memos/server/server.go

127 lines
2.8 KiB
Go
Raw Normal View History

2022-02-03 15:32:03 +08:00
package server
import (
"fmt"
2022-02-04 18:54:24 +08:00
"time"
2022-02-03 15:32:03 +08:00
2023-01-01 21:32:17 +08:00
"github.com/usememos/memos/api"
"github.com/usememos/memos/common"
2022-06-27 22:09:06 +08:00
"github.com/usememos/memos/server/profile"
"github.com/usememos/memos/store"
2022-02-05 17:04:23 +08:00
"github.com/gorilla/securecookie"
2022-02-03 15:32:03 +08:00
"github.com/gorilla/sessions"
"github.com/labstack/echo-contrib/session"
"github.com/labstack/echo/v4"
"github.com/labstack/echo/v4/middleware"
)
type Server struct {
e *echo.Echo
2022-10-29 11:15:39 +08:00
Collector *MetricCollector
2022-05-22 09:29:34 +08:00
Profile *profile.Profile
2022-03-29 20:53:43 +08:00
2022-05-16 07:37:23 +08:00
Store *store.Store
2022-02-03 15:32:03 +08:00
}
2022-05-22 09:29:34 +08:00
func NewServer(profile *profile.Profile) *Server {
2022-02-03 15:32:03 +08:00
e := echo.New()
e.Debug = true
e.HideBanner = true
2022-05-20 22:48:36 +08:00
e.HidePort = true
2022-02-03 15:32:03 +08:00
2023-01-01 21:32:17 +08:00
s := &Server{
e: e,
Profile: profile,
}
2022-02-04 18:54:24 +08:00
e.Use(middleware.LoggerWithConfig(middleware.LoggerConfig{
2022-08-19 00:45:02 +08:00
Format: `{"time":"${time_rfc3339}",` +
`"method":"${method}","uri":"${uri}",` +
`"status":${status},"error":"${error}"}` + "\n",
2022-02-04 18:54:24 +08:00
}))
2022-12-30 00:17:19 +08:00
e.Use(middleware.CSRFWithConfig(middleware.CSRFConfig{
2023-01-01 21:32:17 +08:00
Skipper: s.OpenAPISkipper,
2022-12-30 00:17:19 +08:00
TokenLookup: "cookie:_csrf",
}))
2022-07-30 14:52:37 +08:00
e.Use(middleware.CORS())
e.Use(middleware.Secure())
2022-02-04 18:54:24 +08:00
e.Use(middleware.TimeoutWithConfig(middleware.TimeoutConfig{
Skipper: middleware.DefaultSkipper,
ErrorMessage: "Request timeout",
Timeout: 30 * time.Second,
}))
2022-07-10 09:02:56 +08:00
embedFrontend(e)
2022-02-03 15:32:03 +08:00
// In dev mode, set the const secret key to make signin session persistence.
2022-05-21 12:33:18 +08:00
secret := []byte("usememos")
2022-05-02 09:40:25 +08:00
if profile.Mode == "prod" {
2022-03-29 07:30:29 +08:00
secret = securecookie.GenerateRandomKey(16)
}
e.Use(session.Middleware(sessions.NewCookieStore(secret)))
2022-02-03 15:32:03 +08:00
rootGroup := e.Group("")
s.registerRSSRoutes(rootGroup)
webhookGroup := e.Group("/h")
s.registerResourcePublicRoutes(webhookGroup)
2022-09-09 07:40:21 +08:00
publicGroup := e.Group("/o")
s.registerResourcePublicRoutes(publicGroup)
2022-11-21 23:23:05 +08:00
s.registerGetterPublicRoutes(publicGroup)
2022-02-03 15:32:03 +08:00
apiGroup := e.Group("/api")
apiGroup.Use(func(next echo.HandlerFunc) echo.HandlerFunc {
2022-07-27 19:45:37 +08:00
return aclMiddleware(s, next)
2022-02-03 15:32:03 +08:00
})
2022-03-29 20:53:43 +08:00
s.registerSystemRoutes(apiGroup)
2022-02-03 15:32:03 +08:00
s.registerAuthRoutes(apiGroup)
s.registerUserRoutes(apiGroup)
s.registerMemoRoutes(apiGroup)
s.registerShortcutRoutes(apiGroup)
s.registerResourceRoutes(apiGroup)
2022-06-21 21:58:33 +08:00
s.registerTagRoutes(apiGroup)
2022-02-03 15:32:03 +08:00
return s
}
func (server *Server) Run() error {
2022-03-29 20:53:43 +08:00
return server.e.Start(fmt.Sprintf(":%d", server.Profile.Port))
2022-02-03 15:32:03 +08:00
}
2023-01-01 21:32:17 +08:00
func (server *Server) OpenAPISkipper(c echo.Context) bool {
ctx := c.Request().Context()
path := c.Path()
// Skip auth.
if common.HasPrefixes(path, "/api/auth") {
return true
}
// If there is openId in query string and related user is found, then skip auth.
openID := c.QueryParam("openId")
if openID != "" {
userFind := &api.UserFind{
OpenID: &openID,
}
user, err := server.Store.FindUser(ctx, userFind)
if err != nil && common.ErrorCode(err) != common.NotFound {
return false
}
if user != nil {
// Stores userID into context.
c.Set(getUserIDContextKey(), user.ID)
return true
}
}
return false
}