Request) *files.File {
 | 
			
		||||
	const (
 | 
			
		||||
		keyMaxViews  = "max_views"
 | 
			
		||||
		keyExpiresOn = "exp"
 | 
			
		||||
	)
 | 
			
		||||
 | 
			
		||||
	var f files.File
 | 
			
		||||
 | 
			
		||||
	q := r.URL.Query()
 | 
			
		||||
 | 
			
		||||
	if q.Has(keyMaxViews) {
 | 
			
		||||
		views, err := strconv.ParseUint(q.Get(keyMaxViews), 10, 64) // nolint: gomnd
 | 
			
		||||
		if err == nil {
 | 
			
		||||
			f.MaxViews = uint(views)
 | 
			
		||||
		}
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if q.Has(keyExpiresOn) {
 | 
			
		||||
		exp, err := time.Parse(time.RFC3339, q.Get(keyExpiresOn))
 | 
			
		||||
		if err == nil {
 | 
			
		||||
			f.ExpiresOn = exp
 | 
			
		||||
		}
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return &f
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										180
									
								
								api/http_test.go
									
									
									
									
									
								
							
							
						
						
									
										180
									
								
								api/http_test.go
									
									
									
									
									
								
							@@ -8,24 +8,30 @@ import (
 | 
			
		||||
	"mime/multipart"
 | 
			
		||||
	"net/http"
 | 
			
		||||
	"net/http/httptest"
 | 
			
		||||
	"strings"
 | 
			
		||||
	"testing"
 | 
			
		||||
	"time"
 | 
			
		||||
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/api"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/files"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/users"
 | 
			
		||||
	"github.com/google/go-cmp/cmp"
 | 
			
		||||
	"github.com/google/uuid"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
func TestHandlers(t *testing.T) {
 | 
			
		||||
	cfg := &gpaste.ServerConfig{
 | 
			
		||||
		SigningSecret: "abc123",
 | 
			
		||||
		Store: &gpaste.ServerStoreConfig{
 | 
			
		||||
			Type: "memory",
 | 
			
		||||
		},
 | 
			
		||||
		URL: "http://localhost:8080",
 | 
			
		||||
	}
 | 
			
		||||
	hs := api.NewHTTPServer(cfg)
 | 
			
		||||
	//cfg := &gpaste.ServerConfig{
 | 
			
		||||
	//	SigningSecret: "abc123",
 | 
			
		||||
	//	Store: &gpaste.ServerStoreConfig{
 | 
			
		||||
	//		Type: "memory",
 | 
			
		||||
	//	},
 | 
			
		||||
	//	URL: "http://localhost:8080",
 | 
			
		||||
	//}
 | 
			
		||||
	//hs := api.NewHTTPServer(cfg)
 | 
			
		||||
 | 
			
		||||
	t.Run("HandlerIndex", func(t *testing.T) {
 | 
			
		||||
	t.Run("index", func(t *testing.T) {
 | 
			
		||||
		hs := newServer()
 | 
			
		||||
		rr := httptest.NewRecorder()
 | 
			
		||||
		req := httptest.NewRequest(http.MethodGet, "/", nil)
 | 
			
		||||
 | 
			
		||||
@@ -40,7 +46,11 @@ func TestHandlers(t *testing.T) {
 | 
			
		||||
			t.Errorf("Body does not match expected. Got %s want %s", body, expectedBody)
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
	t.Run("HandlerAPIFilePost", func(t *testing.T) {
 | 
			
		||||
	t.Run("api", func(t *testing.T) {
 | 
			
		||||
		t.Run("file", func(t *testing.T) {
 | 
			
		||||
			// POST /api/file
 | 
			
		||||
			t.Run("POST", func(t *testing.T) {
 | 
			
		||||
				hs := newServer()
 | 
			
		||||
				rr := httptest.NewRecorder()
 | 
			
		||||
				buf := &bytes.Buffer{}
 | 
			
		||||
				mw := multipart.NewWriter(buf)
 | 
			
		||||
@@ -54,7 +64,7 @@ func TestHandlers(t *testing.T) {
 | 
			
		||||
				}
 | 
			
		||||
				mw.Close()
 | 
			
		||||
 | 
			
		||||
		req := httptest.NewRequest(http.MethodPost, "/api/file", buf)
 | 
			
		||||
				req := httptest.NewRequest(http.MethodPost, "/api/file?max_views=99", buf)
 | 
			
		||||
				req.Header.Add("Content-Type", mw.FormDataContentType())
 | 
			
		||||
 | 
			
		||||
				hs.Handler.ServeHTTP(rr, req)
 | 
			
		||||
@@ -63,29 +73,52 @@ func TestHandlers(t *testing.T) {
 | 
			
		||||
					t.Errorf("Returned unexpected status. Got %d want %d", status, http.StatusAccepted)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
		var expectedResp []struct {
 | 
			
		||||
			Message string `json:"message"`
 | 
			
		||||
			ID      string `json:"id"`
 | 
			
		||||
			URL     string `json:"url"`
 | 
			
		||||
		}
 | 
			
		||||
				var expectedResp api.ResponseAPIFilePost
 | 
			
		||||
 | 
			
		||||
				decoder := json.NewDecoder(rr.Result().Body)
 | 
			
		||||
				if err := decoder.Decode(&expectedResp); err != nil {
 | 
			
		||||
					t.Fatalf("error decoding response: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
		if l := len(expectedResp); l != 1 {
 | 
			
		||||
				if l := len(expectedResp.Files); l != 1 {
 | 
			
		||||
					t.Errorf("Response has wrong length. Got %d want %d", l, 1)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
		uploadID := expectedResp[0].ID
 | 
			
		||||
				uploadID := expectedResp.Files[0].ID
 | 
			
		||||
				if uploadID == "" {
 | 
			
		||||
					t.Errorf("Response has empty id")
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
		t.Run("HandlerAPIFileGet", func(t *testing.T) {
 | 
			
		||||
				retrieved, err := hs.Files.Get(uploadID)
 | 
			
		||||
				if err != nil {
 | 
			
		||||
					t.Errorf("Error retrieving file: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
				defer retrieved.Body.Close()
 | 
			
		||||
				retBuf := new(bytes.Buffer)
 | 
			
		||||
				io.Copy(retBuf, retrieved.Body)
 | 
			
		||||
				if diff := cmp.Diff(retBuf.String(), expectedData); diff != "" {
 | 
			
		||||
					t.Errorf("Retrieved file mismatch: %s", diff)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				if retrieved.MaxViews != 99 {
 | 
			
		||||
					t.Errorf("Uploaded file has wrong max_views: %d", retrieved.MaxViews)
 | 
			
		||||
				}
 | 
			
		||||
			})
 | 
			
		||||
			// GET /api/file/id
 | 
			
		||||
			t.Run("GET", func(t *testing.T) {
 | 
			
		||||
				hs := newServer()
 | 
			
		||||
				fileData := "abc123456"
 | 
			
		||||
				sr := io.NopCloser(strings.NewReader(fileData))
 | 
			
		||||
				file := &files.File{
 | 
			
		||||
					ID:               uuid.NewString(),
 | 
			
		||||
					OriginalFilename: "test-file.txt",
 | 
			
		||||
					MaxViews:         99,
 | 
			
		||||
					ExpiresOn:        time.Now().Add(90 * time.Second),
 | 
			
		||||
					Body:             sr,
 | 
			
		||||
				}
 | 
			
		||||
				hs.Files.Store(file)
 | 
			
		||||
				rr := httptest.NewRecorder()
 | 
			
		||||
			url := fmt.Sprintf("/api/file/%s", uploadID)
 | 
			
		||||
				url := fmt.Sprintf("/api/file/%s", file.ID)
 | 
			
		||||
				req := httptest.NewRequest(http.MethodGet, url, nil)
 | 
			
		||||
 | 
			
		||||
				hs.Handler.ServeHTTP(rr, req)
 | 
			
		||||
@@ -94,12 +127,100 @@ func TestHandlers(t *testing.T) {
 | 
			
		||||
					t.Errorf("Returned unexpected status. Got %d want %d", status, http.StatusAccepted)
 | 
			
		||||
					t.Logf(url)
 | 
			
		||||
				}
 | 
			
		||||
			if body := rr.Body.String(); body != expectedData {
 | 
			
		||||
				t.Errorf("Returned body does not match expected.")
 | 
			
		||||
				if diff := cmp.Diff(rr.Body.String(), fileData); diff != "" {
 | 
			
		||||
					t.Errorf("Returned body does not match expected: %s", diff)
 | 
			
		||||
				}
 | 
			
		||||
			})
 | 
			
		||||
 | 
			
		||||
			// DELETE /api/file/id
 | 
			
		||||
			t.Run("DELETE", func(t *testing.T) {
 | 
			
		||||
				hs := newServer()
 | 
			
		||||
				fileBody := io.NopCloser(strings.NewReader("roflcopter"))
 | 
			
		||||
				file := &files.File{
 | 
			
		||||
					ID:               uuid.NewString(),
 | 
			
		||||
					OriginalFilename: "testpls.txt",
 | 
			
		||||
					MaxViews:         9,
 | 
			
		||||
					ExpiresOn:        time.Now().Add(10 * time.Hour),
 | 
			
		||||
					Body:             fileBody,
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				if err := hs.Files.Store(file); err != nil {
 | 
			
