http.ts 29.5 KB
Newer Older
A
Asher 已提交
1
import { field, logger } from "@coder/logger"
A
Asher 已提交
2 3
import * as fs from "fs-extra"
import * as http from "http"
A
Asher 已提交
4
import proxy from "http-proxy"
A
Asher 已提交
5 6 7 8 9 10 11 12 13 14
import * as httpolyglot from "httpolyglot"
import * as https from "https"
import * as net from "net"
import * as path from "path"
import * as querystring from "querystring"
import safeCompare from "safe-compare"
import { Readable } from "stream"
import * as tls from "tls"
import * as url from "url"
import { HttpCode, HttpError } from "../common/http"
A
Asher 已提交
15
import { normalize, Options, plural, split } from "../common/util"
A
Asher 已提交
16
import { SocketProxyProvider } from "./socket"
17
import { getMediaMime, paths } from "./util"
A
Asher 已提交
18 19 20 21

export type Cookies = { [key: string]: string[] | undefined }
export type PostData = { [key: string]: string | string[] | undefined }

A
Asher 已提交
22 23 24 25
interface ProxyRequest extends http.IncomingMessage {
  base?: string
}

A
Asher 已提交
26 27 28 29 30 31 32 33 34 35 36
interface AuthPayload extends Cookies {
  key?: string[]
}

export enum AuthType {
  Password = "password",
  None = "none",
}

export type Query = { [key: string]: string | string[] | undefined }

A
Asher 已提交
37 38 39 40 41 42 43 44 45 46 47
export interface ProxyOptions {
  /**
   * A base path to strip from from the request before proxying if necessary.
   */
  base?: string
  /**
   * The port to proxy.
   */
  port: string
}

A
Asher 已提交
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65
export interface HttpResponse<T = string | Buffer | object> {
  /*
   * Whether to set cache-control headers for this response.
   */
  cache?: boolean
  /**
   * If the code cannot be determined automatically set it here. The
   * defaults are 302 for redirects and 200 for successful requests. For errors
   * you should throw an HttpError and include the code there. If you
   * use Error it will default to 404 for ENOENT and EISDIR and 500 otherwise.
   */
  code?: number
  /**
   * Content to write in the response. Mutually exclusive with stream.
   */
  content?: T
  /**
   * Cookie to write with the response.
A
Asher 已提交
66
   * NOTE: Cookie paths must be absolute. The default is /.
A
Asher 已提交
67
   */
A
Asher 已提交
68
  cookie?: { key: string; value: string; path?: string }
A
Asher 已提交
69 70 71 72 73 74 75 76 77 78 79 80 81
  /**
   * Used to automatically determine the appropriate mime type.
   */
  filePath?: string
  /**
   * Additional headers to include.
   */
  headers?: http.OutgoingHttpHeaders
  /**
   * If the mime type cannot be determined automatically set it here.
   */
  mime?: string
  /**
A
Asher 已提交
82 83
   * Redirect to this path. This is constructed against the site base (not the
   * provider's base).
A
Asher 已提交
84 85 86 87 88 89 90 91 92 93 94
   */
  redirect?: string
  /**
   * Stream this to the response. Mutually exclusive with content.
   */
  stream?: Readable
  /**
   * Query variables to add in addition to current ones when redirecting. Use
   * `undefined` to remove a query variable.
   */
  query?: Query
A
Asher 已提交
95
  /**
A
Asher 已提交
96 97 98 99 100 101 102 103
   * Indicates the request should be proxied.
   */
  proxy?: ProxyOptions
}

export interface WsResponse {
  /**
   * Indicates the web socket should be proxied.
A
Asher 已提交
104
   */
A
Asher 已提交
105
  proxy?: ProxyOptions
A
Asher 已提交
106 107 108 109 110 111 112 113 114 115 116
}

/**
 * Use when you need to run search and replace on a file's content before
 * sending it.
 */
export interface HttpStringFileResponse extends HttpResponse {
  content: string
  filePath: string
}

A
Asher 已提交
117 118 119 120
export interface RedirectResponse extends HttpResponse {
  redirect: string
}

A
Asher 已提交
121
export interface HttpServerOptions {
A
Asher 已提交
122
  readonly auth?: AuthType
A
Asher 已提交
123 124
  readonly cert?: string
  readonly certKey?: string
A
Asher 已提交
125
  readonly commit?: string
A
Asher 已提交
126
  readonly host?: string
A
Asher 已提交
127
  readonly password?: string
A
Asher 已提交
128
  readonly port?: number
A
Asher 已提交
129
  readonly proxyDomains?: string[]
A
Asher 已提交
130 131 132
  readonly socket?: string
}

