registry.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include "daemon/common.h"
  3. #include "registry_internals.h"
  4. #define REGISTRY_STATUS_OK "ok"
  5. #define REGISTRY_STATUS_REDIRECT "redirect"
  6. #define REGISTRY_STATUS_FAILED "failed"
  7. #define REGISTRY_STATUS_DISABLED "disabled"
  8. // ----------------------------------------------------------------------------
  9. // REGISTRY concurrency locking
  10. static inline void registry_lock(void) {
  11. netdata_mutex_lock(&registry.lock);
  12. }
  13. static inline void registry_unlock(void) {
  14. netdata_mutex_unlock(&registry.lock);
  15. }
  16. // ----------------------------------------------------------------------------
  17. // COOKIES
  18. static void registry_set_cookie(struct web_client *w, const char *guid) {
  19. char edate[100];
  20. time_t et = now_realtime_sec() + registry.persons_expiration;
  21. struct tm etmbuf, *etm = gmtime_r(&et, &etmbuf);
  22. strftime(edate, sizeof(edate), "%a, %d %b %Y %H:%M:%S %Z", etm);
  23. buffer_sprintf(w->response.header, "Set-Cookie: " NETDATA_REGISTRY_COOKIE_NAME "=%s; Expires=%s\r\n", guid, edate);
  24. if(registry.enable_cookies_samesite_secure)
  25. buffer_sprintf(w->response.header, "Set-Cookie: " NETDATA_REGISTRY_COOKIE_NAME "=%s; Expires=%s; SameSite=None; Secure\r\n", guid, edate);
  26. if(registry.registry_domain && *registry.registry_domain) {
  27. buffer_sprintf(w->response.header, "Set-Cookie: " NETDATA_REGISTRY_COOKIE_NAME "=%s; Expires=%s; Domain=%s\r\n", guid, edate, registry.registry_domain);
  28. if(registry.enable_cookies_samesite_secure)
  29. buffer_sprintf(w->response.header, "Set-Cookie: " NETDATA_REGISTRY_COOKIE_NAME "=%s; Expires=%s; Domain=%s; SameSite=None; Secure\r\n", guid, edate, registry.registry_domain);
  30. }
  31. w->response.has_cookies = true;
  32. }
  33. static inline void registry_set_person_cookie(struct web_client *w, REGISTRY_PERSON *p) {
  34. registry_set_cookie(w, p->guid);
  35. }
  36. // ----------------------------------------------------------------------------
  37. // JSON GENERATION
  38. static inline void registry_json_header(RRDHOST *host, struct web_client *w, const char *action, const char *status) {
  39. buffer_flush(w->response.data);
  40. w->response.data->content_type = CT_APPLICATION_JSON;
  41. buffer_json_initialize(w->response.data, "\"", "\"", 0, true, false);
  42. buffer_json_member_add_string(w->response.data, "action", action);
  43. buffer_json_member_add_string(w->response.data, "status", status);
  44. buffer_json_member_add_string(w->response.data, "hostname", rrdhost_registry_hostname(host));
  45. buffer_json_member_add_string(w->response.data, "machine_guid", host->machine_guid);
  46. }
  47. static inline void registry_json_footer(struct web_client *w) {
  48. buffer_json_finalize(w->response.data);
  49. }
  50. static inline int registry_json_disabled(RRDHOST *host, struct web_client *w, const char *action) {
  51. registry_json_header(host, w, action, REGISTRY_STATUS_DISABLED);
  52. buffer_json_member_add_string(w->response.data, "registry", registry.registry_to_announce);
  53. registry_json_footer(w);
  54. return HTTP_RESP_OK;
  55. }
  56. // ----------------------------------------------------------------------------
  57. // CALLBACKS FOR WALKING THROUGH REGISTRY OBJECTS
  58. // structure used be the callbacks below
  59. struct registry_json_walk_person_urls_callback {
  60. REGISTRY_PERSON *p;
  61. REGISTRY_MACHINE *m;
  62. struct web_client *w;
  63. int count;
  64. };
  65. // callback for rendering PERSON_URLs
  66. static int registry_json_person_url_callback(void *entry, void *data) {
  67. REGISTRY_PERSON_URL *pu = (REGISTRY_PERSON_URL *)entry;
  68. struct registry_json_walk_person_urls_callback *c = (struct registry_json_walk_person_urls_callback *)data;
  69. struct web_client *w = c->w;
  70. if (!strcmp(pu->url->url,"***")) return 0;
  71. buffer_json_add_array_item_array(w->response.data);
  72. buffer_json_add_array_item_string(w->response.data, pu->machine->guid);
  73. buffer_json_add_array_item_string(w->response.data, pu->url->url);
  74. buffer_json_add_array_item_uint64(w->response.data, pu->last_t * (uint64_t) 1000);
  75. buffer_json_add_array_item_uint64(w->response.data, pu->usages);
  76. buffer_json_add_array_item_string(w->response.data, pu->machine_name);
