api.js 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472
  1. import { arrayToB64, b64ToArray, delay } from './utils';
  2. import { ECE_RECORD_SIZE } from './ece';
  3. let fileProtocolWssUrl = null;
  4. try {
  5. fileProtocolWssUrl = localStorage.getItem('wssURL');
  6. } catch (e) {
  7. // NOOP
  8. }
  9. if (!fileProtocolWssUrl) {
  10. fileProtocolWssUrl = 'wss://send.firefox.com/api/ws';
  11. }
  12. export class ConnectionError extends Error {
  13. constructor(cancelled, duration, size) {
  14. super(cancelled ? '0' : 'connection closed');
  15. this.cancelled = cancelled;
  16. this.duration = duration;
  17. this.size = size;
  18. }
  19. }
  20. export function setFileProtocolWssUrl(url) {
  21. localStorage && localStorage.setItem('wssURL', url);
  22. fileProtocolWssUrl = url;
  23. }
  24. export function getFileProtocolWssUrl() {
  25. return fileProtocolWssUrl;
  26. }
  27. let apiUrlPrefix = '';
  28. export function getApiUrl(path) {
  29. return apiUrlPrefix + path;
  30. }
  31. export function setApiUrlPrefix(prefix) {
  32. apiUrlPrefix = prefix;
  33. }
  34. function post(obj, bearerToken) {
  35. const h = {
  36. 'Content-Type': 'application/json'
  37. };
  38. if (bearerToken) {
  39. h['Authentication'] = `Bearer ${bearerToken}`;
  40. }
  41. return {
  42. method: 'POST',
  43. headers: new Headers(h),
  44. body: JSON.stringify(obj)
  45. };
  46. }
  47. export function parseNonce(header) {
  48. header = header || '';
  49. return header.split(' ')[1];
  50. }
  51. async function fetchWithAuth(url, params, keychain) {
  52. const result = {};
  53. params = params || {};
  54. const h = await keychain.authHeader();
  55. params.headers = new Headers({
  56. Authorization: h,
  57. 'Content-Type': 'application/json'
  58. });
  59. const response = await fetch(url, params);
  60. result.response = response;
  61. result.ok = response.ok;
  62. const nonce = parseNonce(response.headers.get('WWW-Authenticate'));
  63. result.shouldRetry = response.status === 401 && nonce !== keychain.nonce;
  64. keychain.nonce = nonce;
  65. return result;
  66. }
  67. async function fetchWithAuthAndRetry(url, params, keychain) {
  68. const result = await fetchWithAuth(url, params, keychain);
  69. if (result.shouldRetry) {
  70. return fetchWithAuth(url, params, keychain);
  71. }
  72. return result;
  73. }
  74. export async function del(id, owner_token) {
  75. const response = await fetch(
  76. getApiUrl(`/api/delete/${id}`),
  77. post({ owner_token })
  78. );
  79. return response.ok;
  80. }
  81. export async function setParams(id, owner_token, bearerToken, params) {
  82. const response = await fetch(
  83. getApiUrl(`/api/params/${id}`),
  84. post(
  85. {
  86. owner_token,
  87. dlimit: params.dlimit
  88. },
  89. bearerToken
  90. )
  91. );
  92. return response.ok;
  93. }
  94. export async function fileInfo(id, owner_token) {
  95. const response = await fetch(
  96. getApiUrl(`/api/info/${id}`),
  97. post({ owner_token })
  98. );
  99. if (response.ok) {
  100. const obj = await response.json();
  101. return obj;
  102. }
  103. throw new Error(response.status);
  104. }
  105. export async function metadata(id, keychain) {
  106. const result = await fetchWithAuthAndRetry(
  107. getApiUrl(`/api/metadata/${id}`),
  108. { method: 'GET' },
  109. keychain
  110. );
  111. if (result.ok) {
  112. const data = await result.response.json();
  113. const meta = await keychain.decryptMetadata(b64ToArray(data.metadata));
  114. return {
  115. size: meta.size,
  116. ttl: data.ttl,
  117. name: meta.name,
  118. type: meta.type,
  119. manifest: meta.manifest,
  120. flagged: data.flagged
  121. };
  122. }
  123. throw new Error(result.response.status);
  124. }
  125. export async function setPassword(id, owner_token, keychain) {
  126. const auth = await keychain.authKeyB64();
  127. const response = await fetch(
  128. getApiUrl(`/api/password/${id}`),
  129. post({ owner_token, auth })
  130. );
  131. return response.ok;
  132. }
  133. function asyncInitWebSocket(server) {
  134. return new Promise((resolve, reject) => {
  135. try {
  136. const ws = new WebSocket(server);
  137. ws.addEventListener('open', () => resolve(ws), { once: true });
