frontend_proxy.py 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259
  1. #!/usr/bin/env python
  2. # -*- coding: utf-8 -*-
  3. # Copyright 2016 OpenMarket Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. import logging
  17. import sys
  18. from twisted.internet import defer, reactor
  19. from twisted.web.resource import NoResource
  20. import synapse
  21. from synapse import events
  22. from synapse.api.errors import HttpResponseException, SynapseError
  23. from synapse.app import _base
  24. from synapse.config._base import ConfigError
  25. from synapse.config.homeserver import HomeServerConfig
  26. from synapse.config.logger import setup_logging
  27. from synapse.http.server import JsonResource
  28. from synapse.http.servlet import RestServlet, parse_json_object_from_request
  29. from synapse.http.site import SynapseSite
  30. from synapse.logging.context import LoggingContext
  31. from synapse.metrics import METRICS_PREFIX, MetricsResource, RegistryProxy
  32. from synapse.replication.slave.storage._base import BaseSlavedStore
  33. from synapse.replication.slave.storage.appservice import SlavedApplicationServiceStore
  34. from synapse.replication.slave.storage.client_ips import SlavedClientIpStore
  35. from synapse.replication.slave.storage.devices import SlavedDeviceStore
  36. from synapse.replication.slave.storage.registration import SlavedRegistrationStore
  37. from synapse.replication.tcp.client import ReplicationClientHandler
  38. from synapse.rest.client.v2_alpha._base import client_patterns
  39. from synapse.server import HomeServer
  40. from synapse.storage.engines import create_engine
  41. from synapse.util.httpresourcetree import create_resource_tree
  42. from synapse.util.manhole import manhole
  43. from synapse.util.versionstring import get_version_string
  44. logger = logging.getLogger("synapse.app.frontend_proxy")
  45. class PresenceStatusStubServlet(RestServlet):
  46. PATTERNS = client_patterns("/presence/(?P<user_id>[^/]*)/status")
  47. def __init__(self, hs):
  48. super(PresenceStatusStubServlet, self).__init__()
  49. self.http_client = hs.get_simple_http_client()
  50. self.auth = hs.get_auth()
  51. self.main_uri = hs.config.worker_main_http_uri
  52. @defer.inlineCallbacks
  53. def on_GET(self, request, user_id):
  54. # Pass through the auth headers, if any, in case the access token
  55. # is there.
  56. auth_headers = request.requestHeaders.getRawHeaders("Authorization", [])
  57. headers = {"Authorization": auth_headers}
  58. try:
  59. result = yield self.http_client.get_json(
  60. self.main_uri + request.uri.decode("ascii"), headers=headers
  61. )
  62. except HttpResponseException as e:
  63. raise e.to_synapse_error()
  64. return 200, result
  65. @defer.inlineCallbacks
  66. def on_PUT(self, request, user_id):
  67. yield self.auth.get_user_by_req(request)
  68. return 200, {}
  69. class KeyUploadServlet(RestServlet):
  70. PATTERNS = client_patterns("/keys/upload(/(?P<device_id>[^/]+))?$")
  71. def __init__(self, hs):
  72. """
  73. Args:
  74. hs (synapse.server.HomeServer): server
  75. """
  76. super(KeyUploadServlet, self).__init__()
  77. self.auth = hs.get_auth()
  78. self.store = hs.get_datastore()
  79. self.http_client = hs.get_simple_http_client()
  80. self.main_uri = hs.config.worker_main_http_uri
  81. @defer.inlineCallbacks
  82. def on_POST(self, request, device_id):
  83. requester = yield self.auth.get_user_by_req(request, allow_guest=True)
  84. user_id = requester.user.to_string()
  85. body = parse_json_object_from_request(request)
  86. if device_id is not None:
  87. # passing the device_id here is deprecated; however, we allow it
  88. # for now for compatibility with older clients.
  89. if requester.device_id is not None and device_id != requester.device_id:
  90. logger.warning(
  91. "Client uploading keys for a different device "
  92. "(logged in as %s, uploading for %s)",
  93. requester.device_id,
  94. device_id,
  95. )
  96. else:
  97. device_id = requester.device_id
  98. if device_id is None:
  99. raise SynapseError(
  100. 400, "To upload keys, you must pass device_id when authenticating"
  101. )
  102. if body:
  103. # They're actually trying to upload something, proxy to main synapse.
  104. # Pass through the auth headers, if any, in case the access token
  105. # is there.
