http.ts 28.5 KB
Newer Older
A
Asher 已提交
1
import { field, logger } from "@coder/logger"
A
Asher 已提交
2 3
import * as fs from "fs-extra"
import * as http from "http"
A
Asher 已提交
4
import proxy from "http-proxy"
A
Asher 已提交
5 6 7 8 9 10 11 12 13 14
import * as httpolyglot from "httpolyglot"
import * as https from "https"
import * as net from "net"
import * as path from "path"
import * as querystring from "querystring"
import safeCompare from "safe-compare"
import { Readable } from "stream"
import * as tls from "tls"
import * as url from "url"
import { HttpCode, HttpError } from "../common/http"
A
Asher 已提交
15
import { normalize, Options, plural, split } from "../common/util"
A
Asher 已提交
16
import { SocketProxyProvider } from "./socket"
A
Asher 已提交
17
import { getMediaMime, xdgLocalDir } from "./util"
A
Asher 已提交
18 19 20 21

export type Cookies = { [key: string]: string[] | undefined }
export type PostData = { [key: string]: string | string[] | undefined }

A
Asher 已提交
22 23 24 25
interface ProxyRequest extends http.IncomingMessage {
  base?: string
}

A
Asher 已提交
26 27 28 29 30 31 32 33 34 35 36
interface AuthPayload extends Cookies {
  key?: string[]
}

export enum AuthType {
  Password = "password",
  None = "none",
}

export type Query = { [key: string]: string | string[] | undefined }

A
Asher 已提交
37 38 39 40 41 42 43 44 45 46 47
export interface ProxyOptions {
  /**
   * A base path to strip from from the request before proxying if necessary.
   */
  base?: string
  /**
   * The port to proxy.
   */
  port: string
}

A
Asher 已提交
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65
export interface HttpResponse<T = string | Buffer | object> {
  /*
   * Whether to set cache-control headers for this response.
   */
  cache?: boolean
  /**
   * If the code cannot be determined automatically set it here. The
   * defaults are 302 for redirects and 200 for successful requests. For errors
   * you should throw an HttpError and include the code there. If you
   * use Error it will default to 404 for ENOENT and EISDIR and 500 otherwise.
   */
  code?: number
  /**
   * Content to write in the response. Mutually exclusive with stream.
   */
  content?: T
  /**
   * Cookie to write with the response.
A
Asher 已提交
66
   * NOTE: Cookie paths must be absolute. The default is /.
A
Asher 已提交
67
   */
A
Asher 已提交
68
  cookie?: { key: string; value: string; path?: string }
A
Asher 已提交
69 70 71 72 73 74 75 76 77 78 79 80 81 82 83
  /**
   * Used to automatically determine the appropriate mime type.
   */
  filePath?: string
  /**
   * Additional headers to include.
   */
  headers?: http.OutgoingHttpHeaders
  /**
   * If the mime type cannot be determined automatically set it here.
   */
  mime?: string
  /**
   * Redirect to this path. Will rewrite against the base path but NOT the
   * provider endpoint so you must include it. This allows redirecting outside
A
Asher 已提交
84
   * of your endpoint.
A
Asher 已提交
85 86 87 88 89 90 91 92 93 94 95
   */
  redirect?: string
  /**
   * Stream this to the response. Mutually exclusive with content.
   */
  stream?: Readable
  /**
   * Query variables to add in addition to current ones when redirecting. Use
   * `undefined` to remove a query variable.
   */
  query?: Query
A
Asher 已提交
96
  /**
A
Asher 已提交
97 98 99 100 101 102 103 104
   * Indicates the request should be proxied.
   */
  proxy?: ProxyOptions
}

export interface WsResponse {
  /**
   * Indicates the web socket should be proxied.
A
Asher 已提交
105
   */
A
Asher 已提交
106
  proxy?: ProxyOptions
A
Asher 已提交
107 108 109 110 111 112 113 114 115 116 117
}

/**
 * Use when you need to run search and replace on a file's content before
 * sending it.
 */
export interface HttpStringFileResponse extends HttpResponse {
  content: string
  filePath: string
}

A
Asher 已提交
118 119 120 121
export interface RedirectResponse extends HttpResponse {
  redirect: string
}