		||||
					t.Fatalf("Error storing file: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				rr := httptest.NewRecorder()
 | 
			
		||||
				url := fmt.Sprintf("/api/file/%s", file.ID)
 | 
			
		||||
				req := httptest.NewRequest(http.MethodDelete, url, nil)
 | 
			
		||||
				hs.Handler.ServeHTTP(rr, req)
 | 
			
		||||
 | 
			
		||||
				if rr.Result().StatusCode != http.StatusOK {
 | 
			
		||||
					t.Fatalf("Delete returned wrong status: %s", rr.Result().Status)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				if _, err := hs.Files.Get(file.ID); err == nil {
 | 
			
		||||
					t.Errorf("Getting after delete returned no error")
 | 
			
		||||
				}
 | 
			
		||||
			})
 | 
			
		||||
		})
 | 
			
		||||
	t.Run("HandlerAPILogin", func(t *testing.T) {
 | 
			
		||||
		// /api/user
 | 
			
		||||
 | 
			
		||||
		t.Run("user", func(t *testing.T) {
 | 
			
		||||
			t.Run("POST", func(t *testing.T) {
 | 
			
		||||
				hs := newServer()
 | 
			
		||||
				adminPw := "admin"
 | 
			
		||||
				admin := &users.User{
 | 
			
		||||
					Username: "admin",
 | 
			
		||||
					Role:     users.RoleAdmin,
 | 
			
		||||
				}
 | 
			
		||||
				_ = admin.SetPassword(adminPw)
 | 
			
		||||
				_ = hs.Users.Store(admin)
 | 
			
		||||
 | 
			
		||||
				token, err := hs.Auth.Login(admin.Username, adminPw)
 | 
			
		||||
				if err != nil {
 | 
			
		||||
					t.Fatalf("error getting admin token: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				requestData := &api.RequestAPIUserCreate{
 | 
			
		||||
					Username: "test",
 | 
			
		||||
					Password: "test",
 | 
			
		||||
				}
 | 
			
		||||
				body := new(bytes.Buffer)
 | 
			
		||||
				encoder := json.NewEncoder(body)
 | 
			
		||||
				if err := encoder.Encode(requestData); err != nil {
 | 
			
		||||
					t.Fatalf("Error encoding data: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				rr := httptest.NewRecorder()
 | 
			
		||||
				req := httptest.NewRequest(http.MethodPost, "/api/user", body)
 | 
			
		||||
				req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", token))
 | 
			
		||||
				hs.Handler.ServeHTTP(rr, req)
 | 
			
		||||
 | 
			
		||||
				if rr.Result().StatusCode != http.StatusAccepted {
 | 
			
		||||
					t.Fatalf("Create returned wrong status: %s", rr.Result().Status)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				user, err := hs.Users.Get(requestData.Username)
 | 
			
		||||
				if err != nil {
 | 
			
		||||
					t.Fatalf("Unable to get user after create: %s", err)
 | 
			
		||||
				}
 | 
			
		||||
 | 
			
		||||
				expectedUser := &users.User{
 | 
			
		||||
					Username: requestData.Username,
 | 
			
		||||
					Role:     users.RoleUser,
 | 
			
		||||
				}
 | 
			
		||||
				ignorePW := cmp.FilterPath(func(p cmp.Path) bool {
 | 
			
		||||
					return p.String() == "HashedPassword"
 | 
			
		||||
				}, cmp.Ignore())
 | 
			
		||||
 | 
			
		||||
				if diff := cmp.Diff(user, expectedUser, ignorePW); diff != "" {
 | 
			
		||||
					t.Errorf("User does not match expected: %s", diff)
 | 
			
		||||
				}
 | 
			
		||||
			})
 | 
			
		||||
		})
 | 
			
		||||
 | 
			
		||||
		// /api/login
 | 
			
		||||
		t.Run("Login", func(t *testing.T) {
 | 
			
		||||
			hs := newServer()
 | 
			
		||||
			// TODO: Add test
 | 
			
		||||
			username := "admin"
 | 
			
		||||
			password := "admin"
 | 
			
		||||
@@ -143,4 +264,17 @@ func TestHandlers(t *testing.T) {
 | 
			
		||||
				t.Fatalf("Unable to validate received token: %s", err)
 | 
			
		||||
			}
 | 
			
		||||
		})
 | 
			
		||||
	})
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func newServer() *api.HTTPServer {
 | 
			
		||||
	cfg := &gpaste.ServerConfig{
 | 
			
		||||
		SigningSecret: "abc123",
 | 
			
		||||
		Store: &gpaste.ServerStoreConfig{
 | 
			
		||||
			Type: "memory",
 | 
			
		||||
		},
 | 
			
		||||
		URL: "http://localhost:8080",
 | 
			
		||||
	}
 | 
			
		||||
	return api.NewHTTPServer(cfg)
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -15,6 +15,14 @@ type ResponseAPILogin struct {
 | 
			
		||||
}
 | 
			
		||||
type ResponseAPIFilePost struct {
 | 
			
		||||
	Message string                     `json:"message"`
 | 
			
		||||
	Files   []ResponseAPIFilePostFiles `json:"files"`
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
type ResponseAPIFilePostFiles struct {
 | 
			
		||||
	ID  string `json:"id"`
 | 
			
		||||
	URL string `json:"url"`
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
type ResponseAPIUserList struct {
 | 
			
		||||
	Usernames []string `json:"usernames"`
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -10,6 +10,7 @@ import (
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/users"
 | 
			
		||||
	"github.com/go-chi/chi/v5/middleware"
 | 
			
		||||
	"go.uber.org/zap"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
type authCtxKey int
 | 
			
		||||
@@ -27,43 +28,73 @@ func (s *HTTPServer) MiddlewareAccessLogger(next http.Handler) http.Handler {
 | 
			
		||||
 | 
			
		||||
		reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
		// TODO: Maybe desugar in HTTPServer to avoid doing for all requests
 | 
			
		||||
		logger := s.AccessLogger.Desugar()
 | 
			
		||||
 | 
			
		||||
		defer func() {
 | 
			
		||||
			s.AccessLogger.Infow(r.Method,
 | 
			
		||||
				"path", r.URL.Path,
 | 
			
		||||
				"status", ww.Status(),
 | 
			
		||||
				"written", ww.BytesWritten(),
 | 
			
		||||
				"remote_addr", r.RemoteAddr,
 | 
			
		||||
				"processing_time_ms", time.Since(t1).Milliseconds(),
 | 
			
		||||
				"req_id", reqID)
 | 
			
		||||
			// DEBUG level
 | 
			
		||||
			if ce := logger.Check(zap.DebugLevel, r.Method); ce != nil {
 | 
			
		||||
				ct := r.Header.Get("Content-Type")
 | 
			
		||||
				ce.Write(
 | 
			
		||||
					zap.String("req_id", reqID),
 | 
			
		||||
					zap.String("path", r.URL.Path),
 | 
			
		||||
					zap.Int("status", ww.Status()),
 | 
			
		||||
					zap.String("remote_addr", r.RemoteAddr),
 | 
			
		||||
					zap.Int("bytes_written", ww.BytesWritten()),
 | 
			
		||||
					zap.Duration("processing_time", time.Since(t1)),
 | 
			
		||||
					zap.String("content_type", ct),
 | 
			
		||||
					zap.Any("headers", r.Header),
 | 
			
		||||
				)
 | 
			
		||||
			} else {
 | 
			
		||||
				// INFO level
 | 
			
		||||
				if ce := logger.Check(zap.InfoLevel, r.Method); ce != nil {
 | 
			
		||||
					ce.Write(
 | 
			
		||||
						zap.String("req_id", reqID),
 | 
			
		||||
						zap.String("path", r.URL.Path),
 | 
			
		||||
						zap.Int("status", ww.Status()),
 | 
			
		||||
						zap.String("remote_addr", r.RemoteAddr),
 | 
			
		||||
						zap.Int("bytes_written", ww.BytesWritten()),
 | 
			
		||||
						zap.Duration("processing_time", time.Since(t1)),
 | 
			
		||||
					)
 | 
			
		||||
				}
 | 
			
		||||
			}
 | 
			
		||||
 | 
			
		||||
			_ = logger.Sync()
 | 
			
		||||
		}()
 | 
			
		||||
 | 
			
		||||
		next.ServeHTTP(ww, r)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return http.HandlerFunc(fn)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *HTTPServer) MiddlewareAuthentication(next http.Handler) http.Handler {
 | 
			
