resource.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410
  1. package server
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "fmt"
  6. "io"
  7. "net/http"
  8. "net/url"
  9. "os"
  10. "path"
  11. "path/filepath"
  12. "regexp"
  13. "strconv"
  14. "strings"
  15. "time"
  16. "github.com/labstack/echo/v4"
  17. "github.com/pkg/errors"
  18. "github.com/usememos/memos/api"
  19. "github.com/usememos/memos/common"
  20. "github.com/usememos/memos/common/log"
  21. "github.com/usememos/memos/plugin/storage/s3"
  22. "go.uber.org/zap"
  23. )
  24. const (
  25. // The max file size is 32MB.
  26. maxFileSize = 32 << 20
  27. )
  28. var fileKeyPattern = regexp.MustCompile(`\{[a-z]{1,9}\}`)
  29. func (s *Server) registerResourceRoutes(g *echo.Group) {
  30. g.POST("/resource", func(c echo.Context) error {
  31. ctx := c.Request().Context()
  32. userID, ok := c.Get(getUserIDContextKey()).(int)
  33. if !ok {
  34. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  35. }
  36. resourceCreate := &api.ResourceCreate{}
  37. if err := json.NewDecoder(c.Request().Body).Decode(resourceCreate); err != nil {
  38. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted post resource request").SetInternal(err)
  39. }
  40. resourceCreate.CreatorID = userID
  41. // Only allow those external links with http prefix.
  42. if resourceCreate.ExternalLink != "" && !strings.HasPrefix(resourceCreate.ExternalLink, "http") {
  43. return echo.NewHTTPError(http.StatusBadRequest, "Invalid external link")
  44. }
  45. resource, err := s.Store.CreateResource(ctx, resourceCreate)
  46. if err != nil {
  47. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create resource").SetInternal(err)
  48. }
  49. if err := s.createResourceCreateActivity(c, resource); err != nil {
  50. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create activity").SetInternal(err)
  51. }
  52. return c.JSON(http.StatusOK, composeResponse(resource))
  53. })
  54. g.POST("/resource/blob", func(c echo.Context) error {
  55. ctx := c.Request().Context()
  56. userID, ok := c.Get(getUserIDContextKey()).(int)
  57. if !ok {
  58. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  59. }
  60. if err := c.Request().ParseMultipartForm(maxFileSize); err != nil {
  61. return echo.NewHTTPError(http.StatusBadRequest, "Upload file overload max size").SetInternal(err)
  62. }
  63. file, err := c.FormFile("file")
  64. if err != nil {
  65. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to get uploading file").SetInternal(err)
  66. }
  67. if file == nil {
  68. return echo.NewHTTPError(http.StatusBadRequest, "Upload file not found").SetInternal(err)
  69. }
  70. filetype := file.Header.Get("Content-Type")
  71. size := file.Size
  72. sourceFile, err := file.Open()
  73. if err != nil {
  74. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to open file").SetInternal(err)
  75. }
  76. defer sourceFile.Close()
  77. var resourceCreate *api.ResourceCreate
  78. systemSettingStorageServiceID, err := s.Store.FindSystemSetting(ctx, &api.SystemSettingFind{Name: api.SystemSettingStorageServiceIDName})
  79. if err != nil && common.ErrorCode(err) != common.NotFound {
  80. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find storage").SetInternal(err)
  81. }
  82. storageServiceID := api.DatabaseStorage
  83. if systemSettingStorageServiceID != nil {
  84. err = json.Unmarshal([]byte(systemSettingStorageServiceID.Value), &storageServiceID)
  85. if err != nil {
  86. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to unmarshal storage service id").SetInternal(err)
  87. }
  88. }
  89. if storageServiceID == api.DatabaseStorage {
  90. fileBytes, err := io.ReadAll(sourceFile)
  91. if err != nil {
  92. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to read file").SetInternal(err)
  93. }
  94. resourceCreate = &api.ResourceCreate{
  95. CreatorID: userID,
  96. Filename: file.Filename,
  97. Type: filetype,
  98. Size: size,
  99. Blob: fileBytes,
  100. }
  101. } else if storageServiceID == api.LocalStorage {
  102. systemSettingLocalStoragePath, err := s.Store.FindSystemSetting(ctx, &api.SystemSettingFind{Name: api.SystemSettingLocalStoragePathName})
  103. if err != nil && common.ErrorCode(err) != common.NotFound {
  104. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find local storage path setting").SetInternal(err)
  105. }
  106. localStoragePath := ""
  107. if systemSettingLocalStoragePath != nil {
  108. err = json.Unmarshal([]byte(systemSettingLocalStoragePath.Value), &localStoragePath)
  109. if err != nil {
  110. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to unmarshal local storage path setting").SetInternal(err)
  111. }
  112. }
  113. filePath := localStoragePath
  114. if !strings.Contains(filePath, "{filename}") {
  115. filePath = path.Join(filePath, "{filename}")
  116. }
  117. filePath = path.Join(s.Profile.Data, replacePathTemplate(filePath, file.Filename))
  118. dir, filename := filepath.Split(filePath)
  119. if err = os.MkdirAll(dir, os.ModePerm); err != nil {
