|
| 1 | +// Copyright 2021 The Gitea Authors. All rights reserved. |
| 2 | +// SPDX-License-Identifier: MIT |
| 3 | + |
| 4 | +package terraform |
| 5 | + |
| 6 | +import ( |
| 7 | + "code.gitea.io/gitea/modules/globallock" |
| 8 | + "errors" |
| 9 | + "fmt" |
| 10 | + "net/http" |
| 11 | + "regexp" |
| 12 | + "strings" |
| 13 | + "unicode" |
| 14 | + |
| 15 | + packages_model "code.gitea.io/gitea/models/packages" |
| 16 | + "code.gitea.io/gitea/modules/log" |
| 17 | + packages_module "code.gitea.io/gitea/modules/packages" |
| 18 | + "code.gitea.io/gitea/routers/api/packages/helper" |
| 19 | + "code.gitea.io/gitea/services/context" |
| 20 | + packages_service "code.gitea.io/gitea/services/packages" |
| 21 | +) |
| 22 | + |
| 23 | +var ( |
| 24 | + packageNameRegex = regexp.MustCompile(`\A[-_+.\w]+\z`) |
| 25 | + filenameRegex = regexp.MustCompile(`\A[-_+=:;.()\[\]{}~!@#$%^& \w]+\z`) |
| 26 | + lockRelease globallock.ReleaseFunc = nil |
| 27 | +) |
| 28 | + |
| 29 | +func apiError(ctx *context.Context, status int, obj any) { |
| 30 | + helper.LogAndProcessError(ctx, status, obj, func(message string) { |
| 31 | + ctx.PlainText(status, message) |
| 32 | + }) |
| 33 | +} |
| 34 | + |
| 35 | +// DownloadPackageFile serves the specific terraform package. |
| 36 | +func DownloadPackageFile(ctx *context.Context) { |
| 37 | + s, u, pf, err := packages_service.GetFileStreamByPackageNameAndVersion( |
| 38 | + ctx, |
| 39 | + &packages_service.PackageInfo{ |
| 40 | + Owner: ctx.Package.Owner, |
| 41 | + PackageType: packages_model.TypeTerraform, |
| 42 | + Name: ctx.PathParam("packagename"), |
| 43 | + Version: ctx.PathParam("filename"), |
| 44 | + }, |
| 45 | + &packages_service.PackageFileInfo{ |
| 46 | + Filename: "tfstate", |
| 47 | + // CompositeKey: "state", |
| 48 | + }, |
| 49 | + ) |
| 50 | + if err != nil { |
| 51 | + if errors.Is(err, packages_model.ErrPackageNotExist) || errors.Is(err, packages_model.ErrPackageFileNotExist) { |
| 52 | + apiError(ctx, http.StatusNotFound, err) |
| 53 | + return |
| 54 | + } |
| 55 | + apiError(ctx, http.StatusInternalServerError, err) |
| 56 | + return |
| 57 | + } |
| 58 | + |
| 59 | + helper.ServePackageFile(ctx, s, u, pf) |
| 60 | +} |
| 61 | + |
| 62 | +func isValidPackageName(packageName string) bool { |
| 63 | + if len(packageName) == 1 && !unicode.IsLetter(rune(packageName[0])) && !unicode.IsNumber(rune(packageName[0])) { |
| 64 | + return false |
| 65 | + } |
| 66 | + return packageNameRegex.MatchString(packageName) && packageName != ".." |
| 67 | +} |
| 68 | + |
| 69 | +func isValidFileName(filename string) bool { |
| 70 | + return filenameRegex.MatchString(filename) && |
| 71 | + strings.TrimSpace(filename) == filename && |
| 72 | + filename != "." && filename != ".." |
| 73 | +} |
| 74 | + |
| 75 | +// UploadPackage uploads the specific terraform package. |
| 76 | +func UploadPackage(ctx *context.Context) { |
| 77 | + packageName := ctx.PathParam("packagename") |
| 78 | + filename := ctx.PathParam("filename") |
| 79 | + |
| 80 | + if !isValidPackageName(packageName) { |
| 81 | + apiError(ctx, http.StatusBadRequest, errors.New("invalid package name")) |
| 82 | + return |
| 83 | + } |
| 84 | + |
| 85 | + if !isValidFileName(filename) { |
| 86 | + apiError(ctx, http.StatusBadRequest, errors.New("invalid filename")) |
| 87 | + return |
| 88 | + } |
| 89 | + |
| 90 | + upload, needToClose, err := ctx.UploadStream() |
| 91 | + if err != nil { |
| 92 | + apiError(ctx, http.StatusInternalServerError, err) |
| 93 | + return |
| 94 | + } |
| 95 | + if needToClose { |
| 96 | + defer upload.Close() |
| 97 | + } |
| 98 | + |
| 99 | + buf, err := packages_module.CreateHashedBufferFromReader(upload) |
| 100 | + if err != nil { |
| 101 | + log.Error("Error creating hashed buffer: %v", err) |
| 102 | + apiError(ctx, http.StatusInternalServerError, err) |
| 103 | + return |
| 104 | + } |
| 105 | + defer buf.Close() |
| 106 | + |
