forked from tangled.org/core
Monorepo for Tangled — https://tangled.org
1package xrpc 2 3import ( 4 "encoding/json" 5 "log/slog" 6 "net/http" 7 "strings" 8 9 securejoin "github.com/cyphar/filepath-securejoin" 10 "tangled.org/core/api/tangled" 11 "tangled.org/core/idresolver" 12 "tangled.org/core/jetstream" 13 "tangled.org/core/knotserver/config" 14 "tangled.org/core/knotserver/db" 15 "tangled.org/core/notifier" 16 "tangled.org/core/rbac" 17 xrpcerr "tangled.org/core/xrpc/errors" 18 "tangled.org/core/xrpc/serviceauth" 19 20 "github.com/go-chi/chi/v5" 21) 22 23type Xrpc struct { 24 Config *config.Config 25 Db *db.DB 26 Ingester *jetstream.JetstreamClient 27 Enforcer *rbac.Enforcer 28 Logger *slog.Logger 29 Notifier *notifier.Notifier 30 Resolver *idresolver.Resolver 31 ServiceAuth *serviceauth.ServiceAuth 32} 33 34func (x *Xrpc) Router() http.Handler { 35 r := chi.NewRouter() 36 37 r.Group(func(r chi.Router) { 38 r.Use(x.ServiceAuth.VerifyServiceAuth) 39 40 r.Post("/"+tangled.RepoSetDefaultBranchNSID, x.SetDefaultBranch) 41 r.Post("/"+tangled.RepoDeleteBranchNSID, x.DeleteBranch) 42 r.Post("/"+tangled.RepoCreateNSID, x.CreateRepo) 43 r.Post("/"+tangled.RepoDeleteNSID, x.DeleteRepo) 44 r.Post("/"+tangled.RepoForkStatusNSID, x.ForkStatus) 45 r.Post("/"+tangled.RepoForkSyncNSID, x.ForkSync) 46 r.Post("/"+tangled.RepoHiddenRefNSID, x.HiddenRef) 47 r.Post("/"+tangled.RepoMergeNSID, x.Merge) 48 }) 49 50 // merge check is an open endpoint 51 // 52 // TODO: should we constrain this more? 53 // - we can calculate on PR submit/resubmit/gitRefUpdate etc. 54 // - use ETags on clients to keep requests to a minimum 55 r.Post("/"+tangled.RepoMergeCheckNSID, x.MergeCheck) 56 57 // repo query endpoints (no auth required) 58 r.Get("/"+tangled.RepoTreeNSID, x.RepoTree) 59 r.Get("/"+tangled.RepoLogNSID, x.RepoLog) 60 r.Get("/"+tangled.RepoBranchesNSID, x.RepoBranches) 61 r.Get("/"+tangled.RepoTagsNSID, x.RepoTags) 62 r.Get("/"+tangled.RepoBlobNSID, x.RepoBlob) 63 r.Get("/"+tangled.RepoDiffNSID, x.RepoDiff) 64 r.Get("/"+tangled.RepoCompareNSID, x.RepoCompare) 65 r.Get("/"+tangled.RepoGetDefaultBranchNSID, x.RepoGetDefaultBranch) 66 r.Get("/"+tangled.RepoBranchNSID, x.RepoBranch) 67 r.Get("/"+tangled.RepoArchiveNSID, x.RepoArchive) 68 r.Get("/"+tangled.RepoLanguagesNSID, x.RepoLanguages) 69 70 // knot query endpoints (no auth required) 71 r.Get("/"+tangled.KnotListKeysNSID, x.ListKeys) 72 r.Get("/"+tangled.KnotVersionNSID, x.Version) 73 74 // service query endpoints (no auth required) 75 r.Get("/"+tangled.OwnerNSID, x.Owner) 76 77 return r 78} 79 80// parseRepoParam parses a repo parameter in 'did/repoName' format and returns 81// the full repository path on disk 82func (x *Xrpc) parseRepoParam(repo string) (string, error) { 83 if repo == "" { 84 return "", xrpcerr.NewXrpcError( 85 xrpcerr.WithTag("InvalidRequest"), 86 xrpcerr.WithMessage("missing repo parameter"), 87 ) 88 } 89 90 // Parse repo string (did/repoName format) 91 parts := strings.SplitN(repo, "/", 2) 92 if len(parts) != 2 { 93 return "", xrpcerr.NewXrpcError( 94 xrpcerr.WithTag("InvalidRequest"), 95 xrpcerr.WithMessage("invalid repo format, expected 'did/repoName'"), 96 ) 97 } 98 99 did := parts[0] 100 repoName := parts[1] 101 102 // Construct repository path using the same logic as didPath 103 didRepoPath, err := securejoin.SecureJoin(did, repoName) 104 if err != nil { 105 return "", xrpcerr.RepoNotFoundError 106 } 107 108 repoPath, err := securejoin.SecureJoin(x.Config.Repo.ScanPath, didRepoPath) 109 if err != nil { 110 return "", xrpcerr.RepoNotFoundError 111 } 112 113 return repoPath, nil 114} 115 116func writeError(w http.ResponseWriter, e xrpcerr.XrpcError, status int) { 117 w.Header().Set("Content-Type", "application/json") 118 w.WriteHeader(status) 119 json.NewEncoder(w).Encode(e) 120} 121 122func writeJson(w http.ResponseWriter, response any) { 123 w.Header().Set("Content-Type", "application/json") 124 if err := json.NewEncoder(w).Encode(response); err != nil { 125 writeError(w, xrpcerr.GenericError(err), http.StatusInternalServerError) 126 return 127 } 128}