  138. } catch (e) {
  139. reject(new ConnectionError(false));
  140. }
  141. });
  142. }
  143. function listenForResponse(ws, canceller) {
  144. return new Promise((resolve, reject) => {
  145. function handleClose(event) {
  146. // a 'close' event before a 'message' event means the request failed
  147. ws.removeEventListener('message', handleMessage);
  148. reject(new ConnectionError(canceller.cancelled));
  149. }
  150. function handleMessage(msg) {
  151. ws.removeEventListener('close', handleClose);
  152. try {
  153. const response = JSON.parse(msg.data);
  154. if (response.error) {
  155. throw new Error(response.error);
  156. } else {
  157. resolve(response);
  158. }
  159. } catch (e) {
  160. reject(e);
  161. }
  162. }
  163. ws.addEventListener('message', handleMessage, { once: true });
  164. ws.addEventListener('close', handleClose, { once: true });
  165. });
  166. }
  167. async function upload(
  168. stream,
  169. metadata,
  170. verifierB64,
  171. timeLimit,
  172. dlimit,
  173. bearerToken,
  174. onprogress,
  175. canceller
  176. ) {
  177. let size = 0;
  178. const start = Date.now();
  179. const host = window.location.hostname;
  180. const port = window.location.port;
  181. const protocol = window.location.protocol === 'https:' ? 'wss:' : 'ws:';
  182. const endpoint =
  183. window.location.protocol === 'file:'
  184. ? fileProtocolWssUrl
  185. : `${protocol}//${host}${port ? ':' : ''}${port}/api/ws`;
  186. const ws = await asyncInitWebSocket(endpoint);
  187. try {
  188. const metadataHeader = arrayToB64(new Uint8Array(metadata));
  189. const fileMeta = {
  190. fileMetadata: metadataHeader,
  191. authorization: `send-v1 ${verifierB64}`,
  192. bearer: bearerToken,
  193. timeLimit,
  194. dlimit
  195. };
  196. const uploadInfoResponse = listenForResponse(ws, canceller);
  197. ws.send(JSON.stringify(fileMeta));
  198. const uploadInfo = await uploadInfoResponse;
  199. const completedResponse = listenForResponse(ws, canceller);
  200. const reader = stream.getReader();
  201. let state = await reader.read();
  202. while (!state.done) {
  203. if (canceller.cancelled) {
  204. ws.close();
  205. }
  206. if (ws.readyState !== WebSocket.OPEN) {
  207. break;
  208. }
  209. const buf = state.value;
  210. ws.send(buf);
  211. onprogress(size);
  212. size += buf.length;
  213. state = await reader.read();
  214. while (
  215. ws.bufferedAmount > ECE_RECORD_SIZE * 2 &&
  216. ws.readyState === WebSocket.OPEN &&
  217. !canceller.cancelled
  218. ) {
  219. await delay();
  220. }
  221. }
  222. if (ws.readyState === WebSocket.OPEN) {
  223. ws.send(new Uint8Array([0])); //EOF
  224. }
  225. await completedResponse;
  226. uploadInfo.duration = Date.now() - start;
  227. return uploadInfo;
  228. } catch (e) {
  229. e.size = size;
  230. e.duration = Date.now() - start;
  231. throw e;
  232. } finally {
  233. if (![WebSocket.CLOSED, WebSocket.CLOSING].includes(ws.readyState)) {
  234. ws.close();
  235. }
  236. }
  237. }
  238. export function uploadWs(
  239. encrypted,
  240. metadata,
  241. verifierB64,
  242. timeLimit,
  243. dlimit,
  244. bearerToken,
  245. onprogress
  246. ) {
  247. const canceller = { cancelled: false };
  248. return {
  249. cancel: function() {
  250. canceller.cancelled = true;
  251. },
  252. result: upload(
  253. encrypted,
  254. metadata,
  255. verifierB64,
  256. timeLimit,
  257. dlimit,
  258. bearerToken,
  259. onprogress,
  260. canceller
  261. )
  262. };
  263. }
  264. ////////////////////////
  265. async function _downloadStream(id, dlToken, signal) {
  266. const response = await fetch(getApiUrl(`/api/download/${id}`), {
  267. signal: signal,
  268. method: 'GET',
  269. headers: { Authorization: `Bearer ${dlToken}` }
  270. });
  271. if (response.status !== 200) {
  272. throw new Error(response.status);
  273. }
  274. return response.body;
  275. }
  276. async function tryDownloadStream(id, dlToken, signal, tries = 2) {
  277. try {
  278. const result = await _downloadStream(id, dlToken, signal);
  279. return result;
  280. } catch (e) {
  281. if (e.message === '401' && --tries > 0) {
  282. return tryDownloadStream(id, dlToken, signal, tries);
