mirror of
https://github.com/gotenberg/gotenberg.git
synced 2026-10-08 05:23:18 +01:00
Compare commits
5 Commits
v8.37.0
...
ff817f6cf8
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ff817f6cf8 | ||
|
|
ab18384a51 | ||
|
|
70783a01c6 | ||
|
|
2f9020455a | ||
|
|
8e850b1c93 |
@@ -498,7 +498,7 @@ FROM gotenberg AS gotenberg-aws-lambda
|
||||
|
||||
USER root
|
||||
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
|
||||
ENV AWS_LWA_PORT=3000
|
||||
ENV AWS_LWA_READINESS_CHECK_PATH=/health
|
||||
@@ -516,7 +516,7 @@ FROM gotenberg-chromium AS gotenberg-aws-lambda-chromium
|
||||
|
||||
USER root
|
||||
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
|
||||
ENV AWS_LWA_PORT=3000
|
||||
ENV AWS_LWA_READINESS_CHECK_PATH=/health
|
||||
@@ -534,7 +534,7 @@ FROM gotenberg-libreoffice AS gotenberg-aws-lambda-libreoffice
|
||||
|
||||
USER root
|
||||
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:0.9.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
COPY --from=public.ecr.aws/awsguru/aws-lambda-adapter:1.0.1 /lambda-adapter /opt/extensions/lambda-adapter
|
||||
|
||||
ENV AWS_LWA_PORT=3000
|
||||
ENV AWS_LWA_READINESS_CHECK_PATH=/health
|
||||
|
||||
6
go.mod
6
go.mod
@@ -8,11 +8,11 @@ require (
|
||||
github.com/chromedp/chromedp v0.14.2 // pinned: v0.15.x breaks the headless print-mode paint pipeline (rAF / ResizeObserver / IntersectionObserver stop firing, blank charts). See https://github.com/gotenberg/gotenberg/issues/1535.
|
||||
github.com/coreos/go-oidc/v3 v3.21.0
|
||||
github.com/cucumber/godog v0.16.0
|
||||
github.com/dlclark/regexp2 v1.12.0
|
||||
github.com/dlclark/regexp2/v2 v2.8.0
|
||||
github.com/gomarkdown/markdown v0.0.0-20260824154242-13c5cf49db8d
|
||||
github.com/google/uuid v1.6.0
|
||||
github.com/hashicorp/go-retryablehttp v0.7.8
|
||||
github.com/labstack/echo/v4 v4.15.4
|
||||
github.com/labstack/echo/v5 v5.3.1
|
||||
github.com/labstack/gommon v0.5.0
|
||||
github.com/mholt/archives v0.1.5
|
||||
github.com/microcosm-cc/bluemonday v1.0.27
|
||||
@@ -114,8 +114,6 @@ require (
|
||||
github.com/tklauser/go-sysconf v0.4.0 // indirect
|
||||
github.com/tklauser/numcpus v0.12.0 // indirect
|
||||
github.com/ulikunitz/xz v0.5.16 // indirect
|
||||
github.com/valyala/bytebufferpool v1.0.0 // indirect
|
||||
github.com/valyala/fasttemplate v1.2.2 // indirect
|
||||
github.com/yusufpapurcu/wmi v1.2.4 // indirect
|
||||
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
||||
go.opentelemetry.io/contrib/bridges/prometheus v0.71.0 // indirect
|
||||
|
||||
12
go.sum
12
go.sum
@@ -58,8 +58,8 @@ github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSs
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5QvfrDyIgxBk=
|
||||
github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E=
|
||||
github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8=
|
||||
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
|
||||
github.com/dlclark/regexp2/v2 v2.8.0 h1:CekDhPLGfm+GAJmPVFIG+5dqMIQPkyHJll7BbdneDfw=
|
||||
github.com/dlclark/regexp2/v2 v2.8.0/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU=
|
||||
github.com/docker/go-connections v0.8.1 h1:JibmG5hULs5qXSr/cp/w3Pw5fZuStt4MOHMUExb29/M=
|
||||
github.com/docker/go-connections v0.8.1/go.mod h1:no1qkHdjq7kLMGUXYAduOhYPSJxxvgWBh7ogVvptn3Q=
|
||||
github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4=
|
||||
@@ -131,8 +131,8 @@ github.com/klauspost/pgzip v1.2.6 h1:8RXeL5crjEUFnR2/Sn6GJNWtSQ3Dk8pq4CL3jvdDyjU
|
||||
github.com/klauspost/pgzip v1.2.6/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs=
|
||||
github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc=
|
||||
github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw=
|
||||
github.com/labstack/echo/v4 v4.15.4 h1:DL45vVYa+BWE+XuW+zZNd9H0YEdZ80UAWJGcTVW4EVs=
|
||||
github.com/labstack/echo/v4 v4.15.4/go.mod h1:CuMetKIRwsuO/qlAgMq+KTAalwGoB/h4tC+yPdrTj1g=
|
||||
github.com/labstack/echo/v5 v5.3.1 h1:75maCxkQVGualckLc/5s/ihgpH1a1Dc6AuGWNVNs6bw=
|
||||
github.com/labstack/echo/v5 v5.3.1/go.mod h1:4iEGNQiPPZnkfYpNR/L6fINd3NLiGWUD5+eBotFALas=
|
||||
github.com/labstack/gommon v0.5.0 h1:6VSQ2NOzsnEJ5W6+84E0RbcaDDmgB6NIAzWCczTEe6c=
|
||||
github.com/labstack/gommon v0.5.0/go.mod h1:Rzlg7HHy1maLfzBYGg9NZcVuz1sA68HHhLjhcEllYE0=
|
||||
github.com/ledongthuc/pdf v0.0.0-20220302134840-0c2507a12d80 h1:6Yzfa6GP0rIo/kULo2bwGEkFvCePZ3qHDDTC3/J9Swo=
|
||||
@@ -231,10 +231,6 @@ github.com/tklauser/numcpus v0.12.0/go.mod h1:ABHeXzJnr/qqwguhClkZKT1/8VABcYrsyU
|
||||
github.com/ulikunitz/xz v0.5.8/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14=
|
||||
github.com/ulikunitz/xz v0.5.16 h1:ld6NyySjx5lowVKwJvMRLnW5nxKX/xnpSiFYZ/Lxur0=
|
||||
github.com/ulikunitz/xz v0.5.16/go.mod h1:H9Rt/W6/Qj27PGauhQc6nfCDy7vHpzsOThBSaYDoEhw=
|
||||
github.com/valyala/bytebufferpool v1.0.0 h1:GqA5TC/0021Y/b9FG4Oi9Mr3q7XYx6KllzawFIhcdPw=
|
||||
github.com/valyala/bytebufferpool v1.0.0/go.mod h1:6bBcMArwyJ5K/AmCkWv1jt77kVWyCJ6HpOuEn7z0Csc=
|
||||
github.com/valyala/fasttemplate v1.2.2 h1:lxLXG0uE3Qnshl9QyaK6XJxMXlQZELvChBOCmQD0Loo=
|
||||
github.com/valyala/fasttemplate v1.2.2/go.mod h1:KHLXt3tVN2HBp8eijSv/kGJopbvo7S+qRAEEKiv+SiQ=
|
||||
github.com/xyproto/randomstring v1.0.5 h1:YtlWPoRdgMu3NZtP45drfy1GKoojuR7hmRcnhZqKjWU=
|
||||
github.com/xyproto/randomstring v1.0.5/go.mod h1:rgmS5DeNXLivK7YprL0pY+lTuhNQW3iGxZ18UQApw/E=
|
||||
github.com/yusufpapurcu/wmi v1.2.4 h1:zFUKzehAFReQwLys1b/iSMl+JQGSCSjtVqQn9bBrPo0=
|
||||
|
||||
@@ -3,7 +3,7 @@ package gotenberg
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
)
|
||||
|
||||
func TestAuditAllowList(t *testing.T) {
|
||||
@@ -93,7 +93,7 @@ func TestAuditAllowList_FlaggedPatternsAreActuallyExploitable(t *testing.T) {
|
||||
t.Fatalf("pattern %q was not flagged", tc.pattern)
|
||||
}
|
||||
|
||||
ok, err := regexp2.MustCompile(tc.pattern, 0).MatchString(tc.attack)
|
||||
ok, err := regexp2.MustCompile(tc.pattern, regexp2.None).MatchString(tc.attack)
|
||||
if err != nil {
|
||||
t.Fatalf("match %q: %v", tc.attack, err)
|
||||
}
|
||||
@@ -129,7 +129,7 @@ func TestAuditAllowList_SafePatternsRejectTheAttacks(t *testing.T) {
|
||||
t.Fatalf("safe pattern %q was flagged as %q", pattern, findings[0].Risk)
|
||||
}
|
||||
|
||||
re := regexp2.MustCompile(pattern, 0)
|
||||
re := regexp2.MustCompile(pattern, regexp2.None)
|
||||
for _, attack := range attacks {
|
||||
ok, err := re.MatchString(attack)
|
||||
if err != nil {
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/labstack/gommon/bytes"
|
||||
flag "github.com/spf13/pflag"
|
||||
|
||||
@@ -222,6 +222,10 @@ func (f *ParsedFlags) MustDeprecatedHumanReadableBytes(deprecated string, newNam
|
||||
// built. Patterns compiled any other way keep regexp2's default of
|
||||
// math.MaxInt64, which it treats as no timeout at all, so a hand-built slice
|
||||
// must set this itself before reaching [DecideOutbound].
|
||||
//
|
||||
// The ceiling is wall-clock. Match through [MatchPattern] rather than calling
|
||||
// regexp2 directly: a match that never approaches the ceiling still aborts if
|
||||
// the process loses the CPU at the wrong moment.
|
||||
const PatternMatchTimeout = 250 * time.Millisecond
|
||||
|
||||
// MustRegexp returns the regular expression of a flag given by name.
