2014-08-22 23:08:44 +04:00
|
|
|
/*
|
|
|
|
* Bittorrent Client using Qt and libtorrent.
|
2022-04-12 13:39:35 +03:00
|
|
|
* Copyright (C) 2014, 2017, 2022 Vladimir Golovnev <glassez@yandex.ru>
|
2014-08-22 23:08:44 +04:00
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version 2
|
|
|
|
* of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
*
|
|
|
|
* In addition, as a special exception, the copyright holders give permission to
|
|
|
|
* link this program with the OpenSSL project's "OpenSSL" library (or with
|
|
|
|
* modified versions of it that use the same license as the "OpenSSL" library),
|
|
|
|
* and distribute the linked executables. You must obey the GNU General Public
|
|
|
|
* License in all respects for all of the code used other than "OpenSSL". If you
|
|
|
|
* modify file(s), you may extend this exception to your version of the file(s),
|
|
|
|
* but you are not obligated to do so. If you do not wish to do so, delete this
|
|
|
|
* exception statement from your version.
|
|
|
|
*/
|
|
|
|
|
2017-10-14 16:27:21 +03:00
|
|
|
#pragma once
|
2014-08-22 23:08:44 +04:00
|
|
|
|
2022-04-12 13:39:35 +03:00
|
|
|
#include <type_traits>
|
2022-08-15 06:56:59 +03:00
|
|
|
#include <utility>
|
2022-04-12 13:39:35 +03:00
|
|
|
|
2017-10-14 16:27:21 +03:00
|
|
|
#include <QDateTime>
|
2019-06-13 17:43:34 +03:00
|
|
|
#include <QElapsedTimer>
|
2017-10-14 16:27:21 +03:00
|
|
|
#include <QHash>
|
2022-09-07 08:29:46 +03:00
|
|
|
#include <QHostAddress>
|
2022-04-12 13:39:35 +03:00
|
|
|
#include <QMap>
|
2017-10-14 16:27:21 +03:00
|
|
|
#include <QObject>
|
|
|
|
#include <QRegularExpression>
|
|
|
|
#include <QSet>
|
2018-06-07 20:07:28 +03:00
|
|
|
#include <QTranslator>
|
2022-09-07 08:29:46 +03:00
|
|
|
#include <QVector>
|
2014-08-22 23:08:44 +04:00
|
|
|
|
2022-06-25 15:46:55 +03:00
|
|
|
#include "base/applicationcomponent.h"
|
2022-03-26 06:53:50 +03:00
|
|
|
#include "base/global.h"
|
2017-10-14 16:27:21 +03:00
|
|
|
#include "base/http/irequesthandler.h"
|
|
|
|
#include "base/http/responsebuilder.h"
|
|
|
|
#include "base/http/types.h"
|
2022-02-08 06:03:48 +03:00
|
|
|
#include "base/path.h"
|
2018-07-14 10:47:34 +03:00
|
|
|
#include "base/utils/net.h"
|
2017-10-14 16:27:21 +03:00
|
|
|
#include "base/utils/version.h"
|
2022-03-26 06:53:50 +03:00
|
|
|
#include "api/isessionmanager.h"
|
2017-10-14 16:27:21 +03:00
|
|
|
|
2023-01-28 20:40:38 +03:00
|
|
|
inline const Utils::Version<3, 2> API_VERSION {2, 9, 0};
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
class APIController;
|
2022-04-12 13:39:35 +03:00
|
|
|
class AuthController;
|
2017-10-14 16:27:21 +03:00
|
|
|
class WebApplication;
|
|
|
|
|
2022-06-25 15:46:55 +03:00
|
|
|
class WebSession final : public QObject, public ApplicationComponent, public ISession
|
2017-10-14 16:27:21 +03:00
|
|
|
{
|
|
|
|
public:
|
2022-06-25 15:46:55 +03:00
|
|
|
explicit WebSession(const QString &sid, IApplication *app);
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
QString id() const override;
|
2019-06-13 17:43:34 +03:00
|
|
|
|
|
|
|
bool hasExpired(qint64 seconds) const;
|
|
|
|
void updateTimestamp();
|
2017-10-14 16:27:21 +03:00
|
|
|
|
2022-04-12 13:39:35 +03:00
|
|
|
template <typename T>
|
|
|
|
void registerAPIController(const QString &scope)
|
|
|
|
{
|
|
|
|
static_assert(std::is_base_of_v<APIController, T>, "Class should be derived from APIController.");
|
2022-06-25 15:46:55 +03:00
|
|
|
m_apiControllers[scope] = new T(app(), this);
|
2022-04-12 13:39:35 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
APIController *getAPIController(const QString &scope) const;
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
private:
|
|
|
|
const QString m_sid;
|
2019-06-13 17:43:34 +03:00
|
|
|
QElapsedTimer m_timer; // timestamp
|
2022-04-12 13:39:35 +03:00
|
|
|
QMap<QString, APIController *> m_apiControllers;
|
2017-10-14 16:27:21 +03:00
|
|
|
};
|
|
|
|
|
2020-04-17 07:37:53 +03:00
|
|
|
class WebApplication final
|
2022-06-25 15:46:55 +03:00
|
|
|
: public QObject, public ApplicationComponent
|
|
|
|
, public Http::IRequestHandler, public ISessionManager
|
2017-10-14 16:27:21 +03:00
|
|
|
, private Http::ResponseBuilder
|
2014-08-22 23:08:44 +04:00
|
|
|
{
|
2017-10-14 16:27:21 +03:00
|
|
|
Q_OBJECT
|
2021-06-29 09:45:23 +03:00
|
|
|
Q_DISABLE_COPY_MOVE(WebApplication)
|
2014-08-22 23:08:44 +04:00
|
|
|
|
|
|
