mirror of
https://github.com/hacdias/webdav.git
synced 2026-09-24 04:01:54 +08:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6aeb3f8a30 | ||
|
|
59c5f1343f |
+9
-45
@@ -2,7 +2,6 @@ package lib
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/url"
|
|
||||||
"os"
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -19,7 +18,6 @@ type handlerUser struct {
|
|||||||
type Handler struct {
|
type Handler struct {
|
||||||
noPassword bool
|
noPassword bool
|
||||||
behindProxy bool
|
behindProxy bool
|
||||||
prefix string
|
|
||||||
user *handlerUser
|
user *handlerUser
|
||||||
users map[string]*handlerUser
|
users map[string]*handlerUser
|
||||||
}
|
}
|
||||||
@@ -28,12 +26,12 @@ func NewHandler(c *Config) (http.Handler, error) {
|
|||||||
h := &Handler{
|
h := &Handler{
|
||||||
noPassword: c.NoPassword,
|
noPassword: c.NoPassword,
|
||||||
behindProxy: c.BehindProxy,
|
behindProxy: c.BehindProxy,
|
||||||
prefix: c.Prefix,
|
|
||||||
user: &handlerUser{
|
user: &handlerUser{
|
||||||
User: User{
|
User: User{
|
||||||
UserPermissions: c.UserPermissions,
|
UserPermissions: c.UserPermissions,
|
||||||
},
|
},
|
||||||
Handler: webdav.Handler{
|
Handler: webdav.Handler{
|
||||||
|
Prefix: c.Prefix,
|
||||||
FileSystem: Dir{
|
FileSystem: Dir{
|
||||||
Dir: webdav.Dir(c.Directory),
|
Dir: webdav.Dir(c.Directory),
|
||||||
noSniff: c.NoSniff,
|
noSniff: c.NoSniff,
|
||||||
@@ -48,6 +46,7 @@ func NewHandler(c *Config) (http.Handler, error) {
|
|||||||
h.users[u.Username] = &handlerUser{
|
h.users[u.Username] = &handlerUser{
|
||||||
User: u,
|
User: u,
|
||||||
Handler: webdav.Handler{
|
Handler: webdav.Handler{
|
||||||
|
Prefix: c.Prefix,
|
||||||
FileSystem: Dir{
|
FileSystem: Dir{
|
||||||
Dir: webdav.Dir(u.Directory),
|
Dir: webdav.Dir(u.Directory),
|
||||||
noSniff: c.NoSniff,
|
noSniff: c.NoSniff,
|
||||||
@@ -116,51 +115,16 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
|||||||
zap.L().Info("user authorized", zap.String("username", username), zap.String("remote_address", remoteAddr))
|
zap.L().Info("user authorized", zap.String("username", username), zap.String("remote_address", remoteAddr))
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate and clean destination header if it exists, by stripping out the
|
// Convert the HTTP request into an internal request type
|
||||||
// prefix and only keeping the actual destination path, always prefixed by
|
req, err := newRequest(r, h.user.Prefix)
|
||||||
// a forward slash to ensure that the rules can successful match the path.
|
if err != nil {
|
||||||
if destination := r.Header.Get("Destination"); destination != "" {
|
zap.L().Info("invalid request path or destination", zap.Error(err))
|
||||||
u, err := url.Parse(destination)
|
http.Error(w, "Invalid request path or destination", http.StatusBadRequest)
|
||||||
if err != nil {
|
return
|
||||||
http.Error(w, "Invalid Destination header", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
if h.prefix != "" {
|
|
||||||
destination = strings.TrimPrefix(u.Path, h.prefix)
|
|
||||||
if len(destination) >= len(u.Path) {
|
|
||||||
http.Error(w, "Invalid URL prefix", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if !strings.HasPrefix(destination, "/") {
|
|
||||||
destination = "/" + destination
|
|
||||||
}
|
|
||||||
|
|
||||||
r.Header.Set("Destination", destination)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Clean up URL path by stripping out the prefix, and ensuring it always begins
|
|
||||||
// with a forward slash, so that it can match against the rules.
|
|
||||||
path := r.URL.Path
|
|
||||||
|
|
||||||
if h.prefix != "" {
|
|
||||||
path = strings.TrimPrefix(r.URL.Path, h.prefix)
|
|
||||||
if len(path) >= len(r.URL.Path) {
|
|
||||||
http.Error(w, "Invalid URL prefix", http.StatusBadRequest)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if !strings.HasPrefix(path, "/") {
|
|
||||||
path = "/" + path
|
|
||||||
}
|
|
||||||
|
|
||||||
r.URL.Path = path
|
|
||||||
|
|
||||||
// Checks for user permissions relatively to this PATH.
|
// Checks for user permissions relatively to this PATH.
