| 1 | /** |
| 2 | * Download ZIP: a branch, tag or commit of a repository as one zip, its |
| 3 | * files under `<repo>-<ref>/` as `git archive` would name them. For anyone |
| 4 | * who can see the repository. Made on request and not kept, so it is capped: |
| 5 | * a repository past the caps is cloned instead. |
| 6 | */ |
| 7 | import type { Route } from "./+types/archive"; |
| 8 | import { repos } from "../../lib/services.server"; |
| 9 | import { getViewer } from "../../lib/session.server"; |
| 10 | import { zip } from "../../lib/zip"; |
| 11 | |
| 12 | /** The most files, and bytes in all, an archive is made of. */ |
| 13 | const MAX_FILES = 10_000; |
| 14 | // The bytes, their base64 and the zip are all held at once, in a Worker of 128 MB. |
| 15 | const MAX_BYTES = 24 * 1024 * 1024; |
| 16 | /** Blobs read per call to the repository, and calls at once. */ |
| 17 | const PER_READ = 100; |
| 18 | const READS_AT_ONCE = 8; |
| 19 | |
| 20 | function refused(status: number, message: string): Response { |
| 21 | return new Response(`${message}\n`, { status, headers: { "content-type": "text/plain; charset=utf-8", "cache-control": "no-store" } }); |
| 22 | } |
| 23 | |
| 24 | export async function loader({ params, context }: Route.LoaderArgs) { |
| 25 | const viewer = getViewer(context); |
| 26 | const asked = params["*"] ?? ""; |
| 27 | if (!asked.endsWith(".zip") || asked.length <= 4) return refused(404, "Ask for <branch, tag or commit>.zip."); |
| 28 | const ref = asked.slice(0, -4); |
| 29 | const repo = await repos.get({ namespace: params.owner, name: params.repo }, viewer).catch(() => null); |
| 30 | if (!repo?.ok) return refused(404, "There is no such repository, or you cannot see it."); |
| 31 | const listed = await repos.listFiles(repo.value.id, ref, MAX_FILES + 1).catch(() => null); |
| 32 | if (!listed?.commit) return refused(404, `There is no branch, tag or commit named ${ref}.`); |
| 33 | const clone = `git clone https://g1t.sh/${repo.value.namespace}/${repo.value.name}.git`; |
| 34 | if (listed.truncated || listed.files.length > MAX_FILES) { |
| 35 | return refused(413, `It has more than ${MAX_FILES.toLocaleString("en-US")} files, too many for a download. Clone it instead: ${clone}`); |
| 36 | } |
| 37 | const files = listed.files.filter((file): file is { path: string; hash: string } => file.hash != null); |
| 38 | const unique = [...new Set(files.map((file) => file.hash))]; |
| 39 | const bytes = new Map<string, Uint8Array>(); |
| 40 | let total = 0; |
| 41 | let tooLarge = false; |
| 42 | const batches: string[][] = []; |
| 43 | for (let at = 0; at < unique.length; at += PER_READ) batches.push(unique.slice(at, at + PER_READ)); |
| 44 | // A few reads at a time, each taking the next batch, until all are read or it is too large. |
| 45 | const reader = async () => { |
| 46 | for (let batch = batches.shift(); batch && !tooLarge; batch = batches.shift()) { |
| 47 | for (const blob of await repos.rawBlobs(repo.value.id, batch, MAX_BYTES)) { |
| 48 | total += blob.size; |
| 49 | if (total > MAX_BYTES || (blob.data == null && blob.size > 0)) tooLarge = true; |
| 50 | else bytes.set(blob.hash, Uint8Array.from(atob(blob.data ?? ""), (c) => c.charCodeAt(0))); |
| 51 | } |
| 52 | } |
| 53 | }; |
| 54 | await Promise.all(Array.from({ length: READS_AT_ONCE }, reader)); |
| 55 | if (tooLarge) return refused(413, `It is over ${MAX_BYTES / 1024 / 1024} MB, too large for a download. Clone it instead: ${clone}`); |
| 56 | // A branch name can hold slashes; the folder and file name cannot. |
| 57 | const label = `${repo.value.name}-${ref.replaceAll("/", "-")}`; |
| 58 | const archive = await zip(files.map((file) => ({ path: `${label}/${file.path}`, data: bytes.get(file.hash) ?? new Uint8Array() }))); |
| 59 | return new Response(archive, { |
| 60 | headers: { |
| 61 | "content-type": "application/zip", |
| 62 | "content-disposition": `attachment; filename="${label}.zip"`, |
| 63 | // A commit's files never change; a branch's do. |
| 64 | "cache-control": /^[0-9a-f]{40}$/.test(ref) ? "private, max-age=31536000, immutable" : "private, no-cache", |
| 65 | }, |
| 66 | }); |
| 67 | } |