miniflux/ui/proxy.go

119 lines
3.5 KiB
Go
Raw Normal View History

// SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
// SPDX-License-Identifier: Apache-2.0
2017-11-20 06:10:04 +01:00
2018-10-08 03:42:43 +02:00
package ui // import "miniflux.app/ui"
2017-11-20 06:10:04 +01:00
import (
2022-10-15 08:17:17 +02:00
"crypto/hmac"
"crypto/sha256"
2017-11-20 06:10:04 +01:00
"encoding/base64"
"errors"
"net/http"
2017-11-20 06:10:04 +01:00
"time"
2017-11-22 08:09:01 +01:00
"miniflux.app/config"
2018-08-25 06:51:50 +02:00
"miniflux.app/crypto"
"miniflux.app/http/request"
"miniflux.app/http/response"
"miniflux.app/http/response/html"
2019-09-22 20:17:15 +02:00
"miniflux.app/logger"
2017-11-20 06:10:04 +01:00
)
func (h *handler) mediaProxy(w http.ResponseWriter, r *http.Request) {
// If we receive a "If-None-Match" header, we assume the media is already stored in browser cache.
if r.Header.Get("If-None-Match") != "" {
2018-10-08 03:42:43 +02:00
w.WriteHeader(http.StatusNotModified)
2017-11-22 08:09:01 +01:00
return
}
2022-10-15 08:17:17 +02:00
encodedDigest := request.RouteStringParam(r, "encodedDigest")
encodedURL := request.RouteStringParam(r, "encodedURL")
2017-11-20 06:10:04 +01:00
if encodedURL == "" {
2018-10-08 03:42:43 +02:00
html.BadRequest(w, r, errors.New("No URL provided"))
2017-11-20 06:10:04 +01:00
return
}
2022-10-15 08:17:17 +02:00
decodedDigest, err := base64.URLEncoding.DecodeString(encodedDigest)
if err != nil {
html.BadRequest(w, r, errors.New("Unable to decode this Digest"))
return
}
decodedURL, err := base64.URLEncoding.DecodeString(encodedURL)
2017-11-20 06:10:04 +01:00
if err != nil {
2018-10-08 03:42:43 +02:00
html.BadRequest(w, r, errors.New("Unable to decode this URL"))
2017-11-20 06:10:04 +01:00
return
2022-10-15 08:17:17 +02:00
}
mac := hmac.New(sha256.New, config.Opts.ProxyPrivateKey())
mac.Write(decodedURL)
expectedMAC := mac.Sum(nil)
if !hmac.Equal(decodedDigest, expectedMAC) {
html.Forbidden(w, r)
return
2017-11-20 06:10:04 +01:00
}
mediaURL := string(decodedURL)
logger.Debug(`[Proxy] Fetching %q`, mediaURL)
2019-09-22 20:17:15 +02:00
req, err := http.NewRequest("GET", mediaURL, nil)
2017-11-20 06:10:04 +01:00
if err != nil {
2018-10-08 03:42:43 +02:00
html.ServerError(w, r, err)
2017-11-20 06:10:04 +01:00
return
}
// Note: User-Agent HTTP header is omitted to avoid being blocked by bot protection mechanisms.
req.Header.Add("Connection", "close")
2017-11-20 06:10:04 +01:00
forwardedRequestHeader := []string{"Range", "Accept", "Accept-Encoding"}
for _, requestHeaderName := range forwardedRequestHeader {
if r.Header.Get(requestHeaderName) != "" {
req.Header.Add(requestHeaderName, r.Header.Get(requestHeaderName))
}
}
clt := &http.Client{
Transport: &http.Transport{
IdleConnTimeout: time.Duration(config.Opts.ProxyHTTPClientTimeout()) * time.Second,
},
Timeout: time.Duration(config.Opts.ProxyHTTPClientTimeout()) * time.Second,
}
resp, err := clt.Do(req)
if err != nil {
logger.Error(`[Proxy] Unable to initialize HTTP client: %v`, err)
http.Error(w, http.StatusText(http.StatusInternalServerError), http.StatusInternalServerError)
return
}
defer resp.Body.Close()
if resp.StatusCode == http.StatusRequestedRangeNotSatisfiable {
logger.Error(`[Proxy] Status Code is %d for URL %q`, resp.StatusCode, mediaURL)
html.RequestedRangeNotSatisfiable(w, r, resp.Header.Get("Content-Range"))
return
}
if resp.StatusCode != http.StatusOK && resp.StatusCode != http.StatusPartialContent {
logger.Error(`[Proxy] Status Code is %d for URL %q`, resp.StatusCode, mediaURL)
2018-10-08 03:42:43 +02:00
html.NotFound(w, r)
2017-11-20 06:10:04 +01:00
return
}
etag := crypto.HashFromBytes(decodedURL)
2017-11-20 06:10:04 +01:00
response.New(w, r).WithCaching(etag, 72*time.Hour, func(b *response.Builder) {
b.WithStatus(resp.StatusCode)
b.WithHeader("Content-Security-Policy", `default-src 'self'`)
b.WithHeader("Content-Type", resp.Header.Get("Content-Type"))
forwardedResponseHeader := []string{"Content-Encoding", "Content-Type", "Content-Length", "Accept-Ranges", "Content-Range"}
for _, responseHeaderName := range forwardedResponseHeader {
if resp.Header.Get(responseHeaderName) != "" {
b.WithHeader(responseHeaderName, resp.Header.Get(responseHeaderName))
}
}
b.WithBody(resp.Body)
2018-10-08 03:42:43 +02:00
b.WithoutCompression()
b.Write()
})
2017-11-20 06:10:04 +01:00
}