  120. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create directory").SetInternal(err)
  121. }
  122. dst, err := os.Create(filePath)
  123. if err != nil {
  124. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create file").SetInternal(err)
  125. }
  126. defer dst.Close()
  127. _, err = io.Copy(dst, sourceFile)
  128. if err != nil {
  129. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to copy file").SetInternal(err)
  130. }
  131. resourceCreate = &api.ResourceCreate{
  132. CreatorID: userID,
  133. Filename: filename,
  134. Type: filetype,
  135. Size: size,
  136. InternalPath: filePath,
  137. }
  138. } else {
  139. storage, err := s.Store.FindStorage(ctx, &api.StorageFind{ID: &storageServiceID})
  140. if err != nil {
  141. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find storage").SetInternal(err)
  142. }
  143. if storage.Type == api.StorageS3 {
  144. s3Config := storage.Config.S3Config
  145. s3Client, err := s3.NewClient(ctx, &s3.Config{
  146. AccessKey: s3Config.AccessKey,
  147. SecretKey: s3Config.SecretKey,
  148. EndPoint: s3Config.EndPoint,
  149. Region: s3Config.Region,
  150. Bucket: s3Config.Bucket,
  151. URLPrefix: s3Config.URLPrefix,
  152. URLSuffix: s3Config.URLSuffix,
  153. })
  154. if err != nil {
  155. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to new s3 client").SetInternal(err)
  156. }
  157. filePath := s3Config.Path
  158. if !strings.Contains(filePath, "{filename}") {
  159. filePath = path.Join(filePath, "{filename}")
  160. }
  161. filePath = replacePathTemplate(filePath, file.Filename)
  162. _, filename := filepath.Split(filePath)
  163. link, err := s3Client.UploadFile(ctx, filePath, filetype, sourceFile)
  164. if err != nil {
  165. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to upload via s3 client").SetInternal(err)
  166. }
  167. resourceCreate = &api.ResourceCreate{
  168. CreatorID: userID,
  169. Filename: filename,
  170. Type: filetype,
  171. ExternalLink: link,
  172. }
  173. } else {
  174. return echo.NewHTTPError(http.StatusInternalServerError, "Unsupported storage type")
  175. }
  176. }
  177. publicID := common.GenUUID()
  178. resourceCreate.PublicID = publicID
  179. resource, err := s.Store.CreateResource(ctx, resourceCreate)
  180. if err != nil {
  181. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create resource").SetInternal(err)
  182. }
  183. if err := s.createResourceCreateActivity(c, resource); err != nil {
  184. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create activity").SetInternal(err)
  185. }
  186. return c.JSON(http.StatusOK, composeResponse(resource))
  187. })
  188. g.GET("/resource", func(c echo.Context) error {
  189. ctx := c.Request().Context()
  190. userID, ok := c.Get(getUserIDContextKey()).(int)
  191. if !ok {
  192. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  193. }
  194. resourceFind := &api.ResourceFind{
  195. CreatorID: &userID,
  196. }
  197. if limit, err := strconv.Atoi(c.QueryParam("limit")); err == nil {
  198. resourceFind.Limit = &limit
  199. }
  200. if offset, err := strconv.Atoi(c.QueryParam("offset")); err == nil {
  201. resourceFind.Offset = &offset
  202. }
  203. list, err := s.Store.FindResourceList(ctx, resourceFind)
  204. if err != nil {
  205. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource list").SetInternal(err)
  206. }
  207. return c.JSON(http.StatusOK, composeResponse(list))
  208. })
  209. g.PATCH("/resource/:resourceId", func(c echo.Context) error {
  210. ctx := c.Request().Context()
  211. userID, ok := c.Get(getUserIDContextKey()).(int)
  212. if !ok {
  213. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  214. }
  215. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  216. if err != nil {
  217. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  218. }
  219. resourceFind := &api.ResourceFind{
  220. ID: &resourceID,
  221. }
  222. resource, err := s.Store.FindResource(ctx, resourceFind)
  223. if err != nil {
  224. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
  225. }
  226. if resource.CreatorID != userID {
  227. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  228. }
  229. currentTs := time.Now().Unix()
  230. resourcePatch := &api.ResourcePatch{
  231. UpdatedTs: &currentTs,
  232. }
  233. if err := json.NewDecoder(c.Request().Body).Decode(resourcePatch); err != nil {
  234. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted patch resource request").SetInternal(err)
  235. }
  236. if resourcePatch.ResetPublicID != nil && *resourcePatch.ResetPublicID {
  237. publicID := common.GenUUID()
  238. resourcePatch.PublicID = &publicID
  239. }
  240. resourcePatch.ID = resourceID
  241. resource, err = s.Store.PatchResource(ctx, resourcePatch)
  242. if err != nil {
  243. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to patch resource").SetInternal(err)
  244. }
  245. return c.JSON(http.StatusOK, composeResponse(resource))
  246. })
  247. g.DELETE("/resource/:resourceId", func(c echo.Context) error {
