weblib/remlib: white/black lists: allow sources with /
[fanfix.git] / src / be / nikiroo / fanfix / library / WebLibraryServer.java
CommitLineData
f433d153
NR
1package be.nikiroo.fanfix.library;
2
3import java.io.ByteArrayInputStream;
f433d153
NR
4import java.io.IOException;
5import java.io.InputStream;
f433d153 6import java.util.ArrayList;
5c4ce687 7import java.util.Arrays;
f433d153
NR
8import java.util.HashMap;
9import java.util.LinkedList;
10import java.util.List;
11import java.util.Map;
12
f433d153
NR
13import org.json.JSONArray;
14import org.json.JSONObject;
15
16import be.nikiroo.fanfix.Instance;
17import be.nikiroo.fanfix.bundles.Config;
f433d153
NR
18import be.nikiroo.fanfix.data.Chapter;
19import be.nikiroo.fanfix.data.JsonIO;
20import be.nikiroo.fanfix.data.MetaData;
21import be.nikiroo.fanfix.data.Paragraph;
22import be.nikiroo.fanfix.data.Paragraph.ParagraphType;
23import be.nikiroo.fanfix.data.Story;
f433d153 24import be.nikiroo.utils.Image;
fce0a73f 25import be.nikiroo.utils.LoginResult;
f433d153 26import be.nikiroo.utils.NanoHTTPD;
f433d153
NR
27import be.nikiroo.utils.NanoHTTPD.Response;
28import be.nikiroo.utils.NanoHTTPD.Response.Status;
f433d153 29
33d40b9f
NR
30public class WebLibraryServer extends WebLibraryServerHtml {
31 class WLoginResult extends LoginResult {
f433d153
NR
32 private boolean rw;
33 private boolean wl;
d11fb35b 34 private boolean bl;
fce0a73f
NR
35
36 public WLoginResult(boolean badLogin, boolean badCookie) {
37 super(badLogin, badCookie);
38 }
39
40 public WLoginResult(String who, String key, String subkey, boolean rw,
41 boolean wl, boolean bl) {
42 super(who, key, subkey, (rw ? "|rw" : "") + (wl ? "|wl" : "")
43 + (bl ? "|bl" : "") + "|");
f433d153
NR
44 this.rw = rw;
45 this.wl = wl;
d11fb35b 46 this.bl = bl;
f433d153
NR
47 }
48
fce0a73f 49 public WLoginResult(String cookie, String who, String key,
f433d153 50 List<String> subkeys) {
fce0a73f
NR
51 super(cookie, who, key, subkeys,
52 subkeys == null || subkeys.isEmpty());
f433d153
NR
53 }
54
55 public boolean isRw() {
fce0a73f 56 return getOption().contains("|rw|");
f433d153
NR
57 }
58
59 public boolean isWl() {
fce0a73f 60 return getOption().contains("|wl|");
f433d153
NR
61 }
62
d11fb35b 63 public boolean isBl() {
fce0a73f 64 return getOption().contains("|bl|");
f433d153
NR
65 }
66 }
67
f433d153
NR
68 private Map<String, Story> storyCache = new HashMap<String, Story>();
69 private LinkedList<String> storyCacheOrder = new LinkedList<String>();
70 private long storyCacheSize = 0;
71 private long maxStoryCacheSize;
f433d153 72
d11fb35b
NR
73 private List<String> whitelist;
74 private List<String> blacklist;
75
f433d153 76 public WebLibraryServer(boolean secure) throws IOException {
33d40b9f 77 super(secure);
f433d153
NR
78
79 int cacheMb = Instance.getInstance().getConfig()
80 .getInteger(Config.SERVER_MAX_CACHE_MB, 100);
81 maxStoryCacheSize = cacheMb * 1024 * 1024;
82
83 setTraceHandler(Instance.getInstance().getTraceHandler());
84
d11fb35b
NR
85 whitelist = Instance.getInstance().getConfig()
86 .getList(Config.SERVER_WHITELIST, new ArrayList<String>());
87 blacklist = Instance.getInstance().getConfig()
88 .getList(Config.SERVER_BLACKLIST, new ArrayList<String>());
f433d153
NR
89 }
90
91 /**
92 * Start the server (listen on the network for new connections).
