2021-03-04 05:56:28 +08:00
|
|
|
defmodule LivebookWeb.Endpoint do
|
|
|
|
use Phoenix.Endpoint, otp_app: :livebook
|
2021-01-08 03:55:45 +08:00
|
|
|
|
|
|
|
# The session will be stored in the cookie and signed,
|
|
|
|
# this means its contents can be read but not tampered with.
|
|
|
|
# Set :encryption_salt if you would also like to encrypt it.
|
|
|
|
@session_options [
|
|
|
|
store: :cookie,
|
2024-04-02 21:25:08 +08:00
|
|
|
key: "lb_session",
|
2022-11-10 23:02:59 +08:00
|
|
|
signing_salt: "deadbook"
|
2021-01-08 03:55:45 +08:00
|
|
|
]
|
|
|
|
|
2022-02-08 04:03:25 +08:00
|
|
|
# Don't check the origin as we don't know how the web app is gonna be accessed.
|
|
|
|
# It runs locally, but may be exposed via IP or domain name. The WebSocket
|
|
|
|
# connection is already protected from CSWSH by using CSRF token.
|
|
|
|
@websocket_options [
|
|
|
|
check_origin: false,
|
|
|
|
connect_info: [:user_agent, :uri, session: @session_options]
|
|
|
|
]
|
|
|
|
|
|
|
|
socket "/live", Phoenix.LiveView.Socket, websocket: @websocket_options
|
|
|
|
socket "/socket", LivebookWeb.Socket, websocket: @websocket_options
|
2021-01-08 04:16:54 +08:00
|
|
|
|
2021-10-19 04:32:09 +08:00
|
|
|
# We use Escript for distributing Livebook, so we don't have access to the static
|
|
|
|
# files at runtime in the prod environment. To overcome this we load contents of
|
|
|
|
# those files at compilation time, so that they become a part of the executable
|
|
|
|
# and can be served from memory.
|
2021-03-17 08:53:44 +08:00
|
|
|
defmodule AssetsMemoryProvider do
|
|
|
|
use LivebookWeb.MemoryProvider,
|
2021-10-19 04:32:09 +08:00
|
|
|
from: Path.expand("../../static", __DIR__),
|
2021-03-17 08:53:44 +08:00
|
|
|
gzip: true
|
|
|
|
end
|
|
|
|
|
|
|
|
defmodule AssetsFileSystemProvider do
|
|
|
|
use LivebookWeb.FileSystemProvider,
|
2021-05-20 18:27:30 +08:00
|
|
|
from: "tmp/static_dev"
