Add --port
This commit is contained in:
+42
-14
@@ -26,24 +26,16 @@ func (s *Server) handleDelete(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
secret := bearer(r)
|
||||
if secret == "" {
|
||||
// A small form post; the 4 KiB cap keeps this from being a way to
|
||||
// stream a body into memory.
|
||||
r.Body = http.MaxBytesReader(w, r.Body, maxFieldBytes)
|
||||
if err := r.ParseForm(); err == nil {
|
||||
secret = strings.TrimSpace(r.PostFormValue("token"))
|
||||
}
|
||||
}
|
||||
if secret == "" {
|
||||
presented := s.deleteCredentials(w, r)
|
||||
if len(presented) == 0 {
|
||||
s.fail(w, r, http.StatusUnauthorized, "A delete token or an owning token is required.")
|
||||
return
|
||||
}
|
||||
|
||||
if !s.mayDelete(m, secret) {
|
||||
if !s.authorised(m, presented) {
|
||||
s.fail(w, r, http.StatusForbidden, "That token cannot delete this file.")
|
||||
return
|
||||
}
|
||||
|
||||
if err := s.store.Delete(id); err != nil {
|
||||
s.log.Error("deleting object", "id", id, "err", err)
|
||||
s.fail(w, r, http.StatusInternalServerError, "Could not delete the file.")
|
||||
@@ -62,8 +54,44 @@ func (s *Server) handleDelete(w http.ResponseWriter, r *http.Request) {
|
||||
})
|
||||
}
|
||||
|
||||
// mayDelete checks the presented secret against the object's delete token
|
||||
// first, then against the token file.
|
||||
// deleteCredentials collects every secret the request carries.
|
||||
//
|
||||
// Three can legitimately arrive at once — the object's delete token in the
|
||||
// form, a token in the header, and a remembered token in the cookie — and any
|
||||
// one of them may be the sufficient one. They are all collected so that the
|
||||
// first one present cannot shadow the others.
|
||||
func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string {
|
||||
var out []string
|
||||
add := func(secret string) {
|
||||
if secret = strings.TrimSpace(secret); secret != "" {
|
||||
out = append(out, secret)
|
||||
}
|
||||
}
|
||||
|
||||
add(bearer(r))
|
||||
add(cookieCredential(r))
|
||||
|
||||
// A small form post; the cap keeps this from being a way to stream a body
|
||||
// into memory. A non-form body simply fails to parse and is ignored.
|
||||
r.Body = http.MaxBytesReader(w, r.Body, maxFieldBytes)
|
||||
if err := r.ParseForm(); err == nil {
|
||||
add(r.PostFormValue("token"))
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// authorised reports whether any of the presented secrets may delete m.
|
||||
func (s *Server) authorised(m *store.Meta, presented []string) bool {
|
||||
for _, secret := range presented {
|
||||
if s.mayDelete(m, secret) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// mayDelete checks one secret against the object's delete token first, then
|
||||
// against the token file.
|
||||
func (s *Server) mayDelete(m *store.Meta, secret string) bool {
|
||||
if auth.EqualHash(m.DeleteHash, auth.HashSecret(secret)) {
|
||||
return true
|
||||
|
||||
Reference in New Issue
Block a user