Compare commits
227 Commits
6874aebfc7
...
renovate/s
| Author | SHA1 | Date | |
|---|---|---|---|
| 65b66c1156 | |||
| f0e8c799ff | |||
| b4e7cb8718 | |||
| 7a590e882b | |||
| 9a643ced94 | |||
| 5f2a6478a7 | |||
| 1db929a31b | |||
| 0b2c4071e8 | |||
| 61ecfc5af1 | |||
| 661793f58d | |||
| d253e73099 | |||
| f0d3d311e9 | |||
| 592203aa4a | |||
| aeb35029c3 | |||
| 1dc56d5ec1 | |||
| 51b1ab380c | |||
| b5abddaacb | |||
| 2f74c3b1a6 | |||
| d2791f821f | |||
| 4a7eb57cf3 | |||
| 29e32c56cc | |||
| bde815b123 | |||
| c428e51df0 | |||
| 1967b29b9f | |||
| ed8ee5dc58 | |||
| 1c9ce3cc32 | |||
| f4e9fcf40f | |||
| f522d0e700 | |||
| 45213e74cb | |||
| 627647bf47 | |||
| 392b9fd5d6 | |||
| 1c47cbe0d8 | |||
| becfea8e82 | |||
| f6c9d7f4d6 | |||
| 34bca2b609 | |||
| 5cd681b8da | |||
| 55b253c9a6 | |||
| 504dabfe67 | |||
| 75b04a4998 | |||
| e076c4b9fe | |||
| ce5f8c6c70 | |||
| 20f28d2e6f | |||
| 7e853d4c89 | |||
| e2c16d9450 | |||
| ae1550248e | |||
| 03e5c375fb | |||
| 3db32e24c7 | |||
| f9fe44f53d | |||
| 659433911a | |||
| 27bb4d3382 | |||
| b7c7b74122 | |||
| 731cf7327c | |||
| 34d228e7b8 | |||
| 20800668c9 | |||
| ea022a0cfe | |||
| fa088077d5 | |||
| e7e8016b67 | |||
| d88cd8cd8d | |||
| 08c2009421 | |||
| fddd9d011a | |||
| e8271834eb | |||
| 82a0a19b1c | |||
| a5d2af3a8d | |||
| 95ae3de818 | |||
| ae79f16d17 | |||
| 57893e557c | |||
| 526a7dbb1f | |||
| d0f297e354 | |||
| ecb3fb7196 | |||
| 0fc067a6c5 | |||
| 213281f7b6 | |||
| 8ae1b7fb78 | |||
| 87fed55d8c | |||
| 7db8b8a1b9 | |||
| 299b05cf7b | |||
| d3717dcb8d | |||
| 0b99f1e44b | |||
| d7de13a002 | |||
| ed83ce4a10 | |||
| 22f6f2cca5 | |||
| a8d28526df | |||
| b24d214b3f | |||
| a9947c155a | |||
| bbdfc9affb | |||
| a54f406371 | |||
| afac1c9f93 | |||
| 1f0ca1823f | |||
| 1534b11606 | |||
| dc179184f7 | |||
| ecba5816d9 | |||
| 24e8804aed | |||
| 0e9880fec6 | |||
| 16b6d20b5d | |||
| aaf49ec02b | |||
| 619a4d6ba5 | |||
| 1ac1b0b13f | |||
| 176766623a | |||
| 77d618a87d | |||
| ff928609da | |||
| 54dd04b65e | |||
| 8ca288748d | |||
| 3849e812a8 | |||
| 57e49a86d9 | |||
| 9cfe3f33e9 | |||
| 26d1ee3602 | |||
| 286547d455 | |||
| 47337dc140 | |||
| e1b0c9563f | |||
| 5e84b40d05 | |||
| 4d1587dda2 | |||
| 06202d5e9d | |||
| bc49b0e59e | |||
| 233eb9c250 | |||
| acf92592ff | |||
| da82b820fd | |||
| 409e84951b | |||
| f7527e6bc5 | |||
| 0106b2bfea | |||
| b6020b99c6 | |||
| ed7a0688c3 | |||
| 9480f0dae9 | |||
| b99eb4d178 | |||
| 044a089f4a | |||
| f1a7943d93 | |||
| 82c3c3a7b7 | |||
| 7bc21fbb68 | |||
| f67e680522 | |||
| c296196933 | |||
| 3adc2f424a | |||
| 479d4d76bd | |||
| 4b4897c1f4 | |||
| 443ba0f7d5 | |||
| 86fc06e51f | |||
| b81b7657cc | |||
| e14c8af5c5 | |||
| 44c59aadab | |||
| ee0558233b | |||
| c2d82cf9c4 | |||
| a75ff3fc64 | |||
| bf8122ae81 | |||
| 04f4255aab | |||
| f350ee4ca9 | |||
| fdb3187d69 | |||
| ec5d2cc40f | |||
| 79efdc95bf | |||
| fab873d920 | |||
| 33f181f20b | |||
| c23b6ca0b9 | |||
| 55d70fc8d9 | |||
| fe3c441e7b | |||
| 68ce10f3ad | |||
| e40c567254 | |||
| 0c73bc7b51 | |||
| e876258394 | |||
| 59de36eda5 | |||
| 8112608736 | |||
| 0d68c31e0e | |||
| f4d3af3a89 | |||
| e124abf496 | |||
| 53dea2c8f8 | |||
| 54a0a9c914 | |||
| 9c25527e83 | |||
| e1accbfa21 | |||
| 25f31cf9fb | |||
| 2d8973aec5 | |||
| e01fe63cfd | |||
| 44ce00c69b | |||
| b877ecd759 | |||
| 6bf56f7489 | |||
| a7edb1e163 | |||
| d341f8f42d | |||
| 0bd5bc18a6 | |||
| e94d2f7681 | |||
| 72a3bb5d9f | |||
| 4ae19f315c | |||
| fe3de01bbf | |||
| 201d8d5b86 | |||
| 8f3ee31524 | |||
| 3ae504e18e | |||
| 9b6f0c59d9 | |||
| 25a52bfcb2 | |||
| d9a5bf6781 | |||
| 77e978c0f0 | |||
| 0db3a85a52 | |||
| 72f8c8c829 | |||
| 65df24578d | |||
| 7086ad823e | |||
| aac8a04182 | |||
| faf0d3acee | |||
| ecec54723e | |||
| 27d56c3c8f | |||
| 896ea03a36 | |||
| bfd24395d8 | |||
| ab96bc6a00 | |||
| 282cf44f58 | |||
| e5273d162c | |||
| 5ce066cdea | |||
| 4a55c84c8c | |||
| 244d36830d | |||
| 2f161841eb | |||
| 064aa92cb4 | |||
| 0b16fd2202 | |||
| bab8edbe7f | |||
| ff43364df3 | |||
| 95ca1f0ba6 | |||
| d68e3eca3b | |||
| 3640f72d73 | |||
| 6adc0c1fbb | |||
| fa4665280d | |||
| 4589b3b339 | |||
| 53186d2e24 | |||
| b91b1ba096 | |||
| 4ee26df97b | |||
| 3822c209d3 | |||
| 17e086b43c | |||
| bb1e412d36 | |||
| b8a8e14f3c | |||
| 558d5cda3f | |||
| 4ff72e073e | |||
| c573d2f74a | |||
| babb3a2e07 | |||
| e6b347f90f | |||
| 8df3afe75e | |||
| af1dd4d122 | |||
| 501520a9df | |||
| 08f535c15c | |||
| 0e8b4751b4 |
12
.drone.yml
Normal file
12
.drone.yml
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
kind: pipeline
|
||||||
|
type: docker
|
||||||
|
name: default
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: cargo_check
|
||||||
|
image: rust
|
||||||
|
commands:
|
||||||
|
- rustup component add clippy
|
||||||
|
- cargo clippy -- -D warnings
|
||||||
|
- cargo test
|
||||||
1360
Cargo.lock
generated
1360
Cargo.lock
generated
File diff suppressed because it is too large
Load Diff
43
Cargo.toml
43
Cargo.toml
@@ -4,25 +4,32 @@ version = "0.1.0"
|
|||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
log = "0.4.25"
|
log = "0.4.28"
|
||||||
env_logger = "0.11.6"
|
env_logger = "0.11.8"
|
||||||
clap = { version = "4.5.26", features = ["derive", "env"] }
|
clap = { version = "4.5.53", features = ["derive", "env"] }
|
||||||
lazy_static = "1.5.0"
|
lazy_static = "1.5.0"
|
||||||
anyhow = "1.0.95"
|
anyhow = "1.0.100"
|
||||||
serde = { version = "1.0.217", features = ["derive"] }
|
serde = { version = "1.0.228", features = ["derive"] }
|
||||||
serde_json = "1.0.137"
|
serde_json = "1.0.145"
|
||||||
rust-s3 = { version = "0.36.0-beta.2", features = ["tokio"] }
|
rust-s3 = { version = "0.37.0", features = ["tokio"] }
|
||||||
actix-web = "4"
|
actix-web = "4.12.1"
|
||||||
actix-session = { version = "0.10.1", features = ["redis-session"] }
|
actix-session = { version = "0.11.0", features = ["redis-session"] }
|
||||||
light-openid = "1.0.2"
|
light-openid = "1.0.4"
|
||||||
thiserror = "2.0.11"
|
thiserror = "2.0.17"
|
||||||
rand = "0.9.0-beta.3"
|
rand = "0.9.2"
|
||||||
rust-embed = "8.5.0"
|
rust-embed = "8.9.0"
|
||||||
mime_guess = "2.0.5"
|
mime_guess = "2.0.5"
|
||||||
askama = "0.12.1"
|
askama = "0.14.0"
|
||||||
urlencoding = "2.1.3"
|
urlencoding = "2.1.3"
|
||||||
uuid = { version = "1.12.1", features = ["v4", "serde"] }
|
uuid = { version = "1.18.0", features = ["v4", "serde"] }
|
||||||
ipnet = { version = "2.11.0", features = ["serde"] }
|
ipnet = { version = "2.11.0", features = ["serde"] }
|
||||||
chrono = "0.4.39"
|
chrono = "0.4.42"
|
||||||
futures-util = "0.3.31"
|
futures-util = { version = "0.3.31", features = ["sink"] }
|
||||||
jwt-simple = { version = "0.12.11", default-features=false, features=["pure-rust"] }
|
jwt-simple = { version = "0.12.13", default-features = false, features = ["pure-rust"] }
|
||||||
|
actix-remote-ip = "0.1.0"
|
||||||
|
bytes = "1.11.0"
|
||||||
|
sha2 = "0.11.0-rc.3"
|
||||||
|
base16ct = { version = "0.3.0", features = ["alloc"] }
|
||||||
|
ruma = { version = "0.14.0", features = ["client-api-c", "client-ext-client-api", "client-hyper-native-tls", "rand"] }
|
||||||
|
actix-ws = "0.3.0"
|
||||||
|
tokio = { version = "1.48.0", features = ["rt", "time", "macros", "rt-multi-thread"] }
|
||||||
|
|||||||
10
Dockerfile
Normal file
10
Dockerfile
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
FROM debian:bookworm-slim
|
||||||
|
|
||||||
|
RUN apt-get update \
|
||||||
|
&& apt-get install -y libssl3 \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
COPY matrix_gateway /usr/local/bin/matrix_gateway
|
||||||
|
|
||||||
|
ENTRYPOINT ["/usr/local/bin/matrix_gateway"]
|
||||||
|
|
||||||
674
LICENSE
Normal file
674
LICENSE
Normal file
@@ -0,0 +1,674 @@
|
|||||||
|
GNU GENERAL PUBLIC LICENSE
|
||||||
|
Version 3, 29 June 2007
|
||||||
|
|
||||||
|
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
|
||||||
|
Everyone is permitted to copy and distribute verbatim copies
|
||||||
|
of this license document, but changing it is not allowed.
|
||||||
|
|
||||||
|
Preamble
|
||||||
|
|
||||||
|
The GNU General Public License is a free, copyleft license for
|
||||||
|
software and other kinds of works.
|
||||||
|
|
||||||
|
The licenses for most software and other practical works are designed
|
||||||
|
to take away your freedom to share and change the works. By contrast,
|
||||||
|
the GNU General Public License is intended to guarantee your freedom to
|
||||||
|
share and change all versions of a program--to make sure it remains free
|
||||||
|
software for all its users. We, the Free Software Foundation, use the
|
||||||
|
GNU General Public License for most of our software; it applies also to
|
||||||
|
any other work released this way by its authors. You can apply it to
|
||||||
|
your programs, too.
|
||||||
|
|
||||||
|
When we speak of free software, we are referring to freedom, not
|
||||||
|
price. Our General Public Licenses are designed to make sure that you
|
||||||
|
have the freedom to distribute copies of free software (and charge for
|
||||||
|
them if you wish), that you receive source code or can get it if you
|
||||||
|
want it, that you can change the software or use pieces of it in new
|
||||||
|
free programs, and that you know you can do these things.
|
||||||
|
|
||||||
|
To protect your rights, we need to prevent others from denying you
|
||||||
|
these rights or asking you to surrender the rights. Therefore, you have
|
||||||
|
certain responsibilities if you distribute copies of the software, or if
|
||||||
|
you modify it: responsibilities to respect the freedom of others.
|
||||||
|
|
||||||
|
For example, if you distribute copies of such a program, whether
|
||||||
|
gratis or for a fee, you must pass on to the recipients the same
|
||||||
|
freedoms that you received. You must make sure that they, too, receive
|
||||||
|
or can get the source code. And you must show them these terms so they
|
||||||
|
know their rights.
|
||||||
|
|
||||||
|
Developers that use the GNU GPL protect your rights with two steps:
|
||||||
|
(1) assert copyright on the software, and (2) offer you this License
|
||||||
|
giving you legal permission to copy, distribute and/or modify it.
|
||||||
|
|
||||||
|
For the developers' and authors' protection, the GPL clearly explains
|
||||||
|
that there is no warranty for this free software. For both users' and
|
||||||
|
authors' sake, the GPL requires that modified versions be marked as
|
||||||
|
changed, so that their problems will not be attributed erroneously to
|
||||||
|
authors of previous versions.
|
||||||
|
|
||||||
|
Some devices are designed to deny users access to install or run
|
||||||
|
modified versions of the software inside them, although the manufacturer
|
||||||
|
can do so. This is fundamentally incompatible with the aim of
|
||||||
|
protecting users' freedom to change the software. The systematic
|
||||||
|
pattern of such abuse occurs in the area of products for individuals to
|
||||||
|
use, which is precisely where it is most unacceptable. Therefore, we
|
||||||
|
have designed this version of the GPL to prohibit the practice for those
|
||||||
|
products. If such problems arise substantially in other domains, we
|
||||||
|
stand ready to extend this provision to those domains in future versions
|
||||||
|
of the GPL, as needed to protect the freedom of users.
|
||||||
|
|
||||||
|
Finally, every program is threatened constantly by software patents.
|
||||||
|
States should not allow patents to restrict development and use of
|
||||||
|
software on general-purpose computers, but in those that do, we wish to
|
||||||
|
avoid the special danger that patents applied to a free program could
|
||||||
|
make it effectively proprietary. To prevent this, the GPL assures that
|
||||||
|
patents cannot be used to render the program non-free.
|
||||||
|
|
||||||
|
The precise terms and conditions for copying, distribution and
|
||||||
|
modification follow.
|
||||||
|
|
||||||
|
TERMS AND CONDITIONS
|
||||||
|
|
||||||
|
0. Definitions.
|
||||||
|
|
||||||
|
"This License" refers to version 3 of the GNU General Public License.
|
||||||
|
|
||||||
|
"Copyright" also means copyright-like laws that apply to other kinds of
|
||||||
|
works, such as semiconductor masks.
|
||||||
|
|
||||||
|
"The Program" refers to any copyrightable work licensed under this
|
||||||
|
License. Each licensee is addressed as "you". "Licensees" and
|
||||||
|
"recipients" may be individuals or organizations.
|
||||||
|
|
||||||
|
To "modify" a work means to copy from or adapt all or part of the work
|
||||||
|
in a fashion requiring copyright permission, other than the making of an
|
||||||
|
exact copy. The resulting work is called a "modified version" of the
|
||||||
|
earlier work or a work "based on" the earlier work.
|
||||||
|
|
||||||
|
A "covered work" means either the unmodified Program or a work based
|
||||||
|
on the Program.
|
||||||
|
|
||||||
|
To "propagate" a work means to do anything with it that, without
|
||||||
|
permission, would make you directly or secondarily liable for
|
||||||
|
infringement under applicable copyright law, except executing it on a
|
||||||
|
computer or modifying a private copy. Propagation includes copying,
|
||||||
|
distribution (with or without modification), making available to the
|
||||||
|
public, and in some countries other activities as well.
|
||||||
|
|
||||||
|
To "convey" a work means any kind of propagation that enables other
|
||||||
|
parties to make or receive copies. Mere interaction with a user through
|
||||||
|
a computer network, with no transfer of a copy, is not conveying.
|
||||||
|
|
||||||
|
An interactive user interface displays "Appropriate Legal Notices"
|
||||||
|
to the extent that it includes a convenient and prominently visible
|
||||||
|
feature that (1) displays an appropriate copyright notice, and (2)
|
||||||
|
tells the user that there is no warranty for the work (except to the
|
||||||
|
extent that warranties are provided), that licensees may convey the
|
||||||
|
work under this License, and how to view a copy of this License. If
|
||||||
|
the interface presents a list of user commands or options, such as a
|
||||||
|
menu, a prominent item in the list meets this criterion.
|
||||||
|
|
||||||
|
1. Source Code.
|
||||||
|
|
||||||
|
The "source code" for a work means the preferred form of the work
|
||||||
|
for making modifications to it. "Object code" means any non-source
|
||||||
|
form of a work.
|
||||||
|
|
||||||
|
A "Standard Interface" means an interface that either is an official
|
||||||
|
standard defined by a recognized standards body, or, in the case of
|
||||||
|
interfaces specified for a particular programming language, one that
|
||||||
|
is widely used among developers working in that language.
|
||||||
|
|
||||||
|
The "System Libraries" of an executable work include anything, other
|
||||||
|
than the work as a whole, that (a) is included in the normal form of
|
||||||
|
packaging a Major Component, but which is not part of that Major
|
||||||
|
Component, and (b) serves only to enable use of the work with that
|
||||||
|
Major Component, or to implement a Standard Interface for which an
|
||||||
|
implementation is available to the public in source code form. A
|
||||||
|
"Major Component", in this context, means a major essential component
|
||||||
|
(kernel, window system, and so on) of the specific operating system
|
||||||
|
(if any) on which the executable work runs, or a compiler used to
|
||||||
|
produce the work, or an object code interpreter used to run it.