A
Asher 已提交
133
export interface Route {
A
Asher 已提交
134
  /**
A
Asher 已提交
135 136 137 138 139
   * Provider base path part (for /provider/base/path it would be /provider).
   */
  providerBase: string
  /**
   * Base path part (for /provider/base/path it would be /base).
A
Asher 已提交
140
   */
A
Asher 已提交
141
  base: string
A
Asher 已提交
142
  /**
A
Asher 已提交
143 144
   * Remaining part of the route after factoring out the base and provider base
   * (for /provider/base/path it would be /path). It can be blank.
A
Asher 已提交
145
   */
A
Asher 已提交
146
  requestPath: string
A
Asher 已提交
147 148 149
  /**
   * Query variables included in the request.
   */
A
Asher 已提交
150
  query: querystring.ParsedUrlQuery
A
Asher 已提交
151 152 153
  /**
   * Normalized version of `originalPath`.
   */
A
Asher 已提交
154
  fullPath: string
A
Asher 已提交
155 156 157
  /**
   * Original path of the request without any modifications.
   */
A
Asher 已提交
158 159 160
  originalPath: string
}

A
Asher 已提交
161 162 163 164
interface ProviderRoute extends Route {
  provider: HttpProvider
}

A
Asher 已提交
165 166
export interface HttpProviderOptions {
  readonly auth: AuthType
A
Asher 已提交
167
  readonly commit: string
A
Asher 已提交
168
  readonly password?: string
A
Asher 已提交
169 170 171 172 173 174 175 176 177
}

/**
 * Provides HTTP responses. This abstract class provides some helpers for
 * interpreting, creating, and authenticating responses.
 */
export abstract class HttpProvider {
  protected readonly rootPath = path.resolve(__dirname, "../..")

A
Asher 已提交
178
  public constructor(protected readonly options: HttpProviderOptions) {}
A
Asher 已提交
179

A
Asher 已提交
180
  public async dispose(): Promise<void> {
A
Asher 已提交
181 182 183 184
    // No default behavior.
  }

  /**
A
Asher 已提交
185 186 187
   * Handle web sockets on the registered endpoint. Normally the provider
   * handles the request itself but it can return a response when necessary. The
   * default is to throw a 404.
A
Asher 已提交
188
   */
189 190 191 192 193 194 195
  public handleWebSocket(
    /* eslint-disable @typescript-eslint/no-unused-vars */
    _route: Route,
    _request: http.IncomingMessage,
    _socket: net.Socket,
    _head: Buffer,
    /* eslint-enable @typescript-eslint/no-unused-vars */
A
Asher 已提交
196
  ): Promise<WsResponse | void> {
197 198
    throw new HttpError("Not found", HttpCode.NotFound)
  }
A
Asher 已提交
199 200 201 202

  /**
   * Handle requests to the registered endpoint.
   */
A
Asher 已提交
203
  public abstract handleRequest(route: Route, request: http.IncomingMessage): Promise<HttpResponse>
A
Asher 已提交
204

A
Asher 已提交
205
  /**
A
Asher 已提交
206 207 208 209 210 211 212
   * Get the base relative to the provided route. For each slash we need to go
   * up a directory. For example:
   * / => ./
   * /foo => ./
   * /foo/ => ./../
   * /foo/bar => ./../
   * /foo/bar/ => ./../../
A
Asher 已提交
213
   */
A
Asher 已提交
214
  public base(route: Route): string {
A
Asher 已提交
215
    const depth = (route.originalPath.match(/\//g) || []).length
A
Asher 已提交
216 217 218
    return normalize("./" + (depth > 1 ? "../".repeat(depth - 1) : ""))
  }

A
Asher 已提交
219 220 221
  /**
   * Get error response.
   */
A
Asher 已提交
222 223 224 225 226 227
  public async getErrorRoot(route: Route, title: string, header: string, body: string): Promise<HttpResponse> {
    const response = await this.getUtf8Resource(this.rootPath, "src/browser/pages/error.html")
    response.content = response.content
      .replace(/{{ERROR_TITLE}}/g, title)
      .replace(/{{ERROR_HEADER}}/g, header)
      .replace(/{{ERROR_BODY}}/g, body)
A
Asher 已提交
228 229 230 231 232 233
    return this.replaceTemplates(route, response)
  }