|
||||
@@ -235,7 +239,7 @@ func (f *ParsedFlags) MustRegexp(name string) *regexp2.Regexp {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
re := regexp2.MustCompile(val, 0)
|
||||
re := regexp2.MustCompile(val, regexp2.None)
|
||||
re.MatchTimeout = PatternMatchTimeout
|
||||
|
||||
return re
|
||||
@@ -272,7 +276,7 @@ func (f *ParsedFlags) MustRegexpSlice(name string) []*regexp2.Regexp {
|
||||
continue
|
||||
}
|
||||
|
||||
re := regexp2.MustCompile(val, 0)
|
||||
re := regexp2.MustCompile(val, regexp2.None)
|
||||
re.MatchTimeout = PatternMatchTimeout
|
||||
|
||||
regexps = append(regexps, re)
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
flag "github.com/spf13/pflag"
|
||||
)
|
||||
|
||||
|
||||
@@ -15,7 +15,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/hashicorp/go-retryablehttp"
|
||||
"golang.org/x/net/http/httpproxy"
|
||||
)
|
||||
@@ -109,11 +109,18 @@ var nonPublicIPv4Prefixes = []netip.Prefix{
|
||||
// the prefixes themselves are deprecated or translation-only. See
|
||||
// [nonPublicIPv6Prefixes] and [nonPublicIPv4Prefixes] for the full lists
|
||||
// and rationale.
|
||||
//
|
||||
// An IPv6 zone identifier is ignored, so [::%1] classifies the same as [::].
|
||||
func IsPublicIP(addr netip.Addr) bool {
|
||||
if !addr.IsValid() {
|
||||
return false
|
||||
}
|
||||
addr = addr.Unmap()
|
||||
// A zone does not change where a non-link-local address routes, but
|
||||
// [netip.Prefix.Contains] never matches a zoned address and
|
||||
// [netip.Addr.IsUnspecified] compares the zone too. Keeping it would let
|
||||
// http://[::%251]/ or any zoned address in the prefixes below pass as
|
||||
// public.
|
||||
addr = addr.WithZone("").Unmap()
|
||||
switch {
|
||||
case addr.IsLoopback(),
|
||||
addr.IsPrivate(),
|
||||
@@ -329,12 +336,16 @@ func DecideOutbound(ctx context.Context, rawURL string, allowList, denyList []*r
|
||||
allowMatched := false
|
||||
if len(allowList) > 0 {
|
||||
for _, pattern := range allowList {
|
||||
ok, err := pattern.MatchString(normalized)
|
||||
ok, err := MatchPattern(pattern, normalized)
|
||||
if err != nil {
|
||||
if time.Now().After(deadline) {
|
||||
return OutboundDecision{}, context.DeadlineExceeded
|
||||
}
|
||||
return OutboundDecision{}, fmt.Errorf("'%s' cannot handle '%s': %w", pattern.String(), normalized, err)
|
||||
// The pattern could not be evaluated, so the URL cannot be
|
||||
// cleared for the IP-check bypass an allow-list match grants.
|
||||
// Fail closed like an unresolvable host does below, so the
|
||||
// client gets a generic 403 rather than a 500.
|
||||
return OutboundDecision{}, fmt.Errorf("'%s' cannot handle '%s': %v: %w", pattern.String(), normalized, err, ErrFiltered)
|
||||
}
|
||||
|
||||
if ok {
|
||||
@@ -349,12 +360,15 @@ func DecideOutbound(ctx context.Context, rawURL string, allowList, denyList []*r
|
||||
}
|
||||
|
||||
for _, pattern := range denyList {
|
||||
ok, err := pattern.MatchString(normalized)
|
||||
ok, err := MatchPattern(pattern, normalized)
|
||||
if err != nil {
|
||||
if time.Now().After(deadline) {
|
||||
return OutboundDecision{}, context.DeadlineExceeded
|
||||
}
|
||||
return OutboundDecision{}, fmt.Errorf("'%s' cannot handle '%s': %w", pattern.String(), normalized, err)
|
||||
// The pattern could not be evaluated, so the URL cannot be proven
|
||||
// to fall outside the deny-list. Fail closed rather than letting a
|
||||
// deny-list that never ran pass the request through.
|
||||
return OutboundDecision{}, fmt.Errorf("'%s' cannot handle '%s': %v: %w", pattern.String(), normalized, err, ErrFiltered)
|
||||
}
|
||||
|
||||
if ok {
|
||||
|
||||
@@ -9,7 +9,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
)
|
||||
|
||||
func TestIsPublicIP(t *testing.T) {
|
||||
@@ -103,6 +103,23 @@ func TestIsPublicIP(t *testing.T) {
|
||||
|
||||
// Discard prefix (RFC 6666).
|
||||
{"100::1", false},
|
||||
|
||||
// A zone identifier must not change the classification.
|
||||
{"::%1", false},
|
||||
{"::%lo", false},
|
||||
{"::1%1", false},
|
||||
{"fe80::1%eth0", false},
|
||||
{"fc00::1%1", false},
|
||||
{"::ffff:127.0.0.1%1", false},
|
||||
{"fec0::1%eth0", false},
|
||||
{"2002:a9fe:a9fe::%1", false},
|
||||
{"2001:0:abcd:ef12:3456:7890:a9fe:a9fe%1", false},
|
||||
{"64:ff9b::a9fe:a9fe%1", false},
|
||||
{"64:ff9b:1::a9fe:a9fe%1", false},
|
||||
{"::a9fe:a9fe%1", false},
|
||||
{"2001:db8::1%1", false},
|
||||
{"100::1%1", false},
|
||||
{"2606:4700:4700::1111%1", true},
|
||||
} {
|
||||
t.Run(tc.addr, func(t *testing.T) {
|
||||
addr, err := netip.ParseAddr(tc.addr)
|
||||
@@ -147,10 +164,10 @@ func mustAddrs(t *testing.T, ss ...string) []netip.Addr {
|
||||
|
||||
func TestFilterOutboundURL(t *testing.T) {
|
||||
defaultDeny := []*regexp2.Regexp{
|
||||
regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, 0),
|
||||
regexp2.MustCompile(`^https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|127\.|localhost|\[::1\]|\[fd)`, regexp2.None),
|
||||
}
|
||||
chromiumDeny := []*regexp2.Regexp{
|
||||
regexp2.MustCompile(`^file:(?!//\/tmp/).*`, 0),
|
||||
regexp2.MustCompile(`^file:(?!//\/tmp/).*`, regexp2.None),
|
||||
}
|
||||
|
||||
for _, tc := range []struct {
|
||||
@@ -229,7 +246,7 @@ func TestFilterOutboundURL(t *testing.T) {
|
||||
{
|
||||
scenario: "allow-list match bypasses IP check",
|
||||
rawURL: "http://internal.service/api",
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, 0)},
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal\.service`, regexp2.None)},
|
||||
deny: defaultDeny,
|
||||
opts: []DecideOption{WithDenyPrivateIPs(true)},
|
||||
expectErr: false,
|
||||
@@ -237,15 +254,15 @@ func TestFilterOutboundURL(t *testing.T) {
|
||||
{
|
||||
scenario: "deny-list still wins over allow-list match",
|
||||
rawURL: "http://internal.service/api",
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, 0)},
|
||||
deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, 0)},
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^http://internal`, regexp2.None)},
|
||||
deny: []*regexp2.Regexp{regexp2.MustCompile(`/api$`, regexp2.None)},
|
||||
expectErr: true,
|
||||
expectIs: ErrFiltered,
|
||||
},
|
||||
{
|
||||
scenario: "allow-list non-empty and no match rejects",
|
||||
rawURL: "https://other.example/",
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, 0)},
|
||||
allow: []*regexp2.Regexp{regexp2.MustCompile(`^https://allowed\.example`, regexp2.None)},
|
||||
expectErr: true,
|
||||
expectIs: ErrFiltered,
|
||||
},
|
||||
@@ -304,6 +321,22 @@ func TestFilterOutboundURL(t *testing.T) {
|
||||
expectErr: true,
|
||||
expectIs: ErrFiltered,
|
||||
},
|
||||
{
|
||||
scenario: "zoned unspecified address blocked with deny-private-ips",
|
||||
rawURL: "http://[::%251]:9999/",
|
||||
deny: defaultDeny,
|
||||
opts: []DecideOption{WithDenyPrivateIPs(true)},
|
||||
expectErr: true,
|
||||
expectIs: ErrFiltered,
|
||||
},
|
||||
{
|
||||
scenario: "zoned site-local address blocked with deny-private-ips",
|
||||
rawURL: "http://[fec0:1234::3%25eth0]:8080/",
|
||||
deny: defaultDeny,
|
||||
opts: []DecideOption{WithDenyPrivateIPs(true)},
|
||||
expectErr: true,
|
||||
expectIs: ErrFiltered,
|
||||
},
|
||||
} {
|
||||
t.Run(tc.scenario, func(t *testing.T) {
|
||||
if tc.stub != nil {
|
||||
@@ -506,7 +539,7 @@ func TestDecideOutbound_DenyLists_WinOverDenyPrivateIPs(t *testing.T) {
|
||||
// The regex deny-list fires before any resolution; verifies that
|
||||
// operator-supplied deny patterns remain effective regardless of
|
||||
// IP-class options.
|
||||
deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, 0)}
|
||||
deny := []*regexp2.Regexp{regexp2.MustCompile(`^http://evil\.`, regexp2.None)}
|
||||
|
||||
_, err := DecideOutbound(
|
||||
context.Background(),
|
||||
@@ -572,7 +605,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) {
|
||||
context.Background(),
|
||||
rawURL,
|
||||
nil,
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)},
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)},
|
||||
time.Now().Add(5*time.Second),
|
||||
)
|
||||
if !errors.Is(err, ErrFiltered) {
|
||||
@@ -584,7 +617,7 @@ func TestDecideOutbound_UserinfoDoesNotEvadeDenyList(t *testing.T) {
|
||||
|
||||
func TestDecideOutbound_UserinfoDoesNotSatisfyAllowList(t *testing.T) {
|
||||
// A host-terminated allow-list, the shape the documentation recommends.