		||||
	fn := func(w http.ResponseWriter, r *http.Request) {
 | 
			
		||||
		reqID := middleware.GetReqID(r.Context())
 | 
			
		||||
 | 
			
		||||
		header := r.Header.Get("Authorization")
 | 
			
		||||
		if header == "" {
 | 
			
		||||
			s.Logger.Debugw("Request has no auth header.", "req_id", reqID)
 | 
			
		||||
			next.ServeHTTP(w, r)
 | 
			
		||||
 | 
			
		||||
			return
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		splitHeader := strings.Split(header, "Bearer ")
 | 
			
		||||
		if len(splitHeader) != 2 {
 | 
			
		||||
		if len(splitHeader) != 2 { // nolint: gomnd
 | 
			
		||||
			s.Logger.Debugw("Request has invalid token.", "req_id", reqID)
 | 
			
		||||
			next.ServeHTTP(w, r)
 | 
			
		||||
 | 
			
		||||
			return
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		token := splitHeader[1]
 | 
			
		||||
 | 
			
		||||
		claims, err := s.Auth.ValidateToken(token)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			s.Logger.Debugw("Request has invalid token.", "req_id", reqID)
 | 
			
		||||
			next.ServeHTTP(w, r)
 | 
			
		||||
 | 
			
		||||
			return
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
@@ -71,6 +102,7 @@ func (s *HTTPServer) MiddlewareAuthentication(next http.Handler) http.Handler {
 | 
			
		||||
		ctx = context.WithValue(ctx, authCtxAuthLevel, claims.Role)
 | 
			
		||||
		ctx = context.WithValue(ctx, authCtxClaims, claims)
 | 
			
		||||
		withCtx := r.WithContext(ctx)
 | 
			
		||||
 | 
			
		||||
		s.Logger.Debugw("Request is authenticated.", "req_id", reqID, "username", claims.Subject, "role", claims.Role)
 | 
			
		||||
 | 
			
		||||
		next.ServeHTTP(w, withCtx)
 | 
			
		||||
@@ -84,10 +116,12 @@ func UsernameFromRequest(r *http.Request) (string, error) {
 | 
			
		||||
	if rawUsername == nil {
 | 
			
		||||
		return "", fmt.Errorf("no username")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	username, ok := rawUsername.(string)
 | 
			
		||||
	if !ok {
 | 
			
		||||
		return "", fmt.Errorf("no username")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return username, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -96,10 +130,12 @@ func RoleFromRequest(r *http.Request) (users.Role, error) {
 | 
			
		||||
	if rawLevel == nil {
 | 
			
		||||
		return users.RoleUnset, fmt.Errorf("no username")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	level, ok := rawLevel.(users.Role)
 | 
			
		||||
	if !ok {
 | 
			
		||||
		return users.RoleUnset, fmt.Errorf("no username")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return level, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -108,9 +144,11 @@ func ClaimsFromRequest(r *http.Request) *gpaste.Claims {
 | 
			
		||||
	if rawClaims == nil {
 | 
			
		||||
		return nil
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	claims, ok := rawClaims.(*gpaste.Claims)
 | 
			
		||||
	if !ok {
 | 
			
		||||
		return nil
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return claims
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										3
									
								
								auth.go
									
									
									
									
									
								
							
							
						
						
									
										3
									
								
								auth.go
									
									
									
									
									
								
							@@ -44,6 +44,7 @@ func (as *AuthService) Login(username, password string) (string, error) {
 | 
			
		||||
	claims.Role = user.Role
 | 
			
		||||
 | 
			
		||||
	token := jwt.NewWithClaims(jwt.GetSigningMethod("HS256"), claims)
 | 
			
		||||
 | 
			
		||||
	signed, err := token.SignedString(as.hmacSecret)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return "", err
 | 
			
		||||
@@ -57,9 +58,11 @@ func (as *AuthService) ValidateToken(rawToken string) (*Claims, error) {
 | 
			
		||||
	token, err := jwt.ParseWithClaims(rawToken, claims, func(t *jwt.Token) (interface{}, error) {
 | 
			
		||||
		return as.hmacSecret, nil
 | 
			
		||||
	})
 | 
			
		||||
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if !token.Valid {
 | 
			
		||||
		return nil, fmt.Errorf("invalid token")
 | 
			
		||||
	}
 | 
			
		||||
 
 | 
			
		||||
@@ -8,24 +8,70 @@ import (
 | 
			
		||||
	"io"
 | 
			
		||||
	"mime/multipart"
 | 
			
		||||
	"net/http"
 | 
			
		||||
	"os"
 | 
			
		||||
	"path/filepath"
 | 
			
		||||
	"time"
 | 
			
		||||
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/api"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/files"
 | 
			
		||||
	"github.com/google/uuid"
 | 
			
		||||
	"github.com/kirsle/configdir"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
const defaultTimeout = 10 * time.Second
 | 
			
		||||
 | 
			
		||||
type Client struct {
 | 
			
		||||
	BaseURL   string
 | 
			
		||||
	AuthToken string
 | 
			
		||||
	BaseURL   string `json:"baseUrl"`
 | 
			
		||||
	AuthToken string `json:"authToken"`
 | 
			
		||||
 | 
			
		||||
	httpClient http.Client
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) WriteConfigToWriter(w io.Writer) error {
 | 
			
		||||
	encoder := json.NewEncoder(w)
 | 
			
		||||
	return encoder.Encode(c)
 | 
			
		||||
}
 | 
			
		||||
func (c *Client) WriteConfig() error {
 | 
			
		||||
	dir := configdir.LocalConfig("gpaste")
 | 
			
		||||
	// Ensure dir exists
 | 
			
		||||
	err := os.MkdirAll(dir, os.ModePerm)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	path := filepath.Join(dir, "client.json")
 | 
			
		||||
 | 
			
		||||
	f, err := os.Create(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
	defer f.Close()
 | 
			
		||||
 | 
			
		||||
	return c.WriteConfigToWriter(f)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) LoadConfig() error {
 | 
			
		||||
	dir := configdir.LocalCache("gpaste")
 | 
			
		||||
	path := filepath.Join(dir, "client.json")
 | 
			
		||||
 | 
			
		||||
	f, err := os.Open(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
	defer f.Close()
 | 
			
		||||
 | 
			
		||||
	return c.LoadConfigFromReader(f)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) LoadConfigFromReader(r io.Reader) error {
 | 
			
		||||
	decoder := json.NewDecoder(r)
 | 
			
		||||
	return decoder.Decode(c)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) Login(ctx context.Context, username, password string) error {
 | 
			
		||||
	url := fmt.Sprintf("%s/api/login", c.BaseURL)
 | 
			
		||||
	// TODO: Change timeout
 | 
			
		||||
	ctx, cancel := context.WithTimeout(ctx, 10*time.Second)
 | 
			
		||||
	ctx, cancel := context.WithTimeout(ctx, defaultTimeout)
 | 
			
		||||
	defer cancel()
 | 
			
		||||
 | 
			
		||||
	body := new(bytes.Buffer)
 | 
			
		||||
@@ -33,10 +79,12 @@ func (c *Client) Login(ctx context.Context, username, password string) error {
 | 
			
		||||
		Username: username,
 | 
			
		||||
		Password: password,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	encoder := json.NewEncoder(body)
 | 
			
		||||
	if err := encoder.Encode(&requestData); err != nil {
 | 
			
		||||
		return fmt.Errorf("error encoding response: %w", err)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, body)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("error creating request: %w", err)
 | 
			
		||||
@@ -58,6 +106,7 @@ func (c *Client) Login(ctx context.Context, username, password string) error {
 | 
			
		||||
	if err := decoder.Decode(&responseData); err != nil {
 | 
			
		||||
		return fmt.Errorf("unable to parse response: %s", err)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	c.AuthToken = responseData.Token
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
@@ -71,6 +120,7 @@ func (c *Client) UserCreate(ctx context.Context, username, password string) erro
 | 
			
		||||
		Username: username,
 | 
			
		||||
		Password: password,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	encoder := json.NewEncoder(body)
 | 
			
		||||
	if err := encoder.Encode(requestData); err != nil {
 | 
			
		||||
		return fmt.Errorf("error encoding response: %w", err)
 | 
			
		||||
@@ -118,14 +168,11 @@ func (c *Client) Download(ctx context.Context, id string) (io.ReadCloser, error)
 | 
			
		||||
	return resp.Body, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) Upload(ctx context.Context, files ...*files.File) ([]api.ResponseAPIFilePost, error) {
 | 
			