| 107 | + _, _, err = packages_service.CreatePackageOrAddFileToExisting( |
| 108 | + ctx, |
| 109 | + &packages_service.PackageCreationInfo{ |
| 110 | + PackageInfo: packages_service.PackageInfo{ |
| 111 | + Owner: ctx.Package.Owner, |
| 112 | + PackageType: packages_model.TypeTerraform, |
| 113 | + Name: packageName, |
| 114 | + Version: filename, |
| 115 | + }, |
| 116 | + Creator: ctx.Doer, |
| 117 | + }, |
| 118 | + &packages_service.PackageFileCreationInfo{ |
| 119 | + PackageFileInfo: packages_service.PackageFileInfo{ |
| 120 | + Filename: "tfstate", |
| 121 | + }, |
| 122 | + Creator: ctx.Doer, |
| 123 | + Data: buf, |
| 124 | + IsLead: true, |
| 125 | + OverwriteExisting: true, |
| 126 | + }, |
| 127 | + ) |
| 128 | + if err != nil { |
| 129 | + switch err { |
| 130 | + case packages_model.ErrDuplicatePackageFile: |
| 131 | + apiError(ctx, http.StatusConflict, err) |
| 132 | + case packages_service.ErrQuotaTotalCount, packages_service.ErrQuotaTypeSize, packages_service.ErrQuotaTotalSize: |
| 133 | + apiError(ctx, http.StatusForbidden, err) |
| 134 | + default: |
| 135 | + apiError(ctx, http.StatusInternalServerError, err) |
| 136 | + } |
| 137 | + return |
| 138 | + } |
| 139 | + |
| 140 | + ctx.Status(http.StatusCreated) |
| 141 | +} |
| 142 | + |
| 143 | +// DeletePackage deletes the specific terraform package. |
| 144 | +func DeletePackage(ctx *context.Context) { |
| 145 | + err := packages_service.RemovePackageVersionByNameAndVersion( |
| 146 | + ctx, |
| 147 | + ctx.Doer, |
| 148 | + &packages_service.PackageInfo{ |
| 149 | + Owner: ctx.Package.Owner, |
| 150 | + PackageType: packages_model.TypeTerraform, |
| 151 | + Name: ctx.PathParam("packagename"), |
| 152 | + // Version: ctx.PathParam("filename"), |
| 153 | + }, |
| 154 | + ) |
| 155 | + if err != nil { |
| 156 | + if errors.Is(err, packages_model.ErrPackageNotExist) { |
| 157 | + apiError(ctx, http.StatusNotFound, err) |
| 158 | + return |
| 159 | + } |
| 160 | + apiError(ctx, http.StatusInternalServerError, err) |
| 161 | + return |
| 162 | + } |
| 163 | + |
| 164 | + ctx.Status(http.StatusNoContent) |
| 165 | +} |
| 166 | + |
| 167 | +// DeletePackageFile deletes the specific file of a terraform package. |
| 168 | +func DeletePackageFile(ctx *context.Context) { |
| 169 | + pv, pf, err := func() (*packages_model.PackageVersion, *packages_model.PackageFile, error) { |
| 170 | + pv, err := packages_model.GetVersionByNameAndVersion(ctx, ctx.Package.Owner.ID, packages_model.TypeTerraform, ctx.PathParam("packagename"), ctx.PathParam("filename")) |
| 171 | + if err != nil { |
| 172 | + return nil, nil, err |
| 173 | + } |
| 174 | + |
| 175 | + pf, err := packages_model.GetFileForVersionByName(ctx, pv.ID, "tfstate", packages_model.EmptyFileKey) |
| 176 | + if err != nil { |
| 177 | + return nil, nil, err |
| 178 | + } |
| 179 | + |
| 180 | + return pv, pf, nil |
| 181 | + }() |
| 182 | + if err != nil { |
| 183 | + if errors.Is(err, packages_model.ErrPackageNotExist) || errors.Is(err, packages_model.ErrPackageFileNotExist) { |
| 184 | + apiError(ctx, http.StatusNotFound, err) |
| 185 | + return |
| 186 | + } |
| 187 | + apiError(ctx, http.StatusInternalServerError, err) |
| 188 | + return |
| 189 | + } |
| 190 | + |
| 191 | + pfs, err := packages_model.GetFilesByVersionID(ctx, pv.ID) |
| 192 | + if err != nil { |
| 193 | + apiError(ctx, http.StatusInternalServerError, err) |
| 194 | + return |
| 195 | + } |
| 196 | + |
| 197 | + if len(pfs) == 1 { |
| 198 | + if err := packages_service.RemovePackageVersion(ctx, ctx.Doer, pv); err != nil { |
| 199 | + apiError(ctx, http.StatusInternalServerError, err) |
| 200 | + return |
| 201 | + } |
| 202 | + } else { |
| 203 | + if err := packages_service.DeletePackageFile(ctx, pf); err != nil { |
| 204 | + apiError(ctx, http.StatusInternalServerError, err) |
| 205 | + return |
| 206 | + } |
| 207 | + } |
| 208 | + |
| 209 | + ctx.Status(http.StatusNoContent) |
| 210 | +} |
0 commit comments