|
||||||
|
|
||||||
|
The "Corresponding Source" for a work in object code form means all
|
||||||
|
the source code needed to generate, install, and (for an executable
|
||||||
|
work) run the object code and to modify the work, including scripts to
|
||||||
|
control those activities. However, it does not include the work's
|
||||||
|
System Libraries, or general-purpose tools or generally available free
|
||||||
|
programs which are used unmodified in performing those activities but
|
||||||
|
which are not part of the work. For example, Corresponding Source
|
||||||
|
includes interface definition files associated with source files for
|
||||||
|
the work, and the source code for shared libraries and dynamically
|
||||||
|
linked subprograms that the work is specifically designed to require,
|
||||||
|
such as by intimate data communication or control flow between those
|
||||||
|
subprograms and other parts of the work.
|
||||||
|
|
||||||
|
The Corresponding Source need not include anything that users
|
||||||
|
can regenerate automatically from other parts of the Corresponding
|
||||||
|
Source.
|
||||||
|
|
||||||
|
The Corresponding Source for a work in source code form is that
|
||||||
|
same work.
|
||||||
|
|
||||||
|
2. Basic Permissions.
|
||||||
|
|
||||||
|
All rights granted under this License are granted for the term of
|
||||||
|
copyright on the Program, and are irrevocable provided the stated
|
||||||
|
conditions are met. This License explicitly affirms your unlimited
|
||||||
|
permission to run the unmodified Program. The output from running a
|
||||||
|
covered work is covered by this License only if the output, given its
|
||||||
|
content, constitutes a covered work. This License acknowledges your
|
||||||
|
rights of fair use or other equivalent, as provided by copyright law.
|
||||||
|
|
||||||
|
You may make, run and propagate covered works that you do not
|
||||||
|
convey, without conditions so long as your license otherwise remains
|
||||||
|
in force. You may convey covered works to others for the sole purpose
|
||||||
|
of having them make modifications exclusively for you, or provide you
|
||||||
|
with facilities for running those works, provided that you comply with
|
||||||
|
the terms of this License in conveying all material for which you do
|
||||||
|
not control copyright. Those thus making or running the covered works
|
||||||
|
for you must do so exclusively on your behalf, under your direction
|
||||||
|
and control, on terms that prohibit them from making any copies of
|
||||||
|
your copyrighted material outside their relationship with you.
|
||||||
|
|
||||||
|
Conveying under any other circumstances is permitted solely under
|
||||||
|
the conditions stated below. Sublicensing is not allowed; section 10
|
||||||
|
makes it unnecessary.
|
||||||
|
|
||||||
|
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
||||||
|
|
||||||
|
No covered work shall be deemed part of an effective technological
|
||||||
|
measure under any applicable law fulfilling obligations under article
|
||||||
|
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
||||||
|
similar laws prohibiting or restricting circumvention of such
|
||||||
|
measures.
|
||||||
|
|
||||||
|
When you convey a covered work, you waive any legal power to forbid
|
||||||
|
circumvention of technological measures to the extent such circumvention
|
||||||
|
is effected by exercising rights under this License with respect to
|
||||||
|
the covered work, and you disclaim any intention to limit operation or
|
||||||
|
modification of the work as a means of enforcing, against the work's
|
||||||
|
users, your or third parties' legal rights to forbid circumvention of
|
||||||
|
technological measures.
|
||||||
|
|
||||||
|
4. Conveying Verbatim Copies.
|
||||||
|
|
||||||
|
You may convey verbatim copies of the Program's source code as you
|
||||||
|
receive it, in any medium, provided that you conspicuously and
|
||||||
|
appropriately publish on each copy an appropriate copyright notice;
|
||||||
|
keep intact all notices stating that this License and any
|
||||||
|
non-permissive terms added in accord with section 7 apply to the code;
|
||||||
|
keep intact all notices of the absence of any warranty; and give all
|
||||||
|
recipients a copy of this License along with the Program.
|
||||||
|
|
||||||
|
You may charge any price or no price for each copy that you convey,
|
||||||
|
and you may offer support or warranty protection for a fee.
|
||||||
|
|
||||||
|
5. Conveying Modified Source Versions.
|
||||||
|
|
||||||
|
You may convey a work based on the Program, or the modifications to
|
||||||
|
produce it from the Program, in the form of source code under the
|
||||||
|
terms of section 4, provided that you also meet all of these conditions:
|
||||||
|
|
||||||
|
a) The work must carry prominent notices stating that you modified
|
||||||
|
it, and giving a relevant date.
|
||||||
|
|
||||||
|
b) The work must carry prominent notices stating that it is
|
||||||
|
released under this License and any conditions added under section
|
||||||
|
7. This requirement modifies the requirement in section 4 to
|
||||||
|
"keep intact all notices".
|
||||||
|
|
||||||
|
c) You must license the entire work, as a whole, under this
|
||||||
|
License to anyone who comes into possession of a copy. This
|
||||||
|
License will therefore apply, along with any applicable section 7
|
||||||
|
additional terms, to the whole of the work, and all its parts,
|
||||||
|
regardless of how they are packaged. This License gives no
|
||||||
|
permission to license the work in any other way, but it does not
|
||||||
|
invalidate such permission if you have separately received it.
|
||||||
|
|
||||||
|
d) If the work has interactive user interfaces, each must display
|
||||||
|
Appropriate Legal Notices; however, if the Program has interactive
|
||||||
|
interfaces that do not display Appropriate Legal Notices, your
|
||||||
|
work need not make them do so.
|
||||||
|
|
||||||
|
A compilation of a covered work with other separate and independent
|
||||||
|
works, which are not by their nature extensions of the covered work,
|
||||||
|
and which are not combined with it such as to form a larger program,
|
||||||
|
in or on a volume of a storage or distribution medium, is called an
|
||||||
|
"aggregate" if the compilation and its resulting copyright are not
|
||||||
|
used to limit the access or legal rights of the compilation's users
|
||||||
|
beyond what the individual works permit. Inclusion of a covered work
|
||||||
|
in an aggregate does not cause this License to apply to the other
|
||||||
|
parts of the aggregate.
|
||||||
|
|
||||||
|
6. Conveying Non-Source Forms.
|
||||||
|
|
||||||
|
You may convey a covered work in object code form under the terms
|
||||||
|
of sections 4 and 5, provided that you also convey the
|
||||||
|
machine-readable Corresponding Source under the terms of this License,
|
||||||
|
in one of these ways:
|
||||||
|
|
||||||
|
a) Convey the object code in, or embodied in, a physical product
|
||||||
|
(including a physical distribution medium), accompanied by the
|
||||||
|
Corresponding Source fixed on a durable physical medium
|
||||||
|
customarily used for software interchange.
|
||||||
|
|
||||||
|
b) Convey the object code in, or embodied in, a physical product
|
||||||
|
(including a physical distribution medium), accompanied by a
|
||||||
|
written offer, valid for at least three years and valid for as
|
||||||
|
long as you offer spare parts or customer support for that product
|
||||||
|
model, to give anyone who possesses the object code either (1) a
|
||||||
|
copy of the Corresponding Source for all the software in the
|
||||||
|
product that is covered by this License, on a durable physical
|
||||||
|
medium customarily used for software interchange, for a price no
|
||||||
|
more than your reasonable cost of physically performing this
|
||||||
|
conveying of source, or (2) access to copy the
|
||||||
|
Corresponding Source from a network server at no charge.
|
||||||
|
|
||||||
|
c) Convey individual copies of the object code with a copy of the
|
||||||
|
written offer to provide the Corresponding Source. This
|
||||||
|
alternative is allowed only occasionally and noncommercially, and
|
||||||
|
only if you received the object code with such an offer, in accord
|
||||||
|
with subsection 6b.
|
||||||
|
|
||||||
|
d) Convey the object code by offering access from a designated
|
||||||
|
place (gratis or for a charge), and offer equivalent access to the
|
||||||
|
Corresponding Source in the same way through the same place at no
|
||||||
|
further charge. You need not require recipients to copy the
|
||||||
|
Corresponding Source along with the object code. If the place to
|
||||||
|
copy the object code is a network server, the Corresponding Source
|
||||||
|
may be on a different server (operated by you or a third party)
|
||||||
|
that supports equivalent copying facilities, provided you maintain
|
||||||
|
clear directions next to the object code saying where to find the
|
||||||
|
Corresponding Source. Regardless of what server hosts the
|
||||||
|
Corresponding Source, you remain obligated to ensure that it is
|
||||||
|
available for as long as needed to satisfy these requirements.
|
||||||
|
|
||||||
|
e) Convey the object code using peer-to-peer transmission, provided
|
||||||
|
you inform other peers where the object code and Corresponding
|
||||||
|
Source of the work are being offered to the general public at no
|
||||||
|
charge under subsection 6d.
|
||||||
|
|
||||||
|
A separable portion of the object code, whose source code is excluded
|
||||||
|
from the Corresponding Source as a System Library, need not be
|
||||||
|
included in conveying the object code work.
|
||||||
|
|
||||||
|
A "User Product" is either (1) a "consumer product", which means any
|
||||||
|
tangible personal property which is normally used for personal, family,
|
||||||
|
or household purposes, or (2) anything designed or sold for incorporation
|
||||||
|
into a dwelling. In determining whether a product is a consumer product,
|
||||||
|
doubtful cases shall be resolved in favor of coverage. For a particular
|
||||||
|
product received by a particular user, "normally used" refers to a
|
||||||
|
typical or common use of that class of product, regardless of the status
|
||||||
|
of the particular user or of the way in which the particular user
|
||||||
|
actually uses, or expects or is expected to use, the product. A product
|
||||||
|
is a consumer product regardless of whether the product has substantial
|
||||||
|
commercial, industrial or non-consumer uses, unless such uses represent
|
||||||
|
the only significant mode of use of the product.
|
||||||
|
|
||||||
|
"Installation Information" for a User Product means any methods,
|
||||||
|
procedures, authorization keys, or other information required to install
|
||||||
|
and execute modified versions of a covered work in that User Product from
|
||||||
|
a modified version of its Corresponding Source. The information must
|
||||||
|
suffice to ensure that the continued functioning of the modified object
|
||||||
|
code is in no case prevented or interfered with solely because
|
||||||
|
modification has been made.
|
||||||
|
|
||||||
|
If you convey an object code work under this section in, or with, or
|
||||||
|
specifically for use in, a User Product, and the conveying occurs as
|
||||||
|
part of a transaction in which the right of possession and use of the
|
||||||
|
User Product is transferred to the recipient in perpetuity or for a
|
||||||
|
fixed term (regardless of how the transaction is characterized), the
|
||||||
|
Corresponding Source conveyed under this section must be accompanied
|
||||||
|
by the Installation Information. But this requirement does not apply
|
||||||
|
if neither you nor any third party retains the ability to install
|
||||||
|
modified object code on the User Product (for example, the work has
|
||||||
|
been installed in ROM).
|
||||||
|
|
||||||
|
The requirement to provide Installation Information does not include a
|
||||||
|
requirement to continue to provide support service, warranty, or updates
|
||||||
|
for a work that has been modified or installed by the recipient, or for
|
||||||
|
the User Product in which it has been modified or installed. Access to a
|
||||||
|
network may be denied when the modification itself materially and
|
||||||
|
adversely affects the operation of the network or violates the rules and
|
||||||
|
protocols for communication across the network.
|
||||||
|
|
||||||
|
Corresponding Source conveyed, and Installation Information provided,
|
||||||
|
in accord with this section must be in a format that is publicly
|
||||||
|
documented (and with an implementation available to the public in
|
||||||
|
source code form), and must require no special password or key for
|
||||||
|
unpacking, reading or copying.
|
||||||
|
|
||||||
|
7. Additional Terms.
|
||||||
|
|
||||||
|
"Additional permissions" are terms that supplement the terms of this
|
||||||
|
License by making exceptions from one or more of its conditions.
|
||||||
|
Additional permissions that are applicable to the entire Program shall
|
||||||
|
be treated as though they were included in this License, to the extent
|
||||||
|
that they are valid under applicable law. If additional permissions
|
||||||
|
apply only to part of the Program, that part may be used separately
|
||||||
|
under those permissions, but the entire Program remains governed by
|
||||||
|
this License without regard to the additional permissions.
|
||||||
|
|
||||||
|
When you convey a copy of a covered work, you may at your option
|
||||||
|
remove any additional permissions from that copy, or from any part of
|
||||||
|
it. (Additional permissions may be written to require their own
|
||||||
|
removal in certain cases when you modify the work.) You may place
|
||||||
|
additional permissions on material, added by you to a covered work,
|
||||||
|
for which you have or can give appropriate copyright permission.
|
||||||
|
|
||||||
|
Notwithstanding any other provision of this License, for material you
|
||||||
|
add to a covered work, you may (if authorized by the copyright holders of
|
||||||
|
that material) supplement the terms of this License with terms:
|
||||||
|
|
||||||
|
a) Disclaiming warranty or limiting liability differently from the
|
||||||
|
terms of sections 15 and 16 of this License; or
|
||||||
|
|
||||||
|
b) Requiring preservation of specified reasonable legal notices or
|
||||||
|
author attributions in that material or in the Appropriate Legal
|
||||||
|
Notices displayed by works containing it; or
|
||||||
|
|
||||||
|
c) Prohibiting misrepresentation of the origin of that material, or
|
||||||
|
requiring that modified versions of such material be marked in
|
||||||
|
reasonable ways as different from the original version; or
|
||||||
|
|
||||||
|
d) Limiting the use for publicity purposes of names of licensors or
|
||||||
|
authors of the material; or
|
||||||
|
|
||||||
|
e) Declining to grant rights under trademark law for use of some
|
||||||
|
trade names, trademarks, or service marks; or
|
||||||
|
|
||||||
|
f) Requiring indemnification of licensors and authors of that
|
||||||
|
material by anyone who conveys the material (or modified versions of
|
||||||
|
it) with contractual assumptions of liability to the recipient, for
|
||||||
|
any liability that these contractual assumptions directly impose on
|
||||||
|
those licensors and authors.
|
||||||
|
|
||||||
|
All other non-permissive additional terms are considered "further
|
||||||
|
restrictions" within the meaning of section 10. If the Program as you
|
||||||
|
received it, or any part of it, contains a notice stating that it is
|
||||||
|
governed by this License along with a term that is a further
|
||||||
|
restriction, you may remove that term. If a license document contains
|
||||||
|
a further restriction but permits relicensing or conveying under this
|
||||||
|
License, you may add to a covered work material governed by the terms
|
||||||
|
of that license document, provided that the further restriction does
|
||||||
|
not survive such relicensing or conveying.
|
||||||
|
|
||||||
|
If you add terms to a covered work in accord with this section, you
|
||||||
|
must place, in the relevant source files, a statement of the
|
||||||
|
additional terms that apply to those files, or a notice indicating
|
||||||
|
where to find the applicable terms.
|
||||||
|
|
||||||
|
Additional terms, permissive or non-permissive, may be stated in the
|
||||||
|
form of a separately written license, or stated as exceptions;
|
||||||
|
the above requirements apply either way.
|
||||||
|
|
||||||
|
8. Termination.
|
||||||
|
|
||||||
|
You may not propagate or modify a covered work except as expressly
|
||||||
|
provided under this License. Any attempt otherwise to propagate or
|
||||||
|
modify it is void, and will automatically terminate your rights under
|
||||||
|
this License (including any patent licenses granted under the third
|
||||||
|
paragraph of section 11).
|
||||||
|
|
||||||
|
However, if you cease all violation of this License, then your
|
||||||
|
license from a particular copyright holder is reinstated (a)
|
||||||
|
provisionally, unless and until the copyright holder explicitly and
|
||||||
|
finally terminates your license, and (b) permanently, if the copyright
|
||||||
|
holder fails to notify you of the violation by some reasonable means
|
||||||
|
prior to 60 days after the cessation.
|
||||||
|
|
||||||
|
Moreover, your license from a particular copyright holder is
|
||||||
|
reinstated permanently if the copyright holder notifies you of the
|
||||||
|
violation by some reasonable means, this is the first time you have
|
||||||
|
received notice of violation of this License (for any work) from that
|
||||||
|
copyright holder, and you cure the violation prior to 30 days after
|
||||||
|
your receipt of the notice.
|
||||||
|
|
||||||
|
Termination of your rights under this section does not terminate the
|
||||||
|
licenses of parties who have received copies or rights from you under
|
||||||
|
this License. If your rights have been terminated and not permanently
|
||||||
|
reinstated, you do not qualify to receive new licenses for the same
|
||||||
|
material under section 10.
|
||||||
|
|
||||||
|
9. Acceptance Not Required for Having Copies.
|
||||||
|
|
||||||
|
You are not required to accept this License in order to receive or
|
||||||
|
run a copy of the Program. Ancillary propagation of a covered work
|
||||||
|
occurring solely as a consequence of using peer-to-peer transmission
|
||||||
|
to receive a copy likewise does not require acceptance. However,
|
||||||
|
nothing other than this License grants you permission to propagate or
|
||||||
|
modify any covered work. These actions infringe copyright if you do
|
||||||
|
not accept this License. Therefore, by modifying or propagating a
|
||||||
|
covered work, you indicate your acceptance of this License to do so.
|
||||||
|
|
||||||
|
10. Automatic Licensing of Downstream Recipients.
|
||||||
|
|
||||||
|
Each time you convey a covered work, the recipient automatically
|
||||||
|
receives a license from the original licensors, to run, modify and
|
||||||
|
propagate that work, subject to this License. You are not responsible
|
||||||
|
for enforcing compliance by third parties with this License.
|
||||||
|
|
||||||
|
An "entity transaction" is a transaction transferring control of an
|
||||||
|
organization, or substantially all assets of one, or subdividing an
|
||||||
|
organization, or merging organizations. If propagation of a covered
|
||||||
|
work results from an entity transaction, each party to that
|
||||||
|
transaction who receives a copy of the work also receives whatever
|
||||||
|
licenses to the work the party's predecessor in interest had or could
|
||||||
|
give under the previous paragraph, plus a right to possession of the
|
||||||
|
Corresponding Source of the work from the predecessor in interest, if
|
||||||
|
the predecessor has it or can get it with reasonable efforts.
