resource.go 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277
  1. package server
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "io"
  6. "net/http"
  7. "net/url"
  8. "strconv"
  9. "time"
  10. "github.com/usememos/memos/api"
  11. "github.com/usememos/memos/common"
  12. metric "github.com/usememos/memos/plugin/metrics"
  13. "github.com/labstack/echo/v4"
  14. )
  15. const (
  16. // The max file size is 32MB.
  17. maxFileSize = (32 * 8) << 20
  18. )
  19. func (s *Server) registerResourceRoutes(g *echo.Group) {
  20. g.POST("/resource", func(c echo.Context) error {
  21. ctx := c.Request().Context()
  22. userID, ok := c.Get(getUserIDContextKey()).(int)
  23. if !ok {
  24. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  25. }
  26. if err := c.Request().ParseMultipartForm(maxFileSize); err != nil {
  27. return echo.NewHTTPError(http.StatusBadRequest, "Upload file overload max size").SetInternal(err)
  28. }
  29. file, err := c.FormFile("file")
  30. if err != nil {
  31. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to get uploading file").SetInternal(err)
  32. }
  33. if file == nil {
  34. return echo.NewHTTPError(http.StatusBadRequest, "Upload file not found").SetInternal(err)
  35. }
  36. filename := file.Filename
  37. filetype := file.Header.Get("Content-Type")
  38. size := file.Size
  39. src, err := file.Open()
  40. if err != nil {
  41. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to open file").SetInternal(err)
  42. }
  43. defer src.Close()
  44. fileBytes, err := io.ReadAll(src)
  45. if err != nil {
  46. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to read file").SetInternal(err)
  47. }
  48. resourceCreate := &api.ResourceCreate{
  49. CreatorID: userID,
  50. Filename: filename,
  51. Type: filetype,
  52. Size: size,
  53. Blob: fileBytes,
  54. }
  55. resource, err := s.Store.CreateResource(ctx, resourceCreate)
  56. if err != nil {
  57. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create resource").SetInternal(err)
  58. }
  59. s.Collector.Collect(ctx, &metric.Metric{
  60. Name: "resource created",
  61. })
  62. c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
  63. if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
  64. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
  65. }
  66. return nil
  67. })
  68. g.GET("/resource", func(c echo.Context) error {
  69. ctx := c.Request().Context()
  70. userID, ok := c.Get(getUserIDContextKey()).(int)
  71. if !ok {
  72. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  73. }
  74. resourceFind := &api.ResourceFind{
  75. CreatorID: &userID,
  76. }
  77. list, err := s.Store.FindResourceList(ctx, resourceFind)
  78. if err != nil {
  79. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource list").SetInternal(err)
  80. }
  81. for _, resource := range list {
  82. memoResourceList, err := s.Store.FindMemoResourceList(ctx, &api.MemoResourceFind{
  83. ResourceID: &resource.ID,
  84. })
  85. if err != nil {
  86. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find memo resource list").SetInternal(err)
  87. }
  88. resource.LinkedMemoAmount = len(memoResourceList)
  89. }
  90. c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
  91. if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(list)); err != nil {
  92. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource list response").SetInternal(err)
  93. }
  94. return nil
  95. })
  96. g.GET("/resource/:resourceId", func(c echo.Context) error {
  97. ctx := c.Request().Context()
  98. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  99. if err != nil {
  100. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  101. }
  102. userID, ok := c.Get(getUserIDContextKey()).(int)
  103. if !ok {
  104. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  105. }
  106. resourceFind := &api.ResourceFind{
  107. ID: &resourceID,
  108. CreatorID: &userID,
  109. }
  110. resource, err := s.Store.FindResource(ctx, resourceFind)
  111. if err != nil {
  112. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource").SetInternal(err)
  113. }
  114. c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
  115. if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
  116. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
  117. }
  118. return nil
  119. })
  120. g.GET("/resource/:resourceId/blob", func(c echo.Context) error {
  121. ctx := c.Request().Context()
  122. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  123. if err != nil {
  124. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  125. }
  126. userID, ok := c.Get(getUserIDContextKey()).(int)
  127. if !ok {
  128. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  129. }
  130. resourceFind := &api.ResourceFind{
