upgrade-handler.ts 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131
  1. import type { IPage, IUserHasId } from '@growi/core';
  2. import { YJS_WEBSOCKET_BASE_PATH } from '@growi/core/dist/consts';
  3. import expressSession from 'express-session';
  4. import type { IncomingMessage, ServerResponse } from 'http';
  5. import mongoose from 'mongoose';
  6. import passport from 'passport';
  7. import type { Duplex } from 'stream';
  8. import type { SessionConfig } from '~/interfaces/session-config';
  9. import loggerFactory from '~/utils/logger';
  10. import type { PageModel } from '../../models/page';
  11. const logger = loggerFactory('growi:service:yjs:upgrade-handler');
  12. type AuthenticatedRequest = IncomingMessage & {
  13. user?: IUserHasId;
  14. };
  15. /**
  16. * Connect-style middleware that operates on raw Node.js HTTP types.
  17. * Express middleware (express-session, passport) is compatible because
  18. * express.Request extends IncomingMessage and express.Response extends ServerResponse.
  19. */
  20. type ConnectMiddleware = (
  21. req: IncomingMessage,
  22. res: ServerResponse,
  23. next: (err?: unknown) => void,
  24. ) => void;
  25. /**
  26. * Run a Connect-style middleware against a raw IncomingMessage.
  27. * Safe for express-session, passport.initialize(), and passport.session() which
  28. * only read/write `req` properties and call `next()` — they never write to `res`.
  29. */
  30. const runMiddleware = (
  31. middleware: ConnectMiddleware,
  32. req: IncomingMessage,
  33. ): Promise<void> =>
  34. new Promise((resolve, reject) => {
  35. const stubRes = {} as ServerResponse;
  36. middleware(req, stubRes, (err?: unknown) => {
  37. if (err) return reject(err);
  38. resolve();
  39. });
  40. });
  41. /**
  42. * Extracts pageId from upgrade request URL.
  43. * Expected format: /yjs/{pageId}
  44. */
  45. const pageIdPattern = new RegExp(`^${YJS_WEBSOCKET_BASE_PATH}/([a-f0-9]{24})`);
  46. const extractPageId = (url: string | undefined): string | null => {
  47. if (url == null) return null;
  48. const match = url.match(pageIdPattern);
  49. return match?.[1] ?? null;
  50. };
  51. /**
  52. * Writes an HTTP error response to the socket.
  53. * Does NOT close the socket — the caller (yjs.ts) manages socket lifecycle
  54. * so that guardSocket can safely intercept end/destroy during async auth.
  55. */
  56. const writeErrorResponse = (
  57. socket: Duplex,
  58. statusCode: number,
  59. message: string,
  60. ): void => {
  61. socket.write(`HTTP/1.1 ${statusCode} ${message}\r\n\r\n`);
  62. };
  63. export type UpgradeResult =
  64. | { authorized: true; request: AuthenticatedRequest; pageId: string }
  65. | { authorized: false; statusCode: number };
  66. /**
  67. * Creates an upgrade handler that authenticates WebSocket connections
  68. * using the existing express-session + passport mechanism.
  69. */
  70. export const createUpgradeHandler = (sessionConfig: SessionConfig) => {
  71. const sessionMiddleware = expressSession(sessionConfig as any);
  72. const passportInit = passport.initialize();
  73. const passportSession = passport.session();
  74. return async (
  75. request: IncomingMessage,
  76. socket: Duplex,
  77. _head: Buffer,
  78. ): Promise<UpgradeResult> => {
  79. const pageId = extractPageId(request.url);
  80. if (pageId == null) {
  81. logger.warn('Invalid URL path for Yjs upgrade', { url: request.url });
  82. writeErrorResponse(socket, 400, 'Bad Request');
  83. return { authorized: false, statusCode: 400 };
  84. }
  85. try {
  86. // Run session + passport middleware chain
  87. await runMiddleware(sessionMiddleware as ConnectMiddleware, request);
  88. await runMiddleware(passportInit as ConnectMiddleware, request);
  89. await runMiddleware(passportSession as ConnectMiddleware, request);
  90. } catch (err) {
  91. logger.warn('Session/passport middleware failed on upgrade', { err });
  92. writeErrorResponse(socket, 401, 'Unauthorized');
  93. return { authorized: false, statusCode: 401 };
  94. }
  95. const user = (request as AuthenticatedRequest).user ?? null;
  96. // Check page access
  97. const Page = mongoose.model<IPage, PageModel>('Page');
  98. const isAccessible = await Page.isAccessiblePageByViewer(pageId, user);
  99. if (!isAccessible) {
  100. const statusCode = user == null ? 401 : 403;
  101. const message = user == null ? 'Unauthorized' : 'Forbidden';
  102. logger.warn(`Yjs upgrade rejected: ${message}`, {
  103. pageId,
  104. userId: user?._id,
  105. });
  106. writeErrorResponse(socket, statusCode, message);
  107. return { authorized: false, statusCode };
  108. }
  109. return {
  110. authorized: true,
  111. request: request as AuthenticatedRequest,
  112. pageId,
  113. };
  114. };
  115. };