server_twilio.go 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199
  1. package server
  2. import (
  3. "bytes"
  4. "encoding/xml"
  5. "fmt"
  6. "github.com/prometheus/client_golang/prometheus"
  7. "heckel.io/ntfy/log"
  8. "heckel.io/ntfy/user"
  9. "heckel.io/ntfy/util"
  10. "io"
  11. "net/http"
  12. "net/url"
  13. "strings"
  14. )
  15. const (
  16. twilioCallEndpoint = "Calls.json"
  17. twilioCallFormat = `
  18. <Response>
  19. <Pause length="1"/>
  20. <Say loop="5">
  21. You have a notification from notify on topic %s. Message:
  22. <break time="1s"/>
  23. %s
  24. <break time="1s"/>
  25. End message.
  26. <break time="1s"/>
  27. This message was sent by user %s. It will be repeated up to five times.
  28. <break time="3s"/>
  29. </Say>
  30. <Say>Goodbye.</Say>
  31. </Response>`
  32. )
  33. func (s *Server) convertPhoneNumber(u *user.User, phoneNumber string) (string, *errHTTP) {
  34. if u == nil {
  35. return "", errHTTPBadRequestAnonymousCallsNotAllowed
  36. }
  37. phoneNumbers, err := s.userManager.PhoneNumbers(u.ID)
  38. if err != nil {
  39. return "", errHTTPInternalError
  40. } else if len(phoneNumbers) == 0 {
  41. return "", errHTTPBadRequestPhoneNumberNotVerified
  42. }
  43. if toBool(phoneNumber) {
  44. return phoneNumbers[0], nil
  45. } else if util.Contains(phoneNumbers, phoneNumber) {
  46. return phoneNumber, nil
  47. }
  48. for _, p := range phoneNumbers {
  49. if p == phoneNumber {
  50. return phoneNumber, nil
  51. }
  52. }
  53. return "", errHTTPBadRequestPhoneNumberNotVerified
  54. }
  55. func (s *Server) callPhone(v *visitor, r *http.Request, m *message, to string) {
  56. u, sender := v.User(), m.Sender.String()
  57. if u != nil {
  58. sender = u.Name
  59. }
  60. body := fmt.Sprintf(twilioCallFormat, xmlEscapeText(m.Topic), xmlEscapeText(m.Message), xmlEscapeText(sender))
  61. data := url.Values{}
  62. data.Set("From", s.config.TwilioFromNumber)
  63. data.Set("To", to)
  64. data.Set("Twiml", body)
  65. s.twilioMessagingRequest(v, r, m, metricCallsMadeSuccess, metricCallsMadeFailure, twilioCallEndpoint, to, body, data)
  66. }
  67. func (s *Server) verifyPhone(v *visitor, r *http.Request, phoneNumber string) error {
  68. logvr(v, r).Tag(tagTwilio).Field("twilio_to", phoneNumber).Debug("Sending phone verification")
  69. data := url.Values{}
  70. data.Set("To", phoneNumber)
  71. data.Set("Channel", "sms")
  72. requestURL := fmt.Sprintf("%s/v2/Services/%s/Verifications", s.config.TwilioVerifyBaseURL, s.config.TwilioVerifyService)
  73. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  74. if err != nil {
  75. return err
  76. }
  77. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  78. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  79. resp, err := http.DefaultClient.Do(req)
  80. if err != nil {
  81. return err
  82. }
  83. response, err := io.ReadAll(resp.Body)
  84. ev := logvr(v, r).Tag(tagTwilio)
  85. if err != nil {
  86. ev.Err(err).Warn("Error sending Twilio phone verification request")
  87. return err
  88. }
  89. if ev.IsTrace() {
  90. ev.Field("twilio_response", string(response)).Trace("Received successful Twilio phone verification response")
  91. } else if ev.IsDebug() {
  92. ev.Debug("Received successful Twilio phone verification response")
  93. }
  94. return nil
  95. }
  96. func (s *Server) checkVerifyPhone(v *visitor, r *http.Request, phoneNumber, code string) error {
  97. logvr(v, r).Tag(tagTwilio).Field("twilio_to", phoneNumber).Debug("Checking phone verification")
  98. data := url.Values{}
  99. data.Set("To", phoneNumber)
  100. data.Set("Code", code)
  101. requestURL := fmt.Sprintf("%s/v2/Services/%s/VerificationCheck", s.config.TwilioVerifyBaseURL, s.config.TwilioVerifyService)
  102. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  103. if err != nil {
  104. return err
  105. }
  106. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  107. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  108. log.Fields(httpContext(req)).Field("http_body", data.Encode()).Info("Twilio call")
  109. ev := logvr(v, r).
