Skip to content
Extraits de code Groupes Projets
request.rb 4,03 ko
Newer Older
  • Learn to ignore specific revisions
  • Eugen Rochko's avatar
    Eugen Rochko a validé
    # frozen_string_literal: true
    
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
    class Request
      REQUEST_TARGET = '(request-target)'
    
      include RoutingHelper
    
    
      def initialize(verb, url, **options)
    
        raise ArgumentError if url.blank?
    
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
        @verb    = verb
        @url     = Addressable::URI.parse(url).normalize
    
        @options = options.merge(use_proxy? ? Rails.configuration.x.http_client_proxy : { socket_class: Socket })
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
        @headers = {}
    
    
        raise Mastodon::HostValidationError, 'Instance does not support hidden service connections' if block_hidden_service?
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
        set_common_headers!
    
      def on_behalf_of(account, key_id_format = :acct)
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
        raise ArgumentError unless account.local?
    
    
        @account       = account
        @key_id_format = key_id_format
    
        self
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      end
    
      def add_headers(new_headers)
        @headers.merge!(new_headers)
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      end
    
      def perform
    
        begin
          response = http_client.headers(headers).public_send(@verb, @url.to_s, @options)
        rescue => e
          raise e.class, "#{e.message} on #{@url}", e.backtrace[0]
        end
    
        begin
    
          yield response.extend(ClientLimit)
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      end
    
      def headers
        (@account ? @headers.merge('Signature' => signature) : @headers).without(REQUEST_TARGET)
      end
    
      private
    
      def set_common_headers!
        @headers[REQUEST_TARGET] = "#{@verb} #{@url.path}"
        @headers['User-Agent']   = user_agent
        @headers['Host']         = @url.host
        @headers['Date']         = Time.now.utc.httpdate
      end
    
    
      def set_digest!
        @headers['Digest'] = "SHA-256=#{Digest::SHA256.base64digest(@options[:body])}"
      end
    
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      def signature
        algorithm = 'rsa-sha256'
        signature = Base64.strict_encode64(@account.keypair.sign(OpenSSL::Digest::SHA256.new, signed_string))
    
        "keyId=\"#{key_id}\",algorithm=\"#{algorithm}\",headers=\"#{signed_headers}\",signature=\"#{signature}\""
      end
    
      def signed_string
        @headers.map { |key, value| "#{key.downcase}: #{value}" }.join("\n")
      end
    
      def signed_headers
        @headers.keys.join(' ').downcase
      end
    
      def user_agent
        @user_agent ||= "#{HTTP::Request::USER_AGENT} (Mastodon/#{Mastodon::Version}; +#{root_url})"
      end
    
    
      def key_id
        case @key_id_format
        when :acct
          @account.to_webfinger_s
        when :uri
          [ActivityPub::TagManager.instance.uri_for(@account), '#main-key'].join
        end
      end
    
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      def timeout
        { write: 10, connect: 10, read: 10 }
      end
    
      def http_client
    
        @http_client ||= HTTP.timeout(:per_operation, timeout).follow(max_hops: 2)
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
      end
    
      def use_proxy?
        Rails.configuration.x.http_client_proxy.present?
      end
    
      def block_hidden_service?
        !Rails.configuration.x.access_to_hidden_service && /\.(onion|i2p)$/.match(@url.host)
      end
    
    
      module ClientLimit
        def body_with_limit(limit = 1.megabyte)
          raise Mastodon::LengthValidationError if content_length.present? && content_length > limit
    
          if charset.nil?
            encoding = Encoding::BINARY
          else
            begin
              encoding = Encoding.find(charset)
            rescue ArgumentError
              encoding = Encoding::BINARY
            end
          end
    
          contents = String.new(encoding: encoding)
    
          while (chunk = readpartial)
            contents << chunk
            chunk.clear
    
            raise Mastodon::LengthValidationError if contents.bytesize > limit
          end
    
          contents
        end
      end
    
    
      class Socket < TCPSocket
        class << self
          def open(host, *args)
    
            return super host, *args if thru_hidden_service? host
    
            outer_e = nil
            Addrinfo.foreach(host, nil, nil, :SOCK_STREAM) do |address|
              begin
                raise Mastodon::HostValidationError if PrivateAddressCheck.private_address? IPAddr.new(address.ip_address)
                return super address.ip_address, *args
              rescue => e
                outer_e = e
              end
            end
            raise outer_e if outer_e
    
    
          def thru_hidden_service?(host)
            Rails.configuration.x.hidden_service_via_transparent_proxy && /\.(onion|i2p)$/.match(host)
          end
    
      private_constant :ClientLimit, :Socket
    
    Eugen Rochko's avatar
    Eugen Rochko a validé
    end