|
||||||
|
|
||||||
|
You may not impose any further restrictions on the exercise of the
|
||||||
|
rights granted or affirmed under this License. For example, you may
|
||||||
|
not impose a license fee, royalty, or other charge for exercise of
|
||||||
|
rights granted under this License, and you may not initiate litigation
|
||||||
|
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
||||||
|
any patent claim is infringed by making, using, selling, offering for
|
||||||
|
sale, or importing the Program or any portion of it.
|
||||||
|
|
||||||
|
11. Patents.
|
||||||
|
|
||||||
|
A "contributor" is a copyright holder who authorizes use under this
|
||||||
|
License of the Program or a work on which the Program is based. The
|
||||||
|
work thus licensed is called the contributor's "contributor version".
|
||||||
|
|
||||||
|
A contributor's "essential patent claims" are all patent claims
|
||||||
|
owned or controlled by the contributor, whether already acquired or
|
||||||
|
hereafter acquired, that would be infringed by some manner, permitted
|
||||||
|
by this License, of making, using, or selling its contributor version,
|
||||||
|
but do not include claims that would be infringed only as a
|
||||||
|
consequence of further modification of the contributor version. For
|
||||||
|
purposes of this definition, "control" includes the right to grant
|
||||||
|
patent sublicenses in a manner consistent with the requirements of
|
||||||
|
this License.
|
||||||
|
|
||||||
|
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
||||||
|
patent license under the contributor's essential patent claims, to
|
||||||
|
make, use, sell, offer for sale, import and otherwise run, modify and
|
||||||
|
propagate the contents of its contributor version.
|
||||||
|
|
||||||
|
In the following three paragraphs, a "patent license" is any express
|
||||||
|
agreement or commitment, however denominated, not to enforce a patent
|
||||||
|
(such as an express permission to practice a patent or covenant not to
|
||||||
|
sue for patent infringement). To "grant" such a patent license to a
|
||||||
|
party means to make such an agreement or commitment not to enforce a
|
||||||
|
patent against the party.
|
||||||
|
|
||||||
|
If you convey a covered work, knowingly relying on a patent license,
|
||||||
|
and the Corresponding Source of the work is not available for anyone
|
||||||
|
to copy, free of charge and under the terms of this License, through a
|
||||||
|
publicly available network server or other readily accessible means,
|
||||||
|
then you must either (1) cause the Corresponding Source to be so
|
||||||
|
available, or (2) arrange to deprive yourself of the benefit of the
|
||||||
|
patent license for this particular work, or (3) arrange, in a manner
|
||||||
|
consistent with the requirements of this License, to extend the patent
|
||||||
|
license to downstream recipients. "Knowingly relying" means you have
|
||||||
|
actual knowledge that, but for the patent license, your conveying the
|
||||||
|
covered work in a country, or your recipient's use of the covered work
|
||||||
|
in a country, would infringe one or more identifiable patents in that
|
||||||
|
country that you have reason to believe are valid.
|
||||||
|
|
||||||
|
If, pursuant to or in connection with a single transaction or
|
||||||
|
arrangement, you convey, or propagate by procuring conveyance of, a
|
||||||
|
covered work, and grant a patent license to some of the parties
|
||||||
|
receiving the covered work authorizing them to use, propagate, modify
|
||||||
|
or convey a specific copy of the covered work, then the patent license
|
||||||
|
you grant is automatically extended to all recipients of the covered
|
||||||
|
work and works based on it.
|
||||||
|
|
||||||
|
A patent license is "discriminatory" if it does not include within
|
||||||
|
the scope of its coverage, prohibits the exercise of, or is
|
||||||
|
conditioned on the non-exercise of one or more of the rights that are
|
||||||
|
specifically granted under this License. You may not convey a covered
|
||||||
|
work if you are a party to an arrangement with a third party that is
|
||||||
|
in the business of distributing software, under which you make payment
|
||||||
|
to the third party based on the extent of your activity of conveying
|
||||||
|
the work, and under which the third party grants, to any of the
|
||||||
|
parties who would receive the covered work from you, a discriminatory
|
||||||
|
patent license (a) in connection with copies of the covered work
|
||||||
|
conveyed by you (or copies made from those copies), or (b) primarily
|
||||||
|
for and in connection with specific products or compilations that
|
||||||
|
contain the covered work, unless you entered into that arrangement,
|
||||||
|
or that patent license was granted, prior to 28 March 2007.
|
||||||
|
|
||||||
|
Nothing in this License shall be construed as excluding or limiting
|
||||||
|
any implied license or other defenses to infringement that may
|
||||||
|
otherwise be available to you under applicable patent law.
|
||||||
|
|
||||||
|
12. No Surrender of Others' Freedom.
|
||||||
|
|
||||||
|
If conditions are imposed on you (whether by court order, agreement or
|
||||||
|
otherwise) that contradict the conditions of this License, they do not
|
||||||
|
excuse you from the conditions of this License. If you cannot convey a
|
||||||
|
covered work so as to satisfy simultaneously your obligations under this
|
||||||
|
License and any other pertinent obligations, then as a consequence you may
|
||||||
|
not convey it at all. For example, if you agree to terms that obligate you
|
||||||
|
to collect a royalty for further conveying from those to whom you convey
|
||||||
|
the Program, the only way you could satisfy both those terms and this
|
||||||
|
License would be to refrain entirely from conveying the Program.
|
||||||
|
|
||||||
|
13. Use with the GNU Affero General Public License.
|
||||||
|
|
||||||
|
Notwithstanding any other provision of this License, you have
|
||||||
|
permission to link or combine any covered work with a work licensed
|
||||||
|
under version 3 of the GNU Affero General Public License into a single
|
||||||
|
combined work, and to convey the resulting work. The terms of this
|
||||||
|
License will continue to apply to the part which is the covered work,
|
||||||
|
but the special requirements of the GNU Affero General Public License,
|
||||||
|
section 13, concerning interaction through a network will apply to the
|
||||||
|
combination as such.
|
||||||
|
|
||||||
|
14. Revised Versions of this License.
|
||||||
|
|
||||||
|
The Free Software Foundation may publish revised and/or new versions of
|
||||||
|
the GNU General Public License from time to time. Such new versions will
|
||||||
|
be similar in spirit to the present version, but may differ in detail to
|
||||||
|
address new problems or concerns.
|
||||||
|
|
||||||
|
Each version is given a distinguishing version number. If the
|
||||||
|
Program specifies that a certain numbered version of the GNU General
|
||||||
|
Public License "or any later version" applies to it, you have the
|
||||||
|
option of following the terms and conditions either of that numbered
|
||||||
|
version or of any later version published by the Free Software
|
||||||
|
Foundation. If the Program does not specify a version number of the
|
||||||
|
GNU General Public License, you may choose any version ever published
|
||||||
|
by the Free Software Foundation.
|
||||||
|
|
||||||
|
If the Program specifies that a proxy can decide which future
|
||||||
|
versions of the GNU General Public License can be used, that proxy's
|
||||||
|
public statement of acceptance of a version permanently authorizes you
|
||||||
|
to choose that version for the Program.
|
||||||
|
|
||||||
|
Later license versions may give you additional or different
|
||||||
|
permissions. However, no additional obligations are imposed on any
|
||||||
|
author or copyright holder as a result of your choosing to follow a
|
||||||
|
later version.
|
||||||
|
|
||||||
|
15. Disclaimer of Warranty.
|
||||||
|
|
||||||
|
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
||||||
|
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
||||||
|
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
||||||
|
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
||||||
|
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||||
|
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
||||||
|
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
||||||
|
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||||
|
|
||||||
|
16. Limitation of Liability.
|
||||||
|
|
||||||
|
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||||
|
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
||||||
|
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
||||||
|
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
||||||
|
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
||||||
|
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
||||||
|
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
||||||
|
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
||||||
|
SUCH DAMAGES.
|
||||||
|
|
||||||
|
17. Interpretation of Sections 15 and 16.
|
||||||
|
|
||||||
|
If the disclaimer of warranty and limitation of liability provided
|
||||||
|
above cannot be given local legal effect according to their terms,
|
||||||
|
reviewing courts shall apply local law that most closely approximates
|
||||||
|
an absolute waiver of all civil liability in connection with the
|
||||||
|
Program, unless a warranty or assumption of liability accompanies a
|
||||||
|
copy of the Program in return for a fee.
|
||||||
|
|
||||||
|
END OF TERMS AND CONDITIONS
|
||||||
|
|
||||||
|
How to Apply These Terms to Your New Programs
|
||||||
|
|
||||||
|
If you develop a new program, and you want it to be of the greatest
|
||||||
|
possible use to the public, the best way to achieve this is to make it
|
||||||
|
free software which everyone can redistribute and change under these terms.
|
||||||
|
|
||||||
|
To do so, attach the following notices to the program. It is safest
|
||||||
|
to attach them to the start of each source file to most effectively
|
||||||
|
state the exclusion of warranty; and each file should have at least
|
||||||
|
the "copyright" line and a pointer to where the full notice is found.
|
||||||
|
|
||||||
|
<one line to give the program's name and a brief idea of what it does.>
|
||||||
|
Copyright (C) <year> <name of author>
|
||||||
|
|
||||||
|
This program is free software: you can redistribute it and/or modify
|
||||||
|
it under the terms of the GNU General Public License as published by
|
||||||
|
the Free Software Foundation, either version 3 of the License, or
|
||||||
|
(at your option) any later version.
|
||||||
|
|
||||||
|
This program is distributed in the hope that it will be useful,
|
||||||
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
GNU General Public License for more details.
|
||||||
|
|
||||||
|
You should have received a copy of the GNU General Public License
|
||||||
|
along with this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
|
|
||||||
|
Also add information on how to contact you by electronic and paper mail.
|
||||||
|
|
||||||
|
If the program does terminal interaction, make it output a short
|
||||||
|
notice like this when it starts in an interactive mode:
|
||||||
|
|
||||||
|
<program> Copyright (C) <year> <name of author>
|
||||||
|
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||||
|
This is free software, and you are welcome to redistribute it
|
||||||
|
under certain conditions; type `show c' for details.
|
||||||
|
|
||||||
|
The hypothetical commands `show w' and `show c' should show the appropriate
|
||||||
|
parts of the General Public License. Of course, your program's commands
|
||||||
|
might be different; for a GUI interface, you would use an "about box".
|
||||||
|
|
||||||
|
You should also get your employer (if you work as a programmer) or school,
|
||||||
|
if any, to sign a "copyright disclaimer" for the program, if necessary.
|
||||||
|
For more information on this, and how to apply and follow the GNU GPL, see
|
||||||
|
<https://www.gnu.org/licenses/>.
|
||||||
|
|
||||||
|
The GNU General Public License does not permit incorporating your program
|
||||||
|
into proprietary programs. If your program is a subroutine library, you
|
||||||
|
may consider it more useful to permit linking proprietary applications with
|
||||||
|
the library. If this is what you want to do, use the GNU Lesser General
|
||||||
|
Public License instead of this License. But first, please read
|
||||||
|
<https://www.gnu.org/licenses/why-not-lgpl.html>.
|
||||||
14
Makefile
Normal file
14
Makefile
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
DOCKER_TEMP_DIR=temp
|
||||||
|
|
||||||
|
all: gateway
|
||||||
|
|
||||||
|
gateway:
|
||||||
|
cargo clippy -- -D warnings && cargo build --release
|
||||||
|
|
||||||
|
gateway_docker: gateway
|
||||||
|
rm -rf $(DOCKER_TEMP_DIR)
|
||||||
|
mkdir $(DOCKER_TEMP_DIR)
|
||||||
|
cp target/release/matrix_gateway $(DOCKER_TEMP_DIR)
|
||||||
|
docker build -t pierre42100/matrix_gateway -f ./Dockerfile "$(DOCKER_TEMP_DIR)"
|
||||||
|
rm -rf $(DOCKER_TEMP_DIR)
|
||||||
|
|
||||||
28
README.md
28
README.md
@@ -1,16 +1,37 @@
|
|||||||
# Matrix Gateway
|
# Matrix Gateway
|
||||||
WIP project
|
[](https://drone.communiquons.org/pierre/MatrixGW)
|
||||||
|
|
||||||
|
Project that expose a simple API to make use of Matrix API. It acts as a Matrix client (like Element for example)
|
||||||
|
|
||||||
|
**Known limitations**:
|
||||||
|
|
||||||
|
- Supports only a limited subset of Matrix API
|
||||||
|
- Does not support E2E encryption
|
||||||
|
- Does not support spaces
|
||||||
|
|
||||||
|
Project written in Rust. Releases are published on Docker Hub.
|
||||||
|
|
||||||
|
## Docker image options
|
||||||
|
```bash
|
||||||
|
docker run --rm -it docker.io/pierre42100/matrix_gateway --help
|
||||||
|
```
|
||||||
|
|
||||||
## Setup dev environment
|
## Setup dev environment
|
||||||
```
|
```
|
||||||
mkdir -p storage/postgres storage/synapse storage/minio
|
mkdir -p storage/maspostgres storage/synapse storage/minio
|
||||||
docker compose up
|
docker compose up
|
||||||
```
|
```
|
||||||
|
|
||||||
|
To create default account, in another terminal, run the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose --profile create-accounts up -d
|
||||||
|
```
|
||||||
|
|
||||||
URLs:
|
URLs:
|
||||||
* Element: http://localhost:8080/
|
* Element: http://localhost:8080/
|
||||||
* Synapse: http://localhost:8448/
|
* Synapse: http://localhost:8448/
|
||||||
|
* Matrix Authentication Service: http://localhost:8778/
|
||||||
* OpenID configuration: http://127.0.0.1:9001/dex/.well-known/openid-configuration
|
* OpenID configuration: http://127.0.0.1:9001/dex/.well-known/openid-configuration
|
||||||
* Minio console: http://localhost:9002/
|
* Minio console: http://localhost:9002/
|
||||||
|
|
||||||
@@ -19,4 +40,5 @@ Auto-created Matrix accounts:
|
|||||||
* `admin1` : `admin1`
|
* `admin1` : `admin1`
|
||||||
* `user1` : `user1`
|
* `user1` : `user1`
|
||||||
|
|
||||||
Minio administration credentials: `minioadmin` : `minioadmin`
|
Minio administration credentials: `minioadmin` : `minioadmin`
|
||||||
|
|
||||||
|
|||||||
68
assets/ws_debug.js
Normal file
68
assets/ws_debug.js
Normal file
@@ -0,0 +1,68 @@
|
|||||||
|
let ws;
|
||||||
|
|
||||||
|
const JS_MESSAGE = "JS code";
|
||||||
|
const IN_MESSAGE = "Incoming";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Log message
|
||||||
|
*/
|
||||||
|
function log(src, txt) {
|
||||||
|
const target = document.getElementById("ws_log");
|
||||||
|
const msg = document.createElement("div");
|
||||||
|
msg.className = "message";
|
||||||
|
msg.innerHTML = `<div class='type'>${src}</div><div>${txt}</div>`
|
||||||
|
target.insertBefore(msg, target.firstChild);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Set the state of the WebSocket
|
||||||
|
*/
|
||||||
|
function setState(state) {
|
||||||
|
document.getElementById("state").innerText = state;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Initialize WebSocket connection
|
||||||
|
*/
|
||||||
|
function connect() {
|
||||||
|
disconnect();
|
||||||
|
log(JS_MESSAGE, "Initialize connection...");
|
||||||
|
ws = new WebSocket("/api/ws");
|
||||||
|
setState("Connecting...");
|
||||||
|
ws.onopen = function () {
|
||||||
|
log(JS_MESSAGE, "Connected to WebSocket !");
|
||||||
|
setState("Connected");
|
||||||
|
}
|
||||||
|
ws.onmessage = function (event) {
|
||||||
|
log(IN_MESSAGE, event.data);
|
||||||
|
}
|
||||||
|
ws.onclose = function () {
|
||||||
|
log(JS_MESSAGE, "Disconnected from WebSocket !");
|
||||||
|
setState("Disconnected");
|
||||||
|
}
|
||||||
|
ws.onerror = function (event) {
|
||||||
|
console.error("WS Error!", event);
|
||||||
|
log(JS_MESSAGE, `Error with websocket! ${event}`);
|
||||||
|
setState("Error");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Close WebSocket connection
|
||||||
|
*/
|
||||||
|
function disconnect() {
|
||||||
|
if (ws && ws.readyState === WebSocket.OPEN) {
|
||||||
|
log(JS_MESSAGE, "Close connection...");
|
||||||
|
ws.close();
|
||||||
|
}
|
||||||
|
|
||||||
|
setState("Disconnected");
|
||||||
|
ws = undefined;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Clear WS logs
|
||||||
|
*/
|
||||||
|
function clearLogs() {
|
||||||
|
document.getElementById("ws_log").innerHTML = "";
|
||||||
|
}
|
||||||
@@ -1,15 +1,48 @@
|
|||||||
services:
|
services:
|
||||||
|
mas:
|
||||||
|
image: ghcr.io/element-hq/matrix-authentication-service:main
|
||||||
|
user: "1000"
|
||||||
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
- masdb
|
||||||
|
volumes:
|
||||||
|
- ./docker/mas:/config:ro
|
||||||
|
command: server -c /config/config.yaml
|
||||||
|
ports:
|
||||||
|
- "8778:8778/tcp"
|
||||||
|
|
||||||
|
mas_create_admin1:
|
||||||
|
image: ghcr.io/element-hq/matrix-authentication-service:main
|
||||||
|
user: "1000"
|
||||||
|
restart: no
|
||||||
|
profiles: ["create-accounts"]
|
||||||
|
depends_on:
|
||||||
|
- mas
|
||||||
|
volumes:
|
||||||
|
- ./docker/mas:/config:ro
|
||||||
|
command: |
|
||||||
|
manage register-user -c /config/config.yaml -y --ignore-password-complexity
|
||||||
|
-p admin1 -e admin1@admin1.local --admin -d "Admin One" admin1
|
||||||
|
|
||||||
|
mas_create_user1:
|
||||||
|
image: ghcr.io/element-hq/matrix-authentication-service:main
|
||||||
|
user: "1000"
|
||||||
|
restart: no
|
||||||
|
profiles: ["create-accounts"]
|
||||||
|
depends_on:
|
||||||
|
- mas
|
||||||
|
volumes:
|
||||||
|
- ./docker/mas:/config:ro
|
||||||
|
command: |
|
||||||
|
manage register-user -c /config/config.yaml -y --ignore-password-complexity
|
||||||
|
-p user1 -e user1@user1.local -d "User One" user1
|
||||||
|
|
||||||
synapse:
|
synapse:
|
||||||
image: docker.io/matrixdotorg/synapse:latest
|
image: docker.io/matrixdotorg/synapse:latest
|
||||||
user: "1000"
|
user: "1000"
|
||||||
# Since synapse does not retry to connect to the database, restart upon
|
# Since synapse does not retry to connect to the database, restart upon
|
||||||
# failure
|
# failure
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
entrypoint: /bin/bash
|
|
||||||
command: >
|
|
||||||
-c "nohup bash -c 'sleep 10; /config/delayed_accounts_creation.sh' \&
|
|
||||||
./start.py"
|
|
||||||
|
|
||||||
# See the readme for a full documentation of the environment settings
|
# See the readme for a full documentation of the environment settings
|
||||||
# NOTE: You must edit homeserver.yaml to use postgres, it defaults to sqlite
|
# NOTE: You must edit homeserver.yaml to use postgres, it defaults to sqlite
|
||||||
environment:
|
environment:
|
||||||
@@ -22,25 +55,25 @@ services:
|
|||||||
# - ./files:/data
|
# - ./files:/data
|
||||||
# - /path/to/ssd:/data/uploads
|
# - /path/to/ssd:/data/uploads
|
||||||
# - /path/to/large_hdd:/data/media
|
# - /path/to/large_hdd:/data/media
|
||||||
depends_on:
|
|
||||||
- db
|
|
||||||
# In order to expose Synapse, remove one of the following, you might for
|
# In order to expose Synapse, remove one of the following, you might for
|
||||||
# instance expose the TLS port directly:
|
# instance expose the TLS port directly:
|
||||||
ports:
|
ports:
|
||||||
- 8448:8448/tcp
|
- "8448:8448/tcp"
|
||||||
|
|
||||||
db:
|
masdb:
|
||||||
image: docker.io/postgres:12-alpine
|
image: docker.io/postgres:18-alpine
|
||||||
user: "1000"
|
user: "1000"
|
||||||
environment:
|
environment:
|
||||||
- POSTGRES_USER=synapse
|
- POSTGRES_DB=masdb
|
||||||
|
- POSTGRES_USER=masdb
|
||||||
- POSTGRES_PASSWORD=changeme
|
- POSTGRES_PASSWORD=changeme
|
||||||
# ensure the database gets created correctly
|
# ensure the database gets created correctly
|
||||||
# https://element-hq.github.io/synapse/latest/postgres.html#set-up-database
|
# https://element-hq.github.io/synapse/latest/postgres.html#set-up-database
|
||||||
- POSTGRES_INITDB_ARGS=--encoding=UTF-8 --lc-collate=C --lc-ctype=C
|
- POSTGRES_INITDB_ARGS=--encoding=UTF-8 --lc-collate=C --lc-ctype=C
|
||||||
|
- PGDATA=/data
|
||||||
volumes:
|
volumes:
|
||||||
# You may store the database tables in a local folder..
|
# You may store the database tables in a local folder..
|
||||||
- ./storage/postgres:/var/lib/postgresql/data
|
- ./storage/maspostgres:/data
|
||||||
# .. or store them on some high performance storage for better results
|
# .. or store them on some high performance storage for better results
|
||||||
# - /path/to/ssd/storage:/var/lib/postgresql/data
|
# - /path/to/ssd/storage:/var/lib/postgresql/data
|
||||||
|
|
||||||
|
|||||||
113
docker/mas/config.yaml
Normal file
113
docker/mas/config.yaml
Normal file
@@ -0,0 +1,113 @@
|
|||||||
|
http:
|
||||||
|
listeners:
|
||||||
|
- name: web
|
||||||
|
resources:
|
||||||
|
- name: discovery
|
||||||
|
- name: human
|
||||||
|
- name: oauth
|
||||||
|
- name: compat
|
||||||
|
- name: graphql
|
||||||
|
- name: assets
|
||||||
|
binds:
|
||||||
|
- address: '[::]:8778'
|
||||||
|
proxy_protocol: false
|
||||||
|
- name: internal
|
||||||
|
resources:
|
||||||
|
- name: health
|
||||||
|
binds:
|
||||||
|
- host: localhost
|
||||||
|
port: 8081
|
||||||
|
proxy_protocol: false
|
||||||
|
trusted_proxies:
|
||||||
|
- 192.168.0.0/16
|
||||||
|
- 172.16.0.0/12
|
||||||
|
- 10.0.0.0/10
|
||||||
|
- 127.0.0.1/8
|
||||||
|
- fd00::/8
|
||||||
|
- ::1/128
|
||||||
|
public_base: http://localhost:8778/
|
||||||
|
issuer: http://localhost:8778/
|
||||||
|
database:
|
||||||
|
uri: postgresql://masdb:changeme@masdb/masdb
|
||||||
|
max_connections: 10
|
||||||
|
min_connections: 0
|
||||||
|
connect_timeout: 30
|
||||||
|
idle_timeout: 600
|
||||||
|
max_lifetime: 1800
|
||||||
|
email:
|
||||||
|
from: '"Authentication Service" <root@localhost>'
|
||||||
|
reply_to: '"Authentication Service" <root@localhost>'
|
||||||
|
transport: blackhole
|
||||||
|
secrets:
|
||||||
|
encryption: 12de9ad7bc2bacfa2ab9b1e3f7f1b3feb802195c8ebe66a8293cdb27f00be471
|
||||||
|
keys:
|
||||||
|
- kid: Bj2PICQ7mf
|
||||||
|
key: |
|
||||||
|
-----BEGIN RSA PRIVATE KEY-----
|
||||||
|
MIIEogIBAAKCAQEAsCYCrrCJA7IuGbTYzP5yZN74QszbzudBUCX6MyN/+36HO2r6
|
||||||
|
xL8x1PRJ+Klx9Y90J9pWuo+cIuEmFLqO+Yfblo9fSQgZVvkWAFpO6Xh8J4z9qg49
|
||||||
|
M8xm0Ct8EnRDZDCEOBnwoDaAB9RTbpJGa1RPVCiamfi+xU+j47Zl4Er5jvLm81O7
|
||||||
|
DSlH9eK8Eih8AxuKTkAbKE1zyXquImE26Mj2dmMRfjDrWV/I8oqE3WFViAKR12Av
|
||||||
|
zw6TUyduiz8nK9pONCF3NIcQvBdHntBz1HlDXv6i0fRvlGIhjNL5LBgo6XQ3rNM1
|
||||||
|
bW2KYOw/iFP0YbfD4/xRjkBPvK2coQ8aRzK2VwIDAQABAoH/G4XU5Xav8ePlUB7x
|
||||||
|
wRYAycINCGL59Vos2lkUvujNFn6uopoUlKlLH/sLk87l/3hqrc9vvbayrsB/Mr3z
|
||||||
|
mQmhReUg/khFrVE+Hs/9hH1O6N8ew3N2HKHTbrNcr4V7AiySfDGRZ3ccihyi7KPu
|
||||||
|
XNbPjlbJ0UUMicfn06ysPl94nt0So0UAmXg+c7sDDqyzh3cY8emedYZ5FCljo/jA
|
||||||
|
F8k40rs7CywLJYMJB9O1vtomgt1xkDRO4F8UrZrriMIcYn0iFKe7i4AH8D6nkgNu
|
||||||
|
/v9Z43Leu8yRKrUvbpH3NaX8DlUSFWAXKpwUWr4sAQgWcLkVgjAXG1v9jCE97qW2
|
||||||
|
f0nBAoGBAOaKrnY5rWeZ74dERnPhSCsYiqRMneQAh7eJR+Er+xu1yF/bxwkhq2tK
|
||||||
|
/txheTK448DqhQRtr095t/v7TMZcPl3bSmybT1CQg/wiMJsgDMZqlC9tofvcq6uz
|
||||||
|
xP8vxMFHd0YSMSP693dkny4MzNY6LuoVWDLT+HxKPJyzGs1alruzAoGBAMOZp5J2
|
||||||
|
3ODcHQlcsGBtj1yVpQ4UXMvrSZF2ygiGK9bagL/f1iAtwACVOh5rgmbiOLSVgmR2
|
||||||
|
n4nupTgSAXMYkjmAmDyEh0PDaRl4WWvYEKp8GMvTPVPvjc6N0dT+y8Mf9bu+LcEt
|
||||||
|
+uZqPOZNbO5Vi+UgGeM9zZpxq/K7dpJmM/jNAoGBALsYHRGxKTsEwFEkZZCxaWIg
|
||||||
|
HpPL4e8hRwL6FC13BeitFBpHQDX27yi5yi+Lo1I4ngz3xk+bvERhYaDLhrkML0j4
|
||||||
|
KGQPfsTBI3vBO3UJA5Ua9XuwG19M7L0BvYPjfmfk2bUyGlM63w4zyMMUfD/3JA+w
|
||||||
|
ls1ZHTWxAZOh/sRdGirlAoGAX16B1+XgmDp6ZeAtlzaUGd5U1eKTxFF6U1SJ+VIB
|
||||||
|
+gYblHI84v+riB06cy6ULDnM0C+9neJAs24KXKZa0pV+Zk8O6yLrGN0kV2jYoL5+
|
||||||
|
kcFkDa13T3+TssxvLNz22LKyi9GUWYZjuQi/nMLPg/1t8k+Oj7/Iia822WkRzRvL
|
||||||
|
51kCgYEAwrN5Us8LR+fThm3C0vhvwv2wap6ccw0qq5+FTN+igAZAmmvKKvhow2Vi
|
||||||
|
LnPKBkc7QvxvQSNoXkdUo4qs3zOQ7DGvJLqSG9pwxFW5X1+78pNEm5OWe8AlT1uZ
|
||||||
|
Jz8Z1/Ae7fr/fFaucW9LkWjcuoPwPLiZ3b7ZQ6phs8qzoL+FpBI=
|
||||||
|
-----END RSA PRIVATE KEY-----
|
||||||
|
- kid: HcRvLHat12
|
||||||
|
key: |
|
||||||
|
-----BEGIN EC PRIVATE KEY-----
|
||||||
|
MHcCAQEEIOCCFSnkfz1ksln6kus8enQstBTu0q62IGJVzuX0WiXPoAoGCCqGSM49
|
||||||
|
AwEHoUQDQgAEVWPLbvSdxquLAjU3zJLcCWdaxr6QK1tPVbV1IS+87QUMv/zKiCMa
|
||||||
|
fNpwgBXwU7dF0gY507R2yY9pcdTmRtnRug==
|
||||||
|
-----END EC PRIVATE KEY-----
|
||||||
|
- kid: YjMITk5VSn
|
||||||
|
key: |
|
||||||
|
-----BEGIN EC PRIVATE KEY-----
|
||||||
|
MIGkAgEBBDCoPSjaN7qqnPz+vdzHeIy8RZCCtFOqLTkvylM1gz6xOGaVsS63VJw9
|
||||||
|
Td9BtpolZ0egBwYFK4EEACKhZANiAAT8tH88HYBHNiQTSqZzlxElSuSDC0+Xn0O9
|
||||||
|
ukj0xTTVBp8rUM9lCJQAlB8PjS2XK/n0YvYdzysQb3AYqszJa45/rOGvSar30YNE
|
||||||
|
gwpJvu36xNIKZT+nHalNwg069FdjNBc=
|
||||||
|
-----END EC PRIVATE KEY-----
|
||||||
|
- kid: NvFzzeMRU3
|
||||||
|
key: |
|
||||||
|
-----BEGIN EC PRIVATE KEY-----
|
||||||
|
MHQCAQEEILJEmFPDGFZoBVBQf1P6h4YfasYsFiu8a6FrFxiJvKXPoAcGBSuBBAAK
|
||||||
|
oUQDQgAE4NY5H3+D8r9GNOhrpbUn2dvLZIzi4A+SiwfqvtvPEmZkW+KDbd2tzKmx
|
||||||
|
maydZBn52QWedVY65snGAEoh9mV1TQ==
|
||||||
|
-----END EC PRIVATE KEY-----
|
||||||
|
passwords:
|
||||||
|
enabled: true
|
||||||
|
schemes:
|
||||||
|
- version: 1
|
||||||
|
algorithm: argon2id
|
||||||
|
minimum_complexity: 0
|
||||||
|
account:
|
||||||
|
password_registration_enabled: true
|
||||||
|
password_registration_email_required: false
|
||||||
|
matrix:
|
||||||
|
kind: synapse
|
||||||
|
homeserver: localhost
|
||||||
|
secret: IhKoLn6jWf1qRRZWvqgaKuIdwD6H0Mvx
|
||||||
|
endpoint: http://synapse:8448/
|
||||||
|
|
||||||
|
policy:
|
||||||
|
data:
|
||||||
|
client_registration:
|
||||||
|
allow_insecure_uris: true
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
register_new_matrix_user -a --user admin1 --password admin1 --config /config/homeserver.yaml;
|
|
||||||
register_new_matrix_user --no-admin --user user1 --password user1 --config /config/homeserver.yaml;
|
|
||||||
@@ -33,3 +33,9 @@ signing_key_path: "/config/localhost.signing.key"
|
|||||||
trusted_key_servers:
|
trusted_key_servers:
|
||||||
- server_name: "matrix.org"
|
- server_name: "matrix.org"
|
||||||
# vim:ft=yaml
|
# vim:ft=yaml
|
||||||
|
matrix_authentication_service:
|
||||||
|
enabled: true
|
||||||
|
endpoint: http://mas:8778/
|
||||||
|
secret: "IhKoLn6jWf1qRRZWvqgaKuIdwD6H0Mvx"
|
||||||
|
# Alternatively, using a file:
|
||||||
|
#secret_file: /path/to/secret.txt
|
||||||
|
|||||||
86
examples/api_curl.rs
Normal file
86
examples/api_curl.rs
Normal file
@@ -0,0 +1,86 @@
|
|||||||
|
use clap::Parser;
|
||||||
|
use jwt_simple::algorithms::HS256Key;
|
||||||
|
use jwt_simple::prelude::{Clock, Duration, JWTClaims, MACLike};
|
||||||
|
use matrix_gateway::extractors::client_auth::TokenClaims;
|
||||||
|
use matrix_gateway::utils::base_utils::rand_str;
|
||||||
|
use std::ops::Add;
|
||||||
|
use std::os::unix::prelude::CommandExt;
|
||||||
|
use std::process::Command;
|
||||||
|
|
||||||
|
/// cURL wrapper to query MatrixGW
|
||||||
|
#[derive(Parser, Debug)]
|
||||||
|
#[command(version, about, long_about = None)]
|
||||||
|
struct Args {
|
||||||
|
/// URL of Matrix GW
|
||||||
|
#[arg(short('U'), long, env, default_value = "http://localhost:8000")]
|
||||||
|
matrix_gw_url: String,
|
||||||
|
|
||||||
|
/// Token ID
|
||||||
|
#[arg(short('i'), long, env)]
|
||||||
|
token_id: String,
|
||||||
|
|
||||||
|
/// User ID
|
||||||
|
#[arg(short('u'), long, env)]
|
||||||
|
user_id: String,
|
||||||
|
|
||||||
|
/// Token secret
|
||||||
|
#[arg(short('t'), long, env)]
|
||||||
|
token_secret: String,
|
||||||
|
|
||||||
|
/// Request verb
|
||||||
|
#[arg(short('X'), long, default_value = "GET")]
|
||||||
|
method: String,
|
||||||
|
|
||||||
|
/// Payload SHA256 digest
|
||||||
|
#[arg(short('D'), long)]
|
||||||
|
payload_digest: Option<String>,
|
||||||
|
|
||||||
|
/// Request URI
|
||||||
|
uri: String,
|
||||||
|
|
||||||
|
/// Command line arguments to pass to cURL
|
||||||
|
#[clap(trailing_var_arg = true, allow_hyphen_values = true)]
|
||||||
|
run: Vec<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
fn main() {
|
||||||
|
let args: Args = Args::parse();
|
||||||
|
|
||||||
|
let full_url = format!("{}{}", args.matrix_gw_url, args.uri);
|
||||||
|
log::debug!("Full URL: {full_url}");
|
||||||
|
|
||||||
|
let key = HS256Key::from_bytes(args.token_secret.as_bytes());
|
||||||
|
|
||||||
|
let claims = JWTClaims::<TokenClaims> {
|
||||||
|
issued_at: Some(Clock::now_since_epoch()),
|
||||||
|
expires_at: Some(Clock::now_since_epoch().add(Duration::from_mins(15))),
|
||||||
|
invalid_before: None,
|
||||||
|
issuer: None,
|
||||||
|
subject: None,
|
||||||
|
audiences: None,
|
||||||
|
jwt_id: None,
|
||||||
|
nonce: Some(rand_str(10)),
|
||||||
|
custom: TokenClaims {
|
||||||
|
method: args.method.to_string(),
|
||||||
|
uri: args.uri,
|
||||||
|
payload_sha256: args.payload_digest.clone(),
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
let jwt = key
|
||||||
|
.with_key_id(&format!(
|
||||||
|
"{}#{}",
|
||||||
|
urlencoding::encode(&args.user_id),
|
||||||
|
urlencoding::encode(&args.token_id)
|
||||||
|
))
|
||||||
|
.authenticate(claims)
|
||||||
|
.expect("Failed to sign JWT!");
|
||||||
|
|
||||||
|
let _ = Command::new("curl")
|
||||||
|
.args(["-X", &args.method])
|
||||||
|
.args(["-H", &format!("x-client-auth: {jwt}")])
|
||||||
|
.args(args.run)
|
||||||
|
.arg(full_url)
|
||||||
|
.exec();
|
||||||
|
panic!("Failed to run curl!")