  283. }
  284. if (e.name === 'AbortError') {
  285. throw new Error('0');
  286. }
  287. throw e;
  288. }
  289. }
  290. export function downloadStream(id, dlToken) {
  291. const controller = new AbortController();
  292. function cancel() {
  293. controller.abort();
  294. }
  295. return {
  296. cancel,
  297. result: tryDownloadStream(id, dlToken, controller.signal)
  298. };
  299. }
  300. //////////////////
  301. async function download(id, dlToken, onprogress, canceller) {
  302. const xhr = new XMLHttpRequest();
  303. canceller.oncancel = function() {
  304. xhr.abort();
  305. };
  306. return new Promise(function(resolve, reject) {
  307. xhr.addEventListener('loadend', function() {
  308. canceller.oncancel = function() {};
  309. if (xhr.status !== 200) {
  310. return reject(new Error(xhr.status));
  311. }
  312. const blob = new Blob([xhr.response]);
  313. resolve(blob);
  314. });
  315. xhr.addEventListener('progress', function(event) {
  316. if (event.target.status === 200) {
  317. onprogress(event.loaded);
  318. }
  319. });
  320. xhr.open('get', getApiUrl(`/api/download/blob/${id}`));
  321. xhr.setRequestHeader('Authorization', `Bearer ${dlToken}`);
  322. xhr.responseType = 'blob';
  323. xhr.send();
  324. onprogress(0);
  325. });
  326. }
  327. async function tryDownload(id, dlToken, onprogress, canceller, tries = 2) {
  328. try {
  329. const result = await download(id, dlToken, onprogress, canceller);
  330. return result;
  331. } catch (e) {
  332. if (e.message === '401' && --tries > 0) {
  333. return tryDownload(id, dlToken, onprogress, canceller, tries);
  334. }
  335. throw e;
  336. }
  337. }
  338. export function downloadFile(id, dlToken, onprogress) {
  339. const canceller = {
  340. oncancel: function() {} // download() sets this
  341. };
  342. function cancel() {
  343. canceller.oncancel();
  344. }
  345. return {
  346. cancel,
  347. result: tryDownload(id, dlToken, onprogress, canceller)
  348. };
  349. }
  350. export async function getFileList(bearerToken, kid) {
  351. const headers = new Headers({ Authorization: `Bearer ${bearerToken}` });
  352. const response = await fetch(getApiUrl(`/api/filelist/${kid}`), { headers });
  353. if (response.ok) {
  354. const encrypted = await response.blob();
  355. return encrypted;
  356. }
  357. throw new Error(response.status);
  358. }
  359. export async function setFileList(bearerToken, kid, data) {
  360. const headers = new Headers({ Authorization: `Bearer ${bearerToken}` });
  361. const response = await fetch(getApiUrl(`/api/filelist/${kid}`), {
  362. headers,
  363. method: 'POST',
  364. body: data
  365. });
  366. return response.ok;
  367. }
  368. export function sendMetrics(blob) {
  369. if (!navigator.sendBeacon) {
  370. return;
  371. }
  372. try {
  373. navigator.sendBeacon(getApiUrl('/api/metrics'), blob);
  374. } catch (e) {
  375. console.error(e);
  376. }
  377. }
  378. export async function getConstants() {
  379. const response = await fetch(getApiUrl('/config'));
  380. if (response.ok) {
  381. const obj = await response.json();
  382. return obj;
  383. }
  384. throw new Error(response.status);
  385. }
  386. export async function reportLink(id, keychain, reason) {
  387. const result = await fetchWithAuthAndRetry(
  388. getApiUrl(`/api/report/${id}`),
  389. {
  390. method: 'POST',
  391. body: JSON.stringify({ reason })
  392. },
  393. keychain
  394. );
  395. if (result.ok) {
  396. return;
  397. }
  398. throw new Error(result.response.status);
  399. }
  400. export async function getDownloadToken(id, keychain) {
  401. const result = await fetchWithAuthAndRetry(
  402. getApiUrl(`/api/download/token/${id}`),
  403. {
  404. method: 'GET'
  405. },
  406. keychain
  407. );
  408. if (result.ok) {
  409. return (await result.response.json()).token;
  410. }
  411. throw new Error(result.response.status);
  412. }
  413. export async function downloadDone(id, dlToken) {
  414. const headers = new Headers({ Authorization: `Bearer ${dlToken}` });
  415. const response = await fetch(getApiUrl(`/api/download/done/${id}`), {
  416. headers,
  417. method: 'POST'
  418. });
  419. return response.ok;
  420. }