|
||||
allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, 0)}
|
||||
allowList := []*regexp2.Regexp{regexp2.MustCompile(`^https://trusted\.example\.com(:[0-9]+)?(/|$)`, regexp2.None)}
|
||||
|
||||
for _, rawURL := range []string{
|
||||
"https://trusted.example.com@169.254.169.254/latest/meta-data/",
|
||||
@@ -623,7 +656,7 @@ func TestDecideOutbound_UserinfoKeptOutOfErrorMessages(t *testing.T) {
|
||||
context.Background(),
|
||||
"http://alice:hunter2@127.0.0.1:9999/",
|
||||
nil,
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, 0)},
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(privateIPsDenyList, regexp2.None)},
|
||||
time.Now().Add(5*time.Second),
|
||||
)
|
||||
if err == nil {
|
||||
@@ -647,7 +680,7 @@ func TestDecideOutbound_LegitimateCredentialsStillReachTheHost(t *testing.T) {
|
||||
decision, err := DecideOutbound(
|
||||
context.Background(),
|
||||
"https://alice:hunter2@example.com/report.pdf",
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, 0)},
|
||||
[]*regexp2.Regexp{regexp2.MustCompile(`^https://example\.com(:[0-9]+)?(/|$)`, regexp2.None)},
|
||||
nil,
|
||||
time.Now().Add(5*time.Second),
|
||||
WithDenyPrivateIPs(true),
|
||||
@@ -741,7 +774,7 @@ func TestDecideOutboundBoundsCatastrophicPatterns(t *testing.T) {
|
||||
// caller's whole budget, so a 30s API_TIMEOUT bought a 30s CPU burn.
|
||||
// The trailing "!" makes the match fail only after the nested quantifier
|
||||
// has explored every way to split the run of "a"s.
|
||||
pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, 0)
|
||||
pattern := regexp2.MustCompile(`^https://example\.com/(a+)+$`, regexp2.None)
|
||||
pattern.MatchTimeout = PatternMatchTimeout
|
||||
|
||||
rawURL := "https://example.com/" + strings.Repeat("a", 40) + "!"
|
||||
@@ -760,6 +793,13 @@ func TestDecideOutboundBoundsCatastrophicPatterns(t *testing.T) {
|
||||
t.Fatal("expected an error from a catastrophic deny-list pattern")
|
||||
}
|
||||
|
||||
// A deny-list that could not be evaluated cannot clear the URL, so the
|
||||
// decision fails closed and the client gets a generic 403 rather than a
|
||||
// 500 naming the pattern.
|
||||
if !errors.Is(err, ErrFiltered) {
|
||||
t.Fatalf("expected ErrFiltered from an unevaluable deny-list pattern but got: %v", err)
|
||||
}
|
||||
|
||||
// Generous headroom over the 250ms ceiling, still far below the 30s
|
||||
// deadline the match would otherwise have been allowed to consume.
|
||||
if elapsed > 5*time.Second {
|
||||
|
||||
55
pkg/gotenberg/pattern.go
Normal file
55
pkg/gotenberg/pattern.go
Normal file
@@ -0,0 +1,55 @@
|
||||
package gotenberg
|
||||
|
||||
import (
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
)
|
||||
|
||||
// patternMatchAttempts caps how many times [MatchPattern] runs one pattern
|
||||
// against one string. It is what keeps a pattern that is genuinely out of
|
||||
// budget from retrying forever: three attempts bound its cost at three
|
||||
// [PatternMatchTimeout], which is still two orders of magnitude below the
|
||||
// --api-timeout (env API_TIMEOUT) the ceiling exists to protect.
|
||||
const patternMatchAttempts = 3
|
||||
|
||||
// MatchPattern reports whether s matches pattern. It bounds the match by the
|
||||
// pattern's MatchTimeout without the false timeouts that the bound alone
|
||||
// produces.
|
||||
//
|
||||
// regexp2 does not time a match against [time.Now]. It derives the deadline
|
||||
// from a process-global clock that a background goroutine advances every
|
||||
// 100ms, and it tests that deadline on the very first step of the match.
|
||||
// Anything that stops the whole process, a cgroup CPU-quota throttle or a long
|
||||
// stop-the-world pause, also stops that goroutine, which then advances the
|
||||
// clock by the full pause in a single write. A match holding a deadline from
|
||||
// before that jump aborts whatever work it had done: a 366ns match against a
|
||||
// short URL reports "match timeout after 250ms". The abort lands on whichever
|
||||
// match straddles the jump rather than on a match that was slow, which is why
|
||||
// it fires on an idle instance and against Gotenberg's own file:///tmp/ URLs.
|
||||
// See https://github.com/gotenberg/gotenberg/issues/1659.
|
||||
//
|
||||
// Retrying separates the two cases. Catastrophic backtracking is
|
||||
// deterministic: the same pattern against the same string exhausts the same
|
||||
// budget on every attempt, so a genuine runaway still aborts, and costs at
|
||||
// most patternMatchAttempts ceilings to prove it. A clock-induced abort needs
|
||||
// the process to lose the CPU inside one specific match, which the next
|
||||
// attempt does not reproduce.
|
||||
//
|
||||
// Elapsed time cannot make that call instead. A match frozen mid-flight
|
||||
// reports the freeze as its own cost, 806ms against a 250ms ceiling in one
|
||||
// measured run, so it is indistinguishable by wall clock from a match that
|
||||
// really did spend its budget. Go exposes no per-goroutine CPU time, and
|
||||
// process CPU time counts every other request in flight.
|
||||
func MatchPattern(pattern *regexp2.Regexp, s string) (bool, error) {
|
||||
var err error
|
||||
|
||||
for range patternMatchAttempts {
|
||||
var ok bool
|
||||
|
||||
ok, err = pattern.MatchString(s)
|
||||
if err == nil {
|
||||
return ok, nil
|
||||
}
|
||||
}
|
||||
|
||||
return false, err
|
||||
}
|
||||
99
pkg/gotenberg/pattern_test.go
Normal file
99
pkg/gotenberg/pattern_test.go
Normal file
@@ -0,0 +1,99 @@
|
||||
package gotenberg
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
)
|
||||
|
||||
// mustPattern compiles a pattern the way the production lists are built.
|
||||
func mustPattern(t *testing.T, expr string) *regexp2.Regexp {
|
||||
t.Helper()
|
||||
|
||||
re := regexp2.MustCompile(expr, regexp2.None)
|
||||
re.MatchTimeout = PatternMatchTimeout
|
||||
|
||||
return re
|
||||
}
|
||||
|
||||
func TestMatchPattern(t *testing.T) {
|
||||
// The abort [MatchPattern] absorbs cannot be staged here: it needs the
|
||||
// whole process to lose the CPU around one specific match, which no test
|
||||
// can schedule. What is testable is the other half of the contract, that
|
||||
// retrying never turns a genuine runaway into a pass.
|
||||
// See https://github.com/gotenberg/gotenberg/issues/1659.
|
||||
for _, tc := range []struct {
|
||||
scenario string
|
||||
pattern *regexp2.Regexp
|
||||
s string
|
||||
expectMatch bool
|
||||
expectError bool
|
||||
}{
|
||||
{
|
||||
scenario: "deny-list match",
|
||||
pattern: mustPattern(t, `^file:(?!//\/tmp/).*`),
|
||||
s: "file:///etc/passwd",
|
||||
expectMatch: true,
|
||||
},
|
||||
{
|
||||
scenario: "no match against Gotenberg's own working directory",
|
||||
pattern: mustPattern(t, `^file:(?!//\/tmp/).*`),
|
||||
s: "file:///tmp/1a2b3c4d/5e6f7a8b/9c0d1e2f.html",
|
||||
expectMatch: false,
|
||||
},
|
||||
{
|
||||
scenario: "no match",
|
||||
pattern: mustPattern(t, `^https://example\.com/`),
|
||||
s: "https://example.org/",
|
||||
expectMatch: false,
|
||||
},
|
||||
{
|
||||
scenario: "catastrophic backtracking still aborts",
|
||||
pattern: mustPattern(t, `^https://example\.com/(a+)+$`),
|
||||
s: "https://example.com/" + strings.Repeat("a", 40) + "!",
|
||||
expectError: true,
|
||||
},
|
||||
} {
|
||||
t.Run(tc.scenario, func(t *testing.T) {
|
||||
ok, err := MatchPattern(tc.pattern, tc.s)
|
||||
|
||||
if tc.expectError && err == nil {
|
||||
t.Fatal("expected an error but got none")
|
||||
}
|
||||
|
||||
if !tc.expectError && err != nil {
|
||||
t.Fatalf("expected no error but got: %v", err)
|
||||
}
|
||||
|
||||
if ok != tc.expectMatch {
|
||||
t.Fatalf("expected match %t but got %t", tc.expectMatch, ok)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestMatchPatternBoundsCatastrophicPattern(t *testing.T) {
|
||||
// Proving a runaway is genuine costs one ceiling per attempt, so the
|
||||
// worst case is patternMatchAttempts of them plus regexp2's clock period
|
||||
// on each, roughly a second. The bound that matters is the one this
|
||||
// replaced: before the ceiling existed, the same match was allowed to
|
||||
// burn a core for the caller's whole 30s budget.
|
||||
pattern := mustPattern(t, `^https://example\.com/(a+)+$`)
|
||||
s := "https://example.com/" + strings.Repeat("a", 40) + "!"
|
||||
|
||||
start := time.Now()
|
||||
_, err := MatchPattern(pattern, s)
|
||||
elapsed := time.Since(start)
|
||||
|
||||
if err == nil {
|
||||
t.Fatal("expected an error from a catastrophic pattern")
|
||||
}
|
||||
|
||||
// Generous headroom over the expected second keeps this stable on a
|
||||
// loaded CI box while still failing if the bound is gone.
|
||||
if elapsed > 5*time.Second {
|
||||
t.Fatalf("match took %s, want at most %d ceilings of %s", elapsed, patternMatchAttempts, PatternMatchTimeout)
|
||||
}
|
||||
}
|
||||
@@ -12,10 +12,9 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/alexliesenfeld/health"
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/labstack/echo/v5"
|
||||
flag "github.com/spf13/pflag"
|
||||
"golang.org/x/net/http2"
|
||||
"golang.org/x/sync/errgroup"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
@@ -58,6 +57,12 @@ type Api struct {
|
||||
fs *gotenberg.FileSystem
|
||||
logger *slog.Logger
|
||||
srv *echo.Echo
|
||||
|
||||
// shutdownCancel triggers the graceful shutdown of the server started by
|
||||
// [echo.StartConfig]. Echo v5 drives shutdown from a context instead of an
|
||||
// Echo.Shutdown method. serveDone closes once that shutdown completed.
