request.rb 2.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107
  1. # frozen_string_literal: true
  2. require 'ipaddr'
  3. require 'socket'
  4. class Request
  5. REQUEST_TARGET = '(request-target)'
  6. include RoutingHelper
  7. def initialize(verb, url, **options)
  8. @verb = verb
  9. @url = Addressable::URI.parse(url).normalize
  10. @options = options.merge(socket_class: Socket)
  11. @headers = {}
  12. set_common_headers!
  13. set_digest! if options.key?(:body)
  14. end
  15. def on_behalf_of(account, key_id_format = :acct)
  16. raise ArgumentError unless account.local?
  17. @account = account
  18. @key_id_format = key_id_format
  19. self
  20. end
  21. def add_headers(new_headers)
  22. @headers.merge!(new_headers)
  23. self
  24. end
  25. def perform
  26. http_client.headers(headers).public_send(@verb, @url.to_s, @options)
  27. rescue => e
  28. raise e.class, "#{e.message} on #{@url}", e.backtrace[0]
  29. end
  30. def headers
  31. (@account ? @headers.merge('Signature' => signature) : @headers).without(REQUEST_TARGET)
  32. end
  33. private
  34. def set_common_headers!
  35. @headers[REQUEST_TARGET] = "#{@verb} #{@url.path}"
  36. @headers['User-Agent'] = user_agent
  37. @headers['Host'] = @url.host
  38. @headers['Date'] = Time.now.utc.httpdate
  39. end
  40. def set_digest!
  41. @headers['Digest'] = "SHA-256=#{Digest::SHA256.base64digest(@options[:body])}"
  42. end
  43. def signature
  44. algorithm = 'rsa-sha256'
  45. signature = Base64.strict_encode64(@account.keypair.sign(OpenSSL::Digest::SHA256.new, signed_string))
  46. "keyId=\"#{key_id}\",algorithm=\"#{algorithm}\",headers=\"#{signed_headers}\",signature=\"#{signature}\""
  47. end
  48. def signed_string
  49. @headers.map { |key, value| "#{key.downcase}: #{value}" }.join("\n")
  50. end
  51. def signed_headers
  52. @headers.keys.join(' ').downcase
  53. end
  54. def user_agent
  55. @user_agent ||= "#{HTTP::Request::USER_AGENT} (Mastodon/#{Mastodon::Version}; +#{root_url})"
  56. end
  57. def key_id
  58. case @key_id_format
  59. when :acct
  60. @account.to_webfinger_s
  61. when :uri
  62. [ActivityPub::TagManager.instance.uri_for(@account), '#main-key'].join
  63. end
  64. end
  65. def timeout
  66. { write: 10, connect: 10, read: 10 }
  67. end
  68. def http_client
  69. HTTP.timeout(:per_operation, timeout).follow(max_hops: 2)
  70. end
  71. class Socket < TCPSocket
  72. class << self
  73. def open(host, *args)
  74. address = IPSocket.getaddress(host)
  75. raise Mastodon::HostValidationError if PrivateAddressCheck.private_address? IPAddr.new(address)
  76. super address, *args
  77. end
  78. alias new open
  79. end
  80. end
  81. private_constant :Socket
  82. end