  /**
   * Replace common templates strings.
   */
234 235 236 237 238 239
  protected replaceTemplates(route: Route, response: HttpStringFileResponse, sessionId?: string): HttpStringFileResponse
  protected replaceTemplates<T extends object>(
    route: Route,
    response: HttpStringFileResponse,
    options: T,
  ): HttpStringFileResponse
A
Asher 已提交
240 241 242
  protected replaceTemplates(
    route: Route,
    response: HttpStringFileResponse,
243
    sessionIdOrOptions?: string | object,
A
Asher 已提交
244
  ): HttpStringFileResponse {
245 246 247 248 249 250 251
    if (typeof sessionIdOrOptions === "undefined" || typeof sessionIdOrOptions === "string") {
      sessionIdOrOptions = {
        base: this.base(route),
        commit: this.options.commit,
        logLevel: logger.level,
        sessionID: sessionIdOrOptions,
      } as Options
A
Asher 已提交
252 253 254
    }
    response.content = response.content
      .replace(/{{COMMIT}}/g, this.options.commit)
255
      .replace(/{{TO}}/g, Array.isArray(route.query.to) ? route.query.to[0] : route.query.to || "/dashboard")
A
Asher 已提交
256
      .replace(/{{BASE}}/g, this.base(route))
257
      .replace(/"{{OPTIONS}}"/, `'${JSON.stringify(sessionIdOrOptions)}'`)
A
Asher 已提交
258 259 260
    return response
  }

A
Asher 已提交
261 262
  protected get isDev(): boolean {
    return this.options.commit === "development"
A
Asher 已提交
263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282
  }

  /**
   * Get a file resource.
   * TODO: Would a stream be faster, at least for large files?
   */
  protected async getResource(...parts: string[]): Promise<HttpResponse> {
    const filePath = path.join(...parts)
    return { content: await fs.readFile(filePath), filePath }
  }

  /**
   * Get a file resource as a string.
   */
  protected async getUtf8Resource(...parts: string[]): Promise<HttpStringFileResponse> {
    const filePath = path.join(...parts)
    return { content: await fs.readFile(filePath, "utf8"), filePath }
  }

  /**
A
Asher 已提交
283
   * Helper to error on invalid methods (default GET).
A
Asher 已提交
284
   */
A
Asher 已提交
285 286 287
  protected ensureMethod(request: http.IncomingMessage, method?: string | string[]): void {
    const check = Array.isArray(method) ? method : [method || "GET"]
    if (!request.method || !check.includes(request.method)) {
A
Asher 已提交
288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314
      throw new HttpError(`Unsupported method ${request.method}`, HttpCode.BadRequest)
    }
  }

  /**
   * Helper to error if not authorized.
   */
  protected ensureAuthenticated(request: http.IncomingMessage): void {
    if (!this.authenticated(request)) {
      throw new HttpError("Unauthorized", HttpCode.Unauthorized)
    }
  }

  /**
   * Use the first query value or the default if there isn't one.
   */
  protected queryOrDefault(value: string | string[] | undefined, def: string): string {
    if (Array.isArray(value)) {
      value = value[0]
    }
    return typeof value !== "undefined" ? value : def
  }

  /**
   * Return the provided password value if the payload contains the right
   * password otherwise return false. If no payload is specified use cookies.
   */
A
Asher 已提交
315
  public authenticated(request: http.IncomingMessage, payload?: AuthPayload): string | boolean {
A
Asher 已提交
316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385
    switch (this.options.auth) {
      case AuthType.None:
        return true
      case AuthType.Password:
        if (typeof payload === "undefined") {
          payload = this.parseCookies<AuthPayload>(request)
        }
        if (this.options.password && payload.key) {
          for (let i = 0; i < payload.key.length; ++i) {
            if (safeCompare(payload.key[i], this.options.password)) {
              return payload.key[i]
            }
          }
        }
        return false
      default:
        throw new Error(`Unsupported auth type ${this.options.auth}`)
    }
  }

  /**
   * Parse POST data.
   */
  protected getData(request: http.IncomingMessage): Promise<string | undefined> {
    return request.method === "POST" || request.method === "DELETE"
      ? new Promise<string>((resolve, reject) => {
          let body = ""
          const onEnd = (): void => {
            off() // eslint-disable-line @typescript-eslint/no-use-before-define
            resolve(body || undefined)
          }
          const onError = (error: Error): void => {
            off() // eslint-disable-line @typescript-eslint/no-use-before-define
            reject(error)
          }
          const onData = (d: Buffer): void => {
            body += d
            if (body.length > 1e6) {
              onError(new HttpError("Payload is too large", HttpCode.LargePayload))
              request.connection.destroy()
            }
          }
          const off = (): void => {
            request.off("error", onError)
            request.off("data", onError)
            request.off("end", onEnd)
          }
          request.on("error", onError)
          request.on("data", onData)
          request.on("end", onEnd)
        })
      : Promise.resolve(undefined)
  }

