Skip to content
141 linesCodeBlameRaw
1/**
2 * The usercontent origin (app/lib/usercontent.ts): repository files and
3 * uploaded avatars, on g1tusercontent.com for g1t.sh. This answers before
4 * anything of the site's runs, and reads no cookie and sets none: nothing
5 * here knows who is asking, only what the address and its token say.
6 */
7import { reposClient } from "@g1t/contracts";
8
9import { MAX_RAW_BYTES, PDF_POLICY, USERCONTENT_POLICY, isCommit, parseRawPath, rawHeaders, verifyRaw } from "../app/lib/usercontent";
10
11/** An uploaded avatar, by the SHA-256 of its bytes. */
12export const AVATAR_PATH = /^\/avatars\/([0-9a-f]{64})$/;
13/** A workspace's custom emoji, by the SHA-256 of its bytes: kept by chat under `emoji/<hash>` in the same namespace. */
14export const EMOJI_PATH = /^\/emoji\/([0-9a-f]{64})$/;
15/** A file put in a Docs page, by its random key: kept by the artifacts service (services/artifacts). */
16export const DOCS_FILE_PATH = /^\/docs-files\/([0-9a-f]{64})$/;
17/** The only types identity stores, having checked each image's bytes. */
18const AVATAR_TYPES = new Set(["image/png", "image/jpeg", "image/webp", "image/gif"]);
19
20function plain(status: number, message: string, cache = "no-store"): Response {
21 return new Response(`${message}\n`, {
22 status,
23 headers: {
24 "content-type": "text/plain; charset=utf-8",
25 "cache-control": cache,
26 "x-content-type-options": "nosniff",
27 "content-security-policy": "default-src 'none'; sandbox",
28 },
29 });
30}
31
32/** Answers a request for `path`, the part of its address under the usercontent origin. */
33export async function serveUsercontent(env: Env, ctx: ExecutionContext, request: Request, path: string): Promise<Response> {
34 const method = request.method;
35 if (method !== "GET" && method !== "HEAD") {
36 return new Response("Method not allowed\n", { status: 405, headers: { allow: "GET, HEAD" } });
37 }
38 if (path === "/robots.txt") {
39 return new Response("User-agent: *\nDisallow: /\n", { headers: { "content-type": "text/plain; charset=utf-8", "cache-control": "public, max-age=86400" } });
40 }
41 const avatar = AVATAR_PATH.exec(path);
42 if (avatar) return serveAvatar(env, ctx, method, avatar[1]!, new URL(request.url).origin);
43 const emoji = EMOJI_PATH.exec(path);
44 if (emoji) return serveAvatar(env, ctx, method, `emoji/${emoji[1]!}`, new URL(request.url).origin);
45 const docsFile = DOCS_FILE_PATH.exec(path);
46 if (docsFile) return serveDocsFile(env, method, docsFile[1]!);
47 const file = parseRawPath(path);
48 if (file) return serveRaw(env, request, method, file);
49 return plain(404, "Not found", "public, max-age=300");
50}
51
52/**
53 * A repository's file. A public repository's to anyone; a private one's
54 * only with a token for this very file (routes/repo/raw.ts makes them).
55 */
56async function serveRaw(env: Env, request: Request, method: string, file: NonNullable<ReturnType<typeof parseRawPath>>): Promise<Response> {
57 const repos = reposClient(env.REPOS);
58 const token = new URL(request.url).searchParams.get("token");
59 let repoId: string | null = null;
60 let isPublic = false;
61 if (token) {
62 if (!env.USERCONTENT_KEY) return plain(404, "Not found");
63 repoId = await verifyRaw(env.USERCONTENT_KEY, file, token);
64 if (!repoId) return plain(403, "This address has expired. Open the file on g1t again for a new one.");
65 } else {
66 // No viewer: only a public repository answers.
