2023-04-21 12:10:13 +12:00
|
|
|
// Package server is the HTTP daemon
|
2022-07-29 23:23:08 +12:00
|
|
|
package server
|
|
|
|
|
|
|
|
import (
|
2023-07-30 17:35:17 +12:00
|
|
|
"bytes"
|
2022-07-29 23:23:08 +12:00
|
|
|
"compress/gzip"
|
|
|
|
"embed"
|
2023-07-30 17:35:17 +12:00
|
|
|
"fmt"
|
2023-01-30 10:56:58 +02:00
|
|
|
"io"
|
|
|
|
"io/fs"
|
|
|
|
"net/http"
|
|
|
|
"os"
|
|
|
|
"strings"
|
|
|
|
"sync/atomic"
|
2023-09-14 22:30:20 +12:00
|
|
|
"text/template"
|
2023-03-12 11:31:15 +13:00
|
|
|
|
|
|
|
"github.com/axllent/mailpit/config"
|
2023-09-29 16:40:23 +13:00
|
|
|
"github.com/axllent/mailpit/internal/auth"
|
2023-09-25 18:08:04 +13:00
|
|
|
"github.com/axllent/mailpit/internal/logger"
|
2023-09-25 19:25:45 +13:00
|
|
|
"github.com/axllent/mailpit/internal/storage"
|
2023-03-12 11:31:15 +13:00
|
|
|
"github.com/axllent/mailpit/server/apiv1"
|
|
|
|
"github.com/axllent/mailpit/server/handlers"
|
|
|
|
"github.com/axllent/mailpit/server/websockets"
|
|
|
|
"github.com/gorilla/mux"
|
2022-07-29 23:23:08 +12:00
|
|
|
)
|
|
|
|
|
|
|
|
//go:embed ui
|
|
|
|
var embeddedFS embed.FS
|
|
|
|
|
2023-04-21 12:49:49 +12:00
|
|
|
// AccessControlAllowOrigin CORS policy
|
|
|
|
var AccessControlAllowOrigin string
|
|
|
|
|
2022-07-29 23:23:08 +12:00
|
|
|
// Listen will start the httpd
|
|
|
|
func Listen() {
|
2023-01-30 10:56:58 +02:00
|
|
|
isReady := &atomic.Value{}
|
|
|
|
isReady.Store(false)
|
|
|
|
|
2022-07-29 23:23:08 +12:00
|
|
|
serverRoot, err := fs.Sub(embeddedFS, "ui")
|
|
|
|
if err != nil {
|
2024-01-01 15:25:38 +13:00
|
|
|
logger.Log().Errorf("[http] %s", err.Error())
|
2022-07-29 23:23:08 +12:00
|
|
|
os.Exit(1)
|
|
|
|
}
|
|
|
|
|
|
|
|
websockets.MessageHub = websockets.NewHub()
|
|
|
|
|
|
|
|
go websockets.MessageHub.Run()
|
|
|
|
|
2023-09-14 22:30:20 +12:00
|
|
|
r := apiRoutes()
|
2022-10-07 19:46:39 +13:00
|
|
|
|
2023-01-30 10:56:58 +02:00
|
|
|
// kubernetes probes
|
2023-09-06 16:14:35 +12:00
|
|
|
r.HandleFunc(config.Webroot+"livez", handlers.HealthzHandler)
|
|
|
|
r.HandleFunc(config.Webroot+"readyz", handlers.ReadyzHandler(isReady))
|
|
|
|
|
|
|
|
// proxy handler for screenshots
|
|
|
|
r.HandleFunc(config.Webroot+"proxy", middleWareFunc(handlers.ProxyHandler)).Methods("GET")
|
2023-01-30 10:56:58 +02:00
|
|
|
|
2023-09-14 22:30:20 +12:00
|
|
|
// virtual filesystem for /dist/ & some individual files
|
|
|
|
r.PathPrefix(config.Webroot + "dist/").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
|
|
|
r.PathPrefix(config.Webroot + "api/").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
|
|
|
r.Path(config.Webroot + "favicon.ico").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
|
|
|
r.Path(config.Webroot + "favicon.svg").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
|
|
|
r.Path(config.Webroot + "mailpit.svg").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
|
|
|
r.Path(config.Webroot + "notification.png").Handler(middlewareHandler(http.StripPrefix(config.Webroot, http.FileServer(http.FS(serverRoot)))))
|