  /**
   * Parse cookies.
   */
  protected parseCookies<T extends Cookies>(request: http.IncomingMessage): T {
    const cookies: { [key: string]: string[] } = {}
    if (request.headers.cookie) {
      request.headers.cookie.split(";").forEach((keyValue) => {
        const [key, value] = split(keyValue, "=")
        if (!cookies[key]) {
          cookies[key] = []
        }
        cookies[key].push(decodeURI(value))
      })
    }
    return cookies as T
  }
386 387 388 389 390 391 392 393

  /**
   * Return true if the route is for the root page. For example /base, /base/,
   * or /base/index.html but not /base/path or /base/file.js.
   */
  protected isRoot(route: Route): boolean {
    return !route.requestPath || route.requestPath === "/index.html"
  }
A
Asher 已提交
394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422
}

/**
 * Provides a heartbeat using a local file to indicate activity.
 */
export class Heart {
  private heartbeatTimer?: NodeJS.Timeout
  private heartbeatInterval = 60000
  private lastHeartbeat = 0

  public constructor(private readonly heartbeatPath: string, private readonly isActive: () => Promise<boolean>) {}

  /**
   * Write to the heartbeat file if we haven't already done so within the
   * timeout and start or reset a timer that keeps running as long as there is
   * activity. Failures are logged as warnings.
   */
  public beat(): void {
    const now = Date.now()
    if (now - this.lastHeartbeat >= this.heartbeatInterval) {
      logger.trace("heartbeat")
      fs.outputFile(this.heartbeatPath, "").catch((error) => {
        logger.warn(error.message)
      })
      this.lastHeartbeat = now
      if (typeof this.heartbeatTimer !== "undefined") {
        clearTimeout(this.heartbeatTimer)
      }
      this.heartbeatTimer = setTimeout(() => {
A
Asher 已提交
423 424 425 426 427 428 429 430 431
        this.isActive()
          .then((active) => {
            if (active) {
              this.beat()
            }
          })
          .catch((error) => {
            logger.warn(error.message)
          })
A
Asher 已提交
432 433 434 435 436
      }, this.heartbeatInterval)
    }
  }
}

A
Asher 已提交
437 438 439 440 441 442 443 444
export interface HttpProvider0<T> {
  new (options: HttpProviderOptions): T
}

export interface HttpProvider1<A1, T> {
  new (options: HttpProviderOptions, a1: A1): T
}

A
Asher 已提交
445 446 447 448
export interface HttpProvider2<A1, A2, T> {
  new (options: HttpProviderOptions, a1: A1, a2: A2): T
}

449 450 451 452
export interface HttpProvider3<A1, A2, A3, T> {
  new (options: HttpProviderOptions, a1: A1, a2: A2, a3: A3): T
}

A
Asher 已提交
453 454 455 456 457 458 459 460 461 462 463
/**
 * An HTTP server. Its main role is to route incoming HTTP requests to the
 * appropriate provider for that endpoint then write out the response. It also
 * covers some common use cases like redirects and caching.
 */
export class HttpServer {
  protected readonly server: http.Server | https.Server
  private listenPromise: Promise<string | null> | undefined
  public readonly protocol: "http" | "https"
  private readonly providers = new Map<string, HttpProvider>()
  private readonly heart: Heart
A
Asher 已提交
464
  private readonly socketProvider = new SocketProxyProvider()
A
Asher 已提交
465 466 467 468 469 470 471 472 473 474

  /**
   * Proxy domains are stored here without the leading `*.`
   */
  public readonly proxyDomains: Set<string>

  /**
   * Provides the actual proxying functionality.
   */
  private readonly proxy = proxy.createProxyServer({})
A
Asher 已提交
475