A
Asher 已提交
122
export interface HttpServerOptions {
A
Asher 已提交
123
  readonly auth?: AuthType
A
Asher 已提交
124 125
  readonly cert?: string
  readonly certKey?: string
A
Asher 已提交
126
  readonly commit?: string
A
Asher 已提交
127
  readonly host?: string
A
Asher 已提交
128
  readonly password?: string
A
Asher 已提交
129
  readonly port?: number
A
Asher 已提交
130
  readonly proxyDomains?: string[]
A
Asher 已提交
131 132 133
  readonly socket?: string
}

A
Asher 已提交
134
export interface Route {
A
Asher 已提交
135 136 137
  /**
   * Base path part (in /test/path it would be "/test").
   */
A
Asher 已提交
138
  base: string
A
Asher 已提交
139 140 141 142
  /**
   * Remaining part of the route (in /test/path it would be "/path"). It can be
   * blank.
   */
A
Asher 已提交
143
  requestPath: string
A
Asher 已提交
144 145 146
  /**
   * Query variables included in the request.
   */
A
Asher 已提交
147
  query: querystring.ParsedUrlQuery
A
Asher 已提交
148 149 150
  /**
   * Normalized version of `originalPath`.
   */
A
Asher 已提交
151
  fullPath: string
A
Asher 已提交
152 153 154
  /**
   * Original path of the request without any modifications.
   */
A
Asher 已提交
155 156 157
  originalPath: string
}

A
Asher 已提交
158 159 160 161
interface ProviderRoute extends Route {
  provider: HttpProvider
}

A
Asher 已提交
162 163
export interface HttpProviderOptions {
  readonly auth: AuthType
A
Asher 已提交
164
  readonly base: string
A
Asher 已提交
165
  readonly commit: string
A
Asher 已提交
166
  readonly password?: string
A
Asher 已提交
167 168 169 170 171 172 173 174 175
}

/**
 * Provides HTTP responses. This abstract class provides some helpers for
 * interpreting, creating, and authenticating responses.
 */
export abstract class HttpProvider {
  protected readonly rootPath = path.resolve(__dirname, "../..")

A
Asher 已提交
176
  public constructor(protected readonly options: HttpProviderOptions) {}
A
Asher 已提交
177 178 179 180 181 182

  public dispose(): void {
    // No default behavior.
  }

  /**
A
Asher 已提交
183 184 185
   * Handle web sockets on the registered endpoint. Normally the provider
   * handles the request itself but it can return a response when necessary. The
   * default is to throw a 404.
A
Asher 已提交
186
   */
187 188 189 190 191 192 193
  public handleWebSocket(
    /* eslint-disable @typescript-eslint/no-unused-vars */
    _route: Route,
    _request: http.IncomingMessage,
    _socket: net.Socket,
    _head: Buffer,
    /* eslint-enable @typescript-eslint/no-unused-vars */
A
Asher 已提交
194
  ): Promise<WsResponse | void> {
195 196
    throw new HttpError("Not found", HttpCode.NotFound)
  }
A
Asher 已提交
197 198 199 200

  /**
   * Handle requests to the registered endpoint.
   */
A
Asher 已提交
201
  public abstract handleRequest(route: Route, request: http.IncomingMessage): Promise<HttpResponse>
A
Asher 已提交
202

A
Asher 已提交
203
  /**
A
Asher 已提交
204 205 206 207 208 209 210
   * Get the base relative to the provided route. For each slash we need to go
   * up a directory. For example:
   * / => ./
   * /foo => ./
   * /foo/ => ./../
   * /foo/bar => ./../
   * /foo/bar/ => ./../../
A
Asher 已提交
211
   */
A
Asher 已提交
212
  public base(route: Route): string {
A
Asher 已提交
213
    const depth = (route.originalPath.match(/\//g) || []).length
A
Asher 已提交
214 215 216
    return normalize("./" + (depth > 1 ? "../".repeat(depth - 1) : ""))
  }

A
Asher 已提交
217 218 219
  /**
   * Get error response.
   */
A
Asher 已提交
220 221 222 223 224 225
  public async getErrorRoot(route: Route, title: string, header: string, body: string): Promise<HttpResponse> {
    const response = await this.getUtf8Resource(this.rootPath, "src/browser/pages/error.html")
    response.content = response.content
      .replace(/{{ERROR_TITLE}}/g, title)
      .replace(/{{ERROR_HEADER}}/g, header)
      .replace(/{{ERROR_BODY}}/g, body)
A
Asher 已提交
226 227 228 229 230 231
    return this.replaceTemplates(route, response)
  }

