fix lib
[fanfix.git] / src / be / nikiroo / fanfix / library / RemoteLibraryServer.java
index d73943831144add2b16bd4edfeaf35cd9c43d94d..015fb7bf33c9c2beb79a81173b1f02f180f48db9 100644 (file)
@@ -2,11 +2,17 @@ package be.nikiroo.fanfix.library;
 
 import java.io.IOException;
 import java.net.URL;
+import java.nio.file.AccessDeniedException;
 import java.util.ArrayList;
 import java.util.Date;
+import java.util.HashMap;
 import java.util.List;
+import java.util.Map;
+
+import javax.net.ssl.SSLException;
 
 import be.nikiroo.fanfix.Instance;
+import be.nikiroo.fanfix.bundles.Config;
 import be.nikiroo.fanfix.data.Chapter;
 import be.nikiroo.fanfix.data.MetaData;
 import be.nikiroo.fanfix.data.Paragraph;
@@ -19,45 +25,51 @@ import be.nikiroo.utils.serial.server.ConnectActionServerObject;
 import be.nikiroo.utils.serial.server.ServerObject;
 
 /**
- * Create a new remote server that will listen for order on the given port.
+ * Create a new remote server that will listen for orders on the given port.
+ * <p>
+ * The available commands are given as arrays of objects (first item is the
+ * command, the rest are the arguments).
  * <p>
- * The available commands are given as arrays of objects (first item is the key,
- * second is the command, the rest are the arguments).
+ * All the commands are always prefixed by the subkey (which can be EMPTY if
+ * none).
  * <p>
- * The md5 is always a String (the MD5 hash of the access key), the commands are
- * also Strings; the parameters vary depending upon the command.
  * <ul>
- * <li>[md5] PING: will return PONG if the key is accepted</li>
- * <li>[md5] GET_METADATA *: will return the metadata of all the stories in the
- * library (array)</li>
- * *
- * <li>[md5] GET_METADATA [luid]: will return the metadata of the story of LUID
- * luid</li>
- * <li>[md5] GET_STORY [luid]: will return the given story if it exists (or NULL
- * if not)</li>
- * <li>[md5] SAVE_STORY [luid]: save the story (that must be sent just after the
+ * <li>PING: will return the mode if the key is accepted (mode can be: "r/o" or
+ * "r/w")</li>
+ * <li>GET_METADATA *: will return the metadata of all the stories in the
+ * library (array)</li> *
+ * <li>GET_METADATA [luid]: will return the metadata of the story of LUID luid</li>
+ * <li>GET_STORY [luid]: will return the given story if it exists (or NULL if
+ * not)</li>
+ * <li>SAVE_STORY [luid]: save the story (that must be sent just after the
  * command) with the given LUID, then return the LUID</li>
- * <li>[md5] IMPORT [url]: save the story found at the given URL, then return
- * the LUID</li>
- * <li>[md5] DELETE_STORY [luid]: delete the story of LUID luid</li>
- * <li>[md5] GET_COVER [luid]: return the cover of the story</li>
- * <li>[md5] GET_CUSTOM_COVER ["SOURCE"|"AUTHOR"] [source]: return the cover for
- * this source/author</li>
- * <li>[md5] SET_COVER ["SOURCE"|"AUTHOR"] [value] [luid]: set the default cover
- * for the given source/author to the cover of the story denoted by luid</li>
- * <li>[md5] CHANGE_SOURCE [luid] [new source]: change the source of the story
- * of LUID luid</li>
- * <li>[md5] EXIT: stop the server</li>
+ * <li>IMPORT [url]: save the story found at the given URL, then return the LUID
+ * </li>
+ * <li>DELETE_STORY [luid]: delete the story of LUID luid</li>
+ * <li>GET_COVER [luid]: return the cover of the story</li>
+ * <li>GET_CUSTOM_COVER ["SOURCE"|"AUTHOR"] [source]: return the cover for this
+ * source/author</li>
+ * <li>SET_COVER ["SOURCE"|"AUTHOR"] [value] [luid]: set the default cover for
+ * the given source/author to the cover of the story denoted by luid</li>
+ * <li>CHANGE_SOURCE [luid] [new source]: change the source of the story of LUID
+ * luid</li>
+ * <li>EXIT: stop the server</li>
  * </ul>
  * 
  * @author niki
  */
 public class RemoteLibraryServer extends ServerObject {
-       private final String md5;
+       private Map<Long, String> commands = new HashMap<Long, String>();
+       private Map<Long, Long> times = new HashMap<Long, Long>();
+       private Map<Long, Boolean> wls = new HashMap<Long, Boolean>();
+       private Map<Long, Boolean> rws = new HashMap<Long, Boolean>();
 
        /**
         * Create a new remote server (will not be active until
         * {@link RemoteLibraryServer#start()} is called).
+        * <p>
+        * Note: the key we use here is the encryption key (it must not contain a
+        * subkey).
         * 
         * @param key
         *            the key that will restrict access to this server
@@ -68,22 +80,28 @@ public class RemoteLibraryServer extends ServerObject {
         *             in case of I/O error
         */
        public RemoteLibraryServer(String key, int port) throws IOException {
-               super("Fanfix remote library", port, true);
-               this.md5 = StringUtils.getMd5Hash(key);
-
+               super("Fanfix remote library", port, key);
                setTraceHandler(Instance.getTraceHandler());
        }
 
