Add --port
This commit is contained in:
@@ -38,6 +38,12 @@ type uploadRequest struct {
|
||||
vanity string
|
||||
expiry string
|
||||
filename string
|
||||
|
||||
// remember is set by the form's checkbox. It decides whether a token used
|
||||
// here is stored in a cookie for next time, and unchecking it is how a
|
||||
// remembered token is cleared from the upload page itself.
|
||||
remember bool
|
||||
explicit bool // the token was typed or sent, not read back from the cookie
|
||||
}
|
||||
|
||||
func (s *Server) handleUpload(w http.ResponseWriter, r *http.Request) {
|
||||
@@ -75,6 +81,10 @@ func (s *Server) uploadRaw(w http.ResponseWriter, r *http.Request, ip string) {
|
||||
expiry: strings.TrimSpace(r.Header.Get("Expiry")),
|
||||
filename: filenameFromDisposition(r.Header.Get("Content-Disposition")),
|
||||
}
|
||||
req.explicit = req.token != ""
|
||||
if req.token == "" {
|
||||
req.token = cookieCredential(r)
|
||||
}
|
||||
s.storeUpload(w, r, req, r.Body, ip)
|
||||
}
|
||||
|
||||
@@ -92,6 +102,7 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar
|
||||
}
|
||||
mr := multipart.NewReader(r.Body, boundary)
|
||||
req := uploadRequest{token: bearer(r)}
|
||||
req.explicit = req.token != ""
|
||||
|
||||
for n := 0; ; n++ {
|
||||
if n > maxFieldCount {
|
||||
@@ -112,6 +123,12 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar
|
||||
if req.filename == "" {
|
||||
req.filename = part.FileName()
|
||||
}
|
||||
// Nothing explicit was supplied, so fall back to what the browser
|
||||
// remembered. This happens after the fields precisely so a typed
|
||||
// token still wins.
|
||||
if req.token == "" {
|
||||
req.token = cookieCredential(r)
|
||||
}
|
||||
s.storeUpload(w, r, req, part, ip)
|
||||
return
|
||||
}
|
||||
@@ -124,9 +141,11 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar
|
||||
}
|
||||
switch part.FormName() {
|
||||
case "token":
|
||||
if value != "" {
|
||||
req.token = value
|
||||
if v := strings.TrimSpace(value); v != "" {
|
||||
req.token, req.explicit = v, true
|
||||
}
|
||||
case "remember":
|
||||
req.remember = true
|
||||
case "vanity":
|
||||
req.vanity = strings.TrimSpace(value)
|
||||
case "expiry":
|
||||
@@ -250,11 +269,28 @@ func (s *Server) storeUpload(w http.ResponseWriter, r *http.Request, req uploadR
|
||||
}
|
||||
committed = true
|
||||
|
||||
s.updateRemembered(w, r, req, lim)
|
||||
|
||||
s.log.Info("stored", "id", m.ID, "bytes", m.Size, "owner", orAnonymous(lim.Name),
|
||||
"ip", ip, "expires", m.Expires)
|
||||
s.respondUploaded(w, r, m, secret)
|
||||
}
|
||||
|
||||
// updateRemembered applies the form's "remember" checkbox to the cookie. It
|
||||
// only ever acts on a browser form post: an API caller sending a bearer token
|
||||
// has its own way of keeping credentials and should not be handed a cookie.
|
||||
func (s *Server) updateRemembered(w http.ResponseWriter, r *http.Request, req uploadRequest, lim auth.Limits) {
|
||||
if bearer(r) != "" {
|
||||
return
|
||||
}
|
||||
switch {
|
||||
case req.remember && req.explicit && lim.Name != "":
|
||||
s.remember(w, r, req.token)
|
||||
case !req.remember && cookieCredential(r) != "":
|
||||
s.forget(w, r)
|
||||
}
|
||||
}
|
||||
|
||||
func orAnonymous(name string) string {
|
||||
if name == "" {
|
||||
return "(anonymous)"
|
||||
|
||||
Reference in New Issue
Block a user