s3api_server.go 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209
  1. package s3api
  2. import (
  3. "fmt"
  4. "net/http"
  5. "strings"
  6. "time"
  7. "github.com/chrislusf/seaweedfs/weed/filer"
  8. "github.com/chrislusf/seaweedfs/weed/pb"
  9. . "github.com/chrislusf/seaweedfs/weed/s3api/s3_constants"
  10. "github.com/chrislusf/seaweedfs/weed/s3api/s3err"
  11. "github.com/chrislusf/seaweedfs/weed/security"
  12. "github.com/chrislusf/seaweedfs/weed/util"
  13. "github.com/gorilla/mux"
  14. "google.golang.org/grpc"
  15. )
  16. type S3ApiServerOption struct {
  17. Filer pb.ServerAddress
  18. Port int
  19. Config string
  20. DomainName string
  21. BucketsPath string
  22. GrpcDialOption grpc.DialOption
  23. AllowEmptyFolder bool
  24. }
  25. type S3ApiServer struct {
  26. option *S3ApiServerOption
  27. iam *IdentityAccessManagement
  28. randomClientId int32
  29. filerGuard *security.Guard
  30. }
  31. func NewS3ApiServer(router *mux.Router, option *S3ApiServerOption) (s3ApiServer *S3ApiServer, err error) {
  32. v := util.GetViper()
  33. signingKey := v.GetString("jwt.filer_signing.key")
  34. v.SetDefault("jwt.filer_signing.expires_after_seconds", 10)
  35. expiresAfterSec := v.GetInt("jwt.filer_signing.expires_after_seconds")
  36. readSigningKey := v.GetString("jwt.filer_signing.read.key")
  37. v.SetDefault("jwt.filer_signing.read.expires_after_seconds", 60)
  38. readExpiresAfterSec := v.GetInt("jwt.filer_signing.read.expires_after_seconds")
  39. s3ApiServer = &S3ApiServer{
  40. option: option,
  41. iam: NewIdentityAccessManagement(option),
  42. randomClientId: util.RandomInt32(),
  43. filerGuard: security.NewGuard([]string{}, signingKey, expiresAfterSec, readSigningKey, readExpiresAfterSec),
  44. }
  45. s3ApiServer.registerRouter(router)
  46. go s3ApiServer.subscribeMetaEvents("s3", filer.IamConfigDirecotry+"/"+filer.IamIdentityFile, time.Now().UnixNano())
  47. return s3ApiServer, nil
  48. }
  49. func (s3a *S3ApiServer) registerRouter(router *mux.Router) {
  50. // API Router
  51. apiRouter := router.PathPrefix("/").Subrouter()
  52. // Readiness Probe
  53. apiRouter.Methods("GET").Path("/status").HandlerFunc(s3a.StatusHandler)
  54. var routers []*mux.Router
  55. if s3a.option.DomainName != "" {
  56. domainNames := strings.Split(s3a.option.DomainName, ",")
  57. for _, domainName := range domainNames {
  58. routers = append(routers, apiRouter.Host(
  59. fmt.Sprintf("%s.%s:%d", "{bucket:.+}", domainName, s3a.option.Port)).Subrouter())
  60. routers = append(routers, apiRouter.Host(
  61. fmt.Sprintf("%s.%s", "{bucket:.+}", domainName)).Subrouter())
  62. }
  63. }
  64. routers = append(routers, apiRouter.PathPrefix("/{bucket}").Subrouter())
  65. for _, bucket := range routers {
  66. // each case should follow the next rule:
  67. // - requesting object with query must precede any other methods
  68. // - requesting object must precede any methods with buckets
  69. // - requesting bucket with query must precede raw methods with buckets
  70. // - requesting bucket must be processed in the end
  71. // objects with query
  72. // CopyObjectPart
  73. bucket.Methods("PUT").Path("/{object:.+}").HeadersRegexp("X-Amz-Copy-Source", `.*?(\/|%2F).*?`).HandlerFunc(track(s3a.iam.Auth(s3a.CopyObjectPartHandler, ACTION_WRITE), "PUT")).Queries("partNumber", "{partNumber:[0-9]+}", "uploadId", "{uploadId:.*}")
  74. // PutObjectPart
  75. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectPartHandler, ACTION_WRITE), "PUT")).Queries("partNumber", "{partNumber:[0-9]+}", "uploadId", "{uploadId:.*}")
  76. // CompleteMultipartUpload
  77. bucket.Methods("POST").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.CompleteMultipartUploadHandler, ACTION_WRITE), "POST")).Queries("uploadId", "{uploadId:.*}")
  78. // NewMultipartUpload
  79. bucket.Methods("POST").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.NewMultipartUploadHandler, ACTION_WRITE), "POST")).Queries("uploads", "")
  80. // AbortMultipartUpload
  81. bucket.Methods("DELETE").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.AbortMultipartUploadHandler, ACTION_WRITE), "DELETE")).Queries("uploadId", "{uploadId:.*}")
  82. // ListObjectParts
  83. bucket.Methods("GET").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.ListObjectPartsHandler, ACTION_READ), "GET")).Queries("uploadId", "{uploadId:.*}")
  84. // ListMultipartUploads
  85. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.ListMultipartUploadsHandler, ACTION_READ), "GET")).Queries("uploads", "")
  86. // GetObjectTagging
  87. bucket.Methods("GET").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.GetObjectTaggingHandler, ACTION_READ), "GET")).Queries("tagging", "")
  88. // PutObjectTagging
  89. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectTaggingHandler, ACTION_TAGGING), "PUT")).Queries("tagging", "")
  90. // DeleteObjectTagging
  91. bucket.Methods("DELETE").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteObjectTaggingHandler, ACTION_TAGGING), "DELETE")).Queries("tagging", "")
  92. // PutObjectACL
  93. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectAclHandler, ACTION_WRITE), "PUT")).Queries("acl", "")
