Skip to content

Commit 6599756

Browse files
author
Brian Tiger Chow
committed
Merge pull request #741 from jbenet/feat/blocklist
add blocklist to gateway executable
2 parents 4c920d0 + 9c489c3 commit 6599756

File tree

3 files changed

+130
-17
lines changed

3 files changed

+130
-17
lines changed

cmd/ipfs-gateway-fs/main.go

+59-8
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
package main
22

33
import (
4+
"bufio"
45
"errors"
56
"flag"
67
"log"
@@ -17,13 +18,15 @@ import (
1718
)
1819

1920
var (
20-
writable = flag.Bool("writable", false, "enable writing objects (with POST, PUT and DELETE)")
21-
refreshAssetsInterval = flag.Duration("refresh-assets-interval", 30*time.Second, "refresh assets")
22-
garbageCollectInterval = flag.Duration("gc-interval", 24*time.Hour, "frequency of repo garbage collection")
23-
assetsPath = flag.String("assets-path", "", "if provided, periodically adds contents of path to IPFS")
24-
host = flag.String("host", "/ip4/0.0.0.0/tcp/8080", "override the HTTP host listening address")
25-
performGC = flag.Bool("gc", false, "perform garbage collection")
26-
nBitsForKeypair = flag.Int("b", 1024, "number of bits for keypair (if repo is uninitialized)")
21+
blocklistFilepath = flag.String("blocklist", "", "keys that should not be served by the gateway")
22+
writable = flag.Bool("writable", false, "enable writing objects (with POST, PUT and DELETE)")
23+
refreshBlockListInterval = flag.Duration("refresh-blocklist-interval", 30*time.Second, "refresh blocklist")
24+
refreshAssetsInterval = flag.Duration("refresh-assets-interval", 30*time.Second, "refresh assets")
25+
garbageCollectInterval = flag.Duration("gc-interval", 24*time.Hour, "frequency of repo garbage collection")
26+
assetsPath = flag.String("assets-path", "", "if provided, periodically adds contents of path to IPFS")
27+
host = flag.String("host", "/ip4/0.0.0.0/tcp/8080", "override the HTTP host listening address")
28+
performGC = flag.Bool("gc", false, "perform garbage collection")
29+
nBitsForKeypair = flag.Int("b", 1024, "number of bits for keypair (if repo is uninitialized)")
2730
)
2831

2932
func main() {
@@ -77,8 +80,18 @@ func run() error {
7780
}
7881
}
7982

83+
blocklist := &corehttp.BlockList{}
84+
gateway := corehttp.NewGateway(corehttp.GatewayConfig{
85+
Writable: *writable,
86+
BlockList: blocklist,
87+
})
88+
89+
if err := runBlockListWorker(blocklist, *blocklistFilepath); err != nil {
90+
return err
91+
}
92+
8093
opts := []corehttp.ServeOption{
81-
corehttp.GatewayOption(*writable),
94+
gateway.ServeOption(),
8295
}
8396
return corehttp.ListenAndServe(node, *host, opts...)
8497
}
@@ -112,3 +125,41 @@ func runFileServerWorker(ctx context.Context, node *core.IpfsNode) error {
112125
}()
113126
return nil
114127
}
128+
129+
func runBlockListWorker(blocklist *corehttp.BlockList, filepath string) error {
130+
if filepath == "" {
131+
return nil
132+
}
133+
go func() {
134+
for _ = range time.Tick(*refreshBlockListInterval) {
135+
log.Println("updating the blocklist...")
136+
func() { // in a func to allow defer f.Close()
137+
f, err := os.Open(filepath)
138+
if err != nil {
139+
log.Println(err)
140+
}
141+
defer f.Close()
142+
scanner := bufio.NewScanner(f)
143+
blocked := make(map[string]struct{}) // Implement using Bloom Filter hybrid if blocklist gets large
144+
for scanner.Scan() {
145+
t := scanner.Text()
146+
blocked[t] = struct{}{}
147+
}
148+
149+
// If an error occurred, do not change the existing decider. This
150+
// is to avoid accidentally clearing the list if the deploy is
151+
// botched.
152+
if err := scanner.Err(); err != nil {
153+
log.Println(err)
154+
} else {
155+
blocklist.SetDecider(func(s string) bool {
156+
_, ok := blocked[s]
157+
return !ok
158+
})
159+
log.Printf("updated the blocklist (%d entries)", len(blocked))
160+
}
161+
}()
162+
}
163+
}()
164+
return nil
165+
}

core/corehttp/gateway.go

+57-2
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,30 @@ package corehttp
22

