webdav.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364
  1. // Copyright 2014 The Go Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. // Package webdav etc etc TODO.
  5. package webdav // import "golang.org/x/net/webdav"
  6. // TODO: ETag, properties.
  7. import (
  8. "errors"
  9. "io"
  10. "net/http"
  11. "os"
  12. "time"
  13. )
  14. // TODO: define the PropSystem interface.
  15. type PropSystem interface{}
  16. type Handler struct {
  17. // FileSystem is the virtual file system.
  18. FileSystem FileSystem
  19. // LockSystem is the lock management system.
  20. LockSystem LockSystem
  21. // PropSystem is an optional property management system. If non-nil, TODO.
  22. PropSystem PropSystem
  23. // Logger is an optional error logger. If non-nil, it will be called
  24. // for all HTTP requests.
  25. Logger func(*http.Request, error)
  26. }
  27. func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  28. status, err := http.StatusBadRequest, error(nil)
  29. if h.FileSystem == nil {
  30. status, err = http.StatusInternalServerError, errNoFileSystem
  31. } else if h.LockSystem == nil {
  32. status, err = http.StatusInternalServerError, errNoLockSystem
  33. } else {
  34. // TODO: COPY, MOVE, PROPFIND, PROPPATCH methods.
  35. // MOVE needs to enforce its Depth constraint. See the parseDepth comment.
  36. switch r.Method {
  37. case "OPTIONS":
  38. status, err = h.handleOptions(w, r)
  39. case "GET", "HEAD", "POST":
  40. status, err = h.handleGetHeadPost(w, r)
  41. case "DELETE":
  42. status, err = h.handleDelete(w, r)
  43. case "PUT":
  44. status, err = h.handlePut(w, r)
  45. case "MKCOL":
  46. status, err = h.handleMkcol(w, r)
  47. case "LOCK":
  48. status, err = h.handleLock(w, r)
  49. case "UNLOCK":
  50. status, err = h.handleUnlock(w, r)
  51. }
  52. }
  53. if status != 0 {
  54. w.WriteHeader(status)
  55. if status != http.StatusNoContent {
  56. w.Write([]byte(StatusText(status)))
  57. }
  58. }
  59. if h.Logger != nil {
  60. h.Logger(r, err)
  61. }
  62. }
  63. type nopReleaser struct{}
  64. func (nopReleaser) Release() {}
  65. func (h *Handler) confirmLocks(r *http.Request) (releaser Releaser, status int, err error) {
  66. hdr := r.Header.Get("If")
  67. if hdr == "" {
  68. return nopReleaser{}, 0, nil
  69. }
  70. ih, ok := parseIfHeader(hdr)
  71. if !ok {
  72. return nil, http.StatusBadRequest, errInvalidIfHeader
  73. }
  74. // ih is a disjunction (OR) of ifLists, so any ifList will do.
  75. for _, l := range ih.lists {
  76. path := l.resourceTag
  77. if path == "" {
  78. path = r.URL.Path
  79. }
  80. releaser, err = h.LockSystem.Confirm(time.Now(), path, l.conditions...)
  81. if err == ErrConfirmationFailed {
  82. continue
  83. }
  84. if err != nil {
  85. return nil, http.StatusInternalServerError, err
  86. }
  87. return releaser, 0, nil
  88. }
  89. return nil, http.StatusPreconditionFailed, ErrLocked
  90. }
  91. func (h *Handler) handleOptions(w http.ResponseWriter, r *http.Request) (status int, err error) {
  92. allow := "OPTIONS, LOCK, PUT, MKCOL"
  93. if fi, err := h.FileSystem.Stat(r.URL.Path); err == nil {
  94. if fi.IsDir() {
  95. allow = "OPTIONS, LOCK, GET, HEAD, POST, DELETE, TRACE, PROPPATCH, COPY, MOVE, UNLOCK, PUT, PROPFIND"
  96. } else {
  97. allow = "OPTIONS, LOCK, GET, HEAD, POST, DELETE, TRACE, PROPPATCH, COPY, MOVE, UNLOCK"
  98. }
  99. }
  100. // http://www.webdav.org/specs/rfc4918.html#dav.compliance.classes
  101. w.Header().Set("DAV", "1, 2")
  102. // http://msdn.microsoft.com/en-au/library/cc250217.aspx
  103. w.Header().Set("MS-Author-Via", "DAV")
  104. w.Header().Set("Allow", allow)
  105. return 0, nil
  106. }
  107. func (h *Handler) handleGetHeadPost(w http.ResponseWriter, r *http.Request) (status int, err error) {
  108. // TODO: check locks for read-only access??