|
||||
shutdownCancel context.CancelFunc
|
||||
serveDone chan struct{}
|
||||
}
|
||||
|
||||
type downloadFromConfig struct {
|
||||
@@ -134,7 +139,7 @@ const (
|
||||
// middleware := Middleware{
|
||||
// Handler: func() echo.MiddlewareFunc {
|
||||
// return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
// return func(c echo.Context) error {
|
||||
// return func(c *echo.Context) error {
|
||||
// rootPath := c.Get("rootPath").(string)
|
||||
// healthURI := fmt.Sprintf("%shealth", rootPath)
|
||||
//
|
||||
@@ -536,16 +541,29 @@ func (a *Api) Validate() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// newEchoServer builds the [echo.Echo] instance with the settings Gotenberg
|
||||
// relies on, independently of the routes and middlewares added by [Api.Start].
|
||||
func newEchoServer() *echo.Echo {
|
||||
srv := echo.New()
|
||||
srv.HTTPErrorHandler = httpErrorHandler()
|
||||
// Echo v5 serves files through Echo.Filesystem, an [fs.FS] rooted at the
|
||||
// working directory, and [fs.FS] rejects absolute names. Every output file
|
||||
// lives under the request's temporary directory, so Context.Attachment gets
|
||||
// an absolute path and the default filesystem answers 404 for every
|
||||
// conversion. Rooting at "/" restores the v4 behavior, where the path was
|
||||
// opened as-is.
|
||||
srv.Filesystem = echo.NewDefaultFS("/")
|
||||
// Echo v5 dropped the X-Forwarded-For and X-Real-IP fallbacks from
|
||||
// Context.RealIP. Keep the previous behavior so that the access log still
|
||||
// reports the client IP when Gotenberg sits behind a reverse proxy.
|
||||
srv.IPExtractor = echo.LegacyIPExtractor()
|
||||
|
||||
return srv
|
||||
}
|
||||
|
||||
// Start starts the HTTP server.
|
||||
func (a *Api) Start() error {
|
||||
a.srv = echo.New()
|
||||
a.srv.HideBanner = true
|
||||
a.srv.HidePort = true
|
||||
a.srv.Server.ReadTimeout = a.timeout
|
||||
a.srv.Server.IdleTimeout = a.timeout
|
||||
// See https://github.com/gotenberg/gotenberg/issues/396.
|
||||
a.srv.Server.WriteTimeout = a.timeout + a.timeout
|
||||
a.srv.HTTPErrorHandler = httpErrorHandler()
|
||||
a.srv = newEchoServer()
|
||||
|
||||
// Let's prepare the modules' routes.
|
||||
var disableTelemetryForPaths []string
|
||||
@@ -609,7 +627,7 @@ func (a *Api) Start() error {
|
||||
securityMiddleware = oidcAuthMiddleware(verifier)
|
||||
default:
|
||||
securityMiddleware = func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
return next(c)
|
||||
}
|
||||
}
|
||||
@@ -641,7 +659,7 @@ func (a *Api) Start() error {
|
||||
// Root route.
|
||||
a.srv.GET(
|
||||
a.rootPath,
|
||||
func(c echo.Context) error {
|
||||
func(c *echo.Context) error {
|
||||
return c.HTML(http.StatusOK, `Hey, Gotenberg has no UI, it's an API. Head to the <a href="https://gotenberg.dev">documentation</a> to learn how to interact with it 🚀`)
|
||||
},
|
||||
securityMiddleware,
|
||||
@@ -650,7 +668,7 @@ func (a *Api) Start() error {
|
||||
// Favicon route.
|
||||
a.srv.GET(
|
||||
fmt.Sprintf("%s%s", a.rootPath, "favicon.ico"),
|
||||
func(c echo.Context) error {
|
||||
func(c *echo.Context) error {
|
||||
return c.NoContent(http.StatusNoContent)
|
||||
},
|
||||
securityMiddleware,
|
||||
@@ -681,7 +699,7 @@ func (a *Api) Start() error {
|
||||
// ...the version route.
|
||||
a.srv.GET(
|
||||
fmt.Sprintf("%s%s", a.rootPath, "version"),
|
||||
func(c echo.Context) error {
|
||||
func(c *echo.Context) error {
|
||||
return c.String(http.StatusOK, gotenberg.Version)
|
||||
},
|
||||
securityMiddleware,
|
||||
@@ -691,7 +709,7 @@ func (a *Api) Start() error {
|
||||
if a.enableDebugRoute {
|
||||
a.srv.GET(
|
||||
fmt.Sprintf("%s%s", a.rootPath, "debug"),
|
||||
func(c echo.Context) error {
|
||||
func(c *echo.Context) error {
|
||||
return c.JSONPretty(http.StatusOK, gotenberg.Debug(), " ")
|
||||
},
|
||||
securityMiddleware,
|
||||
@@ -712,18 +730,50 @@ func (a *Api) Start() error {
|
||||
return fmt.Errorf("waiting for modules readiness: %w", err)
|
||||
}
|
||||
|
||||
startConfig := echo.StartConfig{
|
||||
Address: fmt.Sprintf("%s:%d", a.bindIp, a.port),
|
||||
HideBanner: true,
|
||||
HidePort: true,
|
||||
BeforeServeFunc: func(s *http.Server) error {
|
||||
s.ReadTimeout = a.timeout
|
||||
s.IdleTimeout = a.timeout
|
||||
// See https://github.com/gotenberg/gotenberg/issues/396.
|
||||
s.WriteTimeout = a.timeout + a.timeout
|
||||
|
||||
if a.tlsCertFile == "" || a.tlsKeyFile == "" {
|
||||
// Serve HTTP/2 Cleartext (h2c). Echo v5 dropped
|
||||
// StartH2CServer and golang.org/x/net/http2/h2c is deprecated,
|
||||
// so the standard library serves h2c through Server.Protocols
|
||||
// instead.
|
||||
protocols := new(http.Protocols)
|
||||
protocols.SetHTTP1(true)
|
||||
protocols.SetUnencryptedHTTP2(true)
|
||||
s.Protocols = protocols
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
}
|
||||
|
||||
// Not named cancel: that would reassign the readiness timeout's cancel from
|
||||
// above, whose deferred call is already bound to the old value.
|
||||
serveCtx, serveCancel := context.WithCancel(context.Background())
|
||||
a.shutdownCancel = serveCancel
|
||||
a.serveDone = make(chan struct{})
|
||||
|
||||
// As the following code is blocking, run it in a goroutine.
|
||||
go func() {
|
||||
defer close(a.serveDone)
|
||||
|
||||
var err error
|
||||
if a.tlsCertFile != "" && a.tlsKeyFile != "" {
|
||||
// Start an HTTPS server (supports HTTP/2).
|
||||
err = a.srv.StartTLS(fmt.Sprintf("%s:%d", a.bindIp, a.port), a.tlsCertFile, a.tlsKeyFile)
|
||||
err = startConfig.StartTLS(serveCtx, a.srv, a.tlsCertFile, a.tlsKeyFile)
|
||||
} else {
|
||||
// Start an HTTP/2 Cleartext (non-HTTPS) server.
|
||||
server := &http2.Server{}
|
||||
err = a.srv.StartH2CServer(fmt.Sprintf("%s:%d", a.bindIp, a.port), server)
|
||||
err = startConfig.Start(serveCtx, a.srv)
|
||||
}
|
||||
if !errors.Is(err, http.ErrServerClosed) {
|
||||
if err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||
a.logger.ErrorContext(context.Background(), err.Error())
|
||||
}
|
||||
}()
|
||||
@@ -740,6 +790,26 @@ func (a *Api) StartupMessage() string {
|
||||
return fmt.Sprintf("server started on %s:%d", ip, a.port)
|
||||
}
|
||||
|
||||
// shutdown triggers the server's graceful shutdown and waits for it to
|
||||
// complete, or for ctx to be done. Cancelling the serve context is what Echo v5
|
||||
// exposes in place of Echo.Shutdown: [echo.StartConfig] shuts the server down
|
||||
// on its own deadline, so the shutdown proceeds even when ctx is already done.
|
||||
func (a *Api) shutdown(ctx context.Context) error {
|
||||
if a.shutdownCancel == nil {
|
||||
// Start never ran, so there is nothing to shut down.
|
||||
return nil
|
||||
}
|
||||
|
||||
a.shutdownCancel()
|
||||
|
||||
select {
|
||||
case <-a.serveDone:
|
||||
return nil
|
||||
case <-ctx.Done():
|
||||
return ctx.Err()
|
||||
}
|
||||
}
|
||||
|
||||
// Stop stops the HTTP server.
|
||||
func (a *Api) Stop(ctx context.Context) error {
|
||||
for {
|
||||
@@ -749,7 +819,7 @@ func (a *Api) Stop(ctx context.Context) error {
|
||||
}
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return a.srv.Shutdown(ctx)
|
||||
return a.shutdown(ctx)
|
||||
default:
|
||||
a.logger.DebugContext(ctx, fmt.Sprintf("%d asynchronous requests", count))
|
||||
if count > 0 {
|
||||
@@ -757,7 +827,7 @@ func (a *Api) Stop(ctx context.Context) error {
|
||||
continue
|
||||
}
|
||||
a.logger.DebugContext(ctx, "no more asynchronous requests, continue with shutdown")
|
||||
err := a.srv.Shutdown(ctx)
|
||||
err := a.shutdown(ctx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("shutdown: %w", err)
|
||||
}
|
||||
|
||||
@@ -18,7 +18,7 @@ import (
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/hashicorp/go-retryablehttp"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
"github.com/mholt/archives"
|
||||
"go.opentelemetry.io/otel"
|
||||
"go.opentelemetry.io/otel/codes"
|
||||
@@ -70,7 +70,7 @@ type Context struct {
|
||||
outputFilename string
|
||||
|
||||
logger *slog.Logger
|
||||
echoCtx echo.Context
|
||||
echoCtx *echo.Context
|
||||
mkdirAll gotenberg.MkdirAll
|
||||
pathRename gotenberg.PathRename
|
||||
context.Context
|
||||
@@ -158,7 +158,7 @@ type downloadFrom struct {
|
||||
}
|
||||
|
||||
// newContext returns a [Context] by parsing a "multipart/form-data" request.
