frontend_proxy.py 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254
  1. #!/usr/bin/env python
  2. # -*- coding: utf-8 -*-
  3. # Copyright 2016 OpenMarket Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. import logging
  17. import sys
  18. from twisted.internet import defer, reactor
  19. from twisted.web.resource import NoResource
  20. import synapse
  21. from synapse import events
  22. from synapse.api.errors import HttpResponseException, SynapseError
  23. from synapse.app import _base
  24. from synapse.config._base import ConfigError
  25. from synapse.config.homeserver import HomeServerConfig
  26. from synapse.config.logger import setup_logging
  27. from synapse.http.server import JsonResource
  28. from synapse.http.servlet import RestServlet, parse_json_object_from_request
  29. from synapse.http.site import SynapseSite
  30. from synapse.logging.context import LoggingContext
  31. from synapse.metrics import METRICS_PREFIX, MetricsResource, RegistryProxy
  32. from synapse.replication.slave.storage._base import BaseSlavedStore
  33. from synapse.replication.slave.storage.appservice import SlavedApplicationServiceStore
  34. from synapse.replication.slave.storage.client_ips import SlavedClientIpStore
  35. from synapse.replication.slave.storage.devices import SlavedDeviceStore
  36. from synapse.replication.slave.storage.registration import SlavedRegistrationStore
  37. from synapse.replication.tcp.client import ReplicationClientHandler
  38. from synapse.rest.client.v2_alpha._base import client_patterns
  39. from synapse.server import HomeServer
  40. from synapse.util.httpresourcetree import create_resource_tree
  41. from synapse.util.manhole import manhole
  42. from synapse.util.versionstring import get_version_string
  43. logger = logging.getLogger("synapse.app.frontend_proxy")
  44. class PresenceStatusStubServlet(RestServlet):
  45. PATTERNS = client_patterns("/presence/(?P<user_id>[^/]*)/status")
  46. def __init__(self, hs):
  47. super(PresenceStatusStubServlet, self).__init__()
  48. self.http_client = hs.get_simple_http_client()
  49. self.auth = hs.get_auth()
  50. self.main_uri = hs.config.worker_main_http_uri
  51. @defer.inlineCallbacks
  52. def on_GET(self, request, user_id):
  53. # Pass through the auth headers, if any, in case the access token
  54. # is there.
  55. auth_headers = request.requestHeaders.getRawHeaders("Authorization", [])
  56. headers = {"Authorization": auth_headers}
  57. try:
  58. result = yield self.http_client.get_json(
  59. self.main_uri + request.uri.decode("ascii"), headers=headers
  60. )
  61. except HttpResponseException as e:
  62. raise e.to_synapse_error()
  63. return 200, result
  64. @defer.inlineCallbacks
  65. def on_PUT(self, request, user_id):
  66. yield self.auth.get_user_by_req(request)
  67. return 200, {}
  68. class KeyUploadServlet(RestServlet):
  69. PATTERNS = client_patterns("/keys/upload(/(?P<device_id>[^/]+))?$")
  70. def __init__(self, hs):
  71. """
  72. Args:
  73. hs (synapse.server.HomeServer): server
  74. """
  75. super(KeyUploadServlet, self).__init__()
  76. self.auth = hs.get_auth()
  77. self.store = hs.get_datastore()
  78. self.http_client = hs.get_simple_http_client()
  79. self.main_uri = hs.config.worker_main_http_uri
  80. @defer.inlineCallbacks
  81. def on_POST(self, request, device_id):
  82. requester = yield self.auth.get_user_by_req(request, allow_guest=True)
  83. user_id = requester.user.to_string()
  84. body = parse_json_object_from_request(request)
  85. if device_id is not None:
  86. # passing the device_id here is deprecated; however, we allow it
  87. # for now for compatibility with older clients.
  88. if requester.device_id is not None and device_id != requester.device_id:
  89. logger.warning(
  90. "Client uploading keys for a different device "
  91. "(logged in as %s, uploading for %s)",
  92. requester.device_id,
  93. device_id,
  94. )
  95. else:
  96. device_id = requester.device_id
  97. if device_id is None:
  98. raise SynapseError(
  99. 400, "To upload keys, you must pass device_id when authenticating"
  100. )
  101. if body:
  102. # They're actually trying to upload something, proxy to main synapse.
  103. # Pass through the auth headers, if any, in case the access token
  104. # is there.