|
||||||
|
}
|
||||||
3
renovate.json
Normal file
3
renovate.json
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
{
|
||||||
|
"extends": ["local>renovate/presets"]
|
||||||
|
}
|
||||||
@@ -2,7 +2,7 @@ use clap::Parser;
|
|||||||
use s3::creds::Credentials;
|
use s3::creds::Credentials;
|
||||||
use s3::{Bucket, Region};
|
use s3::{Bucket, Region};
|
||||||
|
|
||||||
/// GeneIT backend API
|
/// Matrix gateway backend API
|
||||||
#[derive(Parser, Debug, Clone)]
|
#[derive(Parser, Debug, Clone)]
|
||||||
#[clap(author, version, about, long_about = None)]
|
#[clap(author, version, about, long_about = None)]
|
||||||
pub struct AppConfig {
|
pub struct AppConfig {
|
||||||
@@ -18,9 +18,13 @@ pub struct AppConfig {
|
|||||||
#[clap(short, long, env)]
|
#[clap(short, long, env)]
|
||||||
pub proxy_ip: Option<String>,
|
pub proxy_ip: Option<String>,
|
||||||
|
|
||||||
|
/// Secret key, used to sign some resources. Must be randomly generated
|
||||||
|
#[clap(short = 'S', long, env, default_value = "")]
|
||||||
|
secret: String,
|
||||||
|
|
||||||
/// Matrix API origin
|
/// Matrix API origin
|
||||||
#[clap(short, long, env, default_value = "http://127.0.0.1:8448")]
|
#[clap(short, long, env, default_value = "http://127.0.0.1:8448")]
|
||||||
pub matrix_api: String,
|
pub matrix_homeserver: String,
|
||||||
|
|
||||||
/// Redis connection hostname
|
/// Redis connection hostname
|
||||||
#[clap(long, env, default_value = "localhost")]
|
#[clap(long, env, default_value = "localhost")]
|
||||||
@@ -99,6 +103,21 @@ impl AppConfig {
|
|||||||
&ARGS
|
&ARGS
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Get app secret
|
||||||
|
pub fn secret(&self) -> &str {
|
||||||
|
let mut secret = self.secret.as_str();
|
||||||
|
|
||||||
|
if cfg!(debug_assertions) && secret.is_empty() {
|
||||||
|
secret = "DEBUGKEYDEBUGKEYDEBUGKEYDEBUGKEYDEBUGKEYDEBUGKEYDEBUGKEYDEBUGKEY";
|
||||||
|
}
|
||||||
|
|
||||||
|
if secret.is_empty() {
|
||||||
|
panic!("SECRET is undefined or too short (min 64 chars)!")
|
||||||
|
}
|
||||||
|
|
||||||
|
secret
|
||||||
|
}
|
||||||
|
|
||||||
/// Get Redis connection configuration
|
/// Get Redis connection configuration
|
||||||
pub fn redis_connection_string(&self) -> String {
|
pub fn redis_connection_string(&self) -> String {
|
||||||
format!(
|
format!(
|
||||||
|
|||||||
46
src/broadcast_messages.rs
Normal file
46
src/broadcast_messages.rs
Normal file
@@ -0,0 +1,46 @@
|
|||||||
|
use crate::sync_client::SyncClientID;
|
||||||
|
use crate::user::{APIClientID, UserID};
|
||||||
|
use ruma::api::client::sync::sync_events::v3::{GlobalAccountData, Presence, Rooms, ToDevice};
|
||||||
|
use ruma::api::client::sync::sync_events::DeviceLists;
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, serde::Deserialize, serde::Serialize)]
|
||||||
|
pub struct SyncEvent {
|
||||||
|
/// Updates to rooms.
|
||||||
|
#[serde(default, skip_serializing_if = "Rooms::is_empty")]
|
||||||
|
pub rooms: Rooms,
|
||||||
|
|
||||||
|
/// Updates to the presence status of other users.
|
||||||
|
#[serde(default, skip_serializing_if = "Presence::is_empty")]
|
||||||
|
pub presence: Presence,
|
||||||
|
|
||||||
|
/// The global private data created by this user.
|
||||||
|
#[serde(default, skip_serializing_if = "GlobalAccountData::is_empty")]
|
||||||
|
pub account_data: GlobalAccountData,
|
||||||
|
|
||||||
|
/// Messages sent directly between devices.
|
||||||
|
#[serde(default, skip_serializing_if = "ToDevice::is_empty")]
|
||||||
|
pub to_device: ToDevice,
|
||||||
|
|
||||||
|
/// Information on E2E device updates.
|
||||||
|
///
|
||||||
|
/// Only present on an incremental sync.
|
||||||
|
#[serde(default, skip_serializing_if = "DeviceLists::is_empty")]
|
||||||
|
pub device_lists: DeviceLists,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Broadcast messages
|
||||||
|
#[derive(Debug, Clone)]
|
||||||
|
pub enum BroadcastMessage {
|
||||||
|
/// Request to close the session of a specific client
|
||||||
|
CloseClientSession(APIClientID),
|
||||||
|
/// Close all the sessions of a given user
|
||||||
|
CloseAllUserSessions(UserID),
|
||||||
|
/// Stop sync client for a given user
|
||||||
|
StopSyncTaskForUser(UserID),
|
||||||
|
/// Start sync client for a given user (if not already running)
|
||||||
|
StartSyncTaskForUser(UserID),
|
||||||
|
/// Stop a client with a given client ID
|
||||||
|
StopSyncClient(SyncClientID),
|
||||||
|
/// Propagate a new sync event
|
||||||
|
SyncEvent(UserID, Box<SyncEvent>),
|
||||||
|
}
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
/// Session key for OpenID login state
|
/// Session key for OpenID login state
|
||||||
pub const STATE_KEY: &str = "oidc-state";
|
pub const STATE_KEY: &str = "oidc-state";
|
||||||
|
|
||||||
@@ -6,3 +8,11 @@ pub const USER_SESSION_KEY: &str = "user";
|
|||||||
|
|
||||||
/// Token length
|
/// Token length
|
||||||
pub const TOKEN_LEN: usize = 20;
|
pub const TOKEN_LEN: usize = 20;
|
||||||
|
|
||||||
|
/// How often heartbeat pings are sent.
|
||||||
|
///
|
||||||
|
/// Should be half (or less) of the acceptable client timeout.
|
||||||
|
pub const WS_HEARTBEAT_INTERVAL: Duration = Duration::from_secs(5);
|
||||||
|
|
||||||
|
/// How long before lack of client response causes a timeout.
|
||||||
|
pub const WS_CLIENT_TIMEOUT: Duration = Duration::from_secs(10);
|
||||||
|
|||||||
@@ -1,21 +1,58 @@
|
|||||||
use crate::user::{APIClient, APIClientID, UserConfig, UserID};
|
use crate::constants::USER_SESSION_KEY;
|
||||||
|
use crate::server::HttpFailure;
|
||||||
|
use crate::user::{APIClient, APIClientID, RumaClient, User, UserConfig, UserID};
|
||||||
|
use crate::utils::base_utils::curr_time;
|
||||||
|
use actix_remote_ip::RemoteIP;
|
||||||
|
use actix_session::Session;
|
||||||
use actix_web::dev::Payload;
|
use actix_web::dev::Payload;
|
||||||
use actix_web::{FromRequest, HttpRequest};
|
use actix_web::{FromRequest, HttpRequest};
|
||||||
|
use bytes::Bytes;
|
||||||
use jwt_simple::common::VerificationOptions;
|
use jwt_simple::common::VerificationOptions;
|
||||||
use jwt_simple::prelude::{HS256Key, MACLike};
|
use jwt_simple::prelude::{Duration, HS256Key, MACLike};
|
||||||
|
use ruma::api::{IncomingResponse, OutgoingRequest};
|
||||||
|
use sha2::{Digest, Sha256};
|
||||||
|
use std::net::IpAddr;
|
||||||
use std::str::FromStr;
|
use std::str::FromStr;
|
||||||
|
|
||||||
pub struct APIClientAuth {
|
pub struct APIClientAuth {
|
||||||
pub user: UserConfig,
|
pub user: UserConfig,
|
||||||
client: APIClient,
|
pub client: Option<APIClient>,
|
||||||
payload: Option<Vec<u8>>,
|
pub payload: Option<Vec<u8>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, serde::Serialize, serde::Deserialize)]
|
#[derive(Debug, serde::Serialize, serde::Deserialize)]
|
||||||
struct JWTClaims {}
|
pub struct TokenClaims {
|
||||||
|
#[serde(rename = "met")]
|
||||||
|
pub method: String,
|
||||||
|
pub uri: String,
|
||||||
|
#[serde(rename = "pay", skip_serializing_if = "Option::is_none")]
|
||||||
|
pub payload_sha256: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
impl APIClientAuth {
|
impl APIClientAuth {
|
||||||
async fn extract_auth(req: &HttpRequest) -> Result<Self, actix_web::Error> {
|
async fn extract_auth(
|
||||||
|
req: &HttpRequest,
|
||||||
|
remote_ip: IpAddr,
|
||||||
|
payload_bytes: Option<Bytes>,
|
||||||
|
) -> Result<Self, actix_web::Error> {
|
||||||
|
// Check if user is authenticated using Web UI
|
||||||
|
let session = Session::from_request(req, &mut Payload::None).await?;
|
||||||
|
|
||||||
|
if let Some(user) = session.get::<User>(USER_SESSION_KEY)? {
|
||||||
|
match UserConfig::load(&user.id, false).await {
|
||||||
|
Ok(config) => {
|
||||||
|
return Ok(Self {
|
||||||
|
user: config,
|
||||||
|
client: None,
|
||||||
|
payload: payload_bytes.map(|bytes| bytes.to_vec()),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to fetch user information for authentication using cookie token! {e}");
|
||||||
|
}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
let Some(token) = req.headers().get("x-client-auth") else {
|
let Some(token) = req.headers().get("x-client-auth") else {
|
||||||
return Err(actix_web::error::ErrorBadRequest(
|
return Err(actix_web::error::ErrorBadRequest(
|
||||||
"Missing authentication header!",
|
"Missing authentication header!",
|
||||||
@@ -78,28 +115,110 @@ impl APIClientAuth {
|
|||||||
|
|
||||||
// Decode JWT
|
// Decode JWT
|
||||||
let key = HS256Key::from_bytes(client.secret.as_bytes());
|
let key = HS256Key::from_bytes(client.secret.as_bytes());
|
||||||
let claims =
|
let verif = VerificationOptions {
|
||||||
match key.verify_token::<JWTClaims>(jwt_token, Some(VerificationOptions::default())) {
|
max_validity: Some(Duration::from_mins(15)),
|
||||||
Ok(t) => t,
|
..Default::default()
|
||||||
Err(e) => {
|
};
|
||||||
log::error!("JWT validation failed! {e}");
|
|
||||||
return Err(actix_web::error::ErrorForbidden("JWT validation failed!"));
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
// TODO : check timing
|
let claims = match key.verify_token::<TokenClaims>(jwt_token, Some(verif)) {
|
||||||
// TODO : check URI & verb
|
Ok(t) => t,
|
||||||
// TODO : handle payload
|
Err(e) => {
|
||||||
// TODO : check read only access
|
log::error!("JWT validation failed! {e}");
|
||||||
// TODO : update last use (if required)
|
return Err(actix_web::error::ErrorForbidden("JWT validation failed!"));
|
||||||
// TODO : check for IP restriction
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// Check for nonce
|
||||||
|
if claims.nonce.is_none() {
|
||||||
|
return Err(actix_web::error::ErrorBadRequest(
|
||||||
|
"A nonce is required in JWT!",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check IP restriction
|
||||||
|
if let Some(net) = client.network {
|
||||||
|
if !net.contains(&remote_ip) {
|
||||||
|
log::error!(
|
||||||
|
"Trying to use client {} from unauthorized IP address: {remote_ip}",
|
||||||
|
client.id.0
|
||||||
|
);
|
||||||
|
return Err(actix_web::error::ErrorForbidden(
|
||||||
|
"This client cannot be used from this IP address!",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check URI & verb
|
||||||
|
if claims.custom.uri != req.uri().to_string() {
|
||||||
|
return Err(actix_web::error::ErrorBadRequest("URI mismatch!"));
|
||||||
|
}
|
||||||
|
if claims.custom.method != req.method().to_string() {
|
||||||
|
return Err(actix_web::error::ErrorBadRequest("Method mismatch!"));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check for write access
|
||||||
|
if client.readonly_client && !req.method().is_safe() {
|
||||||
|
return Err(actix_web::error::ErrorBadRequest(
|
||||||
|
"Read only client cannot perform write operations!",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
let payload = match (payload_bytes, claims.custom.payload_sha256) {
|
||||||
|
(None, _) => None,
|
||||||
|
(Some(_), None) => {
|
||||||
|
return Err(actix_web::error::ErrorBadRequest(
|
||||||
|
"A payload digest must be included in the JWT when the request has a payload!",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
(Some(payload), Some(provided_digest)) => {
|
||||||
|
let computed_digest = base16ct::lower::encode_string(&Sha256::digest(&payload));
|
||||||
|
if computed_digest != provided_digest {
|
||||||
|
log::error!(
|
||||||
|
"Expected digest {provided_digest} but computed {computed_digest}!"
|
||||||
|
);
|
||||||
|
return Err(actix_web::error::ErrorBadRequest(
|
||||||
|
"Computed digest is different from the one provided in the JWT!",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
Some(payload.to_vec())
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// Update last use (if needed)
|
||||||
|
if client.need_update_last_used() {
|
||||||
|
let mut user_up = user.clone();
|
||||||
|
match user_up.find_client_by_id_mut(&client.id) {
|
||||||
|
None => log::error!("Client ID disappeared!!!"),
|
||||||
|
Some(u) => u.used = curr_time().unwrap(),
|
||||||
|
}
|
||||||
|
if let Err(e) = user_up.save().await {
|
||||||
|
log::error!("Failed to update last token usage! {e}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
Ok(Self {
|
Ok(Self {
|
||||||
client: client.clone(),
|
client: Some(client.clone()),
|
||||||
payload: None,
|
payload,
|
||||||
user,
|
user,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Get an instance of Matrix client
|
||||||
|
pub async fn client(&self) -> anyhow::Result<RumaClient> {
|
||||||
|
self.user.matrix_client().await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Send request to matrix server
|
||||||
|
pub async fn send_request<R: OutgoingRequest<IncomingResponse = E>, E: IncomingResponse>(
|
||||||
|
&self,
|
||||||
|
request: R,
|
||||||
|
) -> anyhow::Result<E, HttpFailure> {
|
||||||
|
match self.client().await?.send_request(request).await {
|
||||||
|
Ok(e) => Ok(e),
|
||||||
|
Err(e) => Err(HttpFailure::MatrixClientError(e.to_string())),
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl FromRequest for APIClientAuth {
|
impl FromRequest for APIClientAuth {
|
||||||
@@ -108,6 +227,30 @@ impl FromRequest for APIClientAuth {
|
|||||||
|
|
||||||
fn from_request(req: &HttpRequest, payload: &mut Payload) -> Self::Future {
|
fn from_request(req: &HttpRequest, payload: &mut Payload) -> Self::Future {
|
||||||
let req = req.clone();
|
let req = req.clone();
|
||||||
Box::pin(async move { Self::extract_auth(&req).await })
|
|
||||||
|
let remote_ip = match RemoteIP::from_request(&req, &mut Payload::None).into_inner() {
|
||||||
|
Ok(ip) => ip,
|
||||||
|
Err(e) => return Box::pin(async { Err(e) }),
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut payload = payload.take();
|
||||||
|
|
||||||
|
Box::pin(async move {
|
||||||
|
let payload_bytes = match Bytes::from_request(&req, &mut payload).await {
|
||||||
|
Ok(b) => {
|
||||||
|
if b.is_empty() {
|
||||||
|
None
|
||||||
|
} else {
|
||||||
|
Some(b)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to extract request payload! {e}");
|
||||||
|
None
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
Self::extract_auth(&req, remote_ip.0, payload_bytes).await
|
||||||
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
pub mod app_config;
|
pub mod app_config;
|
||||||
|
pub mod broadcast_messages;
|
||||||
pub mod constants;
|
pub mod constants;
|
||||||
pub mod extractors;
|
pub mod extractors;
|
||||||
pub mod server;
|
pub mod server;
|
||||||
|
pub mod sync_client;
|
||||||
pub mod user;
|
pub mod user;
|
||||||
pub mod utils;
|
pub mod utils;
|
||||||
|
|||||||
38
src/main.rs
38
src/main.rs
@@ -1,12 +1,15 @@
|
|||||||
|
use actix_remote_ip::RemoteIPConfig;
|
||||||
use actix_session::config::SessionLifecycle;
|
use actix_session::config::SessionLifecycle;
|
||||||
use actix_session::{storage::RedisSessionStore, SessionMiddleware};
|
use actix_session::{storage::RedisSessionStore, SessionMiddleware};
|
||||||
use actix_web::cookie::Key;
|
use actix_web::cookie::Key;
|
||||||
use actix_web::{web, App, HttpServer};
|
use actix_web::{web, App, HttpServer};
|
||||||
use matrix_gateway::app_config::AppConfig;
|
use matrix_gateway::app_config::AppConfig;
|
||||||
|
use matrix_gateway::broadcast_messages::BroadcastMessage;
|
||||||
use matrix_gateway::server::{api, web_ui};
|
use matrix_gateway::server::{api, web_ui};
|
||||||
|
use matrix_gateway::sync_client;
|
||||||
use matrix_gateway::user::UserConfig;
|
use matrix_gateway::user::UserConfig;
|
||||||
|
|
||||||
#[actix_web::main]
|
#[tokio::main]
|
||||||
async fn main() -> std::io::Result<()> {
|
async fn main() -> std::io::Result<()> {
|
||||||
env_logger::init_from_env(env_logger::Env::new().default_filter_or("info"));
|
env_logger::init_from_env(env_logger::Env::new().default_filter_or("info"));
|
||||||
|
|
||||||
@@ -14,13 +17,17 @@ async fn main() -> std::io::Result<()> {
|
|||||||
.await
|
.await
|
||||||
.expect("Failed to create bucket!");
|
.expect("Failed to create bucket!");
|
||||||
|
|
||||||
// FIXME : not scalable
|
let secret_key = Key::from(AppConfig::get().secret().as_bytes());
|
||||||
let secret_key = Key::generate();
|
|
||||||
|
|
||||||
let redis_store = RedisSessionStore::new(AppConfig::get().redis_connection_string())
|
let redis_store = RedisSessionStore::new(AppConfig::get().redis_connection_string())
|
||||||
.await
|
.await
|
||||||
.expect("Failed to connect to Redis!");
|
.expect("Failed to connect to Redis!");
|
||||||
|
|
||||||
|
let (ws_tx, _) = tokio::sync::broadcast::channel::<BroadcastMessage>(16);
|
||||||
|
|
||||||
|
// Launch sync manager
|
||||||
|
tokio::spawn(sync_client::sync_client_manager(ws_tx.clone()));
|
||||||
|
|
||||||
log::info!(
|
log::info!(
|
||||||
"Starting to listen on {} for {}",
|
"Starting to listen on {} for {}",
|
||||||
AppConfig::get().listen_address,
|
AppConfig::get().listen_address,
|
||||||
@@ -35,15 +42,38 @@ async fn main() -> std::io::Result<()> {
|
|||||||
.session_lifecycle(SessionLifecycle::BrowserSession(Default::default()))
|
.session_lifecycle(SessionLifecycle::BrowserSession(Default::default()))
|
||||||
.build(),
|
.build(),
|
||||||
)
|
)
|
||||||
|
.app_data(web::Data::new(RemoteIPConfig {
|
||||||
|
proxy: AppConfig::get().proxy_ip.clone(),
|
||||||
|
}))
|
||||||
|
.app_data(web::Data::new(ws_tx.clone()))
|
||||||
// Web configuration routes
|
// Web configuration routes
|
||||||
.route("/assets/{tail:.*}", web::get().to(web_ui::static_file))
|
.route("/assets/{tail:.*}", web::get().to(web_ui::static_file))
|
||||||
.route("/", web::get().to(web_ui::home))
|
.route("/", web::get().to(web_ui::home))
|
||||||
.route("/", web::post().to(web_ui::home))
|
.route("/", web::post().to(web_ui::home))
|
||||||
.route("/oidc_cb", web::get().to(web_ui::oidc_cb))
|
.route("/oidc_cb", web::get().to(web_ui::oidc_cb))
|
||||||
.route("/sign_out", web::get().to(web_ui::sign_out))
|
.route("/sign_out", web::get().to(web_ui::sign_out))
|
||||||
|
.route("/ws_debug", web::get().to(web_ui::ws_debug))
|
||||||
// API routes
|
// API routes
|
||||||
.route("/api/", web::get().to(api::api_home))
|
.route("/api", web::get().to(api::api_home))
|
||||||
|
.route("/api", web::post().to(api::api_home))
|
||||||
|
.route("/api/account/whoami", web::get().to(api::account::who_am_i))
|
||||||
|
.route("/api/room/joined", web::get().to(api::room::joined_rooms))
|
||||||
|
.route("/api/room/{room_id}", web::get().to(api::room::info))
|
||||||
|
.route(
|
||||||
|
"/api/media/{server_name}/{media_id}/download",
|
||||||
|
web::get().to(api::media::download),
|
||||||
|
)
|
||||||
|
.route(
|
||||||
|
"/api/media/{server_name}/{media_id}/thumbnail",
|
||||||
|
web::get().to(api::media::thumbnail),
|
||||||
|
)
|
||||||
|
.route(
|
||||||
|
"/api/profile/{user_id}",
|
||||||
|
web::get().to(api::profile::get_profile),
|
||||||
|
)
|
||||||
|
.service(web::resource("/api/ws").route(web::get().to(api::ws::ws)))
|
||||||
})
|
})
|
||||||
|
.workers(4)
|
||||||
.bind(&AppConfig::get().listen_address)?