A
Asher 已提交
476
  public constructor(private readonly options: HttpServerOptions) {
A
Asher 已提交
477
    this.proxyDomains = new Set((options.proxyDomains || []).map((d) => d.replace(/^\*\./, "")))
478
    this.heart = new Heart(path.join(paths.data, "heartbeat"), async () => {
A
Asher 已提交
479 480 481 482 483 484 485 486 487 488 489
      const connections = await this.getConnections()
      logger.trace(`${connections} active connection${plural(connections)}`)
      return connections !== 0
    })
    this.protocol = this.options.cert ? "https" : "http"
    if (this.protocol === "https") {
      this.server = httpolyglot.createServer(
        {
          cert: this.options.cert && fs.readFileSync(this.options.cert),
          key: this.options.certKey && fs.readFileSync(this.options.certKey),
        },
A
Anmol Sethi 已提交
490
        this.onRequest,
A
Asher 已提交
491 492 493 494
      )
    } else {
      this.server = http.createServer(this.onRequest)
    }
A
Asher 已提交
495 496 497 498
    this.proxy.on("error", (error, _request, response) => {
      response.writeHead(HttpCode.ServerError)
      response.end(error.message)
    })
A
Asher 已提交
499 500 501 502 503 504
    // Intercept the response to rewrite absolute redirects against the base path.
    this.proxy.on("proxyRes", (response, request: ProxyRequest) => {
      if (response.headers.location && response.headers.location.startsWith("/") && request.base) {
        response.headers.location = request.base + response.headers.location
      }
    })
A
Asher 已提交
505 506
  }

A
Asher 已提交
507 508 509 510
  /**
   * Stop and dispose everything. Return an array of disposal errors.
   */
  public async dispose(): Promise<Error[]> {
A
Asher 已提交
511
    this.socketProvider.stop()
A
Asher 已提交
512 513 514 515
    const providers = Array.from(this.providers.values())
    // Catch so all the errors can be seen rather than just the first one.
    const responses = await Promise.all<Error | undefined>(providers.map((p) => p.dispose().catch((e) => e)))
    return responses.filter<Error>((r): r is Error => typeof r !== "undefined")
A
Asher 已提交
516 517 518 519 520 521 522 523 524 525 526 527 528
  }

  public async getConnections(): Promise<number> {
    return new Promise((resolve, reject) => {
      this.server.getConnections((error, count) => {
        return error ? reject(error) : resolve(count)
      })
    })
  }

  /**
   * Register a provider for a top-level endpoint.
   */
A
Asher 已提交
529 530 531 532 533 534
  public registerHttpProvider<T extends HttpProvider>(endpoint: string | string[], provider: HttpProvider0<T>): T
  public registerHttpProvider<A1, T extends HttpProvider>(
    endpoint: string | string[],
    provider: HttpProvider1<A1, T>,
    a1: A1,
  ): T
A
Asher 已提交
535
  public registerHttpProvider<A1, A2, T extends HttpProvider>(
A
Asher 已提交
536
    endpoint: string | string[],
A
Asher 已提交
537 538
    provider: HttpProvider2<A1, A2, T>,
    a1: A1,
539
    a2: A2,
A
Asher 已提交
540
  ): T
541
  public registerHttpProvider<A1, A2, A3, T extends HttpProvider>(
A
Asher 已提交
542
    endpoint: string | string[],
543 544 545 546 547
    provider: HttpProvider3<A1, A2, A3, T>,
    a1: A1,
    a2: A2,
    a3: A3,
  ): T
A
Asher 已提交
548
  // eslint-disable-next-line @typescript-eslint/no-explicit-any
A
Asher 已提交
549
  public registerHttpProvider(endpoint: string | string[], provider: any, ...args: any[]): void {
A
Asher 已提交
550 551 552 553 554 555
    const p = new provider(
      {
        auth: this.options.auth || AuthType.None,
        commit: this.options.commit,
        password: this.options.password,
      },
556
      ...args,
A
Asher 已提交
557
    )
A
Asher 已提交
558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573
    const endpoints = (typeof endpoint === "string" ? [endpoint] : endpoint).map((e) => e.replace(/^\/+|\/+$/g, ""))
    endpoints.forEach((endpoint) => {
      if (/\//.test(endpoint)) {
        throw new Error(`Only top-level endpoints are supported (got ${endpoint})`)
      }
      const existingProvider = this.providers.get(`/${endpoint}`)
      this.providers.set(`/${endpoint}`, p)
      if (existingProvider) {
        logger.debug(`Overridding existing /${endpoint} provider`)
        // If the existing provider isn't registered elsewhere we can dispose.
        if (!Array.from(this.providers.values()).find((p) => p === existingProvider)) {
          logger.debug(`Disposing existing /${endpoint} provider`)
          existingProvider.dispose()
        }
      }
    })
A
Asher 已提交
574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607
  }