33
import (
44
"net/http"
5+
"sync"
56

67
core "github.com/jbenet/go-ipfs/core"
78
)
89

9-
func GatewayOption(writable bool) ServeOption {
10+
// Gateway should be instantiated using NewGateway
11+
type Gateway struct {
12+
Config GatewayConfig
13+
}
14+
15+
type GatewayConfig struct {
16+
BlockList *BlockList
17+
Writable bool
18+
}
19+
20+
func NewGateway(conf GatewayConfig) *Gateway {
21+
return &Gateway{
22+
Config: conf,
23+
}
24+
}
25+
26+
func (g *Gateway) ServeOption() ServeOption {
1027
return func(n *core.IpfsNode, mux *http.ServeMux) error {
11-
gateway, err := newGatewayHandler(n, writable)
28+
gateway, err := newGatewayHandler(n, g.Config)
1229
if err != nil {
1330
return err
1431
}
@@ -17,3 +34,41 @@ func GatewayOption(writable bool) ServeOption {
1734
return nil
1835
}
1936
}
37+
38+
func GatewayOption(writable bool) ServeOption {
39+
g := NewGateway(GatewayConfig{
40+
Writable: writable,
41+
BlockList: &BlockList{},
42+
})
43+
return g.ServeOption()
44+
}
45+
46+
// Decider decides whether to Allow string
47+
type Decider func(string) bool
48+
49+
type BlockList struct {
50+
51+
mu sync.RWMutex
52+
d Decider
53+
}
54+
55+
func (b *BlockList) ShouldAllow(s string) bool {
56+
b.mu.RLock()
57+
d := b.d
58+
b.mu.RUnlock()
59+
if d == nil {
60+
return true
61+
}
62+
return d(s)
63+
}
64+
65+
// SetDecider atomically swaps the blocklist's decider
66+
func (b *BlockList) SetDecider(d Decider) {
67+
b.mu.Lock()
68+
b.d = d
69+
b.mu.Unlock()
70+
}
71+
72+
func (b *BlockList) ShouldBlock(s string) bool {
73+
return !b.ShouldAllow(s)
74+
}

core/corehttp/gateway_handler.go

+14-7
Original file line numberDiff line numberDiff line change
@@ -50,13 +50,13 @@ type directoryItem struct {
5050
type gatewayHandler struct {
5151
node *core.IpfsNode
5252
dirList *template.Template
53-
writable bool
53+
config GatewayConfig
5454
}
5555

56-
func newGatewayHandler(node *core.IpfsNode, writable bool) (*gatewayHandler, error) {
56+
func newGatewayHandler(node *core.IpfsNode, conf GatewayConfig) (*gatewayHandler, error) {
5757
i := &gatewayHandler{
5858
node: node,
59-
writable: writable,
59+
config: conf,
6060
}
6161
err := i.loadTemplate()
6262
if err != nil {
@@ -125,18 +125,20 @@ func (i *gatewayHandler) NewDagReader(nd *dag.Node) (uio.ReadSeekCloser, error)
125125
return uio.NewDagReader(i.node.Context(), nd, i.node.DAG)
126126
}
127127

128+
// TODO(btc): break this apart into separate handlers using a more expressive
129+
// muxer
128130
func (i *gatewayHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
129-
if i.writable && r.Method == "POST" {
131+
if i.config.Writable && r.Method == "POST" {
130132
i.postHandler(w, r)
131133
return
132134
}
133135

134-
if i.writable && r.Method == "PUT" {
136+
if i.config.Writable && r.Method == "PUT" {
135137
i.putHandler(w, r)
136138
return
137139
}
138140

139-
if i.writable && r.Method == "DELETE" {
141+
if i.config.Writable && r.Method == "DELETE" {
140142
i.deleteHandler(w, r)
141143
return
142144
}
@@ -147,7 +149,7 @@ func (i *gatewayHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
147149
}
148150

149151
errmsg := "Method " + r.Method + " not allowed: "
150-
if !i.writable {
152+
if !i.config.Writable {
151153
w.WriteHeader(http.StatusMethodNotAllowed)
152154
errmsg = errmsg + "read only access"
153155
} else {
@@ -164,6 +166,11 @@ func (i *gatewayHandler) getHandler(w http.ResponseWriter, r *http.Request) {
164166

165167
urlPath := r.URL.Path
166168

169+
if i.config.BlockList != nil && i.config.BlockList.ShouldBlock(urlPath) {
170+
w.WriteHeader(http.StatusNotFound)
171+
return
172+
}
173+
167174
nd, p, err := i.ResolvePath(ctx, urlPath)
168175
if err != nil {
169176
if err == routing.ErrNotFound {

0 commit comments

Comments
 (0)