|
.bind(&AppConfig::get().listen_address)?
|
||||||
.run()
|
.run()
|
||||||
.await
|
.await
|
||||||
|
|||||||
23
src/server/api/account.rs
Normal file
23
src/server/api/account.rs
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
use crate::extractors::client_auth::APIClientAuth;
|
||||||
|
use crate::server::HttpResult;
|
||||||
|
use actix_web::HttpResponse;
|
||||||
|
use ruma::api::client::account;
|
||||||
|
use ruma::DeviceId;
|
||||||
|
|
||||||
|
#[derive(serde::Serialize)]
|
||||||
|
struct WhoAmIResponse {
|
||||||
|
user_id: String,
|
||||||
|
device_id: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get current user identity
|
||||||
|
pub async fn who_am_i(auth: APIClientAuth) -> HttpResult {
|
||||||
|
let res = auth
|
||||||
|
.send_request(account::whoami::v3::Request::default())
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
Ok(HttpResponse::Ok().json(WhoAmIResponse {
|
||||||
|
user_id: res.user_id.to_string(),
|
||||||
|
device_id: res.device_id.as_deref().map(DeviceId::to_string),
|
||||||
|
}))
|
||||||
|
}
|
||||||
59
src/server/api/media.rs
Normal file
59
src/server/api/media.rs
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
use crate::extractors::client_auth::APIClientAuth;
|
||||||
|
use crate::server::HttpResult;
|
||||||
|
use actix_web::{web, HttpResponse};
|
||||||
|
use ruma::api::client::media;
|
||||||
|
use ruma::{OwnedServerName, UInt};
|
||||||
|
|
||||||
|
#[derive(serde::Deserialize)]
|
||||||
|
pub struct MediaInfoInPath {
|
||||||
|
server_name: OwnedServerName,
|
||||||
|
media_id: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Download a media
|
||||||
|
#[allow(deprecated)]
|
||||||
|
pub async fn download(auth: APIClientAuth, path: web::Path<MediaInfoInPath>) -> HttpResult {
|
||||||
|
let res = auth
|
||||||
|
.send_request(media::get_content::v3::Request::new(
|
||||||
|
path.media_id.clone(),
|
||||||
|
path.server_name.clone(),
|
||||||
|
))
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let mut http_res = HttpResponse::Ok();
|
||||||
|
if let Some(content_type) = res.content_type {
|
||||||
|
http_res.content_type(content_type);
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(http_res.body(res.file))
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(serde::Deserialize)]
|
||||||
|
pub struct MediaThumbnailQuery {
|
||||||
|
width: Option<UInt>,
|
||||||
|
height: Option<UInt>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get a media thumbnail
|
||||||
|
#[allow(deprecated)]
|
||||||
|
pub async fn thumbnail(
|
||||||
|
auth: APIClientAuth,
|
||||||
|
path: web::Path<MediaInfoInPath>,
|
||||||
|
query: web::Query<MediaThumbnailQuery>,
|
||||||
|
) -> HttpResult {
|
||||||
|
let res = auth
|
||||||
|
.send_request(media::get_content_thumbnail::v3::Request::new(
|
||||||
|
path.media_id.clone(),
|
||||||
|
path.server_name.clone(),
|
||||||
|
query.width.unwrap_or(UInt::new(500).unwrap()),
|
||||||
|
query.height.unwrap_or(UInt::new(500).unwrap()),
|
||||||
|
))
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let mut http_res = HttpResponse::Ok();
|
||||||
|
if let Some(content_type) = res.content_type {
|
||||||
|
http_res.content_type(content_type);
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(http_res.body(res.file))
|
||||||
|
}
|
||||||
@@ -2,6 +2,12 @@ use crate::extractors::client_auth::APIClientAuth;
|
|||||||
use crate::server::HttpResult;
|
use crate::server::HttpResult;
|
||||||
use actix_web::HttpResponse;
|
use actix_web::HttpResponse;
|
||||||
|
|
||||||
|
pub mod account;
|
||||||
|
pub mod media;
|
||||||
|
pub mod profile;
|
||||||
|
pub mod room;
|
||||||
|
pub mod ws;
|
||||||
|
|
||||||
/// API Home route
|
/// API Home route
|
||||||
pub async fn api_home(auth: APIClientAuth) -> HttpResult {
|
pub async fn api_home(auth: APIClientAuth) -> HttpResult {
|
||||||
Ok(HttpResponse::Ok().body(format!("Welcome user {}!", auth.user.user_id.0)))
|
Ok(HttpResponse::Ok().body(format!("Welcome user {}!", auth.user.user_id.0)))
|
||||||
29
src/server/api/profile.rs
Normal file
29
src/server/api/profile.rs
Normal file
@@ -0,0 +1,29 @@
|
|||||||
|
use crate::extractors::client_auth::APIClientAuth;
|
||||||
|
use crate::server::HttpResult;
|
||||||
|
use crate::utils::matrix_utils::ApiMxcURI;
|
||||||
|
use actix_web::{web, HttpResponse};
|
||||||
|
use ruma::api::client::profile;
|
||||||
|
use ruma::OwnedUserId;
|
||||||
|
|
||||||
|
#[derive(serde::Deserialize)]
|
||||||
|
pub struct UserIDInPath {
|
||||||
|
user_id: OwnedUserId,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(serde::Serialize)]
|
||||||
|
struct ProfileResponse {
|
||||||
|
display_name: Option<String>,
|
||||||
|
avatar: Option<ApiMxcURI>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get user profile
|
||||||
|
pub async fn get_profile(auth: APIClientAuth, path: web::Path<UserIDInPath>) -> HttpResult {
|
||||||
|
let res = auth
|
||||||
|
.send_request(profile::get_profile::v3::Request::new(path.user_id.clone()))
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
Ok(HttpResponse::Ok().json(ProfileResponse {
|
||||||
|
display_name: res.displayname,
|
||||||
|
avatar: res.avatar_url.map(ApiMxcURI),
|
||||||
|
}))
|
||||||
|
}
|
||||||
81
src/server/api/room.rs
Normal file
81
src/server/api/room.rs
Normal file
@@ -0,0 +1,81 @@
|
|||||||
|
use crate::extractors::client_auth::APIClientAuth;
|
||||||
|
use crate::server::{HttpFailure, HttpResult};
|
||||||
|
use crate::utils::matrix_utils::ApiMxcURI;
|
||||||
|
use actix_web::{web, HttpResponse};
|
||||||
|
use ruma::api::client::{membership, state};
|
||||||
|
use ruma::events::StateEventType;
|
||||||
|
use ruma::{OwnedMxcUri, OwnedRoomId};
|
||||||
|
use serde::de::DeserializeOwned;
|
||||||
|
|
||||||
|
#[derive(serde::Serialize)]
|
||||||
|
struct GetRoomsMembershipsResponse {
|
||||||
|
rooms: Vec<OwnedRoomId>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get the list of rooms the user has joined
|
||||||
|
pub async fn joined_rooms(auth: APIClientAuth) -> HttpResult {
|
||||||
|
let res = auth
|
||||||
|
.send_request(membership::joined_rooms::v3::Request::default())
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
Ok(HttpResponse::Ok().json(GetRoomsMembershipsResponse {
|
||||||
|
rooms: res.joined_rooms,
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(serde::Deserialize)]
|
||||||
|
pub struct RoomIDInPath {
|
||||||
|
room_id: OwnedRoomId,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(serde::Serialize)]
|
||||||
|
struct GetRoomInfoResponse {
|
||||||
|
name: Option<String>,
|
||||||
|
avatar: Option<ApiMxcURI>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get a room information
|
||||||
|
async fn get_room_info<E: DeserializeOwned>(
|
||||||
|
auth: &APIClientAuth,
|
||||||
|
room_id: OwnedRoomId,
|
||||||
|
event_type: StateEventType,
|
||||||
|
field: &str,
|
||||||
|
) -> anyhow::Result<Option<E>, HttpFailure> {
|
||||||
|
let res = auth
|
||||||
|
.send_request(state::get_state_events_for_key::v3::Request::new(
|
||||||
|
room_id,
|
||||||
|
event_type,
|
||||||
|
String::default(),
|
||||||
|
))
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
Ok(res.content.get_field(field)?)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get room information
|
||||||
|
pub async fn info(auth: APIClientAuth, path: web::Path<RoomIDInPath>) -> HttpResult {
|
||||||
|
let room_name: Option<String> = get_room_info(
|
||||||
|
&auth,
|
||||||
|
path.room_id.clone(),
|
||||||
|
StateEventType::RoomName,
|
||||||
|
"name",
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.ok()
|
||||||
|
.flatten();
|
||||||
|
|
||||||
|
let room_avatar: Option<OwnedMxcUri> = get_room_info(
|
||||||
|
&auth,
|
||||||
|
path.room_id.clone(),
|
||||||
|
StateEventType::RoomAvatar,
|
||||||
|
"url",
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.ok()
|
||||||
|
.flatten();
|
||||||
|
|
||||||
|
Ok(HttpResponse::Ok().json(GetRoomInfoResponse {
|
||||||
|
name: room_name,
|
||||||
|
avatar: room_avatar.map(ApiMxcURI),
|
||||||
|
}))
|
||||||
|
}
|
||||||
176
src/server/api/ws.rs
Normal file
176
src/server/api/ws.rs
Normal file
@@ -0,0 +1,176 @@
|
|||||||
|
use crate::broadcast_messages::{BroadcastMessage, SyncEvent};
|
||||||
|
use crate::constants::{WS_CLIENT_TIMEOUT, WS_HEARTBEAT_INTERVAL};
|
||||||
|
use crate::extractors::client_auth::APIClientAuth;
|
||||||
|
use crate::server::HttpResult;
|
||||||
|
use actix_web::dev::Payload;
|
||||||
|
use actix_web::{web, FromRequest, HttpRequest};
|
||||||
|
use actix_ws::Message;
|
||||||
|
use futures_util::StreamExt;
|
||||||
|
use std::time::Instant;
|
||||||
|
use tokio::select;
|
||||||
|
use tokio::sync::broadcast;
|
||||||
|
use tokio::sync::broadcast::Receiver;
|
||||||
|
use tokio::time::interval;
|
||||||
|
|
||||||
|
/// Messages send to the client
|
||||||
|
#[derive(Debug, serde::Deserialize, serde::Serialize)]
|
||||||
|
#[serde(tag = "type")]
|
||||||
|
pub enum WsMessage {
|
||||||
|
Sync(SyncEvent),
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Main WS route
|
||||||
|
pub async fn ws(
|
||||||
|
req: HttpRequest,
|
||||||
|
stream: web::Payload,
|
||||||
|
tx: web::Data<broadcast::Sender<BroadcastMessage>>,
|
||||||
|
) -> HttpResult {
|
||||||
|
// Forcefully ignore request payload by manually extracting authentication information
|
||||||
|
let auth = APIClientAuth::from_request(&req, &mut Payload::None).await?;
|
||||||
|
|
||||||
|
let (res, session, msg_stream) = actix_ws::handle(&req, stream)?;
|
||||||
|
|
||||||
|
// Ask for sync client to be started
|
||||||
|
if let Err(e) = tx.send(BroadcastMessage::StartSyncTaskForUser(
|
||||||
|
auth.user.user_id.clone(),
|
||||||
|
)) {
|
||||||
|
log::error!("Failed to send StartSyncTaskForUser: {e}");
|
||||||
|
}
|
||||||
|
|
||||||
|
let rx = tx.subscribe();
|
||||||
|
|
||||||
|
// spawn websocket handler (and don't await it) so that the response is returned immediately
|
||||||
|
actix_web::rt::spawn(ws_handler(session, msg_stream, auth, rx));
|
||||||
|
|
||||||
|
Ok(res)
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn ws_handler(
|
||||||
|
mut session: actix_ws::Session,
|
||||||
|
mut msg_stream: actix_ws::MessageStream,
|
||||||
|
auth: APIClientAuth,
|
||||||
|
mut rx: Receiver<BroadcastMessage>,
|
||||||
|
) {
|
||||||
|
log::info!("WS connected");
|
||||||
|
|
||||||
|
let mut last_heartbeat = Instant::now();
|
||||||
|
let mut interval = interval(WS_HEARTBEAT_INTERVAL);
|
||||||
|
|
||||||
|
let reason = loop {
|
||||||
|
// waits for either `msg_stream` to receive a message from the client, the broadcast channel
|
||||||
|
// to send a message, or the heartbeat interval timer to tick, yielding the value of
|
||||||
|
// whichever one is ready first
|
||||||
|
select! {
|
||||||
|
ws_msg = rx.recv() => {
|
||||||
|
let msg = match ws_msg {
|
||||||
|
Ok(msg) => msg,
|
||||||
|
Err(broadcast::error::RecvError::Closed) => break None,
|
||||||
|
Err(broadcast::error::RecvError::Lagged(_)) => continue,
|
||||||
|
};
|
||||||
|
|
||||||
|
match msg {
|
||||||
|
BroadcastMessage::CloseClientSession(id) => {
|
||||||
|
if let Some(client) = &auth.client {
|
||||||
|
if client.id == id {
|
||||||
|
log::info!(
|
||||||
|
"closing client session {id:?} of user {:?} as requested", auth.user.user_id
|
||||||
|
);
|
||||||
|
break None;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
BroadcastMessage::CloseAllUserSessions(userid) => {
|
||||||
|
if userid == auth.user.user_id {
|
||||||
|
log::info!(
|
||||||
|
"closing WS session of user {userid:?} as requested"
|
||||||
|
);
|
||||||
|
break None;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
BroadcastMessage::SyncEvent(userid, event) => {
|
||||||
|
if userid != auth.user.user_id {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Send the message to the websocket
|
||||||
|
if let Ok(msg) = serde_json::to_string(&WsMessage::Sync(*event)) {
|
||||||
|
if let Err(e) = session.text(msg).await {
|
||||||
|
log::error!("Failed to send SyncEvent: {e}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
_ => {}};
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
// heartbeat interval ticked
|
||||||
|
_tick = interval.tick() => {
|
||||||
|
// if no heartbeat ping/pong received recently, close the connection
|
||||||
|
if Instant::now().duration_since(last_heartbeat) > WS_CLIENT_TIMEOUT {
|
||||||
|
log::info!(
|
||||||
|
"client has not sent heartbeat in over {WS_CLIENT_TIMEOUT:?}; disconnecting"
|
||||||
|
);
|
||||||
|
|
||||||
|
break None;
|
||||||
|
}
|
||||||
|
|
||||||
|
// send heartbeat ping
|
||||||
|
let _ = session.ping(b"").await;
|
||||||
|
},
|
||||||
|
|
||||||
|
msg = msg_stream.next() => {
|
||||||
|
let msg = match msg {
|
||||||
|
// received message from WebSocket client
|
||||||
|
Some(Ok(msg)) => msg,
|
||||||
|
|
||||||
|
// client WebSocket stream error
|
||||||
|
Some(Err(err)) => {
|
||||||
|
log::error!("{err}");
|
||||||
|
break None;
|
||||||
|
}
|
||||||
|
|
||||||
|
// client WebSocket stream ended
|
||||||
|
None => break None
|
||||||
|
};
|
||||||
|
|
||||||
|
log::debug!("msg: {msg:?}");
|
||||||
|
|
||||||
|
match msg {
|
||||||
|
Message::Text(s) => {
|
||||||
|
log::info!("Text message: {s}");
|
||||||
|
}
|
||||||
|
|
||||||
|
Message::Binary(_) => {
|
||||||
|
// drop client's binary messages
|
||||||
|
}
|
||||||
|
|
||||||
|
Message::Close(reason) => {
|
||||||
|
break reason;
|
||||||
|
}
|
||||||
|
|
||||||
|
Message::Ping(bytes) => {
|
||||||
|
last_heartbeat = Instant::now();
|
||||||
|
let _ = session.pong(&bytes).await;
|
||||||
|
}
|
||||||
|
|
||||||
|
Message::Pong(_) => {
|
||||||
|
last_heartbeat = Instant::now();
|
||||||
|
}
|
||||||
|
|
||||||
|
Message::Continuation(_) => {
|
||||||
|
log::warn!("no support for continuation frames");
|
||||||
|
}
|
||||||
|
|
||||||
|
// no-op; ignore
|
||||||
|
Message::Nop => {}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// attempt to close connection gracefully
|
||||||
|
let _ = session.close(reason).await;
|
||||||
|
|
||||||
|
log::info!("WS disconnected");
|
||||||
|
}
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
use actix_web::http::StatusCode;
|
use actix_web::http::StatusCode;
|
||||||
use actix_web::{HttpResponse, ResponseError};
|
use actix_web::{HttpResponse, ResponseError};
|
||||||
use std::error::Error;
|
use std::error::Error;
|
||||||
|
use std::fmt::Debug;
|
||||||
|
|
||||||
pub mod api;
|
pub mod api;
|
||||||
pub mod web_ui;
|
pub mod web_ui;
|
||||||
@@ -11,6 +12,8 @@ pub enum HttpFailure {
