2019-10-07 08:14:47 -06:00
|
|
|
// Copyright (c) Mainflux
|
2018-08-26 13:15:48 +02:00
|
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
|
2018-08-06 17:06:55 +02:00
|
|
|
package api
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"encoding/json"
|
|
|
|
"net/http"
|
|
|
|
|
|
|
|
kithttp "github.com/go-kit/kit/transport/http"
|
|
|
|
"github.com/go-zoo/bone"
|
|
|
|
"github.com/mainflux/mainflux"
|
2022-03-03 17:13:46 +01:00
|
|
|
"github.com/mainflux/mainflux/internal/apiutil"
|
2020-06-03 15:16:19 +02:00
|
|
|
"github.com/mainflux/mainflux/pkg/errors"
|
2018-08-06 17:06:55 +02:00
|
|
|
"github.com/mainflux/mainflux/readers"
|
2023-06-14 12:40:37 +02:00
|
|
|
tpolicies "github.com/mainflux/mainflux/things/policies"
|
|
|
|
upolicies "github.com/mainflux/mainflux/users/policies"
|
2018-08-06 17:06:55 +02:00
|
|
|
"github.com/prometheus/client_golang/prometheus/promhttp"
|
|
|
|
"google.golang.org/grpc/codes"
|
|
|
|
"google.golang.org/grpc/status"
|
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2022-03-06 01:49:34 +01:00
|
|
|
contentType = "application/json"
|
|
|
|
offsetKey = "offset"
|
|
|
|
limitKey = "limit"
|
|
|
|
formatKey = "format"
|
|
|
|
subtopicKey = "subtopic"
|
|
|
|
publisherKey = "publisher"
|
|
|
|
protocolKey = "protocol"
|
|
|
|
nameKey = "name"
|
|
|
|
valueKey = "v"
|
|
|
|
stringValueKey = "vs"
|
|
|
|
dataValueKey = "vd"
|
|
|
|
boolValueKey = "vb"
|
|
|
|
comparatorKey = "comparator"
|
|
|
|
fromKey = "from"
|
|
|
|
toKey = "to"
|
|
|
|
defLimit = 10
|
|
|
|
defOffset = 0
|
|
|
|
defFormat = "messages"
|
2018-08-06 17:06:55 +02:00
|
|
|
)
|
|
|
|
|
2022-02-09 21:25:34 +01:00
|
|
|
var (
|
|
|
|
errThingAccess = errors.New("thing has no permission")
|
|
|
|
errUserAccess = errors.New("user has no permission")
|
|
|
|
)
|
2018-08-06 17:06:55 +02:00
|
|
|
|
|
|
|
// MakeHandler returns a HTTP handler for API endpoints.
|
2023-06-14 12:40:37 +02:00
|
|
|
func MakeHandler(svc readers.MessageRepository, tc tpolicies.ThingsServiceClient, ac upolicies.AuthServiceClient, svcName string) http.Handler {
|
2018-08-06 17:06:55 +02:00
|
|
|
|
|
|
|
opts := []kithttp.ServerOption{
|
|
|
|
kithttp.ServerErrorEncoder(encodeError),
|
|
|
|
}
|
|
|
|
|
|
|
|
mux := bone.New()
|
|
|
|
mux.Get("/channels/:chanID/messages", kithttp.NewServer(
|
2022-02-09 21:25:34 +01:00
|
|
|
listMessagesEndpoint(svc, tc, ac),
|
2018-08-06 17:06:55 +02:00
|
|
|
decodeList,
|
|
|
|
encodeResponse,
|
|
|
|
opts...,
|
|
|
|
))
|
|
|
|
|
2022-01-24 21:18:53 +01:00
|
|
|
mux.GetFunc("/health", mainflux.Health(svcName))
|
2018-08-06 17:06:55 +02:00
|
|
|
mux.Handle("/metrics", promhttp.Handler())
|
|
|
|
|
|
|
|
return mux
|
|
|
|
}
|
|
|
|
|
2023-06-14 12:40:37 +02:00
|
|
|
func decodeList(_ context.Context, r *http.Request) (interface{}, error) {
|
2022-03-03 17:13:46 +01:00
|
|
|
offset, err := apiutil.ReadUintQuery(r, offsetKey, defOffset)
|
2018-08-06 17:06:55 +02:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
limit, err := apiutil.ReadUintQuery(r, limitKey, defLimit)
