frontend_proxy.py 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237
  1. #!/usr/bin/env python
  2. # -*- coding: utf-8 -*-
  3. # Copyright 2016 OpenMarket Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. import logging
  17. import sys
  18. from twisted.internet import defer, reactor
  19. from twisted.web.resource import NoResource
  20. import synapse
  21. from synapse import events
  22. from synapse.api.errors import SynapseError
  23. from synapse.app import _base
  24. from synapse.config._base import ConfigError
  25. from synapse.config.homeserver import HomeServerConfig
  26. from synapse.config.logger import setup_logging
  27. from synapse.crypto import context_factory
  28. from synapse.http.server import JsonResource
  29. from synapse.http.servlet import RestServlet, parse_json_object_from_request
  30. from synapse.http.site import SynapseSite
  31. from synapse.metrics import RegistryProxy
  32. from synapse.metrics.resource import METRICS_PREFIX, MetricsResource
  33. from synapse.replication.slave.storage._base import BaseSlavedStore
  34. from synapse.replication.slave.storage.appservice import SlavedApplicationServiceStore
  35. from synapse.replication.slave.storage.client_ips import SlavedClientIpStore
  36. from synapse.replication.slave.storage.devices import SlavedDeviceStore
  37. from synapse.replication.slave.storage.registration import SlavedRegistrationStore
  38. from synapse.replication.tcp.client import ReplicationClientHandler
  39. from synapse.rest.client.v2_alpha._base import client_v2_patterns
  40. from synapse.server import HomeServer
  41. from synapse.storage.engines import create_engine
  42. from synapse.util.httpresourcetree import create_resource_tree
  43. from synapse.util.logcontext import LoggingContext
  44. from synapse.util.manhole import manhole
  45. from synapse.util.versionstring import get_version_string
  46. logger = logging.getLogger("synapse.app.frontend_proxy")
  47. class KeyUploadServlet(RestServlet):
  48. PATTERNS = client_v2_patterns("/keys/upload(/(?P<device_id>[^/]+))?$")
  49. def __init__(self, hs):
  50. """
  51. Args:
  52. hs (synapse.server.HomeServer): server
  53. """
  54. super(KeyUploadServlet, self).__init__()
  55. self.auth = hs.get_auth()
  56. self.store = hs.get_datastore()
  57. self.http_client = hs.get_simple_http_client()
  58. self.main_uri = hs.config.worker_main_http_uri
  59. @defer.inlineCallbacks
  60. def on_POST(self, request, device_id):
  61. requester = yield self.auth.get_user_by_req(request, allow_guest=True)
  62. user_id = requester.user.to_string()
  63. body = parse_json_object_from_request(request)
  64. if device_id is not None:
  65. # passing the device_id here is deprecated; however, we allow it
  66. # for now for compatibility with older clients.
  67. if (requester.device_id is not None and
  68. device_id != requester.device_id):
  69. logger.warning("Client uploading keys for a different device "
  70. "(logged in as %s, uploading for %s)",
  71. requester.device_id, device_id)
  72. else:
  73. device_id = requester.device_id
  74. if device_id is None:
  75. raise SynapseError(
  76. 400,
  77. "To upload keys, you must pass device_id when authenticating"
  78. )
  79. if body:
  80. # They're actually trying to upload something, proxy to main synapse.
  81. # Pass through the auth headers, if any, in case the access token
  82. # is there.
  83. auth_headers = request.requestHeaders.getRawHeaders(b"Authorization", [])
  84. headers = {
  85. "Authorization": auth_headers,
  86. }
  87. result = yield self.http_client.post_json_get_json(
  88. self.main_uri + request.uri,
  89. body,
  90. headers=headers,
  91. )
  92. defer.returnValue((200, result))
  93. else:
  94. # Just interested in counts.
  95. result = yield self.store.count_e2e_one_time_keys(user_id, device_id)
  96. defer.returnValue((200, {"one_time_key_counts": result}))
  97. class FrontendProxySlavedStore(
  98. SlavedDeviceStore,
  99. SlavedClientIpStore,
  100. SlavedApplicationServiceStore,
  101. SlavedRegistrationStore,
  102. BaseSlavedStore,
  103. ):
  104. pass
  105. class FrontendProxyServer(HomeServer):
  106. def setup(self):
  107. logger.info("Setting up.")
