api.js 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440
  1. import { arrayToB64, b64ToArray, delay } from './utils';
  2. import { ECE_RECORD_SIZE } from './ece';
  3. let fileProtocolWssUrl = null;
  4. try {
  5. fileProtocolWssUrl = localStorage.getItem('wssURL');
  6. } catch (e) {
  7. // NOOP
  8. }
  9. if (!fileProtocolWssUrl) {
  10. fileProtocolWssUrl = 'wss://send.firefox.com/api/ws';
  11. }
  12. export class ConnectionError extends Error {
  13. constructor(cancelled, duration, size) {
  14. super(cancelled ? '0' : 'connection closed');
  15. this.cancelled = cancelled;
  16. this.duration = duration;
  17. this.size = size;
  18. }
  19. }
  20. export function setFileProtocolWssUrl(url) {
  21. localStorage && localStorage.setItem('wssURL', url);
  22. fileProtocolWssUrl = url;
  23. }
  24. export function getFileProtocolWssUrl() {
  25. return fileProtocolWssUrl;
  26. }
  27. let apiUrlPrefix = '';
  28. export function getApiUrl(path) {
  29. return apiUrlPrefix + path;
  30. }
  31. export function setApiUrlPrefix(prefix) {
  32. apiUrlPrefix = prefix;
  33. }
  34. function post(obj, bearerToken) {
  35. const h = {
  36. 'Content-Type': 'application/json'
  37. };
  38. if (bearerToken) {
  39. h['Authentication'] = `Bearer ${bearerToken}`;
  40. }
  41. return {
  42. method: 'POST',
  43. headers: new Headers(h),
  44. body: JSON.stringify(obj)
  45. };
  46. }
  47. export function parseNonce(header) {
  48. header = header || '';
  49. return header.split(' ')[1];
  50. }
  51. async function fetchWithAuth(url, params, keychain) {
  52. const result = {};
  53. params = params || {};
  54. const h = await keychain.authHeader();
  55. params.headers = new Headers({ Authorization: h });
  56. const response = await fetch(url, params);
  57. result.response = response;
  58. result.ok = response.ok;
  59. const nonce = parseNonce(response.headers.get('WWW-Authenticate'));
  60. result.shouldRetry = response.status === 401 && nonce !== keychain.nonce;
  61. keychain.nonce = nonce;
  62. return result;
  63. }
  64. async function fetchWithAuthAndRetry(url, params, keychain) {
  65. const result = await fetchWithAuth(url, params, keychain);
  66. if (result.shouldRetry) {
  67. return fetchWithAuth(url, params, keychain);
  68. }
  69. return result;
  70. }
  71. export async function del(id, owner_token) {
  72. const response = await fetch(
  73. getApiUrl(`/api/delete/${id}`),
  74. post({ owner_token })
  75. );
  76. return response.ok;
  77. }
  78. export async function setParams(id, owner_token, bearerToken, params) {
  79. const response = await fetch(
  80. getApiUrl(`/api/params/${id}`),
  81. post(
  82. {
  83. owner_token,
  84. dlimit: params.dlimit
  85. },
  86. bearerToken
  87. )
  88. );
  89. return response.ok;
  90. }
  91. export async function fileInfo(id, owner_token) {
  92. const response = await fetch(
  93. getApiUrl(`/api/info/${id}`),
  94. post({ owner_token })
  95. );
  96. if (response.ok) {
  97. const obj = await response.json();
  98. return obj;
  99. }
  100. throw new Error(response.status);
  101. }
  102. export async function metadata(id, keychain) {
  103. const result = await fetchWithAuthAndRetry(
  104. getApiUrl(`/api/metadata/${id}`),
  105. { method: 'GET' },
  106. keychain
  107. );
  108. if (result.ok) {
  109. const data = await result.response.json();
  110. const meta = await keychain.decryptMetadata(b64ToArray(data.metadata));
  111. return {
  112. size: meta.size,
  113. ttl: data.ttl,
  114. iv: meta.iv,
  115. name: meta.name,
  116. type: meta.type,
  117. manifest: meta.manifest
  118. };
  119. }
  120. throw new Error(result.response.status);
  121. }
  122. export async function setPassword(id, owner_token, keychain) {
  123. const auth = await keychain.authKeyB64();
  124. const response = await fetch(
  125. getApiUrl(`/api/password/${id}`),
  126. post({ owner_token, auth })
  127. );
  128. return response.ok;
  129. }
