forked from tildetown/bbj2
382 lines
8.2 KiB
Go
382 lines
8.2 KiB
Go
package main
|
|
|
|
import (
|
|
"database/sql"
|
|
_ "embed"
|
|
"encoding/json"
|
|
"errors"
|
|
"flag"
|
|
"fmt"
|
|
"io"
|
|
"net/http"
|
|
"os"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/google/uuid"
|
|
_ "github.com/mattn/go-sqlite3"
|
|
)
|
|
|
|
//go:embed schema.sql
|
|
var schemaSQL string
|
|
|
|
type Config struct {
|
|
Admins []string
|
|
Port int
|
|
Host string
|
|
InstanceName string `yaml:"instance_name"`
|
|
AllowAnon bool `yaml:"allow_anon"`
|
|
Debug bool
|
|
DBPath string `yaml:"db_path"`
|
|
}
|
|
|
|
type iostreams struct {
|
|
Err io.Writer
|
|
Out io.Writer
|
|
}
|
|
|
|
type Opts struct {
|
|
ConfigPath string
|
|
IO iostreams
|
|
Log func(string)
|
|
Logf func(string, ...interface{})
|
|
Config Config
|
|
DB *sql.DB
|
|
Reset bool
|
|
}
|
|
|
|
func main() {
|
|
var configFlag = flag.String("config", "config.yml", "A path to a config file.")
|
|
var resetFlag = flag.Bool("reset", false, "reset the database. WARNING this wipes everything.")
|
|
flag.Parse()
|
|
io := iostreams{
|
|
Err: os.Stderr,
|
|
Out: os.Stdout,
|
|
}
|
|
opts := &Opts{
|
|
ConfigPath: *configFlag,
|
|
Reset: *resetFlag,
|
|
IO: io,
|
|
// TODO use real logger
|
|
Log: func(s string) {
|
|
fmt.Fprintln(io.Out, s)
|
|
},
|
|
Logf: func(s string, args ...interface{}) {
|
|
fmt.Fprintf(io.Out, s, args...)
|
|
fmt.Fprintf(io.Out, "\n")
|
|
},
|
|
}
|
|
|
|
err := _main(opts)
|
|
if err != nil {
|
|
fmt.Fprintf(os.Stderr, "failed: %s", err)
|
|
}
|
|
}
|
|
|
|
type Teardown func()
|
|
|
|
func setupDB(opts *Opts) (Teardown, error) {
|
|
db, err := sql.Open("sqlite3", opts.Config.DBPath)
|
|
fmt.Printf("DBG %#v\n", db)
|
|
|
|
opts.DB = db
|
|
|
|
return func() { db.Close() }, err
|
|
}
|
|
|
|
func _main(opts *Opts) error {
|
|
cfg, err := parseConfig(opts.ConfigPath)
|
|
if err != nil {
|
|
fmt.Fprintf(os.Stderr, "could not read config file '%s'", opts.ConfigPath)
|
|
os.Exit(1)
|
|
}
|
|
|
|
opts.Config = *cfg
|
|
|
|
teardown, err := setupDB(opts)
|
|
if err != nil {
|
|
return fmt.Errorf("could not initialize DB: %w", err)
|
|
}
|
|
defer teardown()
|
|
|
|
err = ensureSchema(*opts)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
setupAPI(*opts)
|
|
|
|
// TODO TLS or SSL or something
|
|
opts.Logf("starting server at %s:%d", cfg.Host, cfg.Port)
|
|
if err := http.ListenAndServe(fmt.Sprintf("%s:%d", cfg.Host, cfg.Port), nil); err != nil {
|
|
return fmt.Errorf("http server exited with error: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func ensureSchema(opts Opts) error {
|
|
db := opts.DB
|
|
|
|
if opts.Reset {
|
|
err := os.Remove(opts.Config.DBPath)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to delete database: %w", err)
|
|
}
|
|
}
|
|
rows, err := db.Query("select version from meta")
|
|
if err == nil {
|
|
defer rows.Close()
|
|
rows.Next()
|
|
var version string
|
|
err = rows.Scan(&version)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to check database schema version: %w", err)
|
|
} else if version == "" {
|
|
return errors.New("database is in unknown state")
|
|
}
|
|
return nil
|
|
}
|
|
|
|
if !strings.Contains(err.Error(), "no such table") {
|
|
return fmt.Errorf("got error checking database state: %w", err)
|
|
}
|
|
|
|
_, err = db.Exec(schemaSQL)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to initialize database schema: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func handler(opts Opts, f http.HandlerFunc) http.HandlerFunc {
|
|
// TODO make this more real
|
|
return func(w http.ResponseWriter, req *http.Request) {
|
|
opts.Log(req.URL.Path)
|
|
// TODO add user info to opts
|
|
f(w, req)
|
|
}
|
|
}
|
|
|
|
// TODO I'm not entirely sold on this hash system; without transport
|
|
// encryption, it doesn't really help anything. I'd rather have plaintext +
|
|
// transport encryption and then, on the server side, proper salted hashing.