  110. Tag(tagTwilio).
  111. Field("twilio_to", phoneNumber)
  112. resp, err := http.DefaultClient.Do(req)
  113. if err != nil {
  114. return err
  115. } else if resp.StatusCode != http.StatusOK {
  116. if ev.IsTrace() {
  117. response, err := io.ReadAll(resp.Body)
  118. if err != nil {
  119. return err
  120. }
  121. ev.Field("twilio_response", string(response))
  122. }
  123. ev.Warn("Twilio phone verification failed with status code %d", resp.StatusCode)
  124. if resp.StatusCode == http.StatusNotFound {
  125. return errHTTPGonePhoneVerificationExpired
  126. }
  127. return errHTTPInternalError
  128. }
  129. response, err := io.ReadAll(resp.Body)
  130. if err != nil {
  131. return err
  132. }
  133. if ev.IsTrace() {
  134. ev.Field("twilio_response", string(response)).Trace("Received successful Twilio phone verification response")
  135. } else if ev.IsDebug() {
  136. ev.Debug("Received successful Twilio phone verification response")
  137. }
  138. return nil
  139. }
  140. func (s *Server) twilioMessagingRequest(v *visitor, r *http.Request, m *message, msuccess, mfailure prometheus.Counter, endpoint, to, body string, data url.Values) {
  141. logContext := log.Context{
  142. "twilio_from": s.config.TwilioFromNumber,
  143. "twilio_to": to,
  144. }
  145. ev := logvrm(v, r, m).Tag(tagTwilio).Fields(logContext)
  146. if ev.IsTrace() {
  147. ev.Field("twilio_body", body).Trace("Sending Twilio request")
  148. } else if ev.IsDebug() {
  149. ev.Debug("Sending Twilio request")
  150. }
  151. response, err := s.performTwilioMessagingRequestInternal(endpoint, data)
  152. if err != nil {
  153. ev.
  154. Field("twilio_body", body).
  155. Field("twilio_response", response).
  156. Err(err).
  157. Warn("Error sending Twilio request")
  158. minc(mfailure)
  159. return
  160. }
  161. if ev.IsTrace() {
  162. ev.Field("twilio_response", response).Trace("Received successful Twilio response")
  163. } else if ev.IsDebug() {
  164. ev.Debug("Received successful Twilio response")
  165. }
  166. minc(msuccess)
  167. }
  168. func (s *Server) performTwilioMessagingRequestInternal(endpoint string, data url.Values) (string, error) {
  169. requestURL := fmt.Sprintf("%s/2010-04-01/Accounts/%s/%s", s.config.TwilioMessagingBaseURL, s.config.TwilioAccount, endpoint)
  170. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  171. if err != nil {
  172. return "", err
  173. }
  174. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  175. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  176. resp, err := http.DefaultClient.Do(req)
  177. if err != nil {
  178. return "", err
  179. }
  180. response, err := io.ReadAll(resp.Body)
  181. if err != nil {
  182. return "", err
  183. }
  184. return string(response), nil
  185. }
  186. func xmlEscapeText(text string) string {
  187. var buf bytes.Buffer
  188. _ = xml.EscapeText(&buf, []byte(text))
  189. return buf.String()
  190. }