Add --port

This commit is contained in:
2026-09-12 23:48:03 +02:00
parent a180fe4b52
commit da36645aaf
14 changed files with 677 additions and 40 deletions
+42 -14
View File
@@ -26,24 +26,16 @@ func (s *Server) handleDelete(w http.ResponseWriter, r *http.Request) {
return
}
secret := bearer(r)
if secret == "" {
// A small form post; the 4 KiB cap keeps this from being a way to
// stream a body into memory.
r.Body = http.MaxBytesReader(w, r.Body, maxFieldBytes)
if err := r.ParseForm(); err == nil {
secret = strings.TrimSpace(r.PostFormValue("token"))
}
}
if secret == "" {
presented := s.deleteCredentials(w, r)
if len(presented) == 0 {
s.fail(w, r, http.StatusUnauthorized, "A delete token or an owning token is required.")
return
}
if !s.mayDelete(m, secret) {
if !s.authorised(m, presented) {
s.fail(w, r, http.StatusForbidden, "That token cannot delete this file.")
return
}
if err := s.store.Delete(id); err != nil {
s.log.Error("deleting object", "id", id, "err", err)
s.fail(w, r, http.StatusInternalServerError, "Could not delete the file.")
@@ -62,8 +54,44 @@ func (s *Server) handleDelete(w http.ResponseWriter, r *http.Request) {
})
}
// mayDelete checks the presented secret against the object's delete token
// first, then against the token file.
// deleteCredentials collects every secret the request carries.
//
// Three can legitimately arrive at once — the object's delete token in the
// form, a token in the header, and a remembered token in the cookie — and any
// one of them may be the sufficient one. They are all collected so that the
// first one present cannot shadow the others.
func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string {
var out []string
add := func(secret string) {
if secret = strings.TrimSpace(secret); secret != "" {
out = append(out, secret)
}
}
add(bearer(r))
add(cookieCredential(r))
// A small form post; the cap keeps this from being a way to stream a body
// into memory. A non-form body simply fails to parse and is ignored.
r.Body = http.MaxBytesReader(w, r.Body, maxFieldBytes)
if err := r.ParseForm(); err == nil {
add(r.PostFormValue("token"))
}
return out
}
// authorised reports whether any of the presented secrets may delete m.
func (s *Server) authorised(m *store.Meta, presented []string) bool {
for _, secret := range presented {
if s.mayDelete(m, secret) {
return true
}
}
return false
}
// mayDelete checks one secret against the object's delete token first, then
// against the token file.
func (s *Server) mayDelete(m *store.Meta, secret string) bool {
if auth.EqualHash(m.DeleteHash, auth.HashSecret(secret)) {
return true