|
|
|
|
type User struct {
|
|
// TODO
|
|
ID string
|
|
}
|
|
|
|
type BBJResponse struct {
|
|
Error bool `json:"error"`
|
|
Data interface{} `json:"data"`
|
|
Usermap map[string]User `json:"usermap"`
|
|
}
|
|
|
|
func writeResponse(w http.ResponseWriter, resp BBJResponse) {
|
|
w.WriteHeader(http.StatusOK)
|
|
w.Header().Set("Content-Type", "application/json")
|
|
json.NewEncoder(w).Encode(resp)
|
|
}
|
|
|
|
func writeErrorResponse(w http.ResponseWriter, code int, resp BBJResponse) {
|
|
w.WriteHeader(code)
|
|
w.Header().Set("Content-Type", "application/json")
|
|
json.NewEncoder(w).Encode(resp)
|
|
}
|
|
|
|
// NB breaking: i'm not just returning 200 always but using http status codes
|
|
|
|
func setupAPI(opts Opts) {
|
|
|
|
http.HandleFunc("/instance_info", handler(opts, func(w http.ResponseWriter, req *http.Request) {
|
|
|
|
type instanceInfo struct {
|
|
InstanceName string `json:"instance_name"`
|
|
AllowAnon bool `json:"allow_anon"`
|
|
Admins []string
|
|
}
|
|
writeResponse(w, BBJResponse{
|
|
Data: instanceInfo{
|
|
InstanceName: opts.Config.InstanceName,
|
|
AllowAnon: opts.Config.AllowAnon,
|
|
Admins: opts.Config.Admins,
|
|
},
|
|
})
|
|
}))
|
|
|
|
serverErr := func(w http.ResponseWriter, err error) {
|
|
opts.Logf(err.Error())
|
|
writeErrorResponse(w, 500, BBJResponse{
|
|
Error: true,
|
|
Data: "server error",
|
|
})
|
|
}
|
|
|
|
badMethod := func(w http.ResponseWriter) {
|
|
writeErrorResponse(w, 400, BBJResponse{
|
|
Error: true,
|
|
Data: "bad method",
|
|
})
|
|
}
|
|
|
|
invalidArgs := func(w http.ResponseWriter) {
|
|
writeErrorResponse(w, 400, BBJResponse{
|
|
Error: true,
|
|
Data: "invalid args",
|
|
})
|
|
}
|
|
|
|
http.HandleFunc("/user_register", handler(opts, func(w http.ResponseWriter, req *http.Request) {
|
|
if req.Method != "POST" {
|
|
badMethod(w)
|
|
return
|
|
}
|
|
|
|
type AuthArgs struct {
|
|
Username string `json:"user_name"`
|
|
AuthHash string `json:"auth_hash"`
|
|
}
|
|
|
|
var args AuthArgs
|
|
if err := json.NewDecoder(req.Body).Decode(&args); err != nil {
|
|
invalidArgs(w)
|
|
return
|
|
}
|
|
|
|
if args.AuthHash == "" || args.Username == "" {
|
|
invalidArgs(w)
|
|
return
|
|
}
|
|
|
|
db := opts.DB
|
|
stmt, err := db.Prepare("select auth_hash from users where user_name = ?")