  /**
   * Start listening on the specified port.
   */
  public listen(): Promise<string | null> {
    if (!this.listenPromise) {
      this.listenPromise = new Promise((resolve, reject) => {
        this.server.on("error", reject)
        this.server.on("upgrade", this.onUpgrade)
        const onListen = (): void => resolve(this.address())
        if (this.options.socket) {
          this.server.listen(this.options.socket, onListen)
        } else {
          this.server.listen(this.options.port, this.options.host, onListen)
        }
      })
    }
    return this.listenPromise
  }

  /**
   * The *local* address of the server.
   */
  public address(): string | null {
    const address = this.server.address()
    const endpoint =
      typeof address !== "string" && address !== null
        ? (address.address === "::" ? "localhost" : address.address) + ":" + address.port
        : address
    return endpoint && `${this.protocol}://${endpoint}`
  }

  private onRequest = async (request: http.IncomingMessage, response: http.ServerResponse): Promise<void> => {
A
Asher 已提交
608 609
    this.heart.beat()
    const route = this.parseUrl(request)
A
Asher 已提交
610
    const write = (payload: HttpResponse): void => {
A
Asher 已提交
611 612
      response.writeHead(payload.redirect ? HttpCode.Redirect : payload.code || HttpCode.Ok, {
        "Content-Type": payload.mime || getMediaMime(payload.filePath),
A
Asher 已提交
613
        ...(payload.redirect ? { Location: this.constructRedirect(request, route, payload as RedirectResponse) } : {}),
A
Asher 已提交
614
        ...(request.headers["service-worker"] ? { "Service-Worker-Allowed": route.provider.base(route) } : {}),
A
Asher 已提交
615 616 617
        ...(payload.cache ? { "Cache-Control": "public, max-age=31536000" } : {}),
        ...(payload.cookie
          ? {
A
Asher 已提交
618 619 620
              "Set-Cookie": [
                `${payload.cookie.key}=${payload.cookie.value}`,
                `Path=${normalize(payload.cookie.path || "/", true)}`,
621
                this.getCookieDomain(request.headers.host || ""),
W
Will O'Beirne 已提交
622
                // "HttpOnly",
A
Asher 已提交
623
                "SameSite=lax",
A
Asher 已提交
624 625 626
              ]
                .filter((l) => !!l)
                .join(";"),
A
Asher 已提交
627 628 629 630 631 632 633 634 635
            }
          : {}),
        ...payload.headers,
      })
      if (payload.stream) {
        payload.stream.on("error", (error: NodeJS.ErrnoException) => {
          response.writeHead(error.code === "ENOENT" ? HttpCode.NotFound : HttpCode.ServerError)
          response.end(error.message)
        })
636
        payload.stream.on("close", () => response.end())
A
Asher 已提交
637 638 639 640 641 642 643 644
        payload.stream.pipe(response)
      } else if (typeof payload.content === "string" || payload.content instanceof Buffer) {
        response.end(payload.content)
      } else if (payload.content && typeof payload.content === "object") {
        response.end(JSON.stringify(payload.content))
      } else {
        response.end()
      }
A
Asher 已提交
645
    }
A
Asher 已提交
646

A
Asher 已提交
647
    try {
A
Asher 已提交
648 649
      const payload =
        this.maybeRedirect(request, route) ||
A
Asher 已提交
650 651 652 653 654
        (route.provider.authenticated(request) && this.maybeProxy(request)) ||
        (await route.provider.handleRequest(route, request))
      if (payload.proxy) {
        this.doProxy(route, request, response, payload.proxy)
      } else {
A
Asher 已提交
655
        write(payload)
A
Asher 已提交
656
      }
A
Asher 已提交
657 658 659 660 661
    } catch (error) {
      let e = error
      if (error.code === "ENOENT" || error.code === "EISDIR") {
        e = new HttpError("Not found", HttpCode.NotFound)
      }
A
Asher 已提交
662
      const code = typeof e.code === "number" ? e.code : HttpCode.ServerError
A
Asher 已提交
663 664 665 666
      logger.debug("Request error", field("url", request.url), field("code", code))
      if (code >= HttpCode.ServerError) {
        logger.error(error.stack)
      }
A
Asher 已提交
667 668 669 670 671 672 673 674 675 676 677 678 679
      if (request.headers["content-type"] === "application/json") {
        write({
          code,
          content: {
            error: e.message,
          },
        })
      } else {
        write({
          code,
          ...(await route.provider.getErrorRoot(route, code, code, e.message)),
        })
      }
A
Asher 已提交
680 681 682 683 684 685
    }
  }