        @Override
        protected Object onRequest(ConnectActionServerObject action,
-                       Version clientVersion, Object data) throws Exception {
-               String md5 = "";
+                       Version clientVersion, Object data, long id) throws Exception {
+               long start = new Date().getTime();
+
+               // defaults are positive (as previous versions without the feature)
+               boolean rw = true;
+               boolean wl = true;
+
+               String subkey = "";
                String command = "";
                Object[] args = new Object[0];
                if (data instanceof Object[]) {
                        Object[] dataArray = (Object[]) data;
-                       if (dataArray.length >= 2) {
-                               md5 = "" + dataArray[0];
+                       if (dataArray.length > 0) {
+                               subkey = "" + dataArray[0];
+                       }
+                       if (dataArray.length > 1) {
                                command = "" + dataArray[1];
 
                                args = new Object[dataArray.length - 2];
@@ -93,38 +111,90 @@ public class RemoteLibraryServer extends ServerObject {
                        }
                }
 
-               String trace = "[ " + command + "] ";
-               for (Object arg : args) {
-                       trace += arg + " ";
+               List<String> whitelist = Instance.getConfig().getList(
+                               Config.SERVER_WHITELIST);
+               if (whitelist == null) {
+                       whitelist = new ArrayList<String>();
                }
-               getTraceHandler().trace(trace);
 
-               if (!md5.equals(this.md5)) {
-                       getTraceHandler().trace("Key rejected.");
-                       return null;
+               if (whitelist.isEmpty()) {
+                       wl = false;
                }
 
-               long start = new Date().getTime();
-               Object rep = doRequest(action, command, args);
+               rw = Instance.getConfig().getBoolean(Config.SERVER_RW, rw);
+               if (!subkey.isEmpty()) {
+                       List<String> allowed = Instance.getConfig().getList(
+                                       Config.SERVER_ALLOWED_SUBKEYS);
+                       if (allowed.contains(subkey)) {
+                               if ((subkey + "|").contains("|rw|")) {
+                                       rw = true;
+                               }
+                               if ((subkey + "|").contains("|wl|")) {
+                                       wl = false; // |wl| = bypass whitelist
+                                       whitelist = new ArrayList<String>();
+                               }
+                       }
+               }
+
+               String mode = display(wl, rw);
+
+               String trace = mode + "[ " + command + "] ";
+               for (Object arg : args) {
+                       trace += arg + " ";
+               }
+               System.out.println(trace);
+
+               Object rep = doRequest(action, command, args, rw, whitelist);
 
-               getTraceHandler().trace(
-                               String.format("[>%s]: %d ms", command,
-                                               (new Date().getTime() - start)));
+               commands.put(id, command);
+               wls.put(id, wl);
+               rws.put(id, rw);
+               times.put(id, (new Date().getTime() - start));
 
                return rep;
        }
 
+       private String display(boolean whitelist, boolean rw) {
+               String mode = "";
+               if (!rw) {
+                       mode += "RO: ";
+               }
+               if (whitelist) {
+                       mode += "WL: ";
+               }
+
+               return mode;
+       }
+
+       @Override
+       protected void onRequestDone(long id, long bytesReceived, long bytesSent) {
+               boolean whitelist = wls.get(id);
+               boolean rw = rws.get(id);
+               wls.remove(id);
+               rws.remove(id);
+
+               String rec = StringUtils.formatNumber(bytesReceived) + "b";
+               String sent = StringUtils.formatNumber(bytesSent) + "b";
+               System.out.println(String.format("%s[>%s]: (%s sent, %s rec) in %d ms",
+                               display(whitelist, rw), commands.get(id), sent, rec,
+                               times.get(id)));
+
+               commands.remove(id);
+               times.remove(id);
+       }
+
        private Object doRequest(ConnectActionServerObject action, String command,
-                       Object[] args) throws NoSuchFieldException, NoSuchMethodException,
+                       Object[] args, boolean rw, List<String> whitelist)
+                       throws NoSuchFieldException, NoSuchMethodException,
                        ClassNotFoundException, IOException {
                if ("PING".equals(command)) {
-                       return "PONG";
+                       return rw ? "r/w" : "r/o";
                } else if ("GET_METADATA".equals(command)) {
+                       List<MetaData> metas = new ArrayList<MetaData>();
+
                        if ("*".equals(args[0])) {
                                Progress pg = createPgForwarder(action);
 
-                               List<MetaData> metas = new ArrayList<MetaData>();
-
                                for (MetaData meta : Instance.getLibrary().getMetas(pg)) {
                                        MetaData light;
                                        if (meta.getCover() == null) {
@@ -138,13 +208,41 @@ public class RemoteLibraryServer extends ServerObject {
                                }
 