  /**
   * Replace common templates strings.
   */
232 233 234 235 236 237
  protected replaceTemplates(route: Route, response: HttpStringFileResponse, sessionId?: string): HttpStringFileResponse
  protected replaceTemplates<T extends object>(
    route: Route,
    response: HttpStringFileResponse,
    options: T,
  ): HttpStringFileResponse
A
Asher 已提交
238 239 240
  protected replaceTemplates(
    route: Route,
    response: HttpStringFileResponse,
241
    sessionIdOrOptions?: string | object,
A
Asher 已提交
242
  ): HttpStringFileResponse {
243 244 245 246 247 248 249
    if (typeof sessionIdOrOptions === "undefined" || typeof sessionIdOrOptions === "string") {
      sessionIdOrOptions = {
        base: this.base(route),
        commit: this.options.commit,
        logLevel: logger.level,
        sessionID: sessionIdOrOptions,
      } as Options
A
Asher 已提交
250 251 252
    }
    response.content = response.content
      .replace(/{{COMMIT}}/g, this.options.commit)
253
      .replace(/{{TO}}/g, Array.isArray(route.query.to) ? route.query.to[0] : route.query.to || "/dashboard")
A
Asher 已提交
254
      .replace(/{{BASE}}/g, this.base(route))
255
      .replace(/"{{OPTIONS}}"/, `'${JSON.stringify(sessionIdOrOptions)}'`)
A
Asher 已提交
256 257 258
    return response
  }

A
Asher 已提交
259 260
  protected get isDev(): boolean {
    return this.options.commit === "development"
A
Asher 已提交
261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280
  }

  /**
   * Get a file resource.
   * TODO: Would a stream be faster, at least for large files?
   */
  protected async getResource(...parts: string[]): Promise<HttpResponse> {
    const filePath = path.join(...parts)
    return { content: await fs.readFile(filePath), filePath }
  }

  /**
   * Get a file resource as a string.
   */
  protected async getUtf8Resource(...parts: string[]): Promise<HttpStringFileResponse> {
    const filePath = path.join(...parts)
    return { content: await fs.readFile(filePath, "utf8"), filePath }
  }

  /**
A
Asher 已提交
281
   * Helper to error on invalid methods (default GET).
A
Asher 已提交
282
   */
A
Asher 已提交
283 284 285
  protected ensureMethod(request: http.IncomingMessage, method?: string | string[]): void {
    const check = Array.isArray(method) ? method : [method || "GET"]
    if (!request.method || !check.includes(request.method)) {
A
Asher 已提交
286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312
      throw new HttpError(`Unsupported method ${request.method}`, HttpCode.BadRequest)
    }
  }

  /**
   * Helper to error if not authorized.
   */
  protected ensureAuthenticated(request: http.IncomingMessage): void {
    if (!this.authenticated(request)) {
      throw new HttpError("Unauthorized", HttpCode.Unauthorized)
    }
  }

  /**
   * Use the first query value or the default if there isn't one.
   */
  protected queryOrDefault(value: string | string[] | undefined, def: string): string {
    if (Array.isArray(value)) {
      value = value[0]
    }
    return typeof value !== "undefined" ? value : def
  }

  /**
   * Return the provided password value if the payload contains the right
   * password otherwise return false. If no payload is specified use cookies.
   */
A
Asher 已提交
313
  public authenticated(request: http.IncomingMessage, payload?: AuthPayload): string | boolean {
A
Asher 已提交
314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383
    switch (this.options.auth) {
      case AuthType.None:
        return true
      case AuthType.Password:
        if (typeof payload === "undefined") {
          payload = this.parseCookies<AuthPayload>(request)
        }
        if (this.options.password && payload.key) {
          for (let i = 0; i < payload.key.length; ++i) {
            if (safeCompare(payload.key[i], this.options.password)) {
              return payload.key[i]
            }
          }
        }
        return false
      default:
        throw new Error(`Unsupported auth type ${this.options.auth}`)
    }
  }