2022-10-31 22:13:41 +13:00
|
|
|
|
|
|
|
// redirect to webroot if no trailing slash
|
|
|
|
if config.Webroot != "/" {
|
2023-09-14 22:30:20 +12:00
|
|
|
redirect := strings.TrimRight(config.Webroot, "/")
|
|
|
|
r.HandleFunc(redirect, middleWareFunc(addSlashToWebroot)).Methods("GET")
|
2022-10-31 22:13:41 +13:00
|
|
|
}
|
|
|
|
|
2023-11-02 16:15:45 +13:00
|
|
|
// UI shortcut
|
|
|
|
r.HandleFunc(config.Webroot+"view/latest", handlers.RedirectToLatestMessage).Methods("GET")
|
|
|
|
|
2023-09-27 17:29:03 +13:00
|
|
|
// frontend testing
|
|
|
|
r.HandleFunc(config.Webroot+"view/{id}.html", handlers.GetMessageHTML).Methods("GET")
|
|
|
|
r.HandleFunc(config.Webroot+"view/{id}.txt", handlers.GetMessageText).Methods("GET")
|
|
|
|
|
|
|
|
// web UI via virtual index.html
|
|
|
|
r.PathPrefix(config.Webroot + "view/").Handler(middleWareFunc(index)).Methods("GET")
|
|
|
|
r.Path(config.Webroot + "search").Handler(middleWareFunc(index)).Methods("GET")
|
|
|
|
r.Path(config.Webroot).Handler(middleWareFunc(index)).Methods("GET")
|
2023-09-14 22:30:20 +12:00
|
|
|
|
|
|
|
// put it all together
|
2022-07-29 23:23:08 +12:00
|
|
|
http.Handle("/", r)
|
|
|
|
|
2023-09-29 16:40:23 +13:00
|
|
|
if auth.UICredentials != nil {
|
|
|
|
logger.Log().Info("[http] enabling basic authentication")
|
2022-08-06 20:00:05 +12:00
|
|
|
}
|
|
|
|
|
2023-01-30 10:56:58 +02:00
|
|
|
// Mark the application here as ready
|
|
|
|
isReady.Store(true)
|
|
|
|
|
2023-12-01 15:03:01 +13:00
|
|
|
logger.Log().Infof("[http] starting on %s", config.HTTPListen)
|
|
|
|
|
2023-03-12 11:31:15 +13:00
|
|
|
if config.UITLSCert != "" && config.UITLSKey != "" {
|
2023-12-01 15:03:01 +13:00
|
|
|
logger.Log().Infof("[http] accessible via https://%s%s", logger.CleanHTTPIP(config.HTTPListen), config.Webroot)
|
2023-03-12 11:31:15 +13:00
|
|
|
logger.Log().Fatal(http.ListenAndServeTLS(config.HTTPListen, config.UITLSCert, config.UITLSKey, nil))
|
2022-07-29 23:23:08 +12:00
|
|
|
} else {
|
2023-12-01 15:03:01 +13:00
|
|
|
logger.Log().Infof("[http] accessible via http://%s%s", logger.CleanHTTPIP(config.HTTPListen), config.Webroot)
|
2022-10-13 02:53:53 +13:00
|
|
|
logger.Log().Fatal(http.ListenAndServe(config.HTTPListen, nil))
|
2022-07-29 23:23:08 +12:00
|
|
|
}
|
2022-08-04 17:18:07 +12:00
|
|
|
}
|
2022-07-29 23:23:08 +12:00
|
|
|
|
2023-09-14 22:30:20 +12:00
|
|
|
func apiRoutes() *mux.Router {
|
2022-10-07 19:46:39 +13:00
|
|
|
r := mux.NewRouter()
|
|
|
|
|
|
|
|
// API V1
|
2022-10-31 22:13:41 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/messages", middleWareFunc(apiv1.GetMessages)).Methods("GET")
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/messages", middleWareFunc(apiv1.SetReadStatus)).Methods("PUT")
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/messages", middleWareFunc(apiv1.DeleteMessages)).Methods("DELETE")
|
2023-09-22 06:55:20 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/tags", middleWareFunc(apiv1.GetTags)).Methods("GET")
|