|
||||
func newContext(echoCtx echo.Context, logger *slog.Logger, fs *gotenberg.FileSystem, timeout time.Duration, bodyLimit int64, downloadFromCfg downloadFromConfig) (*Context, context.CancelFunc, error) {
|
||||
func newContext(echoCtx *echo.Context, logger *slog.Logger, fs *gotenberg.FileSystem, timeout time.Duration, bodyLimit int64, downloadFromCfg downloadFromConfig) (*Context, context.CancelFunc, error) {
|
||||
processCtx, processCancel := context.WithTimeout(echoCtx.Request().Context(), timeout)
|
||||
|
||||
// We want to make sure the multipart/form-data does not exceed a given
|
||||
|
||||
@@ -19,8 +19,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
)
|
||||
@@ -875,7 +875,7 @@ func TestNewContext_DownloadFromRedirectVerdictStaysGeneric(t *testing.T) {
|
||||
fs := gotenberg.NewFileSystem(new(gotenberg.OsMkdirAll))
|
||||
|
||||
// The first hop is allowed, the redirect target is denied by the deny-list.
|
||||
denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), 0)}
|
||||
denyList := []*regexp2.Regexp{regexp2.MustCompile("^"+regexp.QuoteMeta(private.URL), regexp2.None)}
|
||||
|
||||
_, cancel, err := newContext(echoCtx, logger, fs, 10*time.Second, 0, downloadFromConfig{
|
||||
denyList: denyList,
|
||||
|
||||
@@ -12,8 +12,8 @@ import (
|
||||
|
||||
"github.com/coreos/go-oidc/v3/oidc"
|
||||
"github.com/google/uuid"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v4/middleware"
|
||||
"github.com/labstack/echo/v5"
|
||||
"github.com/labstack/echo/v5/middleware"
|
||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp"
|
||||
"go.opentelemetry.io/otel"
|
||||
"go.opentelemetry.io/otel/attribute"
|
||||
@@ -37,10 +37,12 @@ var (
|
||||
// ParseError parses an error and returns the corresponding HTTP status and
|
||||
// HTTP message.
|
||||
func ParseError(err error) (int, string) {
|
||||
var echoErr *echo.HTTPError
|
||||
ok := errors.As(err, &echoErr)
|
||||
if ok {
|
||||
return echoErr.Code, http.StatusText(echoErr.Code)
|
||||
// [echo.StatusCode] also matches the router's ErrNotFound and
|
||||
// ErrMethodNotAllowed sentinels, which Echo v5 no longer models as
|
||||
// [echo.HTTPError]. Matching that type alone would let every unrouted
|
||||
// request fall through to a 500.
|
||||
if code := echo.StatusCode(err); code != 0 {
|
||||
return code, http.StatusText(code)
|
||||
}
|
||||
|
||||
if errors.Is(err, context.DeadlineExceeded) {
|
||||
@@ -100,14 +102,14 @@ const statusClientClosedRequest = 499
|
||||
// A server-side timeout is [context.DeadlineExceeded], mapped to 503 by
|
||||
// [ParseError], and is deliberately not treated as a client abort.
|
||||
// See https://github.com/gotenberg/gotenberg/issues/1627.
|
||||
func requestCanceled(c echo.Context, err error) bool {
|
||||
func requestCanceled(c *echo.Context, err error) bool {
|
||||
return errors.Is(err, context.Canceled) && errors.Is(c.Request().Context().Err(), context.Canceled)
|
||||
}
|
||||
|
||||
// httpErrorHandler is the centralized HTTP error handler. It parses the error,
|
||||
// returns a response as "text/plain; charset=UTF-8".
|
||||
func httpErrorHandler() echo.HTTPErrorHandler {
|
||||
return func(err error, c echo.Context) {
|
||||
return func(c *echo.Context, err error) {
|
||||
logger := c.Get("logger").(*slog.Logger)
|
||||
|
||||
if requestCanceled(c, err) {
|
||||
@@ -134,7 +136,7 @@ func httpErrorHandler() echo.HTTPErrorHandler {
|
||||
// startTime := c.Get("startTime").(time.Time)
|
||||
func latencyMiddleware() echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
// First piece for calculating the latency.
|
||||
startTime := time.Now()
|
||||
c.Set("startTime", startTime)
|
||||
@@ -159,7 +161,7 @@ func latencyMiddleware() echo.MiddlewareFunc {
|
||||
// }
|
||||
func rootPathMiddleware(rootPath string) echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
c.Set("rootPath", rootPath)
|
||||
// Call the next middleware in the chain.
|
||||
return next(c)
|
||||
@@ -173,7 +175,7 @@ func rootPathMiddleware(rootPath string) echo.MiddlewareFunc {
|
||||
// outputFilename := c.Get("outputFilename").(string)
|
||||
func outputFilenameMiddleware() echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
filename := c.Request().Header.Get("Gotenberg-Output-Filename")
|
||||
// Keep only the last path segment, so that a caller cannot name an
|
||||
// output file after a path.
|
||||
@@ -203,10 +205,18 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
semconvSrv := semconvutil.NewHTTPServer(meter)
|
||||
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
startTime := c.Get("startTime").(time.Time)
|
||||
rootPath := c.Get("rootPath").(string)
|
||||
|
||||
// Echo v5 returns the bare [http.ResponseWriter] from
|
||||
// Context.Response, so unwrap it to read the recorded status and
|
||||
// size below.
|
||||
response, errUnwrap := echo.UnwrapResponse(c.Response())
|
||||
if errUnwrap != nil {
|
||||
return fmt.Errorf("unwrap response: %w", errUnwrap)
|
||||
}
|
||||
|
||||
request := c.Request()
|
||||
savedCtx := request.Context()
|
||||
defer func() {
|
||||
@@ -239,7 +249,7 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
|
||||
err := next(c)
|
||||
if err != nil {
|
||||
c.Error(err)
|
||||
c.Echo().HTTPErrorHandler(c, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -288,7 +298,7 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
err := next(c)
|
||||
finishTime := time.Now()
|
||||
|
||||
status := c.Response().Status
|
||||
status := response.Status
|
||||
canceled := false
|
||||
if err != nil {
|
||||
canceled = requestCanceled(c, err)
|
||||
@@ -300,13 +310,13 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
}
|
||||
|
||||
span.SetAttributes(attribute.String("error", err.Error()))
|
||||
c.Error(err)
|
||||
c.Echo().HTTPErrorHandler(c, err)
|
||||
}
|
||||
|
||||
span.SetStatus(semconvSrv.Status(status))
|
||||
span.SetAttributes(semconvSrv.ResponseTraceAttrs(semconvutil.ResponseTelemetry{
|
||||
StatusCode: status,
|
||||
WriteBytes: c.Response().Size,
|
||||
WriteBytes: response.Size,
|
||||
})...)
|
||||
|
||||
// Pick the level and message before building the record: err.Error
|
||||
@@ -343,11 +353,11 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
slog.String("path", routePath),
|
||||
slog.String("referer", c.Request().Referer()),
|
||||
slog.String("user_agent", c.Request().UserAgent()),
|
||||
slog.Int("status", c.Response().Status),
|
||||
slog.Int("status", response.Status),
|
||||
slog.Int64("latency", int64(latency)),
|
||||
slog.String("latency_human", latency.String()),
|
||||
slog.Int64("bytes_in", c.Request().ContentLength),
|
||||
slog.Int64("bytes_out", c.Response().Size),
|
||||
slog.Int64("bytes_out", response.Size),
|
||||
)
|
||||
|
||||
additionalAttributes := []attribute.KeyValue{
|
||||
@@ -356,7 +366,7 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
|
||||
semconvSrv.RecordMetrics(ctx, semconvutil.ServerMetricData{
|
||||
ServerName: serverName,
|
||||
ResponseSize: c.Response().Size,
|
||||
ResponseSize: response.Size,
|
||||
Req: request,
|
||||
StatusCode: status,
|
||||
AdditionalAttributes: additionalAttributes,
|
||||
@@ -371,7 +381,7 @@ func telemetryMiddleware(logger *slog.Logger, serverName, correlationIdHeader st
|
||||
|
||||
// basicAuthMiddleware manages basic authentication.
|
||||
func basicAuthMiddleware(username, password string) echo.MiddlewareFunc {
|
||||
return middleware.BasicAuth(func(u string, p string, e echo.Context) (bool, error) {
|
||||
return middleware.BasicAuth(func(c *echo.Context, u string, p string) (bool, error) {
|
||||
if subtle.ConstantTimeCompare([]byte(u), []byte(username)) == 1 &&
|
||||
subtle.ConstantTimeCompare([]byte(p), []byte(password)) == 1 {
|
||||
return true, nil
|
||||
@@ -417,7 +427,7 @@ func (a *Api) buildOidcVerifier() (*oidc.IDTokenVerifier, error) {
|
||||
// it to the client.
|
||||
func oidcAuthMiddleware(verifier *oidc.IDTokenVerifier) echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
rawToken, ok := strings.CutPrefix(c.Request().Header.Get("Authorization"), "Bearer ")
|
||||
if !ok || rawToken == "" {
|
||||
return echo.NewHTTPError(http.StatusUnauthorized, "a Bearer token is required in the Authorization header")
|
||||
@@ -446,7 +456,7 @@ func oidcAuthMiddleware(verifier *oidc.IDTokenVerifier) echo.MiddlewareFunc {
|
||||
// cancel := c.Get("cancel").(context.CancelFunc)
|
||||
func contextMiddleware(fs *gotenberg.FileSystem, timeout time.Duration, bodyLimit int64, downloadFromCfg downloadFromConfig) echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
logger, _ := c.Get("logger").(*slog.Logger)
|
||||
if logger == nil {
|
||||
return errors.New("no logger in context (possible pool reuse)")
|
||||
@@ -507,7 +517,7 @@ func contextMiddleware(fs *gotenberg.FileSystem, timeout time.Duration, bodyLimi
|
||||
// handler fails to timeout as expected.
|
||||
func hardTimeoutMiddleware(hardTimeout time.Duration) echo.MiddlewareFunc {
|
||||
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
// Guard the type assertion so a pooled [echo.Context] whose
|
||||
// store has been recycled under us does not crash the process.