  /**
   * Parse POST data.
   */
  protected getData(request: http.IncomingMessage): Promise<string | undefined> {
    return request.method === "POST" || request.method === "DELETE"
      ? new Promise<string>((resolve, reject) => {
          let body = ""
          const onEnd = (): void => {
            off() // eslint-disable-line @typescript-eslint/no-use-before-define
            resolve(body || undefined)
          }
          const onError = (error: Error): void => {
            off() // eslint-disable-line @typescript-eslint/no-use-before-define
            reject(error)
          }
          const onData = (d: Buffer): void => {
            body += d
            if (body.length > 1e6) {
              onError(new HttpError("Payload is too large", HttpCode.LargePayload))
              request.connection.destroy()
            }
          }
          const off = (): void => {
            request.off("error", onError)
            request.off("data", onError)
            request.off("end", onEnd)
          }
          request.on("error", onError)
          request.on("data", onData)
          request.on("end", onEnd)
        })
      : Promise.resolve(undefined)
  }

  /**
   * Parse cookies.
   */
  protected parseCookies<T extends Cookies>(request: http.IncomingMessage): T {
    const cookies: { [key: string]: string[] } = {}
    if (request.headers.cookie) {
      request.headers.cookie.split(";").forEach((keyValue) => {
        const [key, value] = split(keyValue, "=")
        if (!cookies[key]) {
          cookies[key] = []
        }
        cookies[key].push(decodeURI(value))
      })
    }
    return cookies as T
  }
384 385 386 387 388 389 390 391

  /**
   * Return true if the route is for the root page. For example /base, /base/,
   * or /base/index.html but not /base/path or /base/file.js.
   */
  protected isRoot(route: Route): boolean {
    return !route.requestPath || route.requestPath === "/index.html"
  }
A
Asher 已提交
392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420
}

/**
 * Provides a heartbeat using a local file to indicate activity.
 */
export class Heart {
  private heartbeatTimer?: NodeJS.Timeout
  private heartbeatInterval = 60000
  private lastHeartbeat = 0

  public constructor(private readonly heartbeatPath: string, private readonly isActive: () => Promise<boolean>) {}

  /**
   * Write to the heartbeat file if we haven't already done so within the
   * timeout and start or reset a timer that keeps running as long as there is
   * activity. Failures are logged as warnings.
   */
  public beat(): void {
    const now = Date.now()
    if (now - this.lastHeartbeat >= this.heartbeatInterval) {
      logger.trace("heartbeat")
      fs.outputFile(this.heartbeatPath, "").catch((error) => {
        logger.warn(error.message)
      })
      this.lastHeartbeat = now
      if (typeof this.heartbeatTimer !== "undefined") {
        clearTimeout(this.heartbeatTimer)
      }
      this.heartbeatTimer = setTimeout(() => {
A
Asher 已提交
421 422 423 424 425 426 427 428 429
        this.isActive()
          .then((active) => {
            if (active) {
              this.beat()
            }
          })
          .catch((error) => {
            logger.warn(error.message)
          })
A
Asher 已提交
430 431 432 433 434
      }, this.heartbeatInterval)
    }
  }
}

A
Asher 已提交
435 436 437 438 439 440 441 442
export interface HttpProvider0<T> {
  new (options: HttpProviderOptions): T
}

export interface HttpProvider1<A1, T> {
  new (options: HttpProviderOptions, a1: A1): T
}

A
Asher 已提交
443 444 445 446
export interface HttpProvider2<A1, A2, T> {
  new (options: HttpProviderOptions, a1: A1, a2: A2): T
}

447 448 449 450
export interface HttpProvider3<A1, A2, A3, T> {
  new (options: HttpProviderOptions, a1: A1, a2: A2, a3: A3): T
}

A
Asher 已提交
451 452 453 454 455 456 457 458 459 460 461
/**
 * An HTTP server. Its main role is to route incoming HTTP requests to the
 * appropriate provider for that endpoint then write out the response. It also
 * covers some common use cases like redirects and caching.
 */
export class HttpServer {
  protected readonly server: http.Server | https.Server
  private listenPromise: Promise<string | null> | undefined
  public readonly protocol: "http" | "https"
  private readonly providers = new Map<string, HttpProvider>()
  private readonly heart: Heart
A
Asher 已提交
462
  private readonly socketProvider = new SocketProxyProvider()
A
Asher 已提交
463 464 465 466 467 468 469 470 471 472

  /**
   * Proxy domains are stored here without the leading `*.`
   */
  public readonly proxyDomains: Set<string>

  /**
   * Provides the actual proxying functionality.
   */
  private readonly proxy = proxy.createProxyServer({})
A
Asher 已提交
473