2022-11-13 16:45:54 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/tags", middleWareFunc(apiv1.SetTags)).Methods("PUT")
|
2022-10-31 22:13:41 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/search", middleWareFunc(apiv1.Search)).Methods("GET")
|
2023-09-22 07:00:02 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/search", middleWareFunc(apiv1.DeleteSearch)).Methods("DELETE")
|
2022-10-31 22:13:41 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/part/{partID}", middleWareFunc(apiv1.DownloadAttachment)).Methods("GET")
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/part/{partID}/thumb", middleWareFunc(apiv1.Thumbnail)).Methods("GET")
|
2023-03-31 17:29:04 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/headers", middleWareFunc(apiv1.GetHeaders)).Methods("GET")
|
2023-04-21 17:50:34 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/raw", middleWareFunc(apiv1.DownloadRaw)).Methods("GET")
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/release", middleWareFunc(apiv1.ReleaseMessage)).Methods("POST")
|
2023-07-30 17:04:06 +12:00
|
|
|
if !config.DisableHTMLCheck {
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/html-check", middleWareFunc(apiv1.HTMLCheck)).Methods("GET")
|
|
|
|
}
|
2023-08-16 16:59:31 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}/link-check", middleWareFunc(apiv1.LinkCheck)).Methods("GET")
|
2022-10-31 22:13:41 +13:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/message/{id}", middleWareFunc(apiv1.GetMessage)).Methods("GET")
|
|
|
|
r.HandleFunc(config.Webroot+"api/v1/info", middleWareFunc(apiv1.AppInfo)).Methods("GET")
|
2023-04-21 12:17:14 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/webui", middleWareFunc(apiv1.WebUIConfig)).Methods("GET")
|
2023-07-30 17:35:17 +12:00
|
|
|
r.HandleFunc(config.Webroot+"api/v1/swagger.json", middleWareFunc(swaggerBasePath)).Methods("GET")
|
2022-10-07 19:46:39 +13:00
|
|
|
|
2023-09-14 22:30:20 +12:00
|
|
|
// web UI websocket
|
|
|
|
r.HandleFunc(config.Webroot+"api/events", apiWebsocket).Methods("GET")
|
|
|
|
|
2023-05-09 17:11:57 +12:00
|
|
|
// return blank 200 response for OPTIONS requests for CORS
|
|
|
|
r.PathPrefix(config.Webroot + "api/v1/").Handler(middleWareFunc(apiv1.GetOptions)).Methods("OPTIONS")
|
|
|
|
|
2022-10-07 19:46:39 +13:00
|
|
|
return r
|
|
|
|
}
|
|
|
|
|
2022-08-04 17:18:07 +12:00
|
|
|
// BasicAuthResponse returns an basic auth response to the browser
|
|
|
|
func basicAuthResponse(w http.ResponseWriter) {
|
|
|
|
w.Header().Set("WWW-Authenticate", `Basic realm="Login"`)
|
|
|
|
w.WriteHeader(http.StatusUnauthorized)
|
2022-08-07 00:09:32 +12:00
|
|
|
_, _ = w.Write([]byte("Unauthorised.\n"))
|
2022-07-29 23:23:08 +12:00
|
|
|
}
|
|
|
|
|
|
|
|
type gzipResponseWriter struct {
|
|
|
|
io.Writer
|
|
|
|
http.ResponseWriter
|
|
|
|
}
|
|
|
|
|
|
|
|
func (w gzipResponseWriter) Write(b []byte) (int, error) {
|
|
|
|
return w.Writer.Write(b)
|
|
|
|
}
|
|
|
|
|
2022-08-04 17:18:07 +12:00
|
|
|
// MiddleWareFunc http middleware adds optional basic authentication
|
|
|
|
// and gzip compression.