|
||||||
allowed := user.Allowed(r, func(filename string) bool {
|
allowed := user.Allowed(req, func(filename string) bool {
|
||||||
_, err := user.FileSystem.Stat(r.Context(), filename)
|
_, err := user.FileSystem.Stat(r.Context(), filename)
|
||||||
return !os.IsNotExist(err)
|
return !os.IsNotExist(err)
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -292,82 +292,6 @@ users:
|
|||||||
require.ErrorContains(t, err, "403")
|
require.ErrorContains(t, err, "403")
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestServerRulesPrefix(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
dir := makeTestDirectory(t, map[string][]byte{
|
|
||||||
"foo.txt": []byte("foo"),
|
|
||||||
"bar.js": []byte("foo js"),
|
|
||||||
"a/foo.js": []byte("foo js"),
|
|
||||||
"a/foo.txt": []byte("foo txt"),
|
|
||||||
"b/foo.txt": []byte("foo b"),
|
|
||||||
"c/a.txt": []byte("b"),
|
|
||||||
"c/b.txt": []byte("b"),
|
|
||||||
"c/c.txt": []byte("b"),
|
|
||||||
})
|
|
||||||
|
|
||||||
srv := makeTestServer(t, fmt.Sprintf(`
|
|
||||||
directory: %s
|
|
||||||
permissions: CRUD
|
|
||||||
prefix: /prefix
|
|
||||||
|
|
||||||
users:
|
|
||||||
- username: basic
|
|
||||||
password: basic
|
|
||||||
rules:
|
|
||||||
- regex: "^.+.js$"
|
|
||||||
permissions: R
|
|
||||||
- path: "/b/"
|
|
||||||
permissions: R
|
|
||||||
- path: "/a/foo.txt"
|
|
||||||
permissions: none
|
|
||||||
- path: "/c/"
|
|
||||||
permissions: none
|
|
||||||
`, dir))
|
|
||||||
|
|
||||||
client := gowebdav.NewClient(srv.URL, "basic", "basic")
|
|
||||||
|
|
||||||
files, err := client.ReadDir("/prefix")
|
|
||||||
require.NoError(t, err)
|
|
||||||
require.Len(t, files, 5)
|
|
||||||
|
|
||||||
err = client.Write("/prefix/foo.txt", []byte("new"), 0666)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
err = client.Write("/prefix/new.txt", []byte("new"), 0666)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
err = client.Copy("/prefix/bar.js", "/prefix/b/bar.js", false)
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
err = client.Copy("/prefix/bar.js", "/prefix/bar.jsx", false)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
err = client.Copy("/prefix/b/foo.txt", "/prefix/foo1.txt", false)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
err = client.Rename("/prefix/b/foo.txt", "/prefix/foo2.txt", false)
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
_, err = client.Read("/prefix/a/foo.txt")
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
err = client.Write("/prefix/a/foo.js", []byte("new"), 0666)
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
err = client.Write("/prefix/b/foo.txt", []byte("new"), 0666)
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
_, err = client.ReadDir("/prefix/c")
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
_, err = client.Read("/prefix/c/a.txt")
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
|
|
||||||
err = client.Write("/prefix/c/b.txt", []byte("new"), 0666)
|
|
||||||
require.ErrorContains(t, err, "403")
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestServerPermissions(t *testing.T) {
|
func TestServerPermissions(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
|
|||||||
+10
-11
@@ -3,7 +3,6 @@ package lib
|
|||||||
import (
|
import (
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"net/http"
|
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
@@ -51,12 +50,12 @@ type UserPermissions struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Allowed checks if the user has permission to access a directory/file
|
// Allowed checks if the user has permission to access a directory/file
|
||||||
func (p UserPermissions) Allowed(r *http.Request, fileExists func(string) bool) bool {
|
func (p UserPermissions) Allowed(r *request, fileExists func(string) bool) bool {
|
||||||
// For COPY and MOVE requests, we first check the permissions for the destination
|
// For COPY and MOVE requests, we first check the permissions for the destination
|
||||||
// path. As soon as a rule matches and does not allow the operation at the destination,
|
// path. As soon as a rule matches and does not allow the operation at the destination,
|
||||||
// we fail immediately. If no rule matches, we check the global permissions.
|
// we fail immediately. If no rule matches, we check the global permissions.
|
||||||
if r.Method == "COPY" || r.Method == "MOVE" {
|
if r.method == "COPY" || r.method == "MOVE" {
|
||||||
dst := r.Header.Get("Destination")
|
dst := r.destination
|
||||||
|
|
||||||
for i := len(p.Rules) - 1; i >= 0; i-- {
|
for i := len(p.Rules) - 1; i >= 0; i-- {
|
||||||
if p.Rules[i].Matches(dst) {
|
if p.Rules[i].Matches(dst) {
|
||||||
@@ -77,7 +76,7 @@ func (p UserPermissions) Allowed(r *http.Request, fileExists func(string) bool)
|
|||||||
// Go through rules beginning from the last one, and check the permissions at
|
// Go through rules beginning from the last one, and check the permissions at
|
||||||
// the source. The first matched rule returns.
