From c159f6bbb922d1d773c1344d0b7e6081abb00296 Mon Sep 17 00:00:00 2001 From: Carlos Mogas da Silva Date: Sun, 21 Oct 2018 22:58:24 +0100 Subject: [PATCH] Initial import --- .drone.yml | 8 +++ Dockerfile | 10 ++++ README.md | 26 +++++++++ share_v2.php | 155 +++++++++++++++++++++++++++++++++++++++++++++++++++ 4 files changed, 199 insertions(+) create mode 100644 .drone.yml create mode 100644 Dockerfile create mode 100644 README.md create mode 100644 share_v2.php diff --git a/.drone.yml b/.drone.yml new file mode 100644 index 0000000..0cb2aea --- /dev/null +++ b/.drone.yml @@ -0,0 +1,8 @@ +pipeline: + publish: + image: plugins/docker + repo: r3pek/prosody-http-upload-external + secrets: [ docker_username, docker_password ] + when: + branch: master + event: push diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..8b26269 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,10 @@ +FROM richarvey/nginx-php-fpm + +ENV WEBROOT="/webroot" +ENV SECRET_KEY + +RUN mkdir ${WEBROOT} && mkdir /storage + +VOLUME ["/storage"] + +COPY share_v2.php ${WEBROOT} diff --git a/README.md b/README.md new file mode 100644 index 0000000..0700b48 --- /dev/null +++ b/README.md @@ -0,0 +1,26 @@ +# Prosody HTTP external upload + +![ ](https://drone.r3pek.org/api/badges/r3pek/docker-prosody-http-upload-external/status.svg "Build Status") ![ ](https://img.shields.io/docker/pulls/r3pek/prosody-http-upload-external.svg "Docker Pulls") ![ ](https://img.shields.io/docker/stars/r3pek/prosody-http-upload-external.svg "Docker Stars") + +This image is derived from the [Ric Harvey's nginx Image](https://hub.docker.com/r/richarvey/nginx-php-fpm/) + + +It just serves a simple file named share_v2.php taken from [Prosody's source](https://hub.docker.com/r/richarvey/nginx-php-fpm/). +This server is ment to be using in conjuntion with Prosody XMPP server and *mod\_http\_upload\_external* ([docs](https://modules.prosody.im/mod_http_upload_external.html)) + +## Variables +* SECRET\_KEY: Stores the secret key shared with the prosody server (http\_upload\_external\_secret option) + +## Volumes +* /storage: Used to store and serve the uploaded files + +# Quick Reference +* Where to file issues / suggestions +https://code.r3pek.org/r3pek/docker-prosody-http-upload-external/issues + +* Maintained by +[r3pek](https://code.r3pek.org/r3pek/) + +* Source repository +https://code.r3pek.org/r3pek/docker-prosody-http-upload-external/ + diff --git a/share_v2.php b/share_v2.php new file mode 100644 index 0000000..2b22056 --- /dev/null +++ b/share_v2.php @@ -0,0 +1,155 @@ + + + Permission is hereby granted, free of charge, to any person obtaining a copy of this software + and associated documentation files (the "Software"), to deal in the Software without restriction, + including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, + and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, + subject to the following conditions: + + The above copyright notice and this permission notice shall be included in all copies or substantial + portions of the Software. + + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND + NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, + DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +*/ + +/*\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\*/ +/* CONFIGURATION OPTIONS */ +/*\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\*/ + +/* Change this to a directory that is writable by your web server, but is outside your web root */ +$CONFIG_STORE_DIR = '/tmp'; + +/* This must be the same as 'http_upload_external_secret' that you set in Prosody's config file */ +$CONFIG_SECRET = 'this is your secret string'; + +/* For people who need options to tweak that they don't understand... here you are */ +$CONFIG_CHUNK_SIZE = 4096; + +/*\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\*/ +/* END OF CONFIGURATION */ +/*\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\*/ + +/* Do not edit below this line unless you know what you are doing (spoiler: nobody does) */ + +$upload_file_name = substr($_SERVER['PHP_SELF'], strlen($_SERVER['SCRIPT_NAME'])+1); +$store_file_name = $CONFIG_STORE_DIR . '/store-' . hash('sha256', $upload_file_name); + +$request_method = $_SERVER['REQUEST_METHOD']; + +/* Set CORS headers */ +header('Access-Control-Allow-Methods: GET, PUT, OPTIONS'); +header('Access-Control-Allow-Headers: Content-Type'); +header('Access-Control-Max-Age: 7200'); +header('Access-Control-Allow-Origin: *'); + +if(array_key_exists('v2', $_GET) === TRUE && $request_method === 'PUT') { +// error_log(var_export($_SERVER, TRUE)); + $upload_file_size = $_SERVER['CONTENT_LENGTH']; + $upload_token = $_GET['v2']; + + if(array_key_exists('CONTENT_TYPE', $_SERVER) === TRUE) { + $upload_file_type = $_SERVER['CONTENT_TYPE']; + } else { + $upload_file_type = 'application/octet-stream'; + } + + // Imagine being able to store the file data in the content-type! + if(strlen($upload_file_type) > 255) { + header('HTTP/1.0 400 Bad Request'); + exit; + } + + $calculated_token = hash_hmac('sha256', "$upload_file_name\0$upload_file_size\0$upload_file_type", $CONFIG_SECRET); + if(function_exists('hash_equals')) { + if(hash_equals($calculated_token, $upload_token) !== TRUE) { + error_log("Token mismatch: calculated $calculated_token got $upload_token"); + header('HTTP/1.0 403 Forbidden'); + exit; + } + } + else { + if($upload_token !== $calculated_token) { + error_log("Token mismatch: calculated $calculated_token got $upload_token"); + header('HTTP/1.0 403 Forbidden'); + exit; + } + } + /* Open a file for writing */ + $store_file = fopen($store_file_name, 'x'); + + if($store_file === FALSE) { + header('HTTP/1.0 409 Conflict'); + exit; + } + + /* PUT data comes in on the stdin stream */ + $incoming_data = fopen('php://input', 'r'); + + /* Read the data a chunk at a time and write to the file */ + while ($data = fread($incoming_data, $CONFIG_CHUNK_SIZE)) { + fwrite($store_file, $data); + } + + /* Close the streams */ + fclose($incoming_data); + fclose($store_file); + file_put_contents($store_file_name.'-type', $upload_file_type); +} else if($request_method === 'GET' || $request_method === 'HEAD') { + // Send file (using X-Sendfile would be nice here...) + if(file_exists($store_file_name)) { + $mime_type = file_get_contents($store_file_name.'-type'); + if($mime_type === FALSE) { + $mime_type = 'application/octet-stream'; + header('Content-Disposition: attachment'); + } + header('Content-Type: '.$mime_type); + header('Content-Length: '.filesize($store_file_name)); + header("Content-Security-Policy: \"default-src 'none'\""); + header("X-Content-Security-Policy: \"default-src 'none'\""); + header("X-WebKit-CSP: \"default-src 'none'\""); + if($request_method !== 'HEAD') { + readfile($store_file_name); + } + } else { + header('HTTP/1.0 404 Not Found'); + } +} else if($request_method === 'OPTIONS') { +} else { + header('HTTP/1.0 400 Bad Request'); +} + +exit;