  77. buffer_json_array_close(w->response.data);
  78. return 1;
  79. }
  80. // callback for rendering MACHINE_URLs
  81. static int registry_json_machine_url_callback(const DICTIONARY_ITEM *item __maybe_unused, void *entry, void *data) {
  82. REGISTRY_MACHINE_URL *mu = (REGISTRY_MACHINE_URL *)entry;
  83. struct registry_json_walk_person_urls_callback *c = (struct registry_json_walk_person_urls_callback *)data;
  84. struct web_client *w = c->w;
  85. REGISTRY_MACHINE *m = c->m;
  86. if (!strcmp(mu->url->url,"***")) return 0;
  87. buffer_json_add_array_item_array(w->response.data);
  88. buffer_json_add_array_item_string(w->response.data, m->guid);
  89. buffer_json_add_array_item_string(w->response.data, mu->url->url);
  90. buffer_json_add_array_item_uint64(w->response.data, mu->last_t * (uint64_t) 1000);
  91. buffer_json_add_array_item_uint64(w->response.data, mu->usages);
  92. buffer_json_array_close(w->response.data);
  93. return 1;
  94. }
  95. // ----------------------------------------------------------------------------
  96. // structure used be the callbacks below
  97. struct registry_person_url_callback_verify_machine_exists_data {
  98. REGISTRY_MACHINE *m;
  99. int count;
  100. };
  101. static inline int registry_person_url_callback_verify_machine_exists(void *entry, void *data) {
  102. struct registry_person_url_callback_verify_machine_exists_data *d = (struct registry_person_url_callback_verify_machine_exists_data *)data;
  103. REGISTRY_PERSON_URL *pu = (REGISTRY_PERSON_URL *)entry;
  104. REGISTRY_MACHINE *m = d->m;
  105. if(pu->machine == m)
  106. d->count++;
  107. return 0;
  108. }
  109. // ----------------------------------------------------------------------------
  110. // dynamic update of the configuration
  111. // The registry does not seem to be designed to support this and I cannot see any concurrency protection
  112. // that could make this safe, so try to be as atomic as possible.
  113. void registry_update_cloud_base_url() {
  114. registry.cloud_base_url = appconfig_get(&cloud_config, CONFIG_SECTION_GLOBAL, "cloud base url", DEFAULT_CLOUD_BASE_URL);
  115. setenv("NETDATA_REGISTRY_CLOUD_BASE_URL", registry.cloud_base_url, 1);
  116. }
  117. // ----------------------------------------------------------------------------
  118. // public HELLO request
  119. int registry_request_hello_json(RRDHOST *host, struct web_client *w) {
  120. registry_json_header(host, w, "hello", REGISTRY_STATUS_OK);
  121. buffer_json_member_add_string(w->response.data, "registry", registry.registry_to_announce);
  122. buffer_json_member_add_string(w->response.data, "cloud_base_url", registry.cloud_base_url);
  123. buffer_json_member_add_boolean(w->response.data, "anonymous_statistics", netdata_anonymous_statistics_enabled);
  124. registry_json_footer(w);
  125. return HTTP_RESP_OK;
  126. }
  127. // ----------------------------------------------------------------------------
  128. //public ACCESS request
  129. #define REGISTRY_VERIFY_COOKIES_GUID "give-me-back-this-cookie-now--please"
  130. // the main method for registering an access
  131. int registry_request_access_json(RRDHOST *host, struct web_client *w, char *person_guid, char *machine_guid, char *url, char *name, time_t when) {
  132. if(unlikely(!registry.enabled))
  133. return registry_json_disabled(host, w, "access");
  134. // ------------------------------------------------------------------------
  135. // verify the browser supports cookies
  136. if(registry.verify_cookies_redirects > 0 && !person_guid[0]) {
  137. buffer_flush(w->response.data);
  138. registry_set_cookie(w, REGISTRY_VERIFY_COOKIES_GUID);
  139. w->response.data->content_type = CT_APPLICATION_JSON;
  140. registry_json_header(host, w, "access", REGISTRY_STATUS_REDIRECT);
  141. buffer_json_member_add_string(w->response.data, "registry", registry.registry_to_announce);
  142. registry_json_footer(w);
  143. return HTTP_RESP_OK;
  144. }
  145. if(unlikely(person_guid[0] && !strcmp(person_guid, REGISTRY_VERIFY_COOKIES_GUID)))
  146. person_guid[0] = '\0';
  147. // ------------------------------------------------------------------------
  148. registry_lock();
  149. REGISTRY_PERSON *p = registry_request_access(person_guid, machine_guid, url, name, when);
  150. if(!p) {
