external.agi.go 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209
  1. package agi
  2. import (
  3. "encoding/json"
  4. "io/ioutil"
  5. "log"
  6. "net/http"
  7. "path/filepath"
  8. "strings"
  9. "time"
  10. "github.com/google/uuid"
  11. "imuslab.com/arozos/mod/common"
  12. )
  13. type endpointFormat struct {
  14. Username string `json:"username"`
  15. Path string `json:"path"`
  16. }
  17. //Handle request from EXTERNAL RESTFUL API
  18. func (g *Gateway) ExtAPIHandler(w http.ResponseWriter, r *http.Request) {
  19. // get db
  20. sysdb := g.Option.UserHandler.GetDatabase()
  21. if !sysdb.TableExists("external_agi") {
  22. common.SendErrorResponse(w, "Bad Request, invaild database")
  23. return
  24. }
  25. // get the request URI from the r.URL
  26. requestURI := filepath.ToSlash(filepath.Clean(r.URL.Path))
  27. subpathElements := strings.Split(requestURI[1:], "/")
  28. // check if it contains only two part, [rexec uuid]
  29. if len(subpathElements) != 3 {
  30. common.SendErrorResponse(w, "Bad Request, invaild request sent")
  31. return
  32. }
  33. // check if UUID exists in the database
  34. // get the info from the database
  35. data, isExist := g.checkIfExternalEndpointExist(subpathElements[2])
  36. if !isExist {
  37. common.SendErrorResponse(w, "Bad Request, invaild UUID entered")
  38. return
  39. }
  40. usernameFromDb := data.Username
  41. pathFromDb := data.Path
  42. // get the userinfo and the realPath
  43. userInfo, err := g.Option.UserHandler.GetUserInfoFromUsername(usernameFromDb)
  44. if err != nil {
  45. common.SendErrorResponse(w, "Bad username")
  46. return
  47. }
  48. _, realPath, err := virtualPathToRealPath(pathFromDb, userInfo)
  49. if err != nil {
  50. common.SendErrorResponse(w, "Bad filepath")
  51. return
  52. }
  53. // read the file and store it into scriptContent
  54. scriptContentByte, err := ioutil.ReadFile(realPath)
  55. if err != nil {
  56. common.SendErrorResponse(w, "Bad file I/O")
  57. return
  58. }
  59. scriptContent := string(scriptContentByte)
  60. // execute!
  61. start := time.Now()
  62. g.ExecuteAGIScript(scriptContent, "", "", w, r, userInfo)
  63. duration := time.Since(start)
  64. log.Println("[Remote AGI] IP:", r.RemoteAddr, " executed the script ", pathFromDb, "(", realPath, ")", " on behalf of", userInfo.Username, "with total duration: ", duration)
  65. }
  66. func (g *Gateway) AddExternalEndPoint(w http.ResponseWriter, r *http.Request) {
  67. userInfo, err := g.Option.UserHandler.GetUserInfoFromRequest(w, r)
  68. if err != nil {
  69. common.SendErrorResponse(w, "Bad user!")
  70. return
  71. }
  72. // get db
  73. sysdb := g.Option.UserHandler.GetDatabase()
  74. if !sysdb.TableExists("external_agi") {
  75. sysdb.NewTable("external_agi")
  76. }
  77. var dat endpointFormat
  78. // uuid: [path, id]
  79. path, err := common.Mv(r, "path", false)
  80. if err != nil {
  81. common.SendErrorResponse(w, "Bad parameter")
  82. return
  83. }
  84. id := uuid.New().String()
  85. dat.Path = path
  86. dat.Username = userInfo.Username
  87. jsonStr, err := json.Marshal(dat)
  88. if err != nil {
  89. common.SendErrorResponse(w, "Bad JSON")
  90. return
  91. }
  92. sysdb.Write("external_agi", id, string(jsonStr))
  93. common.SendJSONResponse(w, "\""+id+"\"")
  94. }
  95. func (g *Gateway) RemoveExternalEndPoint(w http.ResponseWriter, r *http.Request) {
  96. userInfo, err := g.Option.UserHandler.GetUserInfoFromRequest(w, r)
  97. if err != nil {
  98. common.SendErrorResponse(w, "Bad User")
  99. return
  100. }
  101. // get db
  102. sysdb := g.Option.UserHandler.GetDatabase()
  103. if !sysdb.TableExists("external_agi") {
  104. sysdb.NewTable("external_agi")
  105. }
  106. // get path
  107. uuid, err := common.Mv(r, "uuid", false)
  108. if err != nil {
  109. common.SendErrorResponse(w, "Bad parameter")
  110. return
  111. }
  112. data, isExist := g.checkIfExternalEndpointExist(uuid)
  113. if !isExist {
  114. common.SendErrorResponse(w, "UUID does not exists in the database!")
  115. return
  116. }
  117. if data.Username != userInfo.Username {
  118. common.SendErrorResponse(w, "Bad Request, you have no permission to access this UUID entry!")
  119. return
  120. }
  121. sysdb.Delete("external_agi", uuid)
  122. common.SendOK(w)
  123. }
  124. func (g *Gateway) ListExternalEndpoint(w http.ResponseWriter, r *http.Request) {
  125. userInfo, err := g.Option.UserHandler.GetUserInfoFromRequest(w, r)
  126. if err != nil {
  127. common.SendErrorResponse(w, "Bad User")
  128. return
  129. }
  130. // get db
  131. sysdb := g.Option.UserHandler.GetDatabase()
  132. if !sysdb.TableExists("external_agi") {
  133. sysdb.NewTable("external_agi")
  134. }
  135. // declare variable for return
  136. dataFromDB := make(map[string]endpointFormat)
  137. // O(n) method to do the lookup
  138. entries, err := sysdb.ListTable("external_agi")
  139. if err != nil {
  140. common.SendErrorResponse(w, "Bad table")
  141. return
  142. }
  143. for _, keypairs := range entries {
  144. //Decode the string
  145. var dataFromResult endpointFormat
  146. result := ""
  147. uuid := string(keypairs[0])
  148. json.Unmarshal(keypairs[1], &result)
  149. //fmt.Println(result)
  150. json.Unmarshal([]byte(result), &dataFromResult)
  151. if dataFromResult.Username == userInfo.Username {
  152. dataFromDB[uuid] = dataFromResult
  153. }
  154. }
  155. returnJson, err := json.Marshal(dataFromDB)
  156. if err != nil {
  157. common.SendErrorResponse(w, "Bad JSON")
  158. return
  159. }
  160. sendJSONResponse(w, string(returnJson))
  161. }
  162. func (g *Gateway) checkIfExternalEndpointExist(uuid string) (endpointFormat, bool) {
  163. // get db
  164. sysdb := g.Option.UserHandler.GetDatabase()
  165. if !sysdb.TableExists("external_agi") {
  166. sysdb.NewTable("external_agi")
  167. }
  168. var dat endpointFormat
  169. if !sysdb.KeyExists("external_agi", uuid) {
  170. return dat, false
  171. }
  172. jsonData := ""
  173. sysdb.Read("external_agi", uuid, &jsonData)
  174. json.Unmarshal([]byte(jsonData), &dat)
  175. return dat, true
  176. }