                                forcePgDoneSent(pg);
-                               return metas.toArray(new MetaData[] {});
+                       } else {
+                               MetaData meta = Instance.getLibrary().getInfo((String) args[0]);
+                               MetaData light;
+                               if (meta.getCover() == null) {
+                                       light = meta;
+                               } else {
+                                       light = meta.clone();
+                                       light.setCover(null);
+                               }
+
+                               metas.add(light);
                        }
 
-                       return new MetaData[] { Instance.getLibrary().getInfo(
-                                       (String) args[0]) };
+                       if (!whitelist.isEmpty()) {
+                               for (int i = 0; i < metas.size(); i++) {
+                                       if (!whitelist.contains(metas.get(i).getSource())) {
+                                               metas.remove(i);
+                                               i--;
+                                       }
+                               }
+                       }
+
+                       return metas.toArray(new MetaData[0]);
                } else if ("GET_STORY".equals(command)) {
                        MetaData meta = Instance.getLibrary().getInfo((String) args[0]);
+                       if (meta == null) {
+                               return null;
+                       }
+
+                       if (!whitelist.isEmpty()) {
+                               if (!whitelist.contains(meta.getSource())) {
+                                       return null;
+                               }
+                       }
+
                        meta = meta.clone();
                        meta.setCover(null);
 
@@ -158,6 +256,11 @@ public class RemoteLibraryServer extends ServerObject {
                                action.rec();
                        }
                } else if ("SAVE_STORY".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("" + args[0], null,
+                                               "Read-Only remote library");
+                       }
+
                        List<Object> list = new ArrayList<Object>();
 
                        action.send(null);
@@ -172,12 +275,22 @@ public class RemoteLibraryServer extends ServerObject {
                        Instance.getLibrary().save(story, (String) args[0], null);
                        return story.getMeta().getLuid();
                } else if ("IMPORT".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("" + args[0], null,
+                                               "Read-Only remote library");
+                       }
+
                        Progress pg = createPgForwarder(action);
                        Story story = Instance.getLibrary().imprt(
                                        new URL((String) args[0]), pg);
                        forcePgDoneSent(pg);
                        return story.getMeta().getLuid();
                } else if ("DELETE_STORY".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("" + args[0], null,
+                                               "Read-Only remote library");
+                       }
+
                        Instance.getLibrary().delete((String) args[0]);
                } else if ("GET_COVER".equals(command)) {
                        return Instance.getLibrary().getCover((String) args[0]);
@@ -192,6 +305,11 @@ public class RemoteLibraryServer extends ServerObject {
                                return null;
                        }
                } else if ("SET_COVER".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("" + args[0], "" + args[1],
+                                               "Read-Only remote library");
+                       }
+
                        if ("SOURCE".equals(args[0])) {
                                Instance.getLibrary().setSourceCover((String) args[1],
                                                (String) args[2]);
@@ -200,11 +318,21 @@ public class RemoteLibraryServer extends ServerObject {
                                                (String) args[2]);
                        }
                } else if ("CHANGE_STA".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("" + args[0], "" + args[1],
+                                               "Read-Only remote library");
+                       }
+
                        Progress pg = createPgForwarder(action);
                        Instance.getLibrary().changeSTA((String) args[0], (String) args[1],
                                        (String) args[2], (String) args[3], pg);
                        forcePgDoneSent(pg);
                } else if ("EXIT".equals(command)) {
+                       if (!rw) {
+                               throw new AccessDeniedException("EXIT", "",
+                                               "Read-Only remote library, cannot close it");
+                       }
+
                        stop(0, false);
                }
 
@@ -213,7 +341,11 @@ public class RemoteLibraryServer extends ServerObject {
 
        @Override
        protected void onError(Exception e) {
-               getTraceHandler().error(e);
+               if (e instanceof SSLException) {
+                       System.out.println("[Client connection refused (bad key)]");
+               } else {
+                       getTraceHandler().error(e);
+               }
        }
 
        /**
@@ -308,8 +440,7 @@ public class RemoteLibraryServer extends ServerObject {
         * 
         * @return the {@link Progress}
         */
-       private static Progress createPgForwarder(
-                       final ConnectActionServerObject action) {
+       private Progress createPgForwarder(final ConnectActionServerObject action) {
                final Boolean[] isDoneForwarded = new Boolean[] { false };
                final Progress pg = new Progress() {
                        @Override
@@ -342,7 +473,7 @@ public class RemoteLibraryServer extends ServerObject {
                                                action.send(new Integer[] { min, max, relativeProgress });
                                                action.rec();
                                        } catch (Exception e) {
-                                               Instance.getTraceHandler().error(e);
+                                               getTraceHandler().error(e);
                                        }
 
                                        lastTime[0] = new Date().getTime();
@@ -356,14 +487,14 @@ public class RemoteLibraryServer extends ServerObject {
        }
 
        // with 30 seconds timeout
-       private static void forcePgDoneSent(Progress pg) {
+       private void forcePgDoneSent(Progress pg) {
                long start = new Date().getTime();
                pg.done();
                while (!pg.isDone() && new Date().getTime() - start < 30000) {
                        try {
                                Thread.sleep(100);
                        } catch (InterruptedException e) {
-                               Instance.getTraceHandler().error(e);
+                               getTraceHandler().error(e);
                        }
                }
        }