|
||||
// See the webhook async handler for the race this protects
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"crypto/rsa"
|
||||
@@ -9,13 +10,15 @@ import (
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/coreos/go-oidc/v3/oidc"
|
||||
"github.com/coreos/go-oidc/v3/oidc/oidctest"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
)
|
||||
|
||||
// TestRequestCanceled pins the client-abort discriminator: only a
|
||||
@@ -73,7 +76,7 @@ func TestHttpErrorHandler_ClientClosedRequest(t *testing.T) {
|
||||
c := echo.New().NewContext(req, rec)
|
||||
c.Set("logger", slog.New(slog.DiscardHandler))
|
||||
|
||||
httpErrorHandler()(tc.err, c)
|
||||
httpErrorHandler()(c, tc.err)
|
||||
|
||||
if rec.Code != tc.wantStatus {
|
||||
t.Fatalf("status = %d, want %d", rec.Code, tc.wantStatus)
|
||||
@@ -105,7 +108,7 @@ func TestOutputFilenameMiddleware(t *testing.T) {
|
||||
{"control characters", "fo\x01o\x7f", "foo"},
|
||||
} {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
handler := outputFilenameMiddleware()(func(c echo.Context) error { return nil })
|
||||
handler := outputFilenameMiddleware()(func(c *echo.Context) error { return nil })
|
||||
|
||||
req := httptest.NewRequest(http.MethodPost, "/", nil)
|
||||
if tc.header != "" {
|
||||
@@ -131,7 +134,7 @@ func TestOutputFilenameMiddleware(t *testing.T) {
|
||||
|
||||
func TestHardTimeoutMiddleware_MissingLoggerReturnsErrorInsteadOfPanicking(t *testing.T) {
|
||||
mw := hardTimeoutMiddleware(100 * time.Millisecond)
|
||||
handler := mw(func(c echo.Context) error { return nil })
|
||||
handler := mw(func(c *echo.Context) error { return nil })
|
||||
|
||||
e := echo.New()
|
||||
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
@@ -220,7 +223,7 @@ func TestOidcAuthMiddleware(t *testing.T) {
|
||||
}
|
||||
c := echo.New().NewContext(req, httptest.NewRecorder())
|
||||
|
||||
handler := oidcAuthMiddleware(verifier)(func(c echo.Context) error {
|
||||
handler := oidcAuthMiddleware(verifier)(func(c *echo.Context) error {
|
||||
return c.NoContent(http.StatusOK)
|
||||
})
|
||||
|
||||
@@ -243,3 +246,114 @@ func TestOidcAuthMiddleware(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestParseError_StatusMapping pins the statuses [ParseError] derives from the
|
||||
// errors Echo and Gotenberg produce.
|
||||
//
|
||||
// Echo v5 models the router's ErrNotFound and ErrMethodNotAllowed as an
|
||||
// unexported type rather than [echo.HTTPError], so matching that type alone
|
||||
// would turn every unrouted request into a 500. It also guards the ordering:
|
||||
// Gotenberg's own [SentinelHttpError] carries a client-facing message and must
|
||||
// not be shadowed by the generic status lookup.
|
||||
func TestParseError_StatusMapping(t *testing.T) {
|
||||
for _, tc := range []struct {
|
||||
scenario string
|
||||
err error
|
||||
wantStatus int
|
||||
wantMessage string
|
||||
}{
|
||||
{"router not found", echo.ErrNotFound, http.StatusNotFound, http.StatusText(http.StatusNotFound)},
|
||||
{"router method not allowed", echo.ErrMethodNotAllowed, http.StatusMethodNotAllowed, http.StatusText(http.StatusMethodNotAllowed)},
|
||||
{"explicit HTTP error", echo.NewHTTPError(http.StatusUnauthorized, "nope"), http.StatusUnauthorized, http.StatusText(http.StatusUnauthorized)},
|
||||
{"wrapped HTTP error", fmt.Errorf("authenticate request: %w", echo.NewHTTPError(http.StatusUnauthorized, "nope")), http.StatusUnauthorized, http.StatusText(http.StatusUnauthorized)},
|
||||
{"sentinel keeps its message", NewSentinelHttpError(http.StatusBadRequest, "Invalid 'foo' form field value"), http.StatusBadRequest, "Invalid 'foo' form field value"},
|
||||
{"unknown error", errors.New("boom"), http.StatusInternalServerError, http.StatusText(http.StatusInternalServerError)},
|
||||
} {
|
||||
t.Run(tc.scenario, func(t *testing.T) {
|
||||
status, message := ParseError(tc.err)
|
||||
if status != tc.wantStatus {
|
||||
t.Fatalf("status = %d, want %d", status, tc.wantStatus)
|
||||
}
|
||||
if message != tc.wantMessage {
|
||||
t.Fatalf("message = %q, want %q", message, tc.wantMessage)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestNewEchoServer_RealIP pins the client IP extraction that the access log's
|
||||
// "remote_ip" field depends on.
|
||||
//
|
||||
// Echo v5.1.0 dropped the X-Forwarded-For and X-Real-IP fallbacks from
|
||||
// Context.RealIP, so without an explicit extractor a Gotenberg behind a reverse
|
||||
// proxy would log the proxy's address for every request. [newEchoServer]
|
||||
// restores the previous behavior.
|
||||
func TestNewEchoServer_RealIP(t *testing.T) {
|
||||
srv := newEchoServer()
|
||||
if srv.IPExtractor == nil {
|
||||
t.Fatal("no IPExtractor configured: remote_ip would report the proxy address")
|
||||
}
|
||||
|
||||
for _, tc := range []struct {
|
||||
scenario string
|
||||
headers map[string]string
|
||||
want string
|
||||
}{
|
||||
{"x-forwarded-for keeps the client, not the proxy", map[string]string{"X-Forwarded-For": "203.0.113.7, 70.41.3.18"}, "203.0.113.7"},
|
||||
{"single x-forwarded-for", map[string]string{"X-Forwarded-For": "203.0.113.7"}, "203.0.113.7"},
|
||||
{"bracketed IPv6 is unwrapped", map[string]string{"X-Forwarded-For": "[2001:db8::1], 70.41.3.18"}, "2001:db8::1"},
|
||||
{"x-real-ip when no x-forwarded-for", map[string]string{"X-Real-IP": "203.0.113.9"}, "203.0.113.9"},
|
||||
{"no headers falls back to the remote address", nil, "192.0.2.1"},
|
||||
} {
|
||||
t.Run(tc.scenario, func(t *testing.T) {
|
||||
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
req.RemoteAddr = "192.0.2.1:1234"
|
||||
for key, value := range tc.headers {
|
||||
req.Header.Set(key, value)
|
||||
}
|
||||
|
||||
c := srv.NewContext(req, httptest.NewRecorder())
|
||||
|
||||
if got := c.RealIP(); got != tc.want {
|
||||
t.Fatalf("RealIP = %q, want %q", got, tc.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestNewEchoServer_AttachmentServesAbsolutePath pins the filesystem that every
|
||||
// conversion response is sent through.
|
||||
//
|
||||
// Echo v5 serves files through Echo.Filesystem, an [fs.FS] rooted at the working
|
||||
// directory, and [fs.FS] rejects absolute names. Gotenberg builds every output
|
||||
// file under the request's temporary directory and hands Context.Attachment an
|
||||
// absolute path, so with the default filesystem every conversion route answers
|
||||
// 404 while still reading the whole upload.
|
||||
func TestNewEchoServer_AttachmentServesAbsolutePath(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "output.pdf")
|
||||
want := []byte("%PDF-1.7 not really a PDF")
|
||||
|
||||
err := os.WriteFile(path, want, 0o600)
|
||||
if err != nil {
|
||||
t.Fatalf("write fixture: %v", err)
|
||||
}
|
||||
|
||||
srv := newEchoServer()
|
||||
rec := httptest.NewRecorder()
|
||||
c := srv.NewContext(httptest.NewRequest(http.MethodPost, "/", nil), rec)
|
||||
|
||||
err = c.Attachment(path, "output.pdf")
|
||||
if err != nil {
|
||||
t.Fatalf("Attachment(%q) = %v, want nil", path, err)
|
||||
}
|
||||
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d, want %d", rec.Code, http.StatusOK)
|
||||
}
|
||||
if got := rec.Body.Bytes(); !bytes.Equal(got, want) {
|
||||
t.Fatalf("body = %q, want %q", got, want)
|
||||
}
|
||||
if got := rec.Header().Get("Content-Disposition"); !strings.Contains(got, `filename="output.pdf"`) {
|
||||
t.Fatalf("Content-Disposition = %q, want it to carry filename=\"output.pdf\"", got)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@ import (
|
||||
"log/slog"
|
||||
|
||||
"github.com/alexliesenfeld/health"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
)
|
||||
@@ -83,7 +83,7 @@ func (ctx *ContextMock) SetLogger(logger *slog.Logger) {
|
||||
//
|
||||
// ctx := &api.ContextMock{Context: &api.Context{}}
|
||||
// ctx.setEchoContext(c)
|
||||
func (ctx *ContextMock) SetEchoContext(c echo.Context) {
|
||||
func (ctx *ContextMock) SetEchoContext(c *echo.Context) {
|
||||
ctx.echoCtx = c
|
||||
}
|
||||
|
||||
|
||||
@@ -17,7 +17,7 @@ import (
|
||||
"github.com/chromedp/cdproto/page"
|
||||
"github.com/chromedp/cdproto/runtime"
|
||||
"github.com/chromedp/chromedp"
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/shirou/gopsutil/v4/process"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
|
||||
"github.com/alexliesenfeld/health"
|
||||
"github.com/chromedp/cdproto/network"
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
flag "github.com/spf13/pflag"
|
||||
"go.opentelemetry.io/otel/attribute"
|
||||
"go.opentelemetry.io/otel/codes"
|
||||
|
||||
@@ -19,7 +19,7 @@ import (
|
||||
"github.com/chromedp/cdproto/page"
|
||||
"github.com/chromedp/cdproto/runtime"
|
||||
"github.com/chromedp/chromedp"
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"golang.org/x/sync/errgroup"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
@@ -206,7 +206,7 @@ func listenForEventRequestPaused(ctx context.Context, logger *slog.Logger, optio
|
||||
}
|
||||
|
||||
matchStart := time.Now()
|
||||
ok, err := header.Scope.MatchString(e.Request.URL)
|
||||
ok, err := gotenberg.MatchPattern(header.Scope, e.Request.URL)
|
||||
budget.consume(time.Since(matchStart))
|
||||
|
||||
switch {
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
"sync/atomic"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"golang.org/x/net/http/httpproxy"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
|
||||
@@ -18,7 +18,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
)
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
)
|
||||
|
||||
@@ -14,9 +14,9 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"github.com/gomarkdown/markdown"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
"github.com/microcosm-cc/bluemonday"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
@@ -466,7 +466,7 @@ func convertUrlRoute(chromium Api, engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/convert/url",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumPdfOptions(ctx)
|
||||
mode := pdfengines.FormDataPdfSplitMode(form, false)
|
||||
@@ -528,7 +528,7 @@ func screenshotUrlRoute(chromium Api) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/screenshot/url",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumScreenshotOptions(ctx)
|
||||
|
||||
@@ -562,7 +562,7 @@ func convertHtmlRoute(chromium Api, engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/convert/html",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumPdfOptions(ctx)
|
||||
mode := pdfengines.FormDataPdfSplitMode(form, false)
|
||||
@@ -621,7 +621,7 @@ func screenshotHtmlRoute(chromium Api) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/screenshot/html",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumScreenshotOptions(ctx)
|
||||
|
||||
@@ -652,7 +652,7 @@ func convertMarkdownRoute(chromium Api, engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/convert/markdown",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumPdfOptions(ctx)
|
||||
mode := pdfengines.FormDataPdfSplitMode(form, false)
|
||||
@@ -720,7 +720,7 @@ func screenshotMarkdownRoute(chromium Api) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/chromium/screenshot/markdown",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
form, options := FormDataChromiumScreenshotOptions(ctx)
|
||||
|
||||
|
||||
@@ -6,7 +6,9 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
)
|
||||
|
||||
func TestScopeMatchBudget(t *testing.T) {
|
||||
@@ -90,7 +92,7 @@ func TestScopeMatchBudget_BoundsCatastrophicBacktracking(t *testing.T) {
|
||||
break
|
||||
}
|
||||
matchStart := time.Now()
|
||||
_, _ = pattern.MatchString(url)
|
||||
_, _ = gotenberg.MatchPattern(pattern, url)
|
||||
b.consume(time.Since(matchStart))
|
||||
matched++
|
||||
}
|
||||
@@ -100,10 +102,13 @@ func TestScopeMatchBudget_BoundsCatastrophicBacktracking(t *testing.T) {
|
||||
t.Errorf("all %d headers were matched, want the budget to stop matching early", headers)
|
||||
}
|
||||
|
||||
// Each match is separately capped at extraHttpHeaderScopeMatchTimeout, so
|
||||
// the worst case is the budget plus one final match that started with the
|
||||
// last of the credit. Generous slack keeps this stable on a loaded CI box.