|
|
|
|
func middleWareFunc(fn http.HandlerFunc) http.HandlerFunc {
|
2022-07-29 23:23:08 +12:00
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
2022-09-15 21:23:27 +12:00
|
|
|
w.Header().Set("Referrer-Policy", "no-referrer")
|
2022-10-07 19:46:39 +13:00
|
|
|
w.Header().Set("Content-Security-Policy", config.ContentSecurityPolicy)
|
2022-09-15 21:23:27 +12:00
|
|
|
|
2023-04-21 12:49:49 +12:00
|
|
|
if AccessControlAllowOrigin != "" && strings.HasPrefix(r.RequestURI, config.Webroot+"api/") {
|
|
|
|
w.Header().Set("Access-Control-Allow-Origin", AccessControlAllowOrigin)
|
2023-05-09 17:11:57 +12:00
|
|
|
w.Header().Set("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
|
2023-05-04 22:23:07 +12:00
|
|
|
w.Header().Set("Access-Control-Allow-Headers", "*")
|
2023-04-21 12:49:49 +12:00
|
|
|
}
|
|
|
|
|
2023-09-29 16:40:23 +13:00
|
|
|
if auth.UICredentials != nil {
|
2022-08-04 17:18:07 +12:00
|
|
|
user, pass, ok := r.BasicAuth()
|
|
|
|
|
|
|
|
if !ok {
|
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-09-29 16:40:23 +13:00
|
|
|
if !auth.UICredentials.Match(user, pass) {
|
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if auth.UICredentials != nil {
|
|
|
|
user, pass, ok := r.BasicAuth()
|
|
|
|
|
|
|
|
if !ok {
|
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if !auth.UICredentials.Match(user, pass) {
|
2022-08-04 17:18:07 +12:00
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-07-29 23:23:08 +12:00
|
|
|
if !strings.Contains(r.Header.Get("Accept-Encoding"), "gzip") {
|
|
|
|
fn(w, r)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
w.Header().Set("Content-Encoding", "gzip")
|
|
|
|
gz := gzip.NewWriter(w)
|
|
|
|
defer gz.Close()
|
|
|
|
gzr := gzipResponseWriter{Writer: gz, ResponseWriter: w}
|
|
|
|
fn(gzr, r)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-04 17:18:07 +12:00
|
|
|
// MiddlewareHandler http middleware adds optional basic authentication
|
|
|
|
// and gzip compression
|
|
|
|
func middlewareHandler(h http.Handler) http.Handler {
|
2022-07-29 23:23:08 +12:00
|
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
2022-09-15 21:23:27 +12:00
|
|
|
w.Header().Set("Referrer-Policy", "no-referrer")
|
2022-10-07 19:46:39 +13:00
|
|
|
w.Header().Set("Content-Security-Policy", config.ContentSecurityPolicy)
|
2022-08-04 17:18:07 +12:00
|
|
|
|
2023-04-21 12:49:49 +12:00
|
|
|
if AccessControlAllowOrigin != "" && strings.HasPrefix(r.RequestURI, config.Webroot+"api/") {
|
|
|
|
w.Header().Set("Access-Control-Allow-Origin", AccessControlAllowOrigin)
|
2023-05-09 17:11:57 +12:00
|
|
|
w.Header().Set("Access-Control-Allow-Methods", "GET, POST, DELETE, PUT, OPTIONS")
|
2023-05-04 22:23:07 +12:00
|
|
|
w.Header().Set("Access-Control-Allow-Headers", "*")
|
2023-04-21 12:49:49 +12:00
|
|
|
}
|
|
|
|
|
2023-09-29 16:40:23 +13:00
|
|
|
if auth.UICredentials != nil {
|
2022-08-04 17:18:07 +12:00
|
|
|
user, pass, ok := r.BasicAuth()
|
|
|
|
|
|
|
|
if !ok {
|
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-09-29 16:40:23 +13:00
|
|
|
if !auth.UICredentials.Match(user, pass) {
|
2022-08-04 17:18:07 +12:00
|
|
|
