2021-02-22 17:27:13 +05:30
|
|
|
package upload
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
"context"
|
2022-08-13 15:12:31 +05:30
|
|
|
"errors"
|
2021-02-22 17:27:13 +05:30
|
|
|
"fmt"
|
2022-07-23 23:45:48 +05:30
|
|
|
"io"
|
2021-02-22 17:27:13 +05:30
|
|
|
"mime/multipart"
|
|
|
|
"net/http"
|
|
|
|
|
2022-05-07 20:08:51 +05:30
|
|
|
"github.com/golang-jwt/jwt/v4"
|
|
|
|
|
2021-10-27 15:23:28 +05:30
|
|
|
"gitlab.com/gitlab-org/gitlab/workhorse/internal/api"
|
2023-03-04 22:38:38 +05:30
|
|
|
"gitlab.com/gitlab-org/gitlab/workhorse/internal/helper/fail"
|
2022-05-07 20:08:51 +05:30
|
|
|
"gitlab.com/gitlab-org/gitlab/workhorse/internal/upload/destination"
|
2021-10-27 15:23:28 +05:30
|
|
|
"gitlab.com/gitlab-org/gitlab/workhorse/internal/upload/exif"
|
|
|
|
"gitlab.com/gitlab-org/gitlab/workhorse/internal/zipartifacts"
|
2021-02-22 17:27:13 +05:30
|
|
|
)
|
|
|
|
|
2022-05-07 20:08:51 +05:30
|
|
|
const RewrittenFieldsHeader = "Gitlab-Workhorse-Multipart-Fields"
|
|
|
|
|
|
|
|
type PreAuthorizer interface {
|
|
|
|
PreAuthorizeHandler(next api.HandleFunc, suffix string) http.Handler
|
|
|
|
}
|
|
|
|
|
|
|
|
type MultipartClaims struct {
|
|
|
|
RewrittenFields map[string]string `json:"rewritten_fields"`
|
2022-07-23 23:45:48 +05:30
|
|
|
jwt.RegisteredClaims
|
2022-05-07 20:08:51 +05:30
|
|
|
}
|
|
|
|
|
2022-04-04 11:22:00 +05:30
|
|
|
// MultipartFormProcessor abstracts away implementation differences
|
|
|
|
// between generic MIME multipart file uploads and CI artifact uploads.
|
2021-02-22 17:27:13 +05:30
|
|
|
type MultipartFormProcessor interface {
|
2022-05-07 20:08:51 +05:30
|
|
|
ProcessFile(ctx context.Context, formName string, file *destination.FileHandler, writer *multipart.Writer) error
|
2021-02-22 17:27:13 +05:30
|
|
|
ProcessField(ctx context.Context, formName string, writer *multipart.Writer) error
|
|
|
|
Finalize(ctx context.Context) error
|
|
|
|
Name() string
|
2021-10-29 20:43:33 +05:30
|
|
|
Count() int
|
2022-07-23 23:45:48 +05:30
|
|
|
TransformContents(ctx context.Context, filename string, r io.Reader) (io.ReadCloser, error)
|
2021-02-22 17:27:13 +05:30
|
|
|
}
|
|
|
|
|
2022-05-07 20:08:51 +05:30
|
|
|
// interceptMultipartFiles is the core of the implementation of
|
|
|
|
// Multipart.
|
2022-07-23 23:45:48 +05:30
|
|
|
func interceptMultipartFiles(w http.ResponseWriter, r *http.Request, h http.Handler, filter MultipartFormProcessor, fa fileAuthorizer, p Preparer) {
|
2021-02-22 17:27:13 +05:30
|
|
|
var body bytes.Buffer
|
|
|
|
writer := multipart.NewWriter(&body)
|
|
|
|
defer writer.Close()
|
|
|
|
|
|
|
|
// Rewrite multipart form data
|
2022-07-23 23:45:48 +05:30
|
|
|
err := rewriteFormFilesFromMultipart(r, writer, filter, fa, p)
|
2021-02-22 17:27:13 +05:30
|
|
|
if err != nil {
|
|
|
|
switch err {
|
|
|
|
case http.ErrNotMultipart:
|
|
|
|
h.ServeHTTP(w, r)
|
2023-03-04 22:38:38 +05:30
|
|
|
case ErrInjectedClientParam, http.ErrMissingBoundary:
|
|
|
|
fail.Request(w, r, err, fail.WithStatus(http.StatusBadRequest))
|
|
|
|
case ErrTooManyFilesUploaded:
|
|
|
|
fail.Request(w, r, err, fail.WithStatus(http.StatusBadRequest), fail.WithBody(err.Error()))
|
|
|
|
case destination.ErrEntityTooLarge, zipartifacts.ErrBadMetadata:
|
|
|
|
fail.Request(w, r, err, fail.WithStatus(http.StatusRequestEntityTooLarge))
|
2021-02-22 17:27:13 +05:30
|
|
|
case exif.ErrRemovingExif:
|
2023-03-04 22:38:38 +05:30
|
|
|
fail.Request(w, r, err, fail.WithStatus(http.StatusUnprocessableEntity),
|
|
|
|
fail.WithBody("Failed to process image"))
|
2021-02-22 17:27:13 +05:30
|
|
|
default:
|
2022-08-13 15:12:31 +05:30
|
|
|
if errors.Is(err, context.DeadlineExceeded) {
|
2023-03-04 22:38:38 +05:30
|
|
|
fail.Request(w, r, err, fail.WithStatus(http.StatusGatewayTimeout),
|
|
|
|
fail.WithBody("deadline exceeded"))
|
2022-08-13 15:12:31 +05:30
|
|
|
} else {
|
2023-03-04 22:38:38 +05:30
|
|
|
fail.Request(w, r, fmt.Errorf("handleFileUploads: extract files from multipart: %v", err))
|
2022-08-13 15:12:31 +05:30
|
|
|
}
|
2021-02-22 17:27:13 +05:30
|
|
|
}
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Close writer
|
|
|
|
writer.Close()
|
|
|
|
|
|
|
|
// Hijack the request
|
2022-07-23 23:45:48 +05:30
|
|
|
r.Body = io.NopCloser(&body)
|
2021-02-22 17:27:13 +05:30
|
|
|
r.ContentLength = int64(body.Len())
|
|
|
|
r.Header.Set("Content-Type", writer.FormDataContentType())
|
|
|
|
|
|
|
|
if err := filter.Finalize(r.Context()); err != nil {
|
2023-03-04 22:38:38 +05:30
|
|
|
fail.Request(w, r, fmt.Errorf("handleFileUploads: Finalize: %v", err))
|
2021-02-22 17:27:13 +05:30
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Proxy the request
|
|
|
|
h.ServeHTTP(w, r)
|
|
|
|
}
|