  248. ctx := c.Request().Context()
  249. userID, ok := c.Get(getUserIDContextKey()).(int)
  250. if !ok {
  251. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  252. }
  253. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  254. if err != nil {
  255. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  256. }
  257. resource, err := s.Store.FindResource(ctx, &api.ResourceFind{
  258. ID: &resourceID,
  259. CreatorID: &userID,
  260. })
  261. if err != nil {
  262. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
  263. }
  264. if resource.CreatorID != userID {
  265. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  266. }
  267. if resource.InternalPath != "" {
  268. err := os.Remove(resource.InternalPath)
  269. if err != nil {
  270. log.Warn(fmt.Sprintf("failed to delete local file with path %s", resource.InternalPath), zap.Error(err))
  271. }
  272. }
  273. resourceDelete := &api.ResourceDelete{
  274. ID: resourceID,
  275. }
  276. if err := s.Store.DeleteResource(ctx, resourceDelete); err != nil {
  277. if common.ErrorCode(err) == common.NotFound {
  278. return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Resource ID not found: %d", resourceID))
  279. }
  280. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to delete resource").SetInternal(err)
  281. }
  282. return c.JSON(http.StatusOK, true)
  283. })
  284. }
  285. func (s *Server) registerResourcePublicRoutes(g *echo.Group) {
  286. g.GET("/r/:resourceId/:publicId", func(c echo.Context) error {
  287. ctx := c.Request().Context()
  288. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  289. if err != nil {
  290. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  291. }
  292. publicID, err := url.QueryUnescape(c.Param("publicId"))
  293. if err != nil {
  294. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("publicID is invalid: %s", c.Param("publicId"))).SetInternal(err)
  295. }
  296. resourceFind := &api.ResourceFind{
  297. ID: &resourceID,
  298. PublicID: &publicID,
  299. GetBlob: true,
  300. }
  301. resource, err := s.Store.FindResource(ctx, resourceFind)
  302. if err != nil {
  303. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to find resource by ID: %v", resourceID)).SetInternal(err)
  304. }
  305. blob := resource.Blob
  306. if resource.InternalPath != "" {
  307. src, err := os.Open(resource.InternalPath)
  308. if err != nil {
  309. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to open the local resource: %s", resource.InternalPath)).SetInternal(err)
  310. }
  311. defer src.Close()
  312. blob, err = io.ReadAll(src)
  313. if err != nil {
  314. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to read the local resource: %s", resource.InternalPath)).SetInternal(err)
  315. }
  316. }
  317. c.Response().Writer.Header().Set(echo.HeaderCacheControl, "max-age=31536000, immutable")
  318. c.Response().Writer.Header().Set(echo.HeaderContentSecurityPolicy, "default-src 'self'")
  319. resourceType := strings.ToLower(resource.Type)
  320. if strings.HasPrefix(resourceType, "text") {
  321. resourceType = echo.MIMETextPlainCharsetUTF8
  322. } else if strings.HasPrefix(resourceType, "video") || strings.HasPrefix(resourceType, "audio") {
  323. http.ServeContent(c.Response(), c.Request(), resource.Filename, time.Unix(resource.UpdatedTs, 0), bytes.NewReader(blob))
  324. return nil
  325. }
  326. return c.Stream(http.StatusOK, resourceType, bytes.NewReader(blob))
  327. })
  328. }
  329. func (s *Server) createResourceCreateActivity(c echo.Context, resource *api.Resource) error {
  330. ctx := c.Request().Context()
  331. payload := api.ActivityResourceCreatePayload{
  332. Filename: resource.Filename,
  333. Type: resource.Type,
  334. Size: resource.Size,
  335. }
  336. payloadBytes, err := json.Marshal(payload)
  337. if err != nil {
  338. return errors.Wrap(err, "failed to marshal activity payload")
  339. }
  340. activity, err := s.Store.CreateActivity(ctx, &api.ActivityCreate{
  341. CreatorID: resource.CreatorID,
  342. Type: api.ActivityResourceCreate,
  343. Level: api.ActivityInfo,
  344. Payload: string(payloadBytes),
  345. })
  346. if err != nil || activity == nil {
  347. return errors.Wrap(err, "failed to create activity")
  348. }
  349. return err
  350. }
  351. func replacePathTemplate(path string, filename string) string {
  352. t := time.Now()
  353. path = fileKeyPattern.ReplaceAllStringFunc(path, func(s string) string {
  354. switch s {
  355. case "{filename}":
  356. return filename
  357. case "{timestamp}":
  358. return fmt.Sprintf("%d", t.Unix())
  359. case "{year}":
  360. return fmt.Sprintf("%d", t.Year())
  361. case "{month}":
  362. return fmt.Sprintf("%02d", t.Month())
  363. case "{day}":
  364. return fmt.Sprintf("%02d", t.Day())
  365. case "{hour}":
  366. return fmt.Sprintf("%02d", t.Hour())
  367. case "{minute}":
  368. return fmt.Sprintf("%02d", t.Minute())
  369. case "{second}":
  370. return fmt.Sprintf("%02d", t.Second())
  371. }
  372. return s
  373. })
  374. return path
  375. }