|
|||||||
Forbidden,
|
Forbidden,
|
||||||
#[error("this resource was not found")]
|
#[error("this resource was not found")]
|
||||||
NotFound,
|
NotFound,
|
||||||
|
#[error("Actix web error")]
|
||||||
|
ActixError(#[from] actix_web::Error),
|
||||||
#[error("an unhandled session insert error occurred")]
|
#[error("an unhandled session insert error occurred")]
|
||||||
SessionInsertError(#[from] actix_session::SessionInsertError),
|
SessionInsertError(#[from] actix_session::SessionInsertError),
|
||||||
#[error("an unhandled session error occurred")]
|
#[error("an unhandled session error occurred")]
|
||||||
@@ -21,6 +24,12 @@ pub enum HttpFailure {
|
|||||||
FetchUserConfig(anyhow::Error),
|
FetchUserConfig(anyhow::Error),
|
||||||
#[error("an unspecified internal error occurred: {0}")]
|
#[error("an unspecified internal error occurred: {0}")]
|
||||||
InternalError(#[from] anyhow::Error),
|
InternalError(#[from] anyhow::Error),
|
||||||
|
#[error("a matrix api client error occurred: {0}")]
|
||||||
|
MatrixApiClientError(#[from] ruma::api::client::Error),
|
||||||
|
#[error("a matrix client error occurred: {0}")]
|
||||||
|
MatrixClientError(String),
|
||||||
|
#[error("a serde_json error occurred: {0}")]
|
||||||
|
SerdeJsonError(#[from] serde_json::error::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
impl ResponseError for HttpFailure {
|
impl ResponseError for HttpFailure {
|
||||||
@@ -37,4 +46,4 @@ impl ResponseError for HttpFailure {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
pub type HttpResult = std::result::Result<HttpResponse, HttpFailure>;
|
pub type HttpResult = Result<HttpResponse, HttpFailure>;
|
||||||
|
|||||||
@@ -1,14 +1,16 @@
|
|||||||
use crate::app_config::AppConfig;
|
use crate::app_config::AppConfig;
|
||||||
|
use crate::broadcast_messages::BroadcastMessage;
|
||||||
use crate::constants::{STATE_KEY, USER_SESSION_KEY};
|
use crate::constants::{STATE_KEY, USER_SESSION_KEY};
|
||||||
use crate::server::{HttpFailure, HttpResult};
|
use crate::server::{HttpFailure, HttpResult};
|
||||||
use crate::user::{APIClient, APIClientID, User, UserConfig, UserID};
|
use crate::user::{APIClient, APIClientID, User, UserConfig, UserID};
|
||||||
use crate::utils;
|
use crate::utils::base_utils;
|
||||||
use actix_session::Session;
|
use actix_session::Session;
|
||||||
use actix_web::{web, HttpResponse};
|
use actix_web::{web, HttpResponse};
|
||||||
use askama::Template;
|
use askama::Template;
|
||||||
use ipnet::IpNet;
|
use ipnet::IpNet;
|
||||||
use light_openid::primitives::OpenIDConfig;
|
use light_openid::primitives::OpenIDConfig;
|
||||||
use std::str::FromStr;
|
use std::str::FromStr;
|
||||||
|
use tokio::sync::broadcast;
|
||||||
|
|
||||||
/// Static assets
|
/// Static assets
|
||||||
#[derive(rust_embed::Embed)]
|
#[derive(rust_embed::Embed)]
|
||||||
@@ -60,11 +62,15 @@ pub struct FormRequest {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Main route
|
/// Main route
|
||||||
pub async fn home(session: Session, form_req: Option<web::Form<FormRequest>>) -> HttpResult {
|
pub async fn home(
|
||||||
|
session: Session,
|
||||||
|
form_req: Option<web::Form<FormRequest>>,
|
||||||
|
tx: web::Data<broadcast::Sender<BroadcastMessage>>,
|
||||||
|
) -> HttpResult {
|
||||||
// Get user information, requesting authentication if information is missing
|
// Get user information, requesting authentication if information is missing
|
||||||
let Some(user): Option<User> = session.get(USER_SESSION_KEY)? else {
|
let Some(user): Option<User> = session.get(USER_SESSION_KEY)? else {
|
||||||
// Generate auth state
|
// Generate auth state
|
||||||
let state = utils::rand_str(50);
|
let state = base_utils::rand_str(50);
|
||||||
session.insert(STATE_KEY, &state)?;
|
session.insert(STATE_KEY, &state)?;
|
||||||
|
|
||||||
let oidc = AppConfig::get().openid_provider();
|
let oidc = AppConfig::get().openid_provider();
|
||||||
@@ -93,10 +99,19 @@ pub async fn home(session: Session, form_req: Option<web::Form<FormRequest>>) ->
|
|||||||
if t.len() < 3 {
|
if t.len() < 3 {
|
||||||
error_message = Some("Specified Matrix token is too short!".to_string());
|
error_message = Some("Specified Matrix token is too short!".to_string());
|
||||||
} else {
|
} else {
|
||||||
// TODO : invalidate all existing connections
|
|
||||||
config.matrix_token = t;
|
config.matrix_token = t;
|
||||||
config.save().await?;
|
config.save().await?;
|
||||||
success_message = Some("Matrix token was successfully updated!".to_string());
|
success_message = Some("Matrix token was successfully updated!".to_string());
|
||||||
|
|
||||||
|
// Close sync task
|
||||||
|
if let Err(e) = tx.send(BroadcastMessage::StopSyncTaskForUser(user.id.clone())) {
|
||||||
|
log::error!("Failed to send StopSyncClientForUser: {e}");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Invalidate all Ws connections
|
||||||
|
if let Err(e) = tx.send(BroadcastMessage::CloseAllUserSessions(user.id.clone())) {
|
||||||
|
log::error!("Failed to send CloseAllUserSessions: {e}");
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -128,7 +143,10 @@ pub async fn home(session: Session, form_req: Option<web::Form<FormRequest>>) ->
|
|||||||
config.clients.retain(|c| c.id != delete_client_id);
|
config.clients.retain(|c| c.id != delete_client_id);
|
||||||
config.save().await?;
|
config.save().await?;
|
||||||
success_message = Some("The client was successfully deleted!".to_string());
|
success_message = Some("The client was successfully deleted!".to_string());
|
||||||
// TODO : close connections with given id
|
|
||||||
|
if let Err(e) = tx.send(BroadcastMessage::CloseClientSession(delete_client_id)) {
|
||||||
|
log::error!("Failed to send CloseClientSession: {e}");
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -197,7 +215,7 @@ pub async fn oidc_cb(session: Session, query: web::Query<AuthCallbackQuery>) ->
|
|||||||
name: user.name.unwrap_or("no_name".to_string()),
|
name: user.name.unwrap_or("no_name".to_string()),
|
||||||
email: user.email.unwrap_or("no@mail.com".to_string()),
|
email: user.email.unwrap_or("no@mail.com".to_string()),
|
||||||
};
|
};
|
||||||
log::info!("Successful authentication as {:?}", user);
|
log::info!("Successful authentication as {user:?}");
|
||||||
session.insert(USER_SESSION_KEY, user)?;
|
session.insert(USER_SESSION_KEY, user)?;
|
||||||
|
|
||||||
Ok(HttpResponse::Found()
|
Ok(HttpResponse::Found()
|
||||||
@@ -213,3 +231,22 @@ pub async fn sign_out(session: Session) -> HttpResult {
|
|||||||
.insert_header(("location", "/"))
|
.insert_header(("location", "/"))
|
||||||
.finish())
|
.finish())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[derive(askama::Template)]
|
||||||
|
#[template(path = "ws_debug.html")]
|
||||||
|
struct WsDebugTemplate {
|
||||||
|
name: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// WebSocket debug
|
||||||
|
pub async fn ws_debug(session: Session) -> HttpResult {
|
||||||
|
let Some(user): Option<User> = session.get(USER_SESSION_KEY)? else {
|
||||||
|
return Ok(HttpResponse::Found()
|
||||||
|
.insert_header(("location", "/"))
|
||||||
|
.finish());
|
||||||
|
};
|
||||||
|
|
||||||
|
Ok(HttpResponse::Ok()
|
||||||
|
.content_type("text/html")
|
||||||
|
.body(WsDebugTemplate { name: user.name }.render().unwrap()))
|
||||||
|
}
|
||||||
|
|||||||
145
src/sync_client.rs
Normal file
145
src/sync_client.rs
Normal file
@@ -0,0 +1,145 @@
|
|||||||
|
use crate::broadcast_messages::{BroadcastMessage, SyncEvent};
|
||||||
|
use crate::user::{UserConfig, UserID};
|
||||||
|
use futures_util::TryStreamExt;
|
||||||
|
use ruma::api::client::sync::sync_events;
|
||||||
|
use ruma::assign;
|
||||||
|
use ruma::presence::PresenceState;
|
||||||
|
use std::collections::HashMap;
|
||||||
|
use std::sync::Arc;
|
||||||
|
use std::time::Duration;
|
||||||
|
use tokio::sync::broadcast;
|
||||||
|
|
||||||
|
/// ID of sync client
|
||||||
|
#[derive(Debug, Clone, Eq, PartialEq)]
|
||||||
|
pub struct SyncClientID(uuid::Uuid);
|
||||||
|
|
||||||
|
/// Sync client launcher loop
|
||||||
|
pub async fn sync_client_manager(tx: broadcast::Sender<BroadcastMessage>) -> ! {
|
||||||
|
let mut rx = tx.subscribe();
|
||||||
|
let tx = Arc::new(tx.clone());
|
||||||
|
|
||||||
|
let mut running_tasks = HashMap::new();
|
||||||
|
|
||||||
|
while let Ok(msg) = rx.recv().await {
|
||||||
|
match msg {
|
||||||
|
BroadcastMessage::StartSyncTaskForUser(user_id) => {
|
||||||
|
if running_tasks.contains_key(&user_id) {
|
||||||
|
log::info!("Won't start sync task for user {user_id:?} because a task is already running for this user!");
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
log::info!("Start sync task for user {user_id:?}");
|
||||||
|
let task_id = SyncClientID(uuid::Uuid::new_v4());
|
||||||
|
running_tasks.insert(user_id.clone(), task_id.clone());
|
||||||
|
|
||||||
|
let tx = tx.clone();
|
||||||
|
tokio::task::spawn(async move {
|
||||||
|
sync_task(task_id, user_id, tx).await;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
BroadcastMessage::StopSyncTaskForUser(user_id) => {
|
||||||
|
// Check if a task is running for this user
|
||||||
|
if let Some(task_id) = running_tasks.remove(&user_id) {
|
||||||
|
log::info!("Stop sync task for user {user_id:?}");
|
||||||
|
tx.send(BroadcastMessage::StopSyncClient(task_id)).unwrap();
|
||||||
|
} else {
|
||||||
|
log::info!("Not stopping sync task for user {user_id:?}: not running");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
panic!("Sync client manager stopped unexpectedly!");
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Sync task for a single user
|
||||||
|
async fn sync_task(
|
||||||
|
id: SyncClientID,
|
||||||
|
user_id: UserID,
|
||||||
|
tx: Arc<broadcast::Sender<BroadcastMessage>>,
|
||||||
|
) {
|
||||||
|
let mut rx = tx.subscribe();
|
||||||
|
|
||||||
|
let Ok(user_config) = UserConfig::load(&user_id, false).await else {
|
||||||
|
log::error!("Failed to load user config in sync thread!");
|
||||||
|
return;
|
||||||
|
};
|
||||||
|
|
||||||
|
let client = match user_config.matrix_client().await {
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to load matrix client for user {user_id:?}: {e}");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
Ok(client) => client,
|
||||||
|
};
|
||||||
|
|
||||||
|
let initial_sync_response = match client
|
||||||
|
.send_request(assign!(sync_events::v3::Request::new(), {
|
||||||
|
filter: None,
|
||||||
|
}))
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(res) => res,
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to perform initial sync request for user {user_id:?}! {e}");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut sync_stream = Box::pin(client.sync(
|
||||||
|
None,
|
||||||
|
initial_sync_response.next_batch,
|
||||||
|
PresenceState::Offline,
|
||||||
|
Some(Duration::from_secs(30)),
|
||||||
|
));
|
||||||
|
|
||||||
|
loop {
|
||||||
|
tokio::select! {
|
||||||
|
// Message from tokio broadcast
|
||||||
|
msg = rx.recv() => {
|
||||||
|
match msg {
|
||||||
|
Ok(BroadcastMessage::StopSyncClient(client_id)) => {
|
||||||
|
if client_id == id {
|
||||||
|
log::info!("A request was received to stop this client! {id:?} for user {user_id:?}");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to receive a message from broadcast! {e}");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(_) => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Message from Matrix
|
||||||
|
msg_stream = sync_stream.try_next() => {
|
||||||
|
match msg_stream {
|
||||||
|
Ok(Some(msg)) => {
|
||||||
|
log::debug!("Received new message from Matrix: {msg:#?}");
|
||||||
|
if let Err(e) = tx.send(BroadcastMessage::SyncEvent(user_id.clone(), Box::new(SyncEvent {
|
||||||
|
rooms: msg.rooms,presence: msg.presence,
|
||||||
|
account_data: msg.account_data,
|
||||||
|
to_device: msg.to_device,
|
||||||
|
device_lists: msg.device_lists,
|
||||||
|
}))) {
|
||||||
|
log::error!("Failed to propagate event! {e}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(None) => {
|
||||||
|
log::debug!("Received no message from Matrix");
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
log::error!("Failed to receive a message from Matrix! {e}");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
35
src/user.rs
35
src/user.rs
@@ -6,15 +6,20 @@ use thiserror::Error;
|
|||||||
|
|
||||||
use crate::app_config::AppConfig;
|
use crate::app_config::AppConfig;
|
||||||
use crate::constants::TOKEN_LEN;
|
use crate::constants::TOKEN_LEN;
|
||||||
use crate::utils::{curr_time, format_time, rand_str};
|
use crate::utils::base_utils::{curr_time, format_time, rand_str};
|
||||||
|
|
||||||
|
type HttpClient = ruma::client::http_client::HyperNativeTls;
|
||||||
|
pub type RumaClient = ruma::Client<HttpClient>;
|
||||||
|
|
||||||
#[derive(Error, Debug)]
|
#[derive(Error, Debug)]
|
||||||
pub enum UserError {
|
pub enum UserError {
|
||||||
#[error("failed to fetch user configuration: {0}")]
|
#[error("failed to fetch user configuration: {0}")]
|
||||||
FetchUserConfig(S3Error),
|
FetchUserConfig(S3Error),
|
||||||
|
#[error("missing matrix token")]
|
||||||
|
MissingMatrixToken,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(serde::Serialize, serde::Deserialize, Debug, Clone)]
|
#[derive(serde::Serialize, serde::Deserialize, Debug, Clone, PartialEq, Eq, Hash)]
|
||||||
pub struct UserID(pub String);
|
pub struct UserID(pub String);
|
||||||
|
|
||||||
impl UserID {
|
impl UserID {
|
||||||
@@ -80,6 +85,10 @@ impl APIClient {
|
|||||||
pub fn fmt_used(&self) -> String {
|
pub fn fmt_used(&self) -> String {
|
||||||
format_time(self.used).unwrap_or_default()
|
format_time(self.used).unwrap_or_default()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub fn need_update_last_used(&self) -> bool {
|
||||||
|
self.used + 60 * 15 < curr_time().unwrap()
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl APIClient {
|
impl APIClient {
|
||||||
@@ -97,7 +106,7 @@ impl APIClient {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(serde::Serialize, serde::Deserialize)]
|
#[derive(serde::Serialize, serde::Deserialize, Clone)]
|
||||||
pub struct UserConfig {
|
pub struct UserConfig {
|
||||||
/// Target user ID
|
/// Target user ID
|
||||||
pub user_id: UserID,
|
pub user_id: UserID,
|
||||||
@@ -138,7 +147,7 @@ impl UserConfig {
|
|||||||
log::warn!("The bucket does not seem to exists, trying to create it!")
|
log::warn!("The bucket does not seem to exists, trying to create it!")