  109. f, err := h.FileSystem.OpenFile(r.URL.Path, os.O_RDONLY, 0)
  110. if err != nil {
  111. return http.StatusNotFound, err
  112. }
  113. defer f.Close()
  114. fi, err := f.Stat()
  115. if err != nil {
  116. return http.StatusNotFound, err
  117. }
  118. http.ServeContent(w, r, r.URL.Path, fi.ModTime(), f)
  119. return 0, nil
  120. }
  121. func (h *Handler) handleDelete(w http.ResponseWriter, r *http.Request) (status int, err error) {
  122. releaser, status, err := h.confirmLocks(r)
  123. if err != nil {
  124. return status, err
  125. }
  126. defer releaser.Release()
  127. // TODO: return MultiStatus where appropriate.
  128. // "godoc os RemoveAll" says that "If the path does not exist, RemoveAll
  129. // returns nil (no error)." WebDAV semantics are that it should return a
  130. // "404 Not Found". We therefore have to Stat before we RemoveAll.
  131. if _, err := h.FileSystem.Stat(r.URL.Path); err != nil {
  132. if os.IsNotExist(err) {
  133. return http.StatusNotFound, err
  134. }
  135. return http.StatusMethodNotAllowed, err
  136. }
  137. if err := h.FileSystem.RemoveAll(r.URL.Path); err != nil {
  138. return http.StatusMethodNotAllowed, err
  139. }
  140. return http.StatusNoContent, nil
  141. }
  142. func (h *Handler) handlePut(w http.ResponseWriter, r *http.Request) (status int, err error) {
  143. releaser, status, err := h.confirmLocks(r)
  144. if err != nil {
  145. return status, err
  146. }
  147. defer releaser.Release()
  148. f, err := h.FileSystem.OpenFile(r.URL.Path, os.O_RDWR|os.O_CREATE|os.O_TRUNC, 0666)
  149. if err != nil {
  150. return http.StatusNotFound, err
  151. }
  152. defer f.Close()
  153. if _, err := io.Copy(f, r.Body); err != nil {
  154. return http.StatusMethodNotAllowed, err
  155. }
  156. return http.StatusCreated, nil
  157. }
  158. func (h *Handler) handleMkcol(w http.ResponseWriter, r *http.Request) (status int, err error) {
  159. releaser, status, err := h.confirmLocks(r)
  160. if err != nil {
  161. return status, err
  162. }
  163. defer releaser.Release()
  164. if r.ContentLength > 0 {
  165. return http.StatusUnsupportedMediaType, nil
  166. }
  167. if err := h.FileSystem.Mkdir(r.URL.Path, 0777); err != nil {
  168. if os.IsNotExist(err) {
  169. return http.StatusConflict, err
  170. }
  171. return http.StatusMethodNotAllowed, err
  172. }
  173. return http.StatusCreated, nil
  174. }
  175. func (h *Handler) handleLock(w http.ResponseWriter, r *http.Request) (retStatus int, retErr error) {
  176. duration, err := parseTimeout(r.Header.Get("Timeout"))
  177. if err != nil {
  178. return http.StatusBadRequest, err
  179. }
  180. li, status, err := readLockInfo(r.Body)
  181. if err != nil {
  182. return status, err
  183. }
  184. token, ld, now := "", LockDetails{}, time.Now()
  185. if li == (lockInfo{}) {
  186. // An empty lockInfo means to refresh the lock.
  187. ih, ok := parseIfHeader(r.Header.Get("If"))
  188. if !ok {
  189. return http.StatusBadRequest, errInvalidIfHeader
  190. }
  191. if len(ih.lists) == 1 && len(ih.lists[0].conditions) == 1 {
  192. token = ih.lists[0].conditions[0].Token
  193. }
  194. if token == "" {
  195. return http.StatusBadRequest, errInvalidLockToken
  196. }
  197. ld, err = h.LockSystem.Refresh(now, token, duration)
  198. if err != nil {
  199. if err == ErrNoSuchLock {
  200. return http.StatusPreconditionFailed, err
  201. }
  202. return http.StatusInternalServerError, err
  203. }
  204. } else {
  205. // Section 9.10.3 says that "If no Depth header is submitted on a LOCK request,
  206. // then the request MUST act as if a "Depth:infinity" had been submitted."
  207. depth := infiniteDepth
  208. if hdr := r.Header.Get("Depth"); hdr != "" {
  209. depth = parseDepth(hdr)
  210. if depth != 0 && depth != infiniteDepth {
  211. // Section 9.10.3 says that "Values other than 0 or infinity must not be
  212. // used with the Depth header on a LOCK method".
  213. return http.StatusBadRequest, errInvalidDepth
  214. }
  215. }
  216. ld = LockDetails{
  217. Root: r.URL.Path,
  218. Duration: duration,
  219. OwnerXML: li.Owner.InnerXML,
  220. ZeroDepth: depth == 0,
  221. }
  222. token, err = h.LockSystem.Create(now, ld)
  223. if err != nil {
  224. if err == ErrLocked {
  225. return StatusLocked, err
  226. }
  227. return http.StatusInternalServerError, err
  228. }
  229. defer func() {
  230. if retErr != nil {
  231. h.LockSystem.Unlock(now, token)
  232. }
  233. }()
  234. // Create the resource if it didn't previously exist.
