2018-04-10 22:02:48 +02:00
|
|
|
package app
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2018-04-14 20:49:39 +02:00
|
|
|
log "github.com/sirupsen/logrus"
|
2018-04-10 22:02:48 +02:00
|
|
|
"golang.org/x/net/webdav"
|
|
|
|
"os"
|
|
|
|
"path"
|
|
|
|
"path/filepath"
|
|
|
|
"strings"
|
|
|
|
)
|
|
|
|
|
|
|
|
// This file is an extension of golang.org/x/net/webdav/file.go.
|
|
|
|
|
2018-04-11 16:19:00 +02:00
|
|
|
// Dir is specialization of webdav.Dir with respect of an authenticated
|
|
|
|
// user to allow configuration access.
|
|
|
|
type Dir struct {
|
|
|
|
Config *Config
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
2018-04-14 20:49:39 +02:00
|
|
|
func (d Dir) resolveUser(ctx context.Context) string {
|
2018-05-19 20:58:57 +02:00
|
|
|
authInfo := AuthFromContext(ctx)
|
2018-04-14 20:49:39 +02:00
|
|
|
if authInfo != nil && authInfo.Authenticated {
|
|
|
|
return authInfo.Username
|
|
|
|
}
|
|
|
|
|
|
|
|
return ""
|
|
|
|
}
|
|
|
|
|
2018-04-10 22:02:48 +02:00
|
|
|
// resolve tries to gain authentication information and suffixes the BaseDir with the
|
|
|
|
// username of the authentication information. If none authentication information can
|
|
|
|
// achieved during the process, the BaseDir is used
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) resolve(ctx context.Context, name string) string {
|
2018-04-10 22:02:48 +02:00
|
|
|
// This implementation is based on Dir.Open's code in the standard net/http package.
|
|
|
|
if filepath.Separator != '/' && strings.IndexRune(name, filepath.Separator) >= 0 ||
|
|
|
|
strings.Contains(name, "\x00") {
|
|
|
|
return ""
|
|
|
|
}
|
2018-04-11 16:19:00 +02:00
|
|
|
dir := string(d.Config.Dir)
|
2018-04-10 22:02:48 +02:00
|
|
|
if dir == "" {
|
|
|
|
dir = "."
|
|
|
|
}
|
|
|
|
|
2018-05-19 20:58:57 +02:00
|
|
|
// Second barrier after basic auth process
|
|
|
|
authInfo := AuthFromContext(ctx)
|
2018-04-11 16:19:00 +02:00
|
|
|
if authInfo != nil && authInfo.Authenticated {
|
|
|
|
userInfo := d.Config.Users[authInfo.Username]
|
|
|
|
if userInfo != nil && userInfo.Subdir != nil {
|
2018-04-23 17:33:36 +02:00
|
|
|
return filepath.Join(dir, *userInfo.Subdir, filepath.FromSlash(path.Clean("/"+name)))
|
2018-04-11 16:19:00 +02:00
|
|
|
}
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
2018-04-11 16:19:00 +02:00
|
|
|
return filepath.Join(dir, filepath.FromSlash(path.Clean("/"+name)))
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Mkdir resolves the physical file and delegates this to an os.Mkdir execution
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) Mkdir(ctx context.Context, name string, perm os.FileMode) error {
|
2018-04-10 22:02:48 +02:00
|
|
|
if name = d.resolve(ctx, name); name == "" {
|
|
|
|
return os.ErrNotExist
|
|
|
|
}
|
2018-04-14 20:49:39 +02:00
|
|
|
err := os.Mkdir(name, perm)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if d.Config.Log.Create {
|
|
|
|
log.WithFields(log.Fields{
|
|
|
|
"path": name,
|
|
|
|
"user": d.resolveUser(ctx),
|
|
|
|
}).Info("Created directory")
|
|
|
|
}
|
|
|
|
|
|
|
|
return err
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// OpenFile resolves the physical file and delegates this to an os.OpenFile execution
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) OpenFile(ctx context.Context, name string, flag int, perm os.FileMode) (webdav.File, error) {
|
2018-04-10 22:02:48 +02:00
|
|
|
if name = d.resolve(ctx, name); name == "" {
|
|
|
|
return nil, os.ErrNotExist
|
|
|
|
}
|
|
|
|
f, err := os.OpenFile(name, flag, perm)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2018-04-14 20:49:39 +02:00
|
|
|
|
|
|
|
if d.Config.Log.Read {
|
|
|
|
log.WithFields(log.Fields{
|
|
|
|
"path": name,
|
|
|
|
"user": d.resolveUser(ctx),
|
|
|
|
}).Info("Opened file")
|
|
|
|
}
|
|
|
|
|
2018-04-10 22:02:48 +02:00
|
|
|
return f, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// RemoveAll resolves the physical file and delegates this to an os.RemoveAll execution
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) RemoveAll(ctx context.Context, name string) error {
|
2018-04-10 22:02:48 +02:00
|
|
|
if name = d.resolve(ctx, name); name == "" {
|
|
|
|
return os.ErrNotExist
|
|
|
|
}
|
2018-04-11 16:19:00 +02:00
|
|
|
if name == filepath.Clean(string(d.Config.Dir)) {
|
2018-04-10 22:02:48 +02:00
|
|
|
// Prohibit removing the virtual root directory.
|
|
|
|
return os.ErrInvalid
|
|
|
|
}
|
2018-04-14 20:49:39 +02:00
|
|
|
|
|
|
|
err := os.RemoveAll(name)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if d.Config.Log.Delete {
|
|
|
|
log.WithFields(log.Fields{
|
|
|
|
"path": name,
|
|
|
|
"user": d.resolveUser(ctx),
|
|
|
|
}).Info("Deleted file or directory")
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Rename resolves the physical file and delegates this to an os.Rename execution
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) Rename(ctx context.Context, oldName, newName string) error {
|
2018-04-10 22:02:48 +02:00
|
|
|
if oldName = d.resolve(ctx, oldName); oldName == "" {
|
|
|
|
return os.ErrNotExist
|
|
|
|
}
|
|
|
|
if newName = d.resolve(ctx, newName); newName == "" {
|
|
|
|
return os.ErrNotExist
|
|
|
|
}
|
2018-04-11 16:19:00 +02:00
|
|
|
if root := filepath.Clean(string(d.Config.Dir)); root == oldName || root == newName {
|
2018-04-10 22:02:48 +02:00
|
|
|
// Prohibit renaming from or to the virtual root directory.
|
|
|
|
return os.ErrInvalid
|
|
|
|
}
|
2018-04-14 20:49:39 +02:00
|
|
|
|
|
|
|
err := os.Rename(oldName, newName)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if d.Config.Log.Update {
|
|
|
|
log.WithFields(log.Fields{
|
|
|
|
"oldPath": oldName,
|
|
|
|
"newPath": newName,
|
|
|
|
"user": d.resolveUser(ctx),
|
|
|
|
}).Info("Renamed file or directory")
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
2018-04-10 22:02:48 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Stat resolves the physical file and delegates this to an os.Stat execution
|
2018-04-11 16:19:00 +02:00
|
|
|
func (d Dir) Stat(ctx context.Context, name string) (os.FileInfo, error) {
|
2018-04-10 22:02:48 +02:00
|
|
|
if name = d.resolve(ctx, name); name == "" {
|
|
|
|
return nil, os.ErrNotExist
|
|
|
|
}
|
|
|
|
return os.Stat(name)
|
|
|
|
}
|