  108. self.datastore = FrontendProxySlavedStore(self.get_db_conn(), self)
  109. logger.info("Finished setting up.")
  110. def _listen_http(self, listener_config):
  111. port = listener_config["port"]
  112. bind_addresses = listener_config["bind_addresses"]
  113. site_tag = listener_config.get("tag", port)
  114. resources = {}
  115. for res in listener_config["resources"]:
  116. for name in res["names"]:
  117. if name == "metrics":
  118. resources[METRICS_PREFIX] = MetricsResource(RegistryProxy)
  119. elif name == "client":
  120. resource = JsonResource(self, canonical_json=False)
  121. KeyUploadServlet(self).register(resource)
  122. resources.update({
  123. "/_matrix/client/r0": resource,
  124. "/_matrix/client/unstable": resource,
  125. "/_matrix/client/v2_alpha": resource,
  126. "/_matrix/client/api/v1": resource,
  127. })
  128. root_resource = create_resource_tree(resources, NoResource())
  129. _base.listen_tcp(
  130. bind_addresses,
  131. port,
  132. SynapseSite(
  133. "synapse.access.http.%s" % (site_tag,),
  134. site_tag,
  135. listener_config,
  136. root_resource,
  137. self.version_string,
  138. )
  139. )
  140. logger.info("Synapse client reader now listening on port %d", port)
  141. def start_listening(self, listeners):
  142. for listener in listeners:
  143. if listener["type"] == "http":
  144. self._listen_http(listener)
  145. elif listener["type"] == "manhole":
  146. _base.listen_tcp(
  147. listener["bind_addresses"],
  148. listener["port"],
  149. manhole(
  150. username="matrix",
  151. password="rabbithole",
  152. globals={"hs": self},
  153. )
  154. )
  155. elif listener["type"] == "metrics":
  156. if not self.get_config().enable_metrics:
  157. logger.warn(("Metrics listener configured, but "
  158. "enable_metrics is not True!"))
  159. else:
  160. _base.listen_metrics(listener["bind_addresses"],
  161. listener["port"])
  162. else:
  163. logger.warn("Unrecognized listener type: %s", listener["type"])
  164. self.get_tcp_replication().start_replication(self)
  165. def build_tcp_replication(self):
  166. return ReplicationClientHandler(self.get_datastore())
  167. def start(config_options):
  168. try:
  169. config = HomeServerConfig.load_config(
  170. "Synapse frontend proxy", config_options
  171. )
  172. except ConfigError as e:
  173. sys.stderr.write("\n" + e.message + "\n")
  174. sys.exit(1)
  175. assert config.worker_app == "synapse.app.frontend_proxy"
  176. assert config.worker_main_http_uri is not None
  177. setup_logging(config, use_worker_options=True)
  178. events.USE_FROZEN_DICTS = config.use_frozen_dicts
  179. database_engine = create_engine(config.database_config)
  180. tls_server_context_factory = context_factory.ServerContextFactory(config)
  181. tls_client_options_factory = context_factory.ClientTLSOptionsFactory(config)
  182. ss = FrontendProxyServer(
  183. config.server_name,
  184. db_config=config.database_config,
  185. tls_server_context_factory=tls_server_context_factory,
  186. tls_client_options_factory=tls_client_options_factory,
  187. config=config,
  188. version_string="Synapse/" + get_version_string(synapse),
  189. database_engine=database_engine,
  190. )
  191. ss.setup()
  192. ss.start_listening(config.worker_listeners)
  193. def start():
  194. ss.get_state_handler().start_caching()
  195. ss.get_datastore().start_profiling()
  196. reactor.callWhenRunning(start)
  197. _base.start_worker_reactor("synapse-frontend-proxy", config)
  198. if __name__ == '__main__':
  199. with LoggingContext("main"):
  200. start(sys.argv[1:])