  105. auth_headers = request.requestHeaders.getRawHeaders(b"Authorization", [])
  106. headers = {"Authorization": auth_headers}
  107. result = yield self.http_client.post_json_get_json(
  108. self.main_uri + request.uri.decode("ascii"), body, headers=headers
  109. )
  110. return 200, result
  111. else:
  112. # Just interested in counts.
  113. result = yield self.store.count_e2e_one_time_keys(user_id, device_id)
  114. return 200, {"one_time_key_counts": result}
  115. class FrontendProxySlavedStore(
  116. SlavedDeviceStore,
  117. SlavedClientIpStore,
  118. SlavedApplicationServiceStore,
  119. SlavedRegistrationStore,
  120. BaseSlavedStore,
  121. ):
  122. pass
  123. class FrontendProxyServer(HomeServer):
  124. DATASTORE_CLASS = FrontendProxySlavedStore
  125. def _listen_http(self, listener_config):
  126. port = listener_config["port"]
  127. bind_addresses = listener_config["bind_addresses"]
  128. site_tag = listener_config.get("tag", port)
  129. resources = {}
  130. for res in listener_config["resources"]:
  131. for name in res["names"]:
  132. if name == "metrics":
  133. resources[METRICS_PREFIX] = MetricsResource(RegistryProxy)
  134. elif name == "client":
  135. resource = JsonResource(self, canonical_json=False)
  136. KeyUploadServlet(self).register(resource)
  137. # If presence is disabled, use the stub servlet that does
  138. # not allow sending presence
  139. if not self.config.use_presence:
  140. PresenceStatusStubServlet(self).register(resource)
  141. resources.update(
  142. {
  143. "/_matrix/client/r0": resource,
  144. "/_matrix/client/unstable": resource,
  145. "/_matrix/client/v2_alpha": resource,
  146. "/_matrix/client/api/v1": resource,
  147. }
  148. )
  149. root_resource = create_resource_tree(resources, NoResource())
  150. _base.listen_tcp(
  151. bind_addresses,
  152. port,
  153. SynapseSite(
  154. "synapse.access.http.%s" % (site_tag,),
  155. site_tag,
  156. listener_config,
  157. root_resource,
  158. self.version_string,
  159. ),
  160. reactor=self.get_reactor(),
  161. )
  162. logger.info("Synapse client reader now listening on port %d", port)
  163. def start_listening(self, listeners):
  164. for listener in listeners:
  165. if listener["type"] == "http":
  166. self._listen_http(listener)
  167. elif listener["type"] == "manhole":
  168. _base.listen_tcp(
  169. listener["bind_addresses"],
  170. listener["port"],
  171. manhole(
  172. username="matrix", password="rabbithole", globals={"hs": self}
  173. ),
  174. )
  175. elif listener["type"] == "metrics":
  176. if not self.get_config().enable_metrics:
  177. logger.warning(
  178. (
  179. "Metrics listener configured, but "
  180. "enable_metrics is not True!"
  181. )
  182. )
  183. else:
  184. _base.listen_metrics(listener["bind_addresses"], listener["port"])
  185. else:
  186. logger.warning("Unrecognized listener type: %s", listener["type"])
  187. self.get_tcp_replication().start_replication(self)
  188. def build_tcp_replication(self):
  189. return ReplicationClientHandler(self.get_datastore())
  190. def start(config_options):
  191. try:
  192. config = HomeServerConfig.load_config("Synapse frontend proxy", config_options)
  193. except ConfigError as e:
  194. sys.stderr.write("\n" + str(e) + "\n")
  195. sys.exit(1)
  196. assert config.worker_app == "synapse.app.frontend_proxy"
  197. assert config.worker_main_http_uri is not None
  198. events.USE_FROZEN_DICTS = config.use_frozen_dicts
  199. ss = FrontendProxyServer(
  200. config.server_name,
  201. config=config,
  202. version_string="Synapse/" + get_version_string(synapse),
  203. )
  204. setup_logging(ss, config, use_worker_options=True)
  205. ss.setup()
  206. reactor.addSystemEventTrigger(
  207. "before", "startup", _base.start, ss, config.worker_listeners
  208. )
  209. _base.start_worker_reactor("synapse-frontend-proxy", config)
  210. if __name__ == "__main__":
  211. with LoggingContext("main"):
  212. start(sys.argv[1:])