  106. auth_headers = request.requestHeaders.getRawHeaders(b"Authorization", [])
  107. headers = {"Authorization": auth_headers}
  108. result = yield self.http_client.post_json_get_json(
  109. self.main_uri + request.uri.decode("ascii"), body, headers=headers
  110. )
  111. return 200, result
  112. else:
  113. # Just interested in counts.
  114. result = yield self.store.count_e2e_one_time_keys(user_id, device_id)
  115. return 200, {"one_time_key_counts": result}
  116. class FrontendProxySlavedStore(
  117. SlavedDeviceStore,
  118. SlavedClientIpStore,
  119. SlavedApplicationServiceStore,
  120. SlavedRegistrationStore,
  121. BaseSlavedStore,
  122. ):
  123. pass
  124. class FrontendProxyServer(HomeServer):
  125. DATASTORE_CLASS = FrontendProxySlavedStore
  126. def _listen_http(self, listener_config):
  127. port = listener_config["port"]
  128. bind_addresses = listener_config["bind_addresses"]
  129. site_tag = listener_config.get("tag", port)
  130. resources = {}
  131. for res in listener_config["resources"]:
  132. for name in res["names"]:
  133. if name == "metrics":
  134. resources[METRICS_PREFIX] = MetricsResource(RegistryProxy)
  135. elif name == "client":
  136. resource = JsonResource(self, canonical_json=False)
  137. KeyUploadServlet(self).register(resource)
  138. # If presence is disabled, use the stub servlet that does
  139. # not allow sending presence
  140. if not self.config.use_presence:
  141. PresenceStatusStubServlet(self).register(resource)
  142. resources.update(
  143. {
  144. "/_matrix/client/r0": resource,
  145. "/_matrix/client/unstable": resource,
  146. "/_matrix/client/v2_alpha": resource,
  147. "/_matrix/client/api/v1": resource,
  148. }
  149. )
  150. root_resource = create_resource_tree(resources, NoResource())
  151. _base.listen_tcp(
  152. bind_addresses,
  153. port,
  154. SynapseSite(
  155. "synapse.access.http.%s" % (site_tag,),
  156. site_tag,
  157. listener_config,
  158. root_resource,
  159. self.version_string,
  160. ),
  161. reactor=self.get_reactor(),
  162. )
  163. logger.info("Synapse client reader now listening on port %d", port)
  164. def start_listening(self, listeners):
  165. for listener in listeners:
  166. if listener["type"] == "http":
  167. self._listen_http(listener)
  168. elif listener["type"] == "manhole":
  169. _base.listen_tcp(
  170. listener["bind_addresses"],
  171. listener["port"],
  172. manhole(
  173. username="matrix", password="rabbithole", globals={"hs": self}
  174. ),
  175. )
  176. elif listener["type"] == "metrics":
  177. if not self.get_config().enable_metrics:
  178. logger.warn(
  179. (
  180. "Metrics listener configured, but "
  181. "enable_metrics is not True!"
  182. )
  183. )
  184. else:
  185. _base.listen_metrics(listener["bind_addresses"], listener["port"])
  186. else:
  187. logger.warn("Unrecognized listener type: %s", listener["type"])
  188. self.get_tcp_replication().start_replication(self)
  189. def build_tcp_replication(self):
  190. return ReplicationClientHandler(self.get_datastore())
  191. def start(config_options):
  192. try:
  193. config = HomeServerConfig.load_config("Synapse frontend proxy", config_options)
  194. except ConfigError as e:
  195. sys.stderr.write("\n" + str(e) + "\n")
  196. sys.exit(1)
  197. assert config.worker_app == "synapse.app.frontend_proxy"
  198. assert config.worker_main_http_uri is not None
  199. events.USE_FROZEN_DICTS = config.use_frozen_dicts
  200. database_engine = create_engine(config.database_config)
  201. ss = FrontendProxyServer(
  202. config.server_name,
  203. db_config=config.database_config,
  204. config=config,
  205. version_string="Synapse/" + get_version_string(synapse),
  206. database_engine=database_engine,
  207. )
  208. setup_logging(ss, config, use_worker_options=True)
  209. ss.setup()
  210. reactor.addSystemEventTrigger(
  211. "before", "startup", _base.start, ss, config.worker_listeners
  212. )
  213. _base.start_worker_reactor("synapse-frontend-proxy", config)
  214. if __name__ == "__main__":
  215. with LoggingContext("main"):
  216. start(sys.argv[1:])