  94. // PutObjectRetention
  95. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectRetentionHandler, ACTION_WRITE), "PUT")).Queries("retention", "")
  96. // PutObjectLegalHold
  97. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectLegalHoldHandler, ACTION_WRITE), "PUT")).Queries("legal-hold", "")
  98. // PutObjectLockConfiguration
  99. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectLockConfigurationHandler, ACTION_WRITE), "PUT")).Queries("object-lock", "")
  100. // GetObjectACL
  101. bucket.Methods("GET").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.GetObjectAclHandler, ACTION_READ), "GET")).Queries("acl", "")
  102. // objects with query
  103. // raw objects
  104. // HeadObject
  105. bucket.Methods("HEAD").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.HeadObjectHandler, ACTION_READ), "GET"))
  106. // GetObject, but directory listing is not supported
  107. bucket.Methods("GET").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.GetObjectHandler, ACTION_READ), "GET"))
  108. // CopyObject
  109. bucket.Methods("PUT").Path("/{object:.+}").HeadersRegexp("X-Amz-Copy-Source", ".*?(\\/|%2F).*?").HandlerFunc(track(s3a.iam.Auth(s3a.CopyObjectHandler, ACTION_WRITE), "COPY"))
  110. // PutObject
  111. bucket.Methods("PUT").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.PutObjectHandler, ACTION_WRITE), "PUT"))
  112. // DeleteObject
  113. bucket.Methods("DELETE").Path("/{object:.+}").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteObjectHandler, ACTION_WRITE), "DELETE"))
  114. // raw objects
  115. // buckets with query
  116. // DeleteMultipleObjects
  117. bucket.Methods("POST").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteMultipleObjectsHandler, ACTION_WRITE), "DELETE")).Queries("delete", "")
  118. // GetBucketACL
  119. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketAclHandler, ACTION_READ), "GET")).Queries("acl", "")
  120. // PutBucketACL
  121. bucket.Methods("PUT").HandlerFunc(track(s3a.iam.Auth(s3a.PutBucketAclHandler, ACTION_WRITE), "PUT")).Queries("acl", "")
  122. // GetBucketPolicy
  123. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketPolicyHandler, ACTION_READ), "GET")).Queries("policy", "")
  124. // PutBucketPolicy
  125. bucket.Methods("PUT").HandlerFunc(track(s3a.iam.Auth(s3a.PutBucketPolicyHandler, ACTION_WRITE), "PUT")).Queries("policy", "")
  126. // DeleteBucketPolicy
  127. bucket.Methods("DELETE").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteBucketPolicyHandler, ACTION_WRITE), "DELETE")).Queries("policy", "")
  128. // GetBucketCors
  129. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketCorsHandler, ACTION_READ), "GET")).Queries("cors", "")
  130. // PutBucketCors
  131. bucket.Methods("PUT").HandlerFunc(track(s3a.iam.Auth(s3a.PutBucketCorsHandler, ACTION_WRITE), "PUT")).Queries("cors", "")
  132. // DeleteBucketCors
  133. bucket.Methods("DELETE").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteBucketCorsHandler, ACTION_WRITE), "DELETE")).Queries("cors", "")
  134. // GetBucketLifecycleConfiguration
  135. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketLifecycleConfigurationHandler, ACTION_READ), "GET")).Queries("lifecycle", "")
  136. // PutBucketLifecycleConfiguration
  137. bucket.Methods("PUT").HandlerFunc(track(s3a.iam.Auth(s3a.PutBucketLifecycleConfigurationHandler, ACTION_WRITE), "PUT")).Queries("lifecycle", "")
  138. // DeleteBucketLifecycleConfiguration
  139. bucket.Methods("DELETE").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteBucketLifecycleHandler, ACTION_WRITE), "DELETE")).Queries("lifecycle", "")
  140. // GetBucketLocation
  141. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketLocationHandler, ACTION_READ), "GET")).Queries("location", "")
  142. // GetBucketRequestPayment
  143. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.GetBucketRequestPaymentHandler, ACTION_READ), "GET")).Queries("requestPayment", "")
  144. // ListObjectsV2
  145. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.ListObjectsV2Handler, ACTION_LIST), "LIST")).Queries("list-type", "2")
  146. // buckets with query
  147. // raw buckets
  148. // PostPolicy
  149. bucket.Methods("POST").HeadersRegexp("Content-Type", "multipart/form-data*").HandlerFunc(track(s3a.iam.Auth(s3a.PostPolicyBucketHandler, ACTION_WRITE), "POST"))
  150. // HeadBucket
  151. bucket.Methods("HEAD").HandlerFunc(track(s3a.iam.Auth(s3a.HeadBucketHandler, ACTION_READ), "GET"))
  152. // PutBucket
  153. bucket.Methods("PUT").HandlerFunc(track(s3a.PutBucketHandler, "PUT"))
  154. // DeleteBucket
  155. bucket.Methods("DELETE").HandlerFunc(track(s3a.iam.Auth(s3a.DeleteBucketHandler, ACTION_WRITE), "DELETE"))
  156. // ListObjectsV1 (Legacy)
  157. bucket.Methods("GET").HandlerFunc(track(s3a.iam.Auth(s3a.ListObjectsV1Handler, ACTION_LIST), "LIST"))
  158. // raw buckets
  159. }
  160. // ListBuckets
  161. apiRouter.Methods("GET").Path("/").HandlerFunc(track(s3a.ListBucketsHandler, "LIST"))
  162. // NotFound
  163. apiRouter.NotFoundHandler = http.HandlerFunc(s3err.NotFoundHandler)
  164. }