|
||||||
}
|
}
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
log::error!("Got unexpected error when querying bucket info: {}", e);
|
log::error!("Got unexpected error when querying bucket info: {e}");
|
||||||
return Err(e.into());
|
return Err(e.into());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -211,4 +220,22 @@ impl UserConfig {
|
|||||||
pub fn find_client_by_id(&self, id: &APIClientID) -> Option<&APIClient> {
|
pub fn find_client_by_id(&self, id: &APIClientID) -> Option<&APIClient> {
|
||||||
self.clients.iter().find(|c| &c.id == id)
|
self.clients.iter().find(|c| &c.id == id)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Find a client by its id and get a mutable reference
|
||||||
|
pub fn find_client_by_id_mut(&mut self, id: &APIClientID) -> Option<&mut APIClient> {
|
||||||
|
self.clients.iter_mut().find(|c| &c.id == id)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get a matrix client instance for the current user
|
||||||
|
pub async fn matrix_client(&self) -> anyhow::Result<RumaClient> {
|
||||||
|
if self.matrix_token.is_empty() {
|
||||||
|
return Err(UserError::MissingMatrixToken.into());
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(ruma::Client::builder()
|
||||||
|
.homeserver_url(AppConfig::get().matrix_homeserver.to_string())
|
||||||
|
.access_token(Some(self.matrix_token.clone()))
|
||||||
|
.build()
|
||||||
|
.await?)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
18
src/utils/matrix_utils.rs
Normal file
18
src/utils/matrix_utils.rs
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
use ruma::OwnedMxcUri;
|
||||||
|
use serde::ser::SerializeMap;
|
||||||
|
use serde::{Serialize, Serializer};
|
||||||
|
|
||||||
|
pub struct ApiMxcURI(pub OwnedMxcUri);
|
||||||
|
|
||||||
|
impl Serialize for ApiMxcURI {
|
||||||
|
fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
|
||||||
|
where
|
||||||
|
S: Serializer,
|
||||||
|
{
|
||||||
|
let mut map = serializer.serialize_map(Some(3))?;
|
||||||
|
map.serialize_entry("uri", &self.0)?;
|
||||||
|
map.serialize_entry("server_name", &self.0.server_name().ok())?;
|
||||||
|
map.serialize_entry("media_id", &self.0.media_id().ok())?;
|
||||||
|
map.end()
|
||||||
|
}
|
||||||
|
}
|
||||||
2
src/utils/mod.rs
Normal file
2
src/utils/mod.rs
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
pub mod base_utils;
|
||||||
|
pub mod matrix_utils;
|
||||||
46
templates/base_page.html
Normal file
46
templates/base_page.html
Normal file
@@ -0,0 +1,46 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<title>Matrix GW</title>
|
||||||
|
<link rel="icon" type="image/png" href="/assets/favicon.png"/>
|
||||||
|
|
||||||
|
<link rel="stylesheet" href="/assets/bootstrap.css"/>
|
||||||
|
<link rel="stylesheet" href="/assets/style.css"/>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<!-- Header -->
|
||||||
|
<header data-bs-theme="dark">
|
||||||
|
<div class="navbar navbar-dark bg-dark shadow-sm">
|
||||||
|
<div class="container">
|
||||||
|
<a href="/" class="navbar-brand d-flex align-items-center">
|
||||||
|
<svg xxmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" stroke="currentColor"
|
||||||
|
stroke-linecap="round" stroke-linejoin="round" stroke-width="1" aria-hidden="true" class="me-2"
|
||||||
|
viewBox="0 0 24 24">
|
||||||
|
<path d="M10 11.5H17V13H10V11.5M10 8.5H19V10H10V8.5M20 5H9C7.9 5 7 5.9 7 7V21L11 17H20C21.1 17 22 16.1 22 15V7C22 5.9 21.1 5 20 5M20 15H10.2L9 16.2V7H20V15M3 7C2.4 7 2 7.4 2 8S2.4 9 3 9H5V7H3M2 11C1.4 11 1 11.4 1 12S1.4 13 2 13H5V11H2M1 15C.4 15 0 15.4 0 16C0 16.6 .4 17 1 17H5V15H1Z"/>
|
||||||
|
</svg>
|
||||||
|
<strong>Matrix GW</strong>
|
||||||
|
</a>
|
||||||
|
<ul class="navbar-nav mr-auto" style="flex: 1">
|
||||||
|
<li class="nav-item"><a href="/ws_debug" class="nav-link">WS Debug</a></li>
|
||||||
|
</ul>
|
||||||
|
|
||||||
|
<div class="navbar" >
|
||||||
|
<span>Hi <span style="font-style: italic;">{{ name }}</span> </span>
|
||||||
|
<a href="/sign_out">Sign out</a>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
|
||||||
|
<div class="body-content">
|
||||||
|
{% block content %}
|
||||||
|
TO_REPLACE
|
||||||
|
{% endblock content %}
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -1,181 +1,146 @@
|
|||||||
<!DOCTYPE html>
|
{% extends "base_page.html" %}
|
||||||
<html lang="en">
|
{% block content %}
|
||||||
<head>
|
<!-- Success message -->
|
||||||
<meta charset="UTF-8">
|
{% if let Some(msg) = success_message %}
|
||||||
<title>Matrix GW</title>
|
<div class="alert alert-success">
|
||||||
<link rel="icon" type="image/png" href="/assets/favicon.png"/>
|
{{ msg }}
|
||||||
|
</div>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
<link rel="stylesheet" href="/assets/bootstrap.css"/>
|
<!-- Error message -->
|
||||||
<link rel="stylesheet" href="/assets/style.css"/>
|
{% if let Some(msg) = error_message %}
|
||||||
<script src="/assets/script.js"></script>
|
<div class="alert alert-danger">
|
||||||
</head>
|
{{ msg }}
|
||||||
<body>
|
</div>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
<!-- Header -->
|
<!-- User ID -->
|
||||||
<header data-bs-theme="dark">
|
<div id="user_id_container"><strong>Current user ID</strong>: {{ user_id.0 }}</div>
|
||||||
<div class="navbar navbar-dark bg-dark shadow-sm">
|
|
||||||
<div class="container">
|
|
||||||
<a href="/" class="navbar-brand d-flex align-items-center">
|
|
||||||
<svg xxmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" stroke="currentColor"
|
|
||||||
stroke-linecap="round" stroke-linejoin="round" stroke-width="1" aria-hidden="true" class="me-2"
|
|
||||||
viewBox="0 0 24 24">
|
|
||||||
<path d="M10 11.5H17V13H10V11.5M10 8.5H19V10H10V8.5M20 5H9C7.9 5 7 5.9 7 7V21L11 17H20C21.1 17 22 16.1 22 15V7C22 5.9 21.1 5 20 5M20 15H10.2L9 16.2V7H20V15M3 7C2.4 7 2 7.4 2 8S2.4 9 3 9H5V7H3M2 11C1.4 11 1 11.4 1 12S1.4 13 2 13H5V11H2M1 15C.4 15 0 15.4 0 16C0 16.6 .4 17 1 17H5V15H1Z"/>
|
|
||||||
</svg>
|
|
||||||
<strong>Matrix GW</strong>
|
|
||||||
</a>
|
|
||||||
<div class="navbar">
|
|
||||||
<span>Hi <span style="font-style: italic;">{{ name }}</span> </span>
|
|
||||||
<a href="/sign_out">Sign out</a>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
|
<!-- Display clients list -->
|
||||||
|
<div class="card border-light mb-3">
|
||||||
|
<div class="card-header">Registered clients</div>
|
||||||
|
<div class="card-body">
|
||||||
|
{% if clients.len() > 0 %}
|
||||||
|
<table class="table table-hover">
|
||||||
|
<thead>
|
||||||
|
<tr>
|
||||||
|
<th scope="col">ID</th>
|
||||||
|
<th scope="col">Description</th>
|
||||||
|
<th scope="col">Read only</th>
|
||||||
|
<th scope="col">Network</th>
|
||||||
|
<th scope="col">Created</th>
|
||||||
|
<th scope="col">Used</th>
|
||||||
|
<th scope="col"></th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
<tbody>
|
||||||
|
{% for client in clients %}
|
||||||
|
<tr>
|
||||||
|
<th scope="row">{{ client.id.0 }}</th>
|
||||||
|
<td>{{ client.description }}</td>
|
||||||
|
<td>
|
||||||
|
{% if client.readonly_client %}
|
||||||
|
<strong>YES</strong>
|
||||||
|
{% else %}
|
||||||
|
<i>NO</i>
|
||||||
|
{% endif %}
|
||||||
|
</td>
|
||||||
|
<td>
|
||||||
|
{% if let Some(net) = client.network %}
|
||||||
|
{{ net }}
|
||||||
|
{% else %}
|
||||||
|
<i>Unrestricted</i>
|
||||||
|
{% endif %}
|
||||||
|
</td>
|
||||||
|
<td>{{ client.fmt_created() }}</td>
|
||||||
|
<td>{{ client.fmt_used() }}</td>
|
||||||
|
<td>
|
||||||
|
<button type="button" class="btn btn-danger btn-sm" onclick="deleteClient('{{ client.id.0 }}');">
|
||||||
|
Delete
|
||||||
|
</button>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
{% endfor %}
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
<div class="body-content">
|
{% if clients.len() == 0 %}
|
||||||
<!-- Success message -->
|
<p>No client registered yet!</p>
|
||||||
{% if let Some(msg) = success_message %}
|
{% endif %}
|
||||||
<div class="alert alert-success">
|
|
||||||
{{ msg }}
|
|
||||||
</div>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- Error message -->
|
|
||||||
{% if let Some(msg) = error_message %}
|
|
||||||
<div class="alert alert-danger">
|
|
||||||
{{ msg }}
|
|
||||||
</div>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
<!-- User ID -->
|
|
||||||
<div id="user_id_container"><strong>Current user ID</strong>: {{ user_id.0 }}</div>
|
|
||||||
|
|
||||||
<!-- Display clients list -->
|
|
||||||
<div class="card border-light mb-3">
|
|
||||||
<div class="card-header">Registered clients</div>
|
|
||||||
<div class="card-body">
|
|
||||||
{% if clients.len() > 0 %}
|
|
||||||
<table class="table table-hover">
|
|
||||||
<thead>
|
|
||||||
<tr>
|
|
||||||
<th scope="col">ID</th>
|
|
||||||
<th scope="col">Description</th>
|
|
||||||
<th scope="col">Read only</th>
|
|
||||||
<th scope="col">Network</th>
|
|
||||||
<th scope="col">Created</th>
|
|
||||||
<th scope="col">Used</th>
|
|
||||||
<th scope="col"></th>
|
|
||||||
</tr>
|
|
||||||
</thead>
|
|
||||||
<tbody>
|
|
||||||
{% for client in clients %}
|
|
||||||
<tr>
|
|
||||||
<th scope="row">{{ client.id.0 }}</th>
|
|
||||||
<td>{{ client.description }}</td>
|
|
||||||
<td>
|
|
||||||
{% if client.readonly_client %}
|
|
||||||
<strong>YES</strong>
|
|
||||||
{% else %}
|
|
||||||
<i>NO</i>
|
|
||||||
{% endif %}
|
|
||||||
</td>
|
|
||||||
<td>
|
|
||||||
{% if let Some(net) = client.network %}
|
|
||||||
{{ net }}
|
|
||||||
{% else %}
|
|
||||||
<i>Unrestricted</i>
|
|
||||||
{% endif %}
|
|
||||||
</td>
|
|
||||||
<td>{{ client.fmt_created() }}</td>
|
|
||||||
<td>{{ client.fmt_used() }}</td>
|
|
||||||
<td>
|
|
||||||
<button type="button" class="btn btn-danger btn-sm" onclick="deleteClient('{{ client.id.0 }}');">
|
|
||||||
Delete
|
|
||||||
</button>
|
|
||||||
</td>
|
|
||||||
</tr>
|
|
||||||
{% endfor %}
|
|
||||||
</tbody>
|
|
||||||
</table>
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if clients.len() == 0 %}
|
|
||||||
<p>No client registered yet!</p>
|
|
||||||
{% endif %}
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<!-- New client -->
|
|
||||||
<div class="card border-light mb-3">
|
|
||||||
<div class="card-header">New client</div>
|
|
||||||
<div class="card-body">
|
|
||||||
<form action="/" method="post">
|
|
||||||
<div>
|
|
||||||
<label for="new_client_desc" class="form-label">Description</label>
|
|
||||||
<input type="text" class="form-control" id="new_client_desc" required minlength="3"
|
|
||||||
aria-describedby="new_client_desc" placeholder="New client description..."
|
|
||||||
name="new_client_desc"/>
|
|
||||||
<small class="form-text text-muted">Client description helps with identification.</small>
|
|
||||||
</div>
|
|
||||||
<div>
|
|
||||||
<label for="ip_network" class="form-label">Allowed IP network</label>
|
|
||||||
<input type="text" class="form-control" id="ip_network" aria-describedby="ip_network"
|
|
||||||
placeholder="Client network (x.x.x.x/x or x:x:x:x:x:x/x" name="ip_network"/>
|
|
||||||
<small class="form-text text-muted">Restrict the networks this IP address can be used from.</small>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<br/>
|
|
||||||
|
|
||||||
<div class="form-check">
|
|
||||||
<input class="form-check-input" type="checkbox" value="" checked id="readonly_client"
|
|
||||||
name="readonly_client"/>
|
|
||||||
<label class="form-check-label" for="readonly_client">
|
|
||||||
Readonly client
|
|
||||||
</label>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<br/>
|
|
||||||
|
|
||||||
|
|
||||||
<input type="submit" class="btn btn-primary" value="Create client"/>
|
|
||||||
</form>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<!-- Matrix authentication token -->
|
|
||||||
<div class="card border-light mb-3">
|
|
||||||
<div class="card-header">Matrix authentication token</div>
|
|
||||||
<div class="card-body">
|
|
||||||
<p>To obtain a new Matrix authentication token:</p>
|
|
||||||
<ol>
|
|
||||||
<li>Sign in to Element <strong>from a private browser window</strong></li>
|
|
||||||
<li>Open <em>All settings</em> and access the <em>Help & About</em> tag</li>
|
|
||||||
<li>Expand <em>Access Token</em> and copy the value</li>
|
|
||||||
<li>Paste the copied value below</li>
|
|
||||||
<li>Close the private browser window <strong>without signing out</strong>!</li>
|
|
||||||
</ol>
|
|
||||||
|
|
||||||
<p>You should not need to replace this value unless you explicitly signed out the associated browser
|
|
||||||
session.</p>
|
|
||||||
|
|
||||||
<p>Tip: you can rename the session to easily identify it among all your other sessions!</p>
|
|
||||||
|
|
||||||
<form action="/" method="post">
|
|
||||||
<div>
|
|
||||||
<label for="accessTokenInput" class="form-label mt-4">New Matrix access token</label>
|
|
||||||
<input type="text" class="form-control" id="accessTokenInput" aria-describedby="tokenHelp"
|
|
||||||
placeholder="{{ matrix_token }}" required minlength="2" name="new_matrix_token"/>
|
|
||||||
<small id="tokenHelp" class="form-text text-muted">Changing this value will reset all active
|
|
||||||
connections
|
|
||||||
to Matrix GW.</small>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<input type="submit" class="btn btn-primary" value="Update"/>
|
|
||||||
</form>
|
|
||||||
</div>
|
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- New client -->
|
||||||
|
<div class="card border-light mb-3">
|
||||||
|
<div class="card-header">New client</div>
|
||||||
|
<div class="card-body">
|
||||||
|
<form action="/" method="post">
|
||||||
|
<div>
|
||||||
|
<label for="new_client_desc" class="form-label">Description</label>
|
||||||
|
<input type="text" class="form-control" id="new_client_desc" required minlength="3"
|
||||||
|
aria-describedby="new_client_desc" placeholder="New client description..."
|
||||||
|
name="new_client_desc"/>
|
||||||
|
<small class="form-text text-muted">Client description helps with identification.</small>
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
<label for="ip_network" class="form-label">Allowed IP network</label>
|
||||||
|
<input type="text" class="form-control" id="ip_network" aria-describedby="ip_network"
|
||||||
|
placeholder="Client network (x.x.x.x/x or x:x:x:x:x:x/x" name="ip_network"/>
|
||||||
|
<small class="form-text text-muted">Restrict the networks this IP address can be used from.</small>
|
||||||
|
</div>
|
||||||
|
|
||||||
</body>
|
<br/>
|
||||||
</html>
|
|
||||||
|
<div class="form-check">
|
||||||
|
<input class="form-check-input" type="checkbox" value="" checked id="readonly_client"
|
||||||
|
name="readonly_client"/>
|
||||||
|
<label class="form-check-label" for="readonly_client">
|
||||||
|
Readonly client
|
||||||
|
</label>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<br/>
|
||||||
|
|
||||||
|
|
||||||
|
<input type="submit" class="btn btn-primary" value="Create client"/>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- Matrix authentication token -->
|
||||||
|
<div class="card border-light mb-3">
|
||||||
|
<div class="card-header">Matrix authentication token</div>
|
||||||
|
<div class="card-body">
|
||||||
|
<p>To obtain a new Matrix authentication token:</p>
|
||||||
|
<ol>
|
||||||
|
<li>Sign in to Element <strong>from a private browser window</strong></li>
|
||||||
|
<li>Open <em>All settings</em> and access the <em>Help & About</em> tag</li>
|
||||||
|
<li>Expand <em>Access Token</em> and copy the value</li>
|
||||||
|
<li>Paste the copied value below</li>
|
||||||
|
<li>Close the private browser window <strong>without signing out</strong>!</li>
|
||||||
|
</ol>
|
||||||
|
|
||||||
|
<p>You should not need to replace this value unless you explicitly signed out the associated browser
|
||||||
|
session.</p>
|
||||||
|
|
||||||
|
<p>Tip: you can rename the session to easily identify it among all your other sessions!</p>
|
||||||
|
|
||||||
|
<form action="/" method="post">
|
||||||
|
<div>
|
||||||
|
<label for="accessTokenInput" class="form-label mt-4">New Matrix access token</label>
|
||||||
|
<input type="text" class="form-control" id="accessTokenInput" aria-describedby="tokenHelp"
|
||||||
|
placeholder="{{ matrix_token }}" required minlength="2" name="new_matrix_token"/>
|
||||||
|
<small id="tokenHelp" class="form-text text-muted">Changing this value will reset all active
|
||||||
|
connections
|
||||||
|
to Matrix GW.</small>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<input type="submit" class="btn btn-primary" value="Update"/>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<script src="/assets/script.js"></script>
|
||||||
|
{% endblock content %}
|
||||||
46
templates/ws_debug.html
Normal file
46
templates/ws_debug.html
Normal file
@@ -0,0 +1,46 @@
|
|||||||
|
{% extends "base_page.html" %}
|
||||||
|
{% block content %}
|
||||||
|
|
||||||
|
<style>
|
||||||
|
#ws_actions {
|
||||||
|
margin: 30px;
|
||||||
|
border: 1px white solid;
|
||||||
|
padding: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
#ws_log {
|
||||||
|
margin: 30px;
|
||||||
|
border: 1px white solid;
|
||||||
|
padding: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
#ws_log .message {
|
||||||
|
display: flex;
|
||||||
|
margin-bottom: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
#ws_log .message .type {
|
||||||
|
font-style: italic;
|
||||||
|
margin-right: 10px;
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
|
||||||
|
|
||||||
|
<h2>WS Debug</h2>
|
||||||
|
|
||||||
|
<div id="ws_actions">
|
||||||
|
<button onclick="connect()">Reconnect</button>
|
||||||
|
<button onclick="disconnect()">Disconnect</button>
|
||||||
|
<button onclick="clearLogs()">Clear logs</button>
|
||||||
|
<span>State: <span id="state">DISCONNECTED</span></span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div id="ws_log">
|
||||||
|
<div class="message">
|
||||||
|
<div class="type">INFO</div>
|
||||||
|
<div>Welcome!</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<script src="/assets/ws_debug.js"></script>
|
||||||
|
{% endblock content %}
|
||||||
Reference in New Issue
Block a user