A
Asher 已提交
474
  public constructor(private readonly options: HttpServerOptions) {
A
Asher 已提交
475
    this.proxyDomains = new Set((options.proxyDomains || []).map((d) => d.replace(/^\*\./, "")))
A
Asher 已提交
476 477 478 479 480 481 482 483 484 485 486 487
    this.heart = new Heart(path.join(xdgLocalDir, "heartbeat"), async () => {
      const connections = await this.getConnections()
      logger.trace(`${connections} active connection${plural(connections)}`)
      return connections !== 0
    })
    this.protocol = this.options.cert ? "https" : "http"
    if (this.protocol === "https") {
      this.server = httpolyglot.createServer(
        {
          cert: this.options.cert && fs.readFileSync(this.options.cert),
          key: this.options.certKey && fs.readFileSync(this.options.certKey),
        },
A
Anmol Sethi 已提交
488
        this.onRequest,
A
Asher 已提交
489 490 491 492
      )
    } else {
      this.server = http.createServer(this.onRequest)
    }
A
Asher 已提交
493 494 495 496
    this.proxy.on("error", (error, _request, response) => {
      response.writeHead(HttpCode.ServerError)
      response.end(error.message)
    })
A
Asher 已提交
497 498 499 500 501 502
    // Intercept the response to rewrite absolute redirects against the base path.
    this.proxy.on("proxyRes", (response, request: ProxyRequest) => {
      if (response.headers.location && response.headers.location.startsWith("/") && request.base) {
        response.headers.location = request.base + response.headers.location
      }
    })
A
Asher 已提交
503 504 505
  }

  public dispose(): void {
A
Asher 已提交
506
    this.socketProvider.stop()
A
Asher 已提交
507 508 509 510 511 512 513 514 515 516 517 518 519 520
    this.providers.forEach((p) => p.dispose())
  }

  public async getConnections(): Promise<number> {
    return new Promise((resolve, reject) => {
      this.server.getConnections((error, count) => {
        return error ? reject(error) : resolve(count)
      })
    })
  }

  /**
   * Register a provider for a top-level endpoint.
   */
A
Asher 已提交
521 522
  public registerHttpProvider<T extends HttpProvider>(endpoint: string, provider: HttpProvider0<T>): T
  public registerHttpProvider<A1, T extends HttpProvider>(endpoint: string, provider: HttpProvider1<A1, T>, a1: A1): T
A
Asher 已提交
523 524 525 526
  public registerHttpProvider<A1, A2, T extends HttpProvider>(
    endpoint: string,
    provider: HttpProvider2<A1, A2, T>,
    a1: A1,
527
    a2: A2,
A
Asher 已提交
528
  ): T
529 530 531 532 533 534 535
  public registerHttpProvider<A1, A2, A3, T extends HttpProvider>(
    endpoint: string,
    provider: HttpProvider3<A1, A2, A3, T>,
    a1: A1,
    a2: A2,
    a3: A3,
  ): T
A
Asher 已提交
536
  // eslint-disable-next-line @typescript-eslint/no-explicit-any
A
Asher 已提交
537
  public registerHttpProvider(endpoint: string, provider: any, ...args: any[]): any {
A
Asher 已提交
538 539 540 541 542 543 544
    endpoint = endpoint.replace(/^\/+|\/+$/g, "")
    if (this.providers.has(`/${endpoint}`)) {
      throw new Error(`${endpoint} is already registered`)
    }
    if (/\//.test(endpoint)) {
      throw new Error(`Only top-level endpoints are supported (got ${endpoint})`)
    }
A
Asher 已提交
545 546 547 548 549 550 551
    const p = new provider(
      {
        auth: this.options.auth || AuthType.None,
        base: `/${endpoint}`,
        commit: this.options.commit,
        password: this.options.password,
      },
552
      ...args,
A
Asher 已提交
553
    )
A
Asher 已提交
554 555
    this.providers.set(`/${endpoint}`, p)
    return p
A
Asher 已提交
556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589
  }

  /**
   * Start listening on the specified port.
   */
  public listen(): Promise<string | null> {
    if (!this.listenPromise) {
      this.listenPromise = new Promise((resolve, reject) => {
        this.server.on("error", reject)
        this.server.on("upgrade", this.onUpgrade)
        const onListen = (): void => resolve(this.address())
        if (this.options.socket) {
          this.server.listen(this.options.socket, onListen)
        } else {
          this.server.listen(this.options.port, this.options.host, onListen)
        }
      })
    }
    return this.listenPromise
  }