93 * <p>
94 * Can only be called once.
95 * <p>
96 * This call is asynchronous, and will just start a new {@link Thread} on
97 * itself (see {@link WebLibraryServer#run()}).
98 */
99 public void start() {
100 new Thread(this).start();
101 }
102
33d40b9f
NR
103 @Override
104 protected WLoginResult login(boolean badLogin, boolean badCookie) {
105 return new WLoginResult(false, false);
f433d153
NR
106 }
107
33d40b9f
NR
108 @Override
109 protected WLoginResult login(String who, String cookie) {
fce0a73f
NR
110 List<String> subkeys = Instance.getInstance().getConfig()
111 .getList(Config.SERVER_ALLOWED_SUBKEYS);
f433d153 112 String realKey = Instance.getInstance().getConfig()
fce0a73f 113 .getString(Config.SERVER_KEY);
d11fb35b 114
fce0a73f 115 return new WLoginResult(cookie, who, realKey, subkeys);
f433d153
NR
116 }
117
118 // allow rw/wl
33d40b9f
NR
119 @Override
120 protected WLoginResult login(String who, String key, String subkey) {
f433d153 121 String realKey = Instance.getInstance().getConfig()
d11fb35b 122 .getString(Config.SERVER_KEY, "");
f433d153
NR
123
124 // I don't like NULLs...
f433d153
NR
125 key = key == null ? "" : key;
126 subkey = subkey == null ? "" : subkey;
127
128 if (!realKey.equals(key)) {
fce0a73f 129 return new WLoginResult(true, false);
f433d153
NR
130 }
131
d11fb35b 132 // defaults are true (as previous versions without the feature)
f433d153
NR
133 boolean rw = true;
134 boolean wl = true;
d11fb35b 135 boolean bl = true;
f433d153 136
599b05c7
NR
137 rw = Instance.getInstance().getConfig().getBoolean(Config.SERVER_RW,
138 rw);
fce0a73f
NR
139
140 List<String> allowed = Instance.getInstance().getConfig().getList(
141 Config.SERVER_ALLOWED_SUBKEYS, new ArrayList<String>());
142
143 if (!allowed.isEmpty()) {
144 if (!allowed.contains(subkey)) {
145 return new WLoginResult(true, false);
146 }
147
148 if ((subkey + "|").contains("|rw|")) {
149 rw = true;
150 }
151 if ((subkey + "|").contains("|wl|")) {
152 wl = false; // |wl| = bypass whitelist
153 }
154 if ((subkey + "|").contains("|bl|")) {
155 bl = false; // |bl| = bypass blacklist
f433d153
NR
156 }
157 }
158
fce0a73f 159 return new WLoginResult(who, key, subkey, rw, wl, bl);
f433d153
NR
160 }
161
33d40b9f 162 @Override
fce0a73f 163 protected Response getList(String uri, WLoginResult login)
f433d153 164 throws IOException {
5ee0fc14 165 if (WebLibraryUrls.LIST_URL_METADATA.equals(uri)) {
f433d153 166 List<JSONObject> jsons = new ArrayList<JSONObject>();
d11fb35b 167 for (MetaData meta : metas(login)) {
f433d153
NR
168 jsons.add(JsonIO.toJson(meta));
169 }
170
171 return newInputStreamResponse("application/json",
599b05c7
NR
172 new ByteArrayInputStream(
173 new JSONArray(jsons).toString().getBytes()));
f433d153
NR
174 }
175
176 return NanoHTTPD.newFixedLengthResponse(Status.BAD_REQUEST,
177 NanoHTTPD.MIME_PLAINTEXT, null);
178 }
179
f433d153
NR
180 // /story/luid/chapter/para <-- text/image
181 // /story/luid/cover <-- image
182 // /story/luid/metadata <-- json
c5103223 183 // /story/luid/json <-- json, whole chapter (no images)
33d40b9f
NR
184 @Override
185 protected Response getStoryPart(String uri, WLoginResult login) {
f433d153
NR
186 String[] cover = uri.split("/");
187 int off = 2;
188
189 if (cover.length < off + 2) {