|
2018-08-06 17:06:55 +02:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
format, err := apiutil.ReadStringQuery(r, formatKey, defFormat)
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
subtopic, err := apiutil.ReadStringQuery(r, subtopicKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
publisher, err := apiutil.ReadStringQuery(r, publisherKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
protocol, err := apiutil.ReadStringQuery(r, protocolKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
name, err := apiutil.ReadStringQuery(r, nameKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
v, err := apiutil.ReadFloatQuery(r, valueKey, 0)
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2019-03-15 18:38:07 +01:00
|
|
|
}
|
2021-01-26 12:23:15 +01:00
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
comparator, err := apiutil.ReadStringQuery(r, comparatorKey, "")
|
2021-02-09 22:44:04 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
vs, err := apiutil.ReadStringQuery(r, stringValueKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
vd, err := apiutil.ReadStringQuery(r, dataValueKey, "")
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
from, err := apiutil.ReadFloatQuery(r, fromKey, 0)
|
2021-01-26 12:23:15 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
to, err := apiutil.ReadFloatQuery(r, toKey, 0)
|
2022-02-18 14:56:01 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2018-08-06 17:06:55 +02:00
|
|
|
req := listMessagesReq{
|
2022-02-09 21:25:34 +01:00
|
|
|
chanID: bone.GetValue(r, "chanID"),
|
2022-03-06 01:49:34 +01:00
|
|
|
token: apiutil.ExtractBearerToken(r),
|
|
|
|
key: apiutil.ExtractThingKey(r),
|
2021-01-26 12:23:15 +01:00
|
|
|
pageMeta: readers.PageMetadata{
|
|
|
|
Offset: offset,
|
|
|
|
Limit: limit,
|
|
|
|
Format: format,
|
|
|
|
Subtopic: subtopic,
|
|
|
|
Publisher: publisher,
|
|
|
|
Protocol: protocol,
|
|
|
|
Name: name,
|
|
|
|
Value: v,
|
2021-02-09 22:44:04 +01:00
|
|
|
Comparator: comparator,
|
2021-01-26 12:23:15 +01:00
|
|
|
StringValue: vs,
|
|
|
|
DataValue: vd,
|
|
|
|
From: from,
|
|
|
|
To: to,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
2022-03-03 17:13:46 +01:00
|
|
|
vb, err := apiutil.ReadBoolQuery(r, boolValueKey, false)
|
2021-03-23 11:48:05 +01:00
|
|
|
if err != nil && err != errors.ErrNotFoundParam {
|
2021-01-26 12:23:15 +01:00
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
if err == nil {
|
|
|
|
req.pageMeta.BoolValue = vb
|
2018-08-06 17:06:55 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return req, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func encodeResponse(_ context.Context, w http.ResponseWriter, response interface{}) error {
|
|
|
|
w.Header().Set("Content-Type", contentType)
|
|
|
|
|
|
|
|
if ar, ok := response.(mainflux.Response); ok {
|
|
|
|
for k, v := range ar.Headers() {
|
|
|
|
w.Header().Set(k, v)
|
|
|
|
}
|
|
|
|
|
|
|
|
w.WriteHeader(ar.Code())
|
|
|
|
|
|
|
|