  /**
   * Return any necessary redirection before delegating to a provider.
   */
A
Asher 已提交
686 687
  private maybeRedirect(request: http.IncomingMessage, route: ProviderRoute): RedirectResponse | undefined {
    // If we're handling TLS ensure all requests are redirected to HTTPS.
A
Asher 已提交
688
    if (this.options.cert && !(request.connection as tls.TLSSocket).encrypted) {
A
Asher 已提交
689
      return { redirect: route.fullPath }
A
Asher 已提交
690
    }
A
Asher 已提交
691

A
Asher 已提交
692 693 694
    return undefined
  }

A
Asher 已提交
695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711
  /**
   * Given a path that goes from the base, construct a relative redirect URL
   * that will get you there considering that the app may be served from an
   * unknown base path. If handling TLS, also ensure HTTPS.
   */
  private constructRedirect(request: http.IncomingMessage, route: ProviderRoute, payload: RedirectResponse): string {
    const query = {
      ...route.query,
      ...(payload.query || {}),
    }

    Object.keys(query).forEach((key) => {
      if (typeof query[key] === "undefined") {
        delete query[key]
      }
    })

A
Asher 已提交
712 713 714
    const secure = (request.connection as tls.TLSSocket).encrypted
    const redirect =
      (this.options.cert && !secure ? `${this.protocol}://${request.headers.host}/` : "") +
A
Asher 已提交
715 716
      normalize(`${route.provider.base(route)}/${payload.redirect}`, true) +
      (Object.keys(query).length > 0 ? `?${querystring.stringify(query)}` : "")
A
Asher 已提交
717
    logger.debug("redirecting", field("secure", !!secure), field("from", request.url), field("to", redirect))
A
Asher 已提交
718
    return redirect
A
Asher 已提交
719 720
  }

A
Asher 已提交
721 722 723 724 725 726 727 728 729 730 731 732 733
  private onUpgrade = async (request: http.IncomingMessage, socket: net.Socket, head: Buffer): Promise<void> => {
    try {
      this.heart.beat()
      socket.on("error", () => socket.destroy())

      if (this.options.cert && !(socket as tls.TLSSocket).encrypted) {
        throw new HttpError("HTTP websocket", HttpCode.BadRequest)
      }

      if (!request.headers.upgrade || request.headers.upgrade.toLowerCase() !== "websocket") {
        throw new HttpError("HTTP/1.1 400 Bad Request", HttpCode.BadRequest)
      }

A
Asher 已提交
734 735
      const route = this.parseUrl(request)
      if (!route.provider) {
A
Asher 已提交
736 737 738
        throw new HttpError("Not found", HttpCode.NotFound)
      }

A
Asher 已提交
739 740 741 742 743 744 745
      // The socket proxy is so we can pass them to child processes (TLS sockets
      // can't be transferred so we need an in-between).
      const socketProxy = await this.socketProvider.createProxy(socket)
      const payload =
        this.maybeProxy(request) || (await route.provider.handleWebSocket(route, request, socketProxy, head))
      if (payload && payload.proxy) {
        this.doProxy(route, request, { socket: socketProxy, head }, payload.proxy)
A
Asher 已提交
746
      }
A
Asher 已提交
747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771
    } catch (error) {
      socket.destroy(error)
      logger.warn(`discarding socket connection: ${error.message}`)
    }
  }

  /**
   * Parse a request URL so we can route it.
   */
  private parseUrl(request: http.IncomingMessage): ProviderRoute {
    const parse = (fullPath: string): { base: string; requestPath: string } => {
      const match = fullPath.match(/^(\/?[^/]*)(.*)$/)
      let [, /* ignore */ base, requestPath] = match ? match.map((p) => p.replace(/\/+$/, "")) : ["", "", ""]
      if (base.indexOf(".") !== -1) {
        // Assume it's a file at the root.
        requestPath = base
        base = "/"
      } else if (base === "") {
        // Happens if it's a plain `domain.com`.
        base = "/"
      }
      return { base, requestPath }
    }

    const parsedUrl = request.url ? url.parse(request.url, true) : { query: {}, pathname: "" }
A
Asher 已提交
772
    const originalPath = parsedUrl.pathname || "/"
A
Asher 已提交
773
    const fullPath = normalize(originalPath, true)
A
Asher 已提交
774 775 776 777 778 779
    const { base, requestPath } = parse(fullPath)