		||||
func (c *Client) Upload(ctx context.Context, files ...*files.File) (*api.ResponseAPIFilePost, error) {
 | 
			
		||||
	url := fmt.Sprintf("%s/api/file", c.BaseURL)
 | 
			
		||||
	client := &http.Client{}
 | 
			
		||||
 | 
			
		||||
	// TODO: Change timeout
 | 
			
		||||
	ctx, cancel := context.WithTimeout(ctx, 10*time.Minute)
 | 
			
		||||
	defer cancel()
 | 
			
		||||
 | 
			
		||||
	// TODO: Improve buffering
 | 
			
		||||
	buf := &bytes.Buffer{}
 | 
			
		||||
	mw := multipart.NewWriter(buf)
 | 
			
		||||
@@ -135,16 +182,21 @@ func (c *Client) Upload(ctx context.Context, files ...*files.File) ([]api.Respon
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			return nil, err
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		if _, err := io.Copy(fw, file.Body); err != nil {
 | 
			
		||||
			return nil, err
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		file.Body.Close()
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	mw.Close()
 | 
			
		||||
 | 
			
		||||
	req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, buf)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	req.Header.Add("Content-Type", mw.FormDataContentType())
 | 
			
		||||
 | 
			
		||||
	resp, err := client.Do(req)
 | 
			
		||||
@@ -153,7 +205,7 @@ func (c *Client) Upload(ctx context.Context, files ...*files.File) ([]api.Respon
 | 
			
		||||
	}
 | 
			
		||||
	defer resp.Body.Close()
 | 
			
		||||
 | 
			
		||||
	var expectedResp []api.ResponseAPIFilePost
 | 
			
		||||
	var expectedResp *api.ResponseAPIFilePost
 | 
			
		||||
 | 
			
		||||
	decoder := json.NewDecoder(resp.Body)
 | 
			
		||||
	if err := decoder.Decode(&expectedResp); err != nil {
 | 
			
		||||
@@ -162,3 +214,26 @@ func (c *Client) Upload(ctx context.Context, files ...*files.File) ([]api.Respon
 | 
			
		||||
 | 
			
		||||
	return expectedResp, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (c *Client) Delete(ctx context.Context, id string) error {
 | 
			
		||||
	url := fmt.Sprintf("%s/api/file/%s", c.BaseURL, id)
 | 
			
		||||
 | 
			
		||||
	req, err := http.NewRequestWithContext(ctx, http.MethodDelete, url, nil)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("error creating request: %w", err)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	req.Header.Set("Authorization", fmt.Sprintf("Bearer %s", c.AuthToken))
 | 
			
		||||
 | 
			
		||||
	resp, err := c.httpClient.Do(req)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("unable to perform request: %s", err)
 | 
			
		||||
	}
 | 
			
		||||
	defer resp.Body.Close()
 | 
			
		||||
 | 
			
		||||
	if resp.StatusCode != http.StatusOK {
 | 
			
		||||
		return fmt.Errorf("got non-ok response from server: %s", resp.Status)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -1,6 +1,7 @@
 | 
			
		||||
package client_test
 | 
			
		||||
 | 
			
		||||
import (
 | 
			
		||||
	"bytes"
 | 
			
		||||
	"context"
 | 
			
		||||
	"fmt"
 | 
			
		||||
	"io"
 | 
			
		||||
@@ -15,6 +16,7 @@ import (
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/files"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/users"
 | 
			
		||||
	"github.com/google/go-cmp/cmp"
 | 
			
		||||
	"github.com/google/go-cmp/cmp/cmpopts"
 | 
			
		||||
	"github.com/google/uuid"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
@@ -118,7 +120,7 @@ func TestClient(t *testing.T) {
 | 
			
		||||
			t.Fatalf("Error uploading: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		retrieved, err := srv.Files.Get(resp[0].ID)
 | 
			
		||||
		retrieved, err := srv.Files.Get(resp.Files[0].ID)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error getting uploaded file from store: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
@@ -162,4 +164,31 @@ func TestClient(t *testing.T) {
 | 
			
		||||
			t.Errorf("File contents does not match: %s", cmp.Diff(buf.String(), fileContents))
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
	t.Run("Save", func(t *testing.T) {
 | 
			
		||||
		c := client.Client{BaseURL: "http://example.org/gpaste", AuthToken: "tokenpls"}
 | 
			
		||||
		expectedConfig := "{\"baseUrl\":\"http://example.org/gpaste\",\"authToken\":\"tokenpls\"}\n"
 | 
			
		||||
		buf := new(bytes.Buffer)
 | 
			
		||||
		err := c.WriteConfigToWriter(buf)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error writing config: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		if diff := cmp.Diff(buf.String(), expectedConfig); diff != "" {
 | 
			
		||||
			t.Errorf("Written config does not match expected: %s", diff)
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
	t.Run("Load", func(t *testing.T) {
 | 
			
		||||
		c := client.Client{}
 | 
			
		||||
		config := "{\"baseUrl\":\"http://pasta.example.org\",\"authToken\":\"tokenpls\"}\n"
 | 
			
		||||
		expectedClient := client.Client{BaseURL: "http://pasta.example.org", AuthToken: "tokenpls"}
 | 
			
		||||
		sr := strings.NewReader(config)
 | 
			
		||||
		if err := c.LoadConfigFromReader(sr); err != nil {
 | 
			
		||||
			t.Fatalf("Error reading config: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		if diff := cmp.Diff(c, expectedClient, cmpopts.IgnoreUnexported(client.Client{})); diff != "" {
 | 
			
		||||
			t.Errorf("Client does not match expected: %s", diff)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
	})
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -15,27 +15,54 @@ import (
 | 
			
		||||
	"golang.org/x/term"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
const defaultTimeout = 10 * time.Second
 | 
			
		||||
 | 
			
		||||
func ActionUpload(c *cli.Context) error {
 | 
			
		||||
	clnt := client.Client{
 | 
			
		||||
		BaseURL: c.String("url"),
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	for _, arg := range c.Args().Slice() {
 | 
			
		||||
		f, err := os.Open(arg)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			return err
 | 
			
		||||
		}
 | 
			
		||||
		defer f.Close()
 | 
			
		||||
 | 
			
		||||
		file := &files.File{
 | 
			
		||||
			OriginalFilename: arg,
 | 
			
		||||
			Body:             f,
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		resp, err := clnt.Upload(c.Context, file)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			errmsg := fmt.Sprintf("Error uploading file: %s", err)
 | 
			
		||||
			return cli.Exit(errmsg, 1)
 | 
			
		||||
		}
 | 
			
		||||
		fmt.Printf("Uploaded file %s - %s", file.OriginalFilename, resp[0].URL)
 | 
			
		||||
 | 
			
		||||
		fmt.Printf("Uploaded file %s - %s", file.OriginalFilename, resp.Files[0].URL)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func ActionDelete(c *cli.Context) error {
 | 
			
		||||
	clnt := client.Client{
 | 
			
		||||
		BaseURL: c.String("url"),
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	for _, arg := range c.Args().Slice() {
 | 
			
		||||
		ctx, cancel := context.WithTimeout(c.Context, defaultTimeout)
 | 
			
		||||
		defer cancel()
 | 
			
		||||
 | 
			
		||||
		if err := clnt.Delete(ctx, arg); err != nil {
 | 
			
		||||
			fmt.Printf("Error deleting file %s\n", arg)
 | 
			
		||||
			fmt.Printf("%s\n", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		fmt.Printf("Deleted %s\n", arg)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -44,6 +71,7 @@ func ActionLogin(c *cli.Context) error {
 | 
			
		||||
	if username == "" {
 | 
			
		||||
		return cli.Exit("USERNAME not supplied.", 1)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	password, err := readPassword()
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("error reading password: %w", err)
 | 
			
		||||
@@ -56,6 +84,11 @@ func ActionLogin(c *cli.Context) error {
 | 
			
		||||
		errmsg := fmt.Sprintf("Error logging in: %s", err)
 | 
			
		||||
		return cli.Exit(errmsg, 1)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if err := clnt.WriteConfig(); err != nil {
 | 
			
		||||
		errMsg := fmt.Sprintf("Failed to write config: %s", err)
 | 
			
		||||
		return cli.Exit(errMsg, 1)
 | 
			
		||||
	}
 | 
			
		||||
	// TODO: Store this somewhere, so we don't need to log in each time
 | 
			
		||||
	fmt.Println("Successfully logged in.")
 | 
			
		||||
 | 
			
		||||
@@ -65,7 +98,9 @@ func ActionLogin(c *cli.Context) error {
 | 
			
		||||
func ActionUserCreate(c *cli.Context) error {
 | 
			
		||||
	// TODO: Needs to supply auth token to actually work
 | 
			
		||||
	fmt.Println("Need to be logged in to create user")
 | 
			
		||||
 | 
			
		||||
	username := readString("Enter username: ")
 | 
			
		||||
 | 
			
		||||
	password, err := readPassword()
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("error reading password: %w", err)
 | 
			