190 return NanoHTTPD.newFixedLengthResponse(Status.BAD_REQUEST,
191 NanoHTTPD.MIME_PLAINTEXT, null);
192 }
193
194 String luid = cover[off + 0];
195 String chapterStr = cover[off + 1];
196 String imageStr = cover.length < off + 3 ? null : cover[off + 2];
197
198 // 1-based (0 = desc)
199 int chapter = 0;
200 if (chapterStr != null && !"cover".equals(chapterStr)
599b05c7
NR
201 && !"metadata".equals(chapterStr)
202 && !"json".equals(chapterStr)) {
f433d153
NR
203 try {
204 chapter = Integer.parseInt(chapterStr);
205 if (chapter < 0) {
206 throw new NumberFormatException();
207 }
208 } catch (NumberFormatException e) {
209 return NanoHTTPD.newFixedLengthResponse(Status.BAD_REQUEST,
210 NanoHTTPD.MIME_PLAINTEXT, "Chapter is not valid");
211 }
212 }
213
214 // 1-based
215 int paragraph = 1;
216 if (imageStr != null) {
217 try {
218 paragraph = Integer.parseInt(imageStr);
219 if (paragraph < 0) {
220 throw new NumberFormatException();
221 }
222 } catch (NumberFormatException e) {
223 return NanoHTTPD.newFixedLengthResponse(Status.BAD_REQUEST,
224 NanoHTTPD.MIME_PLAINTEXT, "Paragraph is not valid");
225 }
226 }
227
228 String mimeType = NanoHTTPD.MIME_PLAINTEXT;
229 InputStream in = null;
230 try {
231 if ("cover".equals(chapterStr)) {
33d40b9f 232 Image img = cover(luid, login);
f433d153
NR
233 if (img != null) {
234 in = img.newInputStream();
235 }
3f468ac7
NR
236 // TODO: get correct image type
237 mimeType = "image/png";
f433d153 238 } else if ("metadata".equals(chapterStr)) {
d11fb35b 239 MetaData meta = meta(luid, login);
f433d153
NR
240 JSONObject json = JsonIO.toJson(meta);
241 mimeType = "application/json";
242 in = new ByteArrayInputStream(json.toString().getBytes());
3fbc084c 243 } else if ("json".equals(chapterStr)) {
d11fb35b 244 Story story = story(luid, login);
c5103223
NR
245 JSONObject json = JsonIO.toJson(story);
246 mimeType = "application/json";
247 in = new ByteArrayInputStream(json.toString().getBytes());
f433d153 248 } else {
d11fb35b 249 Story story = story(luid, login);
f433d153
NR
250 if (story != null) {
251 if (chapter == 0) {
252 StringBuilder builder = new StringBuilder();
253 for (Paragraph p : story.getMeta().getResume()) {
254 if (builder.length() == 0) {
255 builder.append("\n");
256 }
257 builder.append(p.getContent());
258 }
259
599b05c7
NR
260 in = new ByteArrayInputStream(
261 builder.toString().getBytes("utf-8"));
f433d153
NR
262 } else {
263 Paragraph para = story.getChapters().get(chapter - 1)
264 .getParagraphs().get(paragraph - 1);
265 Image img = para.getContentImage();
266 if (para.getType() == ParagraphType.IMAGE) {
267 // TODO: get correct image type
268 mimeType = "image/png";
269 in = img.newInputStream();
270 } else {
599b05c7
NR
271 in = new ByteArrayInputStream(
272 para.getContent().getBytes("utf-8"));
f433d153
NR
273 }
274 }
275 }
276 }
277 } catch (IndexOutOfBoundsException e) {
278 return NanoHTTPD.newFixedLengthResponse(Status.NOT_FOUND,
279 NanoHTTPD.MIME_PLAINTEXT,
280 "Chapter or paragraph does not exist");
281 } catch (IOException e) {
282 Instance.getInstance().getTraceHandler()
283 .error(new IOException("Cannot get image: " + uri, e));
284 return NanoHTTPD.newFixedLengthResponse(Status.INTERNAL_ERROR,
285 NanoHTTPD.MIME_PLAINTEXT, "Error when processing request");
286 }
287