  235. if _, err := h.FileSystem.Stat(r.URL.Path); err != nil {
  236. f, err := h.FileSystem.OpenFile(r.URL.Path, os.O_RDWR|os.O_CREATE|os.O_TRUNC, 0666)
  237. if err != nil {
  238. // TODO: detect missing intermediate dirs and return http.StatusConflict?
  239. return http.StatusInternalServerError, err
  240. }
  241. f.Close()
  242. w.WriteHeader(http.StatusCreated)
  243. // http://www.webdav.org/specs/rfc4918.html#HEADER_Lock-Token says that the
  244. // Lock-Token value is a Coded-URL. We add angle brackets.
  245. w.Header().Set("Lock-Token", "<"+token+">")
  246. }
  247. }
  248. w.Header().Set("Content-Type", "application/xml; charset=utf-8")
  249. writeLockInfo(w, token, ld)
  250. return 0, nil
  251. }
  252. func (h *Handler) handleUnlock(w http.ResponseWriter, r *http.Request) (status int, err error) {
  253. // http://www.webdav.org/specs/rfc4918.html#HEADER_Lock-Token says that the
  254. // Lock-Token value is a Coded-URL. We strip its angle brackets.
  255. t := r.Header.Get("Lock-Token")
  256. if len(t) < 2 || t[0] != '<' || t[len(t)-1] != '>' {
  257. return http.StatusBadRequest, errInvalidLockToken
  258. }
  259. t = t[1 : len(t)-1]
  260. switch err = h.LockSystem.Unlock(time.Now(), t); err {
  261. case nil:
  262. return http.StatusNoContent, err
  263. case ErrForbidden:
  264. return http.StatusForbidden, err
  265. case ErrLocked:
  266. return StatusLocked, err
  267. case ErrNoSuchLock:
  268. return http.StatusConflict, err
  269. default:
  270. return http.StatusInternalServerError, err
  271. }
  272. }
  273. const (
  274. infiniteDepth = -1
  275. invalidDepth = -2
  276. )
  277. // parseDepth maps the strings "0", "1" and "infinity" to 0, 1 and
  278. // infiniteDepth. Parsing any other string returns invalidDepth.
  279. //
  280. // Different WebDAV methods have further constraints on valid depths:
  281. // - PROPFIND has no further restrictions, as per section 9.1.
  282. // - MOVE accepts only "infinity", as per section 9.2.2.
  283. // - LOCK accepts only "0" or "infinity", as per section 9.10.3.
  284. // These constraints are enforced by the handleXxx methods.
  285. func parseDepth(s string) int {
  286. switch s {
  287. case "0":
  288. return 0
  289. case "1":
  290. return 1
  291. case "infinity":
  292. return infiniteDepth
  293. }
  294. return invalidDepth
  295. }
  296. // http://www.webdav.org/specs/rfc4918.html#status.code.extensions.to.http11
  297. const (
  298. StatusMulti = 207
  299. StatusUnprocessableEntity = 422
  300. StatusLocked = 423
  301. StatusFailedDependency = 424
  302. StatusInsufficientStorage = 507
  303. )
  304. func StatusText(code int) string {
  305. switch code {
  306. case StatusMulti:
  307. return "Multi-Status"
  308. case StatusUnprocessableEntity:
  309. return "Unprocessable Entity"
  310. case StatusLocked:
  311. return "Locked"
  312. case StatusFailedDependency:
  313. return "Failed Dependency"
  314. case StatusInsufficientStorage:
  315. return "Insufficient Storage"
  316. }
  317. return http.StatusText(code)
  318. }
  319. var (
  320. errDirectoryNotEmpty = errors.New("webdav: directory not empty")
  321. errInvalidDepth = errors.New("webdav: invalid depth")
  322. errInvalidIfHeader = errors.New("webdav: invalid If header")
  323. errInvalidLockInfo = errors.New("webdav: invalid lock info")
  324. errInvalidLockToken = errors.New("webdav: invalid lock token")
  325. errInvalidPropfind = errors.New("webdav: invalid propfind")
  326. errInvalidResponse = errors.New("webdav: invalid response")
  327. errInvalidTimeout = errors.New("webdav: invalid timeout")
  328. errNoFileSystem = errors.New("webdav: no file system")
  329. errNoLockSystem = errors.New("webdav: no lock system")
  330. errNotADirectory = errors.New("webdav: not a directory")
  331. errUnsupportedLockInfo = errors.New("webdav: unsupported lock info")
  332. )