basicAuthResponse(w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-07-29 23:23:08 +12:00
|
|
|
if !strings.Contains(r.Header.Get("Accept-Encoding"), "gzip") {
|
|
|
|
h.ServeHTTP(w, r)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
w.Header().Set("Content-Encoding", "gzip")
|
|
|
|
gz := gzip.NewWriter(w)
|
|
|
|
defer gz.Close()
|
|
|
|
h.ServeHTTP(gzipResponseWriter{Writer: gz, ResponseWriter: w}, r)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2022-10-31 22:13:41 +13:00
|
|
|
// Redirect to webroot
|
|
|
|
func addSlashToWebroot(w http.ResponseWriter, r *http.Request) {
|
|
|
|
http.Redirect(w, r, config.Webroot, http.StatusFound)
|
|
|
|
}
|
|
|
|
|
2022-10-07 19:46:39 +13:00
|
|
|
// Websocket to broadcast changes
|
|
|
|
func apiWebsocket(w http.ResponseWriter, r *http.Request) {
|
|
|
|
websockets.ServeWs(websockets.MessageHub, w, r)
|
2023-09-22 15:06:03 +12:00
|
|
|
storage.BroadcastMailboxStats()
|
2022-07-29 23:23:08 +12:00
|
|
|
}
|
2023-07-30 17:35:17 +12:00
|
|
|
|
|
|
|
// Wrapper to artificially inject a basePath to the swagger.json if a webroot has been specified
|
|
|
|
func swaggerBasePath(w http.ResponseWriter, _ *http.Request) {
|
|
|
|
f, err := embeddedFS.ReadFile("ui/api/v1/swagger.json")
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if config.Webroot != "/" {
|
|
|
|
// artificially inject a path at the start
|
|
|
|
replacement := fmt.Sprintf("{\n \"basePath\": \"%s\",", strings.TrimRight(config.Webroot, "/"))
|
|
|
|
|
|
|
|
f = bytes.Replace(f, []byte("{"), []byte(replacement), 1)
|
|
|
|
}
|
|
|
|
|
|
|
|
w.Header().Add("Content-Type", "application/json")
|
|
|
|
_, _ = w.Write(f)
|
|
|
|
}
|
2023-09-14 22:30:20 +12:00
|
|
|
|
|
|
|
// Just returns the default HTML template
|
|
|
|
func index(w http.ResponseWriter, _ *http.Request) {
|
|
|
|
|
|
|
|
var h = `<!DOCTYPE html>
|
|
|
|
<html lang="en" class="h-100">
|
|
|
|
|
|
|
|
<head>
|
|
|
|
<meta charset="utf-8">
|
|
|
|
<meta name="viewport" content="width=device-width,initial-scale=1.0">
|
|
|
|
<meta name="referrer" content="no-referrer">
|
|
|
|
<meta name="robots" content="noindex, nofollow, noarchive">
|
|
|
|
<link rel="icon" href="{{ .Webroot }}favicon.svg">
|
|
|
|
<title>Mailpit</title>
|
|
|
|
<link rel=stylesheet href="{{ .Webroot }}dist/app.css?{{ .Version }}">
|
|
|
|
</head>
|
|
|
|
|
|
|
|
<body class="h-100">
|
|
|
|
<div class="container-fluid h-100 d-flex flex-column" id="app" data-webroot="{{ .Webroot }}">
|
|
|
|
<noscript>You require JavaScript to use this app.</noscript>
|
|
|
|
</div>
|
|
|
|
|
|
|
|
<script src="{{ .Webroot }}dist/app.js?{{ .Version }}"></script>
|
|
|
|
</body>
|
|
|
|
|
|
|
|
</html>`
|
|
|
|
|
|
|
|
t, err := template.New("index").Parse(h)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
data := struct {
|
|
|
|
Webroot string
|
|
|
|
Version string
|
|
|
|
}{
|
|
|
|
Webroot: config.Webroot,
|
|
|
|
Version: config.Version,
|
|
|
|
}
|
|
|
|
|
|
|
|
buff := new(bytes.Buffer)
|
|
|
|
|
|
|
|
err = t.Execute(buff, data)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
buff.Bytes()
|
|
|
|
|
|
|
|
w.Header().Add("Content-Type", "text/html")
|
|
|
|
_, _ = w.Write(buff.Bytes())
|
|
|
|
}
|