  /**
   * The *local* address of the server.
   */
  public address(): string | null {
    const address = this.server.address()
    const endpoint =
      typeof address !== "string" && address !== null
        ? (address.address === "::" ? "localhost" : address.address) + ":" + address.port
        : address
    return endpoint && `${this.protocol}://${endpoint}`
  }

  private onRequest = async (request: http.IncomingMessage, response: http.ServerResponse): Promise<void> => {
A
Asher 已提交
590 591
    this.heart.beat()
    const route = this.parseUrl(request)
A
Asher 已提交
592
    const write = (payload: HttpResponse): void => {
A
Asher 已提交
593 594
      response.writeHead(payload.redirect ? HttpCode.Redirect : payload.code || HttpCode.Ok, {
        "Content-Type": payload.mime || getMediaMime(payload.filePath),
A
Asher 已提交
595
        ...(payload.redirect ? { Location: this.constructRedirect(request, route, payload as RedirectResponse) } : {}),
A
Asher 已提交
596
        ...(request.headers["service-worker"] ? { "Service-Worker-Allowed": route.provider.base(route) } : {}),
A
Asher 已提交
597 598 599
        ...(payload.cache ? { "Cache-Control": "public, max-age=31536000" } : {}),
        ...(payload.cookie
          ? {
A
Asher 已提交
600 601 602
              "Set-Cookie": [
                `${payload.cookie.key}=${payload.cookie.value}`,
                `Path=${normalize(payload.cookie.path || "/", true)}`,
603
                this.getCookieDomain(request.headers.host || ""),
W
Will O'Beirne 已提交
604
                // "HttpOnly",
A
Asher 已提交
605
                "SameSite=lax",
A
Asher 已提交
606 607 608
              ]
                .filter((l) => !!l)
                .join(";"),
A
Asher 已提交
609 610 611 612 613 614 615 616 617
            }
          : {}),
        ...payload.headers,
      })
      if (payload.stream) {
        payload.stream.on("error", (error: NodeJS.ErrnoException) => {
          response.writeHead(error.code === "ENOENT" ? HttpCode.NotFound : HttpCode.ServerError)
          response.end(error.message)
        })
618
        payload.stream.on("close", () => response.end())
A
Asher 已提交
619 620 621 622 623 624 625 626
        payload.stream.pipe(response)
      } else if (typeof payload.content === "string" || payload.content instanceof Buffer) {
        response.end(payload.content)
      } else if (payload.content && typeof payload.content === "object") {
        response.end(JSON.stringify(payload.content))
      } else {
        response.end()
      }
A
Asher 已提交
627
    }
A
Asher 已提交
628

A
Asher 已提交
629
    try {
A
Asher 已提交
630 631
      const payload =
        this.maybeRedirect(request, route) ||
A
Asher 已提交
632 633 634 635 636
        (route.provider.authenticated(request) && this.maybeProxy(request)) ||
        (await route.provider.handleRequest(route, request))
      if (payload.proxy) {
        this.doProxy(route, request, response, payload.proxy)
      } else {
A
Asher 已提交
637
        write(payload)
A
Asher 已提交
638
      }
A
Asher 已提交
639 640 641 642 643
    } catch (error) {
      let e = error
      if (error.code === "ENOENT" || error.code === "EISDIR") {
        e = new HttpError("Not found", HttpCode.NotFound)
      }
A
Asher 已提交
644
      const code = typeof e.code === "number" ? e.code : HttpCode.ServerError
A
Asher 已提交
645 646 647 648
      logger.debug("Request error", field("url", request.url), field("code", code))
      if (code >= HttpCode.ServerError) {
        logger.error(error.stack)
      }
A
Asher 已提交
649 650 651 652 653 654 655 656 657 658 659 660 661
      if (request.headers["content-type"] === "application/json") {
        write({
          code,
          content: {
            error: e.message,
          },
        })
      } else {
        write({
          code,
          ...(await route.provider.getErrorRoot(route, code, code, e.message)),
        })
      }
A
Asher 已提交
662 663 664 665 666 667
    }
  }