|
2021-03-17 08:53:44 +08:00
|
|
|
end
|
|
|
|
|
2021-10-31 14:14:35 +08:00
|
|
|
# Serve static files at "/"
|
2021-03-24 00:46:33 +08:00
|
|
|
|
|
|
|
if code_reloading? do
|
2021-05-20 05:50:18 +08:00
|
|
|
# In development we use assets from tmp/static_dev (rebuilt dynamically on every change).
|
2021-10-19 04:32:09 +08:00
|
|
|
# Note that this directory doesn't contain predefined files (e.g. images), so we also
|
|
|
|
# use `AssetsMemoryProvider` to serve those from static/.
|
2021-03-24 00:46:33 +08:00
|
|
|
plug LivebookWeb.StaticPlug,
|
|
|
|
at: "/",
|
|
|
|
file_provider: AssetsFileSystemProvider,
|
|
|
|
gzip: false
|
|
|
|
end
|
|
|
|
|
2021-03-17 08:53:44 +08:00
|
|
|
plug LivebookWeb.StaticPlug,
|
2021-01-08 03:55:45 +08:00
|
|
|
at: "/",
|
2021-03-24 00:46:33 +08:00
|
|
|
file_provider: AssetsMemoryProvider,
|
2021-03-17 08:53:44 +08:00
|
|
|
gzip: true
|
2021-01-08 03:55:45 +08:00
|
|
|
|
2022-03-24 01:24:58 +08:00
|
|
|
plug :force_ssl
|
|
|
|
|
2021-01-08 03:55:45 +08:00
|
|
|
# Code reloading can be explicitly enabled under the
|
|
|
|
# :code_reloader configuration of your endpoint.
|
|
|
|
if code_reloading? do
|
|
|
|
socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket
|
|
|
|
plug Phoenix.LiveReloader
|
|
|
|
plug Phoenix.CodeReloader
|
|
|
|
end
|
|
|
|
|
2021-04-15 02:10:25 +08:00
|
|
|
plug Phoenix.LiveDashboard.RequestLogger,
|
|
|
|
param_key: "request_logger",
|
|
|
|
cookie_key: "request_logger"
|
|
|
|
|
2021-01-08 03:55:45 +08:00
|
|
|
plug Plug.RequestId
|
|
|
|
plug Plug.Telemetry, event_prefix: [:phoenix, :endpoint]
|
2024-05-21 04:04:04 +08:00
|
|
|
plug LivebookWeb.ProxyPlug
|
2021-01-08 03:55:45 +08:00
|
|
|
|
|
|
|
plug Plug.Parsers,
|
|
|
|
parsers: [:urlencoded, :multipart, :json],
|
|
|
|
pass: ["*/*"],
|
|
|
|
json_decoder: Phoenix.json_library()
|
|
|
|
|
|
|
|
plug Plug.MethodOverride
|
|
|
|
plug Plug.Head
|
2022-11-10 23:02:59 +08:00
|
|
|
plug :session
|
2023-03-28 23:11:44 +08:00
|
|
|
plug :purge_cookies
|
2021-10-05 06:44:27 +08:00
|
|
|
|
|
|
|
# Run custom plugs from the app configuration
|
|
|
|
plug LivebookWeb.ConfiguredPlug
|
|
|
|
|
2021-03-04 05:56:28 +08:00
|
|
|
plug LivebookWeb.Router
|
2021-07-01 18:17:49 +08:00
|
|
|
|
2022-11-10 23:02:59 +08:00
|
|
|
@plug_session Plug.Session.init(@session_options ++ [same_site: "Lax"])
|
|
|
|
@plug_session_iframe Plug.Session.init(@session_options ++ [same_site: "None", secure: true])
|
|
|
|
def session(conn, _opts) do
|
|
|
|
if Livebook.Config.within_iframe?() do
|
|
|
|
Plug.Session.call(conn, @plug_session_iframe)
|
|
|
|
else
|
|
|
|
Plug.Session.call(conn, @plug_session)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2024-05-14 19:22:17 +08:00
|
|
|
@plug_ssl Plug.SSL.init(
|
|
|
|
host: {Livebook.Config, :force_ssl_host, []},
|
|
|
|
rewrite_on: {Livebook.Config, :rewrite_on, []}
|
|
|
|
)
|
2022-03-24 01:24:58 +08:00
|
|
|
def force_ssl(conn, _opts) do
|
2022-11-10 23:03:50 +08:00
|
|
|
if Livebook.Config.force_ssl_host() do
|
2022-03-24 01:24:58 +08:00
|
|
|
Plug.SSL.call(conn, @plug_ssl)
|
|
|
|
else
|
|
|
|
conn
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-04-28 22:38:17 +08:00
|
|
|
def cookie_options() do
|
|
|
|
if Livebook.Config.within_iframe?() do
|
|
|
|
[same_site: "None", secure: true]
|
|
|
|
else
|
|
|
|
[same_site: "Lax"]
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2023-03-28 23:11:44 +08:00
|
|
|
# Because we run on localhost, we may accumulate
|
|
|
|
# cookies from several other apps. Our header limit
|
|
|
|
# is set to 32kB. Once we are 75% of said limit,
|
|
|
|
# we clear other cookies to make sure we don't go
|
|
|
|
# over the limit.
|
|
|
|
def purge_cookies(conn, _opts) do
|
|
|
|
cookie_size =
|
|
|
|
conn
|
|
|
|
|> Plug.Conn.get_req_header("cookie")
|
|
|
|
|> Enum.map(&byte_size/1)
|
|
|
|
|> Enum.sum()
|
|
|
|
|
|
|
|
if cookie_size > 24576 do
|
|
|
|
conn.cookies
|
2024-04-02 21:25:08 +08:00
|
|
|
|> Enum.reject(fn {key, _value} -> String.starts_with?(key, "lb_") end)
|
2023-03-28 23:11:44 +08:00
|
|
|
|> Enum.take(10)
|
|
|
|
|> Enum.reduce(conn, fn {key, _value}, conn ->
|
|
|
|
Plug.Conn.delete_resp_cookie(conn, key)
|
|
|
|
end)
|
|
|
|
else
|
|
|
|
conn
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2022-01-21 16:18:02 +08:00
|
|
|
def access_struct_url() do
|
|
|
|
base =
|
|
|
|
case struct_url() do
|
|
|
|
%URI{scheme: "https", port: 0} = uri ->
|
2023-12-25 17:59:36 +08:00
|
|
|
%{uri | port: port(:https, 433)}
|
2022-01-21 16:18:02 +08:00
|
|
|
|
|
|
|
%URI{scheme: "http", port: 0} = uri ->
|
2023-12-25 17:59:36 +08:00
|
|
|
%{uri | port: port(:http, 80)}
|
2022-01-21 16:18:02 +08:00
|
|
|
|
|
|
|
%URI{} = uri ->
|
|
|
|
uri
|
|
|
|
end
|
|
|
|
|
|
|
|
base = update_in(base.path, &(&1 || "/"))
|
2021-07-01 18:17:49 +08:00
|
|
|
|
|
|
|
if Livebook.Config.auth_mode() == :token do
|
|
|
|
token = Application.fetch_env!(:livebook, :token)
|
2022-01-21 16:18:02 +08:00
|
|
|
%{base | query: "token=" <> token}
|
|
|
|
else
|
|
|
|
base
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def access_url do
|
|
|
|
URI.to_string(access_struct_url())
|
|
|
|
end
|
2023-12-25 17:59:36 +08:00
|
|
|
|
|
|
|
defp port(scheme, default) do
|
|
|
|
try do
|
|
|
|
server_info(scheme)
|
|
|
|
rescue
|
|
|
|
_ -> default
|
|
|
|
else
|
|
|
|
{:ok, {_, port}} when is_integer(port) -> port
|
|
|
|
_ -> default
|
|
|
|
end
|
|
|
|
end
|
2021-01-08 03:55:45 +08:00
|
|
|
end
|