  151. registry_json_header(host, w, "access", REGISTRY_STATUS_FAILED);
  152. registry_json_footer(w);
  153. registry_unlock();
  154. return HTTP_RESP_PRECOND_FAIL;
  155. }
  156. // set the cookie
  157. registry_set_person_cookie(w, p);
  158. // generate the response
  159. registry_json_header(host, w, "access", REGISTRY_STATUS_OK);
  160. buffer_json_member_add_string(w->response.data, "person_guid", p->guid);
  161. buffer_json_member_add_array(w->response.data, "urls");
  162. struct registry_json_walk_person_urls_callback c = { p, NULL, w, 0 };
  163. avl_traverse(&p->person_urls, registry_json_person_url_callback, &c);
  164. buffer_json_array_close(w->response.data); // urls
  165. registry_json_footer(w);
  166. registry_unlock();
  167. return HTTP_RESP_OK;
  168. }
  169. // ----------------------------------------------------------------------------
  170. // public DELETE request
  171. // the main method for deleting a URL from a person
  172. int registry_request_delete_json(RRDHOST *host, struct web_client *w, char *person_guid, char *machine_guid, char *url, char *delete_url, time_t when) {
  173. if(!registry.enabled)
  174. return registry_json_disabled(host, w, "delete");
  175. registry_lock();
  176. REGISTRY_PERSON *p = registry_request_delete(person_guid, machine_guid, url, delete_url, when);
  177. if(!p) {
  178. registry_json_header(host, w, "delete", REGISTRY_STATUS_FAILED);
  179. registry_json_footer(w);
  180. registry_unlock();
  181. return HTTP_RESP_PRECOND_FAIL;
  182. }
  183. // generate the response
  184. registry_json_header(host, w, "delete", REGISTRY_STATUS_OK);
  185. registry_json_footer(w);
  186. registry_unlock();
  187. return HTTP_RESP_OK;
  188. }
  189. // ----------------------------------------------------------------------------
  190. // public SEARCH request
  191. // the main method for searching the URLs of a netdata
  192. int registry_request_search_json(RRDHOST *host, struct web_client *w, char *person_guid, char *machine_guid, char *url, char *request_machine, time_t when) {
  193. if(!registry.enabled)
  194. return registry_json_disabled(host, w, "search");
  195. registry_lock();
  196. REGISTRY_MACHINE *m = registry_request_machine(person_guid, machine_guid, url, request_machine, when);
  197. if(!m) {
  198. registry_json_header(host, w, "search", REGISTRY_STATUS_FAILED);
  199. registry_json_footer(w);
  200. registry_unlock();
  201. return HTTP_RESP_NOT_FOUND;
  202. }
  203. registry_json_header(host, w, "search", REGISTRY_STATUS_OK);
  204. buffer_json_member_add_array(w->response.data, "urls");
  205. struct registry_json_walk_person_urls_callback c = { NULL, m, w, 0 };
  206. dictionary_walkthrough_read(m->machine_urls, registry_json_machine_url_callback, &c);
  207. buffer_json_array_close(w->response.data);
  208. registry_json_footer(w);
  209. registry_unlock();
  210. return HTTP_RESP_OK;
  211. }
  212. // ----------------------------------------------------------------------------
  213. // SWITCH REQUEST
  214. // the main method for switching user identity
  215. int registry_request_switch_json(RRDHOST *host, struct web_client *w, char *person_guid, char *machine_guid, char *url, char *new_person_guid, time_t when) {
  216. if(!registry.enabled)
  217. return registry_json_disabled(host, w, "switch");
  218. (void)url;
  219. (void)when;
  220. registry_lock();
  221. REGISTRY_PERSON *op = registry_person_find(person_guid);
  222. if(!op) {
  223. registry_json_header(host, w, "switch", REGISTRY_STATUS_FAILED);
  224. registry_json_footer(w);
  225. registry_unlock();
  226. return 430;
  227. }
  228. REGISTRY_PERSON *np = registry_person_find(new_person_guid);
  229. if(!np) {
  230. registry_json_header(host, w, "switch", REGISTRY_STATUS_FAILED);
  231. registry_json_footer(w);
  232. registry_unlock();
  233. return 431;
  234. }
  235. REGISTRY_MACHINE *m = registry_machine_find(machine_guid);
  236. if(!m) {
  237. registry_json_header(host, w, "switch", REGISTRY_STATUS_FAILED);
  238. registry_json_footer(w);
  239. registry_unlock();
  240. return 432;
  241. }
  242. struct registry_person_url_callback_verify_machine_exists_data data = { m, 0 };
  243. // verify the old person has access to this machine
  244. avl_traverse(&op->person_urls, registry_person_url_callback_verify_machine_exists, &data);