|
public:
|
2022-06-25 15:46:55 +03:00
|
|
|
explicit WebApplication(IApplication *app, QObject *parent = nullptr);
|
2017-10-14 16:27:21 +03:00
|
|
|
~WebApplication() override;
|
|
|
|
|
2018-03-06 18:41:18 +03:00
|
|
|
Http::Response processRequest(const Http::Request &request, const Http::Environment &env) override;
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
QString clientId() const override;
|
|
|
|
WebSession *session() override;
|
|
|
|
void sessionStart() override;
|
|
|
|
void sessionEnd() override;
|
|
|
|
|
|
|
|
const Http::Request &request() const;
|
|
|
|
const Http::Environment &env() const;
|
2014-08-22 23:08:44 +04:00
|
|
|
|
|
|
|
private:
|
2017-10-14 16:27:21 +03:00
|
|
|
void doProcessRequest();
|
|
|
|
void configure();
|
|
|
|
|
|
|
|
void declarePublicAPI(const QString &apiPath);
|
|
|
|
|
2022-02-08 06:03:48 +03:00
|
|
|
void sendFile(const Path &path);
|
2017-10-14 16:27:21 +03:00
|
|
|
void sendWebUIFile();
|
2014-08-22 23:08:44 +04:00
|
|
|
|
2019-08-14 15:27:06 +03:00
|
|
|
void translateDocument(QString &data) const;
|
2018-06-07 20:07:28 +03:00
|
|
|
|
2017-10-14 16:27:21 +03:00
|
|
|
// Session management
|
|
|
|
QString generateSid() const;
|
|
|
|
void sessionInitialize();
|
|
|
|
bool isAuthNeeded();
|
|
|
|
bool isPublicAPI(const QString &scope, const QString &action) const;
|
|
|
|
|
|
|
|
bool isCrossSiteRequest(const Http::Request &request) const;
|
|
|
|
bool validateHostHeader(const QStringList &domains) const;
|
|
|
|
|
2021-06-23 09:01:36 +03:00
|
|
|
QHostAddress resolveClientAddress() const;
|
|
|
|
|
2017-10-14 16:27:21 +03:00
|
|
|
// Persistent data
|
2019-04-25 21:50:40 +03:00
|
|
|
QHash<QString, WebSession *> m_sessions;
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
// Current data
|
|
|
|
WebSession *m_currentSession = nullptr;
|
|
|
|
Http::Request m_request;
|
|
|
|
Http::Environment m_env;
|
2019-08-04 12:22:28 +03:00
|
|
|
QHash<QString, QString> m_params;
|
2019-04-17 15:09:03 +03:00
|
|
|
const QString m_cacheID;
|
2017-10-14 16:27:21 +03:00
|
|
|
|
2022-03-26 06:53:50 +03:00
|
|
|
const QRegularExpression m_apiPathPattern {u"^/api/v2/(?<scope>[A-Za-z_][A-Za-z_0-9]*)/(?<action>[A-Za-z_][A-Za-z_0-9]*)$"_qs};
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
QSet<QString> m_publicAPIs;
|
2022-08-15 06:56:59 +03:00
|
|
|
const QHash<std::pair<QString, QString>, QString> m_allowedMethod =
|
|
|
|
{
|
|
|
|
// <<controller name, action name>, HTTP method>
|
|
|
|
{{u"app"_qs, u"setPreferences"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"app"_qs, u"shutdown"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"auth"_qs, u"login"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"auth"_qs, u"logout"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"addFeed"_qs}, Http::METHOD_POST},
|
2022-08-15 09:53:51 +03:00
|
|
|
{{u"rss"_qs, u"addFolder"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"markAsRead"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"moveItem"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"refreshItem"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"removeItem"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"removeRule"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"renameRule"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"rss"_qs, u"setRule"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"search"_qs, u"delete"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"search"_qs, u"enablePlugin"_qs}, Http::METHOD_POST},
|
2022-08-15 06:56:59 +03:00
|
|
|
{{u"search"_qs, u"installPlugin"_qs}, Http::METHOD_POST},
|
2022-08-15 09:53:51 +03:00
|
|
|
{{u"search"_qs, u"start"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"search"_qs, u"stop"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"search"_qs, u"uninstallPlugin"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"search"_qs, u"updatePlugins"_qs}, Http::METHOD_POST},
|
2022-08-15 06:56:59 +03:00
|
|
|
{{u"torrents"_qs, u"add"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"addPeers"_qs}, Http::METHOD_POST},
|
2022-08-15 09:53:51 +03:00
|
|
|