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
defer stmt.Close()
|
|
|
|
opts.Logf("querying for %s", args.Username)
|
|
|
|
var authHash string
|
|
err = stmt.QueryRow(args.Username).Scan(&authHash)
|
|
if err == nil {
|
|
opts.Logf("found %s", args.Username)
|
|
// code 4 apparently
|
|
writeErrorResponse(w, 403, BBJResponse{
|
|
Error: true,
|
|
Data: "user already exists",
|
|
})
|
|
return
|
|
} else if err != nil && !strings.Contains(err.Error(), "no rows in result") {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
|
|
stmt, err = db.Prepare(`INSERT INTO users VALUES (?, ?, ?, "", "", 0, 0, ?)`)
|
|
id, err := uuid.NewRandom()
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
|
|
_, err = stmt.Exec(id, args.Username, args.AuthHash, time.Now())
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
}
|
|
|
|
writeResponse(w, BBJResponse{
|
|
Data: true, // TODO probably something else
|
|
// TODO prob usermap
|
|
})
|
|
}))
|
|
|
|
http.HandleFunc("/check_auth", handler(opts, func(w http.ResponseWriter, req *http.Request) {
|
|
if req.Method != "POST" {
|
|
badMethod(w)
|
|
return
|
|
}
|
|
|
|
type AuthArgs struct {
|
|
Username string `json:"target_user"`
|
|
AuthHash string `json:"target_hash"`
|
|
}
|
|
|
|
var args AuthArgs
|
|
if err := json.NewDecoder(req.Body).Decode(&args); err != nil {
|
|
invalidArgs(w)
|
|
return
|
|
}
|
|
|
|
opts.Logf("got %s %s", args.Username, args.AuthHash)
|
|
|
|
db := opts.DB
|
|
|
|
stmt, err := db.Prepare("select auth_hash from users where user_name = ?")
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
defer stmt.Close()
|
|
|
|
var authHash string
|
|
err = stmt.QueryRow(args.Username).Scan(&authHash)
|
|
if err != nil {
|
|
if strings.Contains(err.Error(), "no rows in result") {
|
|
opts.Logf("user not found")
|
|
writeErrorResponse(w, 404, BBJResponse{
|
|
Error: true,
|
|
Data: "user not found",
|
|
})
|
|
} else {
|
|
serverErr(w, err)
|
|
}
|
|
return
|
|
}
|
|
|
|
// TODO unique constraint on user_name
|
|
|
|
if authHash != args.AuthHash {
|
|
http.Error(w, "incorrect password", 403)
|
|
writeErrorResponse(w, 403, BBJResponse{
|
|
Error: true,
|
|
Data: "incorrect password",
|
|
})
|
|
return
|
|
}
|
|
|
|
// TODO include usermap?
|
|
writeResponse(w, BBJResponse{
|
|
Data: true,
|
|
})
|
|
}))
|
|
|
|
http.HandleFunc("/thread_index", handler(opts, func(w http.ResponseWriter, req *http.Request) {
|
|
db := opts.DB
|
|
rows, err := db.Query("SELECT * FROM threads JOIN messages ON threads.thread_id = messages.thread_id")
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
defer rows.Close()
|
|
for rows.Next() {
|
|
var id string
|
|
err = rows.Scan(&id)
|
|
if err != nil {
|
|
serverErr(w, err)
|
|
return
|
|
}
|
|
opts.Log(id)
|
|
}
|
|
writeResponse(w, BBJResponse{Data: "TODO"})
|
|
// TODO
|
|
}))
|
|
|
|
http.HandleFunc("/thread_create", handler(opts, func(w http.ResponseWriter, req *http.Request) {
|
|
// TODO
|
|
writeResponse(w, BBJResponse{Data: "TODO"})
|
|
}))
|
|
}
|