|
// the source. The first matched rule returns.
|
||||||
for i := len(p.Rules) - 1; i >= 0; i-- {
|
for i := len(p.Rules) - 1; i >= 0; i-- {
|
||||||
if p.Rules[i].Matches(r.URL.Path) {
|
if p.Rules[i].Matches(r.path) {
|
||||||
return p.Rules[i].Permissions.Allowed(r, fileExists)
|
return p.Rules[i].Permissions.Allowed(r, fileExists)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -142,8 +141,8 @@ func (p *Permissions) UnmarshalText(data []byte) error {
|
|||||||
|
|
||||||
// Allowed returns whether this permission set has permissions to execute this
|
// Allowed returns whether this permission set has permissions to execute this
|
||||||
// request in the source directory. This applies to all requests with all methods.
|
// request in the source directory. This applies to all requests with all methods.
|
||||||
func (p Permissions) Allowed(r *http.Request, fileExists func(string) bool) bool {
|
func (p Permissions) Allowed(r *request, fileExists func(string) bool) bool {
|
||||||
switch r.Method {
|
switch r.method {
|
||||||
case "GET", "HEAD", "OPTIONS", "POST", "PROPFIND":
|
case "GET", "HEAD", "OPTIONS", "POST", "PROPFIND":
|
||||||
// Note: POST backend implementation just returns the same thing as GET.
|
// Note: POST backend implementation just returns the same thing as GET.
|
||||||
return p.Read
|
return p.Read
|
||||||
@@ -152,7 +151,7 @@ func (p Permissions) Allowed(r *http.Request, fileExists func(string) bool) bool
|
|||||||
case "PROPPATCH":
|
case "PROPPATCH":
|
||||||
return p.Update
|
return p.Update
|
||||||
case "PUT":
|
case "PUT":
|
||||||
if fileExists(r.URL.Path) {
|
if fileExists(r.path) {
|
||||||
return p.Update
|
return p.Update
|
||||||
} else {
|
} else {
|
||||||
return p.Create
|
return p.Create
|
||||||
@@ -172,10 +171,10 @@ func (p Permissions) Allowed(r *http.Request, fileExists func(string) bool) bool
|
|||||||
|
|
||||||
// AllowedDestination returns whether this permissions set has permissions to execute this
|
// AllowedDestination returns whether this permissions set has permissions to execute this
|
||||||
// request in the destination directory. This only applies for COPY and MOVE requests.
|
// request in the destination directory. This only applies for COPY and MOVE requests.
|
||||||
func (p Permissions) AllowedDestination(r *http.Request, fileExists func(string) bool) bool {
|
func (p Permissions) AllowedDestination(r *request, fileExists func(string) bool) bool {
|
||||||
switch r.Method {
|
switch r.method {
|
||||||
case "COPY", "MOVE":
|
case "COPY", "MOVE":
|
||||||
if fileExists(r.Header.Get("Destination")) {
|
if fileExists(r.destination) {
|
||||||
return p.Update
|
return p.Update
|
||||||
} else {
|
} else {
|
||||||
return p.Create
|
return p.Create
|
||||||
|
|||||||
@@ -0,0 +1,57 @@
|
|||||||
|
package lib
|
||||||
|
|
||||||
|
import (
|
||||||
|
"errors"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"strings"
|
||||||
|
)
|
||||||
|
|
||||||
|
type request struct {
|
||||||
|
method string
|
||||||
|
path string
|
||||||
|
destination string
|
||||||
|
}
|
||||||
|
|
||||||
|
func newRequest(r *http.Request, prefix string) (*request, error) {
|
||||||
|
ctx := &request{
|
||||||
|
method: r.Method,
|
||||||
|
}
|
||||||
|
|
||||||
|
if destination := r.Header.Get("Destination"); destination != "" {
|
||||||
|
u, err := url.Parse(destination)
|
||||||
|
if err != nil {
|
||||||
|
return nil, errors.New("invalid destination header")
|
||||||
|
}
|
||||||
|
|
||||||
|
if prefix != "" {
|
||||||
|
destination = strings.TrimPrefix(u.Path, prefix)
|
||||||
|
if len(destination) >= len(u.Path) {
|
||||||
|
return nil, errors.New("invalid url prefix")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if !strings.HasPrefix(destination, "/") {
|
||||||
|
destination = "/" + destination
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx.destination = destination
|
||||||
|
}
|
||||||
|
|
||||||
|
path := r.URL.Path
|
||||||
|
|
||||||
|
if prefix != "" {
|
||||||
|
path = strings.TrimPrefix(r.URL.Path, prefix)
|
||||||
|
if len(path) >= len(r.URL.Path) {
|
||||||
|
return nil, errors.New("invalid url prefix")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if !strings.HasPrefix(path, "/") {
|
||||||
|
path = "/" + path
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx.path = path
|
||||||
|
|
||||||
|
return ctx, nil
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user