  /**
   * Return any necessary redirection before delegating to a provider.
   */
A
Asher 已提交
668 669
  private maybeRedirect(request: http.IncomingMessage, route: ProviderRoute): RedirectResponse | undefined {
    // If we're handling TLS ensure all requests are redirected to HTTPS.
A
Asher 已提交
670
    if (this.options.cert && !(request.connection as tls.TLSSocket).encrypted) {
A
Asher 已提交
671
      return { redirect: route.fullPath }
A
Asher 已提交
672
    }
A
Asher 已提交
673

A
Asher 已提交
674 675 676
    return undefined
  }

A
Asher 已提交
677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693
  /**
   * Given a path that goes from the base, construct a relative redirect URL
   * that will get you there considering that the app may be served from an
   * unknown base path. If handling TLS, also ensure HTTPS.
   */
  private constructRedirect(request: http.IncomingMessage, route: ProviderRoute, payload: RedirectResponse): string {
    const query = {
      ...route.query,
      ...(payload.query || {}),
    }

    Object.keys(query).forEach((key) => {
      if (typeof query[key] === "undefined") {
        delete query[key]
      }
    })

A
Asher 已提交
694 695 696
    const secure = (request.connection as tls.TLSSocket).encrypted
    const redirect =
      (this.options.cert && !secure ? `${this.protocol}://${request.headers.host}/` : "") +
A
Asher 已提交
697 698
      normalize(`${route.provider.base(route)}/${payload.redirect}`, true) +
      (Object.keys(query).length > 0 ? `?${querystring.stringify(query)}` : "")
A
Asher 已提交
699
    logger.debug("redirecting", field("secure", !!secure), field("from", request.url), field("to", redirect))
A
Asher 已提交
700
    return redirect
A
Asher 已提交
701 702
  }

A
Asher 已提交
703 704 705 706 707 708 709 710 711 712 713 714 715
  private onUpgrade = async (request: http.IncomingMessage, socket: net.Socket, head: Buffer): Promise<void> => {
    try {
      this.heart.beat()
      socket.on("error", () => socket.destroy())

      if (this.options.cert && !(socket as tls.TLSSocket).encrypted) {
        throw new HttpError("HTTP websocket", HttpCode.BadRequest)
      }

      if (!request.headers.upgrade || request.headers.upgrade.toLowerCase() !== "websocket") {
        throw new HttpError("HTTP/1.1 400 Bad Request", HttpCode.BadRequest)
      }

A
Asher 已提交
716 717
      const route = this.parseUrl(request)
      if (!route.provider) {
A
Asher 已提交
718 719 720
        throw new HttpError("Not found", HttpCode.NotFound)
      }

A
Asher 已提交
721 722 723 724 725 726 727
      // The socket proxy is so we can pass them to child processes (TLS sockets
      // can't be transferred so we need an in-between).
      const socketProxy = await this.socketProvider.createProxy(socket)
      const payload =
        this.maybeProxy(request) || (await route.provider.handleWebSocket(route, request, socketProxy, head))
      if (payload && payload.proxy) {
        this.doProxy(route, request, { socket: socketProxy, head }, payload.proxy)
A
Asher 已提交
728
      }
A
Asher 已提交
729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753
    } catch (error) {
      socket.destroy(error)
      logger.warn(`discarding socket connection: ${error.message}`)
    }
  }

  /**
   * Parse a request URL so we can route it.
   */
  private parseUrl(request: http.IncomingMessage): ProviderRoute {
    const parse = (fullPath: string): { base: string; requestPath: string } => {
      const match = fullPath.match(/^(\/?[^/]*)(.*)$/)
      let [, /* ignore */ base, requestPath] = match ? match.map((p) => p.replace(/\/+$/, "")) : ["", "", ""]
      if (base.indexOf(".") !== -1) {
        // Assume it's a file at the root.
        requestPath = base
        base = "/"
      } else if (base === "") {
        // Happens if it's a plain `domain.com`.
        base = "/"
      }
      return { base, requestPath }
    }

    const parsedUrl = request.url ? url.parse(request.url, true) : { query: {}, pathname: "" }
A
Asher 已提交
754
    const originalPath = parsedUrl.pathname || "/"
A
Asher 已提交
755
    const fullPath = normalize(originalPath, true)
A
Asher 已提交
756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771
    const { base, requestPath } = parse(fullPath)

    // Providers match on the path after their base so we need to account for
    // that by shifting the next base out of the request path.
    let provider = this.providers.get(base)
    if (base !== "/" && provider) {
      return { ...parse(requestPath), fullPath, query: parsedUrl.query, provider, originalPath }
    }