|
||||
ceiling := budget + extraHttpHeaderScopeMatchTimeout + time.Second
|
||||
// A match that is genuinely out of budget costs a few
|
||||
// extraHttpHeaderScopeMatchTimeout rather than one:
|
||||
// [gotenberg.MatchPattern] retries an abort to tell a real runaway from
|
||||
// one caused by the process losing the CPU. The worst case is the budget
|
||||
// plus one final match that started with the last of the credit. Generous
|
||||
// slack keeps this stable on a loaded CI box.
|
||||
ceiling := budget + 4*extraHttpHeaderScopeMatchTimeout + time.Second
|
||||
if elapsed > ceiling {
|
||||
t.Errorf("matching took %s, want at most %s", elapsed, ceiling)
|
||||
}
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
"golang.org/x/net/http/httpproxy"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
|
||||
@@ -17,14 +17,14 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
)
|
||||
|
||||
func compileRegexes(t *testing.T, patterns ...string) []*regexp2.Regexp {
|
||||
t.Helper()
|
||||
out := make([]*regexp2.Regexp, 0, len(patterns))
|
||||
for _, p := range patterns {
|
||||
r, err := regexp2.Compile(p, 0)
|
||||
r, err := regexp2.Compile(p, regexp2.None)
|
||||
if err != nil {
|
||||
t.Fatalf("compile %q: %v", p, err)
|
||||
}
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"slices"
|
||||
"strconv"
|
||||
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/modules/api"
|
||||
@@ -27,7 +27,7 @@ func convertRoute(libreOffice libreofficeapi.Uno, engine gotenberg.PdfEngine) ap
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/libreoffice/convert",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
defaultOptions := libreofficeapi.DefaultOptions()
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ import (
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/modules/api"
|
||||
|
||||
@@ -11,7 +11,7 @@ import (
|
||||
"strings"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/modules/api"
|
||||
@@ -1011,7 +1011,7 @@ func mergeRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/merge",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1212,7 +1212,7 @@ func splitRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/split",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1364,7 +1364,7 @@ func flattenRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/flatten",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1399,7 +1399,7 @@ func optimizeRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/optimize",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1435,7 +1435,7 @@ func convertRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/convert",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1492,7 +1492,7 @@ func readMetadataRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/metadata/read",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
var inputPaths []string
|
||||
@@ -1546,7 +1546,7 @@ func writeMetadataRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/metadata/write",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1581,7 +1581,7 @@ func readBookmarksRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/bookmarks/read",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
var inputPaths []string
|
||||
@@ -1634,7 +1634,7 @@ func writeBookmarksRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/bookmarks/write",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1669,7 +1669,7 @@ func encryptRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/encrypt",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1714,7 +1714,7 @@ func embedRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/embed",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1776,7 +1776,7 @@ func watermarkRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/watermark",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1833,7 +1833,7 @@ func stampRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/stamp",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1892,7 +1892,7 @@ func rotateRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/rotate",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
@@ -1929,7 +1929,7 @@ func facturXRoute(engine gotenberg.PdfEngine) api.Route {
|
||||
Method: http.MethodPost,
|
||||
Path: "/forms/pdfengines/factur-x",
|
||||
IsMultipart: true,
|
||||
Handler: func(c echo.Context) error {
|
||||
Handler: func(c *echo.Context) error {
|
||||
ctx := c.Get("context").(*api.Context)
|
||||
|
||||
form := ctx.FormData()
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
"github.com/prometheus/client_golang/prometheus"
|
||||
"github.com/prometheus/client_golang/prometheus/promhttp"
|
||||
flag "github.com/spf13/pflag"
|
||||
|
||||
@@ -11,7 +11,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/go-retryablehttp"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
"go.opentelemetry.io/otel"
|
||||
"go.opentelemetry.io/otel/codes"
|
||||
"go.opentelemetry.io/otel/propagation"
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/go-retryablehttp"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/modules/api"
|
||||
@@ -95,7 +95,7 @@ func webhookMiddleware(w *Webhook) api.Middleware {
|
||||
})
|
||||
}
|
||||
|
||||
return func(c echo.Context) error {
|
||||
return func(c *echo.Context) error {
|
||||
webhookUrl := c.Request().Header.Get("Gotenberg-Webhook-Url")
|
||||
if webhookUrl == "" {
|
||||
// No webhook URL, call the next middleware in the chain.
|
||||
@@ -208,7 +208,7 @@ func webhookMiddleware(w *Webhook) api.Middleware {
|
||||
}
|
||||
}
|
||||
|
||||
// Retrieve values from echo.Context before it gets recycled.
|
||||
// Retrieve values from [echo.Context] before it gets recycled.
|
||||
// See https://github.com/gotenberg/gotenberg/issues/1000.
|
||||
startTime := c.Get("startTime").(time.Time)
|
||||
correlationIdHeader := c.Get("correlationIdHeader").(string)
|
||||
@@ -323,16 +323,16 @@ func webhookMiddleware(w *Webhook) api.Middleware {
|
||||
// As a webhook URL has been given, we handle the request in a
|
||||
// goroutine and return immediately.
|
||||
//
|
||||
// Echo returns the echo.Context back to its sync.Pool as
|
||||
// Echo returns the [echo.Context] back to its sync.Pool as
|
||||
// soon as this synchronous handler returns ErrAsyncProcess.
|
||||
// A concurrent request can then claim the recycled context
|
||||
// and c.Reset() wipes the shared store, which would cause
|
||||
// any c.Get("...").(T) assertion downstream of the webhook
|
||||
// goroutine to panic on a nil value and crash the process.
|
||||
// Snapshot the keys downstream reads onto a detached
|
||||
// wrapper before spawning the goroutine so pool reuse
|
||||
// context before spawning the goroutine so pool reuse
|
||||
// cannot reach into our async work.
|
||||
detached := newPoolSafeContext(c, "logger", "context", "correlationId", "correlationIdHeader", "startTime")
|
||||
detached := newDetachedContext(c, "logger", "context", "correlationId", "correlationIdHeader", "startTime")
|
||||
|
||||
w.asyncCount.Add(1)
|
||||
go func() {
|
||||
|
||||
@@ -1,58 +1,34 @@
|
||||
package webhook
|
||||
|
||||
import (
|
||||
"sync"
|
||||
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
)
|
||||
|
||||
// poolSafeContext wraps an [echo.Context] and keeps a private snapshot of
|
||||
// the values that downstream middleware and route handlers read from the
|
||||
// store. Echo returns an [echo.Context] to its sync.Pool as soon as the
|
||||
// synchronous handler returns, including when the webhook middleware
|
||||
// returns [api.ErrAsyncProcess]. A concurrent request can then claim the
|
||||
// recycled context and c.Reset() wipes the shared store out from under
|
||||
// the webhook goroutine, which causes any
|
||||
// `c.Get("logger").(*slog.Logger)`-style assertion further down the
|
||||
// chain to panic on a nil value.
|
||||
// newDetachedContext returns an [echo.Context] carrying a snapshot of the given
|
||||
// keys, detached from Echo's context pool.
|
||||
//
|
||||
// Wrapping c before handing it to the goroutine insulates the async work
|
||||
// from pool reuse: Get/Set read and write the private store while every
|
||||
// other [echo.Context] method delegates to the embedded context for
|
||||
// anything the downstream might still need.