		||||
@@ -74,7 +109,8 @@ func ActionUserCreate(c *cli.Context) error {
 | 
			
		||||
	clnt := client.Client{
 | 
			
		||||
		BaseURL: c.String("url"),
 | 
			
		||||
	}
 | 
			
		||||
	ctx, cancel := context.WithTimeout(c.Context, 10*time.Second)
 | 
			
		||||
 | 
			
		||||
	ctx, cancel := context.WithTimeout(c.Context, defaultTimeout)
 | 
			
		||||
	defer cancel()
 | 
			
		||||
 | 
			
		||||
	if err := clnt.Login(ctx, username, password); err != nil {
 | 
			
		||||
@@ -83,7 +119,9 @@ func ActionUserCreate(c *cli.Context) error {
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	fmt.Println("User to create:")
 | 
			
		||||
 | 
			
		||||
	username = readString("Enter username: ")
 | 
			
		||||
 | 
			
		||||
	password, err = readPassword()
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return fmt.Errorf("error reading password: %w", err)
 | 
			
		||||
@@ -101,20 +139,24 @@ func ActionUserCreate(c *cli.Context) error {
 | 
			
		||||
 | 
			
		||||
func readPassword() (string, error) {
 | 
			
		||||
	fmt.Print("Enter Password: ")
 | 
			
		||||
 | 
			
		||||
	bytePassword, err := term.ReadPassword(int(syscall.Stdin))
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return "", err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	password := string(bytePassword)
 | 
			
		||||
 | 
			
		||||
	return strings.TrimSpace(password), nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func readString(prompt string) string {
 | 
			
		||||
	fmt.Print(prompt)
 | 
			
		||||
 | 
			
		||||
	scanner := bufio.NewScanner(os.Stdin)
 | 
			
		||||
	for scanner.Scan() {
 | 
			
		||||
		return scanner.Text()
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return ""
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -37,6 +37,12 @@ func main() {
 | 
			
		||||
				ArgsUsage: "FILE [FILE]...",
 | 
			
		||||
				Action:    actions.ActionUpload,
 | 
			
		||||
			},
 | 
			
		||||
			{
 | 
			
		||||
				Name:      "delete",
 | 
			
		||||
				Usage:     "Delete file(s)",
 | 
			
		||||
				ArgsUsage: "FILE [FILE]...",
 | 
			
		||||
				Action:    actions.ActionDelete,
 | 
			
		||||
			},
 | 
			
		||||
			{
 | 
			
		||||
				Name:      "login",
 | 
			
		||||
				Usage:     "Login to gpaste server",
 | 
			
		||||
@@ -58,5 +64,5 @@ func main() {
 | 
			
		||||
		},
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	app.Run(os.Args)
 | 
			
		||||
	_ = app.Run(os.Args)
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -2,14 +2,19 @@ package actions
 | 
			
		||||
 | 
			
		||||
import (
 | 
			
		||||
	"context"
 | 
			
		||||
	"io"
 | 
			
		||||
	"net/http"
 | 
			
		||||
	"os"
 | 
			
		||||
	"os/signal"
 | 
			
		||||
	"path/filepath"
 | 
			
		||||
	"strings"
 | 
			
		||||
	"time"
 | 
			
		||||
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/api"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/files"
 | 
			
		||||
	"git.t-juice.club/torjus/gpaste/users"
 | 
			
		||||
	"github.com/google/uuid"
 | 
			
		||||
	"github.com/urfave/cli/v2"
 | 
			
		||||
	"go.uber.org/zap"
 | 
			
		||||
	"go.uber.org/zap/zapcore"
 | 
			
		||||
@@ -21,14 +26,30 @@ func ActionServe(c *cli.Context) error {
 | 
			
		||||
		configPath = c.String("config")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	f, err := os.Open(configPath)
 | 
			
		||||
	var (
 | 
			
		||||
		cfg *gpaste.ServerConfig
 | 
			
		||||
		r   io.ReadCloser
 | 
			
		||||
	)
 | 
			
		||||
 | 
			
		||||
	r, err := os.Open(configPath)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		cfg = &gpaste.ServerConfig{
 | 
			
		||||
			LogLevel:      "INFO",
 | 
			
		||||
			URL:           "localhost:8080",
 | 
			
		||||
			ListenAddr:    ":8080",
 | 
			
		||||
			SigningSecret: "TODO: CHANGE THIS LOL",
 | 
			
		||||
			Store: &gpaste.ServerStoreConfig{
 | 
			
		||||
				Type: "memory",
 | 
			
		||||
			},
 | 
			
		||||
		}
 | 
			
		||||
	} else {
 | 
			
		||||
		defer r.Close()
 | 
			
		||||
		cfg, err = gpaste.ServerConfigFromReader(r)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			if err != nil {
 | 
			
		||||
				return cli.Exit(err, 1)
 | 
			
		||||
			}
 | 
			
		||||
	defer f.Close()
 | 
			
		||||
	cfg, err := gpaste.ServerConfigFromReader(f)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return cli.Exit(err, 1)
 | 
			
		||||
		}
 | 
			
		||||
	}
 | 
			
		||||
	// Setup loggers
 | 
			
		||||
	rootLogger := getRootLogger(cfg.LogLevel)
 | 
			
		||||
@@ -38,28 +59,72 @@ func ActionServe(c *cli.Context) error {
 | 
			
		||||
	// Setup contexts for clean shutdown
 | 
			
		||||
	rootCtx, rootCancel := signal.NotifyContext(context.Background(), os.Interrupt)
 | 
			
		||||
	defer rootCancel()
 | 
			
		||||
 | 
			
		||||
	httpCtx, httpCancel := context.WithCancel(rootCtx)
 | 
			
		||||
	defer httpCancel()
 | 
			
		||||
 | 
			
		||||
	httpShutdownCtx, httpShutdownCancel := context.WithCancel(context.Background())
 | 
			
		||||
	defer httpShutdownCancel()
 | 
			
		||||
 | 
			
		||||
	// Setup stores
 | 
			
		||||
	// Files
 | 
			
		||||
	fileStore, fileClose, err := getFileStore(cfg)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	defer fileClose() // nolint: errcheck
 | 
			
		||||
 | 
			
		||||
	// Users
 | 
			
		||||
	userStore, userClose, err := getUserStore(cfg)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	defer userClose() // nolint: errcheck
 | 
			
		||||
 | 
			
		||||
	if userList, err := userStore.List(); err != nil {
 | 
			
		||||
		serverLogger.Panicw("Error checking userstore for users.", "error", err)
 | 
			
		||||
	} else if len(userList) < 1 {
 | 
			
		||||
		admin := users.User{
 | 
			
		||||
			Username: "admin",
 | 
			
		||||
			Role:     users.RoleAdmin,
 | 
			
		||||
		}
 | 
			
		||||
		password := uuid.NewString()
 | 
			
		||||
		if err := admin.SetPassword(password); err != nil {
 | 
			
		||||
			serverLogger.DPanic("Error setting admin-user password.", "error", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		serverLogger.Warnw("Created admin-user.", "username", admin.Username, "password", password)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	// Auth
 | 
			
		||||
	auth := gpaste.NewAuthService(userStore, []byte(cfg.SigningSecret))
 | 
			
		||||
 | 
			
		||||
	go func() {
 | 
			
		||||
		srv := api.NewHTTPServer(cfg)
 | 
			
		||||
		srv.Users = userStore
 | 
			
		||||
		srv.Files = fileStore
 | 
			
		||||
		srv.Addr = cfg.ListenAddr
 | 
			
		||||
		srv.Logger = serverLogger
 | 
			
		||||
		srv.AccessLogger = accessLogger
 | 
			
		||||
		srv.Auth = auth
 | 
			
		||||
 | 
			
		||||
		// Wait for cancel
 | 
			
		||||
		go func() {
 | 
			
		||||
			<-httpCtx.Done()
 | 
			
		||||
			timeoutCtx, cancel := context.WithTimeout(context.Background(), 10*time.Second)
 | 
			
		||||
 | 
			
		||||
			timeoutCtx, cancel := context.WithTimeout(context.Background(), 10*time.Second) // nolint: gomnd
 | 
			
		||||
			defer cancel()
 | 
			
		||||
			srv.Shutdown(timeoutCtx)
 | 
			
		||||
 | 
			
		||||
			_ = srv.Shutdown(timeoutCtx)
 | 
			
		||||
		}()
 | 
			
		||||
		serverLogger.Infow("Starting HTTP server.", "addr", cfg.ListenAddr)
 | 
			
		||||
 | 
			
		||||
		if err := srv.ListenAndServe(); err != nil && err != http.ErrServerClosed {
 | 
			
