2018-10-05 22:16:34 +00:00
|
|
|
#--require-config tls-api-key
|
|
|
|
#--require-config tls-api-certificate
|
|
|
|
|
|
|
|
import http.server, json, ssl, threading, uuid, urllib.parse
|
2018-10-04 15:01:13 +00:00
|
|
|
import flask
|
2018-10-12 17:07:23 +00:00
|
|
|
from src import ModuleManager, utils
|
2018-10-04 15:01:13 +00:00
|
|
|
|
|
|
|
_bot = None
|
|
|
|
_events = None
|
2018-11-06 17:22:50 +00:00
|
|
|
_log = None
|
2018-10-04 15:01:13 +00:00
|
|
|
class Handler(http.server.BaseHTTPRequestHandler):
|
2018-10-04 16:10:05 +00:00
|
|
|
timeout = 10
|
2018-10-05 22:14:32 +00:00
|
|
|
def _handle(self, method, path, data="", params={}):
|
2018-10-05 21:49:06 +00:00
|
|
|
_, _, endpoint = path[1:].partition("/")
|
|
|
|
endpoint, _, args = endpoint.partition("/")
|
|
|
|
args = list(filter(None, args.split("/")))
|
2018-12-06 12:00:45 +00:00
|
|
|
headers = {key.title(): value for key, value in self.headers}
|
2018-10-04 15:01:13 +00:00
|
|
|
|
2018-10-05 21:49:06 +00:00
|
|
|
response = ""
|
|
|
|
code = 404
|
2018-10-04 16:59:24 +00:00
|
|
|
|
2018-10-05 21:49:06 +00:00
|
|
|
hooks = _events.on("api").on(method).on(endpoint).get_hooks()
|
|
|
|
if hooks:
|
|
|
|
hook = hooks[0]
|
|
|
|
authenticated = hook.get_kwarg("authenticated", True)
|
|
|
|
key = params.get("key", None)
|
2018-11-12 18:16:55 +00:00
|
|
|
key_setting = _bot.get_setting("api-key-%s" % key, {})
|
2018-11-12 18:18:07 +00:00
|
|
|
permissions = key_setting.get("permissions", [])
|
2018-11-10 21:54:08 +00:00
|
|
|
|
2018-11-11 08:53:37 +00:00
|
|
|
if not authenticated or path in permissions or "*" in permissions:
|
2018-10-05 21:49:06 +00:00
|
|
|
if path.startswith("/api/"):
|
2018-10-06 08:24:43 +00:00
|
|
|
event_response = None
|
2018-10-06 08:22:11 +00:00
|
|
|
try:
|
2018-11-27 14:25:12 +00:00
|
|
|
event_response = _bot.trigger(lambda:
|
|
|
|
_events.on("api").on(method).on(
|
2018-11-06 13:02:04 +00:00
|
|
|
endpoint).call_unsafe_for_result(params=params,
|
2018-12-06 12:00:45 +00:00
|
|
|
path=args, data=data, headers=headers))
|
2018-11-06 17:22:50 +00:00
|
|
|
except Exception as e:
|
|
|
|
_log.error("failed to call API endpoint \"%s\"",
|
|
|
|
[path], exc_info=True)
|
2018-10-06 08:22:11 +00:00
|
|
|
code = 500
|
2018-10-04 15:01:13 +00:00
|
|
|
|
2018-11-06 14:09:13 +00:00
|
|
|
if not event_response == None:
|
2018-11-12 18:15:08 +00:00
|
|
|
if _bot.get_setting("rest-api-minify", False):
|
2018-11-11 08:55:49 +00:00
|
|
|
response = json.dumps(event_response,
|
|
|
|
sort_keys=True, separators=(",", ":"))
|
2018-11-11 08:51:50 +00:00
|
|
|
else:
|
|
|
|
response = json.dumps(event_response,
|
|
|
|
sort_keys=True, indent=4)
|
2018-10-05 21:49:06 +00:00
|
|
|
code = 200
|
2018-11-10 21:54:08 +00:00
|
|
|
else:
|
|
|
|
code = 401
|
2018-10-04 15:01:13 +00:00
|
|
|
|
2018-10-05 21:49:06 +00:00
|
|
|
self.send_response(code)
|
|
|
|
self.send_header("Content-type", "application/json")
|
|
|
|
self.end_headers()
|
|
|
|
self.wfile.write(response.encode("utf8"))
|
2018-10-04 15:01:13 +00:00
|
|
|
|
2018-10-05 21:49:06 +00:00
|
|
|
def _decode_params(self, s):
|
|
|