{{u"torrents"_qs, u"addTags"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"addTrackers"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"bottomPrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"createCategory"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"createTags"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"decreasePrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"delete"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"deleteTags"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"editCategory"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"editTracker"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"filePrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"increasePrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"pause"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"reannounce"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"recheck"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"removeCategories"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"removeTags"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"removeTrackers"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"rename"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"renameFile"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"renameFolder"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"resume"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setAutoManagement"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setCategory"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setDownloadLimit"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setDownloadPath"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setForceStart"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setLocation"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setSavePath"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setShareLimits"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setSuperSeeding"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"setUploadLimit"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"toggleFirstLastPiecePrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"toggleSequentialDownload"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"torrents"_qs, u"topPrio"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"transfer"_qs, u"banPeers"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"transfer"_qs, u"setDownloadLimit"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"transfer"_qs, u"setSpeedLimitsMode"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"transfer"_qs, u"setUploadLimit"_qs}, Http::METHOD_POST},
|
|
|
|
{{u"transfer"_qs, u"toggleSpeedLimitsMode"_qs}, Http::METHOD_POST},
|
2022-08-15 06:56:59 +03:00
|
|
|
};
|
2017-10-14 16:27:21 +03:00
|
|
|
bool m_isAltUIUsed = false;
|
2022-02-08 06:03:48 +03:00
|
|
|
Path m_rootFolder;
|
2017-10-14 16:27:21 +03:00
|
|
|
|
|
|
|
struct TranslatedFile
|
|
|
|
{
|
|
|
|
QByteArray data;
|
2019-08-14 12:48:40 +03:00
|
|
|
QString mimeType;
|
2017-10-14 16:27:21 +03:00
|
|
|
QDateTime lastModified;
|
|
|
|
};
|
2022-02-08 06:03:48 +03:00
|
|
|
QHash<Path, TranslatedFile> m_translatedFiles;
|
2018-05-11 15:45:00 +03:00
|
|
|
QString m_currentLocale;
|
2018-06-07 20:07:28 +03:00
|
|
|
QTranslator m_translator;
|
2018-12-08 07:03:43 +03:00
|
|
|
bool m_translationFileLoaded = false;
|
2018-05-21 18:33:44 +03:00
|
|
|
|
2022-04-12 13:39:35 +03:00
|
|
|
AuthController *m_authController = nullptr;
|
2018-07-14 10:47:34 +03:00
|
|
|
bool m_isLocalAuthEnabled;
|
|
|
|
bool m_isAuthSubnetWhitelistEnabled;
|
2019-08-02 07:55:06 +03:00
|
|
|
QVector<Utils::Net::Subnet> m_authSubnetWhitelist;
|
2019-06-13 17:43:34 +03:00
|
|
|
int m_sessionTimeout;
|
2023-01-17 09:31:17 +03:00
|
|
|
QString m_sessionCookieName;
|
2018-07-14 10:47:34 +03:00
|
|
|
|
2018-05-21 18:33:44 +03:00
|
|
|
// security related
|
2018-07-14 10:47:34 +03:00
|
|
|
QStringList m_domainList;
|
2018-05-21 19:43:33 +03:00
|
|
|
bool m_isCSRFProtectionEnabled;
|
2019-12-23 20:58:08 +03:00
|
|
|
bool m_isSecureCookieEnabled;
|
2018-11-16 08:41:27 +03:00
|
|
|
bool m_isHostHeaderValidationEnabled;
|
2018-05-31 07:44:48 +03:00
|
|
|
bool m_isHttpsEnabled;
|
2020-04-22 12:15:12 +03:00
|
|
|
|
2021-06-23 09:01:36 +03:00
|
|
|
// Reverse proxy
|
|
|
|
bool m_isReverseProxySupportEnabled;
|
2022-09-07 08:29:46 +03:00
|
|
|
QVector<Utils::Net::Subnet> m_trustedReverseProxyList;
|
2021-06-23 09:01:36 +03:00
|
|
|
QHostAddress m_clientAddress;
|
|
|
|
|
2020-05-09 21:48:21 +03:00
|
|
|
QVector<Http::Header> m_prebuiltHeaders;
|
2017-10-14 16:27:21 +03:00
|
|
|
};
|