if ar.Empty() {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return json.NewEncoder(w).Encode(response)
|
|
|
|
}
|
|
|
|
|
|
|
|
func encodeError(_ context.Context, err error, w http.ResponseWriter) {
|
2020-04-13 12:57:53 +02:00
|
|
|
switch {
|
|
|
|
case errors.Contains(err, nil):
|
2022-02-09 21:25:34 +01:00
|
|
|
case errors.Contains(err, errors.ErrInvalidQueryParams),
|
2022-03-03 17:13:46 +01:00
|
|
|
errors.Contains(err, errors.ErrMalformedEntity),
|
|
|
|
err == apiutil.ErrMissingID,
|
|
|
|
err == apiutil.ErrLimitSize,
|
|
|
|
err == apiutil.ErrOffsetSize,
|
|
|
|
err == apiutil.ErrInvalidComparator:
|
2018-08-06 17:06:55 +02:00
|
|
|
w.WriteHeader(http.StatusBadRequest)
|
2022-03-03 17:13:46 +01:00
|
|
|
case errors.Contains(err, errors.ErrAuthentication),
|
|
|
|
err == apiutil.ErrBearerToken:
|
2022-02-01 17:33:23 +01:00
|
|
|
w.WriteHeader(http.StatusUnauthorized)
|
2022-02-14 22:49:23 +01:00
|
|
|
case errors.Contains(err, readers.ErrReadMessages):
|
|
|
|
w.WriteHeader(http.StatusInternalServerError)
|
|
|
|
|
2018-08-06 17:06:55 +02:00
|
|
|
default:
|
|
|
|
w.WriteHeader(http.StatusInternalServerError)
|
|
|
|
}
|
2022-02-14 22:49:23 +01:00
|
|
|
|
|
|
|
if errorVal, ok := err.(errors.Error); ok {
|
2020-04-13 12:57:53 +02:00
|
|
|
w.Header().Set("Content-Type", contentType)
|
2022-03-03 17:13:46 +01:00
|
|
|
if err := json.NewEncoder(w).Encode(apiutil.ErrorRes{Err: errorVal.Msg()}); err != nil {
|
2020-04-13 12:57:53 +02:00
|
|
|
w.WriteHeader(http.StatusInternalServerError)
|
|
|
|
}
|
|
|
|
}
|
2018-08-06 17:06:55 +02:00
|
|
|
}
|
|
|
|
|
2023-06-14 12:40:37 +02:00
|
|
|
func authorize(ctx context.Context, req listMessagesReq, tc tpolicies.ThingsServiceClient, ac upolicies.AuthServiceClient) (err error) {
|
2022-02-09 21:25:34 +01:00
|
|
|
switch {
|
2022-03-06 01:49:34 +01:00
|
|
|
case req.token != "":
|
2023-06-14 12:40:37 +02:00
|
|
|
user, err := ac.Identify(ctx, &upolicies.Token{Value: req.token})
|
2022-02-09 21:25:34 +01:00
|
|
|
if err != nil {
|
|
|
|
e, ok := status.FromError(err)
|
|
|
|
if ok && e.Code() == codes.PermissionDenied {
|
|
|
|
return errors.Wrap(errUserAccess, err)
|
|
|
|
}
|
|
|
|
return err
|
|
|
|
}
|
2023-06-14 12:40:37 +02:00
|
|
|
if _, err = tc.Authorize(ctx, &tpolicies.AuthorizeReq{Sub: user.GetId(), Obj: req.chanID, Act: tpolicies.ReadAction, EntityType: tpolicies.GroupEntityType}); err != nil {
|
2022-02-09 21:25:34 +01:00
|
|
|
e, ok := status.FromError(err)
|
|
|
|
if ok && e.Code() == codes.PermissionDenied {
|
|
|
|
return errors.Wrap(errUserAccess, err)
|
|
|
|
}
|
|
|
|
return err
|
2018-08-06 17:06:55 +02:00
|
|
|
}
|
2022-02-09 21:25:34 +01:00
|
|
|
return nil
|
|
|
|
default:
|
2023-06-14 12:40:37 +02:00
|
|
|
if _, err := tc.Authorize(ctx, &tpolicies.AuthorizeReq{Sub: req.key, Obj: req.chanID, Act: tpolicies.ReadAction, EntityType: tpolicies.GroupEntityType}); err != nil {
|
2022-02-09 21:25:34 +01:00
|
|
|
return errors.Wrap(errThingAccess, err)
|
|
|
|
}
|
|
|
|
return nil
|
2018-08-06 17:06:55 +02:00
|
|
|
}
|
|
|
|
}
|