  245. if(!data.count) {
  246. registry_json_header(host, w, "switch", REGISTRY_STATUS_FAILED);
  247. registry_json_footer(w);
  248. registry_unlock();
  249. return 433;
  250. }
  251. // verify the new person has access to this machine
  252. data.count = 0;
  253. avl_traverse(&np->person_urls, registry_person_url_callback_verify_machine_exists, &data);
  254. if(!data.count) {
  255. registry_json_header(host, w, "switch", REGISTRY_STATUS_FAILED);
  256. registry_json_footer(w);
  257. registry_unlock();
  258. return 434;
  259. }
  260. // set the cookie of the new person
  261. // the user just switched identity
  262. registry_set_person_cookie(w, np);
  263. // generate the response
  264. registry_json_header(host, w, "switch", REGISTRY_STATUS_OK);
  265. buffer_json_member_add_string(w->response.data, "person_guid", np->guid);
  266. registry_json_footer(w);
  267. registry_unlock();
  268. return HTTP_RESP_OK;
  269. }
  270. // ----------------------------------------------------------------------------
  271. // STATISTICS
  272. void registry_statistics(void) {
  273. if(!registry.enabled) return;
  274. static RRDSET *sts = NULL, *stc = NULL, *stm = NULL;
  275. if(unlikely(!sts)) {
  276. sts = rrdset_create_localhost(
  277. "netdata"
  278. , "registry_sessions"
  279. , NULL
  280. , "registry"
  281. , NULL
  282. , "Netdata Registry Sessions"
  283. , "sessions"
  284. , "registry"
  285. , "stats"
  286. , 131000
  287. , localhost->rrd_update_every
  288. , RRDSET_TYPE_LINE
  289. );
  290. rrddim_add(sts, "sessions", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  291. }
  292. rrddim_set(sts, "sessions", (collected_number)registry.usages_count);
  293. rrdset_done(sts);
  294. // ------------------------------------------------------------------------
  295. if(unlikely(!stc)) {
  296. stc = rrdset_create_localhost(
  297. "netdata"
  298. , "registry_entries"
  299. , NULL
  300. , "registry"
  301. , NULL
  302. , "Netdata Registry Entries"
  303. , "entries"
  304. , "registry"
  305. , "stats"
  306. , 131100
  307. , localhost->rrd_update_every
  308. , RRDSET_TYPE_LINE
  309. );
  310. rrddim_add(stc, "persons", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  311. rrddim_add(stc, "machines", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  312. rrddim_add(stc, "urls", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  313. rrddim_add(stc, "persons_urls", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  314. rrddim_add(stc, "machines_urls", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  315. }
  316. rrddim_set(stc, "persons", (collected_number)registry.persons_count);
  317. rrddim_set(stc, "machines", (collected_number)registry.machines_count);
  318. rrddim_set(stc, "urls", (collected_number)registry.urls_count);
  319. rrddim_set(stc, "persons_urls", (collected_number)registry.persons_urls_count);
  320. rrddim_set(stc, "machines_urls", (collected_number)registry.machines_urls_count);
  321. rrdset_done(stc);
  322. // ------------------------------------------------------------------------
  323. if(unlikely(!stm)) {
  324. stm = rrdset_create_localhost(
  325. "netdata"
  326. , "registry_mem"
  327. , NULL
  328. , "registry"
  329. , NULL
  330. , "Netdata Registry Memory"
  331. , "KiB"
  332. , "registry"
  333. , "stats"
  334. , 131300
  335. , localhost->rrd_update_every
  336. , RRDSET_TYPE_STACKED
  337. );
  338. rrddim_add(stm, "persons", NULL, 1, 1024, RRD_ALGORITHM_ABSOLUTE);
  339. rrddim_add(stm, "machines", NULL, 1, 1024, RRD_ALGORITHM_ABSOLUTE);
  340. rrddim_add(stm, "urls", NULL, 1, 1024, RRD_ALGORITHM_ABSOLUTE);
  341. rrddim_add(stm, "persons_urls", NULL, 1, 1024, RRD_ALGORITHM_ABSOLUTE);
  342. rrddim_add(stm, "machines_urls", NULL, 1, 1024, RRD_ALGORITHM_ABSOLUTE);
  343. }
  344. rrddim_set(stm, "persons", (collected_number)registry.persons_memory + dictionary_stats_for_registry(registry.persons));
  345. rrddim_set(stm, "machines", (collected_number)registry.machines_memory + dictionary_stats_for_registry(registry.machines));
  346. rrddim_set(stm, "urls", (collected_number)registry.urls_memory);
  347. rrddim_set(stm, "persons_urls", (collected_number)registry.persons_urls_memory);
  348. rrddim_set(stm, "machines_urls", (collected_number)registry.machines_urls_memory);
  349. rrdset_done(stm);
  350. }