288 return newInputStreamResponse(mimeType, in);
289 }
290
33d40b9f
NR
291 @Override
292 protected List<MetaData> metas(WLoginResult login) throws IOException {
d11fb35b
NR
293 BasicLibrary lib = Instance.getInstance().getLibrary();
294 List<MetaData> metas = new ArrayList<MetaData>();
295 for (MetaData meta : lib.getList().getMetas()) {
296 if (isAllowed(meta, login)) {
297 metas.add(meta);
298 }
299 }
300
301 return metas;
302 }
303
f433d153 304 // NULL if not whitelist OK or if not found
33d40b9f
NR
305 @Override
306 protected Story story(String luid, WLoginResult login) throws IOException {
f433d153
NR
307 synchronized (storyCache) {
308 if (storyCache.containsKey(luid)) {
309 Story story = storyCache.get(luid);
d11fb35b 310 if (!isAllowed(story.getMeta(), login))
f433d153 311 return null;
f433d153
NR
312
313 return story;
314 }
315 }
316
317 Story story = null;
d11fb35b 318 MetaData meta = meta(luid, login);
f433d153
NR
319 if (meta != null) {
320 BasicLibrary lib = Instance.getInstance().getLibrary();
321 story = lib.getStory(luid, null);
322 long size = sizeOf(story);
323
324 synchronized (storyCache) {
325 // Could have been added by another request
326 if (!storyCache.containsKey(luid)) {
327 while (!storyCacheOrder.isEmpty()
328 && storyCacheSize + size > maxStoryCacheSize) {
329 String oldestLuid = storyCacheOrder.removeFirst();
330 Story oldestStory = storyCache.remove(oldestLuid);
331 maxStoryCacheSize -= sizeOf(oldestStory);
332 }
333
334 storyCacheOrder.add(luid);
335 storyCache.put(luid, story);
336 }
337 }
338 }
339
340 return story;
341 }
342
33d40b9f
NR
343 private MetaData meta(String luid, WLoginResult login) throws IOException {
344 BasicLibrary lib = Instance.getInstance().getLibrary();
345 MetaData meta = lib.getInfo(luid);
346 if (!isAllowed(meta, login))
347 return null;
f433d153 348
33d40b9f 349 return meta;
f433d153
NR
350 }
351
33d40b9f
NR
352 private Image cover(String luid, WLoginResult login) throws IOException {
353 MetaData meta = meta(luid, login);
354 if (meta != null) {
355 BasicLibrary lib = Instance.getInstance().getLibrary();
356 return lib.getCover(meta.getLuid());
f433d153 357 }
f433d153 358
33d40b9f 359 return null;
f433d153
NR
360 }
361
33d40b9f 362 private boolean isAllowed(MetaData meta, WLoginResult login) {
5c4ce687
NR
363 MetaResultList one = new MetaResultList(Arrays.asList(meta));
364 if (login.isWl() && !whitelist.isEmpty()) {
365 if (one.filter(whitelist, null, null).isEmpty()) {
366 return false;
367 }
f433d153 368 }
5c4ce687
NR
369 if (login.isBl() && !blacklist.isEmpty()) {
370 if (!one.filter(blacklist, null, null).isEmpty()) {
371 return false;
372 }
599b05c7
NR
373 }
374
33d40b9f 375 return true;
599b05c7
NR
376 }
377
33d40b9f
NR
378 private long sizeOf(Story story) {
379 long size = 0;
380 for (Chapter chap : story) {
381 for (Paragraph para : chap) {
382 if (para.getType() == ParagraphType.IMAGE) {
383 size += para.getContentImage().getSize();
384 } else {
385 size += para.getContent().length();
386 }
387 }
6b89e45c
NR
388 }
389
33d40b9f 390 return size;
6b89e45c
NR
391 }
392
3fbc084c
NR
393 public static void main(String[] args) throws IOException {
394 Instance.init();
395 WebLibraryServer web = new WebLibraryServer(false);
396 web.run();
397 }
f433d153 398}