|
||||
type poolSafeContext struct {
|
||||
echo.Context
|
||||
mu sync.RWMutex
|
||||
store map[string]any
|
||||
}
|
||||
|
||||
// newPoolSafeContext snapshots the given keys from c into a detached
|
||||
// store and returns a wrapper whose Get/Set operate on that store
|
||||
// exclusively. Keys absent from c are omitted; the wrapper still
|
||||
// Echo returns an [echo.Context] to its sync.Pool as soon as the synchronous
|
||||
// handler returns, including when the webhook middleware returns
|
||||
// [api.ErrAsyncProcess]. A concurrent request can then claim the recycled
|
||||
// context and c.Reset() wipes the shared store out from under the webhook
|
||||
// goroutine, which causes any `c.Get("logger").(*slog.Logger)`-style assertion
|
||||
// further down the chain to panic on a nil value.
|
||||
//
|
||||
// [echo.NewContext] allocates outside the pool, so recycling cannot reach the
|
||||
// returned context. Keys absent from c are omitted; the returned context still
|
||||
// returns nil for them, matching [echo.Context.Get] behavior.
|
||||
func newPoolSafeContext(c echo.Context, keys ...string) *poolSafeContext {
|
||||
store := make(map[string]any, len(keys))
|
||||
//
|
||||
// Only the asynchronous path uses this. Nothing downstream of the webhook
|
||||
// middleware writes to the response: contextMiddleware sits upstream and has
|
||||
// already answered 204 by the time the goroutine runs.
|
||||
func newDetachedContext(c *echo.Context, keys ...string) *echo.Context {
|
||||
detached := echo.NewContext(c.Request(), c.Response(), c.Echo())
|
||||
|
||||
for _, key := range keys {
|
||||
if v := c.Get(key); v != nil {
|
||||
store[key] = v
|
||||
detached.Set(key, v)
|
||||
}
|
||||
}
|
||||
return &poolSafeContext{Context: c, store: store}
|
||||
}
|
||||
|
||||
// Get returns the value stored in the detached store, not the embedded
|
||||
// context's pooled store.
|
||||
func (p *poolSafeContext) Get(key string) any {
|
||||
p.mu.RLock()
|
||||
defer p.mu.RUnlock()
|
||||
return p.store[key]
|
||||
}
|
||||
|
||||
// Set writes to the detached store, not the embedded context's pooled
|
||||
// store. This prevents downstream middleware writes from leaking into a
|
||||
// later request that claims the same pooled context.
|
||||
func (p *poolSafeContext) Set(key string, val any) {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
p.store[key] = val
|
||||
return detached
|
||||
}
|
||||
|
||||
@@ -6,10 +6,10 @@ import (
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
)
|
||||
|
||||
func TestPoolSafeContext_SurvivesUnderlyingReset(t *testing.T) {
|
||||
func TestNewDetachedContext_SurvivesUnderlyingReset(t *testing.T) {
|
||||
e := echo.New()
|
||||
req := httptest.NewRequest(http.MethodPost, "/", nil)
|
||||
rec := httptest.NewRecorder()
|
||||
@@ -19,10 +19,10 @@ func TestPoolSafeContext_SurvivesUnderlyingReset(t *testing.T) {
|
||||
c.Set("logger", logger)
|
||||
c.Set("correlationId", "abc-123")
|
||||
|
||||
detached := newPoolSafeContext(c, "logger", "correlationId", "missing")
|
||||
detached := newDetachedContext(c, "logger", "correlationId", "missing")
|
||||
|
||||
// Simulate Echo recycling c for a concurrent request. Reset wipes the
|
||||
// shared store, which is exactly the crash scenario the wrapper
|
||||
// Simulate Echo recycling c for a concurrent request. Reset clears the
|
||||
// pooled store, which is exactly the crash scenario the detached context
|
||||
// guards against.
|
||||
c.Reset(httptest.NewRequest(http.MethodGet, "/", nil), httptest.NewRecorder())
|
||||
|
||||
@@ -38,17 +38,17 @@ func TestPoolSafeContext_SurvivesUnderlyingReset(t *testing.T) {
|
||||
|
||||
// Underlying c must remain clean.
|
||||
if c.Get("logger") != nil {
|
||||
t.Fatalf("underlying c.Get(\"logger\") leaked wrapper state after reset")
|
||||
t.Fatalf("underlying c.Get(\"logger\") leaked detached state after reset")
|
||||
}
|
||||
}
|
||||
|
||||
func TestPoolSafeContext_SetDoesNotTouchUnderlying(t *testing.T) {
|
||||
func TestNewDetachedContext_SetDoesNotTouchUnderlying(t *testing.T) {
|
||||
e := echo.New()
|
||||
req := httptest.NewRequest(http.MethodPost, "/", nil)
|
||||
rec := httptest.NewRecorder()
|
||||
c := e.NewContext(req, rec)
|
||||
|
||||
detached := newPoolSafeContext(c)
|
||||
detached := newDetachedContext(c)
|
||||
detached.Set("foo", "bar")
|
||||
|
||||
if got, _ := detached.Get("foo").(string); got != "bar" {
|
||||
|
||||
@@ -5,7 +5,7 @@ import (
|
||||
"sync/atomic"
|
||||
"time"
|
||||
|
||||
"github.com/dlclark/regexp2"
|
||||
"github.com/dlclark/regexp2/v2"
|
||||
flag "github.com/spf13/pflag"
|
||||
|
||||
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
|
||||
|
||||
@@ -15,7 +15,7 @@ import (
|
||||
|
||||
"github.com/cucumber/godog"
|
||||
"github.com/google/uuid"
|
||||
"github.com/labstack/echo/v4"
|
||||
"github.com/labstack/echo/v5"
|
||||
"github.com/mholt/archives"
|
||||
)
|
||||
|
||||
@@ -26,12 +26,17 @@ type server struct {
|
||||
errChan chan error
|
||||
eventBody []byte
|
||||
eventMu sync.Mutex
|
||||
|
||||
shutdown context.CancelFunc
|
||||
done chan struct{}
|
||||
}
|
||||
|
||||
func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
srv := echo.New()
|
||||
srv.HideBanner = true
|
||||
srv.HidePort = true
|
||||
// The static file handlers below serve absolute paths, which Echo v5's
|
||||
// default working-directory filesystem rejects. See newEchoServer in
|
||||
// pkg/modules/api.
|
||||
srv.Filesystem = echo.NewDefaultFS("/")
|
||||
s := &server{
|
||||
srv: srv,
|
||||
errChan: make(chan error, 1),
|
||||
@@ -47,7 +52,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
return err
|
||||
}
|
||||
|
||||
webhookHandler := func(c echo.Context) error {
|
||||
webhookHandler := func(c *echo.Context) error {
|
||||
s.req = c.Request()
|
||||
|
||||
body, err := io.ReadAll(s.req.Body)
|
||||
@@ -131,7 +136,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
|
||||
return webhookErr(c.String(http.StatusOK, http.StatusText(http.StatusOK)))
|
||||
}
|
||||
webhookErrorHandler := func(c echo.Context) error {
|
||||
webhookErrorHandler := func(c *echo.Context) error {
|
||||
s.req = c.Request()
|
||||
body, err := io.ReadAll(s.req.Body)
|
||||
if err != nil {
|
||||
@@ -148,7 +153,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
srv.PATCH("/webhook/error", webhookErrorHandler)
|
||||
srv.PUT("/webhook/error", webhookErrorHandler)
|
||||
|
||||
webhookEventsHandler := func(c echo.Context) error {
|
||||
webhookEventsHandler := func(c *echo.Context) error {
|
||||
body, err := io.ReadAll(c.Request().Body)
|
||||
if err != nil {
|
||||
return c.String(http.StatusInternalServerError, err.Error())
|
||||
@@ -159,7 +164,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
return c.String(http.StatusOK, http.StatusText(http.StatusOK))
|
||||
}
|
||||
srv.POST("/webhook/events", webhookEventsHandler)
|
||||
srv.GET("/static/:path", func(c echo.Context) error {
|
||||
srv.GET("/static/:path", func(c *echo.Context) error {
|
||||
s.req = c.Request()
|
||||
path := c.Param("path")
|
||||
if strings.Contains(path, "teststore") {
|
||||
@@ -167,7 +172,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
}
|
||||
return c.Attachment(fmt.Sprintf("%s/%s", wd, path), filepath.Base(path))
|
||||
})
|
||||
srv.GET("/html/:path", func(c echo.Context) error {
|
||||
srv.GET("/html/:path", func(c *echo.Context) error {
|
||||
s.req = c.Request()
|
||||
path := fmt.Sprintf("%s/%s", wd, c.Param("path"))
|
||||
f, err := os.Open(path)
|
||||
@@ -181,7 +186,7 @@ func newServer(ctx context.Context, workdir string) (*server, error) {
|
||||
}
|
||||
return c.HTML(http.StatusOK, string(b))
|
||||
})
|
||||
srv.GET("/redirect-to-private", func(c echo.Context) error {
|
||||
srv.GET("/redirect-to-private", func(c *echo.Context) error {
|
||||
s.req = c.Request()
|
||||
// Redirect the browser to a non-public address so the outbound filter
|
||||
// is exercised on the redirected request rather than on this URL.
|
||||
@@ -206,9 +211,20 @@ func (s *server) start(ctx context.Context) (int, error) {
|
||||
|
||||
port := ln.Addr().(*net.TCPAddr).Port
|
||||
|
||||
startConfig := echo.StartConfig{
|
||||
Listener: ln,
|
||||
HideBanner: true,
|
||||
HidePort: true,
|
||||
}
|
||||
|
||||
serveCtx, cancel := context.WithCancel(context.Background())
|
||||
s.shutdown = cancel
|
||||
s.done = make(chan struct{})
|
||||
|
||||
go func() {
|
||||
s.srv.Listener = ln
|
||||
err = s.srv.Start("")
|
||||
defer close(s.done)
|
||||
|
||||
err := startConfig.Start(serveCtx, s.srv)
|
||||
if err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||
godog.Log(ctx, err.Error())
|
||||
}
|
||||
@@ -219,5 +235,17 @@ func (s *server) start(ctx context.Context) (int, error) {
|
||||
|
||||
func (s *server) stop(ctx context.Context) error {
|
||||
close(s.errChan)
|
||||
return s.srv.Shutdown(ctx)
|
||||
|
||||
if s.shutdown == nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
s.shutdown()
|
||||
|
||||
select {
|
||||
case <-s.done:
|
||||
return nil
|
||||
case <-ctx.Done():
|
||||
return ctx.Err()
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user