|
params = urllib.parse.parse_qs(s)
|
|
|
|
return dict([(k, v[0]) for k, v in params.items()])
|
|
|
|
|
|
|
|
def do_GET(self):
|
|
|
|
parsed = urllib.parse.urlparse(self.path)
|
|
|
|
get_params = self._decode_params(parsed.query)
|
2018-10-05 22:14:32 +00:00
|
|
|
self._handle("get", parsed.path, params=get_params)
|
2018-10-05 21:49:06 +00:00
|
|
|
|
|
|
|
def do_POST(self):
|
|
|
|
parsed = urllib.parse.urlparse(self.path)
|
2018-10-05 22:14:32 +00:00
|
|
|
post_params = self._decode_params(parsed.query)
|
2018-10-05 21:49:06 +00:00
|
|
|
content_length = int(self.headers.get("content-length", 0))
|
|
|
|
post_body = self.rfile.read(content_length)
|
2018-10-05 22:14:32 +00:00
|
|
|
self._handle("post", parsed.path, data=post_body, params=post_params)
|
2018-10-05 21:49:06 +00:00
|
|
|
|
2018-11-14 23:01:22 +00:00
|
|
|
def log_message(self, format, *args):
|
2018-11-14 23:02:32 +00:00
|
|
|
_log.info("[HTTP] " + format, args)
|
2018-11-14 23:01:22 +00:00
|
|
|
|
2018-10-04 16:09:52 +00:00
|
|
|
@utils.export("botset", {"setting": "rest-api",
|
|
|
|
"help": "Enable/disable REST API",
|
|
|
|
"validate": utils.bool_or_none})
|
2018-11-12 18:15:08 +00:00
|
|
|
@utils.export("botset", {"setting": "rest-api-minify",
|
|
|
|
"help": "Enable/disable REST API minifying",
|
|
|
|
"validate": utils.bool_or_none})
|
2018-10-12 17:07:23 +00:00
|
|
|
class Module(ModuleManager.BaseModule):
|
|
|
|
def on_load(self):
|
2018-10-04 15:01:13 +00:00
|
|
|
global _bot
|
2018-10-12 17:07:23 +00:00
|
|
|
_bot = self.bot
|
2018-10-04 15:01:13 +00:00
|
|
|
|
|
|
|
global _events
|
2018-10-12 17:07:23 +00:00
|
|
|
_events = self.events
|
2018-10-04 15:01:13 +00:00
|
|
|
|
2018-11-06 17:22:50 +00:00
|
|
|
global _log
|
|
|
|
_log = self.log
|
|
|
|
|
2018-10-12 17:07:23 +00:00
|
|
|
if self.bot.get_setting("rest-api", False):
|
2018-10-04 15:01:13 +00:00
|
|
|
self.httpd = http.server.HTTPServer(("", 5000), Handler)
|
2018-10-05 22:16:34 +00:00
|
|
|
self.httpd.socket = ssl.wrap_socket(self.httpd.socket,
|
|
|
|
keyfile=self.bot.config["tls-api-key"],
|
|
|
|
certfile=self.bot.config["tls-api-certificate"],
|
|
|
|
server_side=True)
|
2018-10-04 15:01:13 +00:00
|
|
|
self.thread = threading.Thread(target=self.httpd.serve_forever)
|
|
|
|
self.thread.daemon = True
|
|
|
|
self.thread.start()
|
|
|
|
|
|
|
|
def unload(self):
|
|
|
|
self.httpd.shutdown()
|
2018-10-04 16:09:35 +00:00
|
|
|
|
|
|
|
@utils.hook("received.command.apikey", private_only=True)
|
|
|
|
def api_key(self, event):
|
|
|
|
"""
|
|
|
|
:help: Generate a new API key
|
2018-11-12 20:44:46 +00:00
|
|
|
:usage: <comment> [endpoint [endpoint ...]]
|
2018-10-04 16:09:35 +00:00
|
|
|
:permission: api-key
|
|
|
|
:prefix: APIKey
|
|
|
|
"""
|
2018-11-12 17:59:40 +00:00
|
|
|
api_key = uuid.uuid4().hex
|
|
|
|
comment = event["args_split"][0]
|
|
|
|
self.bot.set_setting("api-key-%s" % api_key, {
|
|
|
|
"comment": comment,
|
2018-11-12 22:20:46 +00:00
|
|
|
"permissions": event["args_split"][1:]
|
2018-11-12 17:59:40 +00:00
|
|
|
})
|
|
|
|
event["stdout"].write("New API key ('%s'): %s" % (comment, api_key))
|