    // Providers match on the path after their base so we need to account for
    // that by shifting the next base out of the request path.
    let provider = this.providers.get(base)
    if (base !== "/" && provider) {
A
Asher 已提交
780
      return { ...parse(requestPath), providerBase: base, fullPath, query: parsedUrl.query, provider, originalPath }
A
Asher 已提交
781 782 783 784 785 786 787
    }

    // Fall back to the top-level provider.
    provider = this.providers.get("/")
    if (!provider) {
      throw new Error(`No provider for ${base}`)
    }
A
Asher 已提交
788
    return { base, providerBase: "/", fullPath, requestPath, query: parsedUrl.query, provider, originalPath }
A
Asher 已提交
789
  }
A
Asher 已提交
790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847

  /**
   * Proxy a request to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: http.ServerResponse,
    options: ProxyOptions,
  ): void
  /**
   * Proxy a web socket to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: { socket: net.Socket; head: Buffer },
    options: ProxyOptions,
  ): void
  /**
   * Proxy a request or web socket to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: http.ServerResponse | { socket: net.Socket; head: Buffer },
    options: ProxyOptions,
  ): void {
    const port = parseInt(options.port, 10)
    if (isNaN(port)) {
      throw new HttpError(`"${options.port}" is not a valid number`, HttpCode.BadRequest)
    }

    // REVIEW: Absolute redirects need to be based on the subpath but I'm not
    // sure how best to get this information to the `proxyRes` event handler.
    // For now I'm sticking it on the request object which is passed through to
    // the event.
    ;(request as ProxyRequest).base = options.base

    const isHttp = response instanceof http.ServerResponse
    const path = options.base ? route.fullPath.replace(options.base, "") : route.fullPath
    const proxyOptions: proxy.ServerOptions = {
      changeOrigin: true,
      ignorePath: true,
      target: `${isHttp ? "http" : "ws"}://127.0.0.1:${port}${path}${
        Object.keys(route.query).length > 0 ? `?${querystring.stringify(route.query)}` : ""
      }`,
      ws: !isHttp,
    }

    if (response instanceof http.ServerResponse) {
      this.proxy.web(request, response, proxyOptions)
    } else {
      this.proxy.ws(request, response.socket, response.head, proxyOptions)
    }
  }

  /**
848 849
   * Get the value that should be used for setting a cookie domain. This will
   * allow the user to authenticate only once. This will use the highest level
A
Asher 已提交
850 851
   * domain (e.g. `coder.com` over `test.coder.com` if both are specified).
   */
852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873
  private getCookieDomain(host: string): string | undefined {
    const idx = host.lastIndexOf(":")
    host = idx !== -1 ? host.substring(0, idx) : host
    if (
      // Might be blank/missing, so there's nothing more to do.
      !host ||
      // IP addresses can't have subdomains so there's no value in setting the
      // domain for them. Assume anything with a : is ipv6 (valid domain name
      // characters are alphanumeric or dashes).
      host.includes(":") ||
      // Assume anything entirely numbers and dots is ipv4 (currently tlds
      // cannot be entirely numbers).
      !/[^0-9.]/.test(host) ||
      // localhost subdomains don't seem to work at all (browser bug?).
      host.endsWith(".localhost") ||
      // It might be localhost (or an IP, see above) if it's a proxy and it
      // isn't setting the host header to match the access domain.
      host === "localhost"
    ) {
      return undefined
    }

A
Asher 已提交
874
    this.proxyDomains.forEach((domain) => {
875 876
      if (host.endsWith(domain) && domain.length < host.length) {
        host = domain
A
Asher 已提交
877 878
      }
    })
879 880

    return host ? `Domain=${host}` : undefined
A
Asher 已提交
881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910
  }

  /**
   * Return a response if the request should be proxied. Anything that ends in a
   * proxy domain and has a *single* subdomain should be proxied. Anything else
   * should return `undefined` and will be handled as normal.
   *
   * For example if `coder.com` is specified `8080.coder.com` will be proxied
   * but `8080.test.coder.com` and `test.8080.coder.com` will not.
   */
  public maybeProxy(request: http.IncomingMessage): HttpResponse | undefined {
    // Split into parts.
    const host = request.headers.host || ""
    const idx = host.indexOf(":")
    const domain = idx !== -1 ? host.substring(0, idx) : host
    const parts = domain.split(".")

    // There must be an exact match.
    const port = parts.shift()
    const proxyDomain = parts.join(".")
    if (!port || !this.proxyDomains.has(proxyDomain)) {
      return undefined
    }

    return {
      proxy: {
        port,
      },
    }
  }
A
Asher 已提交
911
}