67 const found = await repos.get({ namespace: file.owner, name: file.repo }, null).catch(() => null);
68 if (!found?.ok) return plain(404, "There is no such file, or it is not public.", "public, max-age=60");
69 repoId = found.value.id;
70 isPublic = true;
71 }
72 const raw = await repos.rawFile(repoId, file.ref, file.path, MAX_RAW_BYTES).catch(() => null);
73 if (!raw) return plain(404, `There is no such file, or it is over ${MAX_RAW_BYTES / 1024 / 1024} MB. Clone the repository for it.`, "public, max-age=60");
74 const bytes = Uint8Array.from(atob(raw.data), (c) => c.charCodeAt(0));
75 const headers = rawHeaders(file.path, bytes);
76 // A commit's files never change; a branch's or tag's may.
77 const lasting = isCommit(file.ref);
78 headers.set(
79 "cache-control",
80 isPublic ? (lasting ? "public, max-age=31536000, immutable" : "public, max-age=60") : lasting ? "private, max-age=3600" : "private, max-age=60",
81 );
82 if (lasting) headers.set("etag", `"${file.ref}"`);
83 return new Response(method === "HEAD" ? null : bytes, { headers });
84}
85
86/**
87 * An uploaded avatar, or a custom emoji (`key` is then `emoji/<hash>`). Its
88 * address is its hash, so it never changes and is
89 * kept for good: each data centre keeps it in its cache after the first
90 * view, and storage is read about once per place, not once per visitor.
91 * It is served as nothing but an image: the stored type, no sniffing, and
92 * a policy that lets nothing in it run.
93 */
94async function serveAvatar(env: Env, ctx: ExecutionContext, method: string, key: string, origin: string): Promise<Response> {
95 // The Workers runtime's own cache, which the DOM types do not know.
96 const cache = (caches as unknown as { default: Cache }).default;
97 const cacheKey = new Request(`${origin}/${key.startsWith("emoji/") ? key : `avatars/${key}`}`, { method: "GET" });
98 const cached = await cache.match(cacheKey);
99 if (cached) {
100 return method === "HEAD" ? new Response(null, { headers: cached.headers }) : cached;
101 }
102 const { value, metadata } = await env.AVATARS.getWithMetadata<{ contentType?: string }>(key, {
103 type: "arrayBuffer",
104 cacheTtl: 86400,
105 });
106 const contentType = metadata?.contentType;
107 if (!value || !contentType || !AVATAR_TYPES.has(contentType)) {
108 return plain(404, "Not found", "public, max-age=60");
109 }
110 const headers = {
111 "content-type": contentType,
112 "content-length": String(value.byteLength),
113 "cache-control": "public, max-age=31536000, immutable",
114 "x-content-type-options": "nosniff",
115 "content-security-policy": "default-src 'none'; sandbox",
116 "cross-origin-resource-policy": "cross-origin",
117 };
118 ctx.waitUntil(cache.put(cacheKey, new Response(value, { headers })));
119 return new Response(method === "HEAD" ? null : value, { headers });
120}
121
122/**
123 * A file put in a Docs page. Its key is 256 random bits the artifacts service
124 * made, so the address is the permission, as a shared link is; the docs
125 * service serves images, media and PDFs as themselves and everything else
126 * as a download, and nothing here can run script.
127 */
128async function serveDocsFile(env: Env, method: string, key: string): Promise<Response> {
129 let answer: Response;
130 try {
131 answer = await env.ARTIFACTS.fetch(`https://docs/files/${key}`, { method });
132 } catch {
133 return plain(503, "Docs didn't answer");
134 }
135 if (!answer.ok) return plain(answer.status === 404 ? 404 : 502, "Not found", "public, max-age=60");
136 const headers = new Headers(answer.headers);
137 headers.set("x-content-type-options", "nosniff");
138 headers.set("content-security-policy", headers.get("content-type") === "application/pdf" ? PDF_POLICY : USERCONTENT_POLICY);
139 headers.set("cross-origin-resource-policy", "cross-origin");
140 return new Response(method === "HEAD" ? null : answer.body, { status: 200, headers });
141}