    // Fall back to the top-level provider.
    provider = this.providers.get("/")
    if (!provider) {
      throw new Error(`No provider for ${base}`)
    }
    return { base, fullPath, requestPath, query: parsedUrl.query, provider, originalPath }
  }
A
Asher 已提交
772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829

  /**
   * Proxy a request to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: http.ServerResponse,
    options: ProxyOptions,
  ): void
  /**
   * Proxy a web socket to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: { socket: net.Socket; head: Buffer },
    options: ProxyOptions,
  ): void
  /**
   * Proxy a request or web socket to the target.
   */
  private doProxy(
    route: Route,
    request: http.IncomingMessage,
    response: http.ServerResponse | { socket: net.Socket; head: Buffer },
    options: ProxyOptions,
  ): void {
    const port = parseInt(options.port, 10)
    if (isNaN(port)) {
      throw new HttpError(`"${options.port}" is not a valid number`, HttpCode.BadRequest)
    }

    // REVIEW: Absolute redirects need to be based on the subpath but I'm not
    // sure how best to get this information to the `proxyRes` event handler.
    // For now I'm sticking it on the request object which is passed through to
    // the event.
    ;(request as ProxyRequest).base = options.base

    const isHttp = response instanceof http.ServerResponse
    const path = options.base ? route.fullPath.replace(options.base, "") : route.fullPath
    const proxyOptions: proxy.ServerOptions = {
      changeOrigin: true,
      ignorePath: true,
      target: `${isHttp ? "http" : "ws"}://127.0.0.1:${port}${path}${
        Object.keys(route.query).length > 0 ? `?${querystring.stringify(route.query)}` : ""
      }`,
      ws: !isHttp,
    }

    if (response instanceof http.ServerResponse) {
      this.proxy.web(request, response, proxyOptions)
    } else {
      this.proxy.ws(request, response.socket, response.head, proxyOptions)
    }
  }

  /**
830 831
   * Get the value that should be used for setting a cookie domain. This will
   * allow the user to authenticate only once. This will use the highest level
A
Asher 已提交
832 833
   * domain (e.g. `coder.com` over `test.coder.com` if both are specified).
   */
834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855
  private getCookieDomain(host: string): string | undefined {
    const idx = host.lastIndexOf(":")
    host = idx !== -1 ? host.substring(0, idx) : host
    if (
      // Might be blank/missing, so there's nothing more to do.
      !host ||
      // IP addresses can't have subdomains so there's no value in setting the
      // domain for them. Assume anything with a : is ipv6 (valid domain name
      // characters are alphanumeric or dashes).
      host.includes(":") ||
      // Assume anything entirely numbers and dots is ipv4 (currently tlds
      // cannot be entirely numbers).
      !/[^0-9.]/.test(host) ||
      // localhost subdomains don't seem to work at all (browser bug?).
      host.endsWith(".localhost") ||
      // It might be localhost (or an IP, see above) if it's a proxy and it
      // isn't setting the host header to match the access domain.
      host === "localhost"
    ) {
      return undefined
    }

A
Asher 已提交
856
    this.proxyDomains.forEach((domain) => {
857 858
      if (host.endsWith(domain) && domain.length < host.length) {
        host = domain
A
Asher 已提交
859 860
      }
    })
861 862

    return host ? `Domain=${host}` : undefined
A
Asher 已提交
863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892
  }

  /**
   * Return a response if the request should be proxied. Anything that ends in a
   * proxy domain and has a *single* subdomain should be proxied. Anything else
   * should return `undefined` and will be handled as normal.
   *
   * For example if `coder.com` is specified `8080.coder.com` will be proxied
   * but `8080.test.coder.com` and `test.8080.coder.com` will not.
   */
  public maybeProxy(request: http.IncomingMessage): HttpResponse | undefined {
    // Split into parts.
    const host = request.headers.host || ""
    const idx = host.indexOf(":")
    const domain = idx !== -1 ? host.substring(0, idx) : host
    const parts = domain.split(".")

    // There must be an exact match.
    const port = parts.shift()
    const proxyDomain = parts.join(".")
    if (!port || !this.proxyDomains.has(proxyDomain)) {
      return undefined
    }

    return {
      proxy: {
        port,
      },
    }
  }
A
Asher 已提交
893
}