  131. ID: &resourceID,
  132. CreatorID: &userID,
  133. }
  134. resource, err := s.Store.FindResource(ctx, resourceFind)
  135. if err != nil {
  136. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource").SetInternal(err)
  137. }
  138. c.Response().Writer.WriteHeader(http.StatusOK)
  139. c.Response().Writer.Header().Set("Content-Type", resource.Type)
  140. c.Response().Writer.Header().Set(echo.HeaderContentSecurityPolicy, "default-src 'self'")
  141. if _, err := c.Response().Writer.Write(resource.Blob); err != nil {
  142. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to write resource blob").SetInternal(err)
  143. }
  144. return nil
  145. })
  146. g.PATCH("/resource/:resourceId", func(c echo.Context) error {
  147. ctx := c.Request().Context()
  148. userID, ok := c.Get(getUserIDContextKey()).(int)
  149. if !ok {
  150. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  151. }
  152. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  153. if err != nil {
  154. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  155. }
  156. resourceFind := &api.ResourceFind{
  157. ID: &resourceID,
  158. }
  159. resource, err := s.Store.FindResource(ctx, resourceFind)
  160. if err != nil {
  161. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
  162. }
  163. if resource.CreatorID != userID {
  164. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  165. }
  166. currentTs := time.Now().Unix()
  167. resourcePatch := &api.ResourcePatch{
  168. UpdatedTs: &currentTs,
  169. }
  170. if err := json.NewDecoder(c.Request().Body).Decode(resourcePatch); err != nil {
  171. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted patch resource request").SetInternal(err)
  172. }
  173. resource.ID = resourceID
  174. resource, err = s.Store.PatchResource(ctx, resourcePatch)
  175. if err != nil {
  176. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to patch resource").SetInternal(err)
  177. }
  178. c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
  179. if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
  180. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
  181. }
  182. return nil
  183. })
  184. g.DELETE("/resource/:resourceId", func(c echo.Context) error {
  185. ctx := c.Request().Context()
  186. userID, ok := c.Get(getUserIDContextKey()).(int)
  187. if !ok {
  188. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  189. }
  190. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  191. if err != nil {
  192. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  193. }
  194. resource, err := s.Store.FindResource(ctx, &api.ResourceFind{
  195. ID: &resourceID,
  196. CreatorID: &userID,
  197. })
  198. if err != nil {
  199. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
  200. }
  201. if resource.CreatorID != userID {
  202. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  203. }
  204. resourceDelete := &api.ResourceDelete{
  205. ID: resourceID,
  206. }
  207. if err := s.Store.DeleteResource(ctx, resourceDelete); err != nil {
  208. if common.ErrorCode(err) == common.NotFound {
  209. return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Resource ID not found: %d", resourceID))
  210. }
  211. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to delete resource").SetInternal(err)
  212. }
  213. return c.JSON(http.StatusOK, true)
  214. })
  215. }
  216. func (s *Server) registerResourcePublicRoutes(g *echo.Group) {
  217. g.GET("/r/:resourceId/:filename", func(c echo.Context) error {
  218. ctx := c.Request().Context()
  219. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  220. if err != nil {
  221. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  222. }
  223. filename, err := url.QueryUnescape(c.Param("filename"))
  224. if err != nil {
  225. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("filename is invalid: %s", c.Param("filename"))).SetInternal(err)
  226. }
  227. resourceFind := &api.ResourceFind{
  228. ID: &resourceID,
  229. Filename: &filename,
  230. }
  231. resource, err := s.Store.FindResource(ctx, resourceFind)
  232. if err != nil {
  233. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to fetch resource ID: %v", resourceID)).SetInternal(err)
  234. }
  235. c.Response().Writer.Header().Set("Content-Type", resource.Type)
  236. c.Response().Writer.WriteHeader(http.StatusOK)
  237. c.Response().Writer.Header().Set(echo.HeaderCacheControl, "max-age=31536000, immutable")
  238. c.Response().Writer.Header().Set(echo.HeaderContentSecurityPolicy, "default-src 'self'")
  239. if _, err := c.Response().Writer.Write(resource.Blob); err != nil {
  240. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to write response").SetInternal(err)
  241. }
  242. return nil
  243. })
  244. }