  130. function asyncInitWebSocket(server) {
  131. return new Promise((resolve, reject) => {
  132. try {
  133. const ws = new WebSocket(server);
  134. ws.addEventListener('open', () => resolve(ws), { once: true });
  135. } catch (e) {
  136. reject(new ConnectionError(false));
  137. }
  138. });
  139. }
  140. function listenForResponse(ws, canceller) {
  141. return new Promise((resolve, reject) => {
  142. function handleClose(event) {
  143. // a 'close' event before a 'message' event means the request failed
  144. ws.removeEventListener('message', handleMessage);
  145. reject(new ConnectionError(canceller.cancelled));
  146. }
  147. function handleMessage(msg) {
  148. ws.removeEventListener('close', handleClose);
  149. try {
  150. const response = JSON.parse(msg.data);
  151. if (response.error) {
  152. throw new Error(response.error);
  153. } else {
  154. resolve(response);
  155. }
  156. } catch (e) {
  157. reject(e);
  158. }
  159. }
  160. ws.addEventListener('message', handleMessage, { once: true });
  161. ws.addEventListener('close', handleClose, { once: true });
  162. });
  163. }
  164. async function upload(
  165. stream,
  166. metadata,
  167. verifierB64,
  168. timeLimit,
  169. dlimit,
  170. bearerToken,
  171. onprogress,
  172. canceller
  173. ) {
  174. let size = 0;
  175. const start = Date.now();
  176. const host = window.location.hostname;
  177. const port = window.location.port;
  178. const protocol = window.location.protocol === 'https:' ? 'wss:' : 'ws:';
  179. const endpoint =
  180. window.location.protocol === 'file:'
  181. ? fileProtocolWssUrl
  182. : `${protocol}//${host}${port ? ':' : ''}${port}/api/ws`;
  183. const ws = await asyncInitWebSocket(endpoint);
  184. try {
  185. const metadataHeader = arrayToB64(new Uint8Array(metadata));
  186. const fileMeta = {
  187. fileMetadata: metadataHeader,
  188. authorization: `send-v1 ${verifierB64}`,
  189. bearer: bearerToken,
  190. timeLimit,
  191. dlimit
  192. };
  193. const uploadInfoResponse = listenForResponse(ws, canceller);
  194. ws.send(JSON.stringify(fileMeta));
  195. const uploadInfo = await uploadInfoResponse;
  196. const completedResponse = listenForResponse(ws, canceller);
  197. const reader = stream.getReader();
  198. let state = await reader.read();
  199. while (!state.done) {
  200. if (canceller.cancelled) {
  201. ws.close();
  202. }
  203. if (ws.readyState !== WebSocket.OPEN) {
  204. break;
  205. }
  206. const buf = state.value;
  207. ws.send(buf);
  208. onprogress(size);
  209. size += buf.length;
  210. state = await reader.read();
  211. while (
  212. ws.bufferedAmount > ECE_RECORD_SIZE * 2 &&
  213. ws.readyState === WebSocket.OPEN &&
  214. !canceller.cancelled
  215. ) {
  216. await delay();
  217. }
  218. }
  219. if (ws.readyState === WebSocket.OPEN) {
  220. ws.send(new Uint8Array([0])); //EOF
  221. }
  222. await completedResponse;
  223. uploadInfo.duration = Date.now() - start;
  224. return uploadInfo;
  225. } catch (e) {
  226. e.size = size;
  227. e.duration = Date.now() - start;
  228. throw e;
  229. } finally {
  230. if (![WebSocket.CLOSED, WebSocket.CLOSING].includes(ws.readyState)) {
  231. ws.close();
  232. }
  233. }
  234. }
  235. export function uploadWs(
  236. encrypted,
  237. metadata,
  238. verifierB64,
  239. timeLimit,
  240. dlimit,
  241. bearerToken,
  242. onprogress
  243. ) {
  244. const canceller = { cancelled: false };
  245. return {
  246. cancel: function() {
  247. canceller.cancelled = true;
  248. },
  249. result: upload(
  250. encrypted,
  251. metadata,
  252. verifierB64,
  253. timeLimit,
  254. dlimit,
  255. bearerToken,
  256. onprogress,
  257. canceller
  258. )
  259. };
  260. }
  261. ////////////////////////
  262. async function downloadS(id, keychain, signal) {
  263. const auth = await keychain.authHeader();
  264. const response = await fetch(getApiUrl(`/api/download/${id}`), {
  265. signal: signal,
  266. method: 'GET',