		||||
			serverLogger.Errorw("Error during shutdown.", "error", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		serverLogger.Infow("HTTP server shutdown complete.", "addr", cfg.ListenAddr)
 | 
			
		||||
		httpShutdownCancel()
 | 
			
		||||
	}()
 | 
			
		||||
@@ -103,3 +168,48 @@ func getRootLogger(level string) *zap.SugaredLogger {
 | 
			
		||||
 | 
			
		||||
	return rootLogger.Sugar()
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
// nolint: ireturn
 | 
			
		||||
func getUserStore(cfg *gpaste.ServerConfig) (users.UserStore, func() error, error) {
 | 
			
		||||
	closer := func() error { return nil }
 | 
			
		||||
 | 
			
		||||
	switch cfg.Store.Type {
 | 
			
		||||
	case "memory":
 | 
			
		||||
		return users.NewMemoryUserStore(), closer, nil
 | 
			
		||||
 | 
			
		||||
	case "fs":
 | 
			
		||||
		path := filepath.Join(cfg.Store.FS.Dir, "gpaste-users.db")
 | 
			
		||||
 | 
			
		||||
		bs, err := users.NewBoltUserStore(path)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			return nil, closer, cli.Exit("error setting up user store", 1)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		return bs, bs.Close, nil
 | 
			
		||||
 | 
			
		||||
	default:
 | 
			
		||||
		return nil, closer, cli.Exit("no userstore configured", 1)
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
// nolint: ireturn
 | 
			
		||||
func getFileStore(cfg *gpaste.ServerConfig) (files.FileStore, func() error, error) {
 | 
			
		||||
	closer := func() error { return nil }
 | 
			
		||||
 | 
			
		||||
	switch cfg.Store.Type {
 | 
			
		||||
	case "memory":
 | 
			
		||||
		return files.NewMemoryFileStore(), closer, nil
 | 
			
		||||
 | 
			
		||||
	case "fs":
 | 
			
		||||
		var err error
 | 
			
		||||
 | 
			
		||||
		s, err := files.NewFSFileStore(cfg.Store.FS.Dir)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			return nil, closer, cli.Exit("error setting up filestore", 1)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		return s, closer, nil
 | 
			
		||||
	default:
 | 
			
		||||
		return nil, closer, cli.Exit("No store configured", 1)
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -29,5 +29,5 @@ func main() {
 | 
			
		||||
		Action: actions.ActionServe,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	app.Run(os.Args)
 | 
			
		||||
	_ = app.Run(os.Args)
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -33,6 +33,7 @@ func ServerConfigFromReader(r io.Reader) (*ServerConfig, error) {
 | 
			
		||||
			FS: &ServerStoreFSStoreConfig{},
 | 
			
		||||
		},
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	if err := decoder.Decode(&c); err != nil {
 | 
			
		||||
		return nil, fmt.Errorf("error decoding server config: %w", err)
 | 
			
		||||
	}
 | 
			
		||||
 
 | 
			
		||||
@@ -7,11 +7,13 @@ import (
 | 
			
		||||
 | 
			
		||||
type File struct {
 | 
			
		||||
	ID               string    `json:"id"`
 | 
			
		||||
	OriginalFilename string    `json:"original_filename"`
 | 
			
		||||
	MaxViews         uint      `json:"max_views"`
 | 
			
		||||
	ExpiresOn        time.Time `json:"expires_on"`
 | 
			
		||||
	OriginalFilename string    `json:"originalFilename"`
 | 
			
		||||
	MaxViews         uint      `json:"maxViews"`
 | 
			
		||||
	ExpiresOn        time.Time `json:"expiresOn"`
 | 
			
		||||
 | 
			
		||||
	Body io.ReadCloser
 | 
			
		||||
 | 
			
		||||
	FileSize int64 `json:"fileSize"`
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
type FileStore interface {
 | 
			
		||||
 
 | 
			
		||||
@@ -34,20 +34,26 @@ func (s *FSFileStore) Store(f *File) error {
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	path := filepath.Join(s.dir, f.ID)
 | 
			
		||||
 | 
			
		||||
	dst, err := os.Create(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
	defer dst.Close()
 | 
			
		||||
 | 
			
		||||
	if _, err := io.Copy(dst, f.Body); err != nil {
 | 
			
		||||
	n, err := io.Copy(dst, f.Body)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	s.metadata[f.ID] = metadata
 | 
			
		||||
	s.metadata[f.ID].FileSize = n
 | 
			
		||||
 | 
			
		||||
	if err := s.writeMetadata(); err != nil {
 | 
			
		||||
		delete(s.metadata, f.ID)
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -58,11 +64,14 @@ func (s *FSFileStore) Get(id string) (*File, error) {
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	path := filepath.Join(s.dir, id)
 | 
			
		||||
 | 
			
		||||
	f, err := os.Open(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	metadata.Body = f
 | 
			
		||||
 | 
			
		||||
	return metadata, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -71,20 +80,24 @@ func (s *FSFileStore) Delete(id string) error {
 | 
			
		||||
	if err := os.Remove(path); err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	delete(s.metadata, id)
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *FSFileStore) List() ([]string, error) {
 | 
			
		||||
	var results []string
 | 
			
		||||
	results := make([]string, 0, len(s.metadata))
 | 
			
		||||
	for k := range s.metadata {
 | 
			
		||||
		results = append(results, k)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return results, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *FSFileStore) writeMetadata() error {
 | 
			
		||||
	path := filepath.Join(s.dir, "metadata.json")
 | 
			
		||||
 | 
			
		||||
	f, err := os.Create(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
@@ -95,11 +108,13 @@ func (s *FSFileStore) writeMetadata() error {
 | 
			
		||||
	if err := encoder.Encode(s.metadata); err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *FSFileStore) readMetadata() error {
 | 
			
		||||
	path := filepath.Join(s.dir, "metadata.json")
 | 
			
		||||
 | 
			
		||||
	f, err := os.Open(path)
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		// TODO: Handle errors better
 | 
			
		||||
@@ -111,5 +126,6 @@ func (s *FSFileStore) readMetadata() error {
 | 
			
		||||
	if err := decoder.Decode(&s.metadata); err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -7,20 +7,23 @@ import (
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
func TestFSFileStore(t *testing.T) {
 | 
			
		||||
	newFunc := func() files.FileStore {
 | 
			
		||||
		dir := t.TempDir()
 | 
			
		||||
		s, err := files.NewFSFileStore(dir)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error creating store: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
		return s
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	RunFilestoreTest(s, t)
 | 
			
		||||
	RunFilestoreTest(newFunc, t)
 | 
			
		||||
	persistentDir := t.TempDir()
 | 
			
		||||
	newFunc := func() files.FileStore {
 | 
			
		||||
	persistentFunc := func() files.FileStore {
 | 
			
		||||
		s, err := files.NewFSFileStore(persistentDir)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error creating store: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
		return s
 | 
			
		||||
	}
 | 
			
		||||
	RunPersistentFilestoreTest(newFunc, t)
 | 
			
		||||
	RunPersistentFilestoreTest(persistentFunc, t)
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -14,6 +14,7 @@ type fileData struct {
 | 
			
		||||
 | 
			
		||||
	MaxViews  uint
 | 
			
		||||
	ExpiresOn time.Time
 | 
			
		||||
	FileSize  int64
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
type MemoryFileStore struct {
 | 
			
		||||
@@ -28,20 +29,22 @@ func NewMemoryFileStore() *MemoryFileStore {
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *MemoryFileStore) Store(f *File) error {
 | 
			
		||||
 | 
			
		||||
	data := &fileData{
 | 
			
		||||
		ID:        f.ID,
 | 
			
		||||
		MaxViews:  f.MaxViews,
 | 
			
		||||
		ExpiresOn: f.ExpiresOn,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	_, err := io.Copy(&data.Body, f.Body)
 | 
			
		||||
	n, err := io.Copy(&data.Body, f.Body)
 | 
			
		||||
	_ = f.Body.Close()
 | 
			
		||||
 | 
			
		||||
	data.FileSize = n
 | 
			
		||||
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	s.data[f.ID] = data
 | 
			
		||||
 | 
			
		||||
	return err
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -53,11 +56,18 @@ func (s *MemoryFileStore) Get(id string) (*File, error) {
 | 
			
		||||
	if !ok {
 | 
			
		||||
		return nil, fmt.Errorf("no such item")
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	body := new(bytes.Buffer)
 | 
			
		||||
	if _, err := body.Write(fd.Body.Bytes()); err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	f := &File{
 | 
			
		||||
		ID:        fd.ID,
 | 
			
		||||
		MaxViews:  fd.MaxViews,
 | 
			
		||||
		ExpiresOn: fd.ExpiresOn,
 | 
			
		||||
		Body:      io.NopCloser(&fd.Body),
 | 
			
		||||
		Body:      io.NopCloser(body),
 | 
			
		||||
		FileSize:  fd.FileSize,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return f, nil
 | 
			
		||||
@@ -66,17 +76,21 @@ func (s *MemoryFileStore) Get(id string) (*File, error) {
 | 
			
		||||
func (s *MemoryFileStore) Delete(id string) error {
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	delete(s.data, id)
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *MemoryFileStore) List() ([]string, error) {
 | 
			
		||||
	var ids []string
 | 
			
		||||
	ids := make([]string, 0, len(s.data))
 | 
			
		||||
 | 
			
		||||
	s.lock.RLock()
 | 
			
		||||
	defer s.lock.RUnlock()
 | 
			
		||||
 | 
			
		||||
	for id := range s.data {
 | 
			
		||||
		ids = append(ids, id)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return ids, nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -7,7 +7,9 @@ import (
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
func TestMemoryFileStore(t *testing.T) {
 | 
			
		||||
	s := files.NewMemoryFileStore()
 | 
			
		||||
 | 
			
		||||
	RunFilestoreTest(s, t)
 | 
			
		||||
	newFunc := func() files.FileStore {
 | 
			
		||||
		return files.NewMemoryFileStore()
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	RunFilestoreTest(newFunc, t)
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -12,8 +12,11 @@ import (
 | 
			
		||||
	"github.com/google/uuid"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
func RunFilestoreTest(s files.FileStore, t *testing.T) {
 | 
			
		||||
var ignoreBody = cmp.FilterPath(func(p cmp.Path) bool { return p.String() == "Body" }, cmp.Ignore())
 | 
			
		||||
 | 
			
		||||
func RunFilestoreTest(newStoreFunc func() files.FileStore, t *testing.T) {
 | 
			
		||||
	t.Run("Basic", func(t *testing.T) {
 | 
			
		||||
		s := newStoreFunc()
 | 
			
		||||
		// Create
 | 
			
		||||
		dataString := "TEST_LOL_OMG"
 | 
			
		||||
		id := uuid.Must(uuid.NewRandom()).String()
 | 
			
		||||
@@ -22,8 +25,9 @@ func RunFilestoreTest(s files.FileStore, t *testing.T) {
 | 
			
		||||
		body := io.NopCloser(bodyBuf)
 | 
			
		||||
		f := &files.File{
 | 
			
		||||
			ID:        id,
 | 
			
		||||
			MaxViews: 0,
 | 
			
		||||
			MaxViews:  99,
 | 
			
		||||
			Body:      body,
 | 
			
		||||
			ExpiresOn: time.Now().Add(99 * time.Second),
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		err := s.Store(f)
 | 
			
		||||
@@ -50,6 +54,16 @@ func RunFilestoreTest(s files.FileStore, t *testing.T) {
 | 
			
		||||
		if retrievedBuf.String() != dataString {
 | 
			
		||||
			t.Fatalf("Data from retrieved body mismatch. Got %s want %s", retrievedBuf.String(), dataString)
 | 
			
		||||
		}
 | 
			
		||||
		expected := &files.File{
 | 
			
		||||
			ID:        f.ID,
 | 
			
		||||
			MaxViews:  f.MaxViews,
 | 
			
		||||
			ExpiresOn: f.ExpiresOn,
 | 
			
		||||
			FileSize:  int64(len(dataString)),
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		if diff := cmp.Diff(retrieved, expected, ignoreBody); diff != "" {
 | 
			
		||||
			t.Errorf("File comparison failed: %s", diff)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		// List
 | 
			
		||||
		ids, err := s.List()
 | 
			
		||||
@@ -76,9 +90,54 @@ func RunFilestoreTest(s files.FileStore, t *testing.T) {
 | 
			
		||||
			t.Fatalf("List after delete has wrong length: %d", len(ids))
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
	t.Run("MultipleGet", func(t *testing.T) {
 | 
			
		||||
		s := newStoreFunc()
 | 
			
		||||
 | 
			
		||||
		fileContents := "multiple get test !"
 | 
			
		||||
		body := io.NopCloser(strings.NewReader(fileContents))
 | 
			
		||||
		file := &files.File{
 | 
			
		||||
			ID:               uuid.NewString(),
 | 
			
		||||
			OriginalFilename: "multiple.txt",
 | 
			
		||||
			MaxViews:         999,
 | 
			
		||||
			ExpiresOn:        time.Now().Add(1 * time.Hour),
 | 
			
		||||
			Body:             body,
 | 
			
		||||
			FileSize:         int64(len(fileContents)),
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		if err := s.Store(file); err != nil {
 | 
			
		||||
			t.Fatalf("Error storing file: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		first, err := s.Get(file.ID)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Errorf("Error retrieving first file: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		firstBody := new(bytes.Buffer)
 | 
			
		||||
		io.Copy(firstBody, first.Body)
 | 
			
		||||
		first.Body.Close()
 | 
			
		||||
 | 
			
		||||
		if diff := cmp.Diff(firstBody.String(), fileContents); diff != "" {
 | 
			
		||||
			t.Fatalf("File contents mismatch: %s", diff)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		second, err := s.Get(file.ID)
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Errorf("Error retrieving first file: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		secondBody := new(bytes.Buffer)
 | 
			
		||||
		io.Copy(secondBody, second.Body)
 | 
			
		||||
		first.Body.Close()
 | 
			
		||||
 | 
			
		||||
		if diff := cmp.Diff(secondBody.String(), fileContents); diff != "" {
 | 
			
		||||
			t.Fatalf("File contents mismatch: %s", diff)
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.T) {
 | 
			
		||||
	t.Run("Basics", func(t *testing.T) {
 | 
			
		||||
		s := newStoreFunc()
 | 
			
		||||
 | 
			
		||||
		files := []struct {
 | 
			
		||||
@@ -92,6 +151,7 @@ func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.
 | 
			
		||||
					MaxViews:         5,
 | 
			
		||||
					ExpiresOn:        time.Now().Add(10 * time.Minute),
 | 
			
		||||
					Body:             io.NopCloser(strings.NewReader("cocks!")),
 | 
			
		||||
					FileSize:         6,
 | 
			
		||||
				},
 | 
			
		||||
				ExpectedData: "cocks!",
 | 
			
		||||
			},
 | 
			
		||||
@@ -102,6 +162,7 @@ func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.
 | 
			
		||||
					MaxViews:         5,
 | 
			
		||||
					ExpiresOn:        time.Now().Add(10 * time.Minute),
 | 
			
		||||
					Body:             io.NopCloser(strings.NewReader("derps!")),
 | 
			
		||||
					FileSize:         6,
 | 
			
		||||
				},
 | 
			
		||||
				ExpectedData: "derps!",
 | 
			
		||||
			},
 | 
			
		||||
@@ -119,7 +180,6 @@ func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.
 | 
			
		||||
				t.Fatalf("Unable to retrieve file: %s", err)
 | 
			
		||||
			}
 | 
			
		||||
 | 
			
		||||
		ignoreBody := cmp.FilterPath(func(p cmp.Path) bool { return p.String() == "Body" }, cmp.Ignore())
 | 
			
		||||
			if !cmp.Equal(retrieved, f.File, ignoreBody) {
 | 
			
		||||
				t.Errorf("Mismatch: %s", cmp.Diff(retrieved, f.File))
 | 
			
		||||
			}
 | 
			
		||||
@@ -141,7 +201,6 @@ func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.
 | 
			
		||||
				t.Fatalf("Unable to retrieve file: %s", err)
 | 
			
		||||
			}
 | 
			
		||||
 | 
			
		||||
		ignoreBody := cmp.FilterPath(func(p cmp.Path) bool { return p.String() == "Body" }, cmp.Ignore())
 | 
			
		||||
			if !cmp.Equal(retrieved, f.File, ignoreBody) {
 | 
			
		||||
				t.Errorf("Mismatch: %s", cmp.Diff(retrieved, f.File))
 | 
			
		||||
			}
 | 
			
		||||
@@ -154,4 +213,5 @@ func RunPersistentFilestoreTest(newStoreFunc func() files.FileStore, t *testing.
 | 
			
		||||
				t.Fatalf("Data does not match. %s", cmp.Diff(buf.String(), f.ExpectedData))
 | 
			
		||||
			}
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										2
									
								
								go.mod
									
									
									
									
									
								
							
							
						
						
									
										2
									
								
								go.mod
									
									
									
									
									
								
							@@ -9,6 +9,7 @@ require github.com/go-chi/chi/v5 v5.0.7
 | 
			
		||||
require (
 | 
			
		||||
	github.com/golang-jwt/jwt v3.2.2+incompatible
 | 
			
		||||
	github.com/google/go-cmp v0.5.6
 | 
			
		||||
	github.com/kirsle/configdir v0.0.0-20170128060238-e45d2f54772f
 | 
			
		||||
	github.com/pelletier/go-toml v1.9.4
 | 
			
		||||
	github.com/urfave/cli/v2 v2.3.0
 | 
			
		||||
	go.etcd.io/bbolt v1.3.6
 | 
			
		||||
@@ -23,4 +24,5 @@ require (
 | 
			
		||||
	go.uber.org/atomic v1.9.0 // indirect
 | 
			
		||||
	go.uber.org/multierr v1.7.0 // indirect
 | 
			
		||||
	golang.org/x/sys v0.0.0-20220114195835-da31bd327af9 // indirect
 | 
			
		||||
	golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
 | 
			
		||||
)
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										2
									
								
								go.sum
									
									
									
									
									
								
							
							
						
						
									
										2
									
								
								go.sum
									
									
									
									
									
								
							@@ -15,6 +15,8 @@ github.com/google/go-cmp v0.5.6 h1:BKbKCqvP6I+rmFHt06ZmyQtvB8xAkWdhFyr0ZUNZcxQ=
 | 
			
		||||
github.com/google/go-cmp v0.5.6/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
 | 
			
		||||
github.com/google/uuid v1.3.0 h1:t6JiXgmwXMjEs8VusXIJk2BXHsn+wx8BZdTaoZ5fu7I=
 | 
			
		||||
github.com/google/uuid v1.3.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
 | 
			
		||||
github.com/kirsle/configdir v0.0.0-20170128060238-e45d2f54772f h1:dKccXx7xA56UNqOcFIbuqFjAWPVtP688j5QMgmo6OHU=
 | 
			
		||||
github.com/kirsle/configdir v0.0.0-20170128060238-e45d2f54772f/go.mod h1:4rEELDSfUAlBSyUjPG0JnaNGjf13JySHFeRdD/3dLP0=
 | 
			
		||||
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
 | 
			
		||||
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
 | 
			
		||||
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
 | 
			
		||||
 
 | 
			
		||||
@@ -1,6 +1,10 @@
 | 
			
		||||
package users
 | 
			
		||||
 | 
			
		||||
import "golang.org/x/crypto/bcrypt"
 | 
			
		||||
import (
 | 
			
		||||
	"fmt"
 | 
			
		||||
 | 
			
		||||
	"golang.org/x/crypto/bcrypt"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
type Role string
 | 
			
		||||
 | 
			
		||||
@@ -12,14 +16,17 @@ const (
 | 
			
		||||
 | 
			
		||||
type User struct {
 | 
			
		||||
	Username       string `json:"username"`
 | 
			
		||||
	HashedPassword []byte `json:"hashed_password"`
 | 
			
		||||
	HashedPassword []byte `json:"hashedPassword"`
 | 
			
		||||
	Role           Role   `json:"role"`
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
var ErrNoSuchUser = fmt.Errorf("no such user")
 | 
			
		||||
 | 
			
		||||
type UserStore interface {
 | 
			
		||||
	Get(username string) (*User, error)
 | 
			
		||||
	Store(user *User) error
 | 
			
		||||
	Delete(username string) error
 | 
			
		||||
	List() ([]string, error)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (u *User) ValidatePassword(password string) error {
 | 
			
		||||
@@ -31,6 +38,8 @@ func (u *User) SetPassword(password string) error {
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	u.HashedPassword = hashed
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -6,6 +6,8 @@ import (
 | 
			
		||||
	"go.etcd.io/bbolt"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
var _ UserStore = &BoltUserStore{}
 | 
			
		||||
 | 
			
		||||
var keyUsers = []byte("users")
 | 
			
		||||
 | 
			
		||||
type BoltUserStore struct {
 | 
			
		||||
@@ -13,7 +15,7 @@ type BoltUserStore struct {
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func NewBoltUserStore(path string) (*BoltUserStore, error) {
 | 
			
		||||
	db, err := bbolt.Open(path, 0666, nil)
 | 
			
		||||
	db, err := bbolt.Open(path, 0666, nil) // nolint: gomnd
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
@@ -34,6 +36,7 @@ func (s *BoltUserStore) Close() error {
 | 
			
		||||
 | 
			
		||||
func (s *BoltUserStore) Get(username string) (*User, error) {
 | 
			
		||||
	var user User
 | 
			
		||||
 | 
			
		||||
	err := s.db.View(func(tx *bbolt.Tx) error {
 | 
			
		||||
		bkt := tx.Bucket(keyUsers)
 | 
			
		||||
		rawUser := bkt.Get([]byte(username))
 | 
			
		||||
@@ -42,9 +45,11 @@ func (s *BoltUserStore) Get(username string) (*User, error) {
 | 
			
		||||
		}
 | 
			
		||||
		return nil
 | 
			
		||||
	})
 | 
			
		||||
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return &user, nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
@@ -67,3 +72,23 @@ func (s *BoltUserStore) Delete(username string) error {
 | 
			
		||||
		return bkt.Delete([]byte(username))
 | 
			
		||||
	})
 | 
			
		||||
}
 | 
			
		||||
func (s *BoltUserStore) List() ([]string, error) {
 | 
			
		||||
	var ids []string
 | 
			
		||||
 | 
			
		||||
	err := s.db.View(func(tx *bbolt.Tx) error {
 | 
			
		||||
		bkt := tx.Bucket(keyUsers)
 | 
			
		||||
 | 
			
		||||
		c := bkt.Cursor()
 | 
			
		||||
 | 
			
		||||
		for k, _ := c.First(); k != nil; k, _ = c.Next() {
 | 
			
		||||
			ids = append(ids, string(k))
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		return nil
 | 
			
		||||
	})
 | 
			
		||||
	if err != nil {
 | 
			
		||||
		return nil, err
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return ids, nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -5,6 +5,8 @@ import (
 | 
			
		||||
	"sync"
 | 
			
		||||
)
 | 
			
		||||
 | 
			
		||||
var _ UserStore = &MemoryUserStore{}
 | 
			
		||||
 | 
			
		||||
type MemoryUserStore struct {
 | 
			
		||||
	users map[string]*User
 | 
			
		||||
	lock  sync.Mutex
 | 
			
		||||
@@ -16,7 +18,9 @@ func NewMemoryUserStore() *MemoryUserStore {
 | 
			
		||||
func (s *MemoryUserStore) Get(username string) (*User, error) {
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	user, ok := s.users[username]
 | 
			
		||||
 | 
			
		||||
	if !ok {
 | 
			
		||||
		return nil, fmt.Errorf("no such user: %s", username)
 | 
			
		||||
	}
 | 
			
		||||
@@ -27,13 +31,28 @@ func (s *MemoryUserStore) Get(username string) (*User, error) {
 | 
			
		||||
func (s *MemoryUserStore) Store(user *User) error {
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	s.users[user.Username] = user
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
func (s *MemoryUserStore) Delete(username string) error {
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	delete(s.users, username)
 | 
			
		||||
 | 
			
		||||
	return nil
 | 
			
		||||
}
 | 
			
		||||
func (s *MemoryUserStore) List() ([]string, error) {
 | 
			
		||||
	s.lock.Lock()
 | 
			
		||||
	defer s.lock.Unlock()
 | 
			
		||||
 | 
			
		||||
	ids := make([]string, 0, len(s.users))
 | 
			
		||||
	for k := range s.users {
 | 
			
		||||
		ids = append(ids, k)
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	return ids, nil
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -47,5 +47,27 @@ func RunUserStoreTest(newFunc func() (func(), users.UserStore), t *testing.T) {
 | 
			
		||||
				t.Errorf("User mismatch: %s", cmp.Diff(user, userMap[k]))
 | 
			
		||||
			}
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		l, err := s.List()
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error listing users: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
		if len(l) != len(userMap) {
 | 
			
		||||
			t.Errorf("List wrong amount of users.")
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		for _, username := range l {
 | 
			
		||||
			if err := s.Delete(username); err != nil {
 | 
			
		||||
				t.Fatalf("Error deleting user: %s", err)
 | 
			
		||||
			}
 | 
			
		||||
		}
 | 
			
		||||
 | 
			
		||||
		l, err = s.List()
 | 
			
		||||
		if err != nil {
 | 
			
		||||
			t.Fatalf("Error listing after delete: %s", err)
 | 
			
		||||
		}
 | 
			
		||||
		if len(l) != 0 {
 | 
			
		||||
			t.Fatalf("List is not empty after deleting all")
 | 
			
		||||
		}
 | 
			
		||||
	})
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user