  267. headers: { Authorization: auth }
  268. });
  269. const authHeader = response.headers.get('WWW-Authenticate');
  270. if (authHeader) {
  271. keychain.nonce = parseNonce(authHeader);
  272. }
  273. if (response.status !== 200) {
  274. throw new Error(response.status);
  275. }
  276. return response.body;
  277. }
  278. async function tryDownloadStream(id, keychain, signal, tries = 2) {
  279. try {
  280. const result = await downloadS(id, keychain, signal);
  281. return result;
  282. } catch (e) {
  283. if (e.message === '401' && --tries > 0) {
  284. return tryDownloadStream(id, keychain, signal, tries);
  285. }
  286. if (e.name === 'AbortError') {
  287. throw new Error('0');
  288. }
  289. throw e;
  290. }
  291. }
  292. export function downloadStream(id, keychain) {
  293. const controller = new AbortController();
  294. function cancel() {
  295. controller.abort();
  296. }
  297. return {
  298. cancel,
  299. result: tryDownloadStream(id, keychain, controller.signal)
  300. };
  301. }
  302. //////////////////
  303. async function download(id, keychain, onprogress, canceller) {
  304. const auth = await keychain.authHeader();
  305. const xhr = new XMLHttpRequest();
  306. canceller.oncancel = function() {
  307. xhr.abort();
  308. };
  309. return new Promise(function(resolve, reject) {
  310. xhr.addEventListener('loadend', function() {
  311. canceller.oncancel = function() {};
  312. const authHeader = xhr.getResponseHeader('WWW-Authenticate');
  313. if (authHeader) {
  314. keychain.nonce = parseNonce(authHeader);
  315. }
  316. if (xhr.status !== 200) {
  317. return reject(new Error(xhr.status));
  318. }
  319. const blob = new Blob([xhr.response]);
  320. resolve(blob);
  321. });
  322. xhr.addEventListener('progress', function(event) {
  323. if (event.target.status === 200) {
  324. onprogress(event.loaded);
  325. }
  326. });
  327. xhr.open('get', getApiUrl(`/api/download/blob/${id}`));
  328. xhr.setRequestHeader('Authorization', auth);
  329. xhr.responseType = 'blob';
  330. xhr.send();
  331. onprogress(0);
  332. });
  333. }
  334. async function tryDownload(id, keychain, onprogress, canceller, tries = 2) {
  335. try {
  336. const result = await download(id, keychain, onprogress, canceller);
  337. return result;
  338. } catch (e) {
  339. if (e.message === '401' && --tries > 0) {
  340. return tryDownload(id, keychain, onprogress, canceller, tries);
  341. }
  342. throw e;
  343. }
  344. }
  345. export function downloadFile(id, keychain, onprogress) {
  346. const canceller = {
  347. oncancel: function() {} // download() sets this
  348. };
  349. function cancel() {
  350. canceller.oncancel();
  351. }
  352. return {
  353. cancel,
  354. result: tryDownload(id, keychain, onprogress, canceller)
  355. };
  356. }
  357. export async function getFileList(bearerToken, kid) {
  358. const headers = new Headers({ Authorization: `Bearer ${bearerToken}` });
  359. const response = await fetch(getApiUrl(`/api/filelist/${kid}`), { headers });
  360. if (response.ok) {
  361. const encrypted = await response.blob();
  362. return encrypted;
  363. }
  364. throw new Error(response.status);
  365. }
  366. export async function setFileList(bearerToken, kid, data) {
  367. const headers = new Headers({ Authorization: `Bearer ${bearerToken}` });
  368. const response = await fetch(getApiUrl(`/api/filelist/${kid}`), {
  369. headers,
  370. method: 'POST',
  371. body: data
  372. });
  373. return response.ok;
  374. }
  375. export function sendMetrics(blob) {
  376. if (!navigator.sendBeacon) {
  377. return;
  378. }
  379. try {
  380. navigator.sendBeacon(getApiUrl('/api/metrics'), blob);
  381. } catch (e) {
  382. console.error(e);
  383. }
  384. }
  385. export async function getConstants() {
  386. const response = await fetch(getApiUrl('/config'));
  387. if (response.ok) {
  388. const obj = await response